Privacy Policy

Information on the processing of personal data

of users who consult the Italy Travel Plan website pursuant to Article 13 of Regulation (EU) 2016/679.

WHY THIS INFORMATION

Pursuant to Regulation (EU) 2016/679 (hereinafter “GDPR”), this page describes the methods of processing the personal data of users who consult the Italy Travel Plan website (hereinafter “Italy Travel Plan” or the “Company”), accessible online at the following address: https://italytravelplan.com/.

DATA CONTROLLER

Following consultation of the website indicated above, data relating to identified or identifiable natural persons may be processed.
The Data Controller is Gaia Vicamini (e-mail address: gaia@italytravelplan.com) (hereinafter also the “Controller”).
The Controller has not appointed a Data Protection Officer (“DPO”), as such appointment is not mandatory under the GDPR.

LEGAL BASIS OF THE PROCESSING

The legal basis of the processing is the legitimate interest of the Data Controller (Art. 6, par. 1, lett. f) GDPR) in managing and protecting its website.

TYPES OF DATA PROCESSED AND PURPOSES OF PROCESSING

Data provided by the user
The optional, explicit, and voluntary sending of messages to the Company’s contact addresses, as well as private messages sent by users to the Company’s institutional profiles/pages on social media (where such option is available), entails the acquisition of the sender’s contact details, necessary to provide a reply, as well as any personal data included in the communications.

Browsing data
The computer systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.
This category of data includes IP addresses or domain names of computers and terminals used by users, URI/URL (Uniform Resource Identifier/Locator) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (successful outcome, error, etc.), and other parameters relating to the user’s operating system and IT environment.

These data, necessary for the use of web services, are also processed in order to:

  • obtain statistical information on the use of services (most visited pages, number of visitors by time slot or day, geographical areas of origin, etc.);
  • check the proper functioning of the services offered.

SECURITY MEASURES

The Controller complies with the provisions on security in order to avoid the loss, destruction, or modification of users’ data, unauthorized disclosure, or unauthorized access, and has adopted appropriate security measures and procedures to protect users’ personal data.

DATA RECIPIENTS

The data collected following consultation of the Company’s website may be communicated to the following parties:

  • Company staff,
  • suppliers (e.g. web hosting company, companies managing maintenance and updating of the website).

These parties will process personal data, depending on the case, as Persons Authorized to process, Data Processors, or System Administrators appointed in accordance with the law, also with regard to security measures protecting your data. Your data will not be disclosed.

TRANSFER OF PERSONAL DATA ABROAD

Your personal data will be stored electronically:

  • (i) (web hosting) on the servers of Lyrical Host, located in the United Kingdom;
  • (ii) (Google Analytics) by Google LLC, which operates servers also outside the European Union.

With regard to this latter transfer, the contractual safeguards provided by Google apply, in particular the use of standard contractual clauses adopted or approved by the European Commission (Art. 46, par. 2, lett. c) and d) GDPR).

RIGHTS OF DATA SUBJECTS

Data subjects have the right to obtain from the Company, in the cases provided, access to their personal data and the rectification or erasure of such data, or the restriction of processing concerning them, or to object to the processing (Arts. 15 et seq. GDPR).
Data subjects who consider that the processing of their personal data carried out through this website is in violation of the GDPR have the right to lodge a complaint with the Data Protection Authority, pursuant to Art. 77 GDPR, or to seek judicial remedies (Art. 79 GDPR).

THIRD-PARTY WEBSITES AND SERVICES

This website may contain links to external websites. If you use such links, please note that this Privacy Policy does not apply to external websites and that the Company does not control such websites. You are therefore encouraged to read the privacy policies applicable to those external websites.

AMENDMENTS TO THIS PRIVACY POLICY

The contents of this Privacy Policy must be regularly adapted to meet legal requirements. We reserve the right to make changes at any time. The valid version will always be published on this page of our website. We invite you to consult this Privacy Policy regularly when visiting our website. The full text of the referenced legislation can be found at www.garanteprivacy.it.