Privacy policy
This privacy policy is addressed, within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR), to all persons who use this website.
This policy applies only to this website and not to any other websites that the user may access via hyperlinks.
Within the framework of the legal requirements, the operator of this website guarantees that personal data is processed with due regard for the fundamental rights and freedoms and the dignity of the data subject, with particular reference to confidentiality, personal identity and the right to the protection of personal data.
1. Name and address of the controller and the data protection officer
Controller within the meaning of the GDPR:
Gasthof Goldener Löwe
Owner: Pichler Harald & Co. KG
Kirchplatz 11
39040 Montan (BZ)
goldenerloewe@goldenerloewe.it
T. +39 0471 819844
Data protection officer:
goldenerloewe@goldenerloewe.it
2. Place of data processing
ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, D-02742 Friedersdorf (servers located in Germany).
The hosting provider operates its own data centres; data is stored on servers within the European Union and is therefore subject to strict European data protection laws.
3. Scope and legal basis of the processing of personal data
As a rule, we process our users' personal data only to the extent necessary to provide a functional website and our content and services. Personal data is generally processed only with the user's consent. An exception applies in cases where obtaining prior consent is not possible for practical reasons and the processing of the data is permitted or required by law.
The legal basis for the processing of personal data is Art. 6 GDPR and, where applicable, specific contractual agreements with the user and the obligations associated with them.
4. Data erasure and storage period
Unless specifically stated otherwise, we store personal data only for as long as is necessary to fulfil the purposes pursued.
In some cases the law requires personal data to be retained. In these cases, we store the data solely for these legal purposes, do not process it in any other way and erase it once the statutory retention period has expired.
5. General purposes of processing
We use personal data for the purpose of operating this website and for the purposes listed individually below.
6. What data we use and why
Access data / server log files
When you use this website, information about your usage behaviour and your interaction with the site, as well as data about your computer or mobile device, is collected automatically (so-called server log files). This data includes: name and URL of the page accessed, date and time of access, browser type and version, operating system, referrer URL (i.e. the previously visited page) and the IP address of the client/user.
All of the above log files are automatically deleted from our server after 365 days. During this period, the user's IP address is stored only in partially anonymised form. Collecting the data to provide the website and storing it in log files is essential for operating the website. This also constitutes our legitimate interest in data processing pursuant to Art. 6(1)(f) GDPR.
In addition, among other things to detect and defend against cyber attacks, access is logged administratively with the full IP address. This data is deleted after seven days at the latest.
Cookies
Our website uses cookies. Cookies are text files that are stored in the web browser or by the web browser on the user's computer system. Our legitimate interest in using cookies pursuant to Art. 6(1)(f) GDPR lies in making our website more user-friendly, effective and secure.
As cookies are stored directly on your computer, you as the user have full control over their use. By changing the settings in your web browser, you can deactivate or restrict the transmission of cookies. Cookies that have already been stored can be deleted at any time. If cookies are deactivated for our website, it may no longer be possible to use all of the website's functions to their full extent.
Google Web Fonts
For the uniform display of fonts, this site uses so-called web fonts provided by Google. When you open a page, your browser loads the required web fonts into its cache in order to display texts and fonts correctly. For this purpose, the browser you use must connect to Google's servers. This informs Google that our website has been accessed via your IP address. Google Web Fonts are used in the interest of a uniform and appealing presentation of our online services and constitute a legitimate interest within the meaning of Art. 6(1)(f) GDPR.
Contact form and email contact
Our website includes a contact form that can be used to get in touch electronically. If a user takes advantage of this option, the data entered in the input mask is transmitted to us and stored. Your consent to the processing of the data is obtained during the submission process, with reference to this privacy policy. The legal basis for processing the data is therefore your express consent pursuant to Art. 6(1)(a) GDPR.
Alternatively, you can contact us via the email address provided. In this case, the user's personal data transmitted with the email is stored. The data is not passed on to third parties in this context. The data is used exclusively to handle the conversation. The user may revoke their consent to the processing of personal data at any time.
Google Maps
At one or more points on this website we embed maps (“Google Maps”) from the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. These are embedded via a script, as a result of which your IP address and your location data (though not without consent, usually within the settings of your device) are sent to Google. The data may be processed in the USA. Data is transferred to the USA on the basis of the European Commission's adequacy decision on the EU-US Data Privacy Framework, under which Google LLC is certified. In addition, the European Commission's standard contractual clauses apply (Art. 46(2)(c) GDPR).
7. Your rights as a data subject
If your personal data is processed, you are a “data subject” within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
- the right to confirmation and access
- the right to rectification
- the right to erasure (“right to be forgotten”)
- the right to restriction of processing
- the right to notification
- the right to data portability
- the right to object
- the right to withdraw consent under data protection law
- the right not to be subject to a decision based solely on automated processing, including profiling
- the right to lodge a complaint with the supervisory authority
8. Data security
We take great care to protect your data within the scope of applicable data protection laws and technical possibilities. Your personal data is always transmitted to us in encrypted form. You can recognise an encrypted connection by the browser's address bar changing from “http://” to “https://” and by the padlock symbol in your browser bar. We use the SSL (Secure Socket Layer) encryption system but point out that data transmission over the Internet may have security gaps. Complete protection of data against access by third parties is not possible. To secure your data, we maintain technical and organisational security measures in accordance with Art. 32 GDPR, which we continuously adapt to the state of the art.
9. Disclosure of data to third parties
As a rule, we use your personal data only within our company. If and insofar as we engage third parties in the performance of contracts, they receive personal data only to the extent that the transfer is necessary for the relevant service. Where we outsource certain parts of data processing (“processing on behalf”), we contractually oblige processors to use personal data only in accordance with the requirements of data protection law and to ensure the protection of the data subject's rights.
10. Further information
If you have any questions or concerns about data protection, please contact: goldenerloewe@goldenerloewe.it
Competent supervisory authority (Italy): Garante per la protezione dei dati personali, Piazza di Monte Citorio 121, 00186 Rome, tel.: (+39) 06.696771, email: garante@gpdp.it, website: www.garanteprivacy.it