PRIVACY POLICY
1 – DATA CONTROLLER
The Data Controller is Gebel s.r.l., in the person of its legal representative, with registered office at Via Degli Alpini n.9, 65029 Torre de’ Passeri (PE), VAT No. 01114900689. The Controller can be contacted by phone at +39 085 884021 or via email at info@gebel.it.
2 – OBJECT OF THE PROCESSING
The Controller processes personal identification data (e.g., name, surname, address, phone number, email) – hereinafter referred to as “personal data” or “data” – provided by you upon the conclusion of contracts for services provided by the Controller or for other purposes indicated in Art. 3 of this Policy.
3 – PURPOSES OF PROCESSING
Personal data may be processed, pursuant to Art. 4 of the GDPR, for the following purposes:
| Purpose | Retention Period |
| A – Execution of the contract: Processing for stay services, bookings, and fiscal/tax activities in accordance with legal provisions. | Data is stored for the period required by applicable fiscal and tax laws. |
| B – Compliance with public safety laws: Processing for requirements related to public safety (Royal Decree 18/06/1931, n. 773 art. 109). | For the time strictly necessary to fulfill public safety obligations. |
| C – Marketing and communication: Processing for messaging and newsletter distribution. | Data is stored for a period not exceeding two years from the time consent is granted. |
| D – Contact requests: Processing to respond to messages and contact requests via the website or other messaging forms indicated on the site. | Data is stored for a period not exceeding one month or as necessary to provide the requested information. In the event of a subsequent booking, data is processed according to Purpose A. |
Company policy ensures that information is used to guarantee user/customer satisfaction and meet expectations, following the principles of necessity and data minimization.
Legal Basis:
- For Purpose A: Art. 6, par. 1, lett. b) of the GDPR (performance of a contract).
- For Purpose B: Art. 6, par. 1, lett. c) of the GDPR (compliance with a legal obligation).
- For Purposes C and D: Art. 6, par. 1, lett. a) of the GDPR (consent of the data subject).
4 – NATURE OF DATA PROVISION AND CONSENT
The provision of data is optional but necessary to implement the purposes indicated in Art. 3, letters C) and D). It is mandatory for the purposes indicated in letters A) and B). Any refusal by the data subject will make it impossible for the Controller to establish or execute the relationship.
Consent for purposes C and D must be free and informed. The data subject may withdraw consent at any time as specified in Art. 10.
5 – PROCESSING METHODS
The processing of your personal data will be consistent with the principles of correctness, lawfulness, and transparency, protecting your privacy and rights. Data will be processed using IT systems or paper supports by specifically authorized and trained personnel. The Controller has implemented technical and organizational security measures appropriate to the risk level.
6 – COMMUNICATION TO CATEGORIES OF RECIPIENTS
Data may be communicated to:
- Entities authorized by law, regulations, or EU legislation.
- Partner companies/suppliers providing technical support.
- Professional consultants (e.g., Legal and Accounting firms) for accounting and contractual management.
- Carriers, couriers, and postal services for the delivery of products/materials.
- IT service providers for purposes related to the assistance contract with the Controller.Data will not be disseminated without the written consent of the data subject.
7 – RETENTION PERIOD
Retention periods are specified in Art. 3 of this Policy.
8 – DATA TRANSFER ABROAD
Personal data will not be transmitted to third countries or outside the European Union. Should future transfers occur, they will comply with Chapter V of EU Regulation 2016/679 to ensure an adequate level of protection.
9 – AUTOMATED PROCESSES
Gebel s.r.l. does not use decision-making processes based on automated processing, including profiling.
10 – RIGHTS OF THE DATA SUBJECT
Pursuant to Articles 13-22 of the GDPR, the data subject has the right to:
- Confirm the existence of their personal data and receive it in an intelligible form.
- Obtain information on the origin, purpose, and methods of processing.
- Request access, rectification, limitation, or integration of data.
- Request erasure (right to be forgotten) or blocking of data processed in violation of the law.
- Obtain data portability.
- Object, in whole or in part, to processing for legitimate reasons or for marketing purposes.
- Lodge a complaint with the Data Protection Authority (Garante Privacy) at www.garanteprivacy.it.
To exercise these rights, please contact the Controller using the details provided in Art. 1.
Date: 06/05/2023
Who we share your data with
Suggested text: If you request a password reset, your IP address will be included in the reset email.
How long we retain your data
Suggested text: If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
Suggested text: If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Where we send your data
Suggested text: Visitor comments may be checked through an automated spam detection service.
