Privacy & Policy

Privacy Policy of galleriaaccademiafirenze.beniculturali.it


This Application collects some Personal Data of its Users.


This document can be printed using the print command in the settings of any browser.

Data Controller


Ministero per i Beni e le Attività Culturali e per il Turismo (Ministry of Cultural Heritage and Activities and Tourism), which, by Ministerial Decree of 26 May 2018, has identified a Data Protection Officer, pursuant to art. 37 et seq. of the Regulation, who is identified in:
Dr. Stefano Vitali
Director of the Central State Archives
e-mail: rpd@cultura.gov.it
pec: rpd@pec.cultura.gov.it
telephone 06 54548568
via del Collegio Romano 27, 00186 – Rome (ITALY)


Contact details of the Person in charge ex D.M. n. 147 of 14/3/2019


Email: ga-afi.info@cultura.gov.it
pec: ga-afi@pec.cultura.gov.it

 

Types of Data collected

Among the Personal Data collected by this Application, independently or through third parties, are: Cookies; Usage Data; first name; last name; email.


Full details on each type of data collected are provided in the dedicated sections of this privacy policy or by means of specific information texts displayed before the data is collected.
Personal Data may be freely provided by the User or, in case of Usage Data, automatically collected during the use of this Application.
Unless otherwise specified, all Data requested by this Application are mandatory. If the User refuses to communicate them, it may be impossible for this Application to provide the Service. In cases where this Application indicates certain Data as optional, Users are free to refrain from communicating such Data, without any consequences on the availability of the Service or its operation.
Users in doubt as to which Data are mandatory are encouraged to contact the Data Controller.
The possible use of Cookies – or of other tracking tools – by this Application or by the owners of third party services used by this Application, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.


The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Application and guarantees that he/she has the right to communicate or disseminate them, releasing the Owner from any liability towards third parties.

 

Modalities and place of processing of collected Data

Processing methods


The Data Controller adopts appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of Personal Data.
The processing is carried out using computer and/or telematic tools, with organisational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other subjects involved in the organisation of this Application (administrative, sales, marketing, legal, system administrators) or external subjects (such as third party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller, may have access to the Data. The updated list of Data Processors can always be requested from the Data Controller.


Legal basis of the processing


The Data Controller processes Personal Data relating to the User where one of the following conditions exists

 

  • the User has given consent for one or more specific purposes;
    Note: in some jurisdictions, the Controller may be allowed to process Personal Data without the User’s consent or another of the legal bases specified below, until the User objects („opts out“) of such processing. However, this does not apply if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
  • the processing is necessary for the performance of a contract with the User and/or the performance of pre-contractual measures;
  • processing is necessary for the performance of a legal obligation to which the Controller is subject;
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of public authority vested in the Controller;
  • processing is necessary for the pursuit of the legitimate interest of the Controller or of third parties.
    However, it is always possible to request the Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on law, required by a contract or necessary to conclude a contract.

Place


The Data are processed at the Data Controller’s operational headquarters and in any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one where the User is located. To obtain further information on the location of the processing, the User may refer to the section on Personal Data processing details.


The User has the right to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organisation under public international law or consisting of two or more countries, such as the UN, as well as about the security measures taken by the Controller to protect the Data.


The User can verify whether one of the transfers just described takes place by examining the section of this document relating to details on the processing of Personal Data or request information from the Controller by contacting him at the contact details given at the beginning.


Retention period


Data are processed and stored for the time required by the purposes for which they were collected.


Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the performance of such contract is completed.
  • Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller. When the processing is based on the User’s consent, the Data Controller may keep the Personal Data longer until such consent is revoked. Moreover, the Controller may be obliged to keep the Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period the Personal Data will be deleted. Therefore, at the end of this period, the right of access, cancellation, rectification and the right to Data portability can no longer be exercised.

Purposes of the Data collected

The User’s Data are collected to enable the Data Controller to provide the Service, to comply with legal obligations, to respond to requests or enforcement actions, to protect its rights and interests (or those of Users or third parties), to detect any malicious or fraudulent activities, as well as for the following purposes: Interaction with social networks and external platforms, Statistics, Displaying content from external platforms, Contacting the User, Hosting and backend infrastructure, Infrastructure monitoring, Managing contacts and sending messages and Traffic optimisation and distribution.


To obtain detailed information on the purposes of the processing and the Personal Data processed for each purpose, the User may refer to the section „Details on the processing of Personal Data“.


Details of Personal Data processing

Personal Data is collected for the following purposes and using the following services:

  • Contacting the User
    Contact form (This Application)
    The User, by filling in the contact form with his/her Data, consents to the use of such Data in order to reply to requests for information, quotations, or any other nature indicated in the header of the form.
    Personal Data processed: surname; email; name.
  • Managing contacts and sending messages
    This type of service makes it possible to manage a database of email contacts, telephone contacts or contacts of any other type used to communicate with the User.
    These services may also collect data on the date and time the User views messages, as well as the User’s interaction with them, such as information on clicks on links in messages.
    MAILCHIMP
    MAILCHIMP is an address management and email messaging service provided by The Rocket Science Group LLC
    Personal data processed: email.
    Place of processing: USA – Privacy Policy.
  • Hosting and backend infrastructure
    The purpose of these types of services is to host data and files that allow this Application to function, enable its distribution and provide a ready-to-use infrastructure to deliver specific functionalities of this Application.
    Some of these services operate through servers located geographically in different places, making it difficult to determine the exact location where Personal Data is stored.
    CLOUD ITALY
    The hosting for the institutional site of the Accademia Gallery of Florence used is https://cloud.italia.it/marketplace/service/110 (Agid qualified csp), administered by NexusIt
    Personal Data processed: various types of Data as specified by the privacy policy of the service.
    Place of processing: See the privacy policy of NexusIt and Cloud Italia- Privacy Policy.
  • Interaction with social networks and external platform

    This type of service makes it possible to carry out interactions with social networks, or with other external platforms, directly from the pages of this Application.
    The interactions and information acquired by this Application are in any case subject to the User’s privacy settings relating to each social network.
    This type of service may still collect traffic data for the pages where the service is installed, even when Users do not use it.
    It is recommended to disconnect from the respective services to ensure that the data processed on this Application is not linked back to the User’s profile.
    YouTube, LLC
    Is the streaming platform on the site that displays an external widget on which the Accademia Gallery of Florence directly publishes its content
    Personal data processed: Cookies; Usage Data.
    Place of processing: USA – Privacy Policy
    Spreaker Inc. a Voxnest Company
    Is the platform that manages audio content for podcasts that displays an external widget that allows access to podcasts published by the Galleria dell’Accademia di Firenze.
    Personal data processed: Cookies; Usage Data.
    Place of processing: USA – Privacy Policy
    Facebook Like button and social widgets (Facebook, Inc.)
    The Facebook „Like“ button and social widgets are services for interaction with the Facebook social network, provided by Facebook, Inc.
    Personal data processed: Cookie;
    Usage data.Place of processing: USA – Privacy Policy.
    Google+ +1 button and social widgets (Google Inc.)
    The Google+ +1 button and social widgets are services for interaction with the Google+ social network, provided by Google Inc.
    Personal data processed: Cookies; Usage data.
    Place of processing: USA – Privacy Policy.
  • Statistics
    The services contained in this section allow the Data Controller to monitor and analyse traffic data and serve to keep track of the User’s behaviour.
    Google Analytics with anonymized IP (Google Inc.)
    Google Analytics is a web analysis service provided by Google Inc. („Google“). Google uses the Personal Data collected for the purpose of tracking and examining the use of this Application, compiling reports and sharing them with other services provided by Google.
    Google may use the Personal Data to contextualise and personalise the ads in its advertising network.
    This Google Analytics integration makes your IP address anonymous. The anonymisation works by shortening the IP address of the Users within the borders of the member states of the European Union or other countries which are parties to the Agreement on the European Economic Area. Only in exceptional cases, the IP address will be sent to Google’s servers and abbreviated within the United States.
    Personal data processed: Cookies; Usage Data.
    Place of processing: USA – Privacy Policy – Opt Out.
  • Displaying content from external platforms
    This type of service makes it possible to display content hosted on external platforms directly from the pages of this Application and to interact with them.
    If a service of this type is installed, it is possible that, even if Users do not use the service, it may collect traffic data relating to the pages where it is installed.
    The Accademia Gallery of Florence shares content from Instagram and Facebook on its homepage, directly from its profiles.
    Users can share pages/content of the site on their Instagram, Facebook and Twitter profiles and via email .
    Google Maps widget (Google Inc.)
    Google Maps is a map display service operated by Google Inc. that allows this Application to integrate such content within its pages:
    Cookie; Usage Data.
    Place of Processing: USA – Privacy Policy.
    Google Fonts (Google Inc.)
    Google Fonts is a font style display service operated by Google LLC or Google Ireland Limited, depending on where this Application is used, which allows this Application to integrate such content within its pages.
    Personal Data Processed: Usage Data; various types of Data as specified by the privacy policy of the service.
    Place of processing: USA – Privacy Policy.
    YouTube Video Widget (Google Inc.)
    YouTube is a video content display service operated by Google Inc. that allows this Application to integrate such content within its pages.
    Personal Data processed: Cookies; Usage Data.
    Place of Processing: USA – Privacy Policy.
    YouTube Video Widget without Cookies (Google Ireland Limited)
    YouTube is a video content display service operated by Google Ireland Limited that allows this Application to embed such content within its pages.
    This widget is set up so that YouTube does not save information and cookies about Users on this Application, unless they play the video.
    Personal Data processed: Usage Data.
    Place of processing: Ireland – Privacy Policy.

User Rights

Users may exercise certain rights with respect to the Data processed by the Controller.

In particular, the User has the right to:

  • withdraw consent at any time. The User may revoke the consent to the processing of its Personal Data previously expressed.
  • object to the processing oftheir Data. The User may object to the processing of its Data when it is done on a legal basis other than consent. Further details on the right to object are set out in the section below.
  • access to their Data. The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing and to receive a copy of the Data processed.
  • verify and request rectification. The User may verify the correctness of its Data and request that it be updated or corrected.
  • obtain therestriction of the processing. When certain conditions are met, the User may request the restriction of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its preservation.
  • obtain the deletion or removal of their Personal Data. When certain conditions are met, the User may request the deletion of its Data by the Data Controller.
  • receive theirData or have them transferred to another Data Controller. The User has the right to receive its Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another data controller. This provision is applicable when the Data are processed by automated means and the processing is based on the User’s consent, on a contract to which the User is party or on contractual measures related thereto.
  • proposing a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.


Details of the right to object


When Personal Data are processed in the public interest, in the exercise of public authority vested in the Controller or in pursuit of a legitimate interest of the Controller, Users have the right to object to the processing for reasons related to their particular situation.


Users are reminded that if their Data are processed for direct marketing purposes, they may object to the processing without giving any reason. To find out whether the Controller processes Data for direct marketing purposes, Users may refer to the respective sections of this document.


How to exercise rights


To exercise their rights, Users may address a request to the contact details of the Controller indicated in this document. Requests are filed free of charge and processed by the Controller as soon as possible, in any case within one month.


Cookie Policy

This Application makes use of Tracking Tools. To find out more, the User can consult the Cookie Policy.


Further information on processing
Legal defence


The User’s Personal Data may be used by the Owner in legal proceedings or in the preparatory phases of such proceedings to defend against abuses in the use of this Application or related Services by the User.
The User declares that he/she is aware that the Data Controller may be obliged to disclose the Data by order of public authorities.


Specific disclosures


Upon the User’s request, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.


System logs and maintenance


For operation and maintenance purposes, this Application and any third party services used by it may collect system logs, i.e. files that record interactions and that may also contain Personal Data, such as the User’s IP address.


Information not contained in this policy


Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.


Responding to „Do Not Track“ requests


This Application does not support „Do Not Track“ requests.
To find out whether any third party services used support them, the User is invited to consult their respective privacy policies.


Changes to this privacy policy


The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Application as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details it has. Therefore, please consult this page frequently, referring to the date of last modification indicated at the bottom.


If the changes affect processing whose legal basis is consent, the Controller will collect the User’s consent again, if necessary.


Definitions and legal references

Personal data (or Data)


Personal data is any information that, directly or indirectly, even in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.


Usage Data


This is the information collected automatically through this Application (including by third party applications integrated in this Application), including: IP addresses or domain names of the computers used by the User who connects with this Application, URI (Uniform Resource Identifier) notation addresses, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various time connotations of the visit (e.g. the time spent on each page) and details of the itinerary followed by the User. ), the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (e.g. the length of time spent on each page) and the details of the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the operating system and the User’s IT environment.


User


The individual who uses this Application which, unless otherwise specified, coincides with the Data Subject.


Data Subject


The natural person to whom the Personal Data refer.


Data Controller (or Processor)


The natural person, legal entity, public administration and any other entity that processes Personal Data on behalf of the Controller, as set out in this privacy policy.


Data Controller (or Owner)


The natural or legal person, public authority, service or other body that, individually or jointly with others, determines the purposes and means of the processing of personal data and the instruments adopted, including the security measures relating to the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.


This Application


The hardware or software tool through which Users‘ Personal Data are collected and processed.


Service


The Service provided by this Application as defined in the relevant terms (if any) on this site/application.


European Union (or EU)


Unless otherwise specified, any reference to the European Union in this document shall be deemed to include all the current member states of the European Union and the European Economic Area.


Cookies


Cookies are tracking tools that consist of small pieces of data stored within the User’s browser.


Tracking Tool


A Tracking Tool is any technology – e.g. cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting – that allows Users to be tracked, for example by collecting or storing information on the User’s device.

 

Legal references


This Privacy Policy is drafted on the basis of multiple legislative orders, including Articles 13 and 14 of Regulation (EU) 2016/679.


Unless otherwise specified, this privacy policy relates exclusively to this Application.


Last modified: ———-


Cloud Italia hosts this content and collects only the Personal Data strictly necessary for its provision.

FÜR DEN NEWSLETTER ANMELDEN

Bringen Sie etwas Kultur in Ihren Posteingang!

Danke für Ihr Abonnement

Ich habe die Nutzungsbedingungen gelesen und akzeptiere sie