Privacy Policy
Hotel Zone
INFORMATION ON THE PROCESSING OF PERSONAL DATA
of users consulting the website of Hotel Zone pursuant to Article 13 of Regulation (EU) 2016/679
This page describes how the website is managed with regard to the processing of the personal data of users who consult it and their confidentiality. This information notice is also provided pursuant to Art. 13 of European Regulation 679/2016 – Personal Data Protection regulation, to those who interact with the web services of Hotel Zone, accessible electronically from the address: https://www.hotelzone.com
This information does not concern other websites, pages, or online services accessible via hypertext links that may be published on the site but refer to resources external to the domain of Happy Days Chain Hotels Corporation Srl.
THE DATA "CONTROLLER"
Following consultation of this site, data relating to identified or identifiable persons may be processed. The "Controller" of the personal data processed following the consultation of our site and of any other data used for the provision of our services is Happy Days Chain Hotels Corporation Srl, Largo Pietro Vassalletto n.6 00196 Rome Fiscal Code: 02313370583 VAT No. 01042131001.
THE "DATA PROTECTION OFFICER"
The Data Protection Officer (DPO) can be reached at the following email address: amministrazione@groupevaladier.com
PLACE OF DATA PROCESSING
The processing operations connected to the web services of this website [physically hosted by QNT S.r.l. a Socio Unico ("www.qnt.it")] take place at our headquarters and are carried out exclusively by our authorized and instructed personnel, or by persons in charge of occasional maintenance operations.
The personal data provided by users who submit hotel booking requests or requests for information material (information, newsletters, registrations, etc.) are used solely for the purpose of executing the service or performance requested and are not communicated to third parties, except in the following possible cases:
commercial partners of Hotel Zone to whom the data is communicated exclusively to process online bookings, including SimpleBooking (https://www.simplebooking.travel/it);
persons, companies, or professional firms providing assistance and consulting services to Happy Days Chain Hotels Corporation Srl in accounting, administrative, legal, tax, and financial matters;
subjects whose right to access the data is recognized by law or by orders of the authorities.
Credit card data used for bookings will automatically be rendered unavailable after six months from the end date of the stay.
TYPES OF DATA PROCESSED – LEGAL BASIS – NATURE OF THE PROCESSING
NAVIGATION DATA
The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified.
This category of data includes IP addresses or domain names of computers used by users connecting to the site, URI/URL (Uniform Resource Identifier/Locator) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.), and other parameters relating to the user's operating system and computer environment. This data, necessary for the use of web services, is also processed for the purpose of:
obtaining statistical information on the use of services (most visited pages, number of visitors per hour or day, geographical areas of origin, etc.);
checking the correct functioning of the services offered.
The data could be used to ascertain responsibility in the event of hypothetical computer crimes against the site.
Legal Basis: The processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, taking into account the reasonable expectations of the data subject and activities strictly necessary for the operation of the site and navigation itself - (Recital 47 - Art. 6, par. 1, letter f of the GDPR).
Nature of Provision: Provision of data is necessary for browsing the website.
DATA PROCESSED THROUGH SOCIAL MEDIA PLATFORMS
Regarding the processing of personal data carried out by the managers of the Social Media platforms used by the Controller, please refer to the information provided by them through their respective privacy policies. The Controller processes the personal data provided by users through dedicated Social Media platform pages to manage interactions with users (comments, public posts, etc.) and in compliance with applicable regulations.
DATA VOLUNTARILY PROVIDED BY THE USER
The optional, explicit, and voluntary sending of messages to the Controller's contact addresses, private messages sent by users to institutional profiles/pages on social media (where this option is available), as well as the filling out and forwarding of forms present on the controller's website, entail the acquisition of the sender's contact details, necessary to reply, as well as all personal data included in the communications. The data will be stored solely for the requested subscription to newsletters or special offers and will not be communicated to anyone.
Personal information regarding visitors to the website is not collected or used. Visitors remain anonymous. The only exception concerns personally identifiable information required to fulfill contractual booking obligations towards the user.
A. Newsletter
Website visitors can register for our newsletter service. Upon registration, the user's email address will be automatically added to a contact list to which email messages containing periodic updates with information, including commercial and promotional information, relating to initiatives, events, or promotions of the data controller may be sent. To subscribe to the Newsletter, you can use the subscription forms on the site by entering your name and email address. The data entered will be used solely for the purpose of sending our newsletter via email and will not be communicated to third parties.
Legal Basis: The processing is based on consent to the processing of personal data (Recitals 42 and 43 and Art. 6, par. 1, letter a of the GDPR).
Nature of Provision: Provision is optional. Failure to provide the required data will make it impossible to receive communications.
B. Bookings
In the event of a booking on the website, the user is required to provide their name, telephone number, billing address, email address, payment method information, and credit card details. Happy Days Chain Hotels Corporation Srl will use this information only for processing the booking and for sending specific relevant information for the confirmation of the same, such as the receipt, booking code, and terms and conditions.
The information provided will not be used for marketing purposes and will not be sold, transmitted, licensed, or forwarded to third parties in any way, except for the online booking service providers SimpleBooking (https://www.simplebooking.travel), credit card issuing companies that may be contacted for the sole purpose of verifying validity, and online payment service providers Nexi Payments S.p.A. (https://www.nexi.it/it/ecommerce/xpay), exclusively for purposes related to the management of online bookings.
In any case, the website administrator ensures the adoption of scrupulous procedures to protect navigation data and the use of special care to protect credit card data provided during online bookings.
Legal Basis: The processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; (Recital 44 and Art. 6, par. 1, letter b of the GDPR).
Nature of Provision: Provision is necessary. Failure to provide the required data will make it impossible to finalize bookings.
C. Management of Personal Data Collected from Personal Curriculum Vitae (CV)
It is possible to use the contact info of Happy Days Chain Hotels Corporation Srl to send candidates' Curriculum Vitae in paper and/or digital format. The spontaneous and voluntary submission of the CV will be implicitly considered as informed consent granted by the data subject to the receipt and processing of the personal data contained therein, solely for purposes related to the selection of potential candidates.
The data processed for candidate selection purposes is of a personal nature useful for finding the specific profile requested. In general, personal data is of a standard type, except in certain cases where sensitive data may be indicated as necessary to identify specific requirements provided by applicable laws, such as belonging to specific protected categories, suitability for certain jobs, and/or mandatory employment placements, in compliance with the limits indicated by the General Provision of the Italian Data Protection Authority (Garante) dated June 5, 2019, which amended the General Authorization of the Garante No. 1 of December 15, 2016, on the processing of sensitive data in employment relationships.
Legal Basis: The processing is based on consent to the processing of personal data (Recitals 42 and 43 and Art. 6, par. 1, letter a of the GDPR) and/or the processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; (Recital 44 - Art. 6, par. 1, letter b of the GDPR).
Nature of Provision: Provision is necessary. Failure to provide the required data will make it impossible to apply.
General Rules for Sending CVs: Any Curriculum Vitae received spontaneously, in response to an announcement, or upon our request will be archived directly by specific personnel authorized to process personal data, according to the personal data security directives adopted in compliance with the security measures referred to in Chapter IV, Section 2 of GDPR 679/2016. These will be printed only on the occasion of a meeting and interview with the data subject. To send CVs, use the following email addresses: Happy Days Chain Hotels Corporation Srl, Via della Fontanella 15 - 00187 Rome, to the attention of the Human Resources Manager, Email: jobs@groupevaladier.com.
D. Administrative-Accounting Management
For organizational, administrative, financial, accounting, and client/user data management activities, the data controller may process the relevant personal data.
Legal Basis: The processing is necessary for the performance of a contract to which the data subject is party (Recital 44) or for compliance with a legal obligation (Art. 6, par. 1, letter c of the GDPR).
Nature of Provision: The provision of personal data is mandatory, as it is indispensable for executing legal obligations.
COOKIES AND TRACKING TECHNOLOGIES USED
Cookie technologies are applied on this site for different purposes, including computer authentication or session monitoring, and storing specific technical information regarding users who access the web server provider, in compliance with the Guidelines on cookies and other tracking tools adopted on websites (June 10, 2021) by the Italian Privacy Authority (Garante) and the Guidelines of the European Data Protection Board (EDPB) of May 2020. More information on the cookies adopted is available in the Cookie Policy of this website.
However, if the user blocks or deletes a cookie, it may be impossible to restore personalized preferences or settings previously specified, and our ability to customize the user experience will be limited.
Legal Basis: For non-technical cookies and comparable technologies, processing is based on consent to the processing of personal data (Art. 6, par. 1, letter a and Recitals 42 and 43 of the GDPR). Consent is given through the website banner and cookie policy.
Nature of Provision: Please see the cookie policy in the footer of the website.
DATA RETENTION PERIOD OR CRITERIA USED TO DETERMINE THE PERIOD
In compliance with the provisions of Art. 5, paragraph 1, letter e) of EU Reg. 2016/679, the personal data collected will be stored in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
The retention periods for personal data provided through the website depend on the purpose of the processing carried out, in particular:
purposes related to technical navigation data for the correct functioning of the website: except for any liability assessment, navigation data does not persist for more than seven days;
purposes of responding to information requests/provision of requested services: maximum 12 months for contact requests; 10 years for any administrative/accounting/financial documentation related to the provision of a service;
data collection for recruitment/personnel selection: maximum 6 months. In principle, data collected during the recruitment process will be deleted as soon as it becomes clear that no job offer will be made or that the offer will not be accepted by the candidate;
newsletters, marketing, or promotional communications generally via email: maximum 24 months – until consent is revoked;
administrative-accounting management purposes: 10 years as required by law for the retention of administrative/accounting/financial documentation;
purposes related to the management of cookies: see the cookie policy in the footer of the website;
purposes related to the management of whistleblowing reports: see the specific information notice on the whistleblowing portal.
TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES
Personal data is not transferred to non-EU Third Countries, in compliance with the provisions of Chapter V of GDPR 679/2016.
OPTIONAL NATURE OF DATA PROVISION
Apart from what is specified for navigation data, the user is free to provide the personal data requested in forms to Happy Days Chain Hotels Corporation Srl or indicated in contacts with the hotel to send CVs, make online bookings, or request the sending of informative material or other communications. Failure to provide them may make it impossible to obtain what was requested.
PROCESSING METHODS AND DATA PROTECTION MEASURES
Personal data is also processed using automated tools for the time strictly necessary to achieve the purposes for which it was collected, as indicated in this information notice. The Controller and Data Processors ensure the adoption of appropriate organizational, technical, and physical measures to guarantee a level of security appropriate to the risk and that personal data is processed adequately and in accordance with the purposes for which it is managed, in compliance with the provisions of Art. 32 of GDPR 2016/679. Specific security measures are observed to prevent data loss, illicit or incorrect use, and unauthorized access. Automated decision-making processes for data processing are not utilized.
RIGHTS OF THE DATA SUBJECTS
The data controller is Happy Days Chain Hotels Corporation Srl, Via della Fontanella 15 - 00187 Rome. The Data Protection Officer can be reached through the company contacts.
You may contact these subjects at any time to exercise your rights as provided for by Chapter III of GDPR 679/2016, in particular, the right to request access to personal data and the rectification or erasure of the same (Right to be Forgotten), or restriction of processing concerning the data subject, or to object to processing, the right to obtain a copy of the personal data undergoing processing, and the right to data portability, by submitting a specific request, also via the email address: zonehtl@groupevaladier.com
RIGHT TO LODGE A COMPLAINT
Data subjects who believe that the processing of personal data relating to them carried out through this site is in violation of the provisions of the Regulation have the right to lodge a complaint with the Garante (the Italian Data Protection Authority), as provided for by Art. 77 of the Regulation itself, or to seek a judicial remedy (Art. 79 of the Regulation).