Privacy Policy
[Art. 13 of European Union Regulation 2016/679 concerning the protection of natural persons with regard to the processing of personal data and the free movement of such data (hereinafter, EU Regulation)]
Why this notice
This page describes the privacy policy of the website www.fondazioneragghianti.it with regard to the processing of personal data of those who provide such data to the Fondazione Centro Studi sull’Arte Licia e Carlo Ludovico Ragghianti.
This notice is provided pursuant to Article 13 of the EU Regulation 2016/679 to those who interact with the web services of the Foundation. It applies only to the website www.fondazioneragghianti.it and not to other websites that may be accessed via links.
Data processing methods
We inform you that the personal data (hereinafter, data) provided, even prior to the establishment of contractual relationships, will be processed solely for the conclusion and management of relationships established with the Foundation in pursuit of its institutional purposes.
Specifically, data processing is aimed at fulfilling obligations that are:
-
statutory, institutional, contractual (e.g., provision of goods or services);
-
administrative (e.g., collection of pre-contractual information, communications exchange), accounting, and tax-related (e.g., proper bookkeeping, invoicing, archiving of mandatory tax declarations);
-
organizational (e.g., meeting convocations, effective management of relationships).
Providing such data is a legal or contractual requirement and is essential for the purposes mentioned above. Refusal to provide or allow processing of such data will make it impossible to continue our relationship.
The data may be processed manually or through electronic, telematic, or automated tools, in compliance with the technical and organizational security measures outlined in Art. 32 of the EU Regulation, and only by authorized personnel in accordance with Art. 29 of the Regulation.
Appropriate technical and organizational measures are implemented to ensure confidentiality and to prevent unauthorized access.
Data is not transferred to third countries. The Foundation uses cloud services provided by companies operating solely within Italy and selected among those offering adequate guarantees pursuant to Art. 46 of the EU Regulation. The Foundation does not have branches outside Italy, does not interact with European or non-European companies for data exchange, and does not transfer, sell, or share data within or outside the European Union.
Data may be disclosed to:
-
Subsidiary, affiliated, or associated entities; external professionals;
-
Subjects whose involvement is necessary to meet the above purposes or legal obligations (e.g., credit institutions for payment processing).
Moreover, members of the Foundation’s governing bodies (Board of Directors, Audit Body, etc.), employees, and collaborators may have access to the data.
Specific information may be published on the Foundation’s website or otherwise disseminated (e.g., through print, CD-ROMs, DVDs) in relation to institutional activities (e.g., presentation of activities, annual financial statements).
The data processed will be:
-
collected for specific, explicit, and legitimate purposes;
-
adequate, relevant, and limited to what is necessary;
-
accurate and, if necessary, updated;
-
processed lawfully and fairly – in compliance with the data protection security requirements of the EU Regulation – by staff or collaborators performing tasks relevant or instrumental to the Foundation’s operations, or providing administrative, assessment, communication, or support services.
Retention period
The data will be retained no longer than necessary to achieve the purposes for which it was collected, and, in any case, in accordance with the statute of limitations on rights arising from law or contracts.
Data subject rights
As a data subject, you may at any time exercise your rights with respect to the Foundation, the Data Controller, including the right to access (Art. 15), rectify (Art. 16), erase (Art. 17), restrict processing (Art. 18), data portability (Art. 20), and the right to lodge a complaint with the Data Protection Authority if you believe your data has been processed unlawfully.
You also have the right to object (Art. 21) at any time, on grounds relating to your particular situation, to the processing.
Further information may be requested from the Foundation’s Secretariat Office (Email: info@fondazioneragghianti.it).
Data Controller
The Data Controller is the Fondazione Centro Studi sull’Arte Licia e Carlo Ludovico Ragghianti, headquartered in Lucca, Via San Micheletto No. 3 – 55100 Lucca; Email: info@fondazioneragghianti.it; PEC: fondazioneragghianti@pcert.postecert.it
Types of data processed
Browsing data
The IT systems and software procedures used to operate this website acquire, during normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.
These data are not collected to be associated with identified individuals but may, by their nature, allow users to be identified through processing and association with data held by third parties.
This category includes IP addresses or domain names of users’ computers, URI (Uniform Resource Identifier) addresses of requested resources, request time, method used to submit the request to the server, size of the file received, server response codes (success, error, etc.), and other parameters related to the user’s operating system and IT environment.
These data are used solely to obtain anonymous statistical information on site usage and to ensure proper operation and are deleted immediately after processing.
The data may be used to establish responsibility in case of hypothetical computer crimes against the site; otherwise, web contact data is not retained for more than seven days.
If you do not want any form of tracking, even anonymous and aggregated, browser add-ons are available to disable information transfer to Google. These are free and compatible with all browsers.
Data voluntarily provided by the user
The optional, explicit, and voluntary sending of email to addresses listed on this site results in the acquisition of the sender’s address (necessary to respond), as well as any other personal data included in the message.
Specific summary notices will be progressively shown or displayed on the website for particular services upon request.
Cookies
Cookies are small text files that websites store on a user’s device. They record preferences, viewed content, and saved items (e.g., in a bookshop cart). They also store information previously entered in text fields (e.g., name, address, password).
The Ragghianti Foundation website uses two technical cookies: FTG Server and pll_language. The former is used by the server load balancing system to improve navigation; the latter maintains the selected site language.
Offline collection of personal data
If personal data is collected offline (e.g., paper forms), an information notice is provided at the same time, and consent is obtained where required. The same applies to forms downloaded from www.fondazioneragghianti.it, which include relevant notices.
Online collection of personal data
For data collected directly on the website (e.g., registration forms), essential privacy information is provided within each form, while this full privacy policy is always available.
The voluntary sending of email to the addresses on this site entails the acquisition of the sender’s address and any other personal data included.
Browsing without registration
Browsing www.fondazioneragghianti.it is free and does not require registration. Visitors who do not register are not subject to tracking regarding referral sources or pages visited.
Newsletter
By subscribing to the newsletter, user data is added to a contact list for email messages containing information on the Foundation’s activities.
Collected personal data: first name, last name, email.
You may also subscribe by sending a request to info@fondazioneragghianti.it. The newsletter contains news and event information.
It is managed using MailChimp, and email addresses are stored on MailChimp servers. MailChimp’s privacy policy is available here: https://kb.mailchimp.com/accounts/management/about-mailchimp-the-eu-swiss-privacy-shield-and-the-gdpr
MailChimp provides information about who opens newsletters and clicks links; this is used to assess interest. To avoid tracking, you can read emails without downloading images.
You may opt out of receiving future communications at any time by following the instructions at the bottom of each email.
Bookshop
To purchase a book from http://www.fondazioneragghianti.it/bookshop/, you must enter your name, tax code, VAT number, email, and phone number.
These are used solely for shipping and are not used for other purposes (e.g., news or greetings).
The relationship begins with the book request and ends with its shipment. Data is stored in both paper and digital archives (Foundation’s servers).
Retention time: 10 years for customers, and until deletion request for newsletter subscribers.
For credit card or PayPal payments, transactions occur on PayPal’s secure platform. The Foundation does not store credit card data and is not liable for any fraudulent use of such data by third parties.
Interaction with social networks and external platforms
These services enable interactions with social networks or other external platforms directly from this website.
The interactions and information acquired are subject to the user’s privacy settings on each network.
If such services are installed, they may collect traffic data even if not used.
Privacy Shield
On July 12, 2016, the European Commission adopted the Privacy Shield framework, governing data transfers between the EU and the USA.
The agreement protects EU citizens’ fundamental rights and establishes rules for businesses transferring data across the Atlantic.
The framework includes:
-
strict data protection obligations for businesses;
-
safeguards regarding US government access to data;
-
specific legal remedies for individuals;
-
an annual joint review of the agreement’s implementation.
The following social networks participate in the Privacy Shield:
-
Facebook button (Facebook Inc.) – Interaction with Facebook
Personal data collected: Cookies and Usage Data
Data location: USA – Privacy Policy -
Flickr button (Flickr Inc.) – Interaction with Flickr
Personal data collected: Cookies and Usage Data
Data location: USA – Privacy Policy -
Instagram button (Facebook Inc.) – Interaction with Instagram
Personal data collected: Cookies and Usage Data
Data location: USA – Privacy Policy -
LinkedIn button (LinkedIn Corporation) – Interaction with LinkedIn
Personal data collected: Cookies and Usage Data
Data location: USA – Privacy Policy -
YouTube button (Google Inc.) – Video content viewer
Personal data collected: Cookies and Usage Data
Data location: USA – Privacy Policy -
Twitter button (Twitter Inc.) – Interaction with Twitter
Personal data collected: Cookies and Usage Data
Data location: USA – Privacy Policy
We use Google Analytics to obtain anonymized usage statistics.
You may configure your browser to prevent cookies or delete them.
With Your Online Choices, you can view and disable installed cookies.