Costa Group Asia Personal Data Processing Statutory Notice
Effective on:Aug 1, 2018
Costa Crociere S.p.A., Costa Cruises Shipping Services (Shanghai) Co., Ltd and all of its affiliates in Asia (hereinafter collectively also “Costa Crociere”), as data controller, in accordance with article 13 of the General Data Protection Regulation (EU) 2016/679 (hereinafter the “GDPR”), Cyber Security Law of People’s Republic of China and other applicable laws and regulations (hereinafter collectively the “relevant laws”), is providing the following information about the processing of the personal data which you, as the data subject, have provided us:
a) for buying a travel package;
b) within the context of cruises (e.g. purchases made);
c) registration on the Costa Crociere web site and/or app or the filling in of forms on the Costa Crociere web site.
The personal data we will collect
In order to complete the ticket booking procedure, to identify your identity when you are on board and for us to complete our contractual obligations, you need to provide the following information: name, gender, age, birth date, email address, contact number, ID card information, passport information, valid recipient address, reentry permit (if applicable) and mainland travel permit for Taiwan residents (if applicable), when you book tickets through this website (we entrust Shanghai Pan Bo Network Technology Co., Ltd. to operate our official store and online customer service of Fliggy and to collect relevant personal information that you fill in online or submit through online customer service) or “Costa Cruise Customer Service Hotline”. At the same time, in order to comply with the requirement of the government of the calling port, we may require you to provide one of the following financial proof:
1)Certificate of deposit of RMB 50,000 or above; or
2)Owner Certificate of Property of yours; or
3)Owner Certificate of vehicle of yours.
The above financial proof will be provided by us to relevant government authority per their requirement. Besides that, we will not provide the above financial proof to any other third party. Such proof will be deleted after 30 Calendar days since the departure date.
Purposes and legal basis of processing
In addition, the data which you have provided may also include some personal data defined by the Code and the GDPR as “special category data”. Sensitive/special category data shall be processed according to the purposes shown further on and only with your consent.
a) Purpose regarding contractual performance.Your personal data shall be processed for the purpose of performing obligations arising out of the contract for the purchase of the travel package, for allowing Costa Crociere to deliver the service in an optimal manner and, specifically, for:
(i) the formation, management and performance of contractual relations between you and Costa Crociere;
(ii) responding to your requests;
(iii) notification of information regarding the travel package (e.g. changes to contractual terms and conditions, etc.);
(iv) the creation of activities which serve to make your cruise enjoyable and pleasant and to guarantee high entertainment standards on board ships (i.e. party events, photo shoots and video recordings, games, etc.). In addition, in relation to the photos taken and videos recorded by photographers and video operators on board our ship, who work with us to make the cruise experience is unforgettable, please note that whenever you do not wish to be part of photos/videos or whenever you do not want your photos to be displayed on the display board at the Photoshop, you may go to the Photoshops which will record your wishes from time to time. The removal of a photo that features you may only be made after you have reported it.
b) Legal, health and safety purposes.Your personal data shall also be processed for the following purposes:
(i) legal, regulatory, domestic and EU compliance and that arising out of orders issued by authorities within the scope of their legal authority;
(ii) establishing, exercising and/or defending a Costa Crociere legal claim before the courts;
(iii) guaranteeing the necessary medical assistance during the cruise;
(iv) complying with the requirements of the CLIA association and the USPHS.
c) Business and statistics-related purposes.Your personal data shall also be processed for purposes relating or relevant to Costa Crociere business operations and for the processing of statistics in anonymous form and market research.
d) Additional purposes. Furthermore, whenever you expressly give your consent, your personal data shall be processed for the following purposes:
(i) Marketing purposes, including:
a. promotional activities of Costa Crociere, companies in the Carnival Corporation & PLC Group (hereinafter the “Group”), also abroad, and/or commercial partners, implemented using both automated methods (e.g. e-mail, sms, instant messaging apps, etc.) and non-automated methods (e.g. regular mail, telephone with operator, etc). Specifically, Costa Crociere may use your e-mail address provided at the time you purchased a travel package, for sending you information and promotional notifications linked to services and products similar to those offered by Costa Crociere and the Group and/or commercial partners, provided you have consented to said use.
The Carnival Group companies are: Carnival Corporation (CCL), Carnival PLC (P&O, Cunard, Princess Asia), Costa Croceire S.p.A. (AIDA and Costa), Holland America Line N.V., general partner of Cruiseport Curacao C.V. (Holland America Line and Seabourn) Princess Cruise Lines, Ltd (Princess, Alaska, P & O Australia and Cunard), SeaVacations Limited (CCL business in UK).
The commercial partners belong to the following product and market categories:
a) tourism-related activities;
b) airlines/transport services;
c) travel agencies;
d) insurance companies.
b. profiling activities, i.e. analysis of your travel preferences and market research for the purpose of enhancing the offering of services and sales information from Costa Crociere, matching them more closely to your interests. Said activity may also be implemented by submitting customer satisfaction questionnaires and/or the use of profiling cookies used during browsing Costa web sites.
(ii) Purposes for the provision of accessory services, including:
Registration on sites (e.g. MyCosta) and digital platforms, for allowing you to access and use the services provided on the portal and reserved for registered users and for guaranteeing you a customized vacation (e.g. for the purchase of wellness packages, beverage packages, photos, Costa-branded gifts and party events, etc.).
Processing for Marketing Purposes (i.e. for both promotional and profiling activities) may be implemented only with your consent.
We will not use the information collected by Cookies for the purposes which are out of the scope as mentioned in this Privacy Notice. You may manger or delete Cookies based on your preference. You may remove all the Cookies in the computer and most of the website browsers have the function to prevent the Cookies. However, you need to modify your setting of your computer every time before you browse our website. For more information, you may refer to the instructions of your browser.
When you browse, use our website/app or interact with our website/app, we will automatically collect and store the following information: your IP address, device ID, browser information, the domain name of the website before jumping to our website, browse path model and website usage custom.
Nature of data provision and consequences arising out of any refusal
The provision of your personal data is optional; however, without the data requested for the purposes shown in a) and b), the service requested or part thereof may not be performed and you may not be able to take advantage of above-mentioned opportunities.
The provision of optional data shall allow Costa Crociere to enhance the services offered, for rendering them better tailored to the personal interests of its passengers.
The provision of sensitive/special category data is optional; however, without said consent, Costa Crociere may not be able to comply with a number of contractual obligations and guarantee you any necessary medical assistance.
Personal data recipient categories
Your data shall not be disseminated. Your data may be disclosed only for the purposes stated above or upon your consent to the following categories of persons and entities:
- Costa Crociere in-house staff, appointed as data processing agents and/or data processor;
- companies belonging to the Costa Crociere Corporate Group, also located abroad;
- to the suppliers and/or agents/operators which, on board ships and ashore, provide services required during the cruise (e.g. port agents, entertainment operators, etc.);
- persons, companies, associations or professional firms providing services or advisory or consulting services to Costa Crociere for protecting its claims (e.g. chartered accountants, physicians, lawyers, tax consultants, auditors and consultants within auditing or due diligence operations, etc.);
- persons, companies or agencies that provide marketing services and analysis or consulting activities to Costa Crociere;
- persons and entities that are authorized to access your data, both recognized by law and secondary legislation or by orders issued by authorities empowered by law, including port authorities at the place of landing.
The list of persons and entities to which your data have been disclosed is available at the company at the following addresses: email@example.com or firstname.lastname@example.org.
Transfer of personal data outside People’s Republic of China
The Personal Information will be stored within the territory of People’s Republic of China and be backup in the server located in Europe. You understand and agree that we will transfer your Personal Information to Europe.
Transfer of personal data outside the European Union
Your personal data may be transferred abroad to third-party companies belonging or outside the European Union for the purposes stated above.
Whenever data is transferred to States outside the European Union, said States shall guarantee an adequate level of protection, based on a specific decision of the European Commission or, alternatively, the recipient shall have a contractual obligation to protect data adopting an adequate and comparable level of protection to that provided under the GDPR.
Retention of personal data
Personal data shall be retained for a period of time not exceeding that necessary for the purposes for which they were collected and subsequently processed. Personal data shall be retained for the full duration of the contract which you have entered into and for a subsequent period:
i. within the periods established under prevailing legislation;
ii. within the periods established under legislation, including secondary legislation, which require data to be kept (for example tax returns);
iii. within the period necessary for protecting the rights of the data controller in the event of any disputes arising concerning performance;The photos/images and audio/video recordings collected during events and happenings on board shall be retained for a period limited to the duration of the cruise and subsequently they shall be deleted.
Personal data collected and processed for profiling shall be retained for a maximum period of ten (10) years, at the end of which they shall be automatically deleted and rendered permanently anonymous.
How we deal with minor’s personal data
If you are the minors under the age of 18, please make sure that you are under the guidance of your parents or supervisors when you use and browse this website, and obtain your parents or supervisor’s consent before providing your Personal Information to us.
As for the Personal Information of the minors which are collected under the consent of parents, we will only use or disclose such Personal Information if permitted by the law, or obtain express consent of parents or supervisors or being necessary to protect minor.
As soon as we find that we collect the Personal Information of minors without the consent of parents, we will delete relevant data.
Data Controller and Data Processors
The Data Controllers are:
-Costa Crociere S.p.A., with address in Genoa, Piazza Piccapietra, no. 48.
-Costa Cruises Shipping and Services (Shanghai) ltd, with the address in 23F Building One,Corporate Avenue, N°222 Hu Bin Road, 200021 Shanghai, People Republic of China.
Data subject rights
At any time, you are entitled, also in relation to profiling, to:
a) access your personal data;
b) request your personal data to be corrected;
c) revoke, at any time, consent to the use and disclosure of your personal data;
d) request your personal data to be deleted;
e) receive the personal data concerning you in a structured, commonly used and machine-readable format, as well as the right to send your data to another data controller;
f) oppose the processing of personal data concerning you for marketing or profiling purposes;
g) obtain restriction on the processing of personal data;
h) lodge a complaint with a supervisory authority;
i) receive a notification whenever there is a personal data breach;
j) request information about:
i. the purposes of processing;
ii. the categories of personal data;
iii. the recipients or categories of recipients to whom personal data have been or will be disclosed, specifically, whenever data have been sent to recipients in third countries or international organizations and the existence of adequate guarantees;
iv. the period personal data shall be retained;
v. whenever data have not been collected from the data subject, all information regarding their origin.
You may, at any time, oppose the sending of notifications linked to marketing and profiling activities, by clicking on the “unsubscribe” link at the bottom of the e-mail received or by sending a relevant request to the addresses shown further on.You may exercise these rights and/or obtain further information about personal data processing, by sending a notification:
-via e-mail to: email@example.com or firstname.lastname@example.org
Update of this notice
We reserve the right to update this notice from time to time as our services are in the process of continuous improvement and the form and nature of our services may change from time to time. We will release the updated version on this website in a timely manner and mark the latest update date at the top of this notice. We recommend you to check the latest version frequently.