Privacy policy

The “Cammino di San Cristoforo” App requires access to the position in the background so that the device can keep track of the user’s position on the routes and warn him/her if he/she strays from the track even when the App is closed.

 

Data Controller
In the person of the Legal Representative of ItinerAria, Alberto Conte
Owner’s email address: info@itineraria.eu

 

Types of Data collected
Among the Personal Data collected by this site, independently or through third parties, are: Cookies and Usage Data.
Full details on each type of data collected are provided in the dedicated sections of this privacy policy or by means of specific information texts displayed before the data is collected.
Personal Data can be freely provided by the User.
Users in doubt as to which Data are mandatory are encouraged to contact the Data Controller.
The possible use of Cookies – or of other tracking tools – by this Site or by the owners of third party services used by this Site, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Site and warrants that he/she has the right to communicate or disseminate them, releasing the Owner from any liability towards third parties.

 

MODALITIES AND PLACE OF DATA PROCESSING
Processing methods
The Data Controller adopts appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of Personal Data.
The processing is carried out using computer and/or telematic tools, with organisational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other subjects involved in the organisation of this Web Site may have access to the Data if necessary (administrative, commercial, marketing, legal personnel, system administrators), who are Data Processors on the part of the Data Controller. The updated list of Data Processors can always be requested from the Data Controller.


Legal basis of the processing

The Controller processes Personal Data relating to the User if one of the following conditions is met
– the User has given consent for one or more specific purposes; Note: in some jurisdictions, the Controller may be authorised to process Personal Data without the User’s consent or another of the legal bases specified below, until the User objects (“opts-out”) to such processing. However, this does not apply if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
– processing is necessary for the performance of a contract with the User and/or the performance of pre-contractual measures;
– processing is necessary for the performance of a legal obligation to which the Controller is subject;
– processing is necessary for the performance of a task carried out in the public interest or in the exercise of public authority vested in the Controller;
– processing is necessary for the pursuit of the legitimate interest of the Controller or of third parties.
However, it is always possible to ask the Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on law, provided for by a contract or necessary to conclude a contract.

 

Location
The Data are processed at the Data Controller’s premises and at any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one where the User is located. To obtain further information on the location of the processing, the User may refer to the section on Personal Data processing details.
The User has the right to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organisation under public international law or consisting of two or more countries, such as the UN, as well as about the security measures taken by the Controller to protect the Data.
Should one of the transfers just described take place, the User may refer to the respective sections of this document or request information from the Data Controller by contacting it at the contact details given at the beginning.

 

Retention period
Data is processed and kept for the time required by the purposes for which it was collected.
Therefore, Personal Data collected for purposes attributable to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.
When the processing is based on the User’s consent, the Data Controller may keep the Personal Data longer until such consent is revoked. Moreover, the Controller may be obliged to keep the Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period the Personal Data will be deleted. Therefore, after the expiration of this period, the right of access, deletion, rectification and the right to Data portability can no longer be exercised.

 

Purposes of the Data collected
The User’s Data are collected to allow the Data Controller to provide its Services.
To obtain further detailed information on the purposes of the processing and the Personal Data concretely relevant for each purpose, the User may refer to the relevant sections of this document.
Details of Personal Data processing
Personal Data are collected for the following purposes and using the following services:
Contacting the User
Mailing list or newsletter (this Website)
By registering to the mailing list or newsletter, the User’s email address is automatically added to a list of contacts to whom email messages may be sent containing information, including of a commercial and promotional nature, relating to this Website. The User’s email address may also be added to this list as a result of registering on this Website or after making a purchase.
Personal data collected: surname, email and first name.
Contact form (this Website)
The User, by filling in the contact form with his/her Data, consents to their use to answer requests for information or of any other nature indicated in the header of the form.
Personal Data collected: surname, email, first name and telephone number.

 

Tag management
This type of services is functional for the centralised management of tags or scripts used on this Website.
The use of these services entails the flow of the User’s Data through them and, where appropriate, their retention.

 

User Rights
Users may exercise certain rights with reference to the Data processed by the Data Controller.
In particular, the User has the right to
– withdraw consent at any time. The User may revoke the consent to the processing of its Personal Data previously expressed.
– object to the processing of their Data. The User may object to the processing of its Data when it is done on a legal basis other than consent. Further details on the right to object are set out in the section below.
– access to their Data. The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing and to receive a copy of the Data processed.
– verify and request rectification. The User may verify the correctness of its Data and request that it be updated or corrected.
– obtain the restriction of the processing. When certain conditions are met, the User may request the restriction of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its preservation.
– obtain the deletion or removal of their Personal Data. When certain conditions are met, the User may request the deletion of its Data by the Data Controller.

– receive their Data or have them transferred to another data controller. The User has the right to receive his or her Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another controller. This provision is applicable when the Data are processed by automated means and the processing is based on the User’s consent, on a contract to which the User is party or on contractual measures related thereto.
– Proposing a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.

 

Details of the right to object
Where Personal Data are processed in the public interest, in the exercise of public authority vested in the Controller or in pursuit of a legitimate interest of the Controller, Users have the right to object to the processing on grounds relating to their particular situation.
Users are reminded that if their Data are processed for direct marketing purposes, they may object to the processing without giving any reason. To find out whether the Controller processes Data for direct marketing purposes, Users may refer to the respective sections of this document.


How to exercise rights
To exercise their rights, Users may address a request to the contact details of the Controller indicated in this document. Requests are filed free of charge and processed by the Controller as soon as possible, in any case within one month.


Cookie Policy
This Website makes use of Cookies. To find out more and to view the detailed information, the User can consult the Cookie Policy.

 

FURTHER INFORMATION ON TREATMENT
Legal defence
The User’s Personal Data may be used by the Data Controller in legal proceedings or in the preparatory phases of such proceedings to defend against abuses in the use of this Website or related Services by the User.
The User declares that he/she is aware that the Data Controller may be obliged to disclose the Data by order of public authorities.


Specific disclosures
At the User’s request, in addition to the information contained in this privacy policy, this Web Site may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.


Information not contained in this policy
Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

 

Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by informing Users on this page and, if possible, on this Website as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details held by the Data Controller. Please therefore consult this page regularly, referring to the date of last modification indicated at the bottom.
In the event that the changes affect processing whose legal basis is consent, the Controller will collect the User’s consent again, if necessary.


Definitions and legal references
Personal data (or Data)
Personal data is any information that, directly or indirectly, even in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.

 

Usage Data
This is the information collected automatically through this Website (including by third party applications integrated into this Website), including: IP addresses or domain names of the computers used by the User who connects with this Website, URI (Uniform Resource Identifier) notation addresses, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various time connotations of the visit (e.g. time spent on each page) and details of the itinerary of the visit (e.g. time spent on each page) and the time spent on the website. ) the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (e.g. the length of time spent on each page) and the details of the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the operating system and the User’s IT environment.


User
The individual who uses this Website which, unless otherwise specified, coincides with the Data Subject.


Data Subject
The natural person to whom the Personal Data refers.

 

Data Controller (or Processor)
The natural person, legal entity, public administration and any other entity that processes personal data on behalf of the Controller, as set out in this privacy policy.


Data Controller (or Owner)
The natural or legal person, public authority, service or other body that, individually or jointly with others, determines the purposes and means of the processing of personal data and the instruments adopted, including the security measures relating to the operation and use of this Web Site. The Data Controller, unless otherwise specified, is the owner of this Web Site.


This Web Site
The hardware or software tool through which Users’ Personal Data are collected and processed.


Service
The Service provided by this Website as defined in the relevant terms (if any) on this Website.


European Union (or EU)
Unless otherwise specified, any reference in this document to the European Union shall be deemed to include all current member states of the European Union and the European Economic Area.

 

Cookie
Small piece of data stored within the User’s device.


Legal references
This Privacy Policy is drafted on the basis of multiple legislative orders, including Articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy policy relates exclusively to this Website.


Alberto Conte
Legal Representative of ItinerAria