This translation is provided for convenience only; in case of discrepancy, the Italian version prevails.
This privacy policy describes how the personal data of users who visit the website www.tenerife.info is processed, in accordance with Article 13 of Regulation (EU) 2016/679 (the “GDPR”) and Italian data protection legislation.
1. Data controller
The data controller is WebNow Srl, Via Faede, 1 – 25040 Esine (BS), Italy – VAT No. IT03779200983.
If you have any questions about the processing of your data or wish to exercise your rights, you can write to webnow2016@gmail.com.
2. What data we process
Browsing data. As with any website, the computer systems that run the site collect certain data whose transmission is implicit in the use of Internet protocols: IP address, date and time of the request, page requested, server response code, browser type and operating system, and referring page. This data is recorded in the server log files and is not used to identify or profile users.
Data you provide voluntarily. If you contact us by email or telephone, for example to request information or to make advertising proposals, we process the data you give us (name, contact details and the content of your request).
Payment data. The site’s payment pages, which are reserved for customers who have agreed on a service with the data controller, redirect to PayPal. Card or PayPal account details are entered directly on the PayPal website and are never visible to the data controller. We receive only transaction information from PayPal (for example, name, email address, amount and date of payment).
Cookies. The site uses only one technical cookie. Full details can be found in the Cookie policy.
The site does not use any analytics, profiling or advertising tools and does not contain any contact or registration forms.
3. Purposes and legal bases
- Operation and security of the site (browsing data): the data controller’s legitimate interest in providing a functioning and secure website (Art. 6(1)(f) GDPR).
- Responding to your requests: taking steps at your request prior to entering into a contract, and the legitimate interest in responding to those who contact us (Art. 6(1)(b) and (f) GDPR).
- Handling payments and meeting accounting and tax obligations: performance of a contract and compliance with legal obligations (Art. 6(1)(b) and (c) GDPR).
- Establishment, exercise or defence of legal claims: the data controller’s legitimate interest (Art. 6(1)(f) GDPR).
4. How we process data and for how long
Data is processed using IT tools and with appropriate security measures to prevent its loss, unlawful use and unauthorised access. We keep it only for as long as necessary for the purposes set out above:
- browsing data: for as long as strictly necessary for the security of the site, in line with the log retention periods set by the hosting provider, unless the data is needed to investigate criminal offences;
- contact requests: for as long as necessary to handle the request and any relationship arising from it;
- payment data: for 10 years, as required by law for accounting records.
5. Who we share data with
Data is not disseminated. It may be disclosed, solely for the purposes set out above, to:
- technical service providers, such as the site’s hosting provider and the email service provider, which act as data processors or under their own terms of service;
- PayPal (Europe) S.à r.l. et Cie, S.C.A., which processes payment data as an independent data controller in accordance with its own privacy notice;
- the data controller’s advisers (for example, its accountant) and public authorities, where provided for by law.
6. Transfers of data outside the European Union
Some service providers, for example email or payment providers, may also process data outside the European Union. In such cases, data is transferred only on the basis of an adequacy decision of the European Commission (such as the EU-U.S. Data Privacy Framework) or of other safeguards provided for in Articles 44 et seq. of the GDPR, such as standard contractual clauses.
7. Is providing your data mandatory?
Browsing data is necessary in order to use the site. Providing any other data is optional, but without it we cannot respond to your requests or handle payments.
8. Your rights
You can exercise the rights provided for in Articles 15 to 22 of the GDPR at any time:
- access to your data and a copy of it;
- rectification of inaccurate or incomplete data;
- erasure of data (the “right to be forgotten”);
- restriction of processing;
- data portability;
- objection to processing based on legitimate interest.
To exercise them, write to webnow2016@gmail.com. We will reply within one month of your request.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of the European Union country in which you reside or work.
9. Automated decision-making
We do not carry out profiling or take decisions based solely on automated processing.
10. Children
The site is not aimed at children under the age of 14, and we do not knowingly collect data relating to them.
11. Links to other websites
The site contains links to third-party services and websites, such as Google Maps, WhatsApp, Facebook and the official websites of parks and attractions. These links do not transmit any data to third parties until you open them; once they are opened, the privacy policies of those websites apply.
12. Changes to this privacy policy
This privacy policy may be updated, for example in the event of changes in the law or new services offered by the site. The current version is always published on this page, together with the date of the last update.