In compliance with the obligations deriving from national legislation (Italian Legislative Decree no. 196 of 30 June 2003, Code for the protection of personal data) and European legislation (European Regulation for the protection of personal data no. 679/2016, GDPR) and subsequent changes, this website respects and protects the privacy of visitors and users, making every possible and proportionate effort to not infringe the rights of users.
  This privacy policy applies only to the online activities of this website and is valid for visitors/users of the website. It does not apply to information collected through channels other than this website. The purpose of the privacy policy is to provide maximum transparency regarding the information that the website collects and how it is used.
This website processes data based on consent. By using or viewing this website visitors and users explicitly approve this privacy policy and consent to the processing of their personal data in relation to the methods and purposes described below, including any disclosure to third parties if necessary for the provision of a service. 
The provision of data and therefore the consent to the collection and processing of data is optional, the User may refuse consent and may at any time withdraw consent that has already been given (contacting us at the links that you find at the bottom of the page). However, denying consent may make it impossible to provide certain services, and the browsing experience on the website may be compromised. 
Like all websites, this website also makes use of log files in which information collected in an automated manner is stored during user visits. The information collected could be the following: 
- Internet protocol (IP) address
- Type of browser and parameters of the device used to connect to the site
- Name of the Internet service provider (ISP)
- Date and time of the visit
- Visitor's web page of origin (referral) and exit
- Number of clicks
The above information is processed automatically and collected in an exclusively aggregated form in order to verify the correct operation of the website and for security reasons (from 25 May 2018 such information will be processed according to the legitimate interests of the data controller).
For security purposes (spam filters, firewalls, virus detection), the automatically recorded data may possibly also include personal data like IP address, which could be used in accordance with applicable laws to block attempts to damage the website itself or to cause damage to other users or in any case activities that are harmful or that constitute a crime. Such data are never used for the identification or profiling of the user, but only for the protection of the website and its users. 
If the website allows the inclusion of comments, or in the case of specific services requested by the user, the site automatically collects and records some identification data of the user, including the email address. These data are voluntarily provided by the user when requesting the service. By posting a comment or other information, the user expressly accepts the privacy policy, and in particular agrees that the contents included are freely disseminated to third parties.
The data received will be used exclusively for the provision of the requested service and only for the time needed to provide the service.
The information that users of the site deem to make public through the services and tools made available to them are provided by the user knowingly and voluntarily, exempting this website from any liability regarding any violation of laws. It is up to the user to verify that they have permission to enter personal data of third parties or content protected by national and international law.
The data collected by the website during its operation are used exclusively for the purposes specified above and kept for the time strictly necessary to carry out the activities specified. In any case, the data collected from the website will never be provided to third parties for any reason, unless it is a legitimate request by the judicial authority and only in the cases provided by law. 
The data used for security purposes (blocking attempts to damage the site) are kept for seven days.
    The data collected by the website are processed at the headquarters of the Data Controller and at the Web Hosting data centre.
H.J.E. Wenckebachweg 127, 1096 AM Amsterdam, Paesi Bassi 
Cookies
As is customary on all websites, this site also uses cookies, small text files that store information on visitor preferences to improve the functionality of the website, to simplify navigation by automating procedures (e.g. website language) and for the analysis of website use.
Session cookies are essential for distinguishing the connected users and are useful to avoid providing a requested function to the wrong user, as well as for security purposes to prevent cyber attacks on the website. Session cookies do not contain personal data and last only for the current session, i.e. until the browser is closed. No consent is required for this type of cookie.
 By using the website, the visitor expressly consents to the use of cookies.
  Disabling cookies  
Cookies are associated with the browser used and CAN BE DISABLED DIRECTLY BY THE BROWSER, thus refusing/withdrawing consent to the use of cookies. It should be noted that disabling cookies may prevent the correct use of some features of the website itself. Instructions for disabling cookies can be found on the following web pages:
 
Mozilla Firefox - Microsoft Internet Explorer - Microsoft Edge - Google Chrome - Opera - Apple Safari 
Third-party
 cookies This website also acts as an intermediary for third-party cookies used to provide additional services and functions to visitors and to improve the use of the website, like buttons for social media. This site has no control over the cookies of third parties, which are entirely managed by those third parties. As a consequence, the information on the use of these cookies and their purposes, as well as on how to disable them, are provided directly by the third parties on the pages specified below.
In particular, this website uses cookies of the following third parties:
- Google Analytics: a Google analysis tool that uses cookies (performance cookies), collects anonymous browsing data (IP truncated to the last octet) and aggregates them for the purpose of examining the use of the website by users, compiling reports on activities on the website and providing other information, including the number of visitors and pages visited. Google may also transfer this information to third parties where required to do so by law or where such third parties process the information on Google's behalf. Google will not associate the IP address with any other data held by Google. Data provided to Google are stored on Google's servers in the United States. 
On the basis of a specific agreement with Google, which is designated as a data processor, it agrees to process the data according to the requests of the Data Controller, configured through the software settings. Based on these settings, advertising and data sharing options are disabled.
Further information on Google Analytics cookies can be found on the page Google Analytics Cookie Usage on Websites.  The user can selectively disable the collection of data by Google Analytics by installing the specific add-on provided by Google on his/her browser (opt out). 
For more information on the use of the data and their processing by Google, it is recommended to view the information on the page provided by Google and on the page on How Google uses information from sites or apps that use our services. 
Transfer of data to non-EU countries
 This website may share some of the data collected with services located outside the European Union. In particular with Google, Facebook and Microsoft (LinkedIn) through social plugins and the Google Analytics service. The transfer is authorised on the basis of specific decisions of the European Union and the Italian Data Protection Authority, in particular Decision 1250/2016 (Privacy Shield - here is the information page of the Italian Data Protection Authority), therefore no further consent is required. The companies mentioned above guarantee their compliance with the Privacy Shield. 
Security measures
  This website processes the data of users in a lawful and correct manner, adopting the appropriate security measures to prevent unauthorised access, disclosure, modification or unauthorised destruction of data. Processing is carried out using IT and/or digital tools, with organisational methods and logic strictly related to the purposes specified. In addition to the controller, in some cases other categories of employees may have access to the data including those involved in the organisation of the website (administrative, sales, marketing, legal, system administrators) or external parties (like suppliers of third-party technical services, postal couriers, hosting providers, IT companies, communication agencies). 
User rights
  Pursuant to European Regulation 679/2016 (GDPR) and national legislation, the User can, in accordance with the procedures and within the limits established by current legislation, exercise the following rights: - Request confirmation of the existence of personal data concerning him/her (right of access).
- Know their origin.
- Receive intelligible communication about them.
- Receive information about the logic, methods and purposes of the processing.
- Request the updating, correction, completion, deletion, transformation into anonymous form, blocking of data processed in violation of the law, including those no longer necessary for the pursuit of the purposes for which they were collected.
- In cases of consent-based processing, receive only the cost of any media, the data provided to the controller in a structured and legible form by a data processor and in a format commonly used by an electronic device.
- The right to lodge a complaint with the Supervisory Authority (Italian Data Protection Authority - link to the Authority page).
- As well as, more generally, exercising all the rights that are recognised by the current provisions of the law. Requests should be addressed to the Data Controller. 
In the event that the data are processed on the basis of legitimate interests, the rights of data subjects are guaranteed (with the exception of the right to portability that is not provided for by the regulations), in particular the right to oppose the processing that can be exercised by sending a request to the data controller. 
Data Controller
The data controller in accordance with applicable laws is Grande Albergo Excelsior Vittoria S.p.A.
Data Processor
H.J.E. Wenckebachweg 127, 1096 AM Amsterdam, Paesi Bassi 
Google is designated as a data processor, processing data on behalf of the controller (Google Analytics).