Privacy Policy
Privacy Policy of www.museocivicoarcheologiconoto.eu
This website collects certain Personal Data of its Users.
This document can be printed by using the print command in the settings of any browser.
Data Controll
Città di Noto, Assessorato alla Cultura, Settore 8° / Servizio 3° – Biblioteca comunale e Musei, Siti e Ufficio UNESCO
P.zza Municipio, 1, 96017 Noto (SR) – Italy
Holder’s email address: biblioteca@comune.noto.sr.it
Types of Data Collected
Among the Personal Data collected by this website, either independently or through third parties, are: Tracking Tool; Usage Data; first name; last name; telephone number; email.
Full details on each type of data collected are provided in the dedicated sections of this privacy policy or by means of specific information texts displayed prior to the collection of such data.
Personal Data may be freely provided by the User or, in the case of User Data, automatically collected during the use of this website.
Unless otherwise specified, all Data requested by this website are mandatory. If the User refuses to provide it, it may be impossible for this website to provide the Service Where this website indicates certain Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or its operation.
Users in doubt as to which Data are mandatory are encouraged to contact the Data Controller.
Any use of Cookies – or of other tracking tools – by this website or by the owners of third party services used by this website, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this website and warrants that he/she has the right to communicate or disseminate them, releasing the Owner from any liability towards third parties.
Method and place of processing of collected Data
Modalities of processing
The Data Controller adopts appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of Personal Data.
The processing is carried out using computer and/or telematic tools, with organisational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other subjects involved in the organisation of this website (administrative, sales, marketing, legal, system administrators) or external subjects (such as third party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, Data Processors by the Data Controller, may have access to the Data. The updated list of Data Processors can always be requested from the Data Controller
Legal basis of the processing
The Data Controller processes Personal Data relating to the User where one of the following conditions exists:
-
the User has given consent for one or more specific purposes. Note: in some jurisdictions, the Controller may be allowed to process Personal Data without the User’s consent or another of the legal bases specified below, until the User objects (“opts out”) of such processing. However, this does not apply if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
-
processing is necessary for the performance of a contract with the User and/or the performance of pre-contractual measures;
-
processing is necessary for the performance of a legal obligation to which the Controller is subject;
-
processing is necessary for the performance of a task carried out in the public interest or in the exercise of public authority vested in the Controller;
-
processing is necessary for the pursuit of the legitimate interest of the Controller or of third parties..
However, it is always possible to request the Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on law, required by a contract or necessary to conclude a contract.
Place
The Data are processed at the Data Controller’s operational headquarters and in any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the country in which the User is located To obtain further information on the location of the processing, the User may refer to the section on Personal Data processing details.
The User has the right to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organisation under public international law or consisting of two or more countries, such as the UN, as well as about the security measures taken by the Controller to protect the Data.
The User may verify whether one of the transfers just described takes place by examining the section of this document relating to details on the processing of Personal Data or request information from the Controller by contacting it at the contact details given at the beginning.
Retention period
Data are processed and stored for the time required by the purposes for which they were collected.
Therefore: :
Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the performance of such contract is completed.
Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.
When the processing is based on the User’s consent, the Data Controller may keep the Personal Data longer until such consent is revoked. Moreover, the Controller may be obliged to keep the Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period the Personal Data will be deleted. Therefore, at the end of this period, the right of access, cancellation, rectification and the right to Data portability can no longer be exercised.
Purposes of the Data collected
The User’s Data are collected to enable the Data Controller to provide the Service, to comply with legal obligations, to respond to requests or enforcement actions, to protect its rights and interests (or those of Users or third parties), to identify possible fraudulent or malicious activities, as well as for the following purposes: Statistics, Tag Management, Interaction with social networks and external platforms and Contacting the User.
To obtain detailed information on the purposes of the processing and on the Personal Data processed for each purpose, the User may refer to the section “Personal Data Processing Details”.
Details of Personal Data Processing
Personal Data are collected for the following purposes and using the following services:
-
contacting the user
contact form on this website. The User, by filling in the contact form with his/her Data, consents to the use of such Data in order to reply to requests for information, quotes, or of any other nature indicated in the header of the form.
Personal Data processed: surname; email; name; telephone number.
-
tag management
This type of service is functional for the centralised management of tags or scripts used on this website.
The use of these services entails the flow of the User’s Data through them and, where appropriate, their retention.
Google Tag Manager (Google Ireland Limited)
Google Tag Manager is a tag management service provided by Google Ireland Limited.
Personal Data processed: Usage Data.
Place of processing: Ireland – Privacy Policy.
-
Interaction with social networks and external platforms:
This type of service allows for interactions with social networks, or other external platforms, directly from the pages of this website.
Interactions and information collected by this website are in each case subject to the User’s privacy settings for each social network.
This type of service may still collect traffic data for the pages where the service is installed, even when Users do not use it.
It is recommended to disconnect from the respective services to ensure that the data processed on this website is not linked back to the User’s profile.
Facebook Like button and social widgets (Facebook Ireland Ltd)
The Facebook “Like” button and social widgets are services for interaction with the social network Facebook, provided by Facebook Ireland Ltd
Personal data processed: Usage Data; Tracking Tool.
Place of processing: Ireland – Privacy Policy.
-
Statistics
The services contained in this section allow the Data Controller to monitor and analyse traffic data and serve to keep track of the User’s behaviour.
Google Analytics (Google Ireland Limited)
Google Analytics is a web analysis service provided by Google Ireland Limited (“Google”). Google uses the Personal Data collected for the purpose of evaluating your use of this website, compiling reports on website activity for website operators and sharing them with other services provided by Google.
Google may use the Personal Data to contextualise and personalise the ads on its advertising network.
Personal data processed: Usage Data; Tracking Tool.
Personal Data processed: Usage Data; Tracking Tool.
-
Payment management
Unless otherwise specified, this Website processes all payments by credit card, bank transfer or other means through external payment service providers. In general, and unless otherwise stated, Users are requested to provide payment details and personal information directly to such payment service providers. This Website is not involved in the collection and processing of such information: instead, it will only receive a notification from the relevant payment service provider about the successful payment.
STRIPE (STRIPE)
Stripe is a payment service provided by Stripe Inc., which allows the User to make online payments.
Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: Consult the Stripe privacy policy – Privacy Policy.
User Rights
Users may exercise certain rights with reference to the Data processed by the Data Controller.
In particular, the User has the right to
-
revoke consent at any time. The User may revoke the consent to the processing of its Personal Data previously expressed;
-
object to the processing of their Data. The User may object to the processing of its Data when it is done on a legal basis other than consent. Further details on the right to object are set out in the section below;
-
access to their Data. The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing and to receive a copy of the Data processed.
-
verify and request rectification. The User may verify the correctness of its Data and request that it be updated or corrected;
-
obtain the restriction of the processing. When certain conditions are met, the User may request the restriction of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its preservation;
-
obtain the deletion or removal of their Personal Data. When certain conditions are met, the User may request the deletion of its Data by the Data Controller;
-
receive their Data or have them transferred to another Data Controller. The User has the right to receive its Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another data controller. This provision is applicable when the Data are processed by automated means and the processing is based on the User’s consent, on a contract to which the User is party or on contractual measures related thereto;
-
Propose a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.