INFORMATION PURSUANT TO ART. 13 OF EU REGULATION 2016/679 ON THE PROCESSING OF PERSONAL DATA

Pursuant to Art. 13 of EU Regulation 2016/679 on the protection of individuals with regard to the processing of personal data, Widu S.r.l. (hereinafter “Widu”), with registered office in Pistoia (PT), Via di Felceti 9/B, ZIP 51100, VAT No. 02087560476, website: https://widu.digitaloriented.it, in its capacity as Data Controller, informs you that the personal data voluntarily provided by the data subject, including via forms on the website, will be processed in compliance with the regulation cited above.

Any third-party websites referenced or linked to (including third-party service providers’ websites) are the sole responsibility of those third parties and are subject to their own terms, conditions, and privacy policies. In particular, the following information is provided.

CATEGORIES OF DATA

Browsing Data

The IT systems and software procedures used to operate the site acquire, during their normal operation, certain personal data, the transmission of which is implicit in the use of Internet communication protocols. These data are not collected to be associated with identified individuals but could, by their nature and through processing and association with data held by third parties, allow users to be identified. This data category includes IP addresses or domain names of users' computers, URI (Uniform Resource Identifier) addresses of requested resources, time of request, method used to submit the request to the server, size of the file received in response, numerical code indicating the server's response status (success, error, etc.), and other parameters related to the user's operating system and IT environment. These data are used solely for anonymous statistical information about site usage and to ensure proper functioning. They may also be used to determine responsibility in the event of hypothetical cybercrimes against the site. Except for this possibility, web contact data is stored for a limited time and periodically deleted.

Data voluntarily provided by the user

The data subject may voluntarily provide the information necessary for the provision of services by filling out specific data collection forms on the platform. This may include common personal data, such as name, surname, physical and/or telephone and/or electronic contact details, login credentials, email address, passwords, and payment settings (including credit card information, promotional codes, gift cards, and account balances). The data controller does not collect or process “special categories of personal data” as defined by Art. 9 of the Regulation (e.g., health status).

Cookies

The websites use cookies in some areas. Cookies are files that store information on the hard drive or in the browser cache. They allow websites to detect if a user has already visited, apply customizations/preferences (e.g., language, screen size), and collect statistical data (e.g., most visited pages, visit duration). These data help make the websites better suited to users' needs and easier to navigate. For instance, cookies ensure that site content matches the preferences collected/set during previous visits.

PURPOSES AND LEGAL BASIS FOR PROCESSING

Purchase and delivery of products and services

We use personal data to receive and manage orders, provide products/services, process payments, and communicate with the data subject regarding orders, products, services, and promotional offers. Data processing for these purposes—particularly for managing guided tour bookings—will take place without the need for explicit consent, pursuant to Art. 6(1)(b) of the Regulation, for the fulfillment of contractual and/or pre-contractual obligations.

Providing and improving services and troubleshooting

We use personal data to provide functionalities, analyze performance, correct errors, and improve usage and efficiency. These data are processed without explicit consent pursuant to Art. 6(1)(b) and (c) of the Regulation, for contractual and/or legal obligations.

Sending promotional communications and advertising materials

Offering products and/or services (our own or third-party), conducting surveys and market research, through all means, including operator calls or automated systems (e.g., SMS, MMS, fax, auto-responders, push notifications, social media). This requires explicit and free consent under Art. 6(1)(a) of the Regulation.

Newsletter service

The personal data provided via the newsletter sign-up form will be processed using IT and telematic tools to send newsletters automatically and free of charge. These data will be retained as long as the newsletter service remains active. You may unsubscribe by sending an email to amministrazione@wi-du.it. Processing is based on your consent under Art. 6(1)(a) of the Regulation.

NATURE OF DATA PROVISION

Providing personal data for purposes under points 2(a) and 2(b) is mandatory; if you refuse, we cannot provide the requested service. For purposes under points 2(c) and 2(d), consent is required. You can revoke your consent at any time without affecting the lawfulness of the processing based on consent before withdrawal.

PROCESSING METHODS AND DATA RETENTION

The data is collected, processed, and stored primarily on magnetic, electronic, and/or telematic media. Processing is carried out under formal assignment and prior training on appropriate security measures. The data subject will not be subjected to automated decision-making processes, including profiling, producing legal or similarly significant effects. Personal data is retained only as long as necessary for the intended purposes, following the minimization principle (Art. 5.1.c of the Regulation). For ongoing services, Widu S.r.l. will process the data until the service is active or canceled by the user, except for further retention periods required by law for tax/administrative purposes.

DISCLOSURE

Your data may be disclosed to:

The list of Data Processors is available upon request at the contact details below. Data will not be distributed, made available, or disclosed in any form to parties other than those listed or required by law.

TRANSFER OF DATA ABROAD

User data may be transferred outside the national territory for the purposes under Art. 2, to entities as described above, located in the EU or outside it. In the latter case, an adequate level of data protection will be ensured. Third-party cookie processing remains governed by their respective policies.

DATA SUBJECT RIGHTS

Under EU Regulation 2016/679, you have the following rights:

To exercise these rights and for detailed information, refer to www.garanteprivacy.it. If you believe your rights have been violated, you may lodge a complaint with the national Supervisory Authority.

DATA CONTROLLER CONTACT DETAILS

Widu S.r.l.
VAT No.: 02087560476
Address: Via di Felceti 9/B, 51100 Pistoia (PT), Italy
Email: amministrazione@wi-du.it
Certified email (PEC): widu-ita@pec.it
Phone: +39 335 633 4882