Last updated September 2023
We recognise the importance of protecting your privacy and your rights with regards to data protection. The Internet is a very powerful medium when it comes to transmitting personal information; for that reason, we and all other companies belonging to the lastminute.com group (“lm group”) undertake the serious task of respecting the current laws regarding the protection of personal data and the security of the same, with the aim of guaranteeing secure, controlled and confidential navigation for its users and customers who visit and/or use the Website and/or use our Comparison Service (you as a "User") or then purchase or register on our services, download our app and/or give us their consent for a specific purpose (you as a "Customer").
1. Who is the controller of your data? 2. What categories of your data do we collect and use? 3. Why and how do we collect your data? 4. Who sees, receives and uses your data and where? 5. How long do we retain your data? 6. What are your data protection rights and how can you exercise them? 7. Contact details of the data controller 8. Contact details of our data protection officer 9. Information about cookies
It also informs you of how you can exercise Your Rights (including the right to object to some of the data handling we carry out). More information about your rights and how you can exercise them is set out in the section below.
1. Who is the controller of your personal data?
In addition to the above, we inform you that, in accordance with Article 27 of the UK General Data Protection Regulation (UK GDPR), Bravonext has designated as its UK representative LMnext services (UK) Ltd, an English company belonging to the lm group, VAT identification no. UK 205 7906 10 and with its registered office at Clerks Court, Ground Floor, 18-20 Farringdon Lane, London, EC1R 3AH, United Kingdom.
We, being an entity located in Switzerland, are subject to Swiss law regarding the protection of personal data. For that reason, we undertake to comply with the obligations imposed by the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Swiss Federal Act on Data Protection of 25.09.2020 (FADP). In the same vein, we inform our Users and/or Customers that the Decision of the Commission of 26 July 2000 in accordance with Directive 95/46/CE of the European Parliament and the Council relating to the adequate level of protection for personal data in Switzerland declared that, in Switzerland, the laws guarantee an adequate level of protection in accordance with Directive 95/46/CE.
2. What categories of your data do we collect and use?
When you visit the Website and use our Comparison Service (you as a "User") or then purchase or register to our services (you as a "Customer") we collect the categories of personal data as follows:
2.1. Personal data provided by you
The personal data that you share with us including when you register for an account, subscribe to marketing communications and which you provide to us when using our services, downloading our app, including the information entered into our booking platform and included in your comments, reviews or messages sent via telephone to our Customer Care Team, or through the Live Chat or through social media channels.
When you subscribe to the personalised marketing services, you may provide us with: Your personal details (email address), information about when you click on our adverts, the way you access the website, including IP address, online identifiers and browsers details. You may also provide us with your browsing behaviour or your personal interests. Please note that some of this information might be collected automatically in accordance with p. 2.2.
The provision of the above personal data, where requested, is necessary for the adequate performance of the requested service and to allow us to comply with our legal obligations except when we rely on consent as legitimate basis for processing and or our legitimate interest. Without it, we may not be able to provide you with all the requested services.
It is important that all the personal data you give us is correct and accurate. This includes, by way of example only, ensuring that we have your correct contact (including email) details at all times.
2.2. Personal data collected automatically from our Website, from communication we send, and/or from third parties
We collect information about your visits to and use of the Website, such as information about the device and browser you are using, your IP address or domain names of the computers connected to the Websites, uniform resource identifiers for requests made, the time of request, the method used to submit the request to the server, the size of the archive obtained as a response, the numerical code indicating the status of the response given by the server (correct, error, etc.) and other parameters relative to the operating system and the computer environment used, the date and time that you visited, the duration of your visit, the referral source and website navigation paths of your visit and your interactions on the Website including the Services and offers you are interested in. Please note that we may associate this information with your account.
We may use this style to also understand how you engage with communication material that we send to you, such as emails, including the action you take such as any links in them that you click on, your duration and frequency of your engagement with the email.
To the extent permitted by the applicable law wherein we receive additional information about you, such as fraud detection information and warnings from third party service providers and/or partners for our fraud prevention activities.
3. Why do we collect your data?
In general terms, we use your personal data to provide you with the services you request, send you marketing and promotional communications, notify you about important changes to our Website and to deliver our content and ads which we think may be of interest to you. More specifically:
C. To meet the legal, regulatory and compliance requirements and to respond to requests by government or law enforcement authorities conducting an investigation.
On which legal basis?
To comply with the law (i.e. to share personal data with regulatory authorities)
D. To carry out aggregative statistical analyses on anonymised groups or to analyse identifiable individuals behaviour so that we can see how our Website, products and services are being used and how our business is performing.
On which legal basis?
To pursue our legitimate interest (i.e. improving our Website, its features and our products and services)
F. To send you personalised and profiled marketing communications
Only with your prior explicit consent, to share with you via email and/or on our website or third party ones (e.g. using ads) the best deals and offers on products and services we think you might find interesting. If you have already given us your consent to profiling activities through marketing cookies or other means, we may send personalised communications. The personalised service or the offers can be related to the following sectors (please note that we do not share your email address with third parties): tourism, leisure, entertainment, high technology, fashion, decoration, consumer goods, food and beverage, finance, banking, insurance, energy, environment, communication, mass media, real estate, pharmaceuticals, clothing and textiles, education and training, energy, publications and publishing, information and communications technology, retail, sport, telecommunications and general services.
For this purpose we may:
- analyse your personal information to create a profile of your interests and preferences so that we can tailor and target our communications in a way that is timely and relevant to you.
- combine the information you give us via cookies and other tracking technologies with information related to your purchases.
- analyse information about the way you engage with communication material you receive from us, such as data on when emails have been opened or to determine if you have viewed or interacted with an ad, to record the number of times you have viewed each ad, to prevent a single ad being shown to you too frequently etc.
- temporarily share an encrypted version of your email address, with carefully selected partners who may combine this information with other forms of online identifiers or other personal data in order to present you with our offers cross device or cross channel, for example on social networks (Facebook, Pinterest, Instagram, Twitter).
On which legal basis?
Where you give your consent (by ticking the appropriate checkbox or by inserting your email address into the proper field to receive personalised communications about us and our selected third parties).
H. To keep our Website and systems secure and to prevent and detect fraud, security incidents and other crime.
On which legal basis?
To pursue our legitimate interest (i.e. ensuring the security of our Website)
I. To verify compliance with our terms and conditions and for the establishment, exercise or defence of legal claims.
On which legal basis?
To pursue our legitimate interest (i.e. compliance with our terms and conditions, protection of our rights in the event of any dispute or claim)
On which legal basis?
Where you give your consent (i.e. through the cookie banner or by your browser's settings)
Where we rely on legitimate interest as a basis for processing your personal information, we carry out an assessment to ensure that our interest in the use of your data is legitimate and that your fundamental rights of privacy are not outweighed by our legitimate interests (‘balancing test’). You can find out more information about the balancing test by contacting our Data Protection Officer at to email@example.com .
4. Who sees, receives and uses your data and where?
4.1. Categories of recipients of your data
Our authorised employees and/or collaborators that assist and advise us on administration, products, legal affairs, and information systems, as well as those in charge of maintaining our network and hardware/software equipment;
Our third-party service providers (including other entities of the lmastminute.com group), which process your personal data on our behalf and under our instructions for the purposes described hereinabove acting as data processors, such as those providing us with IT and hosting services and customer support, analytics and administration services etc.
Competent authorities when we are required to do so by the current law.
Third parties that receive the data (e.g. business consultants, professionals for delivering due diligence services or assess value and capabilities of the business) when it is necessary in connection with any sale of our business or its assets (in which case your details will be disclosed to our advisers and any prospective purchaser’s advisers and will be passed to the new owners.
The complete list of parties to which your personal data may be disclosed is available at our registered office and may be requested by writing to firstname.lastname@example.org.
4.2. International transfer of your data
Users’ and/or Customers’ personal data is processed in at the Data Controller’s registered office (see point 1), on the lm group servers, and at the offices of other entities to which data may be provided in order to provide the services requested of the Data Controller.
Given the fact that we are an international travel company, we also transfer your personal data to:
European Economic Area (EEA) countries and non-EEA countries offering an adequate level of data protection in accordance with the “Adequacy decisions” of the EU Commission that recognises some countries as providing adequate protection and/or the equivalent Swiss adequacy finding;
non-European Economic Area countries where data protection laws may be less protective than the legislation in the EEA or in Switzerland. This happens when:
we disclose your data to autonomous data controllers such as airlines, hotels, car hire companies, tour operators etc. that might process your data outside the EEA in order to provide you with the requested services. Such recipients may be located in any country worldwide, depending on the services requested. Such transfers are generally performed in connection with the conclusion or performance of a contract in your interest.
Should you want to obtain further details about the safeguards put in place, you can contact us by writing to email@example.com.
5. How long do we retain your data?
DATA USED FOR MARKETING PURPOSES (CRM)
Data used for marketing activities to customers/users subject to the consent.
Retention period: 5 years from the consent or the renewal of the consent via interaction with marketing communications
DATA COLLECTED VIA TAG
Retention period: Max 3 years from the date of browsing on our websites
Retention period: Max 1 year from the date of consent
6. What are your data protection rights and how can you exercise them?
You can exercise the rights provided by the Regulation EU 2016/679 (Articles 15-22), including the right to:
Right of access - To receive confirmation of the existence of your personal data, access its content and obtain a copy.
Right of rectification - To update, rectify and/or correct your personal data.
Right to erasure/right to be forgotten and right to restriction - To request the erasure of your data or restriction of your data which has been processed in violation of the law, including whose storage is not necessary in relation to the purposes for which the data was collected or otherwise processed; where we have made your personal data public, you have also the right to request the erasure of your personal data and to take reasonable steps, including technical measures, to inform other data controllers which are processing the personal data that you have requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
Right to data portability - To receive a copy of your personal data you provided to us for a contract or with your consent in a structured, commonly used and machine-readable format (e.g. data relating to your purchases) and to ask us to transfer that personal data to another data controller.
Right to withdraw your consent - Wherever we rely on your consent, you will always be able to withdraw that consent, although we may have other legal grounds for processing your data for other purposes.
Right to object, at any time - You have the right to object at any time to the processing of your personal data in some circumstances (in particular, where we don’t have to process the data to meet a contractual or other legal requirement , or where we are using your data for direct marketing.
Right not to be subject to a decision based solely on automated processing, including profiling - You can always request a manual decision- making process instead, express your opinion or contest decision based solely on automated processing, including profiling, if such a decision would produce legal effects or otherwise similarly significantly affect you.
You can exercise the above rights at any time by:
Contacting us via email at firstname.lastname@example.org.
As for direct marketing, please note that you can also object at any time by clicking the unsubscribe link which we provide in each communication sent to you
In case you exercise any of the above rights provided by GDPR, please note that we will attend your request considering the personal information held by all the companies within the lm group where BravoNext, S.A. holds, directly or indirectly, 100% of the shares.
Your rights in relation to your personal data might be limited in some situations. For example, if fulfilling your request would reveal personal data about another person or if we have a legal requirement or a compelling legitimate ground we may continue to process your personal data which you have asked us to delete.
You also may have the right to make a complaint if you feel your personal information has been mishandled. We encourage you to come to us in the first instance but, to the extent that this right applies to you, you are entitled to complain directly to the relevant Data Protection Supervisory Authority.
7. Contact details of the data controller
The contact details of the Data Controller of the data processing described hereinabove are:
BravoNext, S.A., a Swiss company belonging to the lm group, listed in the Ticino business register under no. CHE - 115.704.228 and with registered office at Vicolo de’ Calvi 2 - 6830 Chiasso, Switzerland.
8. Contact details of our data protection officer (DPO)
Our Data Protection Officer (or "DPO") is available at:
Vicolo de’ Calvi 2 - 6830 Chiasso, Switzerland.
9. Information about cookies
10. Privacy notice for Facebook
10.1. Facebook Custom Audiences - Facebook pixel We use the remarketing function “Custom Audiences” of Facebook Inc. (1601 Willow Road, Menlo Park, California 94025) or, if you are based in the EU, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. This function allows us to show our Users and/or Customers of our website interest-based ads when they visit Facebook (“Facebook ads”), and to analyze such Facebook ads for statistical and market research purposes, which helps us optimize future advertising. This allows us to serve more relevant advertising.
For this purpose we use the so-called Facebook pixel for our website.
When a User or a Customer visits our website and takes an action (for example, buying something), the Facebook pixel is triggered and reports this action. This way, we will know when a customer took an action after seeing our Facebook ad. We will also be able to reach this customer again by using a Custom Audience. Therefore, this pixel allows user behavior to be tracked after they have been redirected to our Website by clicking on a Facebook ad. This way, we will know when a customer took an action after seeing our Facebook ad. We will also be able to reach this customer again by using a Custom Audience.
Therefore, this enables us to measure the effectiveness of Facebook ads for statistical and market research purposes. The data collected in this way is anonymous to us, i.e. we do not see the personal data of individual users. However, this data is stored and processed by Facebook, which is why we are informing you, based on our knowledge of the situation. Facebook may link this information to your Facebook account and also use it for its own promotional purposes, in accordance with Facebook’s Data Usage Policy https://www.facebook.com/about/privacy. Such data may allow Facebook and its partners to show ads on or off Facebook. A cookie may also be stored on your computer for these purposes.