Privacy Policy & Cookies

-PERSONAL DATA PROCESSING NOTICE-

PRIVACY POLICY

(Pursuant to EU Regulation 2016/679 – GDPR and applicable Italian legislation, including Legislative Decree 196/2003 as amended)
1. Data Controller

Company Name: Rome Italy Explora Srls

VAT Number / Tax Code: 02976160594

Registered Office: Italy – 04100 Latina (LT) – Via Nicolò Paganini, 13

Contact Email Address: romeitalyexplora@gmail.com

Data Protection Officer (DPO): Luigi Capobianco

The Data Controller is the entity that determines the purposes and means of processing personal data. Any questions or requests regarding this notice or the exercise of data subject rights may be sent to the email address indicated above.

2. Types of Data Collected

The Data Controller collects and processes the following categories of personal data:

  • Contact data (email, phone number, address, etc.)
  • Browsing data (IP addresses, log data, cookies, etc.)

Personal data may be provided voluntarily by the User (e.g. via registration or purchase forms) or collected automatically (e.g. through cookies or tracking systems, where applicable).

3. Purposes of Processing

Personal data are processed for the following purposes:

  • Management of orders and contracts (billing, shipping, customer support, etc.)
  • Provision of requested services and/or products
  • Compliance with legal or tax obligations
  • Sending service communications (e.g. updates, technical notifications)
  • Marketing activities (newsletters, promotional offers), subject to User consent
  • Statistical analysis or market research (aggregated or pseudonymized data)
4. Legal Basis for Processing

Processing is based on:

  • Performance of a contract or pre-contractual measures
  • Legal obligations (e.g. accounting and tax requirements)
  • Consent of the data subject (e.g. marketing communications)
  • Legitimate interest of the Data Controller (e.g. IT security, fraud prevention), subject to balancing with the User’s fundamental rights and freedoms
5. Processing Methods and Security Measures

5.1 Personal data are processed using paper, electronic and telematic tools, in compliance with the principles of lawfulness, fairness and transparency, ensuring confidentiality through appropriate security measures.

5.2 The Data Controller adopts technical and organizational measures to prevent unauthorized access, disclosure, alteration or destruction of data.

6. Data Retention Period

Personal data are retained for the time necessary to fulfill the purposes for which they were collected, in accordance with the storage limitation principle (Art. 5 GDPR). In particular:

  • Identification and contact data: site navigation only – 180 days
  • Billing and accounting data: 10 years (as required by tax law)
  • Marketing data: until consent is withdrawn or deletion is requested

At the end of the retention period, data will be deleted or anonymized, unless legal obligations require otherwise.

7. Disclosure to Third Parties and Data Recipients

7.1 Data may be disclosed to third parties exclusively for the purposes described above. Such parties will act as Data Processors or independent Data Controllers, in compliance with applicable laws.

7.2 Categories of recipients may include:

  • Tax or legal advisors (for legal compliance)
  • IT service providers (hosting, maintenance, payment systems, etc.)
  • Competent authorities, where required by law
8. Transfer of Data to Third Countries

8.1 If personal data are transferred outside the European Union, the Data Controller ensures appropriate safeguards (e.g. EU Commission adequacy decisions, standard contractual clauses).

8.2 Data transfers:

8.3 For further information on safeguards applied to international transfers, Users may contact the Data Controller.

9. Cookies and Tracking Technologies

9.1 The use of cookies or other tracking technologies (e.g. web beacons, pixels) is described in a specific Cookie Policy, which complements this notice.

9.2 Cookie Policy available at: https://romeitalyexplora.com/privacy-policy-and-cookies/

10. Data Subject Rights

Users may exercise the rights provided under Articles 15–22 of the GDPR:

  1. Right of access
  2. Right to rectification
  3. Right to erasure (“right to be forgotten”)
  4. Right to restriction of processing
  5. Right to data portability
  6. Right to object
  7. Right to withdraw consent

Requests can be submitted to the Data Controller using the contact details provided in Section 1.

11. Automated Decision-Making and Profiling

No automated decision-making processes (including profiling) are carried out that produce legal effects for the User.

12. Changes to the Privacy Policy

The Data Controller reserves the right to update or modify this notice, for example in case of legal changes or new processing activities. Significant changes will be communicated through:

  • Publication on the website or platform
13. Contacts

For further information or to exercise your rights, you may contact:

Data Controller: Luigi Capobianco

Contact Email: romeitalyexplora@gmail.com

14. Acknowledgment

I declare that I have read and fully understood this Privacy Policy and accept it in its entirety.

Last updated: 25/03/2026

 

Luigi Capobianco

Rome Italy Explora Srls

BOOK NOW