INFORMATION ON THE PROCESSING OF PERSONAL DATA
-Website-

DATA NOT COLLECTED FROM THE DATA SUBJECT

(art. 14 GDPR 2016/679)

Dear Data Subject,

The purpose of this document is to inform the individual (referred to as the “data subject” according to the relevant regulations) about the processing of personal data collected by the data controller Noleggio Barche Lucibello Srl (from now on also referred to as the “controller”), under Article 14 of Regulation (EU) 2016/679 on the protection of natural persons about the processing of personal data (from now on also referred to as the “Regulation” or "GDPR (General Data Protection Regulation)") and Legislative Decree 2003/196 as amended by Legislative Decree 2018/101 “Personal Data Protection Code containing provisions to adapt the national legal system to Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons about the processing of personal data, as well as on the free movement of such data, and repealing Directive 95/46/EC” (from now on also referred to as the “Code”).

The controller may amend this notice, in whole or in part, by notifying the data subjects.

Your data will be processed by the principles of fairness, lawfulness, and transparency. The availability, management, access, storage, and usability of the data are ensured through the adoption of technical and organizational measures deemed appropriate by the data controller to guarantee the proper levels of security under Articles 25 and 32 of Regulation (EU) 2016/679 in reference to its activities.

About the personal data being processed, the controller provides the following information.

General Information and Contact Details of the Data Controller

The data controller of your personal information is Noleggio Barche Lucibello Srl, located at Via del Brigantino, 9 - 84017 Positano, SA - Italy. They are responsible for the lawful and correct use of your data and can be contacted for any information or requests at the following addresses:

PEC: noleggiobarchelucibello@pec.studiomilano.it

Categories of Data Processed

 Your data processed by the data controller pertains to the following categories of information:

Bank details; Payment card data; Behavioral data, user profiles, consumers, taxpayers, etc.; Lifestyle and consumption habits; Contact information (phone number, email, etc.); Geolocation; Third-party cookies; Remarketing cookies; Technical cookies; Tax code and other personal identification numbers; Name, address, or other personal identification elements.

Purpose of Processing

 Your data is collected and processed for the purposes listed below, along with the criteria on which the processing is based and the relevant legal basis, if applicable:

Purpose: Online or broadcasting sales
Lawfulness criterion: The processing is necessary for the execution of a contract to which the data subject is a party or for the execution of pre-contractual measures taken at the request of the data subject
Categories of data processed: Bank details; Payment card data; Contact information (phone number, email, etc.); Tax code and other personal identification numbers; Name, address, or other personal identification elements.

Purpose: Marketing (market analysis and surveys)
Lawfulness criterion: The data subject has given consent to the processing of their data for one or more specific purposes
Categories of data processed: Behavioral data, user profiles, consumers, taxpayers, etc.; Lifestyle and consumption habits; Contact information (phone number, email, etc.); Geolocation; Third-party cookies; Remarketing cookies; Technical cookies.

Purpose: Advertising
Lawfulness criterion: The data subject has given consent to the processing of their data for one or more specific purposes
Categories of data processed: Contact information (phone number, email, etc.)

Purpose: Customer satisfaction survey
Lawfulness criterion: The processing is necessary for the legitimate interests pursued by the data controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, particularly if the data subject is a minor
Categories of data processed: Contact information (phone number, email, etc.)

Legitimate Interest of the Data Controller

In particular, since some purposes derive from a legitimate interest of the Data Controller, a detailed description of the legitimate interests pursued is provided below:

Purpose: Customer satisfaction survey
Description of the Data Controller's legitimate interest: Customer or user satisfaction statistics

Consent to Data Processing

Some of the listed purposes require the express consent of the Data Subject. In such cases, you can legitimately object to these purposes by not giving consent to the related processing of the associated data categories.

Lack of consent results in the consequences that are described in detail below.

Purpose: Marketing (market analysis and surveys)
Consequences of Lack of Consent: Analysis of customer behavior on the website with the enabling of technical cookies and third-party cookies.

Purpose: Advertising
Consequences of Lack of Consent: Sending commercial communications via mailing list; consent will be requested upon newsletter subscription or through informed consent email

Methods of processing and communication of data

The processing will be carried out manually and/or by automated means, in compliance with ‌Article 32 of GDPR 2016/679 on security measures, by specifically appointed individuals, and in compliance with ‌Article 29 of GDPR 2016/679.

The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.

The processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the indicated purposes. Besides the Data Controller, in some cases, other individuals involved in the organization of the company (administrative, commercial, marketing, legal staff, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) appointed‌ as Data Processors by the Data Controller, may have access to the data. The updated list of Data Processors can always be requested from the Data Controller.

Recipients

Your data will be disclosed to recipients as defined in Article 4 of Regulation (EU) 2016/679 under no circumstances.

Retention Period

The data is processed and stored for the time strictly required by the purposes for which it was collected.

In general, data collected for purposes related to the execution of a contract between the Data Controller and the data subject will be processed until the execution of that contract is completed; personal data collected for purposes related to the legitimate interest of the Data Controller will be processed until such legitimate interest exists.

When processing is based on the data subject’s consent, the Data Controller may retain personal data until such consent is revoked.

Additionally, the Data Controller may be required to retain personal data for longer than initially established to comply with a legal obligation or an order from a public authority.

At the end of the retention period, personal data will be deleted. Therefore, after this period, the rights of access, deletion, rectification, and data portability can no longer be exercised by the data subject.

The following table contains detailed information regarding the criterion followed to determine the end of the data life cycle and/or the presumed end date and/or the predetermined period of their processing.

Processing: Predetermined duration of treatment: 1 Year
Description: Analysis of customer behavior on the website with technical and third-party cookies enabled.

Data is collected by the web structure only after the visitor's consent, who can decide whether to activate and/or block each active cookie. The privacy policy specifies all types of active cookies and how to block them in the respective browsers. Only after the visitor's consent, the collected data are saved on the hosting server and retained for a maximum period of 1 year from the moment of collection.

Automated Decision-Making Process

In their processing, personal data is used for automated decision-making processes.

Denomination: Processing 
Website_Group: Website (Website)

Denomination: Condition for automated decision-making process:
Website_Group: Decision based on the explicit consent of the data subject

Denomination: Right to obtain human intervention:
Website_Group: The data subject will be required to accept the categories of cookies active on the platform, categorized into:

  • necessary for the website to function
  • marketing
  • profiling

Denomination: Detailed description of the automated decision-making process and logic used
Website_Group:  The data collection begins with the acceptance of cookies, which collect the necessary data to analyze user behavior during the website visit and their preferences. Remarketing cookies are also activated, which can reoffer services similar to those searched for within the limited time the cookie is active. The data is anonymized, and we cannot identify the user in any way.

Denomination: Consequences, methods, and purposes of the automated decision-making process
Website_Group: This occurs through the user's acceptance of cookies. The purposes are exclusively for advertising and marketing, allowing the reoffering of the searches made by the customer during the use of the site.

Denomination: Direct marketing purposes
Website_Group: YES

Denomination: Means used
Website_Group: Online booking through an IT system

Denomination: Right to object
Website_Group: The data subject has the right to object at any time, for reasons related to their particular situation, to the processing of personal data concerning them under Article 6, paragraph 1, letters e) or f), including profiling based on these provisions. The data controller shall refrain from further processing the personal data unless they demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject.

Transfer of Data

The data controller intends to transfer your data to Third Countries outside the European Union or to an international organization as described below:

Denomination: Processing
Google_Group: Website (Website)

Denomination: Country or organization of transfer destination
Google_Group: United States of America (only PNR)

Denomination: Contact information of the recipient
Google_Group: https://policies.google.com/privacy/frameworks

Denomination: Description of the transfer
Google_Group: Google complies with the EU-US Privacy Shield and the Swiss-US Privacy Shield as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information applicable to member countries of the European Union and Switzerland.

Denomination: The Supervisory Authority has been informed of the transfer
Google_Group: NO 

Denomination: Basis of the transfer
Google_Group:  Transfer based on an adequacy decision (Article 45)

Denomination: Information for the data subject
Google_Group: The transfer of your data to Third Countries outside the European Union or to an international organization occurs in the presence of an adequacy decision by the European Commission, under Article 45 of Regulation (EU) 2016/679, whose details are provided below

Denomination: Details of the adequacy decision (Article 45)
Google_Group: Commission Decision 2004/535/EC of 14 May 2004 on the adequate level of protection of personal data contained in the Passenger Name Records (PNR) transferred to the United States Bureau of Customs and Border Protection.

Denomination: Processing
FB_Group: Website (Website)

Denomination: Country or organization of transfer destination
FB_Group: United States of America (EU-US Privacy Shield)

Denomination: Recipient's contact information
FB_Group: https://it-it.facebook.com/privacy/policy/

Denomination:  Description of the transfer
FB_Group: Meta wants everyone to know what information we collect, how we use it, and how we share it. For this reason, we invite you to read the Privacy Policy so you can use it as you see fit. The Privacy Policy explains how we collect, use, share, store, and transfer information. It also describes your rights. Each section of the Privacy Policy includes helpful examples in understandable language to make our practices easier to understand. We have also added links to resources where you can learn more about privacy topics of interest to you.

Denomination: Data Protection Authority has been informed of the transfer
FB_Group: NO

Denomination:  Transfer basis
FB_Group: Transfer based on an adequacy decision (Article 45)

Denomination: Information for the data subject
FB_Group: The transfer of your data to third countries outside the European Union or to an international organization takes place under an adequacy decision of the European Commission, under Article 45 of Regulation (EU) 2016/679, the details of which are as follows: 

Denomination: Details of the adequacy decision (Article 45)
FB_Group: Implementing Decision (EU) 2023/4745 of the Commission of 10 July 2023 under Regulation (EU) 2016/679 of the European Parliament and the Council on the adequate level of protection of personal data within the EU-US data privacy framework.

 

Rights of the Data Subject 

In addition to the information provided above, to ensure the most correct and transparent processing of your data possible, you need to know that at any time you may exercise, under Articles 15 to 22 of Regulation (EU) 2016/679, the right to:

a) request access to personal data and confirmation of the existence of your data;
b) obtain information about the purposes of the processing, the categories of personal data concerned, the recipients or categories of recipients to whom the personal data have been or will be disclosed, and, where possible, the envisaged period of retention;
c) obtain rectification or erasure of personal data;
d) obtain restriction of processing;
e) receive the personal data concerning you, which you have provided to a controller, in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller without hindrance;
f) object to data processing, including profiling related to direct marketing;
g) object to decisions based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you;
h) withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal;
i) complain with a supervisory authority.

You may exercise your rights by submitting a written request via traditional mail or email to the contact details provided in this document.


INFORMATION ON THE PROCESSING OF PERSONAL DATA - marketing

DATA NOT COLLECTED FROM THE DATA SUBJECT

(art. 14 GDPR 2016/679)

Dear Data Subject,

The purpose of this document is to inform the individual (referred to as the “data subject” according to the relevant regulations) about the processing of personal data collected by the data controller Noleggio Barche Lucibello Srl (from now on also referred to as the “controller”), under Article 14 of Regulation (EU) 2016/679 on the protection of natural persons about the processing of personal data (from now on also referred to as the “Regulation” or "GDPR (General Data Protection Regulation)") and Legislative Decree 2003/196 as amended by Legislative Decree 2018/101 “Personal Data Protection Code containing provisions to adapt the national legal system to Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons about the processing of personal data, as well as on the free movement of such data, and repealing Directive 95/46/EC” (from now on also referred to as the “Code”).

The controller may amend this notice, in whole or in part, by notifying the data subjects.

Your data will be processed by the principles of fairness, lawfulness, and transparency. The availability, management, access, storage, and usability of the data are ensured through the adoption of technical and organizational measures deemed appropriate by the data controller to guarantee the proper levels of security under Articles 25 and 32 of Regulation (EU) 2016/679 in reference to its activities.

About the personal data being processed, the controller provides the following information.

General Information and Contact Details of the Data Controller

The data controller of your personal information is Noleggio Barche Lucibello Srl, located at Via del Brigantino, 9 - 84017 Positano, SA - Italy. They are responsible for the lawful and correct use of your data and can be contacted for any information or requests at the following addresses:

PEC: noleggiobarchelucibello@pec.studiomilano.it

Categories of Data Processed

Your personal data processed by the controller pertains to the following categories of information:

Tax code and other personal identification numbers; Name, address, or other personal identification elements; Contact details (phone number, email, etc.)

Purpose of Processing

 Your data is collected and processed for the purposes listed below, along with the criteria on which the processing is based and the relevant legal basis, if applicable:

Purpose: Marketing (market analysis and research)
Lawfulness criterion: Processing is necessary for the pursuit of the legitimate interests of the data controller or third parties, provided that the interests or fundamental rights and freedoms of the data subject requiring the protection of personal data do not prevail, particularly if the data subject is a minor.
Categories of data processed: Tax code and other personal identification numbers; Name, address, or other personal identification elements; Contact details (phone number, email, etc.)

Purpose: Sending informational and/or advertising material via phone or internet
Lawfulness criterion: The data subject has given consent to the processing of their personal data for one or more specific purposes.
Categories of data processed: Name, address, or other personal identification elements; Contact details (phone number, email, etc.)
Legal Bases: Register of Measures No. 242 dated 15/05/2013

Legitimate interest of the Data Controller

In particular, since some of the purposes derive from a legitimate interest of the Data Controller, a detailed description of the legitimate interests pursued is provided below:

Purpose: Marketing (market analysis and research)
Description of the legitimate interest of the Data Controller: Includes the search for new markets, analysis of reference market data, benchmarking analyses on own and competitor strategies, analysis of market opportunities and risks.

Consent to processing

Some of the listed purposes require express consent from the Data Subject. In such cases, you may legitimately object to these purposes by not providing consent for the related data processing categories.

The lack of consent entails the consequences that are detailed below:

Purpose: Sending informational and/or advertising material, including via phone or internet
Consequences of lack of consent: The controller will not be able to send informational and/or advertising material through the indicated means

Data Processing Methods and Communication 

The processing will be carried out manually and/or automatically, in compliance with the provisions of Art. 32 of GDPR 2016/679 regarding security measures, by specifically appointed individuals and in accordance with Art. 29 of GDPR 2016/679.

The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.

Processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the indicated purposes. In addition to the Data Controller, in some cases, other individuals involved in the organization (administrative, commercial, marketing, legal personnel, system administrators) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communication agencies) may have access to the data, also appointed, if necessary, as Data Processors by the Data Controller. The updated list of Data Processors can always be requested from the Data Controller.

Recipients

Under no circumstances will your data be disclosed to recipients, as defined in Article 4 of Regulation (EU) 2016/679

Retention Period 

Data is processed and stored for the time strictly required for the purposes for which it was collected.

In general, personal data collected for purposes related to the execution of a contract between the controller and the data subject will be processed until the execution of that contract is completed; personal data collected for purposes related to the legitimate interest of the controller will be processed as long as such legitimate interest exists.

When processing is based on the data subject's consent, the controller may retain personal data until such consent is revoked.

Furthermore, the controller may be obligated to retain personal data for a longer period than initially established to comply with a legal obligation or by order of a public authority.

At the end of the retention period, personal data will be deleted. Therefore, after this period, the rights of access, deletion, rectification, and data portability can no longer be exercised by the data subject.

The following table contains detailed information regarding the criteria used to determine the end of the data lifecycle and/or the likely end date and/or the predetermined period of their processing.

Processing: SP01 - Marketing (SP01 - Marketing) 
Description: Predetermined duration of processing: 5 Years

Data is collected by the data controller and/or processor in paper and/or digital form. It will be stored in the company archive and used exclusively for the indicated purposes. Data will be retained for a maximum predetermined period, and within this period, the data subject to this processing and related copies will be permanently deleted from our archives unless expressly requested by the data subject to remain in the archives.

Transfer of personal data

Your data will not be transferred to non-EU countries or to international organizations not established in the territory of the Union.

Rights of the data subject

In addition to the information provided above, to ensure the fairest and most transparent processing of your data, you should be aware that at any time you may exercise, under Articles 15 to 22 of Regulation (EU) 2016/679, the right to:

Request access to personal data and confirmation of whether or not personal data concerning you exists;
Obtain information on the purposes of processing, the categories of personal data, the recipients or categories of recipients to whom the personal data has been or will be disclosed, and, when possible, the retention period;
Obtain rectification and deletion of data;
Obtain the restriction of processing;
Obtain data portability, i.e., receive data from a data controller in a structured, commonly used, and machine-readable format, and transmit it to another data controller without hindrance;
Object to processing at any time, including processing for direct marketing purposes;
Object to automated decision-making, including profiling;
Withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal;
Lodge a complaint with a supervisory authority.
You can exercise your rights by sending a written request via traditional mail or email to the contact details provided in this document.