article 13 EU Reg. 679/2016
Dear Sir/Madam,
We wish to inform you that EU Reg. 679/2016 (and Legislative Decree 196/2003 and subsequent amendments, only as far as EU Reg. 679/2016 is concerned) provides for the protection of individuals with regard to the processing of personal data. According to this legislation, the processing of your data will be based on the principles of correctness, lawfulness and transparency, protecting the confidentiality and security of the data and ensuring the exercise of your rights.
According to the aforementioned article 13 of EU Reg. 679/2016, we therefore provide you with the following information:
A) The identity and the contact details of the controller and, where applicable, of the controller’s representative;
The data controller is:
Piazza del Popolo 1
Località Villa a Sesta – 53019 Castelnuovo Berardenga (SIENA)
C.F.: 04918361009 – P.IVA: 00898570528
Mail: agricola@villasesta.com
Phone: +390577359014
Web: https://www.villasesta.com/
The data controller is located in the European Union and, therefore, is not required to designate a representative of his/hers.
B)The contact details of the data protection officer, where applicable;
The data controller does not currently process data falling under the obligation to designate a “Data Protection Officer”, as detailed in Articles 37-38-39 and Recital 97 of EU Regulation 2016/679.
C) The purposes of the processing for which the personal data are intended as well as the legal basis of the processing;
The purpose of the treatment is as follows:
- To process your request for information/contact with our company, made by completing a specific form for the collection of data on our website villasesta.com/
We inform you that for the aforementioned purpose, your personal data will be processed (personal data, contact data such as, for example, email addresses, telephone numbers).
It should be noted that, in no section of the website, nor for access to any of its functions, is it required to provide “special categories of personal data” and/or “personal data relating to criminal convictions and crimes”, as defined by art. 9 and 10 of EU Reg. 679/2016. If the user spontaneously sends information of the aforementioned type to the data controller, the data controller will process it in compliance with the provisions of EU Reg. 679/2016 and only if and for what is strictly necessary in relation to the requests received by the website visitor; otherwise, these types of data will not be processed and will be immediately deleted by the data controller.
The legal basis of the processing is related to the provisions of art. 6 paragraph 1 letter a) of EU Reg. 679/2016, as the data subject has given consent to the processing of their personal data for one or more specific purposes.
D) If the treatment is based on Article 6, paragraph 1, letter f), the legitimate interests pursued by the data controller or by third parties;
We inform you that the processing of data is not based on Article 6, paragraph 1, letter f), as the processing is not necessary for the pursuit of the legitimate interests of the data controller or third parties, provided that the interests or the rights and the fundamental freedoms of the data subject do not prevail, which require protection of personal data, in particular if the data subject is a minor.
E) Possible recipients or possible categories of recipients of personal data;
Your personal data will be processed by subjects specifically appointed by the data controller as data controllers (if appointed) and/or by anyone acting under their authority and/or under that of the data controller and those who have access to personal data (Directors/partners/workers of the data controller); these subjects will process your data only if necessary in relation to the purposes of the conferment and only in the context of carrying out the tasks assigned to them by the data controller, undertaking to process only the data necessary for carrying out these tasks and to carry out only the operations necessary to carry them out.
Your personal data will not be communicated to third parties and/or subject to circulation.
F) Where applicable, the intention of the data controller to transfer personal data to a third country or to an international organization and the existence or absence of an adequacy decision by the Commission or, in the case of the transfers referred to in article 46 or 47, or article 49, second paragraph, the reference to the appropriate or suitable guarantees and the means to obtain a copy of such data or the place where they were made available.
The data controller does not intend to transfer personal data to a third country or to an international organization.
It should be noted that the personal data relating to the aforementioned treatment are managed in hosting on a server located in Italy.
In addition to the information previously provided, the data controller provides you with the following additional information necessary to ensure correct and transparent treatment:
G) The retention period of personal data or, if not possible, the criteria used to determine that period;
Your data will be kept for the time necessary to achieve the purposes indicated above, in order to respond to the request for information/contact with our company made by you in filling out a specific data collection form on our websitewww.villasesta.com/ (storage for a maximum of 5 years from the time of collection). The data will subsequently be deleted, except for their transformation into anonymous form.
H) The existence of the right of the data subject to ask the data controller for access to personal data and the correction or cancellation of that data or the restriction of the processing concerning him/her or to object to their processing, in addition to the right to portability of the data;
You can, at any time, exercise the following rights in relation to the data controller foreseen by EU Reg. 679/2016, by contacting the data controller at the addresses indicated in point a) of this policy report:
- Right of access by the data subject (Article 15 of EU Reg. 679/2016).
- Right to rectification (Article 16 of EU Reg. 679/2016).
- Right to erasure – “right to be forgotten” (Article 17 of EU Reg. 679/2016).
- Right to restriction of processing (Article 18 of EU Reg. 679/2016).
- Right to object (Article 21 of EU Reg. 679/2016).
- Right to data portability (Article 20 of EU Reg. 679/2016).
I) If the processing is based on article 6, paragraph 1, letter a), or on article 9, paragraph 2, letter a), the existence of the right to withdraw consent at any time without compromising the lawfulness of the processing based on the consent given before the revocation;
You can exercise, against the data controller, the right to withdraw consent at any time without compromising the lawfulness of the treatment based on the consent given before the revocation.
J) The right to lodge a complaint with a supervisory authority;
If you believe that the processing that concerns you violates this regulation, you have the right to lodge a complaint with a supervisory authority (Article 77 of EU Reg. 679/2016).
K) If the communication of personal data is a legal or contractual obligation or a necessary requirement for the conclusion of a contract, and if the data subject has the obligation to provide personal data as well as the possible consequences of the failure to communicate such data;
The data communications previously described are necessary to process your requests for information/contact and are strictly connected to normal business operations; therefore, failure to communicate them could make it impossible to process your requests for information/contact (in particular, as regards the “mandatory fields”, present within the form for the collection of information).
L) The existence of an automated decision-making process, including the profiling referred to in Article 22, paragraphs 1 and 4, and, at least in such cases, significant information on the logic used, as well as the importance and expected consequences of such processing for the data subject.
The data controller informs you that your data will not be subject to an automated decision-making process, including the profiling referred to in Article 22, paragraphs 1 and 4 of EU Reg. 679/2016.
The full text of the articles of EU REG 679/2016 relating to your rights (articles 15 to 22 inclusive) is available at the following link on the website of the Italian Data Protection Authority:
or, as an alternative, it will be provided to you by the Data Controller simply upon your request.
Finally, the data controller informs you that, if the data controller intends to further process personal data for a purpose other than that for which they were collected, before such further processing, he undertakes to provide you with all the information for this different purpose and any further relevant information referred to in Article 13 of EU Reg. 679/2016, paragraph 2.
Date of latest modification of the document:
Castelnuovo Berardenga (SIENA), 23/11/2020