Privacy statement
pursuant to Art. 13 of REGULATION (EU) 2016/679
of the company HBH SRL ("Company"), with its registered office in Strada Damez, 2 A, I-39036 Badia
*****************
Table of contents
1. General information
2. Visiting our website
3. Contacting us via our contact forms on the website, contacting us via e-mail, calling us ("contacting us")
4. Integration of services and contents of third parties
5. The protection of minors
6. Your rights
7. Contact information
*****************
1. General information
1.1 The protection of your personal data is of particular concern to us. We therefore process your data exclusively on the basis of the EU General Data Protection Regulation No. 679/2016 (hereinafter, "GDPR"), as well as the Italian Legislative Decree No. 196/2003.
1.2 In this privacy policy, we inform you about the most important aspects of data processing when you contact us and when you use our services via our internet site www.badiahill.com (hereinafter, "internet site" or "website").
1.3 All terms used in this privacy policy have the meaning defined in the legal sources mentioned in point 1.1.
1.4 Information about the use of cookies on this website can be found in our cookie declaration.
*****************
2. Visiting our website
2.1 When you visit our website, your IP address is collected, the pages you visit, the time of your request, the amount of data transmitted, the type of operating system you use, the navigation path and other data are stored.
Without the collection of the aforementioned data, our website cannot be accessed.
2.2 The following purposes are pursued with the processing of the above-mentioned data:
a. To display the website;
b. To ensure the protection of our rights, property and safety and those of third parties. In this regard, it should be noted that the website hosting company may collect the IP address through an automated process whenever our website is accessed if there is reasonable suspicion of unlawful access (e.g. hacker attack).
2.3 The processing of your data is based on the following lawful grounds:
a. When you visit our website, you give your consent to the collection of the above-mentioned personal data;
b. Furthermore, the processing is carried out within the framework of our legitimate interests. This consists of maintaining our IT security, protecting our rights and those of third parties, as well as our interest in making our website more user-friendly.
2.4 The personal data will be passed on to the following third parties:
Processor | Categories of data transmitted | Purpose of the transmission |
Hosting/Cloud provider/etc. | All categories of personal data mentioned under point 2.1 | System maintenance, improvement and upkeep of the IT system |
External IT consultants | All categories of personal data mentioned under point 2.1 | System maintenance, improvement and upkeep of the IT system |
Your personal data will not be transferred outside the European Economic Area.
2.5 Personal data is deleted as soon as it is no longer required to fulfil the purpose. In exceptional cases, e.g. to block an IP address, certain data may be retained for a longer period of time if we have a legitimate interest in doing so.
*****************
3. Contacting us via our contact forms on the website, contacting us via e-mail, calling us ("contacting us")
3.1 When you contact us, we collect, on a case-by-case basis, your first and last name, email address, place of residence, telephone number and any other additional information and content that you submit, upload or share.
3.2 The aforementioned data form the basis for our offer and for answering any questions, without which we cannot offer our service.
3.3 Any additional personal data provided by you in the course of contacting us, which may include special categories of personal data, will be evaluated by us and processed only in the event that they are necessary for the execution of your order. Otherwise, they will be immediately and irrevocably deleted.
3.4 The following purposes are pursued with the processing of the above-mentioned data:
a. To inform you about services and products;
b. To communicate offers, availability of rooms, quotations, to book stays/vacations/vouchers and to invoice accordingly;
c. To let you participate in a competition, if you request so;
d. To be able to integrate our services, such as the leisure offer with those of third parties;
e. To tailor our services to your preferences, such as food and entertainment;
f. To allow you access to our website areas for registered users;
g. To comply with any other legal obligations.
3.5 The processing of your data is based on the following lawful grounds:
a. When contacting us, you give your implicit consent to the processing of the above-mentioned also special categories of personal data, which in this case are processed on the basis of the lawfulness ground "contract" upon your request.
b. Processing may also take place on the basis of a legal obligation (such as official reporting obligations regarding guests, tax legislation, etc.).
3.6 Personal data may be disclosed to the following third parties:
Processor | Categories of data transmitted | Purpose of the transmission |
External IT consultant | All data stored in our IT system | System maintenance, improvement and upkeep of the IT system |
Accounting | Invoice data | Fulfilment of obligations under tax law |
E-mail provider | All data transmitted when contacting us | Purposes mentioned under 3.4 |
Hotel software | All data transmitted when contacting us | Purposes mentioned under 3.4 |
Your personal data will not be transferred outside the European Economic Area.
3.7 Personal data will be deleted as soon as it is no longer necessary for the fulfilment of the above-mentioned purposes.
*****************
4. Integration of services and contents of third parties
4.1 Based on our legitimate interests (i.e. interest in the analysis, optimisation and economic operation of our online offer), we use service and content offers from third-party providers within our online offer in order to integrate their content and services (hereinafter uniformly referred to as "services/content").
This always requires that the third-party providers of these services/content are aware of the IP address of the user, as without the IP address they would not be able to send the services/content to their browser. The IP address is therefore necessary for the execution of the services or display of this content. We endeavour to only use content whose respective providers only use the IP address to deliver the content. Third-party providers may use so-called tracking codes and pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. Tracking codes and "pixel tags" can be used to analyse information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit and other information about the use of our online offering, as well as being linked to such information from other sources.
a. Google Analytics
Google Analytics may be integrated within our online offer. Google Analytics is a web analysis service offered by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").
The information collected by Google Analytics about your use of this website is generally transmitted to a Google server in the USA and stored there. However, due to the activation of IP anonymisation on these websites, your IP address will be truncated beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator.
You can prevent the collection by Google Analytics by downloading and installing the browser plug-in available under the following link: Browser add-on to disable Google Analytics (https://tools.google.com/dlpage/gaoptout?hl=en).
Google is certified under the Privacy Shield agreement and thereby offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active). For more information on Google's use of data, settings and opt-out options, please refer to Google's privacy policy (https://policies.google.com/technologies/ads) and the settings for the display of advertising by Google (https://adssettings.google.com/authenticated).
b. Vimeo Plugins
We use the provider Vimeo, among others, for the integration of videos. Vimeo is operated by Vimeo, LLC with headquarters at 555 West 18th Street, New York, New York 10011.
On some of our pages, we use plugins from the provider Vimeo. When you call up the Internet pages of our website that are provided with such a plugin - for example, our media library - a connection is established to the Vimeo servers and the plugin is displayed. This transmits to the Vimeo server which of our Internet pages you have visited. If you are logged in as a Vimeo member, Vimeo assigns this information to your personal user account. When using the plugin, such as clicking on the start button of a video, this information is also assigned to your user account. You can prevent this assignment by logging out of your Vimeo user account before using our website and deleting the corresponding cookies from Vimeo.
Further information on data processing and notes on data protection by Vimeo can be found at https://vimeo.com/privacy.
c. ADDITIVE+ NEWSLETTER
On our website you have the possibility to subscribe to our newsletter. For the subscription we need your email address and your consent to receive our newsletter.
To provide you with relevant information we also gather and process voluntary information concerning interests, name, date of birth and country/region of origin. After signing up for our newsletter you will receive an email containing a link to confirm the subscription.
Your subscription can be cancelled any time by clicking on the cancellation link in the respective newsletter.
To process your subscriptions and to send our newsletters we use software provided by ADDITIVE s.n.c., 39011 Lana (BZ), Italy (“ADDITIVE”). Through the use of these services and systems your data will be processed and stored, at least in part, also outside of the EU or the EEC. The adequate level of data protection is based on an adequacy decision taken by the European Commission (“Privacy Shield”) or on data processing agreements.
d. ADDITIVE+ VOUCHERS
On our website you have the possibility to buy vouchers. To process your purchase and to save and store your data we use software provided by ADDITIVE s.n.c., 39011 Lana (BZ), Italy (“ADDITIVE”). Through the use of these services and systems your data will be processed and stored in the EU.
The data you provide is required to fulfil the contract or to carry out pre-contractual measures. Without this data we cannot conclude a contract with you. The data will not be transferred to an outside third party, except for your credit card data which will be transferred to the payment provider and to our tax accountant to fulfil our tax obligations.
The data processing takes place in accordance with the requirements of art. 6 para. 1 lit a (consent) and/or lit b (processing necessary for the performance of a contract) of the GDPR.
e. Facebook Pixel Marketing
Description of Service
This is a Tracking technology offered by Facebook and used by other Facebook services. It is used to track interactions of visitors with websites ("Events") after they have clicked on an ad placed on Facebook or other services provided by Meta ("Conversion").
Processing Company
Meta Platforms Ireland Ltd.
4 Grand Canal Square, Grand Canal Harbour, Dublin, D02, Ireland
Data Protection Officer of Processing Company
Below you can find the email address of the data protection officer of the processing company.
https://www.facebook.com/help/contact/540977946302970
Data Purposes
This list represents the purposes of the data collection and processing.
Analytics
Marketing
Retargeting
Advertisement
Conversion Tracking
Personalisation
Technologies Used
This list represents all technologies this service uses to collect data. Typical technologies are Cookies and Pixels that are placed in the browser.
Cookies
Pixel
Data Collected
This list represents all (personal) data that is collected by or through the use of this service.
Ads viewed
Content viewed
Device information
Geographic location
HTTP-header
Interactions with advertisement, services, and products
IP address
Items clicked
Marketing information
Pages visited
Pixel ID
Referrer URL
Usage data
User behaviour
Facebook cookie information
Facebook user ID
Usage/click behaviour
Browser information
Device operating system
Device ID
User agent
Browser type
Legal Basis
In the following the required legal basis for the processing of data is listed.
Art. 6 para. 1 s. 1 lit. a GDPR
Location of Processing
This is the primary location where the collected data is being processed. If the data is also processed in other countries, you are informed separately.
European Union
Duration to store the data
The retention period is the time span the collected data is saved for the processing purposes. The data needs to be deleted as soon as it is no longer needed for the stated processing purposes.
User’s interactions tracked on websites will not be stored longer than for two years. However, the data will be deleted as soon as they are no longer needed for the processing purposes.
Distribution to third countries
This service may forward the collected data to a different country. Please note that this service might transfer the data to a country without the required data protection standards. If the data is transferred to the USA, there is a risk that your data can be processed by US authorities, for control and surveillance measures, possibly without legal remedies. Below you can find a list of countries to which the data is being transferred. For more information regarding safeguards please refer to the website provider’s privacy policy or contact the website provider directly.
Singapore
United States of America
Worldwide
Data Recipients
In the following the recipients of the data collected are listed.
Meta Platforms Ireland Ltd., Meta Platforms Inc.
Click here to read the privacy policy of the data processor
https://www.facebook.com/privacy/explanation
Click here to read the cookie policy of the data processor
https://www.facebook.com/policies/cookies
Storage Information
Below you can see the longest potential duration for storage on a device, as set when using the cookie method of storage and if there are any other methods used.
Maximum age of cookie storage: 1 year
Non-cookie storage: no
Stored Information
This service uses different means of storing information on a user’s device as listed below.
_fbp
Cookie from Facebook used for website analytics, ad targeting and ad measurement.
Type:
cookie
Duration:
3 months
Domain:
facebook.com
f. USE OF GOOGLE ADWORDS, GOOGLE TAG MANAGER AND REMARKETING (Barbarossa Digtal Marketing)
This website uses cookies for remarketing campaigns, with the objective of addressing visitors with advertising campaigns later on. The affected person has the possibility to disable these types of cookies by visiting the following link: https://adssettings.google.com/?hl=gb.
g. GOOGLE ADS (Simedia Marketing)
We use "Google Ads" (formerly Google AdWords) on our website, a service provided by Google Ireland Limited. Google Ads enables us to draw attention to our offer by means of advertisements. When the visitor reaches our website via a Google ad, a cookie is stored on the device. These cookies enable Google to recognise the web browser. We ourselves do not collect and process any personal data in the aforementioned advertising measures, but only receive statistical evaluations from Google to optimize our advertising measures. If you are logged into your Google account, Google can assign the visit to the user account. You can prevent the installation of cookies by deleting existing cookies and deactivating the storage of cookies in the web browser settings. Please note that in this case you may not be able to use the full functionality of our website. For more information on Google's use of data and on setting options, please refer to the following Google link: Privacy policy: https://policies.google.com/privacy?hl=en
*****************
5. The protection of minors
5.1 We do not offer our services to minors under the age of 14. If you are responsible for the supervision of a person under the age of 14 and notice that the minor has transmitted data to us without our consent, please contact us immediately [email: info@badiahill.com; tel.: +39 3396766396] so that we can take the legal measures in the minor's interest.
*****************
6. Your rights
6.1 You are generally entitled to the rights of access, rectification, deletion, restriction, data portability, revocation and objection pursuant to Art. 15-22 of Regulation 2016/679.
Of course, you have the right to revoke your consent to receive the newsletter at any time (for example, via the opt-out function in the newsletter footer).
6.2 If you revoke your consent to data processing, this will not affect the lawfulness of the data processing prior to the revocation. In certain cases, your personal data may still be processed by us after your revocation; however, this will only be the case if there is a lawful reason other than consent. You can object to direct marketing at any time.
6.3 You have the right at any time to contact the national data protection authority (www.garanteprivacy.it) and lodge a complaint if you believe that your data is not processed in accordance with the purposes listed in this information document and on the basis of the grounds of lawfulness set out accordingly.
*****************
7. Contact information:
For any questions regarding the processing of your personal data, please contact us at the following address:
HBH SRL
Legal representative: Marco Verginer
Address: Strada Damez, 2 A, I-39036 Badia
E-mail address: info@badiahill.com
Tel.: +39 3396766396
Privacy policy for job candidates
Privacy policy about the processing of job candidates´ data in accordance with art. 13, 14 and 21 of the General Data Protection Regulation (GDPR)
of the company HBH SRL ("Company"), with its registered office in I-39036 Badia ("Data Controller").
*****************
Dear job candidate,
Thank you for your interest in our company.
In accordance with the provisions of articles 13, 14 and 21 of the General Data Protection Regulation (GDPR), we hereby inform you about the processing of the personal data you have provided as part of the application process and, if applicable, about the personal data we have collected and your rights in this regard. To ensure that you are fully informed about the processing of your personal data as part of the application process, please take note of the information below.
1. CONTACT DATA
You can request further information about the processing of your personal data and exercise your rights at any time via the following contact data:
HBH SRL
Legal representative: Marco Verginer
Address: Strada Damez, 2 A, I-39036 Badia
E-mail address: info@badiahill.com
Tel.: +39 3396766396
2. PURPOSE OF PROCESSING, DATA PROCESSED, LEGAL BASIS, DELETION DEADLINES
We lawfully process your personal data insofar as this is necessary for the decision on the establishment of an employment relationship with us. The legal basis for this is art. 88 GDPR and, if applicable, art. 6 para. 1 let. b GDPR for the initiation or implementation of contractual relationships. Furthermore, we may process your personal data if this is necessary for the fulfilment of legal obligations (art. 6 para. 1 let. c GDPR) or for the defence of asserted legal claims against us. The legal basis for this is art. 6 para. 1 let. f GDPR. If you give us express consent to process personal data for specific purposes, the lawfulness of this processing is based on your consent in accordance with art. 6 para. 1 let. a GDPR. Consent given can be revoked at any time, with effect for the future.
If an employment relationship is established between you and us, we may, in accordance with art. 88 GDPR, further process the personal data already received from you for the purposes of the employment relationship, insofar as this is necessary for the implementation or termination of the employment relationship or for the exercise or fulfilment of the rights and obligations of the employee representation resulting from a law or a collective agreement, a company or service agreement (collective agreement).
The processing is done as follows:
Purpose of processing |
Type of personal data |
Legal basis |
Data source |
Period of conservation |
Establishment of a new employment and commercial agent relationship |
CV data |
Contract |
CV input via homepage, email. |
Six months |
3. RECIPIENT OF THE DATA
We will only pass on your personal data within our company to the personnel department and to the head(s) of the department(s) for which the application could be of interest.
4. TRANSMISSION TO A THIRD COUNTRY
A transfer of your data outside the European Economic Area (EEA) does not take place and is not currently planned.
5. DURATION OF DATA STORAGE
We store your personal data for as long as is necessary for the decision on your application. In the absence of your consent for longer storage, your personal data or application documents will be deleted after a maximum of six months after the end of the application process (e.g. after notification of the rejection decision), unless longer storage is legally required or permitted. We only store your personal data beyond this if this is required by law or in the specific case for the assertion, exercise or defence of legal claims for the duration of a legal dispute.
If an employment relationship, training relationship, trainee relationship or commercial agent relationship is established following the application process, your data will initially continue to be stored insofar as this is necessary and permissible and will then be transferred to the personnel file.
6. YOUR RIGHTS
Every job candidate has the right to information according to art. 15 of the GDPR, the right to rectification according to art. 16 of the GDPR, the right to erasure according to art. 17 of the GDPR, the right to restriction of processing according to art. 18 of the GDPR, the right to notification according to art. 19 of the GDPR and the right to data portability according to art. 20 of the GDPR.
In addition, you have the right to lodge a complaint with a data protection supervisory authority pursuant to art. 77 GDPR if you are of the opinion that the processing of your personal data is not lawful. This right to lodge a complaint is without prejudice to any other administrative or judicial remedy.
7. NECESSITY OF THE PROVISION OF PERSONAL DATA
The provision of personal data within the scope of application processes is neither legally nor contractually required. You are therefore not obliged to provide information about your personal data. However, please note that these are required for the decision on an application or the conclusion of a contract in relation to an employment relationship with us. If you do not provide us with any personal data, we will not be able to make a decision regarding the establishment of an employment relationship. We recommend that you only provide personal data in your application that is required to complete the application.