In compliance with the obligations deriving from the European regulation for the protection of personal data n. 679/2016, GDPR and subsequent amendments, this site respects and protects the privacy of visitors and users (hereinafter referred to as “interested parties”, ex Art.4, c.1 of the GDPR), putting into force every possible and proportionate effort. not to infringe the rights of the interested parties.
- The principles concerning the protection of your data
- The rights of the interested parties
- Personal data collected from this site
- Place of treatment
- How we use your personal information
- Who has access to your personal data
- How we protect your personal data
- Information about cookies
- Owner and responsible for processing
- Useful contacts and references
Personal Data – any information relating to an identified or identifiable natural person.
Processing – any operation or set of operations performed on personal data or on a set of personal data.
Interested – a natural person whose personal data has been processed.
Children – a natural person under the age of 16.
Principles concerning the protection of your data
We are committed to following the following principles for the protection of your data:
- We process your personal data only for legitimate, fair and transparent purposes, just as the processing of data is always based on legitimate reasons. We process your data always keeping in mind your rights. We will provide, on request, all information on the data that have been processed.
- Data processing is always limited to the purpose of the request. Our processing activities always correspond to the purposes for which personal data have been collected.
- Data processing is performed with strictly necessary data. We collect and process only the minimum amount of personal data required for any purpose.
- Data processing is limited to a certain period of time. We will not store your personal information for longer than necessary.
- We are committed to ensuring the accuracy and respect of your data.
- We are committed to ensuring the integrity and confidentiality of your data.
Rights of the interested party
The interested party has the following rights:
- Right to information – means you need to know if your personal data has been processed; what data are collected, how they are collected, for what purpose and by whom they are processed.
- Right of access – means that you have the right to access your personal data, request and obtain a copy of the personal data that has been collected.
- Right of rectification: means that you have the right to request the correction or deletion of your personal data considered inappropriate or incomplete.
- Right to cancel: under certain circumstances it is possible to request the deletion of personal data from our archives.
- Right to restrict processing – in the sense that under certain conditions, the user has the right to limit the processing of their personal data.
- Right to object to processing: this means that in some cases you have the right to object to the processing of your personal data, for example in the case of direct marketing.
- Right to oppose automated processing: means that you have the right to oppose automatic processing, including profiling; not to be subject to a decision based solely on automated processing. This right does not apply whenever there is a result of profiling that produces legal effects that affect you or that significantly affect you.
- Right to data portability: you have the right to obtain your personal data in a readable format or, if possible, as a direct transfer from one processor to another.
- Right to file a claim – in case of refusal of a request under the right of access, you have the right to know the reasons for the refusal. If you are not satisfied with the way your request was handled, contact us immediately.
- Right to request the intervention of the Control Authority – means that you have the right to request the intervention of the supervisory authority and / or the right to other legal remedies such as, for example, the claim for damages.
- Right of withdrawal of consent – the user has the right to withdraw any consent to the processing of personal data.
Personal data collected from this site
Information provided voluntarily
This information may include your e-mail address, your name, billing address, residence address etc., that is, the data needed to offer you a product / service or to improve your user experience . The optional, explicit and voluntary sending of e-mail and / or ordinary mail to the addresses indicated on this site entails the subsequent acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data included in the message. The user remains solely responsible for the relevance and accuracy of the data sent.
In the comment and / or contact forms of this site, only the data necessary for the response is collected. This information may include, for example, your name and e-mail address. In particular, with regard to the comments, the user expressly consents that the inserted contents are freely viewable also for other visitors. The data received will be used exclusively for the provision of the requested service and only for the time needed to provide the service. The information that users of the site deem to make public through the services and tools made available to them, are provided by the user knowingly and voluntarily, exempting this site from any liability regarding any violation of laws. It is up to the interested parties to verify that they have permission to enter personal data of third parties or contents protected by national and international regulations.
Information that is automatically collected
This is data that is automatically stored in the logs of server log files. The information collected can be the following: (1) the types of browsers and the versions used, (2) the operating system used by the access system, (3) web site of origin and destination of the visitor (referral), (4) ) the country of origin, (5) the date and time of access to the Internet site, (6) an Internet protocol address (IP address), (7) the name of the Internet service provider (ISP) and (8) ) any other similar data and / or information that can be used in case of attacks on the computer system.
This is in any case anonymous information that is mainly used to improve the experience of visitors / users of the site or to ensure an optimal level of protection of personal data processed. Anonymous data from server log files are stored separately from all personal data provided by data subjects. The traffic on this site is monitored by the Aruba spa Web Hosting by collecting the IP addresses of the data subjects for a period of one month.
Information derived from our partners
We also collect information from our trusted partners but only if they have identified appropriate legal justifications for sharing such information. These data are those that you have provided directly to our partners or that they have collected about you for other legal reasons. See the list of partners here .
Information available to the public
We may also collect personal data that you have made publicly available.
Place of treatment
The data collected from this site are processed at the headquarters of the Data Controller, and at the datacenter of the web Hosting Aruba.it located in Italy. Web hosting is responsible for processing data processing data on behalf of the holder, is located in the European Economic Area and acts in accordance with European standards.
Use of personal data
We use your personal information in order to:
- provide you with adequate service. This information includes, for example, the registration of your account.
- provide you with other products and services you have requested;
- providing you with promotional items or services upon your request and communicating with you in relation to such products and / or services;
- communicate and interact with you and to notify you of any changes to the services offered.
- improve your user experience;
- fulfill an obligation under the law or contract;
- send commercial and / or promotional information about our products and services;
- send information and invitations to events or fairs organized by us or by us;
- Send news about this website and our partners;
- use statistics on site visitors in an absolutely anonymous and impersonalized way (Google Analytics).
We will use your personal data for purposes of legitimate interests and / or with your consent.
For reasons related to the conclusion of a contract or the fulfillment of contractual obligations, we will process your personal data for the following purposes:
- to identify you;
- to provide you with a service or to send / offer you a product;
- to communicate information about both sales and billing;
- to handle any claim and / or request for a refund / return from you.
For reasons of legitimate interest, we will process your personal data for the following purposes:
- send you personalized offers * (coming directly from us and / or from our carefully selected partners);
- administer and analyze our customer database (behavior and purchase history) in order to improve the quality, variety and availability of the products / services offered / supplied;
- conduct questionnaires regarding the satisfaction of visitors / users of this site;
- security purposes (spam filters, firewalls, virus detection): the automatically recorded data may possibly also include personal data such as the IP address, which could be used, in compliance with applicable laws, in order to block attempts to damage the site same or to damage other users, or in any case harmful activities or constituting a crime. Such data are never used for the identification or the profiling of the user, neither crossed with other data nor supplied to third parties, but used only for the protection of this site and its users .
Unless otherwise communicated, we may offer products / services similar or equal to your purchase history / browsing behavior in line with our legitimate interest.
With your consent, we will process your personal data for the following purposes:
- to send you newsletters and offers for marketing campaigns;
- to send you invitations to events or promotions reserved for customers and / or subscribers to our website or newsletter;
- for all other purposes for which I have requested your consent .
We may process your personal data also to fulfill the obligations arising from the law and / or use your personal data for cases provided by law. We reserve the right to use only anonymized data.
We will retain billing information and other tax information that only applies to you for the time established by the obligations under the law.
- the connection between purpose, context and nature of personal data is suitable for further processing;
- further processing in any case should not damage your interests;
- there is always adequate protection for data processing.
We will inform you in case of use of the data for further processing or purposes.
Who else can access your personal data
We will not share your personal information with third parties. The personal data of visitors / users of the site in some cases are provided to our trusted partners in order to offer you a better service. We share your information only with:
Third parties connected to this website:
This website has integrated the JS script of Google Analytics (with the anonymizer function). Google Analytics is primarily a web analytics service that collects and analyzes data about visitor behavior on this site. From this analysis we collect information about the origin of the visitor / user (the so-called referrer), the secondary pages visited and the frequency and duration of visits, etc. The purposes of these analyzes are the optimization of this site and the cost-benefit analysis regarding the Internet advertising of this site.
Google Analytics is a service provided by Google Inc., 1600 Amphitheater Pkwy, Mountain View, CA 94043-1351, United States. To perform these analyzes, the code string “_gat” is used. _anonymizeIp “. Through this code, the IP address of the data subject is made anonymous by Google.
The main purpose of Google Analytics is to analyze the traffic on this site. However, Google may use the data and information collected, inter alia, to evaluate its use and to provide online reports representing the activities of this site.
Google Analytics places a cookie on the computer system of those concerned. The definition of cookies has been inserted here . By setting this cookie, Google is enabled to analyze this site. On every page of this site where the Google Analytics tracking script is present, the data of the interested parties, through their browser, will be automatically sent to Google.Through this technical procedure, Google receives the IP address of those involved and will be able to understand the origin of visitors and the number of clicks on the site. The cookie is used to store personal information, such as access time, the position from which access was made and the frequency of visits relating to this website by the interested party.
For each visit to this site, such personal data, including the IP address of the Internet access used by the person concerned, will be transmitted to Google in the United States of America. This personal data is collected by Google through this site and is stored for a period of 26 months. Google may transfer this personal data collected to third parties through the aforementioned technical procedure.
The interested party may prevent the installation of these cookies through this site at any time by means of a corresponding modification of their web browser and therefore permanently refuse the setting of the aforementioned cookies. This change to the Internet browser prevents Google Analytics from setting its cookie. In the same way, through your browser, you can delete cookies already in use by Google Analytics.
Moreover, the interested party has the possibility to prevent the collection and subsequent processing of the data collected, through this site, by Google Analytics. To this end, the interested party must download and install an additional component for their browser directly from this link . This add-on tells Google Analytics not to track visits and / or store data of data subjects.
Further information regarding the applicable provisions on data protection by Google can be found at this link . For more details about Google Analytics linked to this link: https://www.google.com/analytics/ .
We only work with partners who are able to guarantee an adequate level of personal data protection. We will disclose your personal data to third parties or public officials only if they are legally obliged to do so. We may disclose your personal information to third parties only if you have given your consent or if there are other legal reasons that oblige us to do so.
How we protect your data
We will put every effort into keeping your personal information safe. We use secure protocols for communication and data transfer (such as HTTPS). We use anonymized data where it is possible. We constantly monitor our systems to prevent possible vulnerabilities and / or cyber attacks. We perform daily and weekly backup of the site and the data contained therein.We do antivirus, antimalware and anti-intrusion scans on a daily basis to verify the absence of violations of our security systems.
However, Internet-based data transmissions may, in principle, present security gaps, so absolute protection may not be guaranteed. In any case, we will notify any data breaches to the competent authorities in the ways and at the times provided for by the current privacy legislation. You will be informed directly in case of violations related to the confidentiality of your data and your rights or interests. We will do everything reasonably possible to prevent breaches of security.
If you have registered an account on this site, remember to keep your username and password secret.
Children and minors.
We do not knowingly collect personal information about children and young people. Our services are not directed to children or minors.
Cookies and other technologies used
Cookies are small text files that can be used by websites to make the experience more efficient for the user.
The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies it is necessary to have your active permission.
This site uses different types of cookies. Some cookies are placed by third-party services that appear on our pages.
Your consent applies to the following websites: www. atflorence .it
- Necessary cookies: these cookies are necessary to use some important features on our website, such as access (login). These cookies do not collect any personal information.
- Functional cookies: these cookies provide features that make the use of the service more convenient and make more personalized features possible. For example, they might remember your name and e-mail in comment forms so you do not have to re-enter this information in subsequent comments.
- Analytical cookies: these cookies are used to track the use and performance of our website and our services
- Advertising cookies: these cookies are used to publish ads relevant to your interests. In addition, they are used to limit the number of times ads will appear. They are usually placed on the website by advertising networks with the permission of the website operator. These cookies remind you that you have visited a website and this information is shared with other organizations such as advertisers. Often targeting or advertising cookies will be linked to site features provided by other organizations.
You can remove cookies stored on your computer via browser settings. Choosing to disable some cookies prevents the proper use of some features of the site itself. Alternatively, you can control some third-party cookies using a privacy improvement platform like optout.aboutads.info or youronlinechoices.com . For more information about cookies, visit allaboutcookies.org .
Data Controller and Data Processors
Data controller in accordance with the General Data Protection Regulation (GDPR), other data protection laws applicable in EU Member States and other data protection provisions is:
Paola Barbetti certified tourist guide
qualification N. 021/2011
VAT number: 06700590489
Address: Via Borgo la Noce 8
Location: Florence – Italy
Tel .: +39 348 9113143
Responsible for processing : in addition to web hosting, all third-party services on this site are appointed as data processors and who, on the basis of a specific contract, process the data on behalf of the owner. All third-party services used on this site are located in the European Economic Area or in countries belonging to the EU-US and the Swiss-US Privacy Shield Frameworks and act in accordance with European standards and the GDPR.
– Web hosting Aruba.it (Italy)
– Google Analytics (USA)
Useful contacts and references
Changes to this privacy statement