This document describes the management methods of the website with reference to the processing of personal data of users who consult it and their confidentiality. This privacy policy is provided also pursuant to Art. 13 of the GDPR 679/2016 – European General Data Protection Regulation for those who interact with the web services of Musa Hotels - by STRATEGICA SERVIZI SRL, located in Via Laurina, 34 - 00187, Rome - accessible electronically from the following address: https://www.musahotels.com/ – corresponding to the homepage of the company's website.
This privacy policy is provided solely for this website and not for any other websites that may be consulted by the user via links.
DATA CONTROLLER
Following consultation of this site, data relating to identified or identifiable persons may be processed. "Data Controller" of personal data that may be processed following consultation of our site and any other data used for the provision of our services is the company STRATEGICA SERVIZI SRL, located in Via Laurina, 34 - 00187, Rome.
PLACE OF DATA PROCESSING – COMMUNICATION OF DATA
Processing operations connected to the web services of this site, managed by Blastness S.r.l. ("www.blastness.com") specifically designated as Data Processor pursuant to Art. 28 of GDPR 679/2016, take place within the territory of the European Economic Area or in the United Kingdom and are handled only by technical personnel of the Office in charge of processing, or by persons appointed for occasional maintenance operations.
Personal data provided by users who submit hotel booking requests or requests for receiving/sending informative material (information, newsletters, registrations, etc.) are used for the sole purpose of carrying out the service or performance requested and are not disclosed to third parties, except in the following possible cases:
TYPES OF DATA PROCESSED
Browsing data
The IT systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of the computers used by users who connect to the site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.), and other parameters relating to the user's operating system and IT environment, as well as any information regarding site usage and browsing behavior. For the processing of these data through the use of cookies, please refer to the information provided via the banner. The data could be used to ascertain liability in the event of hypothetical cybercrimes against the site: except for this possibility, web contact data currently do not persist for more than seven days.
Data provided voluntarily by the user
The optional, explicit, and voluntary sending of e-mails to the addresses indicated on this site involves the subsequent acquisition of the sender's address, necessary to respond to requests, as well as any other personal data included in the message. Data will be stored solely for any requested subscription to newsletters or special offers and will not be disclosed to anyone. Personal information regarding visitors to the website is neither collected nor used. Visitors remain anonymous. The only exception concerns personally identifiable information necessary to fulfill contractual booking obligations towards the user.
Data required for bookings
In case of booking hotel services offered through this website, the user is required to provide their first name, last name, e-mail address, telephone number, and, when requested, payment and credit card information. The data controller will use such information only for processing the booking and for sending specific information relevant to the booking confirmation, such as the receipt, booking code, and terms and conditions. The information provided will not be used for commercial purposes and will not be sold, transmitted, licensed, or otherwise forwarded to third parties. This is without prejudice to the activities commissioned to our booking service provider Blastness S.r.l. a Socio Unico, subject to the Direction and Coordination of Blastness Group SRL, with registered office in 20121 MILAN (MI), Piazza Castello n.26, VAT number 01195440118, represented by its legal representative pro tempore (hereinafter referred to simply as Blastness).
In the case of hotel bookings, the booking service provider ensures the adoption of rigorous procedures to protect browsing data and the use of special care to protect personal data provided, including credit card details provided during online bookings.
In particular, for the activities necessary to book rooms and services through the site, our provider Blastness guarantees the use of encrypted SSL technologies in order to safeguard confidential information such as Users' credit card details.
Newsletter
Website visitors can register for our newsletter service. Upon registration, the user's e-mail address will automatically be included in a contact list to which e-mail messages containing periodic updates with information, including commercial and promotional content, relating to initiatives, events, or promotions of the data controller may be transmitted.
To subscribe to the Newsletter, users can use the registration forms on the site by entering their first name, last name, telephone number, and e-mail address. The entered data will be used for the sole purpose of sending our newsletter via e-mail and will not be disclosed to third parties.
DATA RETENTION PERIOD OR CRITERIA FOR DETERMINING THE PERIOD
In compliance with Art. 5 paragraph 1 letter e) of EU Reg. 2016/679, the personal data collected will be stored in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
Retention periods for personal data provided through the website depend on the purpose of the processing carried out, in particular:
OPTIONAL NATURE OF DATA PROVISION
Apart from what is specified for browsing data, the user is free to provide personal data stated in the request forms to the data controllers or otherwise indicated in contacts with the Office to make online bookings, request informative material, or other communications. Failure to provide such data may make it impossible to obtain what was requested.
PROCESSING METHODS
Personal data are processed by automated tools for the time strictly necessary to achieve the purposes for which they were collected. Specific security measures are observed to prevent data loss, unlawful or incorrect use, and unauthorized access. Automated decision-making processes are not used in data processing.
RIGHTS OF THE DATA SUBJECTS
You may contact the Data Controller at any time to exercise your rights as provided for in Chapter III of GDPR 679/2016, in particular, the right to request access to personal data and the rectification or erasure thereof (Right to be Forgotten) or the restriction of processing concerning you, or to object to their processing, the right to obtain a copy of the personal data being processed, and the right to data portability. The data subject has the right to receive the requested information without undue delay and, in any case, no later than one month after receipt of the request, extendable if necessary by two months; the data subject also has the right to lodge a judicial remedy and a complaint with the Supervisory Authority, namely the Data Protection Authority (Garante per la protezione dei dati personali - www.garanteprivacy.it: Piazza Venezia n. 11 - 00187 Rome; garante@gpdp.it, or protocollo@pec.gpdp.it).
The aforementioned rights may be exercised by addressing a request to the Data Controller at the following addresses: at the registered office of the company Musa Hotels, by STRATEGICA SERVIZI SRL, located in Via Laurina, 34 – 00187, or via e-mail at the address: privacy@musahotels.com
TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES
Personal data are not transferred to countries outside the European Economic Area, in compliance with Chapter V of GDPR 679/2016.
Regarding website hosting activities, servers located in the United Kingdom are also used and, in this case, the transfer of personal data takes place on the basis of the adequacy decision adopted by the European Commission.
PRIVACY NOTICE PURSUANT TO ART. 13 OF EU REGULATION 2016/679 ("REGULATION")
Company STRATEGICA SERVIZI SRL, located in Via Laurina, 34 - 00187, Rome; CHAT SERVICE (WHATSAPP)
We inform you that, pursuant to Art. 13 of EU Regulation 2016/679 (hereinafter, "Regulation" or "GDPR"), your Personal Data are processed by the company STRATEGICA SERVIZI SRL, in its capacity as Data Controller ("STRATEGICA SERVIZI SRL" or "Data Controller"). The Data Protection Officer (hereinafter, "DPO") is: privacy@musahotels.com. Your personal data will be processed by the Data Controller to respond to your requests for information. The legal basis for processing your data is Art. 6, paragraph 1, letters b) and c) of the Regulation. Your personal data may be shared with natural persons authorized by the Data Controller to process personal data pursuant to Art. 29 GDPR in performance of their job duties (e.g., employees and system administrators, etc.); service providers typically acting as Data Processors pursuant to Art. 28 of the Regulation; entities, bodies, or authorities to whom it is mandatory to communicate your personal data pursuant to statutory provisions or orders of the authorities. Regarding any transfer of data to Third Countries, the Data Controller informs you that processing will take place according to one of the methods permitted by law, such as the consent of the data subject, the adoption of Standard Contractual Clauses approved by the European Commission, or transfer to countries considered safe by the European Commission. Further information is available, upon request, from the Data Controller at the contact details above. Your personal data will be stored only for the time necessary for the purposes for which they were collected, in accordance with the principle of data minimization set forth in Article 5, paragraph 1, letter c) of the GDPR, and in any case no longer than 90 days from the date of provision, for legal evidence requirements. Further information is available from the Data Controller. In relation to the indicated purposes, personal data processing is carried out using manual, IT, and telematic tools with logics strictly related to the purposes themselves and, in any case, in a manner that guarantees the security and confidentiality of the data, as well as compliance with the specific obligations laid down by law. You have the right to request from the Data Controller, at any time, access to your personal data, their rectification, or erasure, or to object to their processing; you have the right to request restriction of processing in the cases provided for by Art. 18 of the Regulation, to withdraw your consent given under Art. 7 of the GDPR at any time; to receive your data in a structured, commonly used, and machine-readable format in the cases provided for by Art. 20 of the Regulation; as well as to lodge a complaint with the competent supervisory authority under Article 77 of the GDPR (Garante per la Protezione dei Dati Personali) pursuant to Art. 77 of the Regulation, if you believe that the processing of your data infringes current regulations. You have the possibility to object to the processing of your data pursuant to Article 21 of the GDPR, stating the grounds justifying your objection: the Data Controller reserves the right to evaluate your request, which would not be accepted in the presence of compelling legitimate grounds for processing that override your interests, rights, and freedoms. Requests must be submitted in writing to the Data Controller at the address privacy@musahotels.com or to the DPO at the contact details provided above.