Last updated June 2019
1. Who is the controller of your data?
2. What categories of your data do we collect and use?
3. Why and how do we collect your data?
4. Who sees, receives and uses your data and where?
5. How long do we retain your data?
6. What are your data protection rights and how can you exercise them?
7. Contact details of the data controller
8. Contact details of our data protection officer
9. Information about cookies
10. Privacy notice for Facebook
In the same vein, we inform our Users and/or Customers that the Decision of the Commission of 26 July 2000 in accordance with Directive 95/46/CE of the European Parliament and the Council relating to the adequate level of protection for personal data in Switzerland declared that, in Switzerland, the laws guarantee an adequate level of protection in accordance with Directive 95/46/CE.
When you visit the Website and use our services we collect the categories of personal data as follows:
2.1. Personal data provided by you
subscribe to marketing communications
provide information to us when using our Services, downloading our app, including the information entered into our platform and included in your comments, or sent through the social media channels.
- Personal data such as name, surname, email, pictures, photographies, videos, music, voices referred to you and/or to any subject included or represented in your User Submission.- Passenger information, passport details, contact details, payment details (i.e. credit data, billing address, account information), date of birth etc.
- Information about your purchases, including what you booked, when and where you booked it and how you paid for it.
- Special categories of personal data, for example, relevant medical data and any special dietary or disability requests, so information concerning your health or revealing religious, philosophical or sexual orientation that you might voluntary provide us in the course of making a booking by selecting the box "special transportation need" and filling in the empty field or by other means, such as via telephone to our Customer Care Team or through the Live Chat or at any moment when making a booking. We will use the special categories of personal data only as strictly necessary to fulfil your request. Where we need to process this data, we will only do it if we have your explicit consent, in accordance with Art.6.1.a) and Art. 9.2 GDPR or if permitted by regulations.
- When you take part in surveys or questionnaires about our services you may provide us with your contact details, your feedback and contributions to customer surveys and questionnaires.
- When you enter your email address to use our Service you may provide us with your email address.
The provision of the above personal data, where requested, is necessary for the adequate performance of the contract between you and us (User Submission publishing) and to allow us to comply with our legal obligations deriving from this contract except when we rely on consent as legitimate basis for processing and or our legitimate interest. Without it, we may not be able to publish the User Submission. It is important that all the personal data you give us is correct and accurate. This includes, by way of example only, ensuring that we have your correct contact (including email) details at all times.
2.2. Personal data collected automatically from our Website, from communication we send, and/or from third parties
In general terms, we process your personal data to allow you to publish User Submissions. More specifically:
On which legal basis?
A. To create and maintain the contractual relationship established for the provision of the Service in all its phases and by way of any possible integration and modification or to take steps at your request in relation to the contract prior to entering into contract.
To fulfil a contract, or take steps linked to a contract (i.e. To publish the User Submission, to use the Service and/or to provide you with any clarification or assistance to you e.g. via Abuse report form)
B. If permitted by the applicable law, to request your participation in our surveys conducted via email phone, SMS, recorded calls or other similar technologies from time to time, so that you can tell us about your experience as a recipient of the Service. We will use your feedback to develop and improve our services. Following our analyses of your feedback, we may consider it necessary to contact you to provide you with a response to your survey submission. You can inform us at anytime if you no longer want to receive our surveys by writing to firstname.lastname@example.org. Please note that your participation in the survey is voluntary and there is no consequences should you prefer not to participate.
To pursue our legitimate interest (i.e. To manage and improve our products, services and day by day operations):
C. To meet the legal, regulatory and compliance requirements and to respond to requests by government or law enforcement authorities conducting an investigation.
To comply with the law (i.e. to share personal data with regulatory authorities)
D. To carry out aggregative statistical analyses on anonymised groups or to analyse identifiable individuals behaviour so that we can see how our Website, products and services are being used and how our business is performing.
To pursue our legitimate interest (i.e. improving our Website, its features and our products and services)
E. To send you (in cases permitted by law except where you did not object) advertising material via email or, where permitted by the law, other equivalent electronic communication regarding products and services similar to those already purchased by you and offered on our Website. On some occasions, we may send you a personalised and tailored version of the aforementioned advertisement materials.
Soft Opt-in/To pursue our legitimate interest (i.e. marketing)
Where you give your consent (by ticking the appropriate check box)
H. To keep our Website and systems secure and to prevent and detect fraud, security incidents and other crimes.
To pursue our legitimate interest (i.e. ensuring the security of our Website)
I. To verify compliance with our terms and conditions and for the establishment, exercise or defence of legal claims.
To pursue our legitimate interest (i.e. compliance with our terms and conditions, protection of our rights in the event of any dispute or claim)
Where you give your consent (i.e. through the cookie banner or by your browser's settings)
Where we rely on legitimate interest as a basis for processing your personal information, we carry out an assessment to ensure that our interest in the use of your data is legitimate and that your fundamental rights of privacy are not outweighed by our legitimate interests (‘balancing test’). You can find out more information about the balancing test by contacting our Data Protection Officer at to email@example.com.
4.1. Categories of recipients of your data
The complete list of parties to which your personal data may be disclosed is available at our registered office and may be requested by writing to firstname.lastname@example.org.
4.2. International transfer of your data
Users’ and/or Customers’ personal data is processed in at the Data Controller’s registered office (see point 1), on the lm group servers, and at the offices of other entities to which data may be provided in order to provide the services requested of the Data Controller. Given the fact that we are an international travel company, we also transfer your personal data to:
- we disclose your data to autonomous data controllers that might process your data outside the EEA in order to provide you with the requested services.
Should you want to obtain further details about the safeguards put in place, you can contact us by writing to email@example.com.
until the contract between you and us is terminated by you
From the date of the submission
Any other record
DATA USED FOR MARKETING PURPOSES (CRM)
Data used for marketing activities to customers/users subject to the consent or under soft-opt in
From the consent or the renewal of the consent via interaction with marketing communications
DATA COLLECTED VIA TAG
Max 3 years
From the date of browsing on our websites
Max 1 year
From the date of consent
You can exercise the rights provided by the Regulation EU 2016/679 (Articles 15-22), including the right to:
Name of the right
Right of access
To receive confirmation of the existence of your personal data, access its content and obtain a copy.
Right of rectification
To update, rectify and/or correct your personal data.
Right to erasure/right to be forgotten and right to restriction
To request the erasure of your data or restriction of your data which has been processed in violation of the law, including whose storage is not necessary in relation to the purposes for which the data was collected or otherwise processed; where we have made your personal data public, you also have the right to request the erasure of your personal data and to take reasonable steps, including technical measures, to inform other data controllers which are processing the personal data that you have requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
Right to data portability
To receive a copy of your personal data you provided to us for a contract or with your consent in a structured, commonly used and machine-readable format (e.g. data relating to your purchases) and to ask us to transfer that personal data to another data controller.
Right to withdraw your consent
Wherever we rely on your consent (see p. 3 - F and J), you will always be able to withdraw that consent, although we may have other legal grounds for processing your data for other purposes.
Right to object, at any time
You have the right to object at any time to the processing of your personal data in some circumstances (in particular, where we don’t have to process the data to meet a contractual or other legal requirement (see p. 3-B,C,D, H, I), or where we are using your data for direct marketing (p. 3-E).
Right not to be subject to a decision based solely on automated processing, including profiling
You can always request a manual decision-making process instead, express your opinion or contest decision based solely on automated processing, including profiling, if such a decision would produce legal effects or otherwise similarly significantly affect you.
You can exercise the above rights at any time by:
Your rights in relation to your personal data might be limited in some situations. For example, if fulfilling your request would reveal personal data about another person or if we have a legal requirement or a compelling legitimate ground we may continue to process your personal data which you have asked us to delete.
You also may have the right to make a complaint if you feel your personal information has been mishandled. We encourage you to come to us in the first instance but, to the extent that this right applies to you, you are entitled to complain directly to the relevant Data Protection Supervisory Authority.
The contact details of the Data Controller of the data processing described hereinabove are:
BravoNext, S.A., a Swiss company belonging to the lm group, listed in the Ticino business register under no. CHE - 115.704.228 and with registered office at Vicolo de’ Calvi 2 - 6830 Chiasso, Switzerland.
Our Data Protection Officer (or "DPO") is available at: firstname.lastname@example.org Vicolo de’ Calvi 2 - 6830 Chiasso, Switzerland.
9.1 Types of cookies according to the managing entity
Depending on what entity manages the computer or domain from which the cookies are sent and processed, there exist the following types of cookies:
9.2. Types of cookies according to the length of time you stay connected:
Depending on the amount of time you remain active on your Device, these are the following types of cookies:
9.3. Types of cookies according to their purpose
Cookies can be grouped as follows:
a) Technical cookies: these cookies are strictly necessary for the operation of our Website and are essential for browsing and allow the use of various features. Without them, you cannot use the search function, compare tool or book other available services on our Website.
b) Personalisation cookies: these are cookies used to make navigating our Website easier, as well as to remember your selections and offer more personalised services. When you select the use of this we may allow advertisers or other third parties to place cookies on our Website to provide personalised content and services. If cookies are blocked, we cannot guarantee the functioning of such services.
c) Analytical cookies for statistical purposes and measuring traffic: these cookies gather information about your use of our Website, the pages you visit and any errors that may occur during navigation. We also use these cookies to recognise the place of origin for visits to our Website. These cookies do not gather information that may personally identify you. All information is collected in an anonymous manner and is used to improve the functioning of our Website through statistical information. Therefore, these cookies do not contain personal data. In some cases, some of these cookies are managed on our behalf by third parties, but may not be used by them for purposes other than those mentioned above.
To see the list of cookies used on this Website, click here https://www.lastminute.com/info/list-cookies.html. The information contained in the above list of cookies has been provided by the other companies which generate them.
There are a number of ways to manage cookies. By modifying your browser settings, you can opt to disable cookies or receive a notification before accepting them. You can also erase all cookies installed on your browser’s cookie folder. Keep in mind that each browser has a different procedure for managing and configuring cookies. Here’s how you manage cookies in the various major browsers:
11.1. Facebook Custom Audiences - Facebook pixel
We use the remarketing function “Custom Audiences” of Facebook Inc. (1601 Willow Road, Menlo Park, California 94025) or, if you are based in the EU, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. This function allows us to show our Users and/or Customers of our website interest-based ads when they visit Facebook (“Facebook ads”), and to analyze such Facebook ads for statistical and market research purposes, which helps us optimize future advertising. This allows us to serve more relevant advertising.
For this purpose we use the so-called Facebook pixel for our website. When a User or a Customer visits our website and takes an action (for example, buying something), the Facebook pixel is triggered and reports this action. This way, we will know when a customer took action after seeing our Facebook ad. We will also be able to reach this customer again by using a Custom Audience. Therefore, this pixel allows user behavior to be tracked after they have been redirected to our Website by clicking on a Facebook ad. This way, we will know when a customer took action after seeing our Facebook ad. We will also be able to reach this customer again by using a Custom Audience.
Therefore, this enables us to measure the effectiveness of Facebook ads for statistical and market research purposes. The data collected in this way is anonymous to us, i.e. we do not see the personal data of individual users. However, this data is stored and processed by Facebook, which is why we are informing you, based on our knowledge of the situation. Facebook may link this information to your Facebook account and also use it for its own promotional purposes, in accordance with Facebook’s Data Usage Policy https://www.facebook.com/about/privacy. Such data may allow Facebook and its partners to show ads on or off Facebook. A cookie may also be stored on your computer for these purposes.
11.2. Facebook SDK
Within our App, we use the Software Development Kit (SDK) from Facebook. The Facebook SDK is issued and administered by Facebook Inc, 1601 S. California Ave, Palo Alto, CA 94304, USA, or, if you are based in the EU, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. By means of this integration, we can link various Facebook services with our App (i.e. Facebook Analytics, Facebook Ads, Facebook Login via the SDK, Facebook Account Ki, Facebook Share, Facebook Graph API and Facebook App Events). In particular, we have linked the following SDK Facebook services with our App:
Facebook Login: to provide you with the possibility to register or log in with your Facebook account
Facebook App Events: To understand people's actions in our app and measure the effectiveness of your Mobile App Ads. We use this service to evaluate the reach of our advertising campaigns and use of Facebook SDK. Facebook merely provides us with an aggregated analysis of user behavior within our app. In addition, as our App is linked to SDK Facebook services, we have to follow Facebook policies, which include that we are obliged to share with Facebook, when you download the App, even when you are not logged in to the social media platform, the following data:
By downloading our App you declare that you agree with the communication of the data to Facebook as described above. Further information about Facebook SDK within iOS can be found here:https://developers.facebook.com/docs/ios. For Android, please refer to: https://developers.facebook.com/docs/android. You can check and modify the status of your connection to Facebook and the respective access privileges of our Apps at any time under your Facebook profile settings (https://www.facebook.com/settings?tab=applications). If you want to cancel the connection between Facebook and our App, please log in to Facebook and make the necessary changes in your profile settings.