visittuscany.com is the official tourism website of the Region of Tuscany and offers users a general overview of the entire cultural and touristic patrimony of Tuscany as well as the possibility to contribute, through dedicated spaces, to spreading knowledge about the region.
visittuscany.com was created and is managed by the Fondazione Sistema Toscana (hereinafter also referred to as “FST”), a legally recognized private entity and in-house provider of the Region of Tuscany, and a tool for carrying out the following institutional aims:
a) development of digital communication for the valorization and promotion of cultural heritage and activities, research and innovation, information society and knowledge;
b) promotion of the integration between cultural offerings and tourism offerings;
c) promotion and diffusion of film and audiovisuals and educational initiatives;
d) film commission activities;
e) promotion and valorization of Tuscan identity and development of youthful policies and rights.
In compliance with national legislation (Legislative Decree 30 June 2003 n.196, Code regarding the protection of personal data) and community law (European regulation for the protection of personal data n. 679/2016, GDPR) and subsequent amendments, this site respects and protects the privacy of visitors and users, making every possible and proportionate effort not to infringe upon the rights of users.
The Data Controller pursuant to the laws in force is:
Regione Toscana - Giunta regionale
Piazza Duomo, 10
The Data Processor, responsible for the processing of the data, by appointment of the Data Controller, pursuant to the laws in force is:
Fondazione Sistema Toscana
Via Duca d’Aosta, 9
The Data Protection Officers (DPOs) of the Data Controller and of the Data Processor can be reached at the following e-mail addresses:
Data Protection Officer of the Regione Toscana - Giunta regionale (regional council): firstname.lastname@example.org
Data Protection Officer of Fondazione Sistema Toscana: email@example.com
This site (hereinafter also referred to as “Application”) processes data based on consent.
The provision of data and therefore consent to the collection and processing of data is optional, the user can deny consent, and can revoke a consent already provided at any time. However, denying consent may make it impossible to provide some services and the browsing experience on the site may be compromised. Starting from 25 May 2018 (date of entry into law of the GDPR), this site can process data based on the legitimate interests of the Data Controller.
visittuscany.com brings together texts and multimedia (texts, images, sounds, film clips, graphics, logos, audiovisuals, etc. henceforth known as “content”) for informational purposes and to promote tourism in Tuscany.
The content is produced by:
All those who provide content through the participation in project by visittuscany.com expressly accept the following legal conditions:
All the content is protected by current laws regarding authors’ rights and intellectual property, and, therefore, unauthorized reproductions, use of content and/or making the content available to the public (even through file-sharing) is not allowed. Anyone who violates this ban is subject to civil and criminal penalties in accordance with the law.
This type of service allows you to view and interact with content hosted on external platforms directly from the pages of this site.
In the event that a service of this type is installed, it is possible that, even if users do not use the service, it collects traffic data relating to the pages in which it is installed.
Google Fonts (Google, Inc.)
Google Fonts is a font style visualization service managed by Google, Inc. that allows this site to integrate such content within its pages.
Widget Google Maps (Google, Inc.)
Google Maps is a map display service managed by Google, Inc. that allows this site to integrate such content within its pages.
Personal Data collected: Cookies and Usage Data.
Visittuscany.com may contain links to other websites or social media that are not necessarily under the control of the Data Controller and of the Data Processor.
The user is encouraged to carefully read the conditions and terms of operation and use of these sites. The Data Controller and the Data Processor do not assume responsibility either for the unauthorized use of user's data or for any further monitoring or profiling that may be carried out by the aforementioned sites.
The website uses log files which conserve data collected automatically during a visit to the website. The data collected could be the following:
The geolocation of the user's device is processed in an automated and entirely anonymous way for the sole purpose of georeferencing the device on a map, calculating the distances between the location of the device and the place the user wants to visit, as well as for statistical purposes and in order to define the areas of local use of the application itself.
To ensure security (anti-spam filters, firewall, survey of viruses), the data registered automatically could be used, in accordance with the relevant current laws, to block attempts to damage the website or other users, as well as damaging or criminal activities. Such data are never used for identifying and profiling the user, but are only intended to safeguard the website and its users (since May 25, 2018, data may be processed on the basis of the legitimate interests of the Data Controller pursuant to current regulations).
The data collected from the website during its operation are used exclusively for the aims indicated and are conserved for the time necessary for carrying out precise activities or, if applicable, until there is a cancellation request for accounts registered to the website. The data collected from the website will never be passed to third parties for any reason, unless there is a legitimate request from judicial authorities and only in cases allowed by law.
By accessing and navigating the website, users accept that the aforementioned data are processed for the previously mentioned purposes of IT security and preventing illegal activities. The user can request that their data be cancelled and/or exercise their rights as protected by current laws.
The data is processed at the Data Center ex TIX (Tuscany Internet Exchange), Via San Piero a Quaracchi n. 250 - Florence, now part of the Sistema Cloud della Toscana (SCT - Tuscany Cloud System).
In compliance with general regulation (European Regulation for the protection of personal data 2016/679, Art. 28, par. 3), organizations who process personal data on behalf of the Data Controller or the Data Processor have been appointed as Data (Sub-)Processors, to ensure compliance with the requirements of the regulation.
Session cookies are essential for distinguishing connected users, and are useful for ensuring that a requested function not be provided to the wrong user, as well as for security purposes so as to avoid damaging attacks on the website. Session cookies do not contain personal data and last only as long as the session does, that is, until the browser is closed. Consent is not needed for them.
Functionality cookies used by the website are strictly necessary for operating the site; they are those connected to a user’s request for a specific function (like login), for which consent is not needed).
Deleting cookies does not preclude use of the site.
Users / visitors can set the computer browser to accept / reject all cookies or display a warning every time a cookie is proposed, in order to evaluate whether to accept it or not.
By default, almost all web browsers are set to automatically accept cookies.
Users / visitors can still change the default setting, or disable cookies (i.e. block them permanently), by setting the highest level of protection in the browser, however, disabling them can compromise the use of site functions.
In any case, it remains possible to delete or remove cookies from your device, using the appropriate functions present in the browser. Deleting the cookies does not preclude the use of the site, but involves the repetition of the authentication procedure, or the re-submission of the access credentials.
There are also components (plugins) for the most popular browsers that allow:
• the management (display, cancellation, block) of cookies
• visualization of the technologies used by the site
• the visualization and (selective) blocking of the different tracking mechanisms
visittuscany.com uses the tools Google Analytics and Tag Manager for monitoring access to the website (number of accesses, new users, number of sessions, visualizations of a page, type of device and browser, etc.) and receiving information regarding user behaviour on the website (referral, duration of sessions, bounce rate, etc.) for statistical and market study purposes. FST does not collect users’ personal data because the information related to accessing the website and user behaviour are provided by Google Analytics and Tag Manager in an aggregated and non-personalized/anonymous form. However, FST does not respond to the processing of data collected by Google Inc. through Analytics and Tag Manager. Google could use, unbeknownst to FST, personal data for contextualizing and personalizing advertisements on their marketing network. Information about the two Google tools used are as follows:
Google Ads conversion tracking (Google Inc.)
Google Ads conversion tracking is a statistics service provided by Google LLC or by Google Ireland Limited, depending on the location in which visittuscany.com is used. It connects data from the Google Ads network with the actions performed internally on visittuscany.com
Personal Data processed: Cookies and Usage Data.
Google Ads Remarketing (Google Inc.)
Google Ads Remarketing is a remarketing and behavioral targeting service provided by Google LLC or by Google Ireland Limited, depending on the location in which visittuscany.com is used. It connects the activity of visittuscany.com with the Google Ads advertising network and DoubleClick Cookies.
Google installs cookies to study and improve advertising, with remarketing actions, in order to send the user messages in line with their interests. Remarketing also helps reach users who have visited the site, depending on the type of interaction they have had with it.
Users can choose not to use Google cookies for ad personalization by visiting the Google ad settings.
Personal Data processed: Cookies and Usage Data.
Remarketing with Google Analytics
Remarketing with Google Analytics is a remarketing and behavioral targeting service provided by Google LLC or by Google Ireland Limited, depending on the location in which visittuscany.com is used. It links the tracking activity carried out by Google Analytics and its Cookies with the Google Ads advertising network and Doubleclick Cookies.
Personal Data processed: Cookies and Usage Data.
The collection and use of data obtained via the plugin are regulated according to the related privacy policies of the social networks, which users are advised to refer to.
visittuscany.com’s code contains Facebook Pixel, a tool for collecting statistical data that allows website managers to measure the effectiveness of their advertising by understanding the actions people take on their websites.
Facebook installs cookies for analyzing and improving advertising through remarketing activities in order to send users messages in line with their interests. Remarketing helps reach users who have visited the websites.
With the aim of increasingly responding to the needs of those using the website, visittuscany.com uses HotJar, a monitoring tool that allows for the analysis of user behaviour, acquiring information about actions, such as clicks, taps, page scrolling, mouse movements, etc.. The data is collected in such a way that it is not traced to the user.
HotJar is a service provided by Hotjar Ltd.
Visittuscany.com uses Clarity, a monitoring tool that allows the analysis of user interaction on the website to identify which areas of a page the cursor passes over or that are clicked on with the mouse, so that the areas attracting the greatest interest can be recognized (heat mapping). Clarity may record sessions and make them available for later analysis.
Clarity is a service provided by Microsoft Ireland Operations Limited.
Periodically, the visittuscany.com staff uses SEMrush and Sprout Social, digital marketing tools that allow for the processing of statistics regarding the performance of the website’s content on social media channels tied to the digital promotion of tourism in Tuscany.
Semrush is a service provided by Semrush Inc. and the subsidiary SEMrush CZ s.r.o.
Sprout Social is a service provided by Sprout Social, Inc.
visittuscany.com uses Sojern pixel to collect information on users navigation and to track cookies for advertising purposes. Through Sojern pixel, data on users travel intentions are collected, however no information is collected that can personally identify them, such as name, address, email address, or telephone number. Examples of the data acquired are: information on the destination, dates, length of stay and number of travellers.
Sojern is a service provided by Sojern, Inc.
By filling in the forms made available on visittuscany.co with their data, users/visitors agree to periodically receive updates on news relating to the subject of the form.
Personal data collected: common data and e-mail address.
Communications are sent via e-mail to those who explicitly request them by filling out the aforementioned forms and authorizing the owner to process their personal data. Providing this data is optional, but by refusing to provide personal data, the user will be unable to send content via the form.
Website users can choose to subscribe to the visittuscany.com newsletter in order to periodically receive updates about the newest changes to the website. The tool used to send and manage the newsletter is Mailchimp, a service provided by The Rocket Science Group, LLC that manages email addresses and sending emails.
Personal data collected: common data and email addresses
The newsletter is sent via email to those who specifically request to receive it by filling out the dedicated form and authorizing FST to process users’ personal data. Providing this data is optional, but by refusing to provide data, the user will be unable to subscribe to the newsletter.
First access: when accessing the website for the first time, users will see a message that gives them the option of accepting or refusing the use of technical and profiling cookies of third parties on the part of visittuscany.com. By providing their consent, users authorize Data Controller and the Data Processor to use all the tools listed in this policy for the purposes described and for the type of personal data indicated.
Geolocation: when accessing some pages of the website for the first time, users will see a message that gives them the option of accepting or refusing the geolocation of their own device, via GPS, mobile network, or IP address, by visittuscany.com. By providing their consent, users authorize the Data Controller and the Data Processor to use all the tools listed in this policy for the purposes listed and for the type of personal data indicated.
This site processes user data in compliance with legal requirements, taking appropriate security measures to prevent unauthorized access, disclosure, modification or unauthorized destruction of data. The data processing is carried out using IT and / or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In addition to the Data Controller and Data Processor, in some cases, categories of employees (administrative, commercial, marketing, legal, system administrators) or external subjects (such as third party technical service providers, hosting providers, IT companies, communication agencies) may have access to the data) appropriately appointed in compliance with current regulations.
In accordance with EU Regulation 679/2016 (GDPR) and national legislation, users can, within the procedures and limits provided by current law, exercise the following rights:
Requests can be addressed to the Data Controller and the Data Processor.
In cases in which data are processed based on legitimate interests, the rights of interested parties are nonetheless guaranteed (except the right of portability, which is not required by current laws), especially the right to oppose processing, which can be applied by sending a request to the Data Controller and the Data Processor.
The general conditions apply to each one of these aforementioned projects, with the exception of the specific points indicated in their individual policies.