Menu

Privacy Policy

Privacy Policy

in accordance with Article 13 of EU Regulation 2016/679 (GDPR)

Data Controller

Honey Travel S.R.L.
Registered office: Via Francesco Melzi d’Eril 7, 20154 Milan (MI)
Registered office: Via Carlo Pisacane 7, 20016 Pero (MI)
VAT number and Tax Code: IT04725280962 – REA MI-1768617
Tel. +39 02 39005170 – PEC: honeytravelsas@pec.it
Travel agency licence no. 152978/05 (Province of Milan)
Public Liability Insurance: Europ Assistance, policy no. 2526322
Travel Guarantee Fund: policy no. 6006002367/B (Nobis)

2. Types of Data Processed

  • Personal details (first name, surname, date of birth, address)
  • Contact details (phone number, email)
  • Identity documents and information on travel documents
  • Travel preferences and special requirements
  • Payment details
  • Any health data required for trip organisation
  • Details of any travel insurance

3. Purpose of Processing

  • Reservation management and organisation of requested tourist services
  • Fulfillment of contractual and pre-contractual obligations
  • Administrative and accounting management
  • Fulfilment of legal obligations
  • Travel Insurance Management
  • Travel assistance
  • Communications relating to the service purchased
  • Direct marketing (with prior specific consent)

4. Legal Basis for Processing

  • Execution of the contract for tourist services requested
  • Fulfilment of legal obligations
  • Consent of the data subject (for marketing and processing of special categories of data)
  • Legitimate interest of the data controller

5. Methods of Treatment

The data is processed in paper and electronic format, in compliance with the security measures provided for by the GDPR.

6. Retention Period

  • 10 years for accounting and tax documentation
  • 5 years for marketing purposes (with prior consent)
  • For the period necessary to pursue the stated purposes
  • For the fulfilment of legal obligations

7. Data Recipients

  • Tourist service providers (accommodation facilities, airlines, etc.)
  • Insurance company
  • Consultants and external professionals
  • Public authorities when provided for by law
  • Banking institutions for payment management

8. Extra-EU Data Transfer

In the case of non-EU destinations, data may be transferred to third countries. Such transfers will take place in compliance with the appropriate safeguards provided for by the GDPR.

9. Data Subject Rights

  • Access your personal data
  • To request its rectification or erasure
  • Limit the treatment
  • Object to treatment
  • Request data portability
  • Withdraw consent at any time
  • Lodge a complaint with the Data Protection Authority

10. Nature of the Contribution

  • Mandatory for the performance of the contract and legal obligations
  • Optional for marketing purposes
×