Right of access (Art. 15)
To obtain confirmation as to whether or not your data is being processed and, if so, to obtain access to that data and to all the information required by law.
Notice on the processing of personal data under Articles 13 and 14 of EU Regulation 2016/679 (GDPR)
Note for non-Italian readers. This is an English translation of the privacy policy provided for your convenience. The official version is published in Italian, as required by Italian and EU data-protection law (GDPR, Italian Privacy Code), and the Italian version is the legally authoritative text. For any clarification, please contact [email protected].
This Privacy Notice describes how the Palio dei Terzieri di Città della Pieve Association (hereinafter also "the Controller", "the Association" or "we") processes the personal data of users who visit the website www.paliodeiterzieri.it (hereinafter "the Site") or who otherwise interact with the Association.
This Notice has been drawn up in compliance with Regulation (EU) 2016/679 (hereinafter "GDPR"), Legislative Decree no. 196 of 30 June 2003 (the "Privacy Code") as amended by Legislative Decree 101/2018, Directive 2002/58/EC ("ePrivacy") and the measures of the Garante per la protezione dei dati personali (the Italian Data Protection Authority), in particular the Guidelines on cookies and other tracking tools of 10 June 2021.
Associazione Palio dei Terzieri di Città della Pieve
Registered office: Piazza G. Matteotti, La Rocca — 06062 Città della Pieve (PG), Italy
Tax code / VAT no.: 94039150548
Email: [email protected]
Telephone: +39 0578 298840
Certified email (PEC): [email protected]
For any request relating to the processing of personal data, the exercise of your rights or any report, you may contact the Controller using the details set out above. The Controller will respond within 30 days of receiving the request, save for a justified extension of up to 60 days in the cases provided for by Article 12 of the GDPR.
Given the purposes of the processing and the volume of data managed, the Association is not among the entities required to appoint a Data Protection Officer (DPO) under Article 37 of the GDPR. You may nonetheless contact the Controller regarding any matter relating to the protection of personal data.
The Controller may process the following categories of personal data:
The computer systems and software procedures used to operate the Site acquire, in the course of their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected in order to be associated with identified data subjects, but which by its very nature could, through processing and association with data held by third parties, make it possible to identify users.
This category includes:
This data is used for the sole purpose of obtaining anonymous statistical information on the use of the Site and to monitor its correct operation. The data may be used to establish liability in the event of any hypothetical computer offences committed against the Site or third parties.
The optional, explicit and voluntary sending of messages to the Association's contact details (email, contact form, telephone), as well as the completion and submission of the forms available on the Site, entails the acquisition of the sender's contact details, which are necessary to respond, as well as of all personal data included in the communications.
In particular, the Association may collect:
Specific summary notices may be reported or displayed on the pages of the Site set up for particular services provided on request.
For detailed information on the cookies used by the Site, on the purpose of each one and on how consent is managed, please refer to the Cookie Policy and to the consent management banner, which can be accessed at any time via the "Manage cookies" button in the footer of the Site.
The Site provides a conversational virtual assistant, accessible via a chat icon present on the pages of the Site, intended to give the user information about the Palio dei Terzieri (events, taverns, news, practical information). The assistant is built using the Claude artificial intelligence model developed by Anthropic PBC (with its registered office in the United States of America), which acts as a Data Processor pursuant to Article 28 of the GDPR.
In connection with the use of the virtual assistant, the following data is processed:
Conversations with the virtual assistant are not associated with any personal identifier (name, email, account) and are not stored persistently on the Controller's servers. The conversation history is kept solely in the user's browser, within the current session, and is lost when the tab is closed. Anthropic, as the provider of the model, temporarily retains the transmitted data solely for the provision of the service and for security purposes (for a period not exceeding 30 days), without using it to train its own models, as provided for by the commercial terms entered into by the Controller.
For statistical purposes, for each question put to the assistant the Controller records only an automatically assigned topic category (for example: programme, taverns, tickets, getting here), the language of the page and the date and time. The text of the messages is not retained, nor is the IP address or any session or device identifier: this is aggregated data that cannot be traced back to the user, used to understand which information is most in demand and to improve the content of the Site. This statistical data is retained for a maximum of 24 months.
Users are asked not to enter into the chat any sensitive personal data, identifying details of third parties or confidential information. The virtual assistant provides responses for informational purposes and is in no way a substitute for direct contact with the Association for formal requests, the exercise of rights or matters of an administrative nature.
The use of the virtual assistant does not constitute automated decision-making producing legal effects within the meaning of Article 22 of the GDPR: it is solely a tool for providing information.
The Site has a restricted area, accessible exclusively by means of credentials, used by the Association's staff and by the representatives of the three Terzieri (Castello, Casalino, Borgo Dentro) to independently update the published content (news, event programme, tavern information and the evening's menu).
In connection with this area, the following data is processed:
The email notification service is provided by Resend, Inc., acting as a Data Processor (see section 7). The data relating to the restricted area is accessible exclusively to the natural persons authorised by the Controller and in no way concerns ordinary visitors to the Site.
Personal data is processed for the following purposes:
| Purpose | Lawful basis (Art. 6 GDPR) | Data concerned |
|---|---|---|
| Operation and use of the Site (technical cookies, system logs) | Art. 6.1.f — the Controller's legitimate interest in ensuring the security and operation of the Site | Browsing data |
| Responding to requests, reports or communications sent by the user | Art. 6.1.b — performance of pre-contractual measures at the data subject's request | Name, email, telephone, content of the communication |
| Compliance with legal obligations (tax, accounting, administrative) | Art. 6.1.c — compliance with a legal obligation | Identification and accounting data |
| Aggregate statistical measurements on the use of the Site (anonymised analytics) | Art. 6.1.f — legitimate interest, or Art. 6.1.a where consent is required | Browsing data, cookie identifiers |
| Sending informational communications about the Association's initiatives (e.g. newsletter) | Art. 6.1.a — explicit consent | Email, name |
| Provision of the virtual assistant service (AI chatbot) to visitors of the Site | Art. 6.1.f — the Controller's legitimate interest in providing a better information service to users | Content of the messages exchanged with the assistant, IP address (rate limiting) |
| Managing access to the restricted area and updating the content of the Site | Art. 6.1.f — the Controller's legitimate interest in ensuring the security and proper administration of the Site | Credentials, session identifiers, access logs, IP, notification emails |
| Defence of the Controller's rights in legal proceedings | Art. 6.1.f — legitimate interest | All data collected, where necessary |
The provision of data for the purposes referred to in points 1, 2 and 3 of the table is necessary in order to access the Site or to obtain a response to your requests; refusal makes it impossible to provide the service. The provision of data for the other purposes is optional, and any refusal does not affect the use of the Site.
Personal data is processed using electronic and paper-based tools, in accordance with the principles of lawfulness, fairness and transparency laid down by Article 5 of the GDPR. Technical and organisational measures are adopted that are adequate to ensure a level of security appropriate to the risk, in particular:
Processing is carried out exclusively by staff authorised by the Controller and duly instructed pursuant to Article 29 of the GDPR and Article 2-quaterdecies of the Privacy Code.
Personal data is retained for no longer than is strictly necessary to achieve the purposes for which it was collected, in accordance with the principle of storage limitation (Art. 5.1.e GDPR). Specifically:
At the end of the retention period, the data will be deleted or irreversibly anonymised, save for retention obligations laid down by law.
Personal data may be disclosed to third parties acting as Data Processors pursuant to Article 28 of the GDPR, duly appointed by means of a dedicated contract. In particular:
The complete and up-to-date list of Data Processors is available on written request to the Controller. Personal data will under no circumstances be disseminated or disclosed to parties other than those indicated, save for the data subject's express consent or specific legal obligations.
The Controller favours service providers with servers located within the European Economic Area. Should a transfer of data to third countries (outside the EEA) become necessary, the transfer will take place exclusively to countries that the European Commission has recognised as providing an adequate level of protection (adequacy decisions pursuant to Article 45 GDPR) or, failing that, on the basis of appropriate safeguards such as the Standard Contractual Clauses approved by the European Commission (Art. 46.2.c GDPR).
In particular, some providers used by the Site (e.g. font services, JavaScript libraries from public CDNs) may involve transfers to the United States. For such processing, the Controller verifies that transfer mechanisms compliant with the GDPR are in place, including the EU–U.S. Data Privacy Framework.
With regard to the services described in sections 3.4 and 3.5 of this Notice, it should be noted in particular that:
As a data subject, you have the right to exercise at any time the rights provided for by Articles 15-22 of the GDPR. In particular:
To obtain confirmation as to whether or not your data is being processed and, if so, to obtain access to that data and to all the information required by law.
To obtain the rectification of inaccurate data or the completion of incomplete data, including by providing a supplementary statement.
To obtain the erasure ("right to be forgotten") of your data in the cases provided for by law, for example where the data is no longer necessary for the purposes for which it was collected.
To obtain the restriction of processing, for example while the accuracy of the data is being verified.
To receive the personal data you have provided in a structured, commonly used and machine-readable format, and to transmit it to another controller without hindrance.
To object at any time to the processing of personal data carried out on the basis of legitimate interest, on grounds relating to your particular situation.
To withdraw at any time the consent you have given, without affecting the lawfulness of the processing based on consent before its withdrawal.
Not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject.
The exercise of these rights is free of charge, and requests may be submitted to the Controller using the details indicated in point 1. The Controller will respond within 30 days, in accordance with Article 12 of the GDPR.
Pursuant to Article 77 of the GDPR, any data subject who believes that the processing of their personal data is carried out in breach of the applicable legislation has the right to lodge a complaint with the competent supervisory authority, which in Italy is the:
Garante per la protezione dei dati personali (Italian Data Protection Authority)
Piazza Venezia n. 11 — 00187 Rome
Switchboard: +39 06 696771
Email: [email protected]
Certified email (PEC): [email protected]
Website: www.garanteprivacy.it
The right to bring an action before the competent judicial authority, pursuant to Article 79 of the GDPR, remains unaffected.
The Site is not intended for an audience of minors under 14 years of age, and the Association does not knowingly collect personal data of persons below that age. Should it become aware that data relating to a minor under 14 has been acquired without the consent of the holder of parental responsibility, such data will be promptly deleted. Parents who believe that their children have provided personal data to the Controller are asked to contact the details indicated in point 1.
In accordance with Articles 33 and 34 of the GDPR, should a personal data breach occur that presents a risk to the rights and freedoms of data subjects, the Controller will notify the breach to the supervisory authority within 72 hours of becoming aware of it. Where the breach presents a high risk to the rights and freedoms of data subjects, the Controller will also promptly communicate the breach to the data subjects themselves, providing the information required by law.
The Site may contain links to third-party websites (for example: social media pages, service providers, partners). The Controller is not responsible for the privacy practices of such sites, which operate independently. Before interacting with such sites, users are encouraged to read their respective privacy notices carefully.
The Controller reserves the right to amend this Notice at any time, giving notice to users via the Site. You are therefore asked to consult this page regularly, referring to the "last revised" date indicated at the top. In the event of material changes to this Notice, these will be communicated prominently on the Site or, where possible, directly to the data subjects for whom the Controller holds a contact.
For any matter, request or report relating to this Notice or to the processing of personal data, you may contact the Controller using the details indicated in point 1 or, alternatively, by writing to [email protected] with the subject line "Privacy — request to exercise rights".