Privacy

BUYTOURISMONLINE.COM

buytourismonline.com is the official portal of BTO – Buy Tourism Online, an “event-conference”, whose brand is own by  Toscana Promozione Turistica / Regione Toscana and Camera di Commercio di Firenze, an integral part of the actions supported by Region of Tuscany for digital communication development and promotion of the tourist offer purposes.

PRIVACY INFORMATION

In accordance with national legislation (Legislative decree 196/June 30, 2003 regarding the protection of personal data) and community legislation (EU regulation for the protection of personal data, n. 679/2016, GDPR) and later modifications, this website respects and safeguards the privacy of visitors and users, ensuring that every possible and proportional attempt will be made to not impinge on the rights of its users.

The present privacy policy applies exclusively to online activity on the present website and is valid for visitors/users of the site. It does not apply to data collected via other channels. This information on the protection of privacy serves to provide maximum transparency regarding the information that the website collects and uses.

DATA CONTROLLER AND DATA PROCESSOR

The Data Controller pursuant to the laws in force is:

Regione Toscana – Giunta regionale
Piazza Duomo, 10
50122 Firenze

DATA PROTECTION OFFICER

The Data Protection Officer (DPO) of the Data Controller can be reached at the following e-mail address:

Data Protection Officer of the Regione Toscana – Giunta regionale (regional council): urp_dpo@regione.toscana.it

LEGAL BASIS OF PROCESSING DATA

The present website processes data only upon agreement.

The provision of data and therefore Agreement to collect and process data is optional; the User can refuse to consent and revoke at any time previously-given consent. Doing so, however, could result in blocked access to some services and navigation of the website could be compromised. Beginning on May 25, 2018 (when the GDPR went into effect), the present website will process some data selected based on the legitimate interests of the owner of the data processing.

CONTENT

buytourismonline.com brings together texts and multimedia (texts, images, sounds, video clips, graphics, logos, audiovisuals, etc., henceforth known as “content”) for aforementioned purposes.

The content is produced by:

  • BTO – Buy Tourism Online owners, organisers and promoters staff
  • Third parties (photographers, videomakers, bloggers, etc.), who grant BTO – Buy Tourism Online owners, organisers and promoters permissions for the use of their own textual and multimedia content

All those who provide content through the participation in BTO – Buy Tourism Online expressly accept the following legal conditions:

  1. They declare and guarantee that they are the sole owners of the authors’ rights to the content (either because they themselves are the authors of the content or because they purchased the rights to use and reproduce it from its legitimate owners); they therefore guarantee BTO – Buy Tourism Online owners, organisers and promoters the content provided, as concerns the legitimacy, veracity, accuracy and legitimate provenance regarding the rights of industrial and/or intellectual property or the laws related to privacy.
  2. They declare and guarantee that the content does not contain images that are offensive, disrespectful or harmful to human dignity and a common sense of decency or that they bear prejudice towards someone or something (including in the form of suspicion or threat). The content must not be discriminatory or incite among the public illegal acts, violence or hate based on religion, skin colour or national or ethnic origin. BTO – Buy Tourism Online owners, organisers and promoters are held harmless of any adverse consequence connected to a violation of this ban.
  3. They declare and guarantee that the content does not include specific information regarding health, race, ethnicity, etc. and that they are submitted with the full responsibility of the providers, with BTO – Buy Tourism Online owners, organisers and promoters limited – for content not produced by its own staff – to simply checking the legitimacy in protection of personal dignity and freedom.

All the content is protected by current laws regarding authors’ rights and intellectual property, and, therefore, unauthorized reproductions, use of content and/or making the content available to the public (even through file-sharing) is not allowed. Anyone who violates this ban is subject to civil and criminal penalties in accordance with the law.

VIEWING CONTENT FROM EXTERNAL PLATFORMS

This service allows for content hosted on external platforms to be viewed directly from the pages of this Application and to interact with them.
When this service is installed, it’s possible that data will be collected regarding the traffic related to the pages on which it is installed, even in the case of Users who don’t use the service.

Google Fonts (Google, Inc.)
Google Fonts is a service for visualizing font styles manages by Google Inc, allowing this Application to incorporate such content into its pages.
Personal Data collected: Cookies and Data Usage.
Processing location: United States – Privacy Policy.

Widget Google Maps (Google Inc.)
Google Maps is a service for visualizing maps managed by Google Inc, allowing this Application to incorporate such content into its pages.
Personal Data collected: Cookies and Usage Data.
Processing location: United States – Privacy Policy.

LINK

buytourismonline.com may contain links to other websites or social media that are not necessarily under the control of the Data Controller and/or of the Data Processors.

The user is encouraged to carefully read the conditions and terms of operation and use of these sites. The Data Controller and/or the Data Processor do not assume responsibility either for the unauthorized use of user’s data or for any further monitoring or profiling that may be carried out by the aforementioned sites.

COLLECTED DATA AND PURPOSES

As with all websites, the present site also uses log files which conserve data collected automatically during a visit to the website. The data collected could be the following:

  • Internet protocol address (IP);
  • Browser type and parameters of the device used for connecting to the site;
  • Name of the internet service provider (ISP);
  • Date and time of visit;
  • Webpage the visitor connected from (referral), as well as the subsequent page upon exiting;
  • Number of clicks.

To ensure security (anti-spam filters, firewall, survey of viruses), the data registered automatically could be used, in accordance with the relevant current laws, to block attempts to damage the website or other users, as well as damaging or criminal activities. Such data are never used for identifying and profiling the user, but are only intended to safeguard the website and its users (since May 25, 2018, data may be processed on the basis of the legitimate interests of the Data Controller pursuant to current regulations).

The data collected from the website during its operation are used exclusively for the aims indicated and are conserved for the time necessary for carrying out precise activities or, if applicable, until there is a cancellation request for accounts registered to the website. The data collected from the website will never be passed to third parties for any reason, unless there is a legitimate request from judicial authorities and only in cases allowed by law.

By accessing and navigating the website, users accept that the aforementioned data are processed for the previously-mentioned purposes of IT security and preventing illegal activities. The user can request that their data be cancelled and/or exercise their rights as protected by current laws.

PROCESSING LOCATION

The data can be processed at the Data Center ex TIX (Tuscany Internet Exchange), Via San Piero a Quaracchi n. 250 – Florence, now part of the Sistema Cloud della Toscana (SCT – Tuscany Cloud System) and at Hetzner Online GmbH, Industriestr. 25 – 91710, Gunzenhausen, Germany. In compliance with community law (European Regulation for the protection of personal data 2016/679,  Art. 28, par. 3), organizations who process personal data on behalf of Data Controller or Data Processor have been appointed as Data (Sub-)Processors,  to ensure compliance with the requirements of the Regulation.

COOKIES

As with all websites, buytourismonline.com also uses cookies, small strings of texts that allow for the website to conserve data regarding users’ preferences in order to improve the site’s operation, simplify navigation by automating processes (ex. login, language) and analyze site use.

Session cookies are essential for distinguishing connected users, and are useful for ensuring that a requested function not be provided to the wrong user, as well as for security purposes so as to avoid damaging attacks on the website. Session cookies do not contain personal data and last only as long as the session does, that is, until the browser is closed. Consent is not needed for them.

Functionality cookies used by the website are strictly necessary for operating the site; they are those connected to a user’s request for a specific function (like login), for which consent is not needed).

Using the website, the visitor expressly agrees to the use of cookies.

MANAGING COOKIES: CONSENTING THEIR USE

Deleting cookies does not preclude use of the site.

Users / visitors can set the computer browser to accept / reject all cookies or display a warning every time a cookie is proposed, in order to evaluate whether to accept it or not.

By default, almost all web browsers are set to automatically accept cookies.
Users / visitors can still change the default setting, or disable cookies (i.e. block them permanently), by setting the highest level of protection in the browser, however, disabling them can compromise the use of site functions.

In any case, it remains possible to delete or remove cookies from your device, using the appropriate functions present in the browser. Deleting the cookies does not preclude the use of the site, but involves the repetition of the authentication procedure, or the re-submission of the access credentials.

There are also components (plugins) for the most popular browsers that allow:
• the management (display, cancellation, block) of cookies
• disabling third party JavaScript pages
• visualization of the technologies used by the site
• the visualization and (selective) blocking of the different tracking mechanisms

DISABLING COOKIES

Cookies can be disabled directly from the browser used, thus denying / revoking consent for the use of cookies. It should be noted that disabling cookies can impede upon the correct use of some functions on the wesbite.

GOOGLE ANALYTICS / TAG MANAGER

The services contained in the present section allow Data Controller and/or Data Processors to monitor and analyse traffic data and serve for tracing the User’s behaviour.

Google Analytics (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc (“Google”). Google uses the Personal Data collected for the purposes of tracing and examining the use of this Application, compiling reports and sharing them with other services developed by Google.
Google can use the Personal Data for contextualizing and personalizing advertisements from its advertising network.
Personal Data collected: Cookies and Usage Data.
Processing location: USA – Privacy Policy – Opt Out.

Google Tag Manager (Google, Inc.)
Google Tag Manager is a statistics service provided by Google, Inc.
Personal Data collected: Cookies and Usage Data.
Processing Location: USA – Privacy Policy

COOKIES FROM SOCIAL NETWORKS

buytourismonline.com can use cookies from social networks, to allow for sharing content on social networks. These plugins are programed so as to not register cookies when accessing the page, safeguarding the user’s privacy. The cookies are registered, if allowed by the social networks, only when the user effectively and voluntarily uses the plugin. It should be kept in mind that if the user navigates when logged into the social network, they already consented to the use of cookies transmitted through this website when registering with the social network.

The collection and use of data obtained via the plugin are regulated according to the related privacy policies of the social networks, which users are advised to refer to.

Like button and Facebook social media widgets (Facebook, Inc.)
The “Like” button and Facebook social media widgets are services for interacting with Facebook, provided by Facebook Inc.
Personal Data collected: Cookies and Usage Data.
Processing location: USA – Privacy Policy

Tweet button and Twitter social media widgets (Twitter Inc.)
The “Tweet” button and Twitter social media widgets are services for interacting with Twitter, provided by Twitter, Inc.
Personal Data collected: Cookies and Usage Data.
Processing location: United States – Privacy Policy.

Pinterest button and Pinterest social media widgets (Pinterest, Inc.)
The Pinterest button and Pinterest social media widgets are services for interacting with Pinterest, provided by Pinterest, Inc.
Personal Data collected: Cookies and Usage Data.
Processing location: United States – Privacy Policy

Instagram button and Instagram social media widgets (Instagram, Inc.)
The Instagram button and Instagram social media widgets are services for interacting with Instagram, provided by Instagram, Inc.
Personal Data collected: Cookies and Usage Data.
Processing location: United States – Privacy Policy

YouTube Videos (Google, Inc.)
YouTube is a service for visualizing videos owned by Google Inc, allowing this Application to incorporate such content into its pages.
Personal Data collected: Cookies and Usage Data.
Processing location: United States – Privacy Policy

LinkedIn SlideShare (LinkedIn Corporation)
LinkedIn SlideShare is an hosting service for professional content including presentations, owned by LinkedIn Corporation, allowing this Application to incorporate such content into its pages.
Personal Data collected: Cookies and Usage Data.
Processing location: United States – Privacy Policy

Flickr Images (SmugMug, Inc.)
Flickr is an image hosting service, allowing this Application to incorporate such content into its pages.
Flickr is owned and operated by Flickr, Inc.,  subsidiary of SmugMug Inc.,
Personal Data collected: Cookies and Usage Data.
Processing location: United States – Privacy Policy

SEMRUSH AND SPROUT SOCIAL

Periodically, the Data Controller and/or Data Processors staff can use SEMrush and Sprout Social, digital marketing tools that allow for the processing of statistics regarding the performance of the website’s content on social media channels tied to the digital promotion of tourism in Tuscany.

Semrush is a service provided by Semrush Inc. and the subsidiary SEMrush CZ s.r.o.
Personal Data collected: Cookies and various types of data as specified in the privacy policy of the service.
Place of data processing: United States and EU – Privacy Policy.
Sprout Social is a service provided by Sprout Social, Inc.
Personal Data collected: Cookies and various types of data as specified in the privacy policy of the service.
Place of data processing: United States – Privacy Policy.

NEWSLETTER

Website users can choose to subscribe to the buytourismonline.com newsletter in order to periodically receive updates about BTO – Buy Tourism Online. The tool used to send and manage the newsletter is Mailchimp, a service provided by The Rocket Science Group, LLC that manages email addresses and sending emails.
Personal data collected: common data and email addresses
Processing location: United States – Privacy Policy.
The newsletter is sent via email to those who specifically request to receive it by filling out the dedicated form and authorizing Data Controller and Data Processors to process users’ personal data. Providing this data is optional, but by refusing to provide data, the user will be unable to subscribe to the newsletter.

CONSENTING DATA PROCESSING

First access: when accessing the website for the first time, users will see a message that gives them the option of accepting or refusing the use of technical and profiling cookies of third parties on the part of buytourismonline.com. By providing their consent, users authorize Data Controller and/or Data Processors to use all the tools listed in this policy for the purposes described and for the type of personal data indicated.

Contact form: by filling in their personal data on contact forms accessible on buytourismonline.com, users authorize their use for the purposes of responding to requests for information or anything else indicated in the form’s header. In all cases, the user fully accepts the policy of buytourismonline.com and all the websites/subdomains attributable to buytourismonline.com.

SECURITY MEASURES

This site processes user data in compliance with legal requirements, taking appropriate security measures to prevent unauthorized access, disclosure, modification or unauthorized destruction of data. The data processing is carried out using IT and / or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In addition to the Data Controller and Data Processors, in some cases, categories of employees (administrative, commercial, marketing, legal, system administrators) or external subjects (such as third party technical service providers, hosting providers, IT companies, communication agencies) may have access to the data) appropriately appointed in compliance with current regulations.

USER RIGHTS

In accordance with EU Regulation 679/2016 (GDPR) and national legislation, the User can, with the procedures and limits provided in current legislation, exercise the following rights:

  • Request the confirmation of the existence of personal data regarding him/herself (right to access);
  • Be informed of their origin;
  • Receive comprehensible communication about them;
  • Receive information about the reason, procedures and aims of their processing;
  • Request an update, modification, integration, cancellation, transformation into anonymity and blocking of data processes that are in violation of the law, including those no longer necessary for carrying out the aims for which they were collected;
  • In cases of consent-based processing, receive the data provided to the owner, in a structured and legible manner, from a data processor and in a format commonly used by an electronic device; the cost for doing so only regards possible support;
  • The right to present a complaint to the Supervisory Authority (Warranty Policy);
  • More generally, all rights that are recognized by current laws.

Requests can be addressed to the Data Controller.

In cases in which data are processed based on legitimate interests, the rights of interested parties are nonetheless guaranteed (except the right of portability, which is not required by current regulations), especially the right to oppose processing, which can be applied by sending a request to the Data Controller.

UPDATES

The present privacy policy was updated on February 25th, 2020.

In reading the above information, with reference to the EU regulation 679/2016, the user agrees:

  • To the processing of personal data, both public and sensitive, regarding him/her, which is used for the aims declared above.
  • To the communication of the data to categories of individuals as stated above.

Consent remains conditional on compliance with the provisions of current legislation.