EXCLUSIVE by ACI BLUETEAM

Privacy Notice for the Processing of Personal Data

(in accordance with European Regulation No. 679/2016 and Italian Legislative Decree 196/03 and subsequent amendments)

A. Website Registration

B. Website Travel Booking

A. Website Registration

We inform you that, for the execution of relationships with its users and clients, ACI blueteam S.p.A. collects data relating to them, classified as “personal data” under EU Regulation 2016/679. The law requires that any entity processing personal data must inform the data subject about which data are being processed and about certain key aspects of the processing, which in any case must be carried out lawfully, fairly, and transparently, safeguarding your privacy and rights. Therefore, pursuant to Article 13 of EU Regulation 2016/679, we provide the following information:

Data Controller and Data Protection Officer

The Data Controller of your personal data is ACI blueteam S.p.A., headquartered in Luisago (CO), Via Risorgimento, 70. The Company has appointed a Data Protection Officer (DPO) who supports the Data Controller in applying national and European data protection regulations, cooperates with the supervisory authority, and serves as a point of contact for data subjects. The DPO can be reached at: privacy@blueteamtravel.it.

Nature of Data Processed

We process the following personal data: name, surname, address, country, phone number, email, and security data (e.g., password for account creation), which are necessary to manage contractual relationships with clients and users. We do not process any “special category” data under Article 9 GDPR nor data relating to criminal convictions or offenses under Article 10 GDPR.

Purpose of Processing and Legal Basis

Collected data will be processed for the following purposes:

a) Create an account;

b) Create, maintain, and update user accounts on our platform and authenticate users;

c) Send newsletters, information, and offers regarding travel products and services.

Processing for purposes a) and b) is based on pre-contractual measures requested by the data subject. Processing for purpose c) is based on explicit consent given by the data subject.

Processing Methods and Retention Period

Data are processed using tools and procedures suitable to ensure security and confidentiality, including electronic means. No automated decision-making processes are adopted.

Data will be retained for the duration of the relationship and, subsequently, for legal, administrative, and commercial purposes, up to 10 years, except for longer periods required by judicial authorities or public bodies or to assert our rights.

Transfer of Data Outside the EU

Your data may be communicated and transferred to entities operating outside the European Economic Area, particularly to the United States for cloud services. Transfers will be carried out with adequate safeguards as required by GDPR, including standard contractual clauses (SCCs).

Obligation or Voluntariness of Providing Data and Consequences of Refusal

Providing data that we are legally obliged to know is necessary to provide requested services and comply with legal obligations. Failure to provide such data may make it impossible to establish or continue the relationship.

Communication and Disclosure

Data collected through the website are not “disclosed” to unspecified parties. They are also not communicated to third parties.

Data Subject Rights

t any time, the data subject may exercise their rights, as listed below, in accordance with EU Regulation 679/2016 and applicable national law:

Right of Access: The data subject has the right to obtain confirmation as to whether or not personal data concerning them is being processed, and, if so, to access such personal data. They may request access at any time to the following information: the purposes of the processing, the categories of data processed, the recipients to whom the personal data have been or will be disclosed, the retention period, the existence of rights in their favor, the origin of the data, and the possible existence of automated decision-making processes.

Right to Rectification: The data subject has the right to obtain from the Data Controller the correction of inaccurate personal data concerning them without undue delay. They also have the right to have incomplete personal data completed, including by providing a supplementary statement. In such cases, the Data Controller is obliged to inform each recipient to whom the personal data have been disclosed of any corrections made.

Right to Erasure: The data subject has the right to obtain the deletion of personal data concerning them without undue delay. Additionally, if their data has been made public, the Data Controller will erase it and take reasonable, including technical, measures to inform other controllers processing the data of the data subject’s request to delete any copies of their personal data.

Right to Restriction of Processing: Where appropriate, the data subject may request the restriction of the processing of personal data concerning them and limit its future processing. In such cases, the Data Controller will communicate the restrictions to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.

Right to Object: The data subject has the right to object at any time, for reasons relating to their particular situation, to the processing of personal data concerning them.

Right to Withdraw Consent: In the case of processing based on consent, the data subject may withdraw their consent at any time. However, this does not affect the lawfulness of processing carried out by the Data Controller prior to the withdrawal.

Right to Lodge a Complaint with the Supervisory Authority: If the data subject believes that their data have been processed unlawfully or in violation of data protection rules and principles, they have the right to lodge a complaint with the Supervisory Authority (Italian Data Protection Authority – Garante Privacy) according to the procedures established by the Authority.

B. Website Travel Booking

We inform you that, for the execution of relationships with its users and clients, ACI blueteam S.p.A. collects data relating to them, classified as “personal data” under EU Regulation 2016/679. The law requires that any entity processing personal data must inform the data subject about which data are being processed and certain key elements of the processing, which in any case must be carried out lawfully, fairly, and transparently, safeguarding your privacy and rights. Therefore, pursuant to Article 13 of EU Regulation 2016/679, we provide the following information:

Data Controller and Data Protection Officer

The Data Controller of your personal data is ACI blueteam S.p.A., headquartered in Luisago (CO), Via Risorgimento, 70. The Company has appointed a Data Protection Officer (DPO) who supports the Data Controller in applying national and European data protection regulations, cooperates with the supervisory authority, and serves as a point of contact for data subjects. The DPO can be reached at: privacy@blueteamtravel.it.

Nature of Data Processed

We process the following personal data (including minors’ data): name, surname, address, country, phone, email, date and place of birth, tax code, identity document details, payment data, travel details, special data (e.g., food intolerances), and data regarding travel companions. These are necessary to finalize the booking.

Purpose of Processing and Legal Basis

Data are processed for:

a) Booking the requested travel/service;

b) Sending newsletters, information, and offers on travel products and services.

Processing for purpose a) is necessary for contract execution; processing for purpose b) is based on explicit consent.

Methods of Processing and Retention Periods

The processing of data is carried out using tools and procedures suitable to ensure its security and confidentiality and may be carried out through the use of electronic instruments. No automated decision-making processes are adopted. Data will be processed for the entire duration of the relationship and also thereafter, for the fulfillment of legal obligations and for administrative purposes, and within a limit of 10 years, except for further use at the request of judicial authorities and other public authorities or to assert our rights. For marketing purposes, data will be retained for no more than 24 months from the end of the relationship between the parties, unless the right to withdraw consent is exercised.

Transfer of Data to a Non-EU Country

Your data may also be communicated and transferred to entities operating in countries outside the European Economic Area, in particular the United States for the use of cloud services. In any case, the transfer of your data will be carried out on the basis of appropriate safeguards as required by the GDPR, in particular standard contractual clauses (SCCs).

Obligation or Possibility to Provide Data and Consequences of Possible Refusal

As regards the data that we are required to know in order to provide the services you requested and comply with the obligations set forth by laws, regulations, and EU legislation, or by provisions issued by Authorities legally empowered by law and supervisory and control bodies, failure to provide such data by the user will make it impossible to establish or continue the relationship, to the extent that such data are necessary for its execution. The provision of data for marketing purposes is optional, and their processing, which requires the explicit consent of the data subject given at the time of activation of the requested services and which remains valid until revoked, may be used to improve products and services. Failure to provide such data will not affect the provision of the requested services and/or the contractual relationship.

Communication and Dissemination

Data collected through the website is not “disseminated” by us, this term meaning making it known to indeterminate parties in any way, including by making it available or accessible.

The personal data of the Data Subject may instead be “communicated” by us (meaning made known to one or more specific parties) to:

  • companies providing transport, accommodation, vehicle rental, activities and excursions, insurance services, or companies that mediate such services through online platforms (for example: GDS – Global Distribution System – such as Amadeus, Sabre; OTA – online travel agency; Bed Bank – hotel databases) and which operate as Independent Data Controllers;

  • third-party service providers. We share personal data with third parties in relation to the provision of services and the management of our business (for example, for processing credit card payments, customer support, business analytics, fraud prevention, and compliance services). Such third-party service providers are required to protect the personal data we share with them and may not directly use any personal identifying data except to provide the services for which we have contracted them.

Rights of the Data Subject

At any time, the data subject may exercise their rights, as listed below, in accordance with EU Regulation 679/2016 and applicable national law:

Right of Access: The data subject has the right to obtain confirmation as to whether or not personal data concerning them is being processed, and, if so, to access such personal data. They may request access at any time to the following information: the purposes of the processing, the categories of data processed, the recipients to whom the personal data have been or will be disclosed, the retention period, the existence of rights in their favor, the origin of the data, and the possible existence of automated decision-making processes.

Right to Rectification: The data subject has the right to obtain from the Data Controller the correction of inaccurate personal data concerning them without undue delay. They also have the right to have incomplete personal data completed, including by providing a supplementary statement. In such cases, the Data Controller is obliged to inform each recipient to whom the personal data have been disclosed of any corrections made.

Right to Erasure: The data subject has the right to obtain the deletion of personal data concerning them without undue delay. Additionally, if their data has been made public, the Data Controller will erase it and take reasonable, including technical, measures to inform other controllers processing the data of the data subject’s request to delete any copies of their personal data. The Foundation will take all appropriate technical and organizational measures to ensure no further disturbance.

Right to Restriction of Processing: Where appropriate, the data subject may request the restriction of the processing of personal data concerning them and limit its future processing. In such cases, the Data Controller will communicate the restrictions to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.

Right to Object: The data subject has the right to object at any time, for reasons relating to their particular situation, to the processing of personal data concerning them.

Right to Withdraw Consent: In the case of processing based on consent, the data subject may withdraw their consent at any time. However, this does not affect the lawfulness of processing carried out by the Data Controller prior to the withdrawal.

Right to Lodge a Complaint with the Supervisory Authority: If the data subject believes that their data have been processed unlawfully or in violation of data protection rules and principles, they have the right to lodge a complaint with the Supervisory Authority (Italian Data Protection Authority – Garante Privacy) according to the procedures established by the Authority.

Our Partnerships
We design your journey

Let get carried away to your next experience and start living it with us.

Contact us