PRIVACY POLICY

Information notice pursuant to and for the purposes of Articles 13/14 Regulation (EU) 2016/679 (GDPR)

DATA CONTROLLER

WeRoad S.r.l., a company part of the OneDay Group, which has its registered office at Viale Cassala, 30, Milan, 20143, tax code and VAT number 10380820968 (and which shall hereinafter be referred to as "WEROAD" or "Owner").

Contacts:

TYPE OF DATA PROCESSED

This information applies to the www.weroad.com website and other web pages that link to www.weroad.com

(all the web pages mentioned above, together will be referred to as the "Site").

- Navigation data automatically gathered by the Site: access and navigation data

Whenever Users access the Site, the computer systems and software procedures used to operate the Site acquire, in the course of their normal operation, access and navigation data (e.g. information on the browser used by the User, pages visited, date, time and duration of each visit, as well as other parameters relating to the User's operating system and computer environment - the "Browsing Data").

- Contact data (email and/or telephone)

- Personal data

- other personal data provided voluntarily

On some areas of the Site (https://www.weroad.com/contacts) it is possible to contact the Owner, by email at [email protected], by phone or WhatsApp or via the Owner's Facebook® group, to request information or clarification relating to WeRoad trips and the opportunity to create partnerships.

- User preference data

Data collected as a result of Users booking a trip and relating to age, sex, and purchase preferences shown by Users.

- Email address

(i) To activate the "Notify me" function, which allows you to be notified by email (rendered as contact data): when a WeRoad travel route is confirmed, the email addresses of users concerned are requested.

(ii) Users are also able to provide their email to WEROAD as contact information when subscribing to a newsletter service, in order to enable the user to benefit from this service and, as a result, to receive email updates on package tour destinations, the world of travel that is possible thanks to WEROAD, and other related activities of the Controller.

(iii) To contact users who have initiated a booking but have not completed it.

- First name, surname, place and date of birth, tax code, sex (gender), passport (number, issue date, expiry date) ("Personal Data"), address, email address, mobile phone number, emergency contact telephone number ("Contact data"), credit card / IBAN data ("Bank Data"), return flight information (date, time, flight number), passport scan (if required for booking purposes), ID card scan (if required for booking purposes), driving licence scan (if required for booking purposes), driving readiness, allergies and intolerances, health conditions, special needs

Gathered in certain areas of the Site where Users are required to provide specific personal data to book and purchase their WeRoad trip.

- The Interested Parties' image

Potentially collected during the trip made with WEROAD.

- First name, surname, beneficiary's first name, beneficiary's surname ("personal data"), address, beneficiary's address, beneficiary's email address, beneficiary's mobile phone number ("contact data"), credit card/IBAN data ("bank data")

Gathered in some areas of the Site where Users are required to provide specific personal data in order to purchase products from the WeRoad Shop, such as gift cards and vouchers. When the products are purchased for a third party, the data of the beneficiary is also requested.

- Data included on a medical certificate in case of cancellation

- Data from surveys

Data collected through surveys, both before departure and once the trip has ended, sent to users who have booked a trip.

- Cookies

The Site uses a number of computer techniques to directly acquire personal data identifying the user, consisting of "strings of code": "cookies".

For all information on the cookies enabled on the Site and the related processing of personal data, we invite you to read the relevant information in the "Cookie policy" section on our Site.

Purpose of the data processing

BROWSING THE WEBSITE

  • relating to the site navigation analysis

  • in an anonymous and aggregated form for statistical purposes related to understanding how the Site is used by Users

  • to detect potential technical problems as soon as possible.

Personal Data may be processed for the collection of anonymised statistical data on the use of the Site by Users, as well as for monitoring the functioning of the Site.

Legal Basis

The Data Controller's legitimate interest in operating and monitoring the Site and obtaining data on its use or your consent.

The Controller's interest has been balanced with that of the user, who will therefore benefit from an increasingly high-performance and optimised Site.

Nature of the Provision

Optional.

Failing to provide Data by disabling cookies in your browser, may prevent you from being able to access all the functions of the Site.

Data Retention Period

The Data shall not be retained for more than 1 week and shall be deleted without delay after their aggregation (except in the event of the need to establish criminal offences by the competent judicial authority). Our cookie policy is available in the "Cookie policy" section on our Site.

Purpose of the data processing

RESPONDING TO CONTACT REQUESTS:

  • it is possible to contact the Controller, by email at [email protected], by phone or WhatsApp or via the Controller's Facebook® group, to ask for information or clarifications relating to WeRoad trips and the opportunity to create partnerships and in general in relation to the services offered;

  • to respond to various User requests (e.g. Notify Me, Newsletter, Personal Travel Assistant, participation in AperiRoad and WeZoom).

Legal Basis

Performance of pre-contractual obligations to which the Data Subject is party (Article 6, paragraph 1, letter b) GDPR).

Nature of the Provision

This is required in order to comply with the request.

If you fail to provide the Data, WEROAD will not be able to respond to your request.

Data Retention Period

WEROAD will delete any Personal Data processed in response to such a request within 1 year from the date the request is closed.

Purpose of the data processing

STATISTICAL AND RESEARCH PURPOSES

anonymising data collected with tickets for internal reporting purposes

Legal Basis

The Controller's legitimate interest (Article 6, paragraph 1, letter f) GDPR) in obtaining statistical and anonymised data to improve their business and extrapolated from requests sent by users.

Nature of the Provision

Optional.

In the event of failure to do so, there will be no prejudice for the persons concerned.

Data Retention Period

The anonymised and used data will be retained for as long as it serves the purpose. Thereafter, the following will be deleted.

Purpose of the data processing

ALLOWING THE PURCHASE OF GIFT CARDS; T-SHIRTS AND GADGETS

and to access the personal purchasing area afterwards.

Legal Basis

Fulfilment of pre-contractual and contractual obligations to which the Data Subject is party (Article 6, paragraph 1, letter b) GDPR).

Nature of the Provision

This is required in order to comply with the request.

If you fail to provide the Data, WEROAD will not be able to process your request and conclude your purchase.

Data Retention Period

The data are retained until the purchase contract is completed and, in any case, for a period of 10 years (ordinary limitation period).

Purpose of the data processing

RESPONDING TO A TRAVEL ROUTE REQUEST ("NOTIFY ME")

Legal Basis

Fulfilment of pre-contractual and contractual obligations to which the Data Subject is party (Article 6, paragraph 1, letter b) GDPR).

Nature of the Provision

This is required to comply with the Data Subject's request.

If you fail to provide the Data, WEROAD will not be able to honour your request to be notified of the confirmation of your travel arrangements.

Data Retention Period

The data will be retained for as long as necessary to achieve the intended purpose and, in any event, for no longer than 1 year after it is provided.

Purpose of the data processing

BOOKING A TRIP

and accessing the personal booking area afterwards.

Legal Basis

Fulfilment of pre-contractual and contractual obligations to which the Data Subject is the party (Article 6, paragraph 1, letter b) GDPR).

In relation to any special data provided (e.g. health status, allergies), the express consent of the Data Subject is required (Article 9, paragraph 2 letter a) GDPR.

Nature of the Provision

This is required to follow up on the booking request.

In the event of failure to provide the Data, WEROAD will not be able to process the request and conclude the purchase, and in relation to specific data, will not be able to fulfil the specific requirements requested.

Data Retention Period

The Data are retained until the purchase contract is performed and, in any case, for a period of 10 years (ordinary limitation period).

Special data will be retained until the contract has been concluded and for a further 6 months unless a longer period is necessary to exercise or defend a right.

Purpose of the data processing

PUBLICATION OF THE INTERESTED PARTIES' IMAGES

collected during the journey with WEROAD on the Site

Legal Basis

The basis of the processing is the express consent of the Data Subject (Article 6, paragraph 1, letter a) GDPR).

Nature of the Provision

Optional.

In the event of failure to do so, there will be no negative repercussions for the Data Subject.

Any withdrawal of consent will not affect the lawfulness of the processing carried out to that point.

Data Retention Period

The data will be retained for 5 years after publication of the images, without prejudice to the Data Subject's right to revoke their consent.

In any case, WEROAD will not be responsible if the images are shared by third parties.

Purpose of the data processing

CONTACTING USERS WHO HAVE ADDED A TRIP TO THE SHOPPING BASKET:

retain the data in the shopping basket in the event of an unfulfilled booking and get in touch with the relevant users

Legal Basis

The legitimate interest of the Data Controller (Article 6, paragraph 1, letter f) GDPR) is to enable better navigation and use of the Site.

The Controller's interest has been balanced against that of the user, who will be able to complete an incomplete travel booking at a later date.

Nature of the Provision

Optional. There will be no negative repercussions for the Data Subject in the event of an objection to processing.

Data Retention Period

The data will be retained for 6 months.

Purpose of the data processing

CANCELLING A RESERVATION

Legal Basis

The basis of the processing is the express consent of the Data Subject to the processing of payment data in order to obtain a refund (Article 6, paragraph 1 letter a) GDPR and data contained in the medical certificate (Article 9, paragraph 2 letter a) GDPR.

Nature of the Provision

Optional.

Failing to provide any data, however, will not allow the reservation to be cancelled.

Data Retention Period

WEROAD will delete the data once the cancellation procedure has been completed.

Purpose of the data processing

COMMUNICATIONS IN CASES OF EMERGENCY

in order to manage communications for extraordinary emergencies.

The Data Subject is also invited to submit this information notice to his/her family members whose contact details are provided.

Legal Basis

Data processing is carried out in the legitimate interests of the Data Controller to enable the best possible management of emergencies, in accordance with Article 6, paragraph 1 letter f) GDPR.

Nature of the Provision

This is necessary for the pursuit of the Controller's legitimate interest, which is fairly balanced against the legitimate interest of the Data Subjects.

Processing is not a mandatory requirement and the Data Subject may object to such processing at any time.

Data Retention Period

WEROAD will delete the data once the trip has ended, and in any case after 1 month from the return.

Purpose of the data processing

SENDING COMMUNICATIONS OF A COMMERCIAL NATURE

i.e. for direct marketing purposes, such as sending newsletters, information and commercial communications, updates on the latest launches, offers and promotions relating to WEROAD's services, by newsletter, email or telephone, including by automated means (SMS, social media).

Legal Basis

Express consent to the processing of Personal Data (Article 6, paragraph 1, letter a) GDPR).

Where the Data Subject has contacted WEROAD, WEROAD may contact or send the Data Subject commercial communications relating to the request. In this case, the legal basis for the processing is WEROAD's legitimate interest in promoting its services to the data subjects in accordance with Article 6, paragraph 1 letter f) GDPR.

Nature of the Provision

Optional.

If the Data is not provided, WEROAD will not be able to update the data subject regularly on its offers and promotions.

The Data Subject may revoke his or her consent at any time by clicking on the "unsubscribe" link included in the marketing email received or by sending an email to [email protected]

If the Data Subject has contacted WEROAD: This is necessary for the pursuit of the Controller's legitimate interest which is fairly balanced with the legitimate interest of the Data Subjects.

Processing is not obligatory, and the Data Subject may object to such processing at any time.

Data Retention Period

The Contact Data processed for this purpose will be retained and processed for 5 years, subject to revocation of consent by the Data Subject.

In the event that the Data Subject has contacted WEROAD: WEROAD will delete the Personal Data that was processed for the purpose of responding to the request within 1 year from the date on which the processing of the request is closed. WEROAD may contact the Data Subject within this period.

Purpose of the data processing

SOFT-SPAM

The email address may be processed to send emails to data subjects regarding the promotion of WEROAD services similar to services already purchased.

Legal Basis

SOFT-SPAM

The email address may be processed to send emails to data subjects regarding the promotion of WEROAD services similar to services already purchased.

The Data Controller's legitimate interest in promoting its services to existing clients.

Nature of the Provision

Optional.

The Data Subject may object to the use of his or her email address at any time by clicking on the "unsubscribe" link in the email received or by sending an email to [email protected] and may also choose to be contacted for the above purpose only through the channels chosen and may object to receiving communications by automated means.

Data Retention Period

WEROAD will no longer use the email address 24 months after the date of the last commercial contact with the data subject.

You may withdraw your consent for marketing and commercial purposes at any time, without affecting the lawfulness of the processing carried out prior to the withdrawal based on your consent.

Purpose of the data processing

USER SEGMENTATION

for sending communications of a personalised commercial nature, based on age and type of travel purchased.

Legal Basis

The legitimate interest of the Data Controller (Article 6, paragraph 1 letter f) GDPR) to improve its commercial offer.

The Controller's interest is balanced against the user's interest in being able to receive commercial communications in line with their interests.

Nature of the Provision

Optional. There will be no negative repercussions for the user in the event of an objection to processing.

Data Retention Period

The data will be retained for 12 months after collection.

Purpose of the data processing

CONDUCTING SATISFACTION SURVEYS for participants before and after a trip.

Legal Basis

The Controller's legitimate interest (Article 6, paragraph 1 letter f) GDPR) to assess and improve the quality and satisfaction with the services offered.

Nature of the Provision

Optional.

Failure to provide the Data, however, will make it impossible to assess the expectations and satisfaction of the clients in relation to the services offered by the Controller.

Data Retention Period

The Data will be stored for 1 year from the time of collection and will subsequently be anonymised and aggregated.

Purpose of the data processing

MANAGING CLAIMS AND DEFENDING IN COURT

Legal Basis

Fulfilment of pre-contractual and contractual obligations to which the Data Subject is party (Article 6, paragraph 1, letter b) GDPR).

Nature of the Provision

Mandatory.

The transfer is necessary to allow the Controller to respond to requests made by Data Subjects and to defend its rights against the Data Subject or third parties before the competent authorities.

Data Retention Period

The data are retained until the purchase contract is completed and, in any case, for a period of 10 years (ordinary limitation period).

Purpose of the data processing

CORPORATE TRANSACTIONS

Sharing personal data in connection with, or in the course of, the negotiation of extraordinary transactions of all or part of WEROAD's business by or in another company

Legal Basis

The Controller's legitimate interest (Article 6, paragraph 1 letter f) of the GDPR).

Nature of the Provision

The processing of data is necessary for the legitimate interests of WEROAD in the negotiation and execution of corporate transactions.

Data Retention Period

The data stored for this purpose will be deleted at the end of the operation.

The information in this policy does not apply to third-party sites, apps and content of any kind, even if they can be accessed from the Site by clicking on links contained therein.

In such cases, the data protection provisions of such third parties may be applied, which may be different from those presented here and which the data subject is invited to consult before disclosing any data.

In addition and without prejudice to the foregoing, the Data Controller undertakes to base the processing of Personal Data on the principles of minimisation, and each year will verify the need to store the data for a period of time not exceeding what is required by the purposes for which the data were collected and processed. The Data Controller may retain the Personal Data in order to comply with the law or to exercise or defend any right or claim in legal proceedings. Once the purposes for which the Personal Data were collected and processed have been achieved, the Data Controller will implement appropriate measures to anonymise the data so that the data subject cannot be identified.

RECIPIENTS/CATEGORIES OF RECIPIENTS OF DATA

The Data shall be processed by employees and collaborators of the Data Controller, expressly authorised to process the Data on the basis of instructions and after appropriate measures have been taken to protect the Data in connection with all the aforementioned purposes.

The following parties may become aware of the Data in relation to the processing purposes provided for in this privacy policy and may process the Data both as independent data controllers and as data processors appropriately appointed by the Data Controller (the list of such data controllers and independent data processors is available upon request by email to be forwarded to [email protected]):

  • persons whose activities are functional to the above purposes, such as IT infrastructure providers, IT support services and consultancy providers, companies that provide data analysis and development services, as well as law firms, accountants and auditors;

  • other companies belonging to the so-called OneDay Group;

  • hotels and other accommodation facilities, car rental companies, airlines, companies providing travel insurance policies, and other third parties rendering services necessary for the realisation of the booked trip;

  • local tourism partners, e.g. local travel agencies; tour guides;

  • companies that offer payment and booking services.

TRANSFER OF THE DATA TO A NON-EU COUNTRY

Your personal data will not be transferred to non-EU countries.

The Data Controller undertakes to transfer personal data to third countries if necessary:

  • after ensuring that the country to which the personal data will be sent can guarantee an adequate level of protection, as provided for in Article 45 of the GDPR; or

  • by respecting the standard contractual clauses approved by the European Commission for the transfer of personal information outside the EEA (these are clauses approved pursuant to Article 46 (2) of the GDPR).

DATA PROCESSING METHODS

The Data will be processed in compliance with the principles of correctness, lawfulness and transparency, through manual and automated methods and the use of paper and electronic means, in any case within the limits of the purposes of the data processing established in this document and, in any case, always guaranteeing the security and confidentiality of your Data.

RIGHTS OF DATA SUBJECTS

The Data Subject may at any time exercise the following rights under the conditions and within the limits provided for in Articles 12-22 of the GDPR by sending an email to [email protected]

  • Right of access (Article 15 GDPR);

  • Right to the rectification of inaccurate personal data and to obtain the integration of incomplete personal data (Article 16 GDPR);

  • Right to erasure of personal data (Article 17 GDPR);

  • Right to limitation of processing (Article 18 GDPR);

  • Right to object to processing in accordance with Article 6, paragraph 1, letter e) or f) of the GDPR, including profiling (Article 21 GDPR);

  • Right to lodge a complaint with the supervisory authority (Article 77 GDPR).

If the data subject considers that the processing of personal data carried out by the Controller is in breach of the provisions of Regulation (EU) 2016/679, he/she has the right to lodge a complaint with the Supervisory Authority, in particular in the Member State in which he or she normally resides, or works or in the place where the alleged breach of the Regulation occurred or to take appropriate legal action.

Date of update: January 2023