Privacy Policy
Information on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 [“GDPR”] and Legislative Decree 30.6.2003 n. 196 [“Privacy Code”]
This privacy notice aims to provide maximum transparency on how personal data is processed for those requesting registration for event or training services, online donations, job applications, volunteering activities, requests for information on institutional activities, and purchases of solidarity products [“The Services”].
Data Controller
The Data Controller is Fondazione Patrizio Paoletti per lo Sviluppo e la Comunicazione (Tax ID: 94092660540), headquartered in Rome, Via Nazionale 230; email: [fondazione@fondazionepatriziopaoletti.org](mailto:fondazione@fondazionepatriziopaoletti.org); certified email: [fondazionepatriziopaoletti@pec.it](mailto:fondazionepatriziopaoletti@pec.it); phone: 06 8082599 [“The Controller”].
The Controller has appointed a Data Protection Officer (DPO) pursuant to Article 37 of the GDPR, Dr. Ilaria Sterpa. You can contact the DPO at any time with questions or requests regarding your personal data and privacy at [privacy@fondazionepatriziopaoletti.org](mailto:privacy@fondazionepatriziopaoletti.org).
Personal Data Processed
When registering for the Services, you will be asked to provide contact details such as name, surname, email address, phone number, and optionally, social media contact.
Purpose of Data Processing, Legal Basis, and Retention Periods
- Use of the Services and Controller’s obligations
Where processing is necessary for:
- your use of the Services, the legal basis is the necessity for the performance of a contract to which the data subject is a party (Art. 6(1)(b) GDPR);
- analysis of service quality and your satisfaction, including for improving the Services, the legal basis is the legitimate interest of the Controller (Art. 6(1)(f) GDPR);
- compliance with legal obligations of the Controller, the legal basis is the fulfillment of a legal obligation (Art. 6(1)(c) GDPR);
- protection of the Controller’s rights, the legal basis is the legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Retention period: Once the need for using the Services and analyzing their quality and user satisfaction ceases, personal data will be used and stored as long as necessary to comply with legal obligations and protect the Controller’s rights within the statute of limitations.
- Sending communications regarding the Controller’s initiatives
The Controller may use your email to send informational messages, including automated messages, about initiatives similar to the Services; the legal basis for this processing is Art. 130(4) of the Privacy Code. You are always free to opt out of future communications.
The Controller may also use your email, phone number, and social media contact to send informational and promotional messages about its initiatives, including newsletters and market research, via automated (email, SMS, fax, MMS, social media messages, WhatsApp, Messenger, online messaging apps) or manual means (postal mail, operator calls); in this case, the legal basis is your consent, freely given during registration.
Retention period: For these purposes, unless consent is withdrawn, data will be retained for a maximum of 36 months, reflecting the duration of project planning and implementation.
- Sharing of personal data
If you wish, the Controller may share your personal data, including email, phone number, and social media contacts, with its Partners who perform related activities within different fields, with whom it has a partnership agreement to develop significant synergies.
These Partners, as independent controllers, may send you informational and promotional messages about their initiatives, including newsletters and market research, via automated or manual channels; the legal basis remains your consent, freely given at registration.
Retention period: Unless consent is withdrawn, data shared for these purposes will be retained for a maximum of 36 months.
- Social network profiles and pages
Fondazione Patrizio Paoletti manages its own pages on major social networks (e.g., Facebook, Instagram, YouTube) to promote activities, sharing informational and promotional content on initiatives, services, and fundraising campaigns.
Users who access and follow these pages implicitly consent to receive informational and promotional messages. The sending of messages via these channels is lawful as long as it is clear from the context and user interaction that consent is implied.
Retention period: Data will be used as long as the user follows the social pages. Unfollowing revokes consent.
Consequences of refusing to provide data or consent
- Failure to provide data required to use the Services prevents registration for the Services.
- Refusing to give consent for promotional communications or data sharing with Partners has no other consequences. You may withdraw consent at any time without affecting the lawfulness of prior processing.
Processing Methods and Security Measures
Personal data will be processed for the purposes for which they were collected, mainly through IT, telematic, and manual tools, adopting security measures to minimize risks of unauthorized or accidental access, disclosure, modification, loss, or destruction.
Disclosure and Categories of Recipients
Personal data will never be publicly disclosed. Data will be processed by authorized personnel and Controllers bound by agreements. Except for Partner sharing with your consent, data may be communicated to third parties (public entities, law enforcement, or other public/private subjects) only to fulfill legal or contractual obligations.
Transfer to Third Countries
Data is processed in EU countries. Transfers outside the EU will only occur to countries deemed to provide adequate protection or with appropriate safeguards (e.g., “standard clauses”) and enforceable rights and remedies for data subjects.
Rights of Data Subjects
You have the rights under Articles 15–21 of GDPR, including access, rectification, deletion, restriction, objection, and data portability. You may also lodge a complaint with a supervisory authority or seek judicial remedies.
For Italy: the supervisory authority is the Garante per la Protezione dei dati personali, Piazza Venezia n. 11 – 00187, Rome; email: [garante@gpdp.it](mailto:garante@gpdp.it); certified email: [protocollo@pec.gpdp.it](mailto:protocollo@pec.gpdp.it); website: [www.garanteprivacy.it](http://www.garanteprivacy.it).
Last update: 23.02.2022
FONDAZIONE PATRIZIO PAOLETTI PER LO SVILUPPO E LA COMUNICAZIONE