Ghostbusters Venice Museum

Roberto Scano's private collection dedicated to the world of Ghostbusters

Information and consent for the processing of personal data and use of cookies

This privacy policy is provided as information pursuant to Art. 13 of Legislative Decree 196/2003 and pursuant to Art. 13 of the GDPR 679/2016 European Privacy Regulation, as well as pursuant to the Provision on cookies no. 229 of May 8, 2014; we wish to inform site visitors about the use of data entered and the cookies used by the site itself.

Information pursuant to Art. 13-14 of the GDPR

Roberto Scano, based in Corte del Montello 3 – 30132 Venice (VE), CF and VAT no. 03378360279 (hereinafter, “Data Controller”), as the data controller, informs you pursuant to Art. 13 of Legislative Decree 30.6.2003 n. 196 (hereinafter, “Privacy Code”) and Art. 13 of EU Regulation n. 2016/679 (hereinafter, “GDPR”) that your data will be processed in the following ways and for the following purposes:

a) Object of processing: The Data Controller processes personal, identifying, and non-sensitive data (specifically, name, surname, tax code, VAT number, email, telephone number – hereinafter, “personal data” or simply “data”) provided by you during registration on the Data Controller’s website.

b) Purpose of processing: data processing will be carried out to allow the provision of requested services (service performance, contact via email, general information, etc.) and (limited to services that require a fee) to provide for the relative invoicing and consequent tax and/or associative obligations. Registered data may also be used for statistical reports on our activity, as well as for sending information related to it to the interested party. Where necessary and limited to the aforementioned reasons, data may also be communicated to third parties. Data obtained through authentication with third-party systems are intended to be provided to the Data Controller through explicit acceptance of the authentication service (o-auth) and will be processed like the data indicated above.

c) Processing methods: data will be processed mainly with electronic and computer tools and stored both on computer media and on paper media and on any other type of suitable support, in compliance with minimum security measures. The processing of your personal data is carried out by means of the operations indicated in Art. 4 of the Privacy Code and Art. 4 n. 2) of the GDPR and precisely: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, deletion, and destruction of data. The Data Controller will process personal data for the time necessary to fulfill the purposes mentioned above and in any case for no longer than ten years from the termination of the relationship for business purposes.

d) Access to data: Your data may be made accessible for the purposes indicated in point b):
– to employees and collaborators of the Data Controller, in their capacity as persons in charge and/or internal data processors and/or system administrators;
– to third parties (for example, providers for the management and maintenance of the website, suppliers, credit institutions, professional firms, etc.) who perform outsourcing activities on behalf of the Data Controller, in their capacity as external data processors.

e) Communication of data: Without your express consent (pursuant to Art. 24 lett. a), b), d) of the Privacy Code and Art. 6 lett. b) and c) of the GDPR), the Data Controller may communicate your data for the purposes indicated in point b) to supervisory bodies, judicial authorities, as well as to all other subjects to whom communication is mandatory by law for the fulfillment of said purposes. Your data will not be disseminated except for the online publication of member profile data, clearly identifiable from both the public page and the administrative area.

f) Data transfer: The management and storage of personal data will take place on servers located within the European Union belonging to the Data Controller and/or third-party companies appointed and duly named as Data Processors. The data will not be transferred outside the European Union. It remains understood in any case that the Data Controller, should it become necessary, will have the right to move the location of the servers to Italy and/or the European Union and/or non-EU countries. In this case, the Data Controller ensures as of now that the transfer of data outside the EU will take place in accordance with applicable legal provisions by stipulating, if necessary, agreements that guarantee an adequate level of protection and/or adopting the standard contractual clauses provided by the European Commission.

g) Nature of data provision and consequences of refusal to respond: The provision of data for the purposes referred to in point b) is mandatory. In their absence, we cannot guarantee either registration to the site or the Services referred to in point b).

h) Rights of the interested party: In your capacity as an interested party, you have the rights referred to in Art. 7 of the Privacy Code and Art. 15 of the GDPR and precisely the rights to:
i. obtain confirmation of the existence or not of personal data concerning you, even if not yet registered, and their communication in an intelligible form;
ii. obtain indication of: a) the origin of the personal data; b) the purposes and methods of processing; c) the logic applied in case of processing carried out with the aid of electronic tools; d) the identification details of the controller, processors, and the representative designated pursuant to Art. 5, paragraph 2 of the Privacy Code and Art. 3, paragraph 1, of the GDPR; e) the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of them as designated representative in the territory of the State, processors, or persons in charge;
iii. obtain: a) updating, rectification or, when you have an interest, integration of data; b) deletion, transformation into anonymous form, or blocking of data processed in violation of the law, including those for which storage is not necessary in relation to the purposes for which the data were collected or subsequently processed; c) certification that the operations referred to in letters a) and b) have been brought to the attention, also as regards their content, of those to whom the data were communicated or disseminated, except in the case where this fulfillment proves impossible or involves a use of means manifestly disproportionate to the protected right;
iv. object, in whole or in part: a) for legitimate reasons to the processing of personal data concerning you, even if pertinent to the purpose of the collection; b) to the processing of personal data concerning you for the purpose of sending advertising material or direct sales or for carrying out market research or commercial communication, through the use of automated calling systems without the intervention of an operator by email and/or through traditional marketing methods by telephone and/or paper mail. It should be noted that the right of opposition of the interested party, set out in point b) above, for direct marketing purposes through automated methods extends to traditional ones and that in any case the possibility for the interested party to exercise the right of opposition even only in part remains. Therefore, the interested party can decide to receive only communications through traditional methods or only automated communications or neither of the two types of communication.
Where applicable, you also have the rights referred to in Articles 16-21 of the GDPR (Right to rectification, right to be forgotten, right to restriction of processing, right to data portability, right to object), as well as the right to lodge a complaint with the Supervisory Authority.

i) How to exercise your rights: You can exercise your rights at any time by sending:
– a registered letter with return receipt to Roberto Scano – Corte del Montello, 3 – 30132 Venice (VE);
– an email to the address mail@robertoscano.info.

l) Minors: This Site and the Data Controller’s Services are not intended for minors under 18 and the Data Controller does not intentionally collect personal information referring to minors. In the event that information on minors is unintentionally recorded, the Data Controller will delete it in a timely manner, upon request of the users.

m) Data Controller, processor and persons in charge: The Data Controller is Roberto Scano. The updated list of processors and persons in charge of processing is kept at the Data Controller’s headquarters.

n) Changes to this Information: This Information may undergo variations. It is therefore advisable to check this Information regularly and refer to the most updated version.

Information on the use of so-called “cookies”

The Data Controller’s websites use cookies and similar technologies to ensure the correct functioning of procedures and improve the user experience of online applications. This document provides detailed information on the use of cookies and similar technologies, how they are used by the Data Controller, and how to manage them.

Definitions

Cookies are short fragments of text (letters and/or numbers) that allow the web server to store information on the client (the browser) to be reused during the same visit to the site (session cookies) or later, even days later (persistent cookies). Cookies are stored, based on user preferences, by the individual  browser on the specific device used (computer, tablet, smartphone).

Similar technologies, such as, for example, web beacons, transparent GIFs, and all forms of local storage introduced with HTML5, can be used to collect information on user behavior and the use of services.

In the remainder of this document, we will refer to cookies and all similar technologies simply using the term “cookie”.

Types of cookies

Based on the characteristics and use of cookies, we can distinguish different categories:

  • Strictly necessary cookies. These are cookies essential for the correct functioning of the Data Controller’s sites and are used to manage login and access to reserved functions of the site. The duration of the cookies is strictly limited to the work session (when the browser is closed, they are deleted). The public part of the Data Controller’s sites normally remains usable.
  • Analysis and performance cookies. These are cookies used to collect and analyze traffic and site usage anonymously. These cookies, while not identifying the user, allow, for example, to detect if the same user returns to connect at different times. They also allow for monitoring the system and improving its performance and usability. Deactivation of these cookies can be performed without any loss of functionality.
  • Profiling cookies. These are permanent cookies used to identify (anonymously and otherwise) user preferences and improve their browsing experience. The Data Controller’s sites do not use cookies of this type.

Third-party cookies

By visiting a website, you may receive cookies both from the visited site (“proprietary”) and from sites managed by other organizations (“third parties”). A notable example is the presence of “social plugins” for Facebook, Twitter, Google+, and LinkedIn. These are parts of the visited page generated directly by the aforementioned sites and integrated into the host site’s page. The most common use of  social plugins is aimed at sharing content on social networks.

The presence of these plugins involves the transmission of cookies to and from all sites managed by third parties. The management of information collected by “third parties” is governed by the relevant information to which you are requested to refer. To ensure greater transparency and convenience, the web addresses of the various information notices and methods for managing cookies are provided below.

Facebook information: https://www.facebook.com/help/cookies/

Facebook (configuration): access your account. Privacy section.

Twitter information: https://support.twitter.com/articles/20170514

Twitter (configuration): https://twitter.com/settings/security

Linkedin information: https://www.linkedin.com/legal/cookie-policy

Linkedin (configuration): https://www.linkedin.com/settings/

Google+ information: http://www.google.it/intl/it/policies/technologies/cookies/

Google+ (configuration): http://www.google.it/intl/it/policies/technologies/managing/

Google Analytics

The Data Controller’s sites also include certain components transmitted by Google Analytics, a web traffic analysis service provided by Google, Inc. (“Google”). Again, these are third-party cookies collected and managed anonymously to monitor and improve the performance of the host site (performance cookies).

Google Analytics uses “cookies” to collect and analyze anonymous information on the usage behavior of the Data Controller’s websites (including the user’s IP address). This information is collected by Google Analytics, which processes it for the purpose of drafting reports for the Data Controller’s operators regarding activities on the websites themselves. This site does not use (and does not allow third parties to use) the Google analysis tool to monitor or collect personal identification information. Google does not associate the IP address with any other data held by Google nor does it try to link an IP address with the identity of a user. Google may also communicate this information to third parties where required by law or where such third parties process the aforementioned information on behalf of Google.

For further information, please refer to the link indicated below:

https://www.google.it/policies/privacy/partners

The user can selectively disable the action of Google Analytics by installing the opt-out component provided by Google on their browser. To disable the action of Google Analytics, please refer to the link indicated below:

https://tools.google.com/dlpage/gaoptout

Duration of cookies

Some cookies (session cookies) remain active only until the browser is closed or the logout command is executed. Other cookies “survive” the closing of the  browser and are also available in subsequent visits by the user.

These cookies are called persistent and their duration is set by the server at the time of their creation. In some cases a deadline is set, in other cases the duration is unlimited.

The Data Controller does not use persistent cookies.

However, by browsing the pages of the Data Controller’s websites, you can interact with sites managed by third parties that can create or modify permanent and profiling cookies.

Cookie management

The user can decide whether or not to accept cookies using the settings of their browser.

Warning: total or partial disabling of technical cookies can compromise the use of site features reserved for registered users. On the contrary, the usability of public content is possible even by completely disabling cookies.

Disabling “third-party” cookies does not affect navigability in any way.

The setting can be defined specifically for different sites and web applications. Furthermore, the best  browsers allow you to define different settings for “proprietary” and “third-party” cookies.

As an example, in Firefox, through the Tools->Options ->Privacy menu, it is possible to access a control panel where you can define whether or not to accept different types of cookies and proceed to their removal.

Chrome: https://support.google.com/chrome/answer/95647?hl=en

Firefox: https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop

Internet Explorer: http://windows.microsoft.com/en-us/windows7/how-to-manage-cookies-in-internet-explorer-9

Opera: https://help.opera.com/en/latest/web-preferences/#cookies

Safari: http://support.apple.com/kb/HT1677?viewlocale=en_US