IT

Last updated: 2 October 2026

This notice explains what personal data the website www.venosaturistica.com collects, why, how long it is kept and what rights you have. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 («GDPR») and the Italian Personal Data Protection Code (Legislative Decree 196/2003).

1. Data controller

Associazione Venosa Turistica
Registered office: Vicolo II A. Diaz, 10 — 85029 Venosa (PZ), Italy
Tax code: 93033830766
Email: [email protected]

For any question about this notice or to exercise your rights, write to the email address above.

2. What data we process and why

2.1 Browsing data

When you visit the website, the server automatically records some technical information: IP address, date and time of the request, the page visited, browser type and operating system. This is needed to run the website, keep it secure and detect abuse.

Legal basis: the controller’s legitimate interest in the security and proper functioning of the website (Art. 6(1)(f) GDPR).
Retention: server logs are deleted automatically within 30 days, unless they are needed to establish an offence.

2.2 «Contact» and «Unisciti a noi» forms, and emails

If you fill in the form on the Contact page (meant for visitors to Venosa) or on the Unisciti a noi page, or if you write to us, we process the data you give us: name, phone number, email and the content of your message. We use it only to reply to you and, if you ask, to consider your membership of the association or your collaboration.

Form messages reach us by email (those from the Contact page go to the portal administrator) and a copy is kept in the website’s administration panel.

Legal basis: steps taken at your request (Art. 6(1)(b) GDPR).
Retention: for as long as needed to handle your request and in any case no longer than 24 months after the last contact. If you become a member, data is kept for the duration of your membership and to meet the related legal obligations.
Providing your data is optional, but we cannot reply without a contact.

2.3 «Fai conoscere la tua attività» form

If you run a business and fill in the form on the Fai conoscere la tua attività page, we process the data you give us: business name and sector, first and last name, phone, email and any message. We use it only to contact you and discuss with you how your business or event could appear on the portal.

The request reaches the portal administrator by email, who will contact you; a copy is kept in the website’s administration panel.

Legal basis: steps taken at your request (Art. 6(1)(b) GDPR).
Retention: for as long as needed to handle the request and in any case no longer than 24 months after the last contact, unless a business relationship follows, in which case for its duration and to meet legal obligations.
Phone and email are required so that we can contact you.

2.4 Visitor statistics (Google Analytics 4)

We use Google Analytics 4 to find out, in aggregate form, how many people visit the website and which pages they read. It is activated only if you consent to the «Statistics» category in the cookie banner. Without consent Google Analytics sets no cookies and records no data about you (Google Consent Mode set to «denied»).

Legal basis: consent (Art. 6(1)(a) GDPR), which you can withdraw at any time through the «Manage consent» link.
Provider: Google Ireland Ltd. Data may be transferred to Google LLC in the United States, which participates in the EU-U.S. Data Privacy Framework.

2.5 Maps

The pages of businesses and sights contain a Google Maps map. The map is loaded only after your consent; until then a placeholder is shown instead. Once the map is loaded, Google receives your IP address and may set its own cookies.

Legal basis: consent (Art. 6(1)(a) GDPR). Provider: Google Ireland Ltd / Google LLC (EU-U.S. Data Privacy Framework).

The Where to eat, Where to stay and Wineries pages show an interactive map built with © OpenStreetMap data instead: the map images are served from our own server, so your browser does not contact any external service and no consent is needed. The «Take me there» button opens Google Maps only if you click it, and from then on Google’s privacy notice applies.

2.6 Security and bot protection (Cloudflare)

The website is delivered through the Cloudflare network, which makes it faster and protects it from attacks and automated traffic. On our forms we use Cloudflare Turnstile, an anti-spam check that does not ask you to solve image puzzles. To do this Cloudflare processes your IP address and some technical characteristics of your browser.

Legal basis: legitimate interest in the security of the website and in preventing spam (Art. 6(1)(f) GDPR).
Provider: Cloudflare, Inc., which participates in the EU-U.S. Data Privacy Framework.

2.7 Links to social networks

The website contains links to our Facebook and Instagram pages. They are plain links: no data is sent to the social networks until you click them. After the click, Meta Platforms’ privacy notices apply.

2.8 Data about the businesses listed on the portal

The portal publishes pages and lists of tourism and commercial businesses in the area (restaurants, accommodation, wineries, pastry shops and others). For each we show business information: name, address, business contacts, website and, where available, opening times.

This data comes from public sources, such as the regional register of accommodation of APT Basilicata, the lists of the Municipality of Venosa and the businesses’ official websites, or was provided directly by the owners.

Legal basis: the association’s legitimate interest in promoting tourism in the area (Art. 6(1)(f) GDPR) and, for pages requested by the owners, the relationship established with them (Art. 6(1)(b) GDPR).
A business owner can at any time ask us to correct the data or to be removed from the portal by writing to [email protected].

3. Cookies

Information on cookies and similar technologies, with the full list and the duration of each, is in the Cookie Policy. You can change your choices at any time through the «Manage consent» link.

4. Who we share data with

Data is never sold or disclosed to the public. It may be accessed, only as far as necessary, by:

5. Transfers outside the European Union

Some providers (Google, including Gmail, Cloudflare, SMTP2GO) may also process data outside the European Union. In these cases the transfer is based on an adequacy decision of the European Commission (for the United States, the EU-U.S. Data Privacy Framework) or on the standard contractual clauses approved by the Commission.

6. Your rights

At any time you can ask the controller for:

To exercise them, write to [email protected]. We reply within one month.

If you believe the processing breaches the law, you can lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it).

7. Other information

We do not make decisions based solely on automated processing, including profiling.

The website is not aimed at children under 14 and we do not knowingly collect their data.

We may update this notice when the website’s services or the law change. The date of the last update is shown at the top of the page.

This is a translation: in case of discrepancy, the Italian version prevails.