Tenuta di Valgiano

Information on the processing of personal data

(pursuant to Article 13 of EU Regulation 2016/679)

Introduction

This page describes how the website www.valgiano.it (hereinafter the “Site”) is managed with regard to the processing of the personal data of the users who consult it. This notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter “GDPR”) to those who interact with the web services of the Site. The notice is provided solely for the Site in question and not for other websites that may be consulted by the user through links  

  1. Data Controller

The Data Controller is Tenuta di Valgiano di Petrini & C. S.A.S. Società Agricola, with registered office at Via di Valgiano, 7 – 55010 Frazione Valgiano – Capannori (LUCCA) (hereinafter the “Controller”)  

For any information or to exercise your rights, you may contact the Controller at the following addresses:

  • Email:info@valgiano.it, PEC: valgiano@pec-mail.it
  • Post: TENUTA DI VALGIANO, Via di Valgiano, 7 – 55010 Frazione Valgiano – Capannori (LUCCA).
  1. Types of Data Processed, Purposes and Legal Basis
  • Browsing Data The computer systems and software procedures used to operate this Site acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes IP addresses, the domain names of the computers used by users, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, and other parameters relating to the user’s operating system and computer environment.
    • Purposes: These data are used to:
      1. Obtain anonymous statistical information on the use of the Site and check that it is functioning correctly.
      2. Ensure the security of the Site and ascertain any liability in the event of hypothetical computer crimes against the Site.
    • Legal Basis: The processing is based on the legitimate interest of the Controller (Art. 6(1)(f) GDPR) in ensuring the proper functioning and security of the Site.
  • Data Voluntarily Provided by the User The optional, explicit and voluntary sending of e-mails to the addresses indicated on this Site, or the completion of the booking forms on the site, entails the subsequent acquisition of the sender’s address, as well as of the other personal data included in the communication, which are necessary to respond to requests.
    • Purposes: Processing and responding to the requests made by the user.
    • Legal Basis: The processing is necessary for the performance of pre-contractual measures taken at the request of the data subject (Art. 6(1)(b) GDPR).
  • Data voluntarily provided by the User concerning health conditions: relating to health status, such as food intolerances, allergies or special dietary requirements. Pursuant to Art. 9 of EU Reg. 2016/679, the voluntary communication of this information by the data subject is equivalent to explicit consent to its processing for the purposes indicated below.
    • Purposes: ensuring safety and well-being during events, including the serving of meals
    • Legal basis: the processing is necessary for the safe performance of contractual obligations
  • Cookies The Site uses technical cookies and third-party cookies. Cookies are small text files that the sites visited send to the user’s terminal, where they are stored and then transmitted back to the same sites on the next visit.
    1. Technical (session) Cookies: The use of these cookies is strictly limited to the transmission of session identifiers necessary to allow safe and efficient browsing of the Site. They are not stored persistently and are deleted when the browser is closed. The prior consent of users is not required for the installation of such cookies.
    2. Analytics Cookies (Google Analytics): The Site uses the Google Analytics service to collect and analyse, in aggregate and anonymous form, information on users’ browsing behaviour. To protect users’ privacy, the Controller has adopted tools that reduce the identifying power of cookies (anonymisation of the IP address) and has configured the service so as to prevent Google from cross-referencing the information collected with other information already in its possession. By virtue of these measures, the use of these cookies is comparable to that of technical cookies and does not require the user’s consent.

For more information, please refer to Google’s privacy policy and to the methods for deactivating the service. For detailed management of cookies, users are invited to consult the Site’s extended cookie notice (cookie policy).

  1. Methods of Processing and Data Retention Period

Personal data are processed with automated and non-automated tools for the time strictly necessary to achieve the purposes for which they were collected. Specific security measures are observed to prevent the loss of data, unlawful or incorrect use and unauthorised access, in accordance with the principle of integrity and confidentiality (Art. 5(1)(f) GDPR)  

The data will be retained for the following periods:

  • Browsing data: They are deleted immediately after statistical processing and retained for a maximum of 7 days for security purposes, except where necessary for the investigation of offences by the judicial authorities.
  • Voluntarily provided data: They are retained for the time necessary to process the user’s request and to comply with any subsequent legal obligations.
  1. Communication and Dissemination of Data

Personal data will not be disseminated. They may be communicated to:

  • Personnel authorised by the Controller to process the data.
  • Third parties carrying out outsourced activities on behalf of the Controller (e.g. technical service providers, hosting providers), appointed, where necessary, as Data Processors pursuant to Art. 28 GDPR. The updated list of Processors may always be requested from the Controller.
  • Public authorities, where required by law or for the prevention and prosecution of crimes.

With regard to the Google Analytics service, the processing of data may involve a transfer outside the European Union. Such transfer is legitimised by the adoption of Standard Contractual Clauses approved by the European Commission, which guarantee an adequate level of protection.

  1. Rights of Data Subjects

As a data subject, you have the right to exercise the rights provided for in Articles 15 to 22 of the GDPR. In particular, you may request from the Controller:

  • theaccess to your personal data (Art. 15);
  • the rectification of inaccurate data or the completion of incomplete data (Art. 16);
  • the erasure of data (the so-called “right to be forgotten”), where one of the conditions provided for in Art. 17 applies;
  • the restriction of processing, where one of the cases provided for in Art. 18 applies;
  • the portability of data, i.e. the right to receive the personal data concerning you in a structured, commonly used and machine-readable format (Art. 20);
  • theobjection to processing on grounds relating to your particular situation (Art. 21).

Requests should be addressed to the Controller’s contact details indicated in point 1. The Controller will respond without undue delay and in any event no later than one month from receipt of the request, a period which may be extended by two months in case of complexity.  

Right to Lodge a Complaint

If you believe that the processing of your personal data infringes the provisions of the GDPR, you have the right to lodge a complaint with the competent supervisory authority, which for Italy is the Garante per la Protezione dei Dati Personali (Italian Data Protection Authority) (www.gpdp.it), as provided for by Art. 77 of the GDPR, or to take appropriate legal action (Art. 79 of the GDPR).

Scroll to Top