Information pursuant to art. 13 of Regulation (EU) no. 679/2016 (“GDPR”)

hotelmessenion.it is owned by B&B srl which protects the confidentiality of personal data and guarantees them the necessary protection from any event that could put them at risk of violation.
As required by European Union Regulation no. 679/2016 (“GDPR”), and in particular art. 13, below we provide the user ("Interested Party") with the information required by law relating to the processing of their personal data.

SECTION I


Who we are and what data we process (art. 13, 1st paragraph letter a, art. 15, letter b GDPR)

B&B srl, based in Messina, Via Faranda, 7, 98122 operates as data controller and can be contacted at the email address info@hotelmessenion.it and collects and/or receives information concerning the interested party, such as:

Data category Exemplification of data types
Personal data name, surname, landline and/or mobile telephone number, email address(es).
Telematic traffic data Log, IP address of origin.


B&B srl does not require the interested party to provide so-called data. “particulars”, that is, in accordance with the provisions of the GDPR (art. 9), personal data that reveal racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data, data biometrics intended to uniquely identify a natural person, data relating to the person's health or sexual life or sexual orientation. In the event that the requested service requires the processing of such data, the interested party will receive specific information in advance and will be asked to give specific consent.
The Data Controller has appointed a Data Protection Officer (DPO) who can be contacted for any information and requests: e-mail: info@hotelmessenion.it Telephone: +39 090712674

SECTION II

For what purposes do we need the data of the interested party (art. 13, 1st paragraph GDPR)
The data is used by the Data Controller to follow up on the request for information and/or contact made through the contact form on this site.
Under no circumstances will B&B srl resell the personal data of the interested party to third parties nor use them for undeclared purposes.
In particular, the data of the interested party will be processed for:


Requests for contact and/or information material.
  • The processing of the interested party's personal data takes place to process requests for rental and/or sending of information material, as well as for the fulfillment of any other obligation arising.
  • The legal basis of such processing is the fulfillment of the services inherent to the requests and compliance with legal obligations.

Promotional activities on Services/Products similar to those requested by the interested party (Recital 47 GDPR)
  • The data controller, even without explicit consent, may use the contact data communicated by the interested party, for the purposes of direct promotion of its own Services/Products, limited to the case in which they are Services/Products similar to those subject to the request, unless the interested party explicitly objects.

Commercial promotion activities on Services/Products different from those purchased by the interested party
  • The personal data of the interested party may also be processed for commercial promotion purposes, for surveys and market research with regard to Services/Products that the Data Controller offers only if the interested party has authorized the processing and does not object to this.
  • This processing can take place if the interested party has not revoked his consent for the use of the data, is not registered in the register of objections referred to in the Presidential Decree. n. 178/2010 in an automated way, with the following methods: e-mail, text message, telephone contact.
    The legal basis of such processing is the consent given by the interested party prior to the processing itself, which can be revoked by the interested party freely and at any time (see Section III).

Cyber security
  • The Data Controller, in line with the provisions of Recital 49 of the GDPR, processes, also through its suppliers (third parties and/or recipients), the personal data of the interested party relating to traffic to a strictly necessary and proportionate extent to guarantee the security of the networks and information, i.e. the ability of a network or information system to resist, at a given level of security, unexpected events or illicit or malicious acts that compromise the availability, authenticity, integrity and confidentiality of personal data stored or transmitted.
  • The Data Controller will promptly inform the Interested Parties if there is a particular risk of violation of their data without prejudice to the obligations deriving from the provisions of the art. 33 of the GDPR relating to notifications of personal data breaches.
  • The legal basis of such processing is compliance with legal obligations and the legitimate interest of the Data Controller in carrying out processing relating to the protection of company assets and the security of offices and systems..

Profiling
  • The personal data of the interested party may also be processed for profiling purposes (such as analysis of the data transmitted and the chosen Services/Products, proposing advertising messages and/or commercial proposals in line with the choices expressed by the users themselves) exclusively in the event that the interested party has provided explicit and informed consent. The legal basis of such processing is the consent given by the interested party prior to the processing itself, which can be revoked by the interested party freely and at any time (see Section III).

Fraud prevention (recital 47 and art. 22 GDPR)
  • The personal data of the interested party, with the exception of particular data (Art 9 GDPR) or judicial data (Art 10 GDPR) will be processed to allow checks for the purpose of monitoring and preventing fraudulent payments, by software systems that carry out checks in a manner automated and prior to the negotiation of Services/Products;
  • passing these checks with a negative result will make it impossible to carry out the transaction; In any case, the interested party may express his/her opinion, obtain an explanation or contest the decision by justifying his/her reasons to the Customer Support service or by contacting info@hotelmessenion.it;
  • Personal data collected for anti-fraud purposes only, unlike the data necessary for the correct execution of the requested service, will be immediately deleted at the end of the control phases.

The protection of minors

The Services/Products offered by the Owner are reserved for subjects legally able, on the basis of the national legislation of reference, to conclude contractual obligations.
The Owner, in order to prevent illegitimate access to its services, implements prevention measures to protect your legitimate interest, such as checking your tax code and/or other checks, when necessary for specific Services/Products, the correctness of the identification data of the identity documents issued by the competent authorities.


Communication to third parties and categories of recipients (art. 13, 1° comma GDPR)

The communication of the interested party's personal data takes place mainly with third parties and/or recipients whose activity is necessary for the performance of activities inherent to the established relationship and to respond to certain legal obligations, such as:

Categories of recipients Purpose
Third party suppliers * Provision of services (assistance, maintenance, delivery/shipping of products, provision of additional services, network providers and electronic communications services) connected to the requested service

Credit and digital payment institutions, banking/postal institutions Management of collections, payments, reimbursements connected to contractual performance
External professionals/consultants and consultancy companies Fulfillment of legal obligations, exercise of rights, protection of contractual rights, debt collection
Financial administration, public bodies, judicial authorities, supervisory and control authorities Fulfillment of legal obligations, exercise of rights, protection of contractual rights, debt collection
Subjects formally delegated or having recognized legal title Legal representatives, curators, guardians, etc.

* The Data Controller requires its third party suppliers and Data Processors to comply with security measures equal to those adopted for the Interested Party, limiting the scope of action of the Data Processor to the processing connected to the service requested.
The Data Controller does not transfer your personal data in countries in which the GDPR is not applied (non-EU countries) unless specific indications to the contrary for which you will be informed in advance and your consent will be requested if necessary. The legal basis of such processing is the fulfillment of the services inherent to the established relationship, compliance with legal obligations and the legitimate interest in carrying out processing necessary for these purposes..

SECTION III

What happens if the interested party does not provide his/her data identified as necessary for the execution of the requested service?? (Art. 13, 2° comma, lett. e GDPR)

The collection and processing of personal data is necessary to follow up on the requested services as well as the provision of any requested services. If the interested party does not provide the personal data expressly foreseen as necessary in the request form, the Data Controller will not be able to carry out the processing related to the management of the requested services and/or the contract and the Services/Products connected to it, nor to the obligations that depend on them.


What happens if the interested party does not provide consent to the processing of personal data for commercial promotion activities on Services/Products other than those purchased?

In the event that the interested party does not give his consent to the processing of personal data for these purposes, said processing will not take place for the same purposes, without this having any effect on the provision of the services requested, nor for those for which he has already given consent, if requested.
In the event that the interested party has given consent and subsequently revokes it or opposes the processing for commercial promotion activities, his/her data will no longer be processed for such activities, without this entails prejudicial consequences or effects for the interested party and for the services requested.

How we process the data of the interested party (art. 32 GDPR)

The Data Controller arranges for the use of adequate security measures in order to preserve the confidentiality, integrity and availability of the interested party's personal data and imposes similar security measures on third party suppliers and managers..


Where we process the data of the interested party

The personal data of the interested party are stored in paper, computer and electronic archives located in countries where the GDPR is applied (paesi UE).


How long are the interested party's data stored for? (art. 13, 2° comma, lett. a GDPR)

Unless the latter explicitly expresses their desire to remove them, the personal data of the interested party will be kept for as long as they are necessary for the legitimate purposes for which they were collected.
In particular, they will be kept for the entire duration of the his personal registration and in any case no later than a maximum period of 24 (Twenty-four) months of inactivity, or if, within this period, no Services are associated and/or Products purchased through the same personal data.
In the case of data provided to the Data Controller for the purposes of commercial promotion for services other than those already acquired by the interested party, for which he initially gave consent, these will be kept for 24 months, unless the consent given is revoked.
In the case of data provided to the Data Controller for profiling purposes, these will be kept for 12 months, unless the consent given is revoked.
It should also be added that, in the event that a user forwards personal data in some way to B&B srl not requested or not necessary for the execution of the requested service or for the provision of a service strictly connected to it, the latter cannot be considered the owner of these data, and will delete them as soon as possible.
A regardless of the interested party's determination to remove them, the personal data will in any case be stored according to the terms established by current legislation and/or national regulations for the fulfillment of obligations (e.g. tax and accounting) which remain even after the termination of the contract (art. 2220 c.c.); for these purposes the Data Controller will only retain the data necessary for the relevant pursuit.
Without prejudice to cases in which the rights deriving from the contract and/or from the registry registration must be asserted in court, in which case the personal data of the 'Interested party, exclusively those necessary for these purposes, will be processed for the time necessary for their pursuit.


What are the rights of the interested party?(artt. 15 – 20 GDPR)

The interested party has the right to obtain from the data controller the following:

  1. confirmation of whether or not personal data concerning him or her are being processed and, if so, to obtain access to the personal data and the following information:
    • the purposes of the processing;
    • the categories of personal data in question;
    • the recipients or categories of recipients to whom the personal data have been or will be communicated, in particular if recipients are from third countries or international organizations;
    • where possible, the expected retention period of personal data or, if this is not possible, the criteria used to determine this period;
    • the existence of the right of the interested party to ask the data controller to rectify or delete personal data or to limit the processing of personal data concerning him or to oppose their processing;
    • the right to lodge a complaint with a supervisory authority;
    • if the data are not collected from the interested party, all available information on their origin;
    • the existence of an automated decision-making process, including profiling, and, at least in such cases, significant information on the logic used, as well as the importance and expected consequences of such processing for the interested party.
    • the adequate guarantees provided by the third country (non-EU) or an international organization to protect any data transferred
  2. the right to obtain a copy of the personal data being processed, provided that this right does not harm the rights and freedoms of others; In case of further copies requested by the interested party, the data controller may charge a reasonable fee based on administrative costs.
  3. the right to obtain from the data controller the rectification of inaccurate personal data concerning him without unjustified delay
  4. the right to obtain from the data controller the deletion of personal data concerning him without unjustified delay, if the reasons provided for by the GDPR in art. exist. 17, including, for example, in the event that they are no longer necessary for the purposes of the processing or if this is considered unlawful, and always if the conditions established by law exist; and in any case if the processing is not justified by another equally legitimate reason;
  5. the right to obtain from the data controller the limitation of processing, in the cases provided for in the art. 18 of the GDPR, for example where you have contested its accuracy, for the period necessary for the Data Controller to verify its accuracy. The interested party must also be informed, within a reasonable time, of when the suspension period has been completed or the cause of the limitation of processing has ceased to exist, and therefore the limitation itself revoked;
  6. the right to obtain communication from the owner of the recipients to whom the requests for any corrections or cancellations or limitations of the processing carried out have been transmitted, unless this proves impossible or involves a disproportionate effort.
  7. the right to receive personal data concerning him in a structured, commonly used and machine-readable format and the right to transmit such data to another data controller without impediments on the part of the data controller to whom he has sent them provided, in the cases provided for by the art. 20 of the GDPR, and the right to obtain the direct transmission of personal data from one data controller to another, if technically feasible.

For any further information and in any case to send your request you must contact the Owner at the address info@hotelmessenion.it. In order to guarantee that the above-mentioned rights are exercised by the interested party and not by unauthorized third parties, the Data Controller may request the same to provide any further information necessary for the purpose..


How and when can the interested party object to the processing of their personal data?(Art. 21 GDPR)

For reasons relating to the particular situation of the interested party, the interested party may object at any time to the processing of their personal data if it is based on legitimate interest or if it takes place for commercial promotional activities, by sending the request to the Data Controller at the address info@hotelmessenion.it

The interested party has the right to have their personal data deleted if there is no overriding legitimate reason of the Data Controller compared to that which gave rise to the request, and in any case in the event that the interested party has objected to the processing for commercial promotion activities.


To whom can the interested party lodge a complaint? (Art. 15 GDPR)

Without prejudice to any other administrative or judicial action, the interested party may submit a complaint to the competent supervisory authority on Italian territory (Personal Data Protection Authority) or to the one that carries out its tasks and exercises its powers. in the Member State where the violation of the GDPR occurred.

Any update to this Information will be communicated promptly and by appropriate means and will also be communicated if the Data Controller processes the data of the interested party for purposes other than those referred to in this Information before proceeding and following the manifestation of the relevant consent of the interested party. 'Interested if necessary.

SECTION IV

COOKIE


General information, deactivation and management of cookies

Cookies are data that are sent by the website and stored by the internet browser on the user's computer or other device (for example, tablet or mobile phone). Technical cookies and third-party cookies may be installed from our website or its subdomains.

In any case, the user will be able to manage, or request the general deactivation or deletion of cookies, by changing the settings of their internet browser. This deactivation, however, may slow down or prevent access to some parts of our site.

The settings for managing or deactivating cookies may vary depending on the internet browser used, therefore, for more information on how to carry out these operations, we suggest the User consult the manual of their device or the " Help” or “Help” of your internet browser.
Below we indicate to Users the links that explain how to manage or disable cookies for the most popular internet browsers:


Tecnical Cookie

The use of technical cookies, i.e. cookies necessary for the transmission of communications on an electronic communications network or cookies strictly necessary for the supplier to provide the service requested by the customer, allows the safe and efficient use of our site.
They may session cookies be installed in order to allow access and permanence in the reserved area of the portal as an authenticated user.
Technical cookies are essential for the correct functioning of our website and are used to allow users normal navigation and the possibility of using the advanced services available on our website. The technical cookies used are divided into session cookies, which are stored exclusively for the duration of navigation until the browser is closed, and persistent cookies which are saved in the memory of the user's device until they expire or are deleted by the user. same. Our site uses the following technical cookies:

  • Technical navigation or session cookies, used to manage normal navigation and user authentication;
  • Functional technical cookies, used to store customizations chosen by the user, such as, for example, the language;
  • Technical analytics cookies, used to understand how users use our website so we can evaluate and improve its functioning.

Third party cookies

Third-party cookies may be installed: these are analytical and profiling cookies from Google Analytics, Google Doubleclick, Criteo, Rocket Fuel, Youtube, Yahoo, Bing and Facebook. These cookies are sent from the websites of the aforementioned third parties external to our site.
Third party analytical cookies are used to detect information on user behavior on the site. The detection takes place anonymously, in order to monitor performance and improve the usability of the site. Third-party profiling cookies are used to create profiles relating to users, in order to propose advertising messages in line with the choices expressed by the users themselves.
The use of these cookies is governed by the rules established by the third parties themselves , therefore, Users are invited to read the privacy information and the instructions for managing or disabling cookies published on the following web pages:

For Google Analytics cookies:

For cookies of Facebook:

For cookies of Youtube: