INFORMATION NOTICE
pursuant to Articles 13 and 14 of EU Regulation 2016/679 (GDPR)
Website calabriaturistica.it and Mobile Application Calabria Turistica
Version 1.0 — Last updated: June 2025
Art. 1 – Data Controller
The Data Controller, within the meaning of Article 4(7) of EU Regulation 2016/679 (hereinafter “GDPR”), is:
Pro Loco Lamezia Terme
VAT No: 03060150798 | Tax Code.: 92013130791
Registered office: Via Calleri, 8 – 88046 Lamezia Terme (CZ)
Email: info@prolocolameziaterme.it
The Data Controller has not appointed a Data Protection Officer (DPO), as the conditions set out in Article 37 GDPR are not met. For any matter relating to the processing of personal data, data subjects may contact the Data Controller at the e-mail address indicated above.
Art. 2 – Scope of Application
This Privacy Policy describes how the Data Controller collects and processes the personal data of users who access the website calabriaturistica.it (hereinafter “Website”) and the mobile application Calabria Turistica (hereinafter “App”), available for iOS and Android devices. The Website and the App constitute a portal dedicated to the discovery and promotion of the Calabrian territory, offering information on itineraries, experiences, events and tourist services.
This Privacy Policy applies exclusively to the Website and the App indicated above and does not apply to third-party websites or applications that may be reached through links contained therein.
Art. 3 – Data Processed, Purposes and Legal Bases
3.1 Navigation data and technical data
The IT systems and software procedures used to operate the Website and the App automatically acquire, in the course of their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified.
This category includes IP addresses or domain names of computers and terminals used by users, URI/URL (Uniform Resource Identifier/Locator) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numeric code indicating the status of the server’s response, and other parameters relating to the user’s operating system and computing environment.
Such data are used solely to obtain anonymous statistical information on the use of the Website and the App, to monitor their correct operation and to identify anomalies or abuses. The data may be used to establish liability in the event of hypothetical computer crimes against the Website or the App.
Legal basis: legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR in the correct technical management and security of the platforms.
3.2 Data voluntarily provided by the user — Account Registration
The Website and the App offer users the entirely voluntary and optional possibility of creating a personal account. Upon registration, users are asked to provide the following data:
- First name
- Last name
- E-mail address
Such data are processed for the following purposes:
- Creation and management of the user account, authentication and access to reserved services;
- Enabling tourist and hospitality operators registered on the platform to list and manage their business on the portal, upon payment of the relevant fee via PayPal;
- Service communications relating to the account (e.g. registration confirmation, password recovery).
Legal basis: performance of a contract or pre-contractual measures taken at the request of the data subject, pursuant to Article 6(1)(b) GDPR. For service communications: legitimate interest pursuant to Article 6(1)(f) GDPR.
Provision of registration data is voluntary; however, failure to provide such data will make it impossible to access services reserved for registered users. Use of the Website and the App in anonymous (unauthenticated) mode remains available in any case.
3.3 Payment data — PayPal
Payment transactions for the listing of tourist and hospitality businesses on the portal are managed exclusively through PayPal, a service provided by PayPal Holdings, Inc. The Data Controller does not directly collect or store data relating to credit cards, bank accounts or other payment instruments. The processing of payment data is governed exclusively by PayPal’s Privacy Policy, available at www.paypal.com/en/webapps/mpp/ua/privacy-full. Users are advised to review it before making any transaction.
Legal basis: performance of a contract pursuant to Article 6(1)(b) GDPR.
3.4 Geolocation data (App)
The App, upon explicit consent granted by the user through the appropriate dialogue windows of the operating system (iOS / Android), may access the geolocation data of the device. This feature is used to show the user points of interest, accommodation facilities, events and services located near their geographical position, enhancing the experience of exploring the Calabrian territory.
Location data are collected exclusively when the App is in active use in the foreground, unless the user expressly grants background access. The user may revoke geolocation permission at any time from their device settings, without prejudice to their ability to continue using the other functions of the App.
Legal basis: consent of the data subject pursuant to Article 6(1)(a) GDPR. Consent may be freely withdrawn at any time.
3.5 Push Notifications (App)
Subject to user consent, the App may send push notifications to the device. Such notifications are used to inform users of relevant updates, new content, upcoming events in the area or service communications relating to the App.
The user may disable push notifications at any time from their device settings or within the App, without prejudice to the use of the remaining features.
Legal basis: consent of the data subject pursuant to Article 6(1)(a) GDPR.
3.6 Data stored locally on the device (cache)
The App temporarily stores certain navigation data locally on the user’s device (cache), in order to ensure a smooth user experience even in conditions of limited connectivity and to reduce content loading times. Such data do not contain sensitive information and are automatically overwritten or deleted in the course of normal App use. The user may manually clear the cache from their device or App settings at any time.
Legal basis: legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR in the efficient delivery of the service.
Art. 4 – Cookies and Tracking Technologies
The Website uses cookies and similar tracking technologies. The Data Controller has implemented a consent management system through the CookieHub platform, which allows users to accept or decline, in a granular manner, the different categories of cookies upon first access to the Website, and to modify their preferences at any time.
The categories of cookies used are set out below:
4.1 Technical and functional cookies (always active)
These are cookies strictly necessary for the operation of the Website and the delivery of the service requested by the user. They include session cookies for account authentication management, cookies of the CookieHub consent management system, and cookies necessary for the correct display of pages. These cookies do not require consent as they are strictly necessary pursuant to the applicable national legislation implementing Article 5(3) of Directive 2002/58/EC.
4.2 Analytical cookies — Google Analytics 4
The Website uses Google Analytics 4 (GA4), a statistical analysis service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics collects data relating to how the Website is used (pages visited, time spent, aggregated geographical origin, devices used, etc.) for the purpose of analysing traffic and improving the content and services offered. The Data Controller has enabled the IP address anonymisation feature. Data collected by Google Analytics may be transferred to the United States; Google adheres to the EU-US Data Privacy Framework, providing adequate safeguards pursuant to Article 46 GDPR.
Google Analytics is connected to Google Search Console in order to integrate traffic data with information relating to the Website’s performance in Google’s organic search results.
Legal basis: consent of the data subject pursuant to Article 6(1)(a) GDPR, obtained through CookieHub.
4.3 Google Maps
The Website integrates the Google Maps service, provided by Google Ireland Limited, to display the precise geographical location of accommodation facilities, services and events listed on the portal. Loading the Google Maps widget involves the transfer of technical data (including the user’s IP address) to Google’s servers. This service is subject to Google’s Privacy Policy, available at policies.google.com/privacy.
Legal basis: consent of the data subject pursuant to Article 6(1)(a) GDPR, obtained through CookieHub; legitimate interest of the Data Controller in providing the geolocation feature for content.
4.4 Google reCAPTCHA
The Website uses the Google reCAPTCHA service, provided by Google Ireland Limited, to protect registration and login areas from automated access (bots) and to ensure the security of the platform. reCAPTCHA analyses user behaviour and collects technical device data to determine whether the interaction is human. Data are processed by Google in accordance with its own Privacy Policy. reCAPTCHA may load automatically in the areas where it is implemented.
Legal basis: legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR in the security and integrity of the platform.
For detailed cookie management, users may access the preference panel at any time via the “Cookie Settings” link at the bottom of each page of the Website.
Art. 5 – Processing Methods and Security Measures
Personal data are processed by means of IT and telematic tools, with organisational logic strictly related to the purposes indicated and adopting technical and organisational security measures appropriate to ensure a level of protection commensurate with the risk, pursuant to Articles 25 and 32 GDPR.
In particular, the Data Controller adopts measures aimed at preventing data loss, unlawful or incorrect use and unauthorised access. Data are stored on servers located within the European Union, at the hosting provider Vhosting, with a data centre located in Italy, in compliance with Articles 44 et seq. GDPR on data transfers.
Processing is carried out by persons specifically authorised by the Data Controller and instructed pursuant to Article 29 GDPR, or by external Data Processors appointed pursuant to Article 28 GDPR.
Art. 6 – Data Retention Period
Personal data collected are retained for the time strictly necessary to achieve the purposes for which they were collected, in accordance with the principle of storage limitation set out in Article 5(1)(e) GDPR, and in any case no longer than the periods indicated below:
- Navigation data and technical data: retained for a period not exceeding 12 (twelve) months from collection, subject to the need to ascertain crimes or unlawful conduct;
- User account data (first name, last name, e-mail): retained for the entire duration of the contractual relationship and, following account deletion, for a further period not exceeding 12 (twelve) months, in order to comply with any legal or accounting obligations;
- Geolocation data: not permanently retained by the Data Controller; used exclusively in real time to provide the functionality and not stored on servers;
- Push notification data: device identification tokens are retained until the user withdraws consent or uninstalls the App;
- PayPal transaction data: accounting references of transactions are retained for 10 (ten) years, in accordance with applicable legal obligations under tax and accounting legislation;
- Analytical cookies: retained for the duration indicated in the relevant cookie policy, managed through CookieHub.
Upon expiry of the retention periods indicated, data will be deleted or irreversibly anonymised.
Art. 7 – Disclosure and Dissemination of Data
Users’ personal data are not sold, transferred free of charge or otherwise disclosed to third parties for commercial profiling or marketing purposes, unless the data subject has given explicit consent.
Data may be disclosed, to the strictly necessary extent, to the following categories of recipients:
- Providers of technical and infrastructural services acting as Data Processors pursuant to Article 28 GDPR (e.g. hosting provider Vhosting, Google LLC for Analytics, Maps and reCAPTCHA services, PayPal for payments, CookieHub for consent management);
- Judicial, police or administrative authorities, in cases provided for by law or in fulfilment of regulatory obligations;
- The Data Controller’s professional advisors and consultants (e.g. accountants, lawyers), within the limits of their respective mandates and subject to confidentiality obligations.
Data are not disseminated to unidentified parties.
Art. 8 – International Data Transfers
Personal data are processed and stored on servers located within the European Union. However, the use of third-party services integrated into the Website and the App (in particular Google Analytics 4, Google Maps, Google reCAPTCHA and PayPal) may involve the transfer of personal data to third countries, including the United States of America.
Such transfers are carried out in compliance with the safeguards provided for in Chapter V of the GDPR, and in particular:
- Google Ireland Limited adheres to the EU-US Data Privacy Framework, recognised by the European Commission as providing an adequate level of protection by adequacy decision of 10 July 2023;
- PayPal Holdings, Inc. adopts the Standard Contractual Clauses approved by the European Commission pursuant to Article 46(2)(c) GDPR.
Users may request further information on the safeguards adopted by contacting the Data Controller at the address indicated in Art. 1.
Art. 9 – Minors
The Website and the App are not intended for individuals under the age of 16 (sixteen). The Data Controller does not knowingly collect personal data from children under 16 years of age. Should the Data Controller become aware of having inadvertently collected personal data from a child under 16 without the consent of the holder of parental responsibility, it will proceed to the immediate deletion of such data. Parents or legal guardians who believe that a minor in their care has provided personal data through the Website or the App are invited to contact the Data Controller at the address indicated in Art. 1.
Art. 10 – Rights of the Data Subject
Pursuant to Articles 15 to 22 GDPR, data subjects have the right to exercise, at any time, the following rights against the Data Controller:
- Right of access (Art. 15 GDPR): to obtain confirmation as to whether or not personal data concerning them are being processed and, where that is the case, to obtain a copy thereof;
- Right to rectification (Art. 16 GDPR): to obtain, without undue delay, the rectification of inaccurate personal data or, taking into account the purposes of the processing, the completion of incomplete personal data;
- Right to erasure (Art. 17 GDPR, “right to be forgotten”): to obtain the erasure of personal data where one of the grounds provided for by the provision applies, unless the processing is necessary to comply with a legal obligation or to establish, exercise or defend legal claims;
- Right to restriction of processing (Art. 18 GDPR): to obtain restriction of processing in the cases provided for by the provision;
- Right to data portability (Art. 20 GDPR): to receive personal data provided to the Data Controller in a structured, commonly used and machine-readable format, in the cases provided for by the provision;
- Right to object (Art. 21 GDPR): to object at any time to the processing of personal data based on the legitimate interest of the Data Controller, unless the latter demonstrates compelling legitimate grounds for the processing that override the interests of the data subject;
- Right to withdraw consent (Art. 7(3) GDPR): to withdraw consent at any time, without prejudice to the lawfulness of processing based on consent before its withdrawal;
- Right to lodge a complaint (Art. 77 GDPR): to lodge a complaint with the competent supervisory authority. In Italy: Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it. Users located in other EU Member States may also contact the supervisory authority of their country of habitual residence.
Requests relating to the exercise of the above rights must be addressed to the Data Controller by written communication to the e-mail address info@prolocolameziaterme.it, specifying the data subject’s first name, last name, e-mail address associated with the account (if applicable) and the right they wish to exercise. The Data Controller will provide a response within 30 (thirty) days of receipt of the request, extendable by a further 60 (sixty) days in cases of particular complexity, with prior notice to the data subject.
Art. 11 – Amendments to this Privacy Policy
The Data Controller reserves the right to amend, supplement or update this Privacy Policy at any time, including as a result of any changes to applicable legislation. Material changes will be notified to registered users by communication to the e-mail address provided at registration, as well as by a prominent notice on the Website and the App. Users are therefore advised to consult this page periodically.
The date of the last update is indicated at the top of this document. Continued use of the Website or the App following publication of the changes constitutes acceptance of the updated version of the Privacy Policy.
Art. 12 – Applicable Law and Jurisdiction
This Privacy Policy is drawn up in accordance with EU Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), Italian Legislative Decree No. 196 of 30 June 2003 (Personal Data Protection Code), as amended by Italian Legislative Decree No. 101 of 10 August 2018, as well as the measures and guidelines issued by the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
For any dispute relating to the application of this Privacy Policy, where jurisdiction is not mandatorily vested in another authority, the Court of Lamezia Terme (CZ), Italy, shall have exclusive jurisdiction.