Privacy Policy for the App

Pursuant to art. 13 of EU Regulation 2016/679 (the "GDPR"), this privacy policy is provided with regard to any personal data (hereinafter, the "Data") that may be processed in connection with the use of the official "Duomo di Orvieto" App offered by OPERA DEL DUOMO DI ORVIETO - FABBRICERIA (hereinafter, "Opera del Duomo di Orvieto" or the "Data Controller"), which can be downloaded free of charge by the User in order to use the Duomo di Orvieto information service and to consult the audio guides (hereinafter, for the sake of brevity, the "Service").

The data controller is OPERA DEL DUOMO DI ORVIETO - FABBRICERIA, tax code 81000670554, with registered offices at no. 26 Piazza del Duomo, Orvieto, Italy – postal code 05018.

Certified e-mail: opsm@pec.it

Telephone number: +39 0763 342477

E-mail: info@duomodiorvieto.it

 

Scope of the data’s disclosure and dissemination

The data collected consist of the identification data of the device used by the data subject (log, IP, user agent) and, if the audioguides are unlocked, the identifier of the ticket acquired.

The Data may be disclosed to employees and/or collaborators of the Data Controller who have been tasked with managing the Data. These individuals have received appropriate instructions from the Data Controller in this regard pursuant to art. 29 of the GDPR, and shall process the Data exclusively for the purposes indicated in this policy and in compliance with the applicable regulations.

The Data may also be disclosed to third parties tasked with processing the Data on behalf of the Data Controller as external data processors, and other third parties who have been adequately selected, with verified experience, capability, and reliability, and who have agreed to comply with the current legal provisions concerning the processing of personal data. The complete and updated list of data processors appointed by the Data Controller can be requested by sending an e-mail to the following address: info@duomodiorvieto.it

 

Types of data processed and purposes of processing

The purpose of the processing is to allow for the use of the Service, in particular:

  • To provide information on the Orvieto Cathedral and the Emilio Greco Museums and Museo dell'Opera del Duomo
  • To provide access to audioguides for holders of authorised tickets
  • With the data subject's prior consent, the App may collect data regarding the user's geographical location. The App uses location services to notify the user of points of interest in the device's vicinity. If the user does not give consent, the App will not have access to location services. The user can activate/deactivate geolocation services at any time through the settings provided by their device and continue using the App.
  • The user's personal data may also be processed by the data controller if the data subject grants his/her specific consent for marketing purposes, which include the sending of advertising material for services, events and initiatives promoted by the Data Controller, through electronic communication tools (e.g. email, text messages, etc.) and through traditional tools (e.g. regular mail and/or marketing calls)

The processing operations carried out by the Data Controller do entail any automated decision-making processes, and the Data will not be disseminated.

The Data will be processed in accordance with the principles of correctness, lawfulness, and transparency, in compliance with the data security and confidentiality rules.

 

Legal basis of the data processing

For the purposes of the services available through the App (provision of information on the Orvieto Cathedral and the Emilio Greco Museums and Museo dell'Opera del Duomo), the legal basis of the data processing is the performance of the contract to which the data subject is a party.

For the purposes of the geolocation services, which can be deactivated via the device at any time, the legal basis of the data processing is the data subject's consent.

For marketing purposes, the legal basis of the data processing is the user's freely given consent, which can be revoked at any time without any effect on the user's ability to use the products and services, and will only impede the Data Controller from keeping users/customers up-to-date on new initiatives or special promotions or benefits that may be available.

 

Processing methods

The processing of the user's personal data will be carried out using manual, computerised and telematic tools, exclusively for the fulfilment of the purposes in question, and, regardless, in such a way as to guarantee their security and confidentiality. The data will be processed using systems designed to store, manage and transmit the data, with logics strictly related to the purposes themselves, based on the data in our possession, and with the user's commitment to promptly notify the data controller of any corrections, additions and/or updates to be applied.

It should be noted that, during the course of their normal operation, the computer systems and software procedures used to operate the App (Apple Store or Google Play) acquire certain data referable to the user, the transmission of which is implicit in the use of internet communication protocols, smartphones, and the devices utilised.

The data subject may consult the privacy information available on the following websites:

 

Data retention

The personal data subject to processing will be retained in compliance with the provisions of article 5(1)(e), cited above, in a form that allows for the identification of the data subjects for a period of time not exceeding the fulfilment of the aforementioned purposes for which the personal data are processed. In particular, the personal data collected for the purpose of providing the services related to the App are only retained for the time strictly necessary for the user's activation and use of the services provided by the App, without prejudice to any legal obligations. The personal data collected for marketing purposes are retained until the data subject decides to revoke his/her consent and, regardless, for no more than 24 months following the deactivation and uninstallation of the App. At the end of the retention period, the data provided the data subject shall be deleted or converted into anonymous form.

 

Data provision

The provision of the personal data by the user and their consequent processing by the data controller are necessary for the provision of the services provided by the App.

Any refusal on the part of the user to provide the personal data requested may make it impossible for the data controller to proceed with the activation of the App and the provision of the services requested.

With regard to the processing of data for geolocation and marketing purposes, the provision of the data by the user is purely optional. Any refusal to provide such data will not have any effect on existing or ongoing legal relationships, and will only prevent the App from using geolocation services and/or sending advertising materials for services, events and initiatives promoted by the Data Controller through electronic communication tools (e.g. email, text messages, etc.) and traditional tools (e.g. regular mail and/or marketing calls).

 

Rights of the data subject

Without prejudice to the preceding paragraphs, the data subject has the right:

  • to request that the Data Controller rectify, delete, or grant him/her access to the Data, or to object to their processing;
  • in the case of processing carried out on the legal basis of consent, to revoke his/her consent at any time, without affecting the lawfulness of the consent-based processing carried out prior to revoking consent;
  • to lodge a complaint with the national supervisory authority;
  • to receive the Data provided in a structured, commonly used, and machine-readable format for portability purposes.

In order to exercise the rights listed above, or for any requests concerning the processing of his/her Data and the security measures adopted, the data subject may write to the following e-mail address info@duomodiorvieto.it

 

Minors

If the person providing the personal data is under 16 years of age, the aforementioned data processing is only considered lawful if, and to the extent that, consent is given or authorised by a parent or guardian. The Data Controller shall bear no responsibility for any untruthful statements provided by the user. If is determined that the personal data provided include false statements, they shall be deleted immediately.