Privacy Policy


The Privacy Policy of cittadellascienza.it is available at:


Data Controller

Fondazione Idis – Città della Scienza – Via Coroglio, 104 – 80124 Napoli (Italy)
Holder’s email address: comunica@cittadellascienza.it


Types of Data Collected

Among the Personal Data collected by this Application, either independently or through third parties, are: Cookies, Usage Data, first name, last name, email, and website.

Full details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific informative texts displayed before the collection of the data itself.
Personal Data may be freely provided by the User or, in the case of Usage Data, automatically collected during the use of this Application.
Unless otherwise specified, all Data requested by this Application are mandatory. If the User refuses to provide them, it may be impossible for this Application to provide the Service. In cases where this Application indicates certain Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or its operation.
Users in doubt about which Data are mandatory are encouraged to contact the Controller.
The possible use of Cookies – or other tracking tools – by this Application or the owners of third party services used by this Application, where not otherwise specified, has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for third party Personal Data obtained, published or shared through this Application and warrants that he/she has the right to communicate or disseminate it, releasing the Owner from any liability to third parties.


Method and place of processing of collected Data

Mode of treatment

The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data.
The processing is carried out by means of computer and/or telematic tools, with organizational methods and logics strictly related to the indicated purposes. In addition to the Data Controller, in some cases, other parties involved in the organization of this Application (administrative, sales, marketing, legal, system administrators) or external parties (such as third party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, Data Processors by the Data Controller may have access to the Data. The updated list of Data Processors can always be requested from the Data Controller.

Legal basis for processing

The Owner processes Personal Data related to the User if one of the following conditions exists:

  • the User has given consent for one or more specific purposes; Note: In some jurisdictions, the Data Controller may be authorized to process Personal Data without the need for the User’s consent or another of the legal bases specified below, as long as the User does not object (“opt-out”) to such processing. However, this does not apply if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
  • processing is necessary for the performance of a contract with the User and/or the execution of pre-contractual measures;
  • processing is necessary to fulfill a legal obligation to which the Controller is subject;
  • the processing is necessary for the performance of a task of public interest or the exercise of public authority vested in the Controller;
  • processing is necessary for the pursuit of the legitimate interest of the Owner or third parties.

However, it is always possible to ask the Data Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on law, required by a contract or necessary to conclude a contract.

Location

The Data is processed at the Owner’s operational headquarters and at any other location where the parties involved in the processing are located. For more information, please contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the country in which the User is located. To obtain more information about the location of the processing, the User may refer to the section on Personal Data processing details.

The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization under public international law or consisting of two or more countries, such as the UN, as well as regarding the security measures taken by the Data Controller to protect the Data.

Should any of the transfers just described take place, the User may refer to the respective sections of this document or request information from the Owner by contacting him at the contact details given at the beginning.

Retention period

Data are processed and kept for the time required by the purposes for which they were collected.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the performance of that contract is completed.
  • Personal Data collected for purposes attributable to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.

When processing is based on the User’s consent, the Controller may retain Personal Data longer until that consent is revoked. In addition, the Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period, the Personal Data will be deleted. Therefore, at the expiration of this period the right of access, deletion, rectification and the right to Data portability can no longer be exercised.

Purposes of the Processing of Collected Data

User Data is collected to enable the Owner to provide its Services, as well as for the following purposes: Statistics, Viewing content from external platforms, Interaction with social networks and external platforms, Commenting on content, Protection from SPAM, Accessing accounts on third party services and Registration and authentication.

To obtain further detailed information on the purposes of processing and the Personal Data concretely relevant for each purpose, the User may refer to the relevant sections of this document.

Facebook permissions required by this Application

This Application may require certain Facebook permissions that allow it to perform actions with the User’s Facebook account and collect information, including Personal Data, from it. This service allows this Application to connect with the User’s account on the social network Facebook, provided by Facebook Inc.
For more information about the permissions below, please refer to the Facebook permissions documentation and Facebook’s privacy policy.

The required permits are as follows:

Background information

The basic information of the User registered on Facebook which normally includes the following Data: id, name, image, gender and language of location and, in some cases Facebook “Friends”. If the User has made additional Data publicly available, the same will be available.

Email

Provides access to the User’s primary email address.

Contact email

Provides access to the User’s contact email address.

Details of the processing of Personal Data

Personal Data are collected for the following purposes and using the following services:

Access to accounts on third-party services

These types of services allow this Application to take Data from your accounts on third-party services and perform actions with them.
These services are not activated automatically, but require the express permission of the User.

Facebook Account Login (This Application)

This service allows this Application to connect with the User’s account on the social network Facebook, provided by Facebook, Inc.
Permissions Required: Email and Contact Email.
Place of Processing: USA – Privacy Policy.

Interaction with social networks and external platforms

These types of services allow for interactions with social networks, or other external platforms, directly from the pages of this Application. The interactions and information acquired by this Application are in any case subject to the User’s privacy settings related to each social network. In the event that a social network interaction service is installed, it is possible that, even if Users do not use the service, it may collect traffic data related to the pages where it is installed.

Facebook’s Like button and social widgets (Facebook, Inc.).

The Facebook “Like” button and social widgets are Facebook social network interaction services provided by Facebook, Inc.
Personal Data Collected: Cookies and Usage Data.
Place of Processing: USA – Privacy Policy.

AddThis (Addthis Inc.).

AddThis is a service provided by Clearspring Technologies Inc. that displays a widget that allows interaction with social networks and external platforms and the sharing of content on this Application.
Depending on the configuration, this service may display widgets belonging to third parties, such as the managers of the social networks on which to share interactions. In this case, the third parties that deliver the widget will also learn about the interaction made and the Usage Data related to the pages where this service is installed.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy.

+1 button and Google+ social widgets (Google Inc.).

The +1 button and Google+ social widgets are services for interaction with the Google+ social network, provided by Google Inc.
Personal Data Collected: Cookies and Usage Data.
Place of Processing: USA – Privacy Policy.

Registration and authentication

By registering or authenticating, the User allows the Application to identify him or her and give him or her access to dedicated services.
Depending on what is indicated below, registration and authentication services may be provided with the help of third parties. If this occurs, this Application may access some Data stored by the third-party service used for registration or identification.

Facebook Authentication (Facebook, Inc.)

Facebook Authentication is a registration and authentication service provided by Facebook, Inc. and connected to the social network Facebook.
Personal Data collected: various types of Data as specified by the privacy policy of the service.
Place of processing: USA – Privacy Policy.

Direct Registration (This Application)

The User registers by filling out the registration form and providing their Personal Data directly to this Application.
Personal Data collected: last name, email and first name.

Viewing content from external platforms

This type of service allows to display content hosted on external platforms directly from the pages of this Application and interact with them. In the event that such a service is installed, it is possible that, even if Users do not use the service, it may collect traffic data related to the pages where it is installed.

YouTube Video Widget (Google Inc.)

YouTube is a video content display service operated by Google Inc. that allows this Application to integrate such content within its pages.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy.

Google Fonts (Google Inc.)

Google Fonts is a font style display service operated by Google Inc. that allows this Application to integrate such content within its pages.
Personal Data collected: Usage Data and various types of Data as specified by the privacy policy of the service.
Place of processing: USA – Privacy Policy.


Content commentary

Commenting services allow Users to make and publish their own comments regarding the content of this Application.
Users, depending on the settings decided by the Owner, may also leave the comment anonymously. In case among the Personal Data released by the User is email, this may be used to send notifications of comments regarding the same content. Users are responsible for the content of their comments.
In the event that a comment service provided by third parties is installed, it is possible that, even if Users do not use the comment service, it may collect traffic data related to the pages where the comment service is installed.

Facebook Comments (Facebook, Inc.)

Facebook Comments is a service operated by Facebook, Inc. that allows Users to leave their own comments and share them within the Facebook platform.
Personal Data Collected: Cookies and Usage Data.
Place of Processing: USA – Privacy Policy.

Disqus (Disqus)

Disqus is a content commenting service provided by Big Heads Labs Inc.
Personal Data collected: Cookies, Usage Data, and various types of Data as specified by the service’s privacy policy.
Place of processing: USA – Privacy PolicyOpt out.

Directly managed commenting system (This Application)

This Application has its own content commenting system.
Personal Data collected: last name, email, first name, and website.


Protection from SPAM

This type of services analyzes the traffic of this Application, potentially containing Users’ Personal Data, in order to filter it from parts of traffic, messages and content recognized as SPAM.

Akismet (Automattic Inc.)

Akismet is a SPAM protection service provided by Automattic Inc.
Personal Data collected: various types of Data as specified by the privacy policy of the service.
Place of processing: USA – Privacy Policy.


Statistics

The services contained in this section allow the Data Controller to monitor and analyze traffic data and serve to track User behavior.

Google Analytics (Google Inc.)

Google Analytics is a web analytics service provided by Google Inc. (“Google”). Google uses the Personal Data collected for the purpose of tracking and examining the use of this Application, compiling reports, and sharing them with other services developed by Google.
Google may use the Personal Data to contextualize and personalize ads in its advertising network.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy PolicyOpt Out.

Google Analytics with anonymized IP (Google Inc.).

Google Analytics is a web analytics service provided by Google Inc. (“Google”). Google uses the Personal Data collected for the purpose of tracking and examining the use of this Application, compiling reports and sharing them with other services developed by Google.
Google may use the Personal Data to contextualize and personalize ads in its advertising network.
This Google Analytics integration anonymizes your IP address. Anonymization works by abbreviating within the borders of the member states of the European Union or other countries that are party to the Agreement on the European Economic Area the IP address of Users. Only in exceptional cases will the IP address be sent to Google’s servers and shortened within the United States.
Personal Data Collected: Cookies and Usage Data.
Place of Processing: USA – Privacy PolicyOpt Out.


User Rights

Users may exercise certain rights with respect to the Data processed by the Data Controller.

In particular, the User has the right to:

  • Revoke consent at any time. The User may revoke the previously expressed consent to the processing of his or her Personal Data.
  • Object to the processing of their Data. Users may object to the processing of their Data when it is done on a legal basis other than consent. Further details on the right to object are provided in the section below.
  • access their Data. The User has the right to obtain information about the Data processed by the Data Controller, certain aspects of the processing, and to receive a copy of the processed Data.
  • Verify and request rectification. The User can check the accuracy of their Data and request that it be updated or corrected.
  • Obtain restriction of processing. When certain conditions are met, the User may request the restriction of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its preservation.
  • Obtain the deletion or removal of their Personal Data. When certain conditions are met, the User may request the deletion of their Data by the Data Controller.
  • receive their Data or have it transferred to another owner. The User has the right to receive his or her Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred unimpeded to another data controller. This provision is applicable when the Data are processed by automated means and the processing is based on the User’s consent, a contract to which the User is a party or contractual measures related thereto.
  • Propose complaint. The User may file a complaint with the relevant data protection supervisory authority or take legal action.

Details of the right to object

When Personal Data are processed in the public interest, in the exercise of public powers vested in the Data Controller or in pursuit of a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.

Users are advised that if their Data were processed for direct marketing purposes, they may object to the processing without providing any reasons. To find out whether the Data Controller processes Data with direct marketing purposes, Users can refer to the respective sections of this document.

How to exercise rights

To exercise the User’s rights, Users may address a request to the contact details of the Controller indicated in this document. Requests are filed free of charge and processed by the Holder as soon as possible, in any case within one month.

This Application makes use of Cookies. To learn more and to view the detailed information, the User may consult the Cookie Policy.


More information about the treatment

Litigation defense

The User’s Personal Data may be used by the Data Controller in court or in the preparatory stages of its possible establishment for the defense against abuse in the use of this Application or related Services by the User.
The User declares that he/she is aware that the Data Controller may be obliged to disclose the Data by order of public authorities.

Specific disclosures

Upon the User’s request, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual disclosures regarding specific Services, or the collection and processing of Personal Data.

System logs and maintenance

For operation and maintenance purposes, this Application and any third-party services it uses may collect System Logs, which are files that record interactions and may also contain Personal Data, such as the User IP address.

Information not contained in this policy

Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

Response to “Do Not Track” requests

This Application does not support “Do Not Track” requests.
To find out whether any third-party services used support them, the User is encouraged to consult their respective privacy policies.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by informing Users on this page and, if possible, on this Application as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details held by the Data Controller . Therefore, please consult this page regularly, referring to the date of last modification indicated at the bottom.

If the changes affect processing whose legal basis is consent, the Owner will re-collect the User’s consent, if necessary.


Definitions and legal references

Personal Data (or Data)

Personal data is any information that, directly or indirectly, including in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.

Usage Data

This is the information collected automatically through this Application (including by third party applications integrated into this Application), including: the IP addresses or domain names of the computers used by the User who connects with this Application, the addresses in URI (Uniform Resource Identifier) notation, the time of the request, the method used in forwarding the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc..) the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (e.g. the length of time spent on each page) and the details of the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the User’s operating system and computer environment.

User

The individual using this Application who, except where otherwise specified, coincides with the Data Subject.

Interested

The natural person to whom the Personal Data refers.

Data Processor (or Manager)

The natural person, legal entity, public administration and any other entity that processes personal data on behalf of the Controller, as set forth in this privacy policy.

Data Controller (or Owner)

The natural or legal person, public authority, service or other body that, individually or jointly with others, determines the purposes and means of the processing of personal data and the instruments adopted, including the security measures relating to the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.

This Application

The hardware or software tool by which Users’ Personal Data are collected and processed.

Service

The Service provided by this Application as defined in the relevant terms (if any) on this site/application.

European Union (or EU)

Unless otherwise specified, any reference to the European Union in this document is understood to extend to all current member states of the European Union and the European Economic Area.

Cookie

Small portion of data stored within the User’s device.


Legal references

This privacy policy is drafted based on multiple legislative orders, including Articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy policy covers this Application only.