Privacy Policy
EXTENDED PRIVACY NOTICE
With this notice, BLUFENNEC S.r.l. (Tax Code and VAT No. 08438840012 – Companies Register No. REA Turin 973094), acting through its pro-tempore legal representative, with registered office in Turin, Via Giacinto Collegno, 10 (10143) (hereinafter also the “Data Controller” or the “Company”) (contact details are provided in the “Contacts” section of the website), intends to describe the methods of management of the website https://en.upperail.com/ (hereinafter, the “Website”) with reference to the processing of personal data and/or other data possibly belonging to special categories pursuant to Art. 9 of the GDPR (hereinafter, the “Data”) of users who browse it, pursuant to Art. 13 of Legislative Decree No. 196 of 30 June 2003 (hereinafter, the “Privacy Code”) and Articles 13 and 14 of EU Regulation No. 2016/679.
1. DATA CONTROLLER, SUBJECT AND PLACE OF PROCESSING
This notice is provided pursuant to current national and international laws to all those who browse the Website, regardless of the method and device used.
Following authorization to data processing, the Data Controller will process the transmitted Data in compliance with the Regulation and applicable national legislation, including any measures issued by the Supervisory Authority (i.e. the Italian Data Protection Authority), where applicable.
The Data of data subjects may be transferred to a country other than the one in which the data subject is located. For further information regarding the place of processing, the data subject may always contact the Data Controller using the details set out in sections 10 and 12 of this Notice.
The Data Controller is committed to protecting the confidentiality of all Website users and invites all users to read the Privacy Policy set out below.
2. METHODS AND PURPOSES OF PROCESSING AND USE
2.1. The purposes of Data processing are made known to data subjects at the time of collection.
Data are collected to enable the Data Controller to provide its services, as well as for the following specific purposes: contacting data subjects, statistical purposes, spam protection, interaction with social networks and, where provided, registration and authentication, contact and payment management, advertising.
Data may be disclosed to the Data Controller’s trusted partners located in the various destination countries of the trip, including outside the European Union (only in the case of trips organized outside the EU).
Such consent is necessary for the performance of the contract, and the data subject has also been informed verbally. The trusted partners used by the Data Controller have all guaranteed compliance with the new regulations. Further information may be requested from the Data Controller and directly from the local partners by the data subjects.
2.2. Any new or different processing of Data will only be activated following notification of a new notice to users and data subjects in order to obtain their specific consent, where required.
2.3. In any case, personal data are not disclosed to third parties or disseminated without the prior consent of the data subject, except in cases expressly provided for by Art. 24 of Legislative Decree No. 196/03.
The Data Controller adopts all appropriate security measures to prevent unauthorized access, modification, disclosure or destruction of data.
Processing is carried out using organizational methods strictly related to the purposes indicated.
It is always possible to obtain detailed information on the purposes of processing and the Data processed for each purpose by contacting the Data Controller using the details provided in sections 10 and 12 of this Notice.
The privacy protocols and standards used by the Company for the protection of personal data are based on the following principles:
2.3.1. RESPONSIBILITY IN PROCESSING AND USE
Data processing is managed over time by designated persons within the company organization.
In certain cases, in addition to the Data Controller, other parties involved in the organization of the Website (e.g. administrative staff, sales staff, legal advisors, system administrators, hosting providers) may have access to the data.
In any case, the data subject may always request the updated list of Data Processors from the Data Controller.
2.3.2. TRANSPARENCY IN PROCESSING AND USE
Data are collected and processed in accordance with the principles expressed in the Privacy Policy adopted by the Data Controller, as set out in this notice. At the time of data provision, the data subject is given a concise but complete information notice, as required by applicable privacy legislation.
In any case, the data subject may always request from the Data Controller the specific legal basis of each processing activity, specifying whether it is based on law, on a contract, or is necessary for the conclusion of a contract.
2.3.3. RELEVANCE IN DATA COLLECTION
Data are collected and processed lawfully and fairly. They are recorded only for specific, explicit and legitimate purposes and are relevant and not excessive in relation to the purposes of processing.
2.3.4. PRINCIPLE OF VERIFIABILITY
Collected Data are updated, organized and stored in such a way as to allow data subjects to know which Data have been collected and recorded, to verify their quality and request any correction, integration or deletion for violations of the law, or to exercise all rights referred to in Art. 9 of this notice, through the methods provided in Art. 10.
2.3.5. PRINCIPLE OF SECURITY AND MEASURES ADOPTED
2.3.5.1. Collected and processed Data are protected by appropriate technologies against unlawful disclosure or alteration and by technical and IT security measures aimed at minimizing the risks of destruction, loss (including accidental loss) or unauthorized access.
2.3.5.2. Such measures are periodically reviewed and updated based on technological progress, the nature of the data and the specific characteristics of the processing.
2.3.5.3. Third parties providing support activities of any kind for the provision of the Company’s services, and who process personal data, are appointed as Data Processors and are required to comply with security and confidentiality measures.
2.3.5.4. The identity of such third parties is communicated and made known to users and data subjects.
3. TYPES OF DATA AND PROCESSING METHODS
3.1. While browsing the Website, users’ professional and personal interests may be detected. Such information is collected solely for the purpose of providing the requested services and, where applicable, monitoring service quality.
Depending on the processing activities, the Data collected by this Website, independently or through third parties, may include: first name, last name, cookies, usage data, tax code, address (for billing purposes, where required).
In general, data may be:
a) Data voluntarily provided by users:
The Data collected and processed on the Website are necessary for the provision of services. Therefore, failure to provide them will prevent the provision of services requiring such data.
Without the express consent of the data subjects for the use of the provided data (e.g. email, landline or mobile phone) for advertising, direct sales or commercial communications, such tools will not be used for these purposes.
Specific notices may be provided in the Website sections dedicated to data provision.
If data subjects voluntarily send emails to the Data Controller’s addresses listed on the Website, the Data Controller will acquire the sender’s address and any other information contained in the message. Such Data will be used solely to perform the requested services.
b) Browsing data:
The Website’s automated systems collect certain Data whose transmission is implicit in the use of Internet communication protocols.
Although such information is not collected to be associated with identified users, by its nature it may, through association with data held by third parties (e.g. Internet service providers), allow users to be identified (e.g. IP addresses, domain names of users’ computers, requested URL addresses, request times, numerical response codes).
These Data are used solely for anonymous statistical purposes related to Website use and proper functioning.
The Data Controller or appointed processors retain connection logs for a limited period in accordance with the law, in order to respond to any requests from judicial authorities in cases of computer crimes.
c) Data entered in Website forms:
In addition to point b), users may freely choose whether to provide their Data through service registration forms.
Some Data may be marked as mandatory; such Data are necessary for service provision. Failure to provide them will prevent the service from being delivered.
At the time of each data submission, users will be provided with a concise notice explaining purposes, methods, whether data provision is mandatory or optional, consequences of failure to provide data, recipients, etc., allowing users to give informed, free and explicit consent.
4. COOKIE POLICY
4.1. The Website uses cookies. Cookies are pieces of code installed in a browser that assist the Data Controller in providing services based on the purposes described.
Unless otherwise specified, cookies are used to provide the requested service, as well as other purposes described in this policy.
Some purposes may require user consent.
The main categories of cookies include:
a) Technical and aggregated statistical cookies
Technical cookies enable activities strictly necessary for Website operation and include:
i. navigation cookies, which save user preferences and optimize browsing;
ii. analytics cookies, which collect aggregated and anonymous statistical information;
iii. functionality cookies – including third-party cookies – necessary to provide services.
These cookies do not require prior user consent.
Other types of cookies or third-party tools
Some listed services may not require user consent and may be managed directly by the Data Controller. If third-party services are involved, they may perform tracking activities without the Data Controller’s knowledge.
Cookies used include:
- Smartlook: https://www.smartlook.com/help/privacy-statement
- Tawk.to: https://www.tawk.to/privacy-policy/
- Facebook: https://www.facebook.com/policies/cookies/
- Google/YouTube/DoubleClick.net: https://policies.google.com/technologies/cookies
- Twitter: https://help.twitter.com/it/rules-and-policies/twitter-cookies
- LinkedIn: https://www.linkedin.com/legal/cookie-policy
Google Analytics
This Website uses Google Analytics, a web analytics service provided by Google Inc. Data are collected anonymously to monitor and improve performance.
More information: https://policies.google.com/technologies/partner-sites
Users may disable Google Analytics via the opt-out browser add-on: https://tools.google.com/dlpage/gaoptout
Cookie management
Users may manage cookie preferences via their browser settings. Disabling all cookies may affect Website functionality.
Information on managing cookies can be found in the privacy sections of Google Chrome, Mozilla Firefox, Apple Safari and Microsoft Internet Explorer.
Users may also use tools such as Your Online Choices (http://www.youronlinechoices.com/it/) to manage tracking preferences.
Further technical information is available at:
https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/2142939
5. DATA RETENTION
Data, including browsing data, are retained in compliance with the GDPR and applicable regulations, only for the time necessary to achieve the purposes described.
6. DATA ACCESS
6.1. Data may be accessed by the Data Controller’s employees and collaborators as authorized persons and/or internal processors, only when necessary for their duties.
6.2. The Data Controller protects user information against unauthorized access, unlawful processing, accidental loss, destruction or damage, and retains it only for as long as necessary.
7. DATA DISCLOSURE
7.1. Without requiring explicit consent, Data may be disclosed to supervisory bodies or judicial authorities, or where required by law, or to protect legal rights. Such entities act as independent data controllers. Data will not be disseminated unless required by the service.
7.2. Where necessary for specific services, Data may be disclosed to third parties acting as independent data controllers.
7.3. Except as stated, Data are not transferred to non-EU countries or international organizations.
8. DATA TRANSFER
8.1. Personal data are stored in data centers located within the EU (specifically Italy) and in data centers outside the EU.
8.2. Should it become necessary to move servers outside the EU, transfers will comply with applicable laws and standard contractual clauses approved by the European Commission.
9. RIGHTS OF DATA SUBJECTS
Data subjects have the rights provided by Art. 7 of the Privacy Code and Art. 15 GDPR, including the right to obtain confirmation of data existence, details on processing, rectification, erasure, restriction, portability, objection, and to lodge a complaint with the Supervisory Authority.
Data subjects may object at any time to processing for direct marketing purposes without providing reasons.
10. EXERCISE OF RIGHTS
Rights may be exercised free of charge by sending:
- a registered letter to Ruta 40 Srl – Via Giacinto Collegno, 40 – 10143 Turin – Italy;
- an email to: privacy@ruta40.it
11. DATA CONTROLLER, PROCESSORS AND AUTHORIZED PERSONS
The Data Controller is the entity identified above.
An updated list of processors and authorized persons is available at the registered office upon request.
12. CONTACTS
Processing related to Website services takes place at the Data Controller’s operational offices or wherever processing parties are located.
For further information, contact: privacy@ruta40.it
13. FUTURE CHANGES TO THE PRIVACY POLICY
Changes in regulations or services may require updates to this policy. Users are invited to consult it periodically.
If changes affect processing based on consent, new consent will be requested where required.
14. REDIRECTS TO THIRD-PARTY WEBSITES
The Website contains redirect plugins to other platforms or social networks (Facebook, Instagram, Twitter, Google+, etc.).
The Data Controller has no control over such third-party websites and is not responsible for their data processing practices. Users are invited to consult the relevant privacy policies.
Last updated: 7 August 2018