Tuscany, Beautiful Everywhere

In accordance with national legislation (Legislative decree 196/June 30, 2003 regarding the protection of personal data) and community legislation (EU regulation for the protection of personal data, n. 679/2016, GDPR) and later modifications, this website respects and safeguards the privacy of visitors and users, ensuring that every possible and proportional attempt will be made to not impinge on the rights of its users.

The present privacy policy applies exclusively to online activity on the present website and is valid for visitors/users of the site. It does not apply to data collected via other channels. This information on the protection of privacy serves to provide maximum transparency regarding the information that the website collects and uses.

LEGAL BASIS OF PROCESSING DATA

The present website processes data only upon agreement.

The provision of data and therefore Agreement to collect and process data is optional; the User can refuse to consent and revoke at any time previously-given consent. Doing so, however, could result in blocked access to some services and navigation of the website could be compromised. Beginning on May 25, 2018 (when the GDPR went into effect), the present website will process some data selected based on the legitimate interests of the owner of the data processing.

DATA COLLECTED AND AIMS

As with all websites, the present site also uses log files which conserve data collected automatically during a visit to the website. The data collected could be the following:

  • Internet protocol address (IP);
  • Browser type and parameters of the device used for connecting to the site;
  • Name of the internet service provider (ISP);
  • Date and time of visit;
  • Webpage the visitor connected from (referral), as well as the subsequent page upon exiting;
  • Number of clicks.

The aforementioned data are processed automatically and collected exclusively in a consolidated form in order to verify the correct operation of the website, and for security reasons (since May 25, 2018, data will be processed based on the legitimate interests of the owner of the data processing).
To ensure security (antispam filters, firewall, survey of viruses), the data registered automatically can potentially include personal data, like an IP address, which could be used, in accordance with the relevant current laws, to block attempts to damage the website or other users, as well as damaging or criminal activities. Such data are never used for identifying and profiling the user, but are only intended to safeguard the website and its users (since May 25, 2018, data will be processed based on the legitimate interests of the owner of the data processing).
The data can also be transferred to specialized banks for reports and marketing.
The data collected from the website during its operation are used exclusively for the aims indicated and are conserved for the time necessary for carrying out precise activities or, if applicable, until there is a cancellation request for accounts registered to the website. The data collected from the website will never be passed to third parties for any reason, unless there is a legitimate request from judicial authorities and only in cases allowed by law.

PROCESSING LOCATION

The data collected from the website are processed at the web hosting’s data centre (TIX – Tuscany Internet Exchange, Via San Piero a Quaracchi 250, Florence).

COOKIES

As with all websites, this site also uses cookies, which are small strings of texts that allow for the website to conserve data and is based on the visitor’s preferences in order to improve the site’s operation, simplify navigation by automating processes (ex. Login, language) and analyze site use.
Session cookies are essential for distinguishing connected users, and are useful for ensuring that a requested function not be provided to the wrong user, as well as for security purposes so as to avoid damaging attacks on the website. Session cookies do not contain personal data and last only as long as the session does, that is, until the browser is closed. Consent is not needed for them.
Functionality cookies used by the website are strictly necessary for operating the site; they are those connected to a user’s request for a specific function (like Login), for which consent is not needed).
Using the website, the visitor expressly agrees to the use of cookies.

DISABLING COOKIES

Cookies are connected to the browser being used and can be disabled directly by the browser, thus refusing/revoking consent for the use of cookies. It should be kept in mind that disabling cookies can impede upon the correct use of some functions on the website.

SOCIAL NETWORK PLUGIN

The present website incorporates plugins and/or buttons for social networks in order to allow for easy sharing of content on your preferred social networks. These plugins are programed so as to not register cookies when accessing the page, safeguarding the user’s privacy. The cookies are registered, if allowed by the social networks, only when the user effectively and voluntarily uses the plugin. It should be kept in mind that if the user navigates when logged into the social network, he/she already consented to the use of cookies transmitted through this website when registering with the social network.
The collection and use of data obtained via the plugin are regulated according to the related privacy policies of the social networks, which users are advised to refer to.

SECURITY MEASURES

The present website processes users’ data legitimately and correctly, adopting appropriate security measures aimed at impeding unauthorized access to and disclosure, modification or destruction of data. Processing is carried out using computer and/or online tools, with organizational procedures and reasons strictly related to the intended aims. In addition to the owner, in some cases certain categories of representatives can have access to data who are involved in the organization of the website (administrative, commercial, marketing and legal personnel and system administrators), as well as external individuals (like providers of third-party technical support, postal workers, hosting providers, IT companies and communication agencies).

USER RIGHTS

In accordance with EU Regulation 679/2016 (GDPR) and national legislation, the User can, with the procedures and limits provided in current legislation, exercise the following rights:

  • Request the confirmation of the existence of personal data regarding him/herself (right to access);
  • Be informed of their origin;
  • Receive comprehensible communication about them;
  • Receive information about the reason, procedures and aims of their processing;
  • Request an update, modification, integration, cancellation, transformation into anonymity and blocking of data processes that are in violation of the law, including those no longer necessary for carrying out the aims for which they were collected;
  • In cases of consent-based processing, receive the data provided to the owner, in a structured and legible manner, from a data processor and in a format commonly used by an electronic device; the cost for doing so only regards possible support;
  • The right to present a complaint to the Supervisory Authority (Warranty Policy);
  • More generally, all rights that are recognized by current laws.

In cases in which data are processed based on legitimate interests, the rights of interested parties are nonetheless guaranteed (except the right of portability, which is not required by current regulations), especially the right to oppose processing, which can be applied by sending a request to the owner of the data processing.

MANAGING COOKIES: CONSENTING THEIR USE

Cancelling cookies does not block use of the website.
Users/visitors can program the browser to accept/refuse all cookies or have appear a warning whenever a cookie is presented in order to evaluate whether or not to accept it.
By default, almost all web browsers are programmed to automatically accept cookies. You can modify the pre-set configuration, which is set to medium security on browsers (like, for example, Internet Explorer 6.0), and disable cookies (block them definitively), programming a higher level of protection in the dedicated tab (Privacy), but it should be kept in mind that disabling cookies can compromise use of the site’s features.
Users also have the possibility of cancelling (or eliminating) cookies from his/her personal computer, using the browser’s specific feature. Cancelling cookies does not block use of the site, but results in the repeated need to re-authorize, that is, include the user’s credentials upon each visit.
If users decide on occasion to accept or refuse cookies, he/she can also program the browser so it generates a message every time a cookie is saved.
To this aim, there are elements (plugins) for the more common browsers that allow for:

  • Management (visualization, cancellation, blocking) of cookies;
  • Disabling JavaScript websites by third parties;
  • Visualizing technology used by the website;
  • Visualizing and blocking (selective) various tracing mechanisms.

OWNER OF THE DATA PROCESSING

In accordance with current laws, the owner of the data processing is Fondazione Sistema Toscana.

SUPERVISOR FOR THE DATA PROCESSING

Mr. Alessandro Giannini has been appointed supervisor for the data processing, having agreed to process the data on behalf of the owner.

UPDATES

The present privacy policy was updated on May 25, 2018.
In reading the above information, with reference to the EU regulation 679/2016, the user agrees:

  • To the processing of personal data, both public and sensitive, regarding him/her, which is used for the aims declared above.
  • To the communication of the data to categories of individuals as stated above.

Consent remains conditional on compliance with the provisions of current legislation.

DETAILS REGARDING THE PROCESSING OF PERSONAL DATA

Personal Data are collected for the following purposes and using the following services:

CONTACTING THE USER

Contact form
The User, in inserting his/her Personal Data when filling out the contact form, agrees to them being used to respond to requests for information, estimates, or any other reason indicated by the owner of the form.
Personal Data collected: surname, email, name, province and various kinds of data specified in the service’s privacy policy.

INTERACTION WITH SOCIAL NETWORKS AND EXTERNAL PLATFORMS

This service permits interactions with social networks or with other external platforms directly from the pages of this Application.
Interactions and information acquired by this Application are subject to the User’s privacy settings for each social network.
Should a service for interacting with social networks be installed, it’s possible that data will be collected regarding the traffic related to the pages on which it is installed, even in the case of Users who don’t use the service.

Like button and Facebook social media widgets (Facebook, Inc.)
The “Like” button and Facebook social media widgets are services for interacting with Facebook, provided by Facebook Inc.
Personal Data collected: Cookies and Usage Data.
Processing location: USA – Privacy Policy

Tweet button and Twitter social media widgets (Twitter Inc.)
The “Tweet” button and Twitter social media widgets are services for interacting with Twitter, provided by Twitter, Inc.
Personal Data collected: Cookies and Usage Data.
Processing location: United States – Privacy Policy.
Subject pertinent to the Privacy Shield.

Pinterest button and Pinterest social media widgets (Pinterest, Inc.)
The Pinterest button and Pinterest social media widgets are services for interacting with Pinterest, provided by Pinterest, Inc.
Personal Data collected: Cookies and Usage Data.
Processing location: United States – Privacy Policy

Instagram button and Instagram social media widgets (Instagram, Inc.)
The Instagram button and Instagram social media widgets are services for interacting with Instagram, provided by Instagram, Inc.
Personal Data collected: Cookies and Usage Data.
Processing location: United States – Privacy Policy

REGISTRATION AND AUTHENTICATION

During registration and authentication, the User agrees to allow the Application to identify him/her and provide him/her with access to dedicated services.

Direct registration
The User registers by filling out a registration form and directly providing this Application with his/her Personal Data.
Personal Data collected: email, name and surname, telephone, office, municipality.

STATISTICS

The services contained in the present section allow the Owner of the Data Processing to monitor and analyse traffic data and serve for tracing the User’s behaviour.

Google Analytics (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc (“Google”). Google uses the Personal Data collected for the purposes of tracing and examining the use of this Application, compiling reports and sharing them with other services developed by Google.
Google can use the Personal Data for contextualizing and personalizing advertisements from its advertising network.
Personal Data collected: Cookies and Usage Data.
Processing location: USA – Privacy Policy – Opt Out.

Google Tag Manager (Google, Inc.)
Google Tag Manager is a statistics service provided by Google, Inc.
Personal Data collected: Cookies and Usage Data.
Processing Location: USA – Privacy Policy

VISUALIZING CONTENT FROM EXTERNAL

This service allows for content hosted on external platforms to be viewed directly from the pages of this Application and to interact with them.
When this service is installed, it’s possible that data will be collected regarding the traffic related to the pages on which it is installed, even in the case of Users who don’t use the service.

Google Fonts (Google, Inc.)
Google Fonts is a service for visualizing font styles manages by Google Inc, allowing this Application to incorporate such content into its pages.
Personal Data collected: Cookies and Data Usage.
Processing location: United States – Privacy Policy.
Subject pertinent to the Privacy Shield.

Widget Google Maps (Google Inc.)
Google Maps is a service for visualizing maps managed by Google Inc, allowing this Application to incorporate such content into its pages.
Personal Data collected: Cookies and Usage Data.
Processing location: United States – Privacy Policy.
Subject pertinent to the Privacy Shield.