DATA CONTROLLER
Adrastea Viaggi s.n.c., represented by its legal representative pro tempore, with registered office in Tirano (SO), postal code 23037, Via Pio Rajna 13, e-mail: info@treninorosso.it, PEC: adrasteaviaggi@pec.it, acting as Data Controller (hereinafter, "Controller"),
INFORMS YOU
that, in compliance with Regulation (EU) 2016/679 (hereinafter, "GDPR"), your personal data will be processed in accordance with the aforementioned regulation and with the methods and for the purposes specified below:
The Controller, in the context of its business activities, processes personal identification and contact data (in particular: name, surname, address, tax code/VAT number, e-mail address, telephone number – hereinafter "personal data") freely provided by the user when filling in data collection forms on the website or when requesting services/quotes.
Your personal data are processed for the following distinct purposes:
2.1 Performance of a contract and legal obligations (Art. 6, par. 1, letters b, c GDPR)
Data are processed to:
a) Manage requests for information, quotes, and the booking/purchase of tourist services;
b) Comply with obligations provided for by law, regulations, EU legislation, or orders of the Authorities (e.g., tax and accounting obligations).
Nature of data provision: The provision of data for these purposes is mandatory. Failure to provide such data will make it impossible to deliver the requested services.
2.2 Direct Marketing purposes (Art. 6, par. 1, letter a GDPR)
Subject to your explicit and optional consent, data may be processed to send promotional and commercial communications, informative materials, and newsletters via e-mail, SMS, messaging systems, or paper mail regarding initiatives and services offered by the Controller (Adrastea Viaggi / Trenino Rosso).
Nature of data provision: The provision of data is optional. You may revoke your consent at any time without affecting the use of the main services.
2.3 Soft-Spam and Legitimate Interest (Art. 6, par. 1, letter f GDPR - Recital 47)
If you are already a customer, the Controller may send you commercial communications via e-mail regarding services or products similar to those you have already purchased, without prejudice to your right to object to such sendings at any time (opt-out) using the dedicated link present in the e-mails or by contacting the details indicated in point 8.
Personal data provided will not be disclosed to third parties for their autonomous marketing purposes. Data may only be communicated to third parties strictly functional to the provision of services or to legal obligations, including:
Consultants and professionals in accounting, tax, legal, and IT matters;
Banking and credit institutions for payment processing;
Technical service providers and e-mail management/sending platforms (e.g., cloud service providers, hosting, CRM/newsletter platforms), duly appointed as Data Processors pursuant to Art. 28 GDPR;
Competent Authorities and Public Bodies to comply with legal obligations.
The processing is carried out using both manual/paper and IT/telematics tools, adopting adequate technical and organizational security measures designed to prevent data loss, unlawful or incorrect use, and unauthorized access (Art. 32 GDPR).
Please note that, taking into account the purposes of processing specified in point 2.1, the provision of data is mandatory and any failure, partial, or inaccurate provision may result in the impossibility of processing your request.
The management and storage of personal data take place on servers located within the European Union. Should technical/operational needs require data transfer to non-EU countries (e.g., use of cloud services or e-mail platforms), the Controller ensures that the transfer will take place in compliance with applicable legal provisions (Arts. 44 et seq. GDPR), guaranteeing adequate levels of protection through adequacy decisions of the European Commission or the adoption of Standard Contractual Clauses.
Contractual and tax data: Retained for the duration of the relationship and subsequently for 10 years to fulfill legal obligations (Art. 2220 of the Italian Civil Code).
Data for Marketing purposes: Retained until consent is revoked by the data subject or until the right to object is exercised (or in any case within the time limits established by law or by measures issued by the Data Protection Authority).
As a data subject, you are recognized the rights established by Arts. 15-22 of EU Regulation 2016/679, specifically the right to:
Request access to your personal data (Art. 15);
Obtain the rectification of inaccurate data or the integration of incomplete data (Art. 16);
Obtain the erasure of data ("right to be forgotten") in the cases provided for by Art. 17;
Obtain restriction of processing (Art. 18);
Request data portability in a structured and readable format (Art. 20);
Object at any time to the processing of personal data (Art. 21);
Withdraw consent at any time, without affecting the lawfulness of processing based on consent given before its withdrawal;
Lodge a complaint with the Data Protection Authority (Garante per la Protezione dei Dati Personali).
You may exercise your rights by sending a request to the Data Controller at the following contacts: adrasteaviaggi@pec.it, info@treninorosso.it - Adrastea Viaggi s.n.c., Via Pio Rajna 13 – 23037 Tirano (SO) ITALY.