Privacy Policy

Privacy Policy

INTRODUCTION

In accordance with European Regulation 2016/679, data is collected for specific and legitimate purposes and processed in a manner compatible with those purposes; data is adequate, relevant, and limited to what is necessary for the purposes for which it is processed; data is processed lawfully, fairly, and transparently.

This Privacy Policy outlines the nature, scope, and purposes of the processing of personal data (hereinafter “data”) for the services offered to our clients via the website, social networks, and any other forms of communication and transmission.

DATA CONTROLLER

The Data Controller is STEMOR S.R.L., headquartered in Ceresara (MN), Via Sant’Agnese No. 3, VAT No. 02647810205, PEC: stemor@legalmail.it, email: privacy@stemor.it

DATA PROCESSING LOCATION

Data processing related to the services of this site occurs at the offices of the Data Controller and External Processors, whose list is available at the Data Controller’s office, and is handled by authorized personnel.

The site stemor.it is hosted on machines managed by SITEGROUND SPAIN S.L., based in the Netherlands.

By using the “book” section, you will be redirected to the “Teamsystem Hospitality” platform provided by TeamSystem S.p.A. The provider TeamSystem states that data is hosted on the AWS infrastructure within the European Union (Frankfurt Region). In exceptional cases, access may be granted to technical staff and subcontractors employed by Azure, located in the United States or other non-European countries, for technical support and maintenance purposes. For such transfers, the provider has declared the signing of contractual clauses pursuant to Article 46 paragraph 2 letter c) of the GDPR for the transfer of personal data to processors established in third countries, approved by the European Commission, and has conducted risk assessments with positive outcomes. A complete and updated list of third parties processing data on behalf of the provider can be requested by writing to privacy@teamsystem.com.

COLLECTION AND PROCESSING OF PERSONAL DATA – PURPOSES AND LEGAL BASIS

Navigation Data

The IT systems and software procedures responsible for the operation of this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. These are information that is not collected to be associated with identified individuals but which, by their very nature, could, through processing and association with data held by third parties, allow the identification of users. This category of data includes IP addresses or domain names of the computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server’s response (successful, error, etc.), and other parameters related to the user’s operating system and IT environment. These data are used solely to derive statistical information on the use of the site and to ensure its correct functioning. Data could be used to ascertain responsibility in the event of hypothetical computer crimes against the site.

Cookies

Information regarding the use of cookies on our website can be found in the dedicated Cookie Policy. (https://stemor.it/cookie-policy/)

Cookies are not used to determine the personal identity of those visiting the website.

Data Voluntarily Provided

In the “contact” section:

You will be asked to provide:

PurposeLegal Basis
Responding to information requests submitted by the individual via email or phone.Execution of pre-contractual and contractual measures upon the individual’s request pursuant to Article 6(1)(b) of the EU Regulation.
Commercial marketing.Consent, pursuant to Article 6(1)(a) of the EU Regulation. Data will be used only with free, optional, and explicit consent, which can be withdrawn at any time.

In the “book” section:

You will be asked to provide:

PurposeLegal Basis
Managing orders and ensuring the correct execution of the purchase contract and related operations, including payment.Execution of pre-contractual and contractual measures upon the individual’s request pursuant to Article 6(1)(b) of the EU Regulation. Providing personal data is necessary; therefore, failure to provide such data will result in the impossibility of executing the contract.
Compliance with fiscal and accounting legal obligations.Legal obligation under national and European regulations pursuant to Article 6(1)(c) of the EU Regulation.

Exercising and defending the Data Controller’s rights in judicial, administrative, arbitration, and/or mediation and conciliation procedures.

The Data Controller’s legitimate interest pursuant to Article 6(1)(f) of the EU Regulation. The processing involves a proper balance between the Data Controller’s right to protect their right of defense and contradiction and the individual’s expectations.
Marketing through “soft spam,” sending commercial communications to its customers about services similar to those already purchased.The Data Controller’s legitimate interest pursuant to Article 6(1)(f) of the EU Regulation, unless otherwise objected to by the individual.

DATA RECIPIENTS

The Data Controller will only disclose personal data to third parties that provide an adequate level of data protection for the following reasons: when necessary to fulfill the individual’s request involving third parties with whom the Data Controller has a relationship; when the disclosure is related to the provision of a requested service; when required by Authorities or by law.

For the purposes mentioned above, the personal data of the individual may be disclosed to the following recipients:

Recipients of the data may act as Independent Data Controllers (i.e., entities that independently determine the purposes and means of data processing) or External Data Processors (i.e., entities processing personal data on behalf of the Data Controller).

The list of Processors is available at the Data Controller’s headquarters.

The Data Controller does not process personal data and/or information obtained through this website for dissemination or sale to third parties for marketing purposes.

DATA TRANSFER

Personal data is stored within the European Union.

PROCESSING METHODS

Personal data may be processed in both paper and electronic formats.

Specific security measures are observed to prevent data loss, unlawful use, unauthorized access, or processing inconsistent with the purposes for which it was collected.

RETENTION PERIOD

Data and information collected regarding website users are retained for the time necessary to achieve the purposes for which they are processed.

For compliance with legal obligations, constraints derived from civil, fiscal, and corporate law, the need to exercise a right in judicial proceedings, or other specific constraints established by the legislator, personal data is retained for 10 years; disputes may lead to additional retention obligations.

Consent for marketing purposes remains valid until withdrawal; marketing activities are based on data collected over the last 36 months.

SECURITY MEASURES

The Data Controller adopts appropriate security measures to minimize the risks of intrusion, loss, unauthorized access, or unauthorized or improper processing of data.

We recommend ensuring that the computer used is equipped with adequate devices for protecting network data transmission, both incoming and outgoing (such as updated antivirus systems).

Data transmission via the Internet is not always secure, and despite taking all necessary measures to ensure data protection, it is not possible to exclude potential risks due to factors beyond the Data Controller’s control. Therefore, when the individual decides to transmit their data through systems with Internet access, they are aware of the potential risks that may arise from such activity.

INDIVIDUAL’S RIGHTS AND GENERAL INFORMATION

Pursuant to Article 7(3) GDPR: the right to withdraw consent at any time with future effect.

Pursuant to Article 15 GDPR: the right to obtain confirmation of whether or not personal data concerning them is being processed and, if so, to access personal data, additional information, and a copy of the data.

Pursuant to Article 16 GDPR: the right to obtain the rectification of inaccurate personal data or the completion of incomplete personal data.

Pursuant to Article 17 GDPR: the right to obtain the erasure of personal data without undue delay, or alternatively, pursuant to Article 18 GDPR, the right to obtain the restriction of personal data processing.

Pursuant to Article 20 GDPR: the right to receive personal data concerning them and the right to transmit such data to another data controller.

Pursuant to Article 21 GDPR: the right to object at any time to the processing of personal data concerning them for the future. The right to object can particularly be exercised concerning direct marketing purposes.

Pursuant to Article 77 GDPR: the right to lodge a complaint with the Data Protection Authority (urp@gdpr.it).

The above rights may be exercised at any time by request to the Data Controller via PEC: stemor@legalmail.it or email: privacy@stemor.it