Keep our town’s history & culture (Pro Loco) alive!

Privacy Policy

PRIVACY POLICY FOR THE PROCESSING OF PERSONAL DATA
iatsantarcangelo.com

Pursuant to Article 13 of EU Regulation 2016/679
(on the protection of natural persons)

1. DEFINITIONS
For the purposes of this policy, the following terms shall have the following meanings:
• “System Administrator”: a person entrusted with the task of overseeing the operating system resources of a computer or database system and authorizing their use, whose activities and access are periodically monitored by the Data Controller.
• “Personal data”: any information relating to an identified or identifiable natural person, including, but not limited to: first name, last name, business name, company name, address, telephone number, fax number, email address, images, video recordings, and bank and payment details.
• “Recipients”: the natural or legal person, public authority, agency, or other body to whom personal data is disclosed, whether or not they are a third party. Public authorities that may receive personal data in the context of a specific investigation in accordance with Union or Member State law are not, however, considered recipients; the processing of such data by those public authorities complies with the applicable data protection rules in accordance with the purposes of the processing.
• “Data Subject”: a natural or legal person, regardless of its organizational structure, who contacts the Company to receive the products and services it offers.
• “Profiling”: any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person.
• “Third country”: A country that is not a member of the European Union.
• “Data processor”: a natural or legal person who processes personal data on behalf of the data controller.
• “Authorized person”: a natural person employed by the Company who processes personal data.
“Data controller” or “Controller”: a natural person or a legal entity that determines the purposes and means of processing personal data.
• “Processing”: any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.

2. DATA CONTROLLER
IAT Pro Loco Office – Via C. Battisti 5, Santarcangelo di Romagna, VAT No. 03295400406, iat@comune.santarcangelo.rn.it, represented by its current legal representative

3. AUTHORIZED PARTIES – DATA CONTROLLER – SYSTEM ADMINISTRATOR
Your data may be disclosed for the purposes set forth in the following sections:
• to the Data Controller’s internal employees, referred to as “Authorized Persons,” who are authorized to process personal data for contractual purposes;
• to third-party companies or other entities (including, but not limited to: financial institutions, professional firms, consultants, insurance companies providing insurance services, companies providing data center services, web hosting, email, etc.) that perform outsourced activities on behalf of the Data Controller, in their capacity as “Data controllers”.
The parties authorized to process the data are: the data controller and/or any representatives designated in writing.
which entities are authorized to access and process personal data for Service and Marketing purposes. The legal representative of Ufficio IAT Pro Loco—Via C. Battisti 5, Santarcangelo di Romagna, VAT No. 03295400406—is also appointed as Data Protection Officer.
Currently, the IAT Pro Loco Office—located at Via C. Battisti 5, Santarcangelo di Romagna, VAT No. 03295400406—does not have any external Data Processors. Should such a role be appointed, a list will be made available for consultation directly at the Data Controller’s registered office.

4. APPLICABLE LAW
This privacy policy complies with the principles set forth in Article 13 of EU Regulation 2016/679 (on the protection of natural persons with regard to the processing of personal data and on the free movement of such data—GDPR) and Article 13 of Legislative Decree 196/2003 (Privacy Code).

5. PURPOSE OF DATA PROCESSING
Like all websites, this site uses log files to store information collected automatically during user visits. The site uses Google Analytics for data processing.
The information collected may include the following:
• Internet Protocol (IP) address;
• browser type and device parameters used to connect to the site;
• name of the Internet service provider (ISP);
• date and time of visit;
• referring webpage and exit page;
• country of origin;
• number of clicks, if applicable;

6. COOKIES
This website also acts as an intermediary for third-party cookies, which are used to provide additional services and features to visitors and to improve the user experience on the site, such as social media buttons. This privacy policy does not apply to services provided by third parties, and this website has no control over their cookies, which are managed entirely by the third parties, nor does it have any access to the information collected through such cookies. The data transfer agreement is made directly between the user/visitor and the third parties, while this site does not participate in any way in such a transfer. Consequently, information regarding the use of these cookies and their purposes, as well as instructions on how to disable them, is provided directly by the third parties on the pages listed below.
In particular, this site uses cookies from the following third parties:
• Google (Google Analytics cookies): Google Analytics is an analytics tool provided by Google that uses cookies (performance cookies) to collect anonymous browsing data in order to analyze how users use the site, compile reports on site activity, and provide other information, including the number of visitors and the pages they visit. Google may also transfer this information to third parties where required by law or where such third parties process the information on Google’s behalf. Google will not associate the IP address with any other data held by Google. The data transmitted to Google is stored on Google’s servers in the United States. Under a specific agreement with Google, which is designated as the data processor for user data, Google undertakes to process the data in accordance with the Data Controller’s instructions, provided directly through the software settings. Based on these settings, advertising and data-sharing options are disabled.
• Further information on Google Analytics cookies can be found on the Google Analytics Cookie Usage on Websites page.
You can selectively disable (opt out of) data collection by Google Analytics by installing the appropriate component provided by Google (opt-out) on your browser.
Google (YouTube cookies). YouTube is a video-sharing platform owned by Google that uses cookies to collect information about users and their browsing devices.
Most of the videos on the site do not set cookies when the page is loaded, as the “advanced privacy (no cookies)” option has been selected, which prevents YouTube from storing information about visitors unless they voluntarily play the video.
• For more information about how Google uses and processes data, please review the information on the page provided by Google, as well as the pages explaining how Google uses data when you use partner websites or apps.

7. SOCIAL MEDIA PLUGINS
This website also incorporates social media plugins and/or buttons to allow you to easily share content on your favorite social media platforms. These plugins are programmed not to set any cookies when you access the page, in order to protect users’ privacy. Cookies may be set, if provided for by the social networks, only when the user actively and voluntarily uses the plugin. Please note that if the user is logged into the social network while browsing, they have already consented to the use of cookies transmitted through this site at the time of registration with the social network.
The collection and use of information obtained through the plugin are governed by the respective privacy policies of the social networks, to which you are asked to refer.
• Facebook;
• Twitter;
• LinkedIn;
• Google+.

8. PRINCIPLES AND PURPOSES OF DATA PROCESSING
Your personal data is:
1. processed lawfully, fairly, and transparently in relation to you;
2. collected for specific, explicit, and legitimate purposes;
3. processed in a manner that is adequate, relevant, and limited to the purposes for which you provided it;
4. processed accurately and updated as promptly as possible;
5. retained for no longer than is necessary to achieve the purposes;
6. retained in a manner that ensures adequate security and protection through appropriate technical and organizational measures.
Your personal data is specifically processed without your express consent, pursuant to Art. Article 6(b) of the GDPR, for the following Service Purposes:
• entering into contracts for services provided by the Data Controller;
• fulfilling pre-contractual, contractual, and tax obligations arising from our existing relationship with you;
• compliance with obligations under the law, regulations, EU legislation, or an order from the Authority (such as those regarding anti-money laundering);
• exercise of the Data Controller’s rights, such as the right to defend itself in court;
Data and information are collected for the following purposes:
• exclusively in aggregated and anonymous form to verify the proper functioning of the website. None of this information is linked to the individual user of the website, and it does not allow for the user’s identification in any way (as of May 25, 2018, this information will be processed based on the data controller’s legitimate interests);
for security purposes (spam filters, firewalls, virus detection), the data automatically recorded may also include personal data such as the IP address, which could be used, in accordance with applicable laws, to block attempts to damage the site itself or harm other users, or otherwise engage in harmful or criminal activities. Such data is never used to identify or profile the user, nor is it cross-referenced with other data, nor provided to third parties, but is used solely for the purpose of protecting the site and its users (as of May 25, 2018, such information will be processed based on the legitimate interests of the data controller);
• disclose data to third parties that perform functions necessary or instrumental to the operation of the service, such as managing comments on the website.
The provision of data for the purposes described in this section is optional. You may therefore choose not to provide any data or subsequently withdraw consent to process data already provided: in such cases, you will not receive newsletters, commercial communications, or advertising material related to the Services offered by the Data Controller. You will, in any case, continue to be entitled to the Services referred to in the preceding section.

9. METHODS AND TIMEFRAMES FOR DATA PROCESSING
The processing of your personal data is carried out through the operations specified in Article 4(2) of the GDPR, namely: collection (including by electronic means), recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, disclosure, erasure, and destruction of data. Your personal data is processed both on paper and electronically and/or automatically.
The Data Controller will retain your data for as long as necessary to provide you with the aforementioned Services, as well as to the extent necessary to ensure compliance with legal obligations, resolve disputes, and ensure compliance with contractual agreements.
Once it is no longer necessary to process your data for the purposes of this Privacy Policy, it will be deleted from the Data Controller’s systems.
Where permitted, the Data Controller will delete the personal data collected at your request.
The specific destruction process and method to be used are as follows:
• Personal data printed on paper will be shredded, burned, pulverized, or incinerated;
• Personal data stored in electronic format will be deleted using technology designed to prevent the recovery of such data.

10. DISCLOSURE OF DATA WITHOUT CONSENT
The Data Controller may disclose your data for the purposes set forth in Article 6, paragraph 2, point A) above to supervisory bodies, judicial authorities, and insurance companies for the provision of insurance services, as well as to those entities to whom disclosure is required by law, for the purposes of fulfilling the aforementioned objectives.
Such entities will process the data in their capacity as independent Data Controllers.

11. RECIPIENTS OF PERSONAL DATA
The recipients of personal data are the parties to whom the data will be disclosed or shared, including for the purpose of providing the requested service.
The data will not be disclosed to any third party but will simply be viewed by the Data Controller.
Personal data is primarily stored on servers belonging to well-known companies specializing in web hosting and data centers that are considered reliable.

12. TRANSFER OF PERSONAL DATA TO THIRD COUNTRIES
The Data Controller, where deemed necessary, may relocate its servers—and thus the personal data contained therein—to third countries. In such cases, the Data Controller hereby guarantees that the transfer of data to third countries will be carried out in accordance with the provisions of Chapter V of the GDPR.

13. SAFETY
The IAT Pro Loco Office—Via C. Battisti 5, Santarcangelo di Romagna, VAT No. 03295400406—establishes and implements appropriate technical and organizational security measures to ensure a level of security commensurate with the risk, including, among others, where applicable:
1. the ability to ensure, on an ongoing basis, the confidentiality, integrity, availability, and resilience of processing systems and services;
2. the ability to promptly restore the availability of and access to personal data in the event of a physical or technical incident;
3. the implementation of periodic testing to regularly verify and assess the effectiveness of technical and organizational measures in order to ensure the security of the processing.
The Data Controller also establishes and implements appropriate technical and organizational measures designed to prevent the unauthorized or unlawful processing of personal data and to prevent the accidental and/or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data. Please note, however, that the Data Controller is unable to completely eliminate the security risks associated with the storage and transmission of personal data.
Links to Other Websites. This Privacy Policy does not apply to companies that are not owned or controlled by the Data Controller or to individuals not bound by an employment relationship with the Data Controller. The Data Controller’s Services may provide or involve a link, at your initiative, or otherwise provide access to third-party websites. Such links are provided solely for your convenience. The Data Controller therefore does not exercise any control over, nor does it review or assume responsibility for, third-party websites, their content, and/or any goods and/or services available through third-party websites. The Privacy Policy adopted by the Data Controller therefore does not apply to third-party websites or to the data provided to them, which you provide at your own risk. You are therefore encouraged to review the privacy policies of all third-party websites with which you interact.

14. RECORD OF PROCESSING ACTIVITIES
Pursuant to Article 30 of the GDPR, the Data Controller maintains a record of the processing activities carried out under its responsibility. This record contains all of the following information:
• the name and contact details of the data controller and, where applicable, of the joint controller, the data controller’s representative, and the data protection officer;
• the purposes of the processing;
• a description of the categories of data subjects and the categories of personal data;
• the categories of recipients to whom the personal data have been or will be disclosed, including recipients in third countries or international organizations;
• where applicable, transfers of personal data to a third country or an international organization, including the identification of the third country or international organization and, for transfers referred to in the second paragraph of Article 49 of the GDPR, documentation of the appropriate safeguards;
• where possible, the retention periods for the various categories of data;
• where possible, a general description of the technical and organizational security measures referred to in Article 32(1) of the GDPR.
The records are maintained in electronic format.
Under EU law, there is no obligation to maintain a record of processing activities for companies or organizations with fewer than 250 employees, unless: (i) the processing they carry out may pose a risk to your rights and freedoms; (ii) the processing is not occasional or involves the processing of special categories of data referred to in Article 9(1) of the GDPR, or personal data relating to criminal convictions and offenses referred to in Article 10.
IAT Pro Loco Office – Via C. Battisti 5, Santarcangelo di Romagna VAT No. 03295400406, not being subject to the obligation to maintain the aforementioned record of processing activities, has decided not to adopt a paper or electronic document that records the processing operations performed on your data, which would otherwise be available for consultation at the Data Controller’s registered and administrative office.

15. NOTIFICATION OF PERSONAL DATA BREACHES
Pursuant to Articles 33 and 34 of the GDPR, in the event of a personal data breach, the Data Controller shall:
• notify the competent supervisory authority of the breach without undue delay and within 72 hours of becoming aware of it;
• notify you of the breach without undue delay, if the breach is likely to result in a high risk to the rights and freedoms of natural persons. Under EU law, the aforementioned notification to you is not required if one of the following conditions is met: (i) the Data Controller has implemented appropriate technical and organizational security measures, and such measures were applied to the personal data subject to the breach, in particular those designed to render the personal data unintelligible to anyone not authorized to access it, such as encryption; (ii) the Data Controller has subsequently taken measures to prevent a high risk to the rights and freedoms of the data subjects referred to in paragraph 1; (iii) such notification would require disproportionate effort. In such a case, it is necessary to proceed by means of a public notice or similar measure, through which the data subjects are informed with equivalent effectiveness.

16. RIGHTS OF THE DATA SUBJECT
As a data subject, you are entitled to the rights set forth in the following articles of EU Regulation No. 2016/679, to which we refer you for the full text.
The aforementioned rights are briefly listed below:
• Right of access to personal data (Art. 15 GDPR): that is, the right to request confirmation as to whether or not your personal data is being processed, and to access your personal data and related information regarding such processing (e.g., the purposes of the processing or the categories of personal data concerned).
• Right to rectification (Art. 16 GDPR): the right to request the correction of personal data, to the extent permitted by law.
• Right to erasure (Art. 17 GDPR): the right to request the erasure of your personal data, to the extent permitted by law. This right may be exercised, among other things: (i) when the personal data is no longer necessary for the purposes for which it was collected or otherwise processed; (ii) when the consent on which the processing is based pursuant to Art. 6(1)(a) or Art. 9(2)(a) of the GDPR has been withdrawn and there is no other legal basis for the processing; (iii) when there is an objection to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or when there is an objection to the processing pursuant to Article 21(2) of the GDPR; or, (iv) when your personal data has been processed unlawfully.
• Right to restriction of processing (Art. 18 GDPR): the right to request that the Data Controller restrict the processing of your personal data when: (i) you contest the accuracy of the personal data, for the period necessary for the Data Controller to verify the accuracy of such personal data; (ii) the processing is unlawful and you oppose the erasure of the personal data and request instead that its use be restricted; (iii) although the Data Controller no longer needs the personal data for processing purposes, you require the personal data to establish, exercise, or defend a legal claim; (iv) you have objected to the processing pursuant to Article 21(1), pending verification as to whether the legitimate grounds of the Data Controller override your own.
• Right to data portability (Art. 20 GDPR): the right to receive the personal data provided to the Data Controller in a structured, commonly used, and machine-readable format, as well as the right, upon request, to have that data transmitted to another controller, including direct transmission, where technically feasible.
• Right to object (Art. 21 GDPR): the right to object to the processing of your personal data by the Data Controller, to the extent permitted by law. This right is limited to processing based on Article 6(1)(e) or (f) of the GDPR, including profiling based on those provisions, and processing for direct marketing purposes. Once exercised, the Data Controller will no longer process your personal data, unless there are valid and legitimate grounds for the processing that override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
• Automated decision-making, including profiling (Art. 22 GDPR): the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This right does not apply if the decision: (i) is necessary for the conclusion or performance of a contract between you and a data controller; (ii) is authorized by Union or Member State law to which the data controller is subject, which also lays down suitable measures to safeguard your rights, freedoms, and legitimate interests; (iii) is based on your explicit consent.

17. HOW TO EXERCISE YOUR RIGHTS
Please be advised that you may exercise the above rights at any time by submitting a written request via:
• Registered mail with return receipt to: Ufficio IAT Pro Loco – via C. Battisti 5, Santarcangelo di Romagna, VAT No. 03295400406;
• Email to: iat@comune.santarcangelo.rn.it
The Data Controller will process requests as soon as possible and, in any case, within the time limits set forth by law. Pursuant to the GDPR, and only in exceptional cases, the Data Controller may charge a fee for providing the service.

18. RIGHT TO FILE A COMPLAINT WITH THE SUPERVISORY AUTHORITY
We encourage you to contact the Data Controller directly so that we can work together to address your needs, questions, and concerns. However, if you believe that the processing of your personal data violates applicable data protection laws, you have the right to file a complaint with a competent data protection supervisory authority, specifically in the European Union member state where the alleged violation occurred.

19. NOTICE WHEN PERSONAL DATA HAS NOT BEEN OBTAINED DIRECTLY FROM THE DATA SUBJECT
If, pursuant to Article 14 of the GDPR, the Data Controller has collected your personal data from third parties, the Data Controller will provide you with all the information set forth in this Policy:
• within a reasonable period of time after obtaining the personal data, but no later than one month, taking into account the specific circumstances in which the personal data is processed;
• if the personal data is intended for communication with you, no later than the time of the first communication with you;
• If the data is to be disclosed to another recipient, no later than the first disclosure of the personal data.
If the Data Controller intends to further process your personal data for a purpose other than that for which it was collected, the Data Controller is required to provide you with information regarding that different purpose and any other relevant information prior to such further processing.
The above provisions do not apply if and to the extent that:
• You already have the information;
• Disclosing such information is impossible or would involve a disproportionate effort, as well as for the reasons specified in the relevant legislation, to which full reference is made.
• the collection or disclosure is expressly provided for by Union law or the law of the Member State to which the data controller is subject, and that law provides for appropriate measures to safeguard your legitimate interests;
• where the personal data must remain confidential in accordance with a professional secrecy obligation governed by Union law or the law of the Member States, including a statutory duty of confidentiality.

20. REFERENCE
For any matters not expressly covered or provided for in this policy, explicit reference is made to the aforementioned EU Regulation 2016/679, which is available at the facility in hard copy and at the following address: https://eur-lex.europa.eu/legal-content/IT/TXT/? uri=uriserv:OJ.L_.2016.119.01.0001.01.ITA&toc=OJ:L:2016:119:TOC and, where applicable, to current legislation and the relevant implementing decrees.