This policy describes how personal data is processed through the Grand Hotel Vesuvio mobile application (the “App”), available for iOS and Android devices, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”).
1. Data Controller
80067 Sorrento (NA) — Italy
VAT no. 01246491219
Phone: +39 081 878 26 45
Email: info@vesuviosorrento.com
To exercise your rights or for any request concerning the processing of personal data, please write to the email address above.
2. Personal data processed
2.1 Data provided by the user
Account registration. First name, last name, email address, password (stored in encrypted form), telephone number, mobile number, nationality, date of birth.
Pre-check-in and stay registration. First name, last name, place and date of birth, residence, country, sex, type of identity document, document number, place of issue, expiry date, photographic image of the identity document.
Services requested during the stay. Booking requests, fault reports, requests for additional supplies, restaurant reservations, room service orders, stay voucher association and consultation of current charges.
2.2 Data collected automatically
Technical and usage data. Device model and operating system, App version, device identifier for push notifications (Firebase Cloud Messaging token), IP address, diagnostic data and crash reports.
Usage statistics. App sections opened, services and areas viewed, application errors. This data is collected in aggregated and anonymous form: it is not linked to the user's identity or account.
2.3 Children
The App is not intended for minors and the Controller does not knowingly collect personal data of minors. Account registration and use of the services are reserved for adults.
Should the Controller become aware of having processed a minor's data in the absence of the legal requirements, it will delete such data without undue delay. Holders of parental responsibility may report such circumstances by writing to the address indicated in section 1.
3. Purposes and legal bases of processing
| Purpose | Legal basis |
|---|---|
| Creation and management of the user account | Performance of a contract (Art. 6.1.b GDPR) |
| Provision of the hotel services requested through the App (pre-check-in, reservations, assistance requests, consultation of charges) | Performance of a contract (Art. 6.1.b GDPR) |
| Compliance with the obligation to report guest particulars to the Public Security Authority (Art. 109 of the Italian Consolidated Law on Public Security) and with statistical reporting obligations | Legal obligation (Art. 6.1.c GDPR) |
| Sending service push notifications relating to the stay | Performance of a contract (Art. 6.1.b GDPR) |
| Sending promotional push notifications and commercial communications | Consent (Art. 6.1.a GDPR), withdrawable at any time |
| Aggregated statistical analysis of App usage and error diagnostics, in order to ensure its operation and improve its functionality | Legitimate interest of the Controller (Art. 6.1.f GDPR) |
| Legal defence and establishment of liability | Legitimate interest of the Controller (Art. 6.1.f GDPR) |
Providing the data required for registration and for the delivery of services is optional, but refusal makes it impossible to use the relevant App features. Providing the data required to comply with public security obligations is mandatory by law.
4. Methods of processing
Data is processed using IT and electronic tools, applying technical and organisational measures appropriate to ensure its security and to prevent unauthorised access, loss or disclosure.
Communications between the App and the Controller's systems take place over an encrypted channel (HTTPS). Access credentials are stored on the user's device in an area protected by the operating system.
No automated decision-making or individual profiling is carried out.
5. Recipients of the data
Personal data may be disclosed to the following parties:
- Application platform provider — the company that develops and manages the technical infrastructure of the App, acting as data processor;
- Property Management System (PMS) of the Controller, to which check-in data and identity document images are transmitted for the management of the stay and for statutory compliance;
- Public Security Authorities and other competent authorities, in the cases provided for by law;
- Google Ireland Limited / Google LLC — Firebase services (Cloud Messaging for push notifications, Analytics for aggregated statistics, Crashlytics for error reports) and Google Maps for mapping features;
- Amazon Web Services — hosting of the App's static content (images and informational material). No identifying data is transmitted to this provider, only the IP address necessary to retrieve the content.
Data is not disseminated nor transferred to third parties for their own independent marketing purposes.
6. Place of processing and transfers outside the EU
Personal data is processed and stored on servers located within the European Union.
Certain technical services provided by Google and Amazon Web Services may involve the transfer of technical data to third countries, in particular the United States of America. Such transfers take place on the basis of the safeguards provided for in Chapter V of the GDPR, such as the Standard Contractual Clauses approved by the European Commission and, where applicable, the provider's certification under the EU-U.S. Data Privacy Framework.
7. Retention period
| Category of data | Retention |
|---|---|
| Account data | For the entire duration of the relationship, until the user requests deletion |
| Check-in data and identity document images | Transferred to the Controller's management system and retained there for the period required by public security obligations and by applicable tax and civil law |
| Data relating to requests and services during the stay | For the duration of the stay and thereafter for the time necessary to handle any disputes |
| Aggregated statistical and diagnostic data | In accordance with the retention periods of the Firebase services, in any case in a form not attributable to the user |
| Consents given | For the entire period of their validity and thereafter as evidence of compliance |
Once these periods have elapsed, data is deleted or irreversibly anonymised.
8. Rights of the data subject
Users have the right, at any time, to:
- access their personal data and obtain a copy of it (Art. 15 GDPR);
- obtain the rectification of inaccurate data or the completion of incomplete data (Art. 16 GDPR);
- obtain the erasure of data in the cases provided for (Art. 17 GDPR);
- obtain the restriction of processing (Art. 18 GDPR);
- receive their data in a structured, commonly used format and transmit it to another controller (portability, Art. 20 GDPR);
- object to processing based on legitimate interest (Art. 21 GDPR);
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7.3 GDPR);
- lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it) or with the supervisory authority of their Member State of residence.
Requests should be addressed to info@vesuviosorrento.com. The Controller will respond without undue delay and in any case within one month of receipt.
9. Account deletion
Deletion of the account and associated data may be requested by completing the form available at the following address:
https://docs.google.com/forms/d/e/1FAIpQLScRs4jXD_Wos7Fagq-zY9_lueVHe4bYIP3K7HjHl0RiEjiw1w/viewform
The request results in the deletion of the account and the data associated with it, with the exception of data that the Controller is required to retain in order to comply with legal obligations, which remains stored only for the prescribed period and is not further used.
10. Permissions requested by the App
| Permission | Purpose |
|---|---|
| Camera | Capturing the photograph of the identity document for pre-check-in |
| Photo library | Selecting an image of the identity document already stored on the device |
| Notifications | Receiving communications relating to the stay and, subject to consent, promotional communications |
| Network access | Communication with the Controller's systems |
Each permission may be revoked at any time from the device settings; revocation may limit the functionality of the App.
11. Push notifications
The App sends two types of notification:
- service notifications, relating to the status of the stay, submitted requests and communications from the property;
- promotional notifications, relating to offers and commercial initiatives of the property, sent only with the user's prior consent.
Consent to promotional notifications may be withdrawn at any time from the App settings or by disabling notifications in the device settings.
12. Changes to this policy
The Controller reserves the right to amend this policy in order to reflect subsequent regulatory changes or changes to the services offered. The updated version is published at this address together with the date of the latest update. In the event of substantial changes, users will be informed through the App.