Information on the processing of personal data of website users

Articles 13 and 14 of Regulation 2016/679/EU (hereinafter also “GDPR”)

Why this notice?

Consorzio Turistico Città di Pistoia (hereinafter also “Company” or “Owner”) is committed to respecting and protecting your privacy and wants you to feel safe both during simple navigation of the site and in the event that you decide to register by providing us with your personal data to use the services made available to its Users and/or Customers. On this page, the Company intends to provide some information on the processing of personal data relating to users who visit or consult the website accessible electronically from the address https://www.pistoiaturismo.it/ (the “Site”). The information is provided only for the Company's website and not for other websites that may be consulted by the user via links (for which reference is made to the respective privacy policies/information). The reproduction or use of pages, materials and information contained within the Site, by any means and on any medium, is not permitted without the prior written consent of the Company. Copying and/or printing is permitted for personal and non-commercial use only (for requests and clarifications contact the Company at the addresses indicated below). Other uses of the contents, services and information on this site are not permitted.

With regard to the contents offered and the information provided, the Company will ensure that the contents of the Site are kept reasonably updated and revised, without offering any guarantee on the adequacy, accuracy or completeness of the information provided, explicitly declining any responsibility for any errors of omission in the information provided on the Site.

Origin - Navigation data

The Company informs that the personal data provided by you and acquired at the same time as the request for information and/or contact, registration on the site and use of services via smartphone or any other instrument used to access the Internet, as well as the data necessary for the provision of such services, including navigation data and data used for the possible purchase of products and services offered by the Company but also the so-called "navigation" data of the site by the Users, will be processed in compliance with the applicable legislation. The computer systems and software procedures used for the operation of this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of the Internet. This information is not collected to be associated with identified interested parties, but by its very nature could, through processing and association with data held by third parties, allow the identification of browsing users. This category of data includes the "IP addresses" or domain names of computers used by users who connect to the site, the URI (Uniform Resource Identifier) ​​addresses of the resources requested, the time of the request, the method used to submit the request to the web server, the size of the file obtained in response, the numerical code indicating the status of the response given by the web server (successful, error, etc.) and other parameters relating to the operating system and the user's computer environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the site and to check the correct functioning of the Company's website. It should be noted that the aforementioned data could be used to ascertain responsibility in the event of computer crimes against the Company's site or other sites connected or linked to it: except for this eventuality, at present the data on web contacts do not persist for more than a few days.

Origin - Data provided by the user

The Company collects, stores and processes your personal data for the purpose of providing the products and services offered on the Site, or for legal obligations. In relation to some specific Services, Products, Promotions, etc., the Company may also process your data for commercial purposes. In such cases, specific, separate, optional and always revocable consent will be requested with the methods and contact details indicated below.

The optional, explicit and voluntary sending of e-mails to the addresses indicated in the appropriate section of the Website, as well as the compilation of questionnaires (e.g. forms), communication via chat, push notification via APP, social networks, call centers, etc., involves the subsequent acquisition of some of your personal data, including those collected through the use of the Apps and related services, necessary to respond to requests. We also point out that when using the mobile connection to access digital content and services offered directly by the Company or by our Partners, it may be necessary to transfer your personal data to such third parties. We point out that you may access the Site or connect to areas where you may be able to publish information using blogs or bulletin boards, communicate with others, for example by coming from the Company page on Facebook®, LinkedIn®, YouTube®, and other social networking sites, review products and offers and publish comments or content. Before interacting with these areas, we invite you to carefully read the General Conditions of Use, taking into account that, in certain circumstances, the information published may be viewed by anyone with access to the Internet and all the information you include in your publications may be read, collected and used by third parties.

Purpose of processing and legal basis

The data is processed for the following purposes:

  1. strictly connected and necessary for registration on the site https://www.pistoiaturismo.it , for the services provided by the Company, for the use of the related information services, for the management of contact or information requests, for the purchase of products and services offered through the Company's site;
  2. for ancillary activities related to the management of User/Customer requests and the sending of feedback which may include the transmission of promotional material; for the completion of the purchase order of the products and services offered, including aspects relating to payment by credit card or PayPal, the management of shipments, any exercise of the right of withdrawal provided for remote purchases, the update on the availability of products and services temporarily unavailable;
  3. related to the fulfillment of obligations set forth by community and national regulations, to the protection of public order, to the identification and repression of crimes;
  4. direct marketing, i.e. sending advertising material, direct sales, carrying out market research or commercial communication of products and/or services offered by the Company; this activity may also concern products and services of Companies of the Company's Group and be carried out by sending advertising/informative/promotional material and/or invitations to participate in initiatives, events and offers aimed at rewarding users/customers, carried out using "traditional" methods (for example, paper mail and/or calls from an operator), or using "automated" contact systems (for example, SMS and/or MMS, telephone calls without operator intervention, e-mail, fax, interactive applications), pursuant to art. 130 paragraphs 1 and 2 of Legislative Decree 196/03 and subsequent amendments;

The provision of data for the purposes referred to in points 1), 2) and 3), connected to a pre-contractual and/or contractual phase or functional to a user request or required by a specific regulatory provision, is mandatory and, in its absence, it will not be possible to receive the information and access the services requested; with regard to point 4) of this Information, the consent to the processing of data by the user/customer is instead free and optional and can always be revoked without consequences on the usability of the products and services except for the impossibility for the Company to keep users/customers updated on new initiatives or on particular promotions or advantages that may be available.

The Company may send commercial communications relating to products and/or services similar to those already provided, pursuant to Directive 2002/58/EU, using the email or paper coordinates indicated by you on such occasions, which you may object to using the methods and contact details below.

Methods, processing logic, storage times and security measures

The processing is also carried out with the aid of electronic or automated means and is carried out by the Company and/or by third parties that the Company may use to store, manage and transmit the data. The data processing will be carried out with the logic of organization and processing of your personal data, also relating to the logs originating from the access and use of the services made available via the web, of the products and services used related to the purposes indicated above and, in any case, in a way to guarantee the security and confidentiality of the data. The personal data processed will be stored for the times established by the legislation applicable at the time.

Always with regard to data security, in the sections of the website set up for particular services, where personal data are requested from the user, the data is encrypted using a security technology called Secure Sockets Layer, abbreviated to SSL. SSL technology encodes the information before it is exchanged via the Internet between the user's computer and the Company's central systems, making it incomprehensible to unauthorized persons and thus guaranteeing the confidentiality of the information transmitted; furthermore, transactions carried out using electronic payment instruments are carried out directly using the Payment Service Provider (PSP) platform and the Company only retains the minimum set of information necessary to manage any disputes. Precisely with reference to the aspects of personal data protection, the user/customer is invited, pursuant to art. 33 of the GDPR, to report to the Company any circumstances or events from which a potential "personal data breach" may arise in order to allow an immediate evaluation and the adoption of any actions aimed at countering such an event by sending a communication to privacy@Azienda.it or by contacting Customer Service. The measures adopted by the Company do not exempt the Customer from paying the necessary attention to the use, where required, of passwords/PINs of adequate complexity, which he/she must update periodically, especially if he/she fears that they have been violated/known by third parties, as well as carefully guarding them and making them inaccessible to third parties, in order to avoid improper and unauthorised use.

Cookies

A cookie is a short string of text that is sent to your browser and, possibly, saved on your computer (alternatively on your smartphone/tablet or any other device used to access the Internet); this sending generally occurs every time you visit a website. The Company uses cookies for various purposes, in order to offer you a fast and safe digital experience, for example, allowing you to keep the connection to the protected area active while browsing through the pages of the site.

Cookies stored on your terminal cannot be used to retrieve any data from your hard disk, transmit computer viruses or identify and use your email address. Each cookie is unique in relation to the browser and device you use to access the Company's Website. In general, the purpose of cookies is to improve the functioning of the website and the user's experience in using it, even if cookies can be used to send advertising messages (as specified below). For more information on what cookies are and how they work, you can consult the website "All about cookies" http://www.allaboutcookies.org .

For detailed information on Cookies, please read the dedicated page ( https://www.pistoiaturismo.it/cookies/ )

Areas of communication and data transfer.

In order to pursue the purposes indicated above, the Company may communicate and have the personal data of users/customers processed, in Italy and abroad, by third parties with whom we have relationships, where these third parties provide services at our request. We will provide these third parties only with the information necessary to perform the requested services, taking all measures to protect your personal data. The data may be transferred outside the European Economic Area if this is necessary for the management of your contractual relationship. In this case, the recipients of the data will be subject to protection and security obligations equivalent to those guaranteed by the Data Controller. In the case of use of services offered directly by Partners, we will provide only the data strictly necessary for their performance. In any case, only the data necessary for the pursuit of the intended purposes will be communicated and, where required, the guarantees applicable to data transfers to third countries will be applied. We may also disclose personal data to our commercial service providers, for marketing reasons, who will be appointed as external data processors for this purpose. Furthermore, personal data may be communicated to the competent public bodies and authorities for compliance with regulatory obligations or to ascertain responsibility in the event of computer crimes against the site, as well as communicated to, or allocated to, third parties (as managers or, in the case of electronic communication service providers, as independent owners), who provide IT and telematic services (e.g. hosting services, management and development of websites) and which the Company uses to carry out tasks and activities of a technical and organizational nature that are instrumental to the functioning of the website. The parties belonging to the categories listed above operate as separate Data Controllers or as Managers appointed for this purpose by the Company.

Personal data may also be disclosed to Company employees/consultants who are specifically trained and appointed as Data Processors.

The categories of recipients to whom the data may be communicated are available by contacting the Company at the addresses indicated below.

Rights of interested parties

You may exercise at any time the rights granted to you by law, including:

  1. to access your personal data, obtaining evidence of the purposes pursued by the Data Controller, the categories of data involved, the recipients to whom they may be communicated, the applicable retention period, the existence of automated decision-making processes;
  2. to obtain without delay the rectification of inaccurate personal data concerning you;
  3. to obtain, in the cases provided for, the deletion of your data;
  4. to obtain the limitation of the processing or to oppose it, when possible;
  5. to request the portability of the data that you have provided to the Company, that is, to receive them in a structured, commonly used and machine-readable format, also to transmit such data to another owner, within the limits and with the constraints set forth in art. 20 of the GDPR;

Furthermore, you may lodge a complaint with the Personal Data Protection Authority pursuant to art. 77 of the GDPR.

For the treatments referred to in point 4) of the purposes, the Customer may always revoke consent and exercise the right to object to direct marketing (in "traditional" and "automated" form). The opposition, in the absence of an indication to the contrary, will refer to both traditional and automated communications.

Data Controller

The data controller, pursuant to art. 4 of the GDPR, is Consorzio Turistico Città di Pistoia, Viale Adua, 128 – 51100 Pistoia (PT) VAT number: 01416600474

The above rights may be exercised upon request of the interested party using the methods disclosed by Customer Service or on the Company's website or by using the following references: Conzorzio Turistico Città di Pistoia (info@pistoiaturismo.it).

The use of the Website, including those intended for tablets and/or smartphones, by the Customer and/or the User implies full knowledge and acceptance of the content and any indications included in this version of the information published by the Company at the time of access to the site. The Company informs that this information may be modified without prior notice and therefore recommends periodic reading.

The Data Controller

Tourist Consortium City of Pistoia

This privacy policy was updated on 05/05/2025

This site and third parties use cookies or similar technologies for technical purposes and, with your consent, for other purposes. Click on Accept to enable them all, on Choose for individual preferences or on Deny to enable only those necessary. To learn more: Cookie policy.