Privacy Policy

The purpose of this document is to inform the natural person (hereinafter referred to as "Interested") concerning the processing of your personal data (hereinafter referred to as "Personal Data") collected by the data controller, GALGANI ILARIA E PAOLA & C. S.R.L., with registered office in Piazza della Cisterna, 13 - 53037 San Gimignano (SI), CF/VAT no. 00212400527, e-mail address info@leonbianco.com, PEC address hotel-leonbianco@legalmail.it, telephone no. 0577 941294, (hereinafter "Owner"), via the website www.leonbianco.com (hereinafter referred to as "Application").

Changes and updates will be binding as soon as they are published on the Application. If you do not accept the changes made to the Privacy Policy, you must cease using this Application and may request the Controller to delete your Personal Data.

  1. Categories of Personal Data processed

    The Data Controller processes the following types of Personal Data voluntarily provided by the Data Subject:

    • Contact detailsname, surname, address, e-mail, telephone, pictures, authentication credentials, any further information sent by the Data Subject, etc.

    The Controller processes the following types of Personal Data collected in an automated manner:

    • Technical DataPersonal Data produced by the devices, applications, tools and protocols used, such as, for example, information about the device used, IP addresses, browser type, Internet Service Provider (ISP) type. Such Personal Data may leave traces that, in particular when combined with unique identifiers and other information received by servers, can be used to create profiles of individuals
    • Application navigation and usage datasuch as, for example, pages visited, number of clicks, actions taken, duration of sessions, etc.
    • Data concerning the exact location of the data subjectFor example, geolocation data that precisely identifies the location of the Data Subject, which may be collected by satellite network (e.g. GPS) and other means, collected with the consent of the Data Subject. The Data Subject may withdraw consent at any time.

    Failure on the part of the Data Subject to provide Personal Data for which there is a legal or contractual obligation, or if they are a necessary requirement for the conclusion of a contract with the Data Controller, will result in the Data Controller's inability to establish or continue the relationship with the Data Subject.

    The Data Subject who communicates Personal Data of third parties to the Controller is directly and exclusively responsible for their origin, collection, processing, communication or dissemination.

  2. Cookies and similar technologies

    The Application uses cookies, web beacons, unique identifiers and other similar technologies to collect Personal Data of the Data Subject about the pages, links visited and other actions performed when the Data Subject uses the Application. They are stored and then transmitted the next time the User visits the Application. You can view the full Cookie Policy at the following address: https://www.leonbianco.com/cookie-policy/

  3. Legal basis and purpose of processing

    The processing of Personal Data is necessary:

    1. for the performance of the contract with the Data Subject, namely:
      1. fulfilment of any obligation arising from the pre-contractual or contractual relationship with the data subject
      2. support and contact with the data subjectto respond to requests from the data subject
    2. by legal obligation, namely:
      1. the fulfilment of any obligation under current regulationslaws and regulations, in particular on tax and fiscal matters
    3. on the basis of the legitimate interest of the Controller, for:
      1. marketing purposes via email of products and/or services of the holder to sell the Controller's products or services directly using the e-mail provided by the Data Subject in the context of the sale of a similar product or service
      2. statistics with anonymous datato perform statistical analyses on aggregated and anonymous data to analyse the behaviour of the Data Subject, to improve the products and/or services provided by the Controller and better meet the Data Subject's expectations
    4. on the basis of the consent of the data subject, for:
      1. profiling of the data subject for marketing purposesto provide the Data Subject with information on the Controller's products and/or services by means of automated processing aimed at collecting personal information for the purpose of predicting or evaluating the Data Subject's preferences or behaviour
      2. retargeting and remarketingto reach with a personalised advertisement the Data Subject who has already visited or shown interest in the products and/or services offered by the Application using his/her Personal Data. The Data Subject may opt-out by visiting the page of the Network Advertising Initiative
      3. marketing purposes of the Controller's products and/or servicesto send commercial and/or promotional information or materials, to carry out direct sales of the Controller's products and/or services or to carry out market research using automated and traditional methods
      4. detection of the exact location of the data subjectto detect the presence of the data subject, to control access, times and the presence of the data subject at a certain location, etc.

    Based on the legitimate interest of the Data Controller, the Application allows interactions with external platforms or social networks whose processing of Personal Data is governed by their respective privacy policies to which please refer. The interactions and information acquired by this Application are in any case subject to the privacy settings that the Data Subject has chosen on such platforms or social networks. This information - in the absence of specific consent to processing for further purposes - is used solely for the purpose of enabling the use of the Application and providing the information and services requested.

    The Data Subject's Personal Data may also be used by the Data Controller to protect itself before the competent courts.

  4. Processing methods and recipients of Personal Data

    The processing of Personal Data is carried out by means of paper-based and computer-based instruments with organisational methods and logics strictly related to the stated purposes and through the adoption of appropriate security measures.

    Personal Data are processed exclusively by:

    • persons authorised by the Data Controller to process Personal Data who have committed themselves to confidentiality or have an appropriate legal obligation of confidentiality;
    • subjects operating autonomously as separate data controllers or by subjects designated as data processors by the Data Controller in order to carry out all the processing activities necessary to pursue the purposes set out in this policy (e.g. business partners, consultants, IT companies, service providers, hosting providers);
    • parties or entities to whom Personal Data must be disclosed by law or by order of the authorities.

    The persons listed above are required to use appropriate safeguards to protect Personal Data and may only have access to Personal Data necessary to perform the tasks assigned to them.

    Personal Data will not be disseminated indiscriminately in any way.

  5. Place

    Personal Data will not be transferred outside the territory of the European Economic Area (EEA).

  6. Period of retention of Personal Data

    Personal Data will be kept for the period of time necessary to fulfil the purposes for which they were collected, in particular:

    • for purposes relating to the performance of the contract between the Data Controller and the Data Subject, shall be retained for the entire duration of the contractual relationship and, after termination, for the ordinary limitation period of 10 years. In the event of litigation, for the entire duration of the same, until the time limit for appeals is exhausted
    • for purposes relating to the legitimate interest of the Controller, will be retained until that interest is fulfilled
    • for the fulfilment of a legal obligation, by order of an authority and for legal protection, shall be retained in accordance with the time limits provided for by such obligations, regulations and in any case until the expiry of the prescriptive period provided for by the applicable rules
    • for purposes based on the consent of the data subject, will be retained until the consent is revoked

    At the end of the retention period, all Personal Data will be deleted or stored in a form that does not allow the identification of the Data Subject.

  7. Rights of the Data Subject

    Data Subjects may exercise certain rights with regard to Personal Data processed by the Controller. In particular, the Data Subject has the right to:

    • be informed about the processing of their Personal Data
    • withdraw consent at any time
    • limit the processing of one's Personal Data
    • object to the processing of your Personal Data
    • access their Personal Data
    • verify and request rectification of their Personal Data
    • obtain the restriction of the processing of their Personal Data
    • obtain the deletion of your Personal Data
    • transfer their Personal Data to another controller
    • file a complaint with the data protection supervisory authority and/or take legal action.

    To exercise their rights, Data Subjects may address a request to the following e-mail address info@leonbianco.com. Requests will be taken up by the Controller immediately and processed as quickly as possible, in any case within 30 days.

Last updated: 18/07/2025