Privacy Policy

Pursuant to Articles 4 and 28 of Italian Legislative Decree No. 196 of 30 June 2003 – the Privacy Code (hereinafter, the “Code”) and Articles 4(7) and 24 of EU Regulation 2016/679 of 27 April 2016 concerning the protection of natural persons with regard to the processing of personal data (hereinafter, the “Regulation”), and pursuant to Article 13 of the Code and the Regulation, Viaggi Salvadori hereby informs you that, for the establishment and performance of its ongoing relationship with you, it holds personal data relating to you (including identification and tax data), acquired directly, including verbally, or through third parties.

To comply with the obligations set out in the Code and in EU regulations concerning privacy in relation to your personal data, we invite you to read the following privacy notice and to provide your consent to the processing of the personal data that our company may acquire.

The General Data Protection Regulation (or GDPR for short) is a positive step toward giving individuals greater control over how their personal data is used. This new legislation came into force on 25 May 2018, and we have updated a number of processes and policies to ensure that our business is fully prepared. We are committed to protecting and respecting the personal information shared with us.

This statement describes the types of information we collect, how it is used, how we share it with other organizations, how you can exercise your rights regarding the information we hold, and how you can contact us.

With regard to direct marketing communications, you can always ask us to stop such activities. We will never send unsolicited emails or communications, nor will we share your data with anyone else. We do not sell your information to third parties, but we work closely with selected partners who help us provide the information, products and services you request.

WHAT INFORMATION IS COLLECTED

We collect personal information through our website, applications, or direct contact. We only collect information that is necessary, relevant, and appropriate for the purpose for which it is provided. The information we collect includes some or all of the following:

  • Personal identification, contact and financial data: this includes first name, surname, date and place of birth, tax code, address, telephone number, email address and other contact details, as well as bank account and payment card details collected exclusively for the purpose of managing the commercial relationship.
  • Special categories of personal data: special categories of data relating to you, in particular information concerning your health status (e.g. in the event of disabilities, medical conditions or intolerances that may require specific arrangements when organizing the trip, as well as for the purpose of taking out an insurance policy).
  • Personal data of family members: finally, for the performance of the contract, the Data Controller may need to collect personal data relating to your family members, including minors.
  • Marketing and communications data: this includes your preferences regarding the receipt of marketing communications from us and from third parties, as well as your communication preferences.
HOW WE USE THE INFORMATION WE COLLECT

Only the information necessary for the purpose for which it was collected is processed. Processing is carried out through the operations, or sets of operations, referred to in Article 4, paragraph 1, letter a) of the Consolidated Act: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, blocking, communication, deletion and destruction of data. The data will be processed in written form and/or on magnetic, electronic or telematic media, including when the data is disclosed to the parties identified in this privacy notice, who in turn undertake to process it using only methods and procedures strictly necessary for the specific purposes of the processing and on the relevant legal basis. Processing is carried out by authorized personnel and collaborators within the scope of their respective duties and in accordance with the instructions received, always and solely for the achievement of the specific purposes, in strict compliance with the principles of confidentiality and security required by the aforementioned legislation. Personal data is used exclusively for the purposes and on the legal bases set out in the following table:

.

Purpose(s) of Processing

Legal Bases for Processing

PURPOSE A.
We may use and process personal information where necessary to perform a contract, to fulfill and complete orders, purchases and other transactions entered into with us, and to analyze contractual performance.
  • Provide technical support for the product.
  • Provide user training courses and certifications to customers.
  • Manage the relationship, including order processing and delivery of the requested product or service, as well as the corresponding relationship with suppliers.
Processing is necessary for the performance of a contract or in order to enter into a contract.
PURPOSE B.
  • Provide information about our company and its products and services, and send newsletters or email updates to the user;
  • To inform you about special offers and products or services that may be of interest to you.
Consent – which may be withdrawn at any time.
PURPOSE C.
  • Measure the interest of customers and suppliers and improve our products, services and website.
  • Provide the requested information, products, or services.
  • To comply with the obligations arising from any contracts entered into.
  • Help us provide the highest level of customer care;
Processing is necessary to support our legitimate business interests in managing our activities. Please note that you have the right to object to the processing of your personal data carried out on the basis of our legitimate interests. In other words, your right to object at any time is fully guaranteed.
PURPOSE D.
For the prevention and detection of fraud, money laundering or other criminal offences, or for the purpose of responding to a binding request from a public authority or court
Processing is necessary to comply with legal and regulatory obligations.
PURPOSE E.
We may need to process personal information in order to contact the data subject in the event of an urgent safety notice.
In rare cases, this may be based on Vital Interests.
3. HOW WE SHARE THIS INFORMATION

We do not share information with third parties. However, from time to time, we may disclose information to the following categories of companies or organizations to which we entrust the management of services on our behalf:

  • airlines, hotels, transfer services and excursion providers;
  • Insurance companies;
  • entities that provide services for the management of the Data Controller’s IT systems;
  • entities providing professional tax, legal and judicial consulting and assistance services;
  • entities responsible for auditing and certifying the financial statements;
  • any other entity to which the data must be disclosed pursuant to an express provision of law.
  • customer support service providers and customer care call centers,
  • direct marketing agencies and consultants, market research firms, and market analysis service providers
  • legal advisors and other professionals.

We make every effort to ensure that all third-party partners handling personal information comply with data protection legislation and safeguard the information in the same way we do. We only disclose the personal information that is STRICTLY necessary to provide the services they perform on our behalf. Wherever possible, we aim to anonymize the information or use specific aggregated data sets.

4. HOW LONG WE RETAIN THE INFORMATION

We will not retain personal information in an identifiable format for longer than necessary. For customers or suppliers, we retain personal information for a longer period than we do for prospective customers/suppliers. In the case of an ongoing relationship (for example, with a customer), we retain personal information for 10 years from the date our relationship ends. We retain personal information for this period in order to establish, pursue or defend any legal claims.

Where we have obtained personal information following a request for information, brochures, quotations or any other information about one of our products or services, we retain the personal information for 1 year and 6 months from the date on which we collect it, unless an actual relationship is established during that period, for example through a purchase. We will continue to process such data in line with the initial request for 6 months, allowing us to establish a relationship with the prospective customer/supplier. After this period, the data will remain inactive for 1 year before being deleted, unless a relationship is established within that time.

The only exceptions to the retention periods mentioned above are where:

  • the law requires us to retain personal information for a longer period, or to delete it sooner;
  • where you have raised a complaint or concern regarding a product or service offered, in which case we will retain your information for a period of 10 years from the date of that complaint or request;
  • you exercise your right to have the information deleted (where applicable), and there is no need to retain it for any of the reasons permitted or required by law.
5. HOW YOUR INFORMATION CAN BE MANAGED

Each data subject has the right, as an individual, to access their personal information and request corrections where necessary. They also have the right to withdraw any consent previously provided to us and to request the deletion of the information we hold. The data subject may also object to the use of their personal information where we rely on our legitimate business interests to process and use such personal data.

There are a number of rights relating to personal information under data protection law. In relation to most of these rights, we will ask for information to confirm your identity and, where applicable, to help us locate your personal information. Except in rare cases, we will respond within 30 days of receiving the request.

Users have the following rights:

  • Request a copy of the information we hold about you;
  • Correct and update your information;
  • Withdraw your consent. Please see “How We Use This Information”;
  • Object to our use of your information (where we rely on our legitimate interests to use your personal information), provided that there are no overriding legitimate grounds for us to continue using and processing the information. Where we rely on our legitimate interests to use your personal information for direct marketing, we will always respect your right to object;
  • Delete your information (or restrict its use), provided that there are no legitimate grounds for us to continue using and processing such information;
  • Transfer your information in a structured data file (in a commonly used and machine-readable format), where we rely on your consent to use and process your personal information or process it in connection with a contract.

In the event of a data subject access request or a request for information, please be aware that if the request is unfounded or excessive, we may charge a fee or refuse to act on the request.

Please also note that when we remove data from our systems, either after the retention periods indicated earlier in this document or upon request, the data is permanently deleted from our systems and this may affect any subsequent access requests.

You can exercise the rights listed above and/or manage your information by contacting us using the details below:

Data Controller: Umberto Sassatelli Salvadori

Email: privacy@viaggisalvadori.it

If you have any specific concerns about data protection or wish to file a complaint, you can contact our Data Protection Team at privacy@viaggisalvadori.it.

6. WHERE WE STORE PERSONAL DATA

The personal data we collect may be transferred to and stored at a destination outside the European Economic Area (EEA) for the purposes described above. We will take all reasonably necessary measures to ensure that personal data is handled securely and in accordance with this Privacy Policy and applicable data protection legislation. To the extent that it is necessary to transfer personal data outside the European Union, we will ensure that appropriate safeguards are in place to protect the privacy and integrity of such personal data, including the European Union’s standard contractual clauses pursuant to Article 46(2) (for example, by using so-called Binding Corporate Rules). Please contact us if you would like further information about these safeguards.