Privacy Policy
Last updated: 2 October 2026
1. Scope This notice covers processing through the club website: browsing, contact requests, events, bookings, technical security and gallery. Linked external services, including SocioPro or SPU Card when configured, have their own notices.
2. Controller The Controller is the entity operating the club and determining purposes and means. Final identity, address and privacy contact must be completed in Admin → Legal before final publication. Missing facts are not invented.
3. Technical and security data Server/hosting infrastructure may process IP address, date/time, requested URL, request result, User-Agent and equivalent technical data. The application uses a technical PHP session and CSRF tokens. Certain anti-abuse functions may retain a pseudonymized technical hash derived from the IP address for anti-abuse purposes; it is not described as absolutely anonymous.
4. Contact form Name, email, subject, message, language and necessary anti-abuse data are processed to answer requests, manage correspondence and protect the service. Depending on the request, the basis may be steps requested by the data subject and/or legitimate interests in managing and securing communications. Contact data must not be reused for marketing without a separate legal basis.
5. Bookings Online booking is a processing activity separate from member management. When enabled, the website processes the name entered for the booking and the email address, together with data strictly necessary for the booking: event, party size, table, status, date/time, verification code and technical data required for security and abuse prevention. The booking website does not consult or display the member's complete profile. A booking is not membership registration and does not replace the membership card required for admission.
6. Operational email Email may be used for OTP, confirmations, booking-related updates and requested replies. Operational messages must not automatically become promotional marketing.
7. Event photographs The gallery may publish event photographs. The legal basis and collection/publication process must match the club's real practice. Requests about an image can identify the event and photograph to the privacy contact.
8. Purposes and legal bases Purposes include requested functionality, contacts and bookings, security and integrity, abuse prevention, legal obligations and establishment/exercise/defence of claims. Depending on the real processing, bases may include GDPR Art. 6(1)(b), 6(1)(c), 6(1)(f) and, where genuinely required, 6(1)(a).
9. Required information Required fields are needed to provide the requested function. Failure to provide them may prevent contact or booking. Optional data should not become mandatory without documented necessity.
10. Controller, authorised persons and SocioPro / SPU Card For association-life, membership-card, access-check and Circolo service data, the Controller is ASSOCIAZIONE CULTURALE CIRCOLO PERUVIANO, registered office Via Volta n. 1, Bolzano (BZ), privacy contact circoloperuviano@proton.me.
Ordinary member-data access is restricted to persons authorised by the Association according to role and need. SocioPro and SPU Card are software developed by Carlos Ramirez. For member registration and access to the digital membership card, the identification data processed in the system are first name, last name, date of birth and email address. These data are processed for the association purposes determined by the Circolo, including membership registration management and access to the digital card. Carlos Ramirez does not use these data for his own purposes and has no ordinary access to member data. For the website and digital systems, Carlos Ramirez acts exclusively in website development and technical management. That technical role does not confer ownership of the Circolo, legal representation, presidency or Controller status for processing decided by the Association. Carlos Ramirez has no ordinary access to member data.
Exceptional technical access for support, maintenance or security must be authorised in advance by the Circolo, limited to what is necessary, protected and logged where technically possible. Where an external provider processes data on behalf of the Controller, the relationship must reflect the actual role, including an Article 28 GDPR arrangement where applicable. Actual hosting, email and other infrastructure providers must be documented separately.
11. Recipients Authorised personnel and genuinely necessary technical providers such as hosting, email, maintenance or security may receive data. The Controller must maintain the real provider list, roles and Art. 28 arrangements where applicable. Disclosure may also occur when required by law or for legal claims.
12. External services The site may link to Instagram, Telegram, WhatsApp, SocioPro and SPU Card. A link does not necessarily transmit data before a click. Embedded third-party content requires separate assessment. The map should load only after a user action rather than automatically.
13. International transfers These depend on the actual providers. Before production, location, role and the applicable GDPR Chapter V mechanism must be verified. No specific transfer is claimed without identifying the real provider.
14. Chatbot and Cloudflare Workers AI The site provides an assistant combining local rules, public website information and transactional PHP functions. For some questions, when enabled, the user’s text and a limited context of relevant public information may be sent to Cloudflare Workers AI to generate a response. Booking, availability, table capacity and OTP verification remain controlled by the site system and are not autonomously confirmed by the AI model. API tokens, SMTP passwords, OTP codes and administrative secrets must not be included in AI context. Unrecognised questions may be stored in limited form (truncated text, language and a technical IP hash) to improve the knowledge base; users should not enter sensitive data in the chatbot.
15. Retention Operational booking data is retained until 06:00 on the day following the event and is then automatically deleted from the operational system, unless longer retention is necessary for a legal obligation, dispute or legal claims. OTP codes are retained only as technically necessary for verification. Contact messages, security/admin logs and backups follow internal periods or criteria proportionate to their actual purpose.
SocioPro/SPU Card association data is retained according to the duration and needs of the membership relationship, applicable obligations and internal rules validly adopted by the Circolo.
Exclusion/blacklist data is retained while the measure remains effective and only as necessary to identify the person and apply access and safety rules. An exclusion may be temporary, indefinite or permanent according to decisions by the Association's competent bodies or authorised persons and applicable internal rules. An indefinite exclusion remains until review or revocation; a permanent exclusion remains unless later revoked. Retention necessity is reviewed periodically and, after expiry or revocation, data is erased or restricted unless further retention is justified by law or legal claims. Notes must be concise, relevant and limited to what is necessary.
15. Backups Operational deletion may not immediately erase existing backups. Backups should be protected, have a defined lifecycle and not be reused for incompatible ordinary purposes.
16. Cookies The Cookie Policy describes current technologies. Introducing analytics, marketing, pixels, profiling or other trackers requires a new review and prior consent where required.
17. Profiling No automated decision-making or legal-effect profiling is claimed unless actually implemented. The notice must be updated before any such future use.
18. Children The website is not designed to intentionally collect children's data through dedicated functions. Event/venue age rules remain governed by applicable requirements.
19. Security Measures include HTTPS when correctly configured, HttpOnly/SameSite session cookies, CSRF protection, prepared queries, Admin access controls and anti-abuse controls. No measure is presented as absolute security.
20. Rights Where applicable: access, rectification, erasure, restriction, portability, objection and withdrawal of consent. Reasonable identity verification may be requested without systematically collecting excessive documents.
21. Complaints A complaint may be lodged with the Garante per la protezione dei dati personali and, where applicable, another competent supervisory authority.
22. Changes This notice must be reviewed when functions, providers, purposes, data or retention change. Material changes should not be hidden behind a date change alone.
Via Volta 1/B, 39100 Bolzano (BZ)
Visualizza la zona e apri le indicazioni sul tuo dispositivo.
