Privacy Policy
Information on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ["GDPR"] and Legislative Decree 30.6.2003 No. 196 ["Privacy Code"]
This privacy policy is intended to provide maximum transparency regarding how personal data is processed for those who request registration for event or training program enrolment services, online donations, job applications, volunteering activities, requests for information on institutional activities, and purchases of solidarity products ["Services"].
Data Controller
The Data Controller is the Patrizio Paoletti Foundation for Development and Communication (tax code: 94092660540), located in Rome, Via Nazionale 230; email [fondazione@fondazionepatriziopaoletti.org](mailto:fondazione@fondazionepatriziopaoletti.org); certified email (PEC) [fondazionepatriziopaoletti@pec.it](mailto:fondazionepatriziopaoletti@pec.it); phone +39 06 8082599 ["Controller"].
The Data Controller has appointed a Data Protection Officer (DPO) pursuant to Article 37 of the GDPR: Dr. Ilaria Sterpa. You may contact the DPO at any time for questions or requests regarding your personal data and privacy at [privacy@fondazionepatriziopaoletti.org](mailto:privacy@fondazionepatriziopaoletti.org).
Personal data processed
At the time of registration for the Services, you will be asked to provide your contact details, such as name, surname, email address, telephone number, and optionally your social media contact.
Purposes of processing, legal basis, and retention periods
- Use of the Services and Controller obligations
Where processing is necessary for:
- your use of the Services, the legal basis is the performance of a contract to which the data subject is party (Art. 6(1)(b) GDPR);
- analysis of service quality and user satisfaction for improvement purposes, the legal basis is the legitimate interest of the Controller (Art. 6(1)(f) GDPR);
- legal compliance by the Controller, the legal basis is compliance with a legal obligation (Art. 6(1)(c) GDPR);
- the protection of legal rights, the legal basis is the legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Retention period: once the purposes related to the use of the Services and quality analysis have ceased, personal data will be stored for as long as necessary to comply with legal obligations and to protect the Controller’s rights within the applicable limitation periods.
- Sending communications about the Controller’s initiatives
The Controller may use your email address to send informational messages, including automated tools, about similar initiatives to the Services: the legal basis is Article 130(4) of the Privacy Code. You may opt out at any time.
The Controller may also use your email address, phone number, and social contact to send informational and promotional messages about its initiatives (including newsletters and market research) via automated tools (email, SMS, fax, MMS, social media messages, WhatsApp, Messenger, instant messaging apps) and non-automated tools (postal mail, telephone calls): the legal basis is your freely given consent at the time of registration.
Retention period: data will be stored for a maximum of 36 months unless consent is withdrawn.
- Sharing of personal data
If you agree, the Controller may share your personal data (including email, phone number, and social contact) with partner organizations for aligned activities.
These partners will become independent data controllers and may send you informational and promotional messages via the same channels.
Retention period: up to 36 months unless consent is withdrawn.
- Social network pages
The Patrizio Paoletti Foundation maintains social media pages (e.g., Facebook, Instagram, YouTube) to promote its activities and initiatives. By following these pages, users agree to receive informational and promotional content.
Retention period: data is processed until the user unfollows the pages.
Consequences of refusal
- Failure to provide required data prevents access to the Services.
- Failure to give consent does not affect access to Services but prevents promotional communications; consent may be withdrawn at any time.
Processing methods and security
Data is processed mainly using electronic, telematic, and manual tools with appropriate security measures to prevent unauthorized access, alteration, loss, or destruction.
Disclosure and recipients
Personal data is not publicly disclosed. It may be processed by authorized personnel and processors or shared with public authorities when required by law.
International transfers
Data is processed within the EU or transferred only to countries with adequate protection levels or appropriate safeguards.
Data subject rights
You may exercise rights under Articles 15–21 GDPR, including access, rectification, deletion, restriction, objection, and portability. You may also file a complaint with the Italian Data Protection Authority ([www.garanteprivacy.it](http://www.garanteprivacy.it)).
Last updated: 23.02.2022
PATRIZIO PAOLETTI FOUNDATION FOR DEVELOPMENT AND COMMUNICATION