Privacy & Cookie Policy for Villa La Rosa Bellagio
Villa La Rosa Bellagio (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use our website,
https://www.villalarosabellagio.it (the “Site”), and our services, in compliance with the General Data Protection Regulation (GDPR), the UK Data Protection Act 2018 (DPA), Brazil’s General Data Protection Law (LGPD), and the California Consumer Privacy Act (CCPA).
1. Data Controller and Contact Information
Villa La Rosa Bellagio, located at Via dei Pini 26, Bellagio, Lake Como, Italy, is the Data Controller of your personal data. For inquiries or requests regarding data processing, please contact us at info@casalarosa.it
2. Data Collection and Usage
We collect and process personal data for the following purposes:
- Reservations & Bookings: To manage reservations, we collect name, surname, email address, and payment information.
- Contact Form: When you contact us through the Site, we require your name, surname, and email address to respond to your inquiries.
- Communication: Data provided in inquiries, communications, or customer service interactions.
- Marketing & Promotions: With your consent, we may use your email for newsletters or promotions.
- Analytics: We use data analytics to enhance user experience and improve website functionality.
3. Categories of Data Collected
- Identifiers: Personal information collected includes name, surname, and email.
- Commercial Information: Booking and transaction history.
- Internet or Technical Data: IP address, browser type, and browsing history for analytics.
- Cookies and Tracking: We use cookies to enhance site functionality and track preferences. Details are provided in our Cookie Policy below.
4. Legal Basis for Processing (GDPR, UK Data Protection, and LGPD)
Our data processing complies with GDPR, the UK DPA, and Brazil’s LGPD, based on the following legal grounds:
- Contractual Necessity: Processing data for managing bookings and reservations.
- Consent: For contact form submissions, marketing communications, and optional services.
- Legitimate Interest: Processing data for analytics, site functionality, and customer service.
- Legal Obligations: Compliance with applicable legal requirements.
5. UK Data Protection Compliance
Under the UK Data Protection Act 2018 (DPA), UK residents have rights similar to those under GDPR, including:
- Right to Access: Request access to the personal data we hold about you.
- Right to Rectification: Correct any inaccurate data.
- Right to Erasure: Request deletion of personal data, subject to certain conditions.
- Right to Restrict Processing: Limit how we use your data.
- Right to Object: Object to data processing based on legitimate interests.
- Right to Data Portability: Request transfer of your data in a structured format.
- Right to Withdraw Consent: Withdraw consent for marketing or other consent-based data processing.
6. Brazil’s LGPD Compliance
Brazil’s General Data Protection Law (LGPD) ensures specific rights for individuals residing in Brazil:
- Right to Confirmation of Processing: Confirm if personal data is being processed.
- Right to Access: Access information about the processing of your data.
- Right to Correction: Request correction of incomplete, inaccurate, or outdated data.
- Right to Anonymization, Blocking, or Deletion: Request anonymization, blocking, or deletion of unnecessary or excessive data.
- Right to Portability: Request transfer of data to another service provider.
- Right to Revoke Consent: Revoke consent previously given for data processing.
7. CCPA Compliance – California Residents
If you are a California resident, the CCPA provides you with specific rights regarding your personal information:
- Right to Know: Request information on categories and specific pieces of personal data collected about you.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out: Opt-out of the sale of your personal information (Note: We do not sell personal data).
- Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your CCPA rights.
8. Data Sharing and Disclosure
We may share your data with:
- Service Providers: Third-party providers for payment processing, booking platforms, and email marketing.
- Hosting Provider (SiteGround): The Site is hosted on SiteGround servers located in Spain. SiteGround may process personal data on its side to manage server hosting, maintenance, and technical support. SiteGround adheres to privacy and data protection standards; please review their privacy policy for more information.
- Legal Requirements: Authorities, if required by law or necessary to protect legal rights.
9. Data Transfers Outside the EU, UK, and Brazil
When data is transferred outside the European Economic Area (EEA), the UK, or Brazil, we ensure compliance through Standard Contractual Clauses or other legally recognized safeguards.
10. Data Retention
We retain personal data only as long as necessary for the purposes outlined above, or as required by law. Booking data is generally retained for seven years for tax purposes.
11. Data Security
We use security measures to protect your data against unauthorized access, alteration, and destruction. However, no internet transmission is entirely secure.
12. Your Rights Summary
In accordance with GDPR, UK DPA, LGPD, and CCPA, you may exercise your rights as follows:
- Access: Request a copy of your data.
- Rectification: Correct inaccurate data.
- Deletion: Request data deletion, subject to certain conditions.
- Portability: Request transfer of data in a structured format.
- Objection: Object to data processing based on legitimate interests.
- Withdraw Consent: Withdraw consent where applicable, such as for marketing.
- CCPA-Specific Rights: Rights for California residents include the right to know, delete, and opt-out.
13. Cookie Policy
Our Site uses cookies and similar tracking technologies to enhance your experience, enable site functionality, and conduct analytics. By using the Site, you consent to the use of cookies as described below.
Types of Cookies Used
- Essential Cookies: Necessary for basic website functionality and cannot be disabled.
- Analytics and Performance Cookies: Used to understand site usage and improve user experience.
- Third-Party Cookies:
- Google Maps: Embedded map content uses cookies to store preferences and track location-based activity. Data may be transferred outside the EU. Please review Google’s privacy policy for more information.
- Google reCAPTCHA: Protects the Site from spam and abuse. This service may collect personal data such as IP address and use cookies for security analysis. More details are available in Google’s privacy policy.
- Font Awesome: Font icons are hosted through SiteGround servers in Spain and may log IP addresses for technical purposes. Please review Font Awesome’s privacy policy for further information.
Managing Cookies
You may control cookie preferences via your browser settings. Note that disabling certain cookies may impact website functionality.
Third-Party Links and Resources
Our Site may link to third-party services or resources, which may independently set cookies and collect personal data. We encourage you to review the privacy policies of these third parties, as we are not responsible for their practices.
14. Updates to This Policy
We may update this Privacy Policy periodically. Significant changes will be communicated on our Site or by email.
Contact Us: For any inquiries or requests regarding this Privacy Policy, please email us at info@casalarosa.it.