Privacy Policy ENG

Privacy Policy

INFORMATION ON THE PROCESSING OF PERSONAL DATA OF WEBSITE USERS
Art. 13 EU REGULATION 2016/679 (GDPR)

1. Data Controller

Pursuant to Art. 13 of Regulation 2016/679/EU (hereinafter “GDPR”), Pontino Ponza (hereinafter “Data Controller”), Strada Piscine, Le Forna – Isola di Ponza
Tax Code/VAT No.: IT03189550597 email: info@pontinoponza.it, in its capacity as “Data Controller,” informs you that your personal data collected will be processed in compliance with the aforementioned regulation, in order to guarantee the rights, fundamental freedoms, and dignity of natural persons, with particular reference to confidentiality and personal identity.

2. Source of personal data

Pursuant to Article 13 of EU Regulation 2016/679, we inform you that Pontino Ponza processes the personal data of data subjects, such as: Name, Surname, Email, Telephone number, which they have voluntarily provided by filling in the appropriate forms such as “Contacts” in the dedicated sections on the Data Controller’s website: https://www.pontinoponza.it/

3. Purpose and legal basis of personal data processing

In accordance with the aforementioned law, the Data Controller guarantees that personal data will be processed in compliance with fundamental rights and freedoms, as well as the dignity of the data subject, with particular reference to confidentiality, personal identity, and the right to personal data protection.
3.1. All personal data provided by data subjects will be processed for the following purposes:

– administrative procedures related to the Pontino Ponza service and the performance of the Data Controller’s activities in order to contact the data subject to respond to their requests;

– inclusion in personal records and computer databases;

– obligations related to the performance of the requested service, such as sending reminders for an event.

The legal basis for the processing is set out in Article 6(1)(b) and (c) of the GDPR, i.e. the collection of data is necessary for the performance of a contract to which the data subject is party and for compliance with legal obligations to which the Data Controller is subject.

4. Provision of data and consequences of failure to consent to processing

The provision of your data for the purposes referred to in point 3.1 is necessary to allow the use and management of the service. Your refusal to provide the data in question will make it impossible to use the specific service requested from the Data Controller.

5. Communication and dissemination of data

The personal data of data subjects may, if necessary, be communicated to:

5.1. our collaborators, employees, and suppliers, within the scope of their duties and/or any contractual obligations with them, relating to their relationships with the data subjects;

5.2. all those subjects whose right of access is recognized by law and to those public and/or private, natural and/or legal persons (legal consulting firms,

administrative and tax authorities, judicial offices, chambers of commerce, Municipality of Isola di Ponza, etc.), if communication is necessary or functional to the performance of our activities and in the manner and for the purposes described above;

In these cases, only essential data that is not excessive in relation to the purposes for which it is communicated will be disclosed.
The Register of Data Processors is held by the Data Controller and can be requested from the contacts listed in this policy.

Transfer of data to third countries
The Data Controller does not transfer personal data to third countries.

6. Methods of processing

The processing concerns common personal identification data, collected using a single-opt method, in a specific database. The processing of personal data is carried out using both paper and electronic media. The archives are organized in a predominantly automated form, in compliance with all precautionary measures, in order to guarantee security and confidentiality. The data will also be managed and protected in environments where access is under constant control; in particular, all technical, IT, organizational, logistical, and procedural security measures will be adopted to ensure the appropriate level of data protection required by law, allowing access only to persons in charge of processing by the Data Controller or any Data Processors designated by the Data Controller.

7. Data retention period

In accordance with the principles of lawfulness, purpose limitation, and data minimization, pursuant to Article 5 of GDPR 2016/679, personal data will be retained for the period of time strictly necessary to achieve the specific purposes of the processing and, specifically:
– for the purposes indicated in point 3.1, for the time necessary to fulfill contractual obligations and, in any case, no later than 10 years from the time your data was collected for the fulfillment of regulatory obligations and, in any case, no later than the terms established by law for the limitation of rights.

8. Right of access to personal data

The data subject may, at any time, exercise the following rights:
• Right of access, Art. 15 GDPR: to obtain confirmation as to whether or not personal data concerning him/her are being processed and, if so, to obtain access to the personal data;
• Right to rectification, Art. 16 GDPR: to obtain the rectification of inaccurate personal data concerning him/her without undue delay;
• Right to be forgotten, Art. 17 GDPR: to obtain the erasure of personal data concerning him/her without undue delay, and the data controller has the obligation to erase personal data without undue delay if certain conditions are met;
• Right to restriction of processing, Art. 18 GDPR: to obtain restriction of processing in certain cases;

• Right to data portability, Art. 20 GDPR: to receive the personal data concerning him or her, which he or she has provided, in a structured, commonly used and machine-readable format and has the right to transmit those data to another controller, without hindrance from the controller to which the personal data have been provided, in certain cases;
• Right to object, Art. 21 GDPR: to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you;
• Withdraw consent at any time (conditions for consent, Art. 7).
• Right to lodge a complaint pursuant to Art. 77 GDPR with the supervisory authority competent for your habitual residence, place of work, or place of infringement of your rights; for Italy, the competent authority is the Garante per la protezione dei dati personali (Italian Data Protection Authority), which can be contacted using the contact details provided on the website http://www.garanteprivacy.it.

The above rights may be exercised by sending a request to the Data Controller at the addresses indicated in this policy, or such a request may be made to the DPO appointed by the Data Controller at the email address indicated at the top of the policy. Requests relating to the exercise of user rights will be processed without undue delay and, in any case, within one month of the request; only in cases of particular complexity and number of requests may this period

be extended for an additional 2 (two) months.

REV. 00 of 09/04/2024

9. Third-party services and external content

A. Cloudflare

Our website uses Cloudflare to improve security and performance. Cloudflare may collect technical data such as IP address and user agent. For more information, please refer to Cloudflare’s Privacy Policy

Link to the official privacy policy: https://www.cloudflare.com/privacypolicy/

B. Font Awesome

The website uses Font Awesome to display icons via their CDN. Some technical data such as your IP address may be transferred to Font Awesome. Please refer to Font Awesome’s Privacy Policy for more details.

Link to the official privacy policy: https://fontawesome.com/privacy

C. Google Fonts

The website uses Google Fonts, which are loaded from Google’s servers. The visitor’s browser may send technical data such as the IP address to Google. More information is available in Google’s Privacy Policy.

Link to the official privacy policy: https://policies.google.com/privacy

COOKIE POLICY