DATA PROTECTION
control over data
Status: October 29, 2020
**Introduction**
We take the protection of the data of users of our website and/or mobile app very seriously and are committed to safeguarding the information that users provide to us in connection with the use of our website and/or mobile app (collectively, "digital assets"). Furthermore, we commit to protecting and using your data in accordance with applicable laws.
This document informs you about the handling and use of your data (type, scope, and purpose of collection) and the data protection on this online service (short "website") in accordance with the European General Data Protection Regulation (EU 2016/679, hereinafter "GDPR").
**Responsible for Data Processing**
Thomas Ebner
Göllerweg 11
39040 Aldein
Tax Number: BNRTMS88T01A952
VAT Number: IT02985960216
**Type of Processed Data**
According to Article 13 of the European General Data Protection Regulation, we process the following data:
- Your personal data (first name, last name, address, phone number, email, date of birth, place of birth, language, etc.)
- Your data in travel documents and ID cards
- Your payment data, EC cards, credit cards, and bank cards
- The duration of the stay you requested and personal preferences related to the stay that you provide us
The data is stored, processed, and, if necessary and legally required, transferred to third parties (e.g., public authorities, tourist associations). Your data will not be transferred to third countries.
If you refuse to provide personal data, travel document data, and bank data, it will not be possible for us to fulfill our contractual obligations and host you on our premises. We do not use profiling or automated decision-making.
**Legal Basis for Data Processing**
The legal basis for these data processing activities are:
- The fulfillment of our pre-contractual and contractual obligations towards you
- Your consents
- Legal, contractual, or other legal obligations on our part (e.g., documentation rights and obligations according to accounting, tax, and customs law, contract law, reporting, or legal disputes)
- Our legitimate interests (e.g., improving our customer service, including direct advertising, or the enforcement of our own legal interests)
The retention period for the data is determined by the duration of our business relationship, your consents, and the statutory retention obligations and legal requirements applicable to us.
**Your Rights**
You may request free of charge at any time information about the personal data we store about you. As a data subject, you also have the right to withdraw, access, delete, correct, restrict, and transfer your personal data, provided there are no legal retention obligations on our part. When exercising your right to withdraw, all your data will be irrevocably deleted, unless higher legal regulations are violated.
For more information about your rights as a data subject, please contact us at the email address above. We will be happy to assist you. For complaints, the supervisory authority "Garante per la protezione dei dati personali" is responsible: Piazza di Monte Citorio n. 121 00186 ROMA, Fax: (+39) 06.69677.3785, Phone: (+39) 06.696771, Email: garante@gpdp.it.
**Disclaimer**
We strive to provide accurate and complete information on this website. However, we assume no liability or guarantee for the timeliness, accuracy, and completeness of the provided information. We reserve the right to make changes or additions to the provided information without prior notice. The applicable offer or booking confirmation is binding. We accept no responsibility for the content of external links, despite careful control. The operators of the linked sites are solely responsible for their content.
---
**INFORMATION ON THE PROCESSING OF PERSONAL DATA under EU Regulation No. 679/2016**
This privacy policy explains our practices regarding the collection, use, and disclosure of your data when using our digital services, when you access the services through your devices.
Please read this privacy policy carefully to ensure that you fully understand our practices concerning your data before using our services. If you have read and fully understood this policy and do not agree with our approach, you must cease using our digital assets and services. By using our services, you acknowledge the terms of this privacy policy. Continued use of the services after any updates indicates your agreement to the changes.
In this privacy policy, you will learn:
- What data we collect
- How we collect data
- Why we collect this data
- To whom we disclose the data
- Where the data is stored
- How long the data is retained
- How we protect the data
- How we handle minors
- Updates or changes to the privacy policy
**What Data Do We Collect?**
Here is an overview of the data we may collect:
- Non-identifiable and non-personally identifiable information you provide during registration or which is collected through the use of our services ("non-personal data"). Non-personal data does not allow conclusions about who it was collected from. Non-personal data primarily consists of technical and aggregated usage information.
- Personally identifiable information, i.e., information that can identify you or be reasonably used to identify you ("personal data"). The personal data we collect may include information such as names, email addresses, addresses, phone numbers, IP addresses, and more. If we combine personal and non-personal data, as long as they remain combined, we treat them as personal data.
**How Do We Collect Data?**
Here are the main methods we use to collect data:
- We collect data during your use of our services. By visiting and using our digital assets, we may collect, store, and track session and usage data.
- We collect data you provide directly to us, for example, when you contact us via communication channels (e.g., an email with a comment or feedback).
- We may collect data from third-party sources.
- We collect data you provide when you sign up through third parties like Facebook or Google.
**Why Do We Collect This Data?**
We may use your data for the following purposes:
- To provide and operate our services
- To develop, customize, and improve our services
- To respond to your feedback, requests, and offer support
- To analyze demand and usage patterns
- For internal, statistical, and research purposes
- To improve our data security and fraud prevention
- To investigate violations and enforce our terms and policies, and to comply with applicable law, regulations, and orders from authorities
- To send you updates, news, promotional materials, and other information related to our services. For promotional emails, you can choose whether to continue receiving them. If not, you can simply click the unsubscribe link.
**To Whom Do We Disclose This Data?**
We may disclose your data to our service providers to operate our services (e.g., data hosting services, technical support, etc.).
▪ Recipient
▪ Legal basis
The personal data provided will be transmitted to the single coordinating body of the Guest Pass in order to enable the creation and use of the Guest Pass and to provide the associated services.
In connection with the issue of the Guest Pass, your data will be transmitted to the Mobilitätskonsortium, VAT Nr. 02735170215, which acts as the cardholder and unified coordinating body and assumes the role of autonomous data controller in processing the transferred data. For further information regarding the processing to which the data will be subjected, you can send an email to privacy@moko.bz.it.
The legal basis for processing is Art. 6 (1) (b) of the GDPR.
We may also disclose your data under the following circumstances:
(i) to investigate, uncover, prevent, or act against unlawful activities or misconduct, (ii) to assert or defend our rights, (iii) to protect our rights, property, or personal safety, as well as the safety of our users or the public, (iv) in the event of a change of control of our company or one of our affiliates (e.g., through a merger, acquisition, or sale of assets), (v) to collect, store, and/or manage your data through authorized third parties (e.g., cloud service providers) for business purposes, (vi) to collaborate with third parties to enhance your user experience. For clarification, we may transfer non-personal data to third parties for their use at our discretion.
Please note that our services allow social interactions (e.g., posting content, information, and comments publicly, or chatting with other users). We remind you that any content or data you provide in these areas can be read, collected, and used by others. We advise against posting or sharing information you do not wish to make public. If you upload content or otherwise provide it while using the service, it is done at your own risk. We cannot control the actions of other users or members of the public who have access to your data or content.
---
**Cookies and Similar Technologies**
When you visit or access our services, we authorize third parties to use web beacons, cookies, pixel tags, scripts, and other technologies and analytics services ("tracking technologies"). These tracking technologies enable third parties to automatically collect your data to improve your navigation experience, optimize performance, and offer a customized user experience, as well as for security and fraud prevention purposes.
To learn more, please read our Cookie Policy.
We may also provide advertisements tailored to you on our services and digital assets (including websites and applications using our services). These advertisements may be based on your recent browsing behavior on websites, devices, or browsers.
We use cookies, JavaScript, web beacons (including clear GIFs), HTML5 local storage, and other technologies to deliver these ads to you. We may also engage third-party network advertisers to display targeted ads. External providers of advertising networks, advertisers, sponsors, and/or website traffic measurement services may also use cookies, JavaScript, web beacons, Flash cookies, and other technologies to measure ad effectiveness and tailor content for you.
---
**Where Do We Store Data?**
- **Non-personal Data**: Our companies and trusted partners and service providers are located worldwide. Non-personal data may be stored and processed in various jurisdictions for the purposes outlined in this privacy policy.
- **Personal Data**: Personal data may be maintained, processed, and stored in the United States, Ireland, South Korea, Taiwan, Israel, and other jurisdictions as necessary for the proper provision of our services and/or as required by law.
---
Would