{"id":8701,"date":"2021-02-04T17:18:47","date_gmt":"2021-02-04T16:18:47","guid":{"rendered":"https:\/\/wpvo.test\/?page_id=8701"},"modified":"2023-08-17T10:54:52","modified_gmt":"2023-08-17T08:54:52","slug":"cookie-policy","status":"publish","type":"page","link":"https:\/\/ticket.santacroceopera.it\/en\/cookie-policy\/","title":{"rendered":"Cookie Policy"},"content":{"rendered":"<h2 class=\"entry-title\">Bozza automatica<\/h2><p><\/p>\n<header class=\"hero\">\n<div class=\"hero__content\">\n<div class=\"hero__heading\">\n<header class=\"hero\">\n<div class=\"hero__content\">\n<div class=\"hero__heading\">\n<h1 class=\"hero__title\">Privacy cookie policy<\/h1>\n<div class=\"hero__text formatted-content\">\n<p>in compliance with Art. 14 of Regulation (EU) 2016\/679 governing the protection of personal data.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/header>\n<div class=\"blocks-container--spaced\">\n<div class=\"blocks-container__item\">\n<section class=\"anchor-offset\">\n<div class=\"formatted-content\">\n<p>1. DATA CONTROLLER AND DATA PROTECTION OFFICER (DPO)<br \/>\nThe Data Controller \u2013 as defined in Articles. 4 and 24 of Regulation (EU) 2016\/679 &#8211; \u00a0is the Opera di Santa Croce, whose registered office is situated in Piazza Santa Croce, 16, Florence (FI), Italy \u2013 VAT Reg. No. 05489970482.<br \/>\nThe Controller may be reached at the following e-mail address: privacy@santacroceopera.it.<br \/>\nThe Controller has also appointed a Data Protection Officer (DPO) \u2013 the lawyer Avv. Domenico Vispo \u2013 who may be contacted in connection with matters regarding the processing of the user\u2019s personal data at the following e-mail address: dpo@santacroceopera.it.<\/p>\n<p>2. TYPE OF DATA COLLECTED AND PROCESSED<br \/>\nThe Controller will process the following personal data:<br \/>\n&#8211; personal and contact details;<br \/>\n&#8211; data concerning educational qualifications and profession;<br \/>\n&#8211; data collected passively, in other words via the website (e.g. IP address, position, type of browser and so forth);<br \/>\n&#8211; cookies and other tracking systems, as illustrated in the cookie notice (see relevant information notice for more in-depth information).<\/p>\n<p>3. LEGAL BASIS FOR DATA PROCESSING<br \/>\nThe communication of personal data is a contractual obligation, or at any rate a necessary prerequisite, for completing the contract for the sale of tickets providing access to the monumental complex, and the prospective purchaser is obliged to supply his or her personal data inasmuch as without it the Controller is unable to process the purchaser\u2019s application. Despatch of the newsletter is enabled only when consent is granted by the user. Data for the website\u2019s security and for the prevention of misuse and spam, as well as data for analysing website traffic (statistics) in aggregate form, is processed on the basis of the Controller\u2019s legitimate interest in protecting both the website and its users.<\/p>\n<p>4. PURPOSE OF DATA PROCESSING<br \/>\nPersonal data is processed by the Controller in order to enable the user to surf the website and to use the services it provides; for the on-line sale of tickets providing access to the monumental complex of Santa Croce; and, in the event the user grants his or her specific consent, for the despatch of the Controller\u2019s newsletter. In addition to the relevant instrumental and necessary purposes associated with provision of the service, processing of the data collected from the website is required for the following purposes:<br \/>\n&#8211; Statistics (analysis): the collection of data and information, solely in an aggregate and anonymous fashion, in order to verify the website\u2019s proper functioning. None of this information is linked to the website\u2019s physical user, nor does it permit the user\u2019s identification in any form whatsoever. Prior consent is not required;<br \/>\n&#8211; Security: the collection of data and information for the purpose of protecting the website\u2019s security (anti-spam filters, firewalls, virus detection) and users\u2019 security, and to prevent or to detect fraud or misuse detrimental to the website. The data is recorded automatically and may also include personal data (IP address) which may be used, in accordance with the relevant law in force at the time, to thwart attempts to damage the website or to harm other users, or in any case for harmful or criminal activities. This data is never used on any account to identify or to profile users, and it is periodically erased. Prior consent is not required.<\/p>\n<p>5. PERSONAL DATA END USERS OR CATEGORIES OF END USERS<br \/>\nData collected may be forwarded to end users, as listed in Article 28 of Regulation (EU) 2016\/679, who process the data in their capacity as external professional figures and\/or bodies acting as independent controllers. Specifically, the data may be forwarded: &#8211; to the Controller\u2019s staff and collaborators, including external collaborators, and to figures who provide services instrumental to the purposes described above. These figures will act in their capacity as supervisors or appointees tasked with processing. Personal data may also be forwarded to other public or private figures but solely in compliance with a legal measure or regulation requiring such a move.<br \/>\nData collected on the website is not generally forwarded to third parties, other than in the following specific instances \u2013 a legitimate request from the judicial authorities and in legally specified cases; &#8211; if required for the provision of a specific service requested by the user; &#8211; for the performance of website security and optimisation controls.<\/p>\n<p>6. TRANSFER OF DATA TO A THIRD COUNTRY AND\/OR INTERNATIONAL ORGANISATION<br \/>\nData collected will not be transferred to third countries outside the European Union. Users should be aware, however, that the use of cloud services may entail the transfer of data onto servers situated abroad (whether in the EU or elsewhere) but always in compliance with the relevant legal measures and in every instance in compliance with maximum security standards.<\/p>\n<p>7. DURATION OF STORAGE OR CRITERIA USED TO ESTABLISH THAT DURATION<br \/>\nData collected during the functioning of the website is stored only for as long as is strictly necessary to perform the activities specified. On expiry, the data will be erased or anonymised unless there are further reasons for storing it. Data (IP address) used for website security purposes (thwarting attempts to harm the website) is stored for 30 days. Data used for analytical purposes (statistics) in stored only in aggregate form. Data processed in connection with the sale of tickets providing access to the monumental complex of Santa Croce will be stored for 10 years; and in connection with the despatch of newsletters, it will be stored for the time required to provide the service. The data is not subject to automatic processing.<\/p>\n<p>8. USER RIGHTS AND HOW TO EXERCISE THOSE RIGHTS<br \/>\nThe user may exercise his or her rights as laid down in Section III (articles 15-22) of Regulation (EU) 2016\/679 by addressing an e-mail to the Data Controller at privacy@santacroceopera.it, by registered post with reply \u2013 c\/o the address of the organisation\u2019s registered office \u2013 or by submitting a hardcopy request.<br \/>\nThe rights which the user enjoys under Regulation (EU) 2016\/679 are the following:<br \/>\n&#8211; access;<br \/>\n&#8211; rectification;<br \/>\n&#8211; erasure;<br \/>\n&#8211; withdrawal of consent;<br \/>\n&#8211; restriction of processing;<br \/>\n&#8211; opposition to processing;<br \/>\n&#8211; portability.<br \/>\nThe above rights are guaranteed at no expense to the user and require no particular formalities for their exercise, which is essentially free of charge.<br \/>\nWithout impairment or prejudice to the user\u2019s right to undertake legal action, he or she may also submit a complaint to the supervisory authority (ombudsman) as stipulated both in Regulation (EU) 2016\/679 and in the Italian Privacy Code as modified by Decree Law 101\/2018.<\/p>\n<p>9. DATA PROCESSING MODALITIES<br \/>\nPersonal data granted will be recorded, processed, managed and stored in hardcopy format and\/or with the assistance of electronic instruments, and in every circumstance in such a way as to ensure its security and confidentiality. Processing will be performed by expressly authorised in-house staff and can be peformed at any time.<\/p>\n<p>10. DATA DISSEMINATION<br \/>\nPersonal data collected will never be disseminated under any circumstances whatsoever to third parties not authorised by the Data Controller and may be shown only on demand to the legal, financial and ombudsman authorities and to any other figures with whom we are legally bound to share that data for the achievement of the aforesaid purposes.<\/p>\n<\/div>\n<\/section>\n<\/div>\n<div class=\"blocks-container__item\">\n<section class=\"anchor-offset\"><span id=\"cookie-policy\" class=\"anchor-offset__target\"><\/span><\/p>\n<header class=\"section-heading\">\n<h2 class=\"section-heading__title\">Cookie policy<\/h2>\n<\/header>\n<div class=\"formatted-content\">\n<p>COMPREHENSIVE NOTICE ON THE USE OF COOKIES<\/p>\n<p>In respect of the Measure formulated by the Ombudsman for the Protection of Personal Data, entitled \u201cIdentification of simplified modalities for information regarding, and the acquisition of prior consent to, the use of cookies \u2013 8 May 2014\u201d (Published in the Official Gazette no. 126 dated 3 June 2914) as amended by the guidelines governing cookies and other tracking tools dated 10 June 2021 (Published in the Official Gazette no 163 dated 9 July 2021), the user should be aware that the OPERA DI SANTA CROCE processes only cookies of a technical and\/or analytical nature, and on no account uses profiling cookies. The user\u2019s prior consent is not required for the installation of technical and\/or analytical cookies, but we are nevertheless bound to provide notice thereof in accordance with Article 16 of Regulation (EU) 2016\/679 governing the protection of personal data.<\/p>\n<p>OPERA DI SANTA CROCE, in its capacity as controller, hereby informs the user releasing his or her IP data through consulting the ticka.santacroceopera.it website, regarding the purposes and modalities of the processing of the personal data collected, the circumstances governing its communication and dissemination, and the nature of its granting.<\/p>\n<p>Data collected from the user is exclusively IP-related, in other words it is data that can be defined as coming from public records, thus prior consent for processing purposes is not required.<\/p>\n<p>The data subject to processing is processed and used directly in order to fulfil purposes instrumental to the website (for example, controls to prevent cyberattacks, statistics) in full compliance with the principle of legal propriety and with the legal measures currently in force.<\/p>\n<p>Where the modalities are concerned, the data is processed by electronic means operated by the controller. The user\u2019s data is not communicated to, sold to or exchanged with any third party, nor is it subject to dissemination, other than where mandatorily required by law.<\/p>\n<p>The user may avail him or herself of his or her rights as laid down in Articles 15-22 or the Regulation (EU) 2016\/679 by addressing a request to the processing controller. In particular, the user can obtain confirmation of the existence \u2013 or otherwise \u2013 of personal data concerning him or her, even if such data has yet to be registered, and insist on communicaton of said data in legible form. Users have the right to obtain information regarding:<br \/>\na) the origin of the personal data;<br \/>\nb) the purpose and modality of its processing;<br \/>\nc) the rationale applied in the event of processing performed with the aid of electronic instruments;<br \/>\nd) the identification details of the controller, managers and appointed representatives as defined in Article 5, Paragraph 2;<br \/>\ne) the end users and categories of end users to whom that personal data may be communicated or who may become acquainted with it in their capacity as appointed representatives on national soil, as managers or as appointees.<\/p>\n<p>The user has the right to obtain:<br \/>\na) the updating, rectification or, when to his or her benefit, the completion of the data;<br \/>\nb) the erasure, the transformation into anonymous format or the blocking of data processed in breach of the law, including data whose storage is not required for the purposes for which the data was collected or subsequently processed;<br \/>\nc) certification that the operations described in letters a) and b) above have been communicated, including with regard to their content, to all those to whom the data may have been released or disseminated, other than where such communication proves to be impossible or entails the use of resources manifestly disproportionate to the right safeguarded.<\/p>\n<p>The user has the right to oppose, in whole or in part:<br \/>\na) for legitimate reasons, the processing of personal data concerning him or her, even if that data is relevant to the purpose for which it was collected;<br \/>\nb) for legitimate reasons, the processing of personal data concerning him or her for purposes related to the despatch of publicity or direct sales material or for conducting market research surveys or commercial communication.<\/p>\n<p>The user may exercise his or her rights by sending an e-mail to the one of following addresses: gdpr@midaticket.it and privacy@santacroceopera.it, or by fax or letter addressed to the addressees on the printed paper.<\/p>\n<p>The data is stored in electronic archives and minimum legal security measures are guaranteed.<\/p>\n<p>The controller reserves the right to block access for those IPs whose visits appear to produce anomalies. Users who cannot see website pages or the website itself may write to one of the following e-mail addresses: gdpr@midaticket.it and privacy@santacroceopera.it.<\/p>\n<p>What are cookies?<br \/>\n&#8220;Cookies&#8221; are small text files which a server can save on a computer\u2019s hard disk and which can memorise certain information regarding the user. Cookies allow the website to record the user\u2019s activity and to memorise his or her preferences. Cookies help to analyse interaction between the user and the website and to allow smoother and more customised surfing.<\/p>\n<p>What types of cookies are there?<br \/>\nA cookie can be classified as a \u201csession\u201d cookie or a \u201cpermanent\u201d cookie according to its duration. \u201cSession\u201d cookies are temporary and disappear from a computer when the user leaves the website visited or closes his or her browser. They are usually memorised in the computer\u2019s cache. \u201cPermanent\u201d cookies remain in the user\u2019s computer even after the browser has been closed, either until their expiry or until the user eliminates them. Their expiry date is determined by the website which installs them. They are often used to track the user\u2019s habits so that when the user returns to the website, the cookie reads the information memorised and adapts it to his or her preferences.<br \/>\nA cookie can be classified as \u201ctechnical\u201d or \u201cprofiling\u201d according to its function.<br \/>\n\u201cTechnical\u201d cookies relate to activities strictly necessary for the proper functioning of the website and for provision of the service required. In most cases they are session cookies. No technical cookies require the user\u2019s prior consent because they are not used for purposes other than ensuring that the website can function properly. \u201cProfiling\u201d cookies may be used to track the user\u2019s habits and surfing preferences in order to deliver advertising and services which reflect his or her interests. This kind of cookie is installed or activated only with the user\u2019s prior consent granted on the first occasion on which he or she visits the website. Consent can be expressed by interacting with the short information banner on the website\u2019s homepage according to the modalities specified (by closing the banner, by explicitly agreeing, by browsing the page or by clicking on any element on the page).<\/p>\n<p>What cookies does OPERA DI SANTA CROCE use?<br \/>\nIn its\u00a0<a title=\"Online ticket office\" href=\"https:\/\/santacroce.midaticket.it\/en\/\" target=\"_blank\" rel=\"noopener\">santacroce.midaticket.it\/en<\/a>\u00a0website OPERA DI SANTA CROCE uses technical cookies generated and used for its own website and on no account by third parties. Visiting this website can generate the following kinds of cookie: &#8211; internal cookies and \u2013 technical session cookies: these are used to improve the user\u2019s surfing experience and interaction with the website.<\/p>\n<p>How to disable cookies using the browser: It is possible to configure the browser used for surfing in order to eliminate cookies and\/or to prevent their installation. The user can control what cookies are installed and what their duration is, and\/or eliminate them. The steps required to perform these operations differ from browser to browser. These are the guidelines for the most commonly used browsers.<\/p>\n<p>Instructions on how to disable cookies may be found in the following web pages:<br \/>\nMozilla Firefox &#8211; Microsoft Internet Explorer &#8211; Microsoft Edge &#8211; Google Chrome &#8211; Opera &#8211; Apple Safari<\/p>\n<p>Disabling certain cookies may hinder access to the website and\/or impair the proper functioning of the e-mail pages.<\/p>\n<\/div>\n<\/section>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/header>\n<p><\/p>\n<div class=\"button-container\"><a class=\"entry-button cta-button\" href=\"https:\/\/ticket.santacroceopera.it\/en\/?p=15121\">Find out more<\/a><\/div>","protected":false},"excerpt":{"rendered":"<p>Bozza automatica Privacy cookie policy in compliance with Art. 14 of Regulation (EU) 2016\/679 governing the protection of personal data. 1. DATA CONTROLLER AND DATA PROTECTION OFFICER (DPO) The Data Controller \u2013 as defined in Articles. 4 and 24 of Regulation (EU) 2016\/679 &#8211; \u00a0is the Opera di Santa Croce, <a class=\"modal-link\" href=\"https:\/\/ticket.santacroceopera.it\/en\/cookie-policy\/\" data-post-id=\"8701\">Read all<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-8701","page","type-page","status-publish","h-entry","hentry","h-as-page"],"acf":[],"_links":{"self":[{"href":"https:\/\/ticket.santacroceopera.it\/en\/wp-json\/wp\/v2\/pages\/8701","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ticket.santacroceopera.it\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/ticket.santacroceopera.it\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/ticket.santacroceopera.it\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/ticket.santacroceopera.it\/en\/wp-json\/wp\/v2\/comments?post=8701"}],"version-history":[{"count":5,"href":"https:\/\/ticket.santacroceopera.it\/en\/wp-json\/wp\/v2\/pages\/8701\/revisions"}],"predecessor-version":[{"id":9655,"href":"https:\/\/ticket.santacroceopera.it\/en\/wp-json\/wp\/v2\/pages\/8701\/revisions\/9655"}],"wp:attachment":[{"href":"https:\/\/ticket.santacroceopera.it\/en\/wp-json\/wp\/v2\/media?parent=8701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}