Information on the processing of personal data pursuant to articles 13 and 14 of Regulation (EU) 2016/679
This Privacy Policy describes how the personal data of users who visit www.guestside.it and use the related services, create an account, request information or quotations, subscribe to the newsletter or make purchases through the GuestSide online store are processed.
This Privacy Policy applies to the GuestSide website and to services managed directly by the Data Controller.
Any third-party sites, platforms or services accessible via external links are governed by their respective information on the protection of personal data.
1. Data Controller
The Data Controller is:
J.F. Amonn S.r.l. – J.F. Amonn G.m.b.H.
Registered office: Via Sebastian Altmann, 12 – 39100 Bolzano (BZ), Italy
VAT no./Tax code: 01373880218
REA: BZ-117206
GuestSide is the brand used to manage the online shop.
For information relating to the processing of personal data or to exercise your rights, you can contact the Data Controller at the following contact details:
E-mail: info@guestside.it
Telephone: +39 045 6083311
If the Data Controller appoints a Data Protection Officer (DPO), the relevant contact details will be published in this Privacy Policy.
2. Data subjects covered by this policy
This information concerns:
- visitors and users of the site;
- customers and potential customers;
- registered users;
- subscribers to the newsletter;
- people requesting information, assistance or quotes;
- professional customers;
- owners, representatives, employees and contact persons of companies, accommodation facilities, commercial activities and other professional subjects who interact with GuestSide.
Information referring exclusively to legal persons does not constitute personal data. However, data protection legislation continues to apply to data relating to natural persons acting on behalf of companies, bodies or other organisations.
3. Categories of data processed
Depending on how the site is used and the services requested, the following categories of data may be processed.
3.1. Navigation data and technical data
The IT systems used to operate the site can automatically acquire information such as:
- IP address;
- date and time of the request;
- addresses of requested resources;
- browser information;
- operating system;
- device type;
- technical identifiers;
- session data;
- information on the functioning and security of the site;
- data relating to errors, malfunctions or unauthorized access attempts.
Such data is processed to allow the functioning of the site, guarantee the security of the systems, prevent abuse and fraud, diagnose technical problems and fulfill any requests from the competent authorities.
3.2. Contact data and requests for information
When the user contacts GuestSide by e-mail, telephone, contact forms or other channels, the following may be processed:
- name and surname;
- company name;
- e-mail address;
- telephone number;
- content of the request;
- any documents or information voluntarily communicated.
3.3. Customer account data
In case of registration or activation of an account, the following may be processed:
- name and surname;
- e-mail address;
- telephone number;
- saved addresses;
- company or professional activity data;
- information relating to access and management of the account;
- order history;
- preferences associated with the profile.
Credentials and authentication systems may be managed through the Shopify platform.
3.4. Data relating to orders
For the management of purchases the following may be processed:
- name and surname;
- company name;
- billing address;
- delivery address;
- e-mail address;
- telephone number;
- products ordered;
- quantity;
- prices;
- discounts;
- shipping data;
- order status;
- return requests;
- withdrawal requests;
- complaints;
- assistance requests;
- information relating to warranty.
3.5. Fiscal and professional data
When necessary for the issuing of tax documents, for the management of professional relationships or for the application of correct VAT treatment, the following may be processed:
- company name;
- seat of business;
- VAT number;
- Tax code;
- recipient code;
- certified email address, where communicated;
- Country of establishment;
- type of activity;
- information necessary for qualification of the Customer;
- result of tax audits;
- data necessary for invoicing and administrative obligations.
For Professional Customers, information relating to the commercial category, account activation and assigned price list may also be processed.
3.6. Payment data
GuestSide does not directly acquire complete payment card data when such information is entered into the environments managed by payment service providers.
GuestSide may receive and process:
- selected payment method;
- identifier of the transaction;
- payment status;
- authorization outcome;
- amount;
- currency;
- transaction date;
- any information necessary to manage refunds, disputes or anti-fraud checks.
The complete data of the payment instruments are processed by the relevant providers according to their own information and conditions.
3.7. Data relating to the newsletter and marketing
In case of subscription to the newsletter, the following may be processed:
- e-mail address;
- name, where requested;
- language;
- date and method of acquisition of the consent;
- expressed preferences;
- information relating to registration and unsubscription;
- technical data necessary to demonstrate the acquisition of consent.
Where permitted by law and by the system used, information relating to interactions with communications may also be processed, such as delivery, opening or link selection.
3.8. Cookies and similar technologies
The site uses cookies and other technical tools necessary for its operation.
With the user's consent, measurement, analysis, personalization or marketing tools may also be used.
Detailed information on the tools used, providers, purposes and retention periods is available in the Cookie Policy and in the “Cookie Preferences” panel.
4. Origin of the data
Personal data may be collected:
- directly from the data subject;
- during navigation and use of the site;
- through the creation of the account;
- during checkout;
- through requests for information or quotes;
- through e-mail or telephone communications;
- through the newsletter;
- through payment service providers;
- through carriers and logistics operators;
- through platforms and applications used for store management;
- through registers, databases or official services used for tax or professional checks.
As part of the verification of intra-community VAT numbers, the Data Controller can acquire the outcome of the checks carried out through the VIES system or other officially available tools.
5. Purposes and legal bases of the processing
5.1. Operation, security and maintenance of the site
The technical and navigation data are processed to:
- allow access and use of the site;
- ensure the correct functioning of the services;
- maintain the security of the systems;
- prevent unauthorized access, abuse and fraudulent activities;
- diagnose and resolve technical problems;
- ensure operational continuity.
The legal basis is the Data Controller's legitimate interest in the secure and efficient management of the website and, where applicable, compliance with legal security obligations.
5.2. Management of requests for information and quotes
The data is processed to:
- respond to requests;
- provide assistance;
- prepare quotes;
- provide the commercial information requested by the data subject;
- carry out activities preliminary to the conclusion of a contract.
The legal basis is the implementation of pre-contractual measures at the request of the data subject.
When the request is not linked to a possible contractual relationship, the processing may be based on the legitimate interest of the Data Controller in managing communications received.
5.3. Creation and management of the account
The data is processed to:
- create and manage the account;
- allow access to reserved services;
- store the information associated with the profile;
- show the history of orders;
- manage any price lists or commercial conditions assigned.
The legal basis is the performance of the contract or pre-contractual measures requested by the data subject.
5.4. Management of orders and the contractual relationship
The data is processed for:
- receive and verify orders;
- manage availability and preparation of products;
- manage payment;
- organise delivery;
- communicate information relating to the order;
- provide after-sales assistance;
- manage returns, withdrawals, refunds, complaints and guarantees;
- fulfil contractual obligations.
The legal basis is the performance of the contract and the implementation of pre-contractual measures requested by the data subject.
5.5. Administrative, accounting and tax obligations
The data is processed to:
- issue and store tax documents;
- carry out accounting records;
- fulfill tax obligations;
- manage payments, refunds and reconciliations;
- respond to requests from the competent authorities.
The legal basis is the fulfillment of legal obligations to which the Data Controller is subject.
5.6. Management of Professional Clients, price lists and VIES checks
The data is processed to:
- verify company data;
- evaluate the requirements for access to professional conditions or price lists;
- assign the Customer to the relevant commercial category;
- verify the validity of the VAT number;
- determine the applicable tax treatment;
- manage any exemptions or tax regimes provided for by the legislation;
- prevent improper use of professional conditions.
The legal basis is the execution of pre-contractual measures, the execution of the contract, the fulfillment of legal obligations and the legitimate interest of the Data Controller in the correct commercial and fiscal management of the relationship.
5.7. Prevention of fraud and protection of rights
The data may be processed to:
- verify anomalous operations;
- prevent fraud and illicit use;
- protect company assets;
- ascertain, exercise or defend rights in judicial or extrajudicial proceedings;
- manage disputes and debt collection.
The legal basis is the legitimate interest of the Data Controller in the prevention of fraud and the protection of its rights.
5.8. Newsletters and promotional communications based on consent
The e-mail address and any additional data provided are processed to send:
- newsletters;
- product updates;
- offers;
- promotions;
- commercial communications;
- information relating to GuestSide activities.
The legal basis is the consent of the data subject.
Consent is optional and can be revoked at any time via the unsubscribe link present in communications or by contacting the Data Controller.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
5.9. Communications relating to similar products - soft spam
Within the limits permitted by law, the Data Controller may use the e-mail address provided by the Customer in connection with a completed sale to send communications concerning products or services similar to those purchased.
Such use occurs without new consent exclusively when all the requirements established by law are met.
The Customer may refuse such use when the address is collected and may object free of charge at any time through the link in each communication or by contacting the Data Controller.
The e-mail address is not used based on this exception to promote products or services of third parties.
5.10. Statistics, analytics and online marketing tools
With the user's consent, when requested, the site may use tools such as Google Analytics, Google Tag Manager or similar technologies to:
- measure the use of the site;
- process statistics;
- evaluate the performance of the pages;
- understand the effectiveness of commercial initiatives;
- improve the browsing experience;
- carry out personalization or marketing activities, when required.
The legal basis is the user's consent, collected through the preference management system.
Consent can be modified or revoked at any time via the “Cookie Preferences” link.
Detailed information is available in the Cookie Policy.
6. Mandatory or optional nature of the provision
The provision of the data necessary to:
- manage an order;
- make a payment;
- organise the delivery;
- issue tax documents;
- fulfill contractual and legal obligations;
is required.
Failure to provide it may prevent the creation of the account, the preparation of a quote, the conclusion of the contract or the execution of the order.
Unnecessary data is optional.
Consent to the newsletter, marketing and unnecessary tracking tools is optional and refusal does not prevent you from browsing the essential features of the site or making purchases.
7. Processing methods and security
Personal data are processed using electronic, IT and, when necessary, paper tools.
The processing is carried out in compliance with the principles of:
- lawfulness;
- correctness;
- transparency;
- purpose limitation;
- data minimization;
- accuracy;
- storage limitation;
- integrity;
- confidentiality.
The Data Controller adopts technical and organizational measures appropriate to the risk to protect the data from:
- loss;
- destruction;
- unauthorised alteration;
- unauthorized access;
- illicit disclosure;
- use not compliant with the declared purposes.
Access to the data is limited to authorized personnel and subjects who need the information to carry out the entrusted activities.
8. Recipients of personal data
Personal data may be communicated, within the limits necessary for the respective activities, to the following categories of recipients:
- authorized personnel of the Data Controller;
- group companies or connected parties, when necessary and in compliance with the law;
- suppliers of the e-commerce platform;
- hosting, cloud infrastructure and IT services providers;
- developers and technical support providers;
- providers of PIM, ERP, management and administrative systems;
- providers of email and newsletter services;
- payment service providers;
- banks and financial institutions;
- couriers, freight forwarders and logistics operators;
- customer support service providers;
- administrative, tax, accounting and legal consultants;
- auditing companies;
- debt collection companies;
- insurance companies;
- providers of fraud prevention services;
- providers of analysis and measurement services, subject to consent when necessary;
- public authorities, financial administrations, control bodies and other subjects to whom communication is required by law.
Suppliers can operate:
- as data processors, on the basis of an agreement pursuant to Article 28 of the GDPR;
- as independent data controllers, when they independently determine the purposes and methods of the processing within their competence.
Personal data are not made publicly available unless the data subject has expressly authorised disclosure or disclosure is required by law.
An up-to-date list of data processors may be requested by contacting the Data Controller.
9. Shopify and e-commerce platform
The GuestSide online store uses the Shopify platform.
For services relating to the management and operation of the store, Shopify generally processes customers' personal data on behalf of the Data Controller and in accordance with the applicable agreements.
The reference contractual entity for European merchants is:
Shopify International Limited
Dublin, Ireland
Shopify may use companies belonging to its group and additional authorized suppliers.
For certain services used directly by the user, such as Shop, Shop Pay or other consumer-facing features, Shopify may process data for its own purposes as an independent data controller.
If advanced features are enabled that involve further processing by Shopify, the site makes available the information and choice tools required by applicable law.
The use of Shopify services may involve processing data in countries other than the data subject's country of residence, as described in the section on international transfers.
10. Payment service providers
GuestSide may use the following providers:
- Nexi XPay;
- PayPal;
- banking institutions for payments by bank transfer;
- any additional tools indicated in the checkout.
Payment providers process the data necessary for:
- authorisation;
- execution of the transaction;
- fraud prevention;
- the management of refunds and disputes;
- compliance with their legal obligations.
For activities determined independently, these subjects operate as independent data controllers and apply their own information.
GuestSide receives only the data relating to the transaction necessary to manage the order and does not receive the complete card data when the payment is managed in the environment of the relevant provider.
11. Management systems, PIM, ERP and tax data verification
Data relating to customers, products, orders, invoicing and logistics may be transmitted to the management, PIM and ERP systems used by the Data Controller.
These systems are used to:
- synchronize information;
- manage catalog and price lists;
- process orders;
- manage the warehouse;
- prepare administrative and fiscal documents;
- manage invoicing;
- verify professional data;
- apply the correct commercial and fiscal treatment.
The data relating to the VAT number can be subjected to verification through VIES or other official services required by law.
12. Data transfers to countries outside the European Economic Area
The use of Shopify and certain technology providers may involve the processing or transfer of personal data to countries outside the European Economic Area.
Shopify International Limited may transfer data to group companies, including Shopify Inc. in Canada, as well as to providers located in other countries.
Transfers are carried out using, as appropriate:
- adequacy decisions adopted by the European Commission;
- standard contractual clauses approved by the European Commission;
- data protection agreements;
- supplementary technical and organisational measures;
- other mechanisms provided for by Articles 44 et seq. of the GDPR.
Other suppliers used by the Data Controller can also carry out international transfers in compliance with the conditions established by the law.
The data subject may request further information on transfers and the safeguards applied by contacting the Data Controller.
13. Retention periods
The data are stored exclusively for the time necessary for the purposes for which they were collected, without prejudice to any legal obligations or needs for the protection of rights.
In particular:
Navigation and security data
The technical data are stored for the period necessary for operation, safety, diagnosis of problems and prevention of abuse.
In the presence of accidents, anomalies or the need for investigation, the data may be retained for longer for the time necessary to manage the event or protect rights.
Requests for information and quotes
The data are retained for the time necessary to manage the request and any subsequent activities.
In the absence of the conclusion of a contract, the data is normally deleted or anonymized within 24 months of the last communication, unless necessary to protect rights or legal obligations.
Customer account
The data relating to the account are retained for the duration of the activation and use of the profile.
In the event of account closure, data that is no longer necessary is deleted or anonymized compatibly with the technical times of the systems.
The information necessary for the fulfillment of legal obligations, the management of orders already placed and the protection of rights remains retained.
Orders, invoicing and administrative data
The data relating to orders, accounting and tax documents and administrative obligations are kept for the period established by applicable legislation and, as a rule, for at least 10 years from the relevant registration, except for longer periods required by proceedings, controls, disputes or protection needs.
Newsletter
The data are processed until consent is withdrawn or the user unsubscribes.
In the absence of interactions or renewal of consent, data used exclusively for the newsletter are reviewed periodically and, as a rule, deleted or deactivated within 48 months of collection or the most recent renewal of consent.
The data necessary to demonstrate the acquisition or revocation of consent may be retained for the period necessary to protect the Data Controller and fulfill the obligations of responsibility.
Soft spam
The use of the e-mail address for communications concerning similar products or services continues until the data subject objects and is, in any event, subject to periodic review.
As a rule, such use does not continue beyond 36 months from the last purchase, unless a new purchase or other circumstance justifies the renewal of the period in compliance with the law.
Cookies and tracking tools
The retention times are indicated in the Cookie Policy and in the "Cookie Preferences" panel.
Litigation and protection of rights
The data necessary for the management of complaints, disputes, proceedings or disputes may be retained until conclusion of the relevant activity and for the subsequent period foreseen by the applicable limitation periods.
Upon expiry of the foreseen periods, the data are deleted, anonymized or stored exclusively when there is a further legal basis.
14. Automated decision-making processes and profiling
The Data Controller does not make decisions based solely on automated processing that produce legal effects concerning the data subject or similarly significantly affect them.
Automated tools can be used to support:
- anti-fraud checks;
- transaction analysis;
- security;
- VAT number verification;
- the assignment or verification of professional conditions;
- the technical management of orders.
When an automated check leads to a report, the Data Controller may carry out further checks before adopting a decision.
Payment providers may use automated fraud prevention and transaction evaluation systems according to their own information.
Any commercial or advertising profiling activities based on cookies or similar technologies are carried out exclusively when there is a valid legal basis and, when required, with the user's prior consent.
15. Rights of the data subject
In the cases and within the limits established by law, the data subject may exercise the following rights:
- obtain confirmation of the existence or otherwise of personal data concerning him/her;
- obtain access to the data and information relating to the processing;
- obtain a copy of personal data;
- request rectification of inaccurate data;
- request integration of incomplete data;
- request deletion of data;
- request limitation of processing;
- oppose processing based on legitimate interest;
- oppose direct marketing at any time;
- receive data in a structured format, commonly used and readable by an automatic device, when the conditions for portability are met;
- request the transmission of data to another data controller, when technically possible;
- revoke consent at any time;
- not be subjected to a decision based exclusively on automated processing in the cases provided for by law;
- lodge a complaint with the competent supervisory authority;
- bring legal proceedings.
The revocation of consent does not affect the lawfulness of the processing carried out before the revocation.
16. Exercise of rights
Requests can be sent to:
J.F. Amonn S.r.l. – J.F. Amonn G.m.b.H.
Via Sebastian Altmann, 12
39100 Bolzano (BZ)
Italy
E-mail: info@guestside.it
The Data Controller may request information reasonably necessary to verify the identity of the applicant and prevent the communication of the data to unauthorized parties.
Requests are handled within the terms established by law.
The exercise of rights is generally free. In the cases provided for by the GDPR, in the presence of manifestly unfounded or excessive requests, the Data Controller may request a reasonable expense contribution or refuse the request, providing the relevant reason.
17. Complaint to the supervisory authority
The data subject has the right to lodge a complaint with:
Garante per la protezione dei dati personali
using the contact details and procedures available on the official website of the Authority.
The data subject may also contact the supervisory authority of the European Union country in which they habitually reside, work or believe that an infringement has occurred.
The right to lodge a complaint does not limit the possibility of exercising other administrative or judicial remedies.
18. Changes to this Privacy Policy
This Privacy Policy may be updated due to:
- regulatory adjustments;
- changes to services;
- introduction of new features;
- changes in suppliers used;
- changes in the processing methods.
The updated version is published on the site.
In the event of significant changes, the Data Controller may inform data subjects through notices on the website, e-mail communications or other appropriate means.