Privacy Policy

1 – Data Controller and Data Protection Officer

Grand Hotel Il Moresco S.r.l. (hereinafter referred to as the “Data Controller”), with registered office in Naples, via Vito Fornari 4, Tax Code and VAT no. 04433700632 (telephone: +39 081/981355; email: grandhotelmorescosrl@pec.it), hereby informs that it is the Data Controller pursuant to Article 4, no. 7), of EU Regulation 2016/679. The company has appointed a Data Protection Officer who can be contacted at the following email address: palmieri@aptconsulting.it.

2 – Data Subject to Processing

The personal data collected by the Controller either independently or through third parties includes: cookies (see the specific cookie policy), usage data, first name, last name, email, and address. Personal data may be freely provided by the User or, in the case of usage data, collected automatically while using this site.

The use of cookies or other tracking tools by this site or third-party service providers used by this site, unless otherwise stated, serves to provide the service requested by the User, in addition to the other purposes described below.

This information is not collected to be associated with identified individuals, but by its very nature could, through processing and association with data held by third parties, allow Users to be identified. This category of data includes IP addresses or domain names of the computers used by Users connecting to the site, URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numeric code indicating the status of the server’s response (successful, error, etc.), and other parameters related to the User’s operating system and computing environment. These data are used solely to obtain anonymous statistical information on the use of the site and to ensure its proper functioning. The data may also be used to determine liability in case of potential computer crimes against the site or upon request of authorities.

The User assumes responsibility for third-party personal data obtained, published, or shared through this site and guarantees they have the right to communicate or disclose them, thereby releasing the Data Controller from any liability toward third parties.

Regarding this type of data, please refer to the cookie policy.

3 – Purpose of Processing and Legal Basis

The Data Controller processes your personal data for the following purposes:

  1. to respond to your requests for information and bookings; to manage contacts; to properly fulfill obligations arising from an existing contract or from pre-contractual activities requested by you. The legal basis for the processing is the performance of a contract with the User/data subject and/or pre-contractual measures (Art.6(1)(b) of EU Regulation 679/2016);
  2. to comply with legal and regulatory obligations. The legal basis for the processing is the fulfillment of a legal obligation (Art.6(1)(c) and (f) of EU Regulation 679/2016);
  3. to protect a legitimate interest (protecting its website and legal defense of its rights);
  4. to periodically send advertising information and/or newsletters. The legal basis for the processing is consent (Art.6(1)(a) of EU Regulation 679/2016).

The provision of data is optional with regard to purposes a) and d). Failure to provide data may make it impossible to achieve the intended purpose (e.g., to be contacted by the Controller or to receive marketing communications).

The provision of data is mandatory with regard to purposes b) and c), and failure to provide it will prevent compliance with legal obligations and the protection of the Controller’s legitimate interest.

4 – Methods of Data Processing

The data will be processed and stored exclusively for the purposes mentioned above using electronic means and processed with tools suitable to guarantee data integrity, security, and confidentiality in accordance with EU Regulation 2016/679. All appropriate technical and organizational measures will be taken to ensure a level of data protection in accordance with the Regulation. Access will be granted only to persons explicitly authorized in writing to process personal data.

5 – Communication to Third Parties and/or Data Dissemination – Transfer of Data Abroad

Recipients of personal data (i.e., entities to whom personal data may be disclosed) include, in addition to the Controller and employees explicitly authorized for processing, third-party entities engaged by the Controller for the performance of contracts and compliance with legal obligations (e.g., communication agencies, IT companies, trade associations, servers [e.g., web hosting, storage hosting]), who are appointed as external Data Processors and are given specific written instructions, as well as judicial and/or governmental authorities to whom, to comply with legal or regulatory obligations or to protect its own interests, the Controller is required to disclose personal data.

The updated list of data processors can be requested from the Controller.

The data will be transmitted exclusively within Italy and the European Union.

6 – Data Retention Period

The personal data collected for the aforementioned purposes will be retained for the following periods:

1 – data provided for the purpose referred to in point a), Art.3 will be kept for the duration of the contractual relationship and, subsequently, for the limitation period of any legal claims;

2 – data provided for the purpose referred to in point b), Art.3 will be kept for the time necessary to comply with legal/regulatory obligations;

3 – data provided for the purpose referred to in point c), Art.3 will be kept for the time necessary to protect the legitimate interest;

4 – data provided for the purpose referred to in point d), Art.3 will be kept until consent is withdrawn.

Afterward, the data will be deleted or anonymized, in full compliance with legal requirements.

7 – Data Subject’s Rights

The data subject may, at any time, exercise the rights referred to in Art. 7(3) and Arts. 15 et seq. of EU Regulation 2016/679: a) right of access to personal data; b) right to rectification or erasure or restriction of processing; c) right to object to processing; d) right to data portability; e) right to withdraw consent, where provided (withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal); f) right to lodge a complaint with the supervisory authority (Garante Privacy).

The exercise of the above rights may be carried out by sending a communication to:

  • Grand Hotel Il Moresco S.r.l., via Vito Fornari, 4, 80121 Naples, or by email to: grandhotelmorescosrll@pec.it
  • Ing. Ugo Palmieri, Vico Santo Spirito di Palazzo 35, 80132 Naples (NA), Tax Code PLMGUO67T26F839N, email: palmieri@aptconsulting.it.