(CLICK PER LA VERSIONE ITALIANA)
Pursuant to Articles 13 and 14 of EU Regulation No. 2016/679 (hereinafter referred to as “GDPR”), concerning the protection of natural persons with regard to the processing of personal data and the free movement of such data, OBLADI’ S.R.L., as the Data Controller, is required to provide you with all relevant information regarding the purposes and methods of the processing of your personal data, the recipients to whom your data may be communicated, and all rights granted to you by law regarding the management of your personal data by the Controller.
- Who determines the purposes and means of the processing?
Data Controller
The Data Controller is OBLADI’ S.R.L., located at IV Novembre 3 in Orio al Serio (BG).
PEC: nannif@pec.stilelibero.bg.it
Phone: +39 035 4226340
- What personal data are processed by the Data Controller?
The Data Controller will collect and process your personal data, meaning any information that can identify you and that is directly or indirectly attributable to you, including but not limited to:
- Personal identification data (name, surname, residence, domicile, email address, phone number, tax code, VAT number, etc.)
- Special categories of data (related to health conditions)
- Data related to the stay (dates, times, any third parties with whom the stay is shared, etc.)
- Personal preferences
- Identification documents
- Handwritten signature
- Purchase history
- Credit card and/or banking data
- Video surveillance images
- Data related to electronic devices used to connect to the facility’s network
and any other data necessary to achieve the purposes described in section 4.
The processing of special categories of data, such as data related to health conditions, is only possible if such data is voluntarily and directly provided by the data subject (freely and unsolicited). In such cases, consent for processing will be collected.
- How are personal data collected?
Personal data are provided directly by the data subject to the Data Controller or collected through other parties such as:
- OTA (Online Travel Agency) such as, com, Venere.com, Worldhotels.com, Trivago.com, Expedia.com, ecc;
- Traditional travel agencies;
- Institutions, associations, organizations, companies or individuals organizing events or stays at the facility.
- Why do you collect my data?
Purpose of processing
The personal data collected by the Data Controller will be processed for the following purposes:
- Customer management;
- Contract subscription and management;
- Administrative management;
- Dispute management;
- Protection of individuals’ physical health;
- Protection and guarantee of personal safety and security;
- Protection of the company’s property and assets;
- Ensuring the use and security of the ICT infrastructure (e.g., WI-FI).
Legal basis of processing
The processing of data will strictly comply with legal provisions, according to the principles of lawfulness and fairness and in respect of the right to privacy. Data will be processed based on:
- Consent;
- Pre-contractual and contractual obligations;
- Legal obligations;
- The Data Controller’s legitimate interest.
- How will the collected data be processed?
Methods of processing
Processing will be carried out using both automated and manual means, in compliance with Article 32 of GDPR 2016/679, and specifically:
- Through operations allowing the collection, recording, organization, storage, consultation, processing, modification, selection, retrieval, use, communication, deletion, and destruction of data;
- Using electronic or otherwise automated tools that allow data to be stored, managed, and transmitted, but always configured to ensure maximum confidentiality and necessary protection;
- Using paper-based documents with appropriate security measures to prevent access by unauthorized persons.
- Why should I provide my data to the Controller? Can I refuse?
Nature of data provision and consequences of refusal
Where the provision of personal data is required to perform a contract (hotel service) or to comply with a legal obligation (e.g., communication to the Police Headquarters pursuant to Article 109 of Royal Decree 773/1931), processing is essential, and if the data subject refuses to provide such data, the Data Controller will be unable to carry out the activities set out in Section 4 and, in general, to fulfill contractual obligations.
For purposes requiring your consent, refusal will not affect compliance with the aforementioned obligations.
- Who will have access to my data?
Data disclosure
Personal data may be transferred and processed by other parties, acting as authorized persons, processors, or autonomous controllers, in order to fulfill pre-contractual, contractual, legal obligations, or for legitimate interest.
Categories of recipients may include, by way of example:
- Authorized personnel;
- Data Processors;
- System Administrators;
- Accounting consultants;
- Legal consultants;
- Banks;
- Insurance entities;
- Auditing firms;
- Service companies for hotel infrastructure maintenance;
- Internet and email service providers;
- Entities, associations, organizations, companies or individuals organizing events or stays at the facility;
- Public authorities and police forces.
The data provided and collected by the Data Controller are not subject to public disclosure or profiling.
The complete list of Data Processors is available upon request by contacting the company.
- Could my data be transferred abroad?
Personal data may be transferred to EU countries or to non-EU countries or international organizations where such processing is necessary to achieve the purposes stated in Section 4 and to fulfill contractual obligations.
- How long will my data be stored?
Data retention
Personal data will be stored for the time strictly necessary to perform the activities related to the purposes described in this notice. Specifically, retention periods will be as follows:
- 10 years (as required by civil law obligations – Art. 2220 Civil Code);
- Up to 3 months from check-out for credit card data;
- Up to 3 years from the last check-out for personal data, special categories of data, stay details, personal preferences, identification documents, handwritten signature, and purchase history, unless otherwise requested by the data subject;
- Up to 72 hours for video surveillance footage;
- 30 days for data regarding access and use of ICT resources (e.g., WI-FI).
Longer retention periods may apply if required by specific sector regulations. In the case of disputes, personal data will be stored until the limitation period for protecting rights arising from the contractual relationship.
- How can I limit, prevent, or object to the processing of my data by the Controller?
Data subject rights
With a written request sent via certified email (PEC) or registered letter with return receipt to the address of the Data Controller (contacts in Section 1), you have the right to:
Right of access (Art. 15, GDPR):
To obtain confirmation from the Data Controller as to whether or not your personal data is being processed, and if so, access to such data and specific information outlined in Article 15 of the GDPR.
Right to rectification (Art. 16, GDPR):
To obtain without undue delay the rectification of inaccurate personal data and to have incomplete data completed.
Right to erasure (Art. 17, GDPR):
To obtain the erasure of your personal data without undue delay, unless there are legal grounds preventing the exercise of this right.
Right to restriction of processing (Art. 18, GDPR):
To request, where applicable, the restriction of processing or to withdraw previously given consent. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Right to data portability (Art. 20, GDPR):
If processing is based on consent or a contract and carried out by automated means, to receive your data in a structured, commonly used, and machine-readable format, and to transmit it to another controller where technically feasible.
Right to object (Art. 21, GDPR):
To object at any time, on grounds relating to your particular situation, to the processing of your data based on the Data Controller’s legitimate interest or your consent, including profiling, unless there are compelling legitimate grounds for the processing.
Right not to be subject to automated decision-making, including profiling (Art. 22, GDPR):
To not be subject to a decision based solely on automated processing that produces legal effects or significantly affects you.
As stated in Section 7, the Data Controller does not use automated decision-making processes.
Right to lodge a complaint with the supervisory authority (Art. 77, GDPR):
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the Supervisory Authority if you believe that your data is being processed in violation of the GDPR.
- How long does it take to receive a reply from the Controller?
In case you request information regarding your data, the Data Controller will respond as soon as possible—unless it proves impossible or requires a disproportionate effort—and in any case within 30 days from the request. Any inability or delay in fulfilling the request will be duly explained.
PRIVACY NOTICE FOR THE PROCESSING OF PERSONAL DATA for users of the “Stile Guest” Wi-Fi network (Article 13 of EU Regulation 679/2016)
Within the “Stile Libero – Bed & Breakfast” premises, managed by Obladì S.r.l., guests may freely access the Wi-Fi network named “Stile Guest”. Access to the network is provided to guests through a password given at check-in. No authentication is required and no personal or identifying data is collected. The only information recorded, which may be potentially linked to the data subject, is the “device name” and the corresponding “MAC Address”.
This notice is provided to ensure transparency regarding the processing of browsing data in cases where the device name may be associated with the user’s identity.
IMPORTANT: In case of illegal activities committed through the “Stile Guest” network, technical connection data may be disclosed to the competent Authorities upon request.
- Nature and provision of data: The technical data collected are necessary to allow access to the free Wi-Fi network provided by Obladì S.r.l. and are automatically recorded during use.
- Purpose of processing: The data are processed solely to enable access to the network, ensure its security, and potentially to prevent misuse.
- Data retention period: The data are retained until the end of the contract execution and, in any case, for a maximum of 30 days.
- Legal basis: The execution of the Wi-Fi service contract (Art. 6, par. 1, letter b GDPR) and, if applicable, the legitimate interest of the Controller (Art. 6, par. 1, letter f GDPR).
- Categories of data: The processing concerns aggregated usage data such as: system logs; IP addresses and any visited URLs; access times; MAC addresses and device names.
- Processing methods: The data are processed electronically with adequate security measures and automated methods, using IT or telecommunication tools. Network access is governed by internal policies that prevent browsing to inappropriate or potentially harmful websites.
- Communication and non-EU data transfers: The data are stored on systems controlled by Obladì S.r.l. and will not be disclosed to third parties, except in compliance with legal obligations or upon request from judicial authorities. Personal data will not be transferred outside the EU; if necessary, such processing will be carried out in accordance with Chapter V of EU Regulation 679/2016, subject to verification of adequacy decisions for third countries, or the existence of appropriate safeguards or binding corporate rules, or specific exceptions, with prior consent of the data subjects and relevant notification.
- Automated decision-making and profiling: No automated decision-making or profiling activities are carried out.
- Data subject rights: Data subjects are informed of their right to request from the Data Controller access to personal data, rectification or erasure of such data, restriction of processing, objection to processing, as well as the right to data portability, as provided for in Articles 15 and following of EU Regulation 679/2016 (requests may be sent to the contact details provided for the Data Controller or the privacy service). Data subjects are also informed of their right to lodge a complaint with the supervisory authority (Italian Data Protection Authority).
- Contacts: For the exercise of rights or further information, you may contact:
Obladì S.r.l. – Via IV Novembre 3, Orio al Serio (BG)
E-mail: welcome@stilelibero.bg.it
Phone: +39 035 422 6340

