Data Controller
The data controller for personal data collected through the website ioamomontesarchio.it and the InfoLocali Montesarchio service is:
For any questions regarding the processing of your personal data, you can contact the controller at the email address indicated above.
Personal Data Collected
2.1 Navigation data
The IT systems and software procedures of the website automatically acquire, during their normal operation, some data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and associations with data held by third parties, allow users to be identified. This category includes IP addresses, browser types, operating system, domain name and addresses of websites from which access was made. Such data are used solely to obtain anonymous statistical information on the use of the site and to check its correct functioning, and are deleted after processing. The data may be used to ascertain liability in case of hypothetical computer crimes against the site.
2.2 Voluntarily provided data β User registration
To access the InfoLocali Montesarchio service and add your business, the user voluntarily provides:
- Email address β used for account verification and service communications
- Password β stored in encrypted form (hash); the controller does not have access to the password in plain text
2.3 Business-related data
After registration, the user voluntarily enters data about their business intended for public publication:
- Business name
- Physical address
- Business category
- Description
- Phone number
- Public contact email
- Website (optional)
- WhatsApp contact (optional)
Purposes and Legal Bases of Processing
Creation and management of account, email verification, authentication.
Legal basis: contract performance (art. 6.1.b GDPR)
Adding the business to the local guide of Montesarchio.
Legal basis: contract performance / legitimate interest (art. 6.1.b and 6.1.f GDPR)
Account-related notifications (verification, approval, technical updates).
Legal basis: contract performance (art. 6.1.b GDPR)
Technical monitoring to prevent unauthorized access and spam.
Legal basis: legitimate interest (art. 6.1.f GDPR)
Personal data will in no case be used for marketing, profiling or commercial communications purposes without explicit consent.
Data Retention
Data is retained for the time strictly necessary for the purposes for which it was collected:
- Account data (email, password hash): for the entire duration of the active account, plus 12 months following deletion or removal request
- Public business data: as long as the business is published and visible, or until deletion request by the data subject
- Navigation logs: maximum 30 days, then automatically deleted
Upon expiration of retention periods, data is securely deleted or irreversibly anonymized.
Sharing with Third Parties
Personal data (email, password hash) is not sold, transferred or communicated to third parties for commercial or promotional purposes.
5.1 Hosting provider
The site is hosted on servers located in Italy. The hosting provider processes data exclusively as data processor pursuant to art. 28 GDPR, based on a specific contract, and guarantees adequate security measures.
5.2 Public data of businesses
The data entered in the business listing (name, address, phone, public email, etc.) is by its nature intended for publication and will therefore be accessible to anyone visiting the site, including search engines. This is the explicit purpose of the service, known and accepted by the user at the time of registration.
5.3 Competent authorities
The controller may communicate personal data to competent authorities where required by law or for the defense of a right in judicial proceedings.
Your Rights (arts. 15β22 GDPR)
As a data subject, you have the right to:
- Access β obtain confirmation that data processing concerning you is taking place and request a copy (art. 15)
- Rectification β request correction of inaccurate or incomplete data (art. 16)
- Erasure ("right to be forgotten") β request deletion of your data, within the limits provided by law (art. 17)
- Restriction of processing β request that processing be limited in certain cases (art. 18)
- Portability β receive your data in a structured, machine-readable format (art. 20)
- Objection β object to processing based on legitimate interest (art. 21)
- Withdrawal of consent β where processing is based on consent, withdraw it at any time without affecting the lawfulness of previous processing
To exercise any of these rights, write to: info@ioamomontesarchio.it
The controller will respond within 30 days from receipt of the request, as provided by art. 12 GDPR.
Data Security
The controller adopts adequate technical and organizational measures to protect personal data from unauthorized access, loss, destruction or accidental disclosure, in accordance with art. 32 GDPR. In particular:
- Passwords are stored in encrypted form (hashing with secure algorithm); the controller never has access to the password in plain text
- The site uses encrypted connection HTTPS/TLS
- Access to data is limited to authorized technical personnel only
In case of personal data breach (data breach) that may pose a risk to the rights and freedoms of data subjects, the controller will notify the Garante within 72 hours and, if necessary, inform affected users, pursuant to arts. 33β34 GDPR.
Minors
The InfoLocali Montesarchio service is intended exclusively for adults (18 years and over) or owners/legal representatives of businesses. We do not knowingly collect personal data from minors under 14 years of age. If we become aware that we have inadvertently collected data from a minor, we will proceed with its immediate deletion.
Changes to This Notice
The controller reserves the right to make changes to this notice at any time, notifying users on this page. Users are therefore invited to consult this page periodically, referring to the last update date indicated at the top.
Changes become effective from the date of their publication. For substantial changes that affect the rights of data subjects, the controller will inform registered users by email.