Privacy Policy
Privacy notice pursuant to Articles 13 and 14 of EU Regulation 2016/679
- Data Controller and Data Protection Officer
The Company Continental Mare S.r.l. (hereinafter, the “Controller”), with registered office in Naples (ZIP 80133), via M. Cervantes De Savaedra 55, Tax Code and VAT No. 03376520635 (phone: +39 081.992577; fax +39 081.992505; email: contimare@leohotels.it, PEC: continentalmaresrl@pec.it), hereby informs that it is the Data Controller pursuant to Article 4(7) of EU Regulation 2016/679.
The company has appointed a Data Protection Officer, who can be contacted by email at: palmieri@aptconsulting.it.
B – Data subject to processing
The data subject to processing, briefly listed below, will be provided by you for the execution of existing legal relationships: identification data, contact details, payment data, images, and health-related data (the latter, hereinafter also “special categories of data”, voluntarily communicated).
Data may be collected directly from the Customer or from third parties (e.g. travel agencies or other intermediaries) through whom bookings are made.
C – Purpose of processing, nature of data provision and legal basis
The personal data you provide will be processed exclusively for the following purposes:
- to fulfil information requests and the accommodation contract;
- to comply with public security obligations pursuant to Art. 109 of Royal Decree No. 773 of 18 June 1931, as amended;
- to comply with general legal, regulatory, EU or Authority orders to which the Controller is subject;
- to fulfil administrative, accounting and tax obligations;
- to provide attentive and personalized services during the stay (e.g. wellness centre) and to speed up check-in procedures;
- to protect the Controller’s credit;
- to send you promotional messages and updates on rates and offers;
- to ensure safety, protection and preservation of clients’ and Controller’s property, preventing any unlawful acts.
The legal basis for processing is: performance of a contract or pre‑contractual measures (point 1), compliance with legal obligations (points 2, 3 and 4), legitimate interest of the Controller (points 5, 6 and 8), and—regarding any health data provided voluntarily—your explicit consent (point 7 and special categories under points 1 and 5).
Providing data for purposes 1 and 5 is optional; failure to provide them will prevent (or correctly prevent) contract execution.
Data provision for purposes 2, 3, 4, 6 and 8 is mandatory; failure to do so will prevent legal compliance and protection of the Controller’s legitimate interest.
Providing data for purpose 7 is optional; without it, newsletters and/or promotional offers will not be sent.
Data will be processed with all technical and organisational measures appropriate to ensure compliance with Regulation 2016/679.
D – Communication to third parties and/or data disclosure – international transfer
For purposes under section C, the Controller informs you that your data may be communicated to the following external, duly appointed data processors: 1) IT service providers (including reservation systems); 2) public security authorities or other authorities for legal compliance; 3) (on voluntary personal care services) wellness centre staff; 4) banks, financial institutions, judicial authorities, professionals or other parties appointed for accounting, administrative or managerial duties connected to the Controller’s business or for defense of its legitimate interest.
Data shall be processed exclusively in Italy and, in any case, within the European Union.
E – Data retention period
Personal data will be retained as follows: I) (in the management system – excluding special data): max 5 years (identification data); 180 days after check‑out (payment data); II) (paper/in local database only): until end of season (identification and payment data), and until check‑out (special data); III) personal data processed for purpose 5 will be retained for 3 years; IV) personal data processed for purpose 7 will be retained for 3 years, unless consent is withdrawn sooner.
Unless a longer period is legally required (e.g. public security). CCTV footage will be retained for no more than 24 hours. In such cases, data will be immediately deleted and/or anonymised.
F – Data subject’s rights
The data subject may at any time exercise the rights under Regulation 2016/679, in particular: a) access; b) rectification, erasure or restriction; c) objection; d) portability; e) withdraw consent (without affecting prior processing); f) lodge a complaint with the supervisory authority (Privacy Authority).
These rights can be exercised by contacting: