Privacy Policy

1. Data Controller

Name / Company NameGemma Pozio
AddressContrada Barbagiulo, 45 – 72014 Cisternino (BR), Italy
Contact E-mailinfo@laiaeilpagliaio.it
Websitehttps://laiaeilpagliaio.it

The Data Controller is the natural person who, individually or together with others, determines the purposes and means of the processing of personal data pursuant to Art. 4, No. 7 of the GDPR.

2. Types of Personal Data Processed

This website collects the following categories of personal data:

2.1 Data provided voluntarily by the user

  • First and last name
  • E-mail address
  • Phone number
  • Preferred date and time for the guided tour
  • Number of participants in the group

2.2 Technical data collected automatically

  • Device IP address (temporarily acquired by the web server)
  • Browser type and operating system
  • Pages visited and session duration
  • Date and time of access to the site
The site does not collect special categories of data (Art. 9 GDPR), such as health, biometric, religious, or political data.

3. Purposes of Processing and Legal Bases

The processing of personal data is carried out for the following purposes, each based on a specific legal basis pursuant to Art. 6 GDPR:

PurposeLegal Basis (Art. 6 GDPR)Data Involved
Management of guided tour bookings via AmeliaArt. 6(1)(b) — Performance of pre-contractual measures at the request of the data subjectName, e-mail, phone, date/time, no. of participants
Display of Google Maps (only with prior consent)Art. 6(1)(a) — Consent of the data subjectIP address (transmitted to Google LLC)
Site security, prevention of abuse, and access logsArt. 6(1)(f) — Legitimate interest of the ControllerServer log data (IP, date, time, HTTP request)
Technical functioning of the site (technical and preference cookies)Art. 6(1)(f) — Legitimate interest / exemption from consent (Art. 122 Legislative Decree 196/2003)CMP preferences (Complianz), sessions

4. Booking System — Amelia Plugin

The site uses the Amelia plugin (developed by TMS Plugins) to manage bookings for guided tours of the historical site. Through the booking form, the user voluntarily provides the following data:

  • First and last name
  • E-mail address
  • Phone number
  • Chosen date and time for the visit
  • Total number of participants in the group

This data is processed exclusively to:

  • Confirm and manage the booking of the guided tour
  • Communicate any changes, cancellations, or updates related to the booking
The booking system does not collect payment data. No payment gateway (Stripe, PayPal, or similar) is active. Payment, if required, takes place exclusively on-site.

Data entered via Amelia is stored in the site’s WordPress database, hosted on servers located within the European Union, and is not transmitted to third parties, except as indicated in point 5.

4.1 Booking confirmation e-mail notifications

Following the booking, the system may automatically send a confirmation e-mail to the address provided by the user. The sending takes place via the site’s mail server. No third-party e-mail marketing provider is used for this purpose.

5. Google Maps — Third-Party Mapping Service

The site integrates Google Maps, a mapping service provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) to indicate the geographical location of the historical site.

5.1 Prior blocking via Complianz

Google Maps is configured in prior blocking mode via the Complianz plugin (Consent Management Platform). The interactive map and Google scripts are not loaded until the user expresses their consent by accepting marketing/tracking cookies in the consent banner.

Before consent: a static placeholder is shown. No data is transmitted to Google.
After consent: Google Maps activates and the user’s IP address is transmitted to Google servers for rendering the map.

5.2 Extra-EEA data transfer

Google LLC is based in the United States of America. Data transfer takes place on the basis of Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914/EU) and Google’s adherence to the EU-U.S. Data Privacy Framework (DPF), as provided for by Art. 46(2)(c) of the GDPR.

For more information: https://policies.google.com/privacy

ServiceProviderLocationTransfer Guarantee
Google Maps APIGoogle LLCUSA (extra-EEA)SCC + EU-U.S. Data Privacy Framework

6. Data Retention Period

Data categoryRetention periodNotes
Booking data (Amelia)12 months from the date of the visitExcept for legal defense requirements
Web server logsMaximum 12 months (automatically overwritten)For security and diagnostics purposes
Consent cookies (Complianz)365 days from the date of consentRenewed at each new visit

7. Rights of the Data Subjects

Pursuant to Artt. 15-22 of Regulation (EU) 2016/679, every data subject has the right to:

Right (GDPR Art.)Description
Access (Art. 15)Obtain confirmation of processing and a copy of the personal data processed.
Rectification (Art. 16)Correct inaccurate or incomplete data concerning you.
Erasure (Art. 17)Obtain the erasure of data (“right to be forgotten”), except for legal retention obligations.
Restriction (Art. 18)Request the suspension of processing in specific circumstances.
Portability (Art. 20)Receive your data in a structured, machine-readable format, where technically applicable.
Objection (Art. 21)Object to processing based on the legitimate interest of the Controller.
Withdrawal of consent (Art. 7(3))Withdraw consent at any time, without affecting the lawfulness of previous processing.
Complaint (Art. 77)Lodge a complaint with the Data Protection Authority (www.garanteprivacy.it).
To exercise your rights, the data subject may contact the Controller at the e-mail address: info@laiaeilpagliaio.it
The Controller will respond within 30 days of receiving the request (Art. 12 GDPR).

8. Communication and Disclosure of Data

Personal data is not sold, transferred, or disclosed to third parties for commercial or marketing purposes.

Data may be communicated exclusively to the following categories of subjects, to the extent strictly necessary:

  • Hosting/server service provider (data processor): limited to technical site access data
  • Google LLC: limited to the IP address, only with the user’s prior consent to activate Google Maps
  • Public authorities: in the event of a legitimate request by the competent authorities (Art. 6(1)(c) GDPR)

No indiscriminate disclosure of data to unspecified subjects is carried out.

9. Transfer of Data to Third Countries

The site transfers personal data to countries outside the European Economic Area (EEA) exclusively through the Google Maps service, under the following conditions:

  • The transfer takes place only after acceptance of marketing cookies by the user
  • Google LLC is based in the United States of America (extra-EEA country)
  • The safeguards for the transfer are: Standard Contractual Clauses (SCC) — Decision 2021/914/UE — and adherence to the EU-U.S. Data Privacy Framework (DPF)

For all other data (Amelia bookings, server logs), processing takes place on servers located within the European Union.

10. Security Measures

The Controller adopts appropriate technical and organizational measures to ensure a level of security appropriate to the risk, pursuant to Art. 32 GDPR, including:

  • Encrypted connection via HTTPS/TLS protocol
  • Access to the WordPress administration panel protected by secure credentials
  • Periodic updates of the WordPress CMS, plugins, and themes
  • Periodic backups of the site database and files
  • Access to the database limited to authorized users only

In the event of a personal data breach (data breach) with risks to the rights of the data subjects, the Controller will notify the Supervisory Authority within the terms provided by Art. 33 GDPR (within 72 hours of becoming aware of the event).

11. Processing of Minors’ Data

This site is not directed at children under the age of 14. The Controller does not knowingly collect personal data from subjects under 14 years of age. Should such data be processed unknowingly, the Controller will immediately delete it upon notification.

For guided tour bookings involving minors, it is required that the booking be made by an adult (parent or legal guardian).

12. Changes to this Policy

The Controller reserves the right to modify, update, or supplement this Policy at any time, also to adapt to regulatory changes or new practices of the Supervisory Authority.

Substantial changes will be communicated via notice on the website and/or by updating the date indicated at the bottom. We invite you to consult this page periodically.

13. Contacts and Complaints

For any request relating to the processing of personal data or to exercise the rights referred to in Artt. 15-22 GDPR:

ControllerGemma Pozio
AddressContrada Barbagiulo, 45 – 72014 Cisternino (BR), Italy
E-mailinfo@laiaeilpagliaio.it
Websitehttps://laiaeilpagliaio.it
Supervisory AuthorityGarante per la Protezione dei Dati Personali — www.garanteprivacy.it