PRIVACY POLICY

The purpose of this privacy policy is to provide maximum transparency regarding the information collected by this website and how it is used. In compliance with the obligations arising from national legislation (Legislative Decree 30 June 2003, No. 196 – Personal Data Protection Code, and subsequent amendments) and European legislation (EU General Data Protection Regulation No. 679/2016, GDPR), this website respects and protects the privacy of visitors and users, making every possible and proportionate effort not to infringe upon users’ rights.

This Cookie Policy relates to the website www.tourinmilan.com (hereinafter “site”).

DATA CONTROLLER

Tour in Milan by The Roman Gay srls
Via Tucidide, 56, 20134, Milano, Italia
Email: tourinmilan@gmail.com
Mobile: +39 347 7555710
P.IVA/CF: 15522141009
PEC: romangay@legalmail.it
REA: RM 1596495
License number GR625446

TYPES OF DATA COLLECTED

  1. Automatically collected data. The computer systems and software applications used to operate this website, during their normal operation, collect some data potentially associated with identifiable users (the transmission of which is implicit in the use of Internet communication protocols). These data are processed only for the time strictly necessary to obtain statistical information about the site’s usage and to ensure its proper functioning. The provision of such data is mandatory as it is directly related to the web browsing experience.
  2. Data voluntarily provided by the user. The voluntary and explicit sending of emails to the addresses listed on this site does not require further consent. Specific summary information will be shown or displayed on pages of the site set up for on-demand services (forms). Contact forms involve the collection of the sender’s/user’s address and data necessary to respond to the submitted requests and/or provide the requested service. Therefore, the user must explicitly consent to the collection and processing of the data provided in these forms to send the request and allow us to respond.
  3. Cookies. This site uses cookies to gather information about its usage and to improve users’ browsing experience over time. The user can choose whether to consent to or reject their use. For more details, visit the dedicated cookies section.

PURPOSES OF DATA PROCESSING

Data processing is based on the user’s consent and is carried out for the following purposes:

  1. To improve the browsing experience.
  2. To use the data provided in information requests in order to respond to submitted inquiries and/or provide the requested service. If data processing is refused, the data controller will not be able to fulfill the request.

METHODS OF DATA PROCESSING

Personal data will be processed by the Data Controller and duly appointed data processors to correctly fulfill the processing purposes indicated above. Data will be collected using electronic tools, paper archives, or other suitable media and will be subject to security measures designed to ensure the confidentiality of personal data and to prevent unauthorized access (Art. 5 para. 1 letter F of the GDPR).

DATA DISCLOSURE

The transmitted data will not be disclosed to third parties or disseminated in any way (e.g., social networks, websites, etc.).

DATA RETENTION PERIOD

Collected data will be retained for no longer than necessary to achieve the purposes for which they were collected (“storage limitation principle”, Art. 5 GDPR), or in accordance with legal deadlines. Periodic checks are carried out to verify the obsolescence of stored data in relation to the purposes for which they were collected.

DATA SUBJECT’S RIGHTS

The data subject always has the right to request access to, rectification, or deletion of their data from the Data Controller, as well as restriction of or objection to processing. The data subject may also request data portability or revoke consent to data processing, asserting these and other rights under the GDPR by simply contacting the Data Controller. Requests may be made by email or registered mail with the subject: “Request from the Data Subject,” specifying the right being exercised (e.g., deletion, rectification, portability, erasure), along with a valid email address/PEC for correspondence. The data controller, or an authorized representative, will fulfill the request within 30 days from receipt. If the request is complex, this timeframe may be extended by an additional 30 days, with prior notification to the data subject. If the data subject deems it necessary, they may also lodge a complaint with the competent supervisory authority.

COOKIE POLICY