Privacy and cookies

Privacy and Cookie Policy

Privacy notice provided pursuant to Articles 12, 13 and 14 of Regulation (EU) 2016/679 on the processing of personal data carried out through this website.

Last updated: 6 September 2026


Section 1Data controller

The data controller is the Associazione Turistica Pro Loco di Cavola, which determines the purposes and means of the processing of the personal data collected through this website.

Name
Associazione Turistica Pro Loco di Cavola
Registered office
Via Santa Maria, 5 · 42010 Cavola (RE)
Codice fiscale
91153320352
Partita IVA
02450480351
General email
info@cavola.it

For information, or to exercise your data protection rights, you can write to info@cavola.it or send a communication to the association's registered office. No data protection officer has been appointed, as the conditions under Article 37 GDPR do not apply.

Section 2Types of data collected

Ordinary personal data

Only the data that the data subject voluntarily enters in the website's forms is collected:

  • Contact form: first name, email and message. Surname and telephone number are optional.
  • Booking form: first name, surname, email, telephone, chosen date, number of people and optional organisational notes.

Browsing data

The IT systems that operate this website may record technical data normally transmitted while browsing, such as the IP address, the date and time of the request, the page requested, the browser and the server response code.

What this website does not collect

  • No profiling, advertising or analytics cookies
  • No third-party statistics tools, such as Google Analytics or social network pixels
  • No embedded content that automatically tracks the visitor, such as maps or social videos
  • No profiling and no automated decision-making within the meaning of Article 22 GDPR

Anyone who provides other people's data, for example the names of the other guests at a lunch, takes responsibility for providing it and warrants that they have the right to pass it on.

Section 3Purposes of the processing

The data collected is used solely in order to:

  1. Reply to contact enquiries received through the website and manage the resulting relationships.
  2. Manage bookings for the Festa del Tartufo lunch: checking availability, confirmation, notification of changes or practical information.
  3. Organise the catering service on the basis of the number of guests and the requirements stated in the organisational notes.
  4. Ensure the security of the website, prevent automated or abusive form submissions and diagnose technical problems.

The data is not used for marketing purposes, sending newsletters, profiling or analysis of visitors' behaviour, and it is not transferred to third parties for commercial purposes.

Section 4Legal basis for the processing

  • Taking steps at the request of the data subject (Article 6(1)(b) GDPR), in order to handle the enquiry and the booking.
  • Legitimate interests of the data controller (Article 6(1)(f) GDPR), in order to reply to the communications received, ensure the security of the website and prevent misuse of the forms.
  • Compliance with legal obligations (Article 6(1)(c) GDPR), where the processing is necessary under a rule applicable to the association.

Section 5Methods, recipients and place of processing

Methods

The forms do not feed any website database. The data is sent by email to the Pro Loco's mailboxes, which therefore constitute the actual archive of requests, and is processed using IT tools by authorised persons who are bound by confidentiality.

The security measures in place include transmission over an encrypted HTTPS connection, data validation on both the browser side and the server side, anti-spam protection based on a hidden field and a limit on submission frequency, and restriction of access to the mailboxes to authorised persons only.

The anti-spam system retains, for no more than 24 hours, an identifier derived from the IP address that is not directly readable, together with the time of the last submission. It does not retain the content of the messages and does not use any external tracking services.

Recipients

  • Persons authorised by the Pro Loco who manage the mailboxes, enquiries and bookings, instructed pursuant to Article 29 GDPR.
  • Catering service staff, limited to the information needed to organise the meal.
  • Aruba S.p.A., hosting and email provider, acting as data processor pursuant to Article 28 GDPR.

Personal data is not disseminated. An up-to-date list of the authorised parties may be requested from the data controller at any time.

Place

The data is processed at the association's premises and on the systems of the hosting and email provider. Aruba states that its standard hosting and email services are run in its own Italian data centres.

For the arrangement described, no transfers of personal data outside the European Economic Area are envisaged. Any future changes of provider or of services will entail a new assessment and an update of this privacy notice.

Section 6Retention periods

The data is kept for no longer than is necessary for the purposes indicated, in accordance with the storage limitation principle set out in Article 5(1)(e) GDPR.

DataRetention
Contact enquiries and bookingsA maximum of 12 months from the last relevant communication: once this period has elapsed, the data is erased. Legal obligations and any retention necessary to defend a claim remain unaffected.
Technical anti-spam identifierA maximum of 24 hours
Provider's technical logsIn accordance with the periods laid down by the service activated and by the applicable legal obligations

At least once a year the Pro Loco reviews its mailboxes in order to delete messages that are no longer needed, empty the bin and check the archive folders.

Once the retention period has elapsed, the data is erased. From that point on, the rights of access, rectification, erasure and data portability can no longer be exercised over that data.

Section 8Rights of the data subject

Within the limits laid down by Articles 15 et seq. GDPR, the data subject has the right to:

  • Withdraw consent at any timeWithdrawal does not affect the lawfulness of the processing carried out before the withdrawal itself.
  • Object to the processingWhere the processing is based on a legal basis other than consent, in particular on the legitimate interests of the data controller, on grounds relating to the data subject's particular situation.
  • Access their dataObtain confirmation of the processing, information on the purposes and the recipients, and a copy of the data processed.
  • Check and request rectificationHave inaccurate or incomplete data corrected, updated or completed.
  • Obtain restriction of processingIn that case the data is only stored and is not used any further.
  • Obtain the erasure of their dataIn the cases provided for by Article 17 GDPR, including the deletion of the messages kept in the mailboxes.
  • Receive their data or have it transmittedIn a structured, commonly used and machine-readable format, where the processing is based on consent or on a contract and is carried out by automated means.
  • Lodge a complaintWith the competent supervisory authority, in Italy the Garante per la protezione dei dati personali (the Italian data protection authority), Piazza Venezia 11, 00187 Roma, or bring proceedings before the courts.

How to exercise these rights

It is enough to send a request to info@cavola.it or a communication to the association's registered office, stating:

  1. the right that you intend to exercise;
  2. the identifying details of the person writing, in particular first name, surname and the email used for the enquiry or the booking;
  3. the event or the booking to which the request relates, where relevant;
  4. a copy of an identity document, only where necessary to verify the identity of the person making the request.

Requests are free of charge and are answered as soon as possible and in any event within one month of receipt; this period may be extended by a further two months in particularly complex cases, with notice to the data subject within the first month.

A complaint may be lodged with the Garante per la protezione dei dati personali, using the contact details published on the authority's website.

Section 9Definitions and legal references

Definitions

Personal data. Any information that, directly or indirectly, including in connection with any other information, makes a natural person identified or identifiable.

Sensitive personal information, or special categories of data. Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data, data concerning health, sex life or sexual orientation. Their processing is generally prohibited by Article 9 GDPR, unless one of the conditions in paragraph 2 applies.

Usage data. Information collected automatically by the website or by the systems hosting it, including the IP address, the time of the request, the address of the resource requested, the method used, the server response code and parameters relating to the user's browser.

User. The person who uses this website and who, unless otherwise stated, is the same person as the data subject.

Data subject. The natural person to whom the personal data relates.

Data processor. The natural or legal person, or other body, which processes personal data on behalf of the data controller, in compliance with the instructions given pursuant to Article 28 GDPR.

Data controller. The party which, alone or jointly with others, determines the purposes and means of the processing of personal data and the security measures relating to the operation of the website. For this website it is the Associazione Turistica Pro Loco di Cavola, identified in Section 1.

Cookie. A tracking tool consisting of small pieces of data stored in the user's browser. Cookies are technical where they are used for the sole purpose of carrying out the transmission of a communication or to the extent strictly necessary to provide a service explicitly requested by the user.

Tracking tool. Any technology, such as cookies, unique identifiers, web beacons, embedded scripts or fingerprinting, that makes it possible to track users by collecting or storing information on their device.

Legal references

  • Regulation (EU) 2016/679 of 27 April 2016 (GDPR), in particular Articles 5, 6, 7, 9, 12 to 22, 28 and 32.
  • Legislative Decree No. 196 of 30 June 2003, as amended by Legislative Decree No. 101 of 10 August 2018.
  • Directive 2002/58/EC, known as the ePrivacy Directive, as amended.
  • Italian Data Protection Authority Decision No. 231 of 10 June 2021, Guidelines on cookies and other tracking tools.

Unless otherwise stated, this privacy notice concerns this website only.

Section 10Updates to this privacy notice

This privacy notice will be updated whenever the forms, the providers, the technical tools or the purposes of the processing change. The current version is permanently published on this page, with the date of the last update shown at the top.

Where the changes concern processing based on consent, consent will be collected again where necessary.

Do you need a simpler version?

The summary sets out in a few lines what data we collect, where it goes, how long it is kept and how to exercise your rights.