Privacy Policy

Privacy Policy on the Processing of Personal Data

– Pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR) –

Bullo & Zambon di Bullo Iginio e Marino S.n.c. (hereinafter, the “Data Controller”)
Dear visitor, with this page we intend to provide you with all the information required under Article 13 of Regulation (EU) 2016/679 (also known as GDPR or General Data Protection Regulation), regarding the processing of personal data of visitors to this website.

This information does not concern other websites, pages or online services that may be reached via hyperlinks published on this website.

If you are looking for information regarding the use of cookies on this website, you can find it in the dedicated section at the bottom of the page, called the cookie policy.

1. Data Controller and Data Protection Officer

The Data Controller is Bullo & Zambon di Bullo Iginio e Marino S.n.c., with registered office in Via Cappuccina 38, Mestre – Venice, VAT and Tax Code 00268340270, email privacy@starfishapartments.it.
The company has appointed a Data Protection Officer (DPO), who can be contacted at the above email address.

2. Purpose and Legal Basis of Processing

The personal data collected during website navigation are processed, in compliance with the legal obligations applicable to the Data Controller, for the following purposes:

  1. proper technical functioning of the website, including checks aimed at preventing fraudulent activities;
  2. allowing and monitoring access to restricted areas of the website;
  3. handling requests for information or services submitted by users through forms available on the website or via company email addresses;
  4. ensuring the provision of customer satisfaction services, offering information about products and assistance services;
  5. managing registrations for events organized by the company through dedicated online forms.

3. Browsing Data

The IT systems and software procedures used to operate this website collect certain personal data whose transmission is implicit in the use of Internet communication protocols.
This category of data includes IP addresses or domain names of users’ devices, the URI/URL addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (success, error, etc.), and other parameters related to the user’s operating system and IT environment.

Except as indicated in the cookie policy available at the end of this document, browsing data are used solely for the purposes described in point 2, number 1, for the duration of the browsing session.

Aggregated and anonymized data may also be processed to obtain statistical information on the use of services (most visited pages, number of visitors by time slot or day, geographical areas of origin, etc.).

4. Data Processors and Recipients of Personal Data

Browsing data and data voluntarily provided by users through forms on the website may also be processed by external parties formally appointed as Data Processors pursuant to Article 28 GDPR, belonging to the following categories:

  • companies providing website and IT system maintenance services;
  • companies providing electronic communication services, particularly email services;
  • companies providing database management and maintenance services for the Data Controller.

Data will not be disclosed to other external parties.

5. Data Retention Period

Browsing data collected for the purposes indicated in point 2, number 1, are stored only for the duration of the browsing session.
Data necessary for access to restricted areas are stored until the authorization expires.
Data processed for the purposes referred to in point 2, numbers 3, 4, 5 are retained for the duration of the relationship with the customer or partner:

  • point 2 number 2) details provided in the cookie policy;
  • point 2 number 3) retained for two years;
  • point 2 number 4) retained for one year;
  • point 2 number 5) retained for two years;
  • point 2 number 6) retained for three years.

6. Nature of Data Provision

For the purposes referred to in point 2, numbers 1 and 2, the provision of data is mandatory.
For the purposes referred to in point 2, numbers 3, 4, 5, data provision is mandatory for fields marked with an asterisk (*), while it is optional for all other fields. Failure to provide mandatory data will make it impossible to process the request. Failure to provide optional data may result in less accurate responses or difficulty in contacting the data subject.

7. Your Rights

Regulation (EU) 2016/679 grants you, as a data subject, several rights which you may exercise by contacting the Data Controller or the DPO using the contact details provided above.
These rights include:

  • the right to know whether your personal data are being processed and to access such data;
  • the right to rectification of inaccurate data and completion of incomplete data;
  • the right to erasure of personal data;
  • the right to restriction of processing;
  • the right to object to processing;
  • the right to data portability.

You also have the right to lodge a complaint with the Italian Data Protection Authority at: https://www.garanteprivacy.it/home/modulistica-e-servizi-online/reclamo.
For more information, you can consult: https://www.garanteprivacy.it/home/diritti

Privacy policy last updated on March 4, 2021.

The Data Controller reserves the right to modify this privacy policy at any time. Users are therefore encouraged to check this page periodically.