INTRODUCTION
In accordance with European Regulation 2016/679, data is collected for specific and legitimate purposes and processed in a manner compatible with those purposes; data is adequate, relevant, and limited to what is necessary for the purposes for which it is processed; data is processed lawfully, fairly, and transparently.
This Privacy Policy outlines the nature, scope, and purposes of the processing of personal data (hereinafter “data”) for the services offered to our clients via the website, social networks, and any other forms of communication and transmission.
DATA CONTROLLER
The Data Controller is STEMOR S.R.L., headquartered in Ceresara (MN), Via Sant’Agnese No. 3, VAT No. 02647810205, PEC: stemor@legalmail.it, email: privacy@stemor.it
DATA PROCESSING LOCATION
Data processing related to the services of this site occurs at the offices of the Data Controller and External Processors, whose list is available at the Data Controller’s office, and is handled by authorized personnel.
The site stemor.it is hosted on machines managed by SITEGROUND SPAIN S.L., based in the Netherlands.
By using the “book” section, you will be redirected to the “Teamsystem Hospitality” platform provided by TeamSystem S.p.A. The provider TeamSystem states that data is hosted on the AWS infrastructure within the European Union (Frankfurt Region). In exceptional cases, access may be granted to technical staff and subcontractors employed by Azure, located in the United States or other non-European countries, for technical support and maintenance purposes. For such transfers, the provider has declared the signing of contractual clauses pursuant to Article 46 paragraph 2 letter c) of the GDPR for the transfer of personal data to processors established in third countries, approved by the European Commission, and has conducted risk assessments with positive outcomes. A complete and updated list of third parties processing data on behalf of the provider can be requested by writing to privacy@teamsystem.com.
COLLECTION AND PROCESSING OF PERSONAL DATA – PURPOSES AND LEGAL BASIS
Navigation Data
The IT systems and software procedures responsible for the operation of this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. These are information that is not collected to be associated with identified individuals but which, by their very nature, could, through processing and association with data held by third parties, allow the identification of users. This category of data includes IP addresses or domain names of the computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server’s response (successful, error, etc.), and other parameters related to the user’s operating system and IT environment. These data are used solely to derive statistical information on the use of the site and to ensure its correct functioning. Data could be used to ascertain responsibility in the event of hypothetical computer crimes against the site.
Cookies
Information regarding the use of cookies on our website can be found in the dedicated Cookie Policy. (https://stemor.it/cookie-policy/)
Cookies are not used to determine the personal identity of those visiting the website.
Data Voluntarily Provided
In the “contact” section:
You will be asked to provide:
- Personal data such as name, surname, phone number, and email address.
| Purpose | Legal Basis |
| Responding to information requests submitted by the individual via email or phone. | Execution of pre-contractual and contractual measures upon the individual’s request pursuant to Article 6(1)(b) of the EU Regulation. |
| Commercial marketing. | Consent, pursuant to Article 6(1)(a) of the EU Regulation. Data will be used only with free, optional, and explicit consent, which can be withdrawn at any time. |
In the “book” section:
You will be asked to provide:
- Personal data required for service provision, such as personal details (name, surname, tax code, ID document, contact details such as phone number and email address),
- Billing information (VAT number, company name),
- Payment details: To complete the payment for the requested service, you will need to enter your payment card details on a page that will communicate securely with the payment service (acting as an independent Data Controller), without passing through the Data Controller’s server, which will not process such data in any way. With reference to payment card details, it is specified that processing is necessary to allow the conclusion of the contract.
- Regarding the possible processing of “special data” (e.g., related to health conditions), such information is not requested and/or collected by the Data Controller, except for spontaneous indications by the individual, which will represent expressed consent to the processing of such data (e.g., reasons for exemption from tourist tax).
| Purpose | Legal Basis |
| Managing orders and ensuring the correct execution of the purchase contract and related operations, including payment. | Execution of pre-contractual and contractual measures upon the individual’s request pursuant to Article 6(1)(b) of the EU Regulation. Providing personal data is necessary; therefore, failure to provide such data will result in the impossibility of executing the contract. |
| Compliance with fiscal and accounting legal obligations. | Legal obligation under national and European regulations pursuant to Article 6(1)(c) of the EU Regulation. |
Exercising and defending the Data Controller’s rights in judicial, administrative, arbitration, and/or mediation and conciliation procedures. | The Data Controller’s legitimate interest pursuant to Article 6(1)(f) of the EU Regulation. The processing involves a proper balance between the Data Controller’s right to protect their right of defense and contradiction and the individual’s expectations. |
| Marketing through “soft spam,” sending commercial communications to its customers about services similar to those already purchased. | The Data Controller’s legitimate interest pursuant to Article 6(1)(f) of the EU Regulation, unless otherwise objected to by the individual. |
DATA RECIPIENTS
The Data Controller will only disclose personal data to third parties that provide an adequate level of data protection for the following reasons: when necessary to fulfill the individual’s request involving third parties with whom the Data Controller has a relationship; when the disclosure is related to the provision of a requested service; when required by Authorities or by law.
For the purposes mentioned above, the personal data of the individual may be disclosed to the following recipients:
- Employees/collaborators of the Data Controller authorized to process data;
- System administrators;
- External professionals providing functional services to achieve the stated purposes (e.g., accountants, data processing centers, lawyers, etc.);
- Banking and insurance institutions;
- Public Safety Authorities, Tax Administration;
- Software houses for website management;
- Software houses for booking service management.
Recipients of the data may act as Independent Data Controllers (i.e., entities that independently determine the purposes and means of data processing) or External Data Processors (i.e., entities processing personal data on behalf of the Data Controller).
The list of Processors is available at the Data Controller’s headquarters.
The Data Controller does not process personal data and/or information obtained through this website for dissemination or sale to third parties for marketing purposes.
DATA TRANSFER
Personal data is stored within the European Union.
PROCESSING METHODS
Personal data may be processed in both paper and electronic formats.
Specific security measures are observed to prevent data loss, unlawful use, unauthorized access, or processing inconsistent with the purposes for which it was collected.
RETENTION PERIOD
Data and information collected regarding website users are retained for the time necessary to achieve the purposes for which they are processed.
For compliance with legal obligations, constraints derived from civil, fiscal, and corporate law, the need to exercise a right in judicial proceedings, or other specific constraints established by the legislator, personal data is retained for 10 years; disputes may lead to additional retention obligations.
Consent for marketing purposes remains valid until withdrawal; marketing activities are based on data collected over the last 36 months.
SECURITY MEASURES
The Data Controller adopts appropriate security measures to minimize the risks of intrusion, loss, unauthorized access, or unauthorized or improper processing of data.
We recommend ensuring that the computer used is equipped with adequate devices for protecting network data transmission, both incoming and outgoing (such as updated antivirus systems).
Data transmission via the Internet is not always secure, and despite taking all necessary measures to ensure data protection, it is not possible to exclude potential risks due to factors beyond the Data Controller’s control. Therefore, when the individual decides to transmit their data through systems with Internet access, they are aware of the potential risks that may arise from such activity.
INDIVIDUAL’S RIGHTS AND GENERAL INFORMATION
Pursuant to Article 7(3) GDPR: the right to withdraw consent at any time with future effect.
Pursuant to Article 15 GDPR: the right to obtain confirmation of whether or not personal data concerning them is being processed and, if so, to access personal data, additional information, and a copy of the data.
Pursuant to Article 16 GDPR: the right to obtain the rectification of inaccurate personal data or the completion of incomplete personal data.
Pursuant to Article 17 GDPR: the right to obtain the erasure of personal data without undue delay, or alternatively, pursuant to Article 18 GDPR, the right to obtain the restriction of personal data processing.
Pursuant to Article 20 GDPR: the right to receive personal data concerning them and the right to transmit such data to another data controller.
Pursuant to Article 21 GDPR: the right to object at any time to the processing of personal data concerning them for the future. The right to object can particularly be exercised concerning direct marketing purposes.
Pursuant to Article 77 GDPR: the right to lodge a complaint with the Data Protection Authority (urp@gdpr.it).
The above rights may be exercised at any time by request to the Data Controller via PEC: stemor@legalmail.it or email: privacy@stemor.it