Protection of Personal Data Policy
PROTECTING PERSONAL INFORMATION
M&T Lignos P.C. will take reasonable measures to (i) protect personal information from unauthorized access, disclosure, alteration or destruction, and (ii) keep personal information accurate and up-to-date as appropriate. M&T Lignos P.C. employs a robust team of dedicated information security professionals who are responsible for creating, updating and managing M&T Lignos P.C.’s security program. M&T Lignos P.C.’s Information Security team is responsible for, among many other things, monitoring our systems for potential intrusions, responding to potential incidents, supporting property-level information security, regularly reviewing and updating the security controls M&T Lignos P.C. uses to protect data and providing training on M&T Lignos P.C.’s information security program. M&T Lignos P.C. maintains a PCI compliance program and an IT compliance program. This compliance program generates audit reports concerning the adequacy and effectiveness of M&T Lignos P.C.’s IT internal controls, including a PCI Attestation of Compliance signed by an external PCI Qualified Security Assessor and a SSAE16/SOC1 report addressing the IT general controls over systems that support certain accounting and financial reporting. In the event of a security incident, M&T Lignos P.C. will notify regulators and/or consumers as required by applicable laws or regulations.
We also seek to require our affiliates and service providers with whom we share personal information to exercise reasonable efforts to maintain the confidentiality of personal information about you. For online transactions, we use reasonable technological measures to protect the personal information that you transmit to us via our site. Unfortunately, however, no security system or system of transmitting data over the Internet can be guaranteed to be entirely secure.
For your own privacy protection, please do not send payment card numbers or any other confidential personal information to us via email.
We will not contact you by mobile/text messaging or email to ask for your confidential personal information or payment card details. We will only ask for payment card details by telephone when you are booking a wine tour or promotional package. We will not contact you to ask for your M&T Lignos P.C. Loyalty account log-in information. If you receive this type of request, you should not respond to it. We also ask that you please notify us at our email address.
INTERNATIONAL TRANSFERS OF PERSONAL INFORMATION
As a company, we endeavor to provide you with the same level of service that you have come to expect at M&T Lignos P.C. whether you are. To provide this service, you acknowledge that we may share your personal information among members of the M&T Lignos P.C. Portfolio of Brands, our service providers, and other third parties, which may be located in countries outside of your own. The data controller may maintain a local copy of your personal information when so required by applicable laws or regulations. Although the data protection laws of various countries may differ from those in your own country, we will take appropriate steps to ensure that your personal information is handled as described in this Statement and in accordance with the law.
CHANGING AND ACCESSING YOUR PERSONAL INFORMATION
If you are a M&T Lignos P.C. Loyalty member, the information you provided to us at the time of registration may be accessed, reviewed and updated at any time by signing in to your M&T Lignos P.C.. To the extent required by applicable law, you may be able to request that we inform you about the personal information we maintain about you and, where appropriate, withdraw your consent for certain data processing activity and/or request that we update, correct, delete, and/or stop processing your personal information. We will make all required updates and changes within the time specified by applicable law and as required by law. When permitted by law, we may charge an appropriate fee to cover the costs of responding to the request. Such requests may be submitted in writing to our email address. To protect your confidentiality, we can only respond to such requests to the email address that you have registered or otherwise provided to us. Please remember that if you make such a request, we may not be able to provide you with the same quality and variety of services to which you are accustomed.
In addition, in some circumstances based on applicable law, you may request that we cease sharing personal information about you with our business partners or that M&T Lignos P.C. cease using personal information about you by contacting us using the email or mailing address above. We will seek to honor those requests consistently with applicable law.
RETAINING PERSONAL INFORMATION
We retain personal information about you for the period necessary to fulfill the purposes outlined in this Statement unless a longer retention period is required or permitted by applicable law. We retain personal information collected in order to fulfill guest reservations for seven years after the stay is completed. We retain other personal information for shorter periods of time if possible and if permitted by law. We will destroy your personal information as early as practicable and in a way that the information may not be restored or reconstructed. If printed on paper, the personal information will be destroyed in a secure manner, such as by cross-shredding or incinerating the paper documents or otherwise and, if saved in electronic form, the personal information will be destroyed by technical means to ensure the information may not be restored or reconstructed at a later time.
CHOICES – MARKETING COMMUNICATIONS
If you have given us your contact information (mail address, fax number, email address or phone number), we may want to inform you in accordance with any preferences you have expressed, and with your consent where required, about our products and services or invite you to events via email, online advertising, social media, Viber, WhatsApp, Messenger, telephone, text message (including SMS and MMS), push notifications, in-app alerts, postal mail, our customer service call center, and other means (including on-property messaging, such as your in-room television).
If you are a M&T Lignos P.C. Loyalty member, you may change the communications you receive from us by logging on to your online account and managing your subscriptions, by writing to us (and including your email address) at our email address. If you prefer not to receive email marketing materials from us, you may opt-out at any time by using the unsubscribe function in the email you receive from us. Opt-out requests can take up to ten business days to be effective.
To opt out of text messages, tell the winery front desk that you do not want to receive text messages from the winery or reply “STOP” to the message you received. To be added to M&T Lignos P.C.’s internal do not call list, send a message to our email address. You may control whether our mobile apps send you push notifications by changing your notification settings on your mobile device. If we engage in sending you in-app messages, we will allow control for those in our apps’ settings. For more information about cookies and interest-based advertising and to learn about how to manage these technologies, please see our Cookies Statement.
STATEMENT MODIFICATIONS
We may modify this Statement from time to time. When we make material changes to this Statement we will post a link to the revised Statement on the homepage of our site, and if you have registered for any of your products or services, will also inform you through a communications channel that you have provided. You can tell when this Statement was last updated by looking at the date at the top of the Statement. Any changes to our Statement will become effective upon posting of the revised Statement on the site. Use of the site, any of our products and services, and/or providing consent to the updated Statement following such changes constitutes your acceptance of the revised Statement then in effect.
CONTACT US
If you have any questions about this Statement or how M&T Lignos P.C. processes your personal information, or if you wish to either provide a compliment or a complaint, please contact us by email.
APPENDIX A
ADDITIONAL PROVISIONS APPLICABLE TO PROCESSING OF
PERSONAL INFORMATION OF EEA RESIDENTS
For individuals residing in the EEA, this Appendix outlines certain additional information that M&T Lignos P.C. is obligated to provide to you, as well as certain rights you have with respect to the processing of your personal information, pursuant to applicable local laws. This Appendix will control to the extent it conflicts with any provision in the main body of this Statement.
Controller: for more information on the M&T Lignos P.C. entities that process your personal information, please write to our email.
Purposes and Legal Basis for Processing: M&T Lignos P.C. processes your personal information for the purposes set forth in Sections 4 (Use of Personal Information Collected About You) and 5 (Personal Information We Share) of the main body of this Statement.
The legal bases for M&T Lignos P.C. ’s processing activities include processing such information as necessary to comply with our contractual obligations, compliance with our legal obligations, protecting the safety of our employees, guests, and ohers, for our legitimate business interests, and pursuant to your consent. The particular legal basis for the processing of your personal information is based on the purpose for which such information was provided or collected:
M&T Lignos P.C. Loyalty Participation: We process the personal information obtained in connection with your participation in the M&T Lignos P.C. Loyalty program on the basis of our contractual relationship with you and in furtherance of our business interests, including to personalize your use of our services and applications, to communicate news and promotional items, and to deliver personalized advertising and content.
Surveys: Completion of surveys is voluntary – we process the information obtained from surveys on the basis of your consent and in furtherance of our business interests, including marketing, service improvements, and analytics.
On-property Collection:
When you make a request or reservation and when you visit our winery, we process your name, address, contact information, along with the details of your visit (arrival and departure day and time, vehicle information and information regarding others traveling or staying with you), on the basis of our contractual relationship with you. We also process such data for our business interests, including for marketing, service improvements, administration of our e-billing program, and analytics and service personalization, as described in Section 4 of our Global Privacy Statement (above).
We collect certain additional personal information during registration/check-in at our properties (such as national ID or passport information), as necessary to comply with our legal obligations.
We use closed-circuit television and other security measures at our properties that may capture or record images of guests and visitors in public areas, as well as information related to your location while on our properties (via keycards and other technologies) for the protection of our staff, guests and visitors to our properties.
We process personal information in connection with on-property services (such as concierge services, allergies, activities, equipment rental, product shopping), in order to provide the services to you and for our business interests including for marketing, service improvements, administration of our e-billing program, and analytics and service personalization, as described in Section 4 of our Global Privacy Statement (above).
Event Profiles: We process the personal information obtained in connection with your event on the basis of our contractual relationship with you and for our business interests, including for marketing, service improvements, and analytics and service personalization, as described in Section 4 of our Global Privacy Statement (above).
Social Media: Participation in M&T Lignos P.C.- sponsored social media activities and offerings is voluntary - we process information obtained from social media participation on the basis of your consent and in furtherance of our related business interests, including for marketing, service improvements, and analytics and service personalization, as described in Section 4 of our Global Privacy Statement (above).
Promotions and Sweepstakes: Participation in sweepstakes, contests, and other promotional offerings is voluntary – we process the information obtained from such participation based on your consent and as necessary to administer the offering. We also use certain data for our business purposes, including for marketing, service improvements, administration of our e-billing program, and analytics and service personalization, as described in Section 4 of our Global Privacy Statement (above).
Direct Marketing: We use your personal information to send you marketing messages on the basis of your consent. You may withdraw your consent for direct marketing communications at any time by contacting us at our mail address, or by following the unsubscribe instructions in the marketing message, or by logging in to your M&T Lignos P.C. Loyalty account and updating your communication preferences.
Franchise and Ownership Opportunities: We process this information on the basis of our contractual relationship with you and for our related business interests, including maintaining and promoting the M&T Lignos P.C. brand and facilitating direct communication between properties within the M&T Lignos P.C. Portfolio of Brands.
Data Portability Requests: You have the right to request that we provide you or a third party that you designate with certain of your personal information in a commonly used, machine-readable format. Please note, however, that data portability rights apply only to personal information that we have obtained directly from you and only where our processing is based on consent or the performance of a contract. Submitting Requests: your requests may be submitted by writing to our email address. You may also update your personal information as provided in Section 12 (Changing and Accessing Your Personal Information) of the main body of this Global Privacy Statement.
We will respond to all such requests within 30 days of our receipt of the request unless there are extenuating circumstances, in which event we may take up to 60 days to respond. We will inform you if we expect our response to take longer than 30 days. Please note, however, that certain personal information may be exempt from such rights pursuant to applicable data protection laws. In addition, we will not respond to any request unless we are able to appropriately verify the requester’s identity. We may charge you a reasonable fee for subsequent copies of data that you request.
If you have concerns about our data practices or the exercise of your rights, you may contact M&T Lignos P.C. at our email address.
Right to Withdraw Consent: You have the right to withdraw your consent to any processing that we conduct solely based on your consent (such as sending direct marketing materials to your personal email account). You may withdraw your consent to marketing activities by following the instructions on any marketing emails or contacting us. For any other activities for which you have previously consented, you may contact us.
Segmentation (also referred to as profiling) and Automated Decision Making: We use personal information to divide large groups of consumers into sub-groups of consumers (known as segments) based on some type of shared characteristics such as geography, behavior, or demographics.
With your consent, we make automated decisions, meaning without human interference, using segmentation and/or your specific personal information to offer you certain benefits based on your characteristics (such as discounted room rates or other special offers based on your geography, behavior, or demographics).
International Data Transfers: We may transfer the personal information we collect about you pursuant to the purposes described in this Statement to countries that have not been found by the European Commission to provide adequate protection.
We use appropriate safeguards for the transfer of personal information among our affiliates in various jurisdictions, and where required, we have implemented European Union controller-to-controller standard contractual clauses or other such safeguards for such purposes. To obtain a copy of these clauses or additional information on transfers, you may send your request at our email address.