Policy
Privacy Policy
This Privacy Policy describes the personal data processing carried out through the VisitCiciliano website, digital platform, and related services.
Data controller
The data controller is indicated in the official VisitCiciliano project communications and in the institutional channels connected to the portal.
Requests concerning personal data protection may be sent through the contact channels published on the website.
Data processed
The website and platform process data required for the operation of services requested by the user, private area management, security, and related administrative activities.
In particular, the following data may be processed:
- registration and access data, such as first name, last name, email, phone number, roles, and account status;
- data required to manage the Ciciliano Library, including loans, reservations, consultations, deadlines, and documents requested for the service;
- data relating to newsletters, communications, preferences, and consents;
- content, attachments, images, and materials uploaded by authorized users in enabled sections;
- technical data required for operation, account protection, and optional notification management.
Purposes of processing
Data is used to allow access to digital services, manage roles and permissions, provide requested services, administer the library catalogue and loans, send summaries or reminders, and protect the platform.
Data may also be used to comply with administrative or legal obligations and to respond to requests sent by the user.
Legal basis
Processing is based, depending on the case, on the performance of the requested service, compliance with legal obligations, public or legitimate interest in portal security and management, or user consent.
Consent is required, in particular, for newsletters, non-essential analytics cookies, and optional push notifications.
Providers and services used
Data may be processed by authorized persons and technical providers required for service operation.
The platform uses AWS infrastructure for authentication, hosting, databases, private storage, application functions, and email delivery. Some features may use Google services, such as Analytics with consent, Maps and Places for addresses and routes, and Books for bibliographic enrichment.
Data retention
Data is retained for as long as needed to provide the service, document requested operations, and ensure platform security and proper operation.
Login sessions expire according to token duration; cookie consent is stored for 6 months; newsletters remain active until withdrawal; library data is kept for loans, reservations, consultations, history, and administrative obligations.
User rights
Users may request access, rectification, erasure, restriction, objection, and data portability within the limits set by applicable law.
Users may also withdraw consent without affecting the lawfulness of processing carried out before withdrawal.