Privacy Policy
(pursuant to Article 13 of EU Regulation 2016/679 – GDPR)
Data Controller
The Data Controller is Funivia al Bernina F.A.B. S.r.l. (the “Data Controller” or “F.A.B.”), with registered office in contrada Vassalini, Chiesa in Valmalenco (SO), Italy, and can be contacted at the following e-mail address: privacy@funiviaalbernina.it.
Types of data processed
As part of the services provided by F.A.B. through the websites
valmalencoskiresort.com
valmalencoskiresort.axess.shop
stayinvalmalenco.com
hotelreziavalmalenco.it
calatrones.com
depending on the specific case, the following personal data may be processed:
personal data and contact details: first name, last name, date and place of birth, residential or domicile address, e-mail address, telephone/mobile number
data for the management of accounts and online services: login credentials, Valmalenco Card number or other cards, data relating to purchased travel tickets/ski passes, purchase history and transactions;
data relating to family members and other ski pass users (including minors, where applicable): first name, last name, date of birth;
data relating to bookings for accommodation and tourist services (arrival/departure dates, selected accommodation facility, number of guests, special requests);
data contained in quotation requests and in messages freely entered by the user in contact forms;
browsing data and data collected through cookies and similar tools, in accordance with the specific cookie policy published on the individual websites.
The provision of data marked as mandatory in the various forms is necessary in order to use the related services. Therefore, failure to provide such data will make it impossible for F.A.B. to deliver the requested service.
Purposes of data processing and legal bases
Personal data will be processed for the following purposes.
3.1 Management of accounts, contracts, and online services (e-commerce services for ski passes, cards, cable car tickets)
Registration and management of user accounts on the e-commerce platforms (including the Valmalenco Card or similar cards) and technical management of the portal;
Online sale of daily and seasonal ski passes, cable car tickets, and other transport/service passes, including the management of related payments, invoicing, and after-sales support;
Management of the purchase of ski passes for third parties (e.g. family members), including minors, and assignment of the purchased passes to the individual users.
Verification of the correct application of any reduced or discounted fares and of the requirements declared by the user, including through random checks and on-site inspections.
Legal basis: performance of a contract or implementation of pre-contractual measures at the request of the data subject (Article 6(1)(b) of the GDPR), compliance with legal obligations (Article 6(1)(c) of the GDPR), and the legitimate interest of the Data Controller in preventing fraud and verifying the accuracy of the declarations provided (Article 6(1)(f) of the GDPR).
3.2 Management of accommodation bookings and tourism services
Management of availability requests and bookings received through the websites stayinvalmalenco.com, hotelreziavalmalenco.it, and other connected platforms (e.g. external booking systems);
Communications with customers regarding their bookings (confirmations, changes, cancellations, and information relating to the stay).
Legal basis: performance of a contract or implementation of pre-contractual measures (Article 6(1)(b) of the GDPR).
3.3 Management of contact requests and quotations
Handling requests for information, quotations, or assistance received through the contact forms on the websites and/or by e-mail, including the operational management of such requests and any subsequent communications.
Legal basis: implementation of pre-contractual measures at the request of the data subject (Article 6(1)(b) of the GDPR) and/or the legitimate interest of the Data Controller in responding to users’ requests (Article 6(1)(f) of the GDPR).
3.4 Sending newsletters and promotional communications (direct marketing)
Subscription to the newsletter and sending by e-mail informational and promotional communications relating to events, offers, services, and initiatives of F.A.B. and its facilities;
Basic, non-profiling analysis of campaign performance (e.g. open and reading rates) solely for the purpose of improving the service.
Legal basis: consent of the data subject (Article 6(1)(a) of the GDPR), freely given through the dedicated forms and revocable at any time by using the unsubscribe link included in each communication or by contacting the Data Controller at the contact details provided.
3.5 Profiling Activities for Marketing Purposes
Analysis of preferences, purchasing habits, and use of services (e.g. type of ski passes purchased, frequency of visits, time of year, type of tourist services booked) for the purpose of sending personalized communications and targeted offers;
Segmentation of users based on relevant criteria (e.g. type of customer, geographical area, frequency of use of the ski facilities, type of stay).
Legal basis: consent of the data subject (Article 6(1)(a) of the GDPR). In the absence of such consent, the user may only receive non-personalized communications (where consent to marketing communications has nevertheless been provided). Consent to profiling may be withdrawn at any time.
Methods of processing
Personal data are processed in accordance with the principles of lawfulness, fairness, transparency, data minimization, and security set out in the GDPR. The data are processed using manual, IT, and telematic tools, according to procedures strictly related to the purposes indicated above and, in any case, in such a way as to ensure the security and confidentiality of the data in compliance with the applicable legislation. Appropriate technical and organizational measures are adopted to prevent data loss, unlawful or improper use, and unauthorized access.
Persons or categories of persons authorized to access the data
Personal data may be processed by employees and collaborators of Funivia al Bernina F.A.B. S.r.l. (duly authorized and instructed pursuant to Article 29 of the GDPR), as well as by third parties providing services to the Data Controller (e.g. e-commerce services, ticketing, newsletter delivery, online booking platforms, IT support, consultants), who may be appointed, where applicable, as Data Processors pursuant to Article 28 of the GDPR. By way of example only, such parties may include:
e-one, for the technical management of newsletter distribution and promotional communications;
Axess AG or other companies within the Axess Group, for the management of the e-commerce platform dedicated to ski passes and cards;
providers of online booking systems (e.g. Bedzzle, Booking Expert, and other similar providers), for the management of hotel and hospitality bookings.
The personal data processed will not be disclosed to the public.
Transfers of data to non-EU countries
The processing of personal data takes place within the European Economic Area (EEA). Should it become necessary to transfer data to a country outside the EEA, such transfer will be carried out in compliance with Articles 44 et seq. of the GDPR, on the basis of an adequacy decision issued by the European Commission or, in the absence thereof, through the adoption of appropriate safeguards (such as, for example, standard contractual clauses for data transfers) and by implementing adequate protection measures.
Data retention period
Data will be retained for the period strictly necessary to achieve the purposes for which it was collected and, in particular:
e-commerce data and data relating to bookings and stays: for the duration of the contractual relationship and, subsequently, for the period required under civil and tax law (generally 10 years for accounting and tax documentation)
data collected for the management of contact requests and quotations: for the time necessary to process the request and for a maximum period of 24 months from the closure of the request, unless further contractual relationships are established;
data processed for analysis or profiling purposes: for a maximum period of 24 months, without prejudice to the possibility of subsequently retaining aggregated or anonymized data;
data used for sending newsletters and promotional communications: until consent is withdrawn or a request for removal from the mailing list is received and, in any case, for no longer than 24 months from the user’s last interaction (e.g. opening an e-mail or making a purchase).
Rights of data subjects
Each data subject may exercise their rights concerning their personal data, within the limits set out in Articles 15 to 22 of the GDPR. In particular, the data subject has the right to:
request from the Data Controller access to, rectification, completion, erasure, or restriction of the processing of personal data concerning them;
object to the processing of personal data;
request data portability, namely, to receive the personal data concerning them in a structured and commonly used format and, where technically feasible, to have such data transmitted to another Data Controller;
lodge a complaint with the competent supervisory authority (for example, in the Member State where the data subject habitually resides, works, or where the alleged infringement occurred);
withdraw consent to the processing of personal data, without affecting the lawfulness of processing based on consent given prior to its withdrawal.
Requests may be submitted to the Data Controller by e-mail at privacy@funiviaalbernina.it.
Amendments to this Privacy Policy
The Data Controller reserves the right to update this Privacy Policy at any time, also in consideration of regulatory changes or updates to the services provided. Any changes will be communicated through publication on the above-mentioned websites; the updated Privacy Policy shall become effective as of the date of publication.