Rome by Cart ยท Moda S.r.l.
๐ฎ๐น Versione italianaThis Privacy Policy is provided pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter also the "Regulation" or the "GDPR") in order to inform users of the manner in which MODA S.r.l. processes Personal Data in connection with the Rome By Cart service.
This Privacy Policy applies to processing operations carried out through the website https://romebycart.com/, including the booking and contact features available on the Site and the links to WhatsApp present on the Site, as well as to interactions with the chatbot accessible via https://linktr.ee/romebycart, published on the official Instagram and TikTok profiles of Rome By Cart, and through direct messages sent to the official Rome By Cart Instagram profile.
This Privacy Policy covers exclusively the processing operations carried out by MODA S.r.l. and does not apply to processing carried out independently by the operators of third-party platforms or services, such as Instagram, TikTok, WhatsApp and Linktree, for which reference should be made to their respective privacy notices.
The Data Controller is MODA S.r.l. (hereinafter, "MODA" or the "Controller"), VAT No. (P. IVA) 17723481002, with registered office in Rome, Via Ignazio Ciampi 18, 00162, Italy.
The Controller may be contacted:
Please be informed that, in the course of your use of the Site, the Controller may collect and process information relating to you. Such information may include, by way of example, identification data such as your name, identification numbers or codes, location data, online identifiers, as well as further elements relating to your physical, physiological, psychological, economic, cultural or social identity which make it possible to identify you, directly or indirectly, in connection with the services requested from time to time (hereinafter, the "Personal Data").
In particular, the Controller may process the following categories of Personal Data:
The Controller may process Personal Data acquired automatically while you browse and use the Site. This category includes, by way of example, the IP address, the country from which the connection originates, the domain names of the device used, the URI (Uniform Resource Identifier) addresses of the resources requested, the date and time of access, the method used to submit the request to the server, the size of the file received in response, and the numerical code indicating the status of the request (for example, successful completion or error).
This information is collected by the IT systems and software procedures that operate the Site in the course of their normal functioning. Although it is not collected in order to be directly associated with identified users, it may, by its very nature or through combination with other information, allow users to be identified. For this reason, such information is also regarded as Personal Data.
The Controller may process the Personal Data that you voluntarily provide through the features and communication channels available on the Site and, in particular:
If you decide to book one of the services offered by Rome By Cart through the "Book Now" or "Book This Tour" features available on the Site, the Controller may process the Personal Data necessary to manage the booking and perform the requested service.
Such data may include:
The Controller may also process the Personal Data you communicate if you decide to interact with a Rome By Cart operator through the links to the WhatsApp service, identified by the relevant icons on the Site.
In this context, the data processed may include your telephone number, the data associated with your WhatsApp account, and the information and content you may include in the communications exchanged with the operator.
We kindly ask you not to communicate, via WhatsApp, any Personal Data that is additional, excessive or not relevant to what is strictly necessary to submit your request and receive the information or assistance you require.
The Controller may also process the Personal Data you provide in the course of your interactions with the chatbot based on artificial-intelligence systems made available by the Controller through channels external to the Site.
The chatbot is accessible via the link https://linktr.ee/romebycart, published on the official Instagram and TikTok profiles of Rome By Cart, as well as by sending a direct message to the official Rome By Cart Instagram profile. Access via direct message is not, however, available on the TikTok profile.
In the course of the interaction with the chatbot, the Controller may process the content of the conversations and the information necessary to respond to the user's requests and to manage any booking of the service. Such data may include, by way of example:
Through the chatbot it is possible to submit and record a booking, which is entered in the Rome By Cart calendar. The chatbot does not, however, allow payments to be made: the price of the booked service will be paid subsequently, in the manner communicated by the Controller.
We kindly ask you not to include in the conversation any Personal Data that is additional, excessive or not relevant to what is strictly necessary to receive information or complete the booking of the service.
The Controller will process Personal Data collected through cookies and other tracking tools. For further information on the Personal Data processed through cookies and other tracking tools, please refer to the relevant Cookie Policy.
Your data will be processed for the following purposes:
The Controller will process the Personal Data referred to in paragraph 2, letter a), in order to allow the user to access the Site and consult its contents, and to ensure the regular functioning and security of the related systems.
The processing is carried out pursuant to Article 6(1)(b) of the Regulation, as it is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
The Controller will process the Personal Data referred to in paragraph 2, letter b), in order to handle and respond to requests for information submitted by users, to receive and confirm bookings, to manage any requests to change or cancel them, and to organise and provide the purchased service.
The processing is carried out pursuant to Article 6(1)(b) of the Regulation, as it is necessary for the implementation of pre-contractual measures taken at the data subject's request or for the performance of the contract concluded with the data subject.
The provision of the Personal Data necessary for these purposes is optional; however, failure to provide such data, even in part, may prevent the Controller from responding to the request, managing or amending the booking and, more generally, providing the requested service.
Once provided, your Personal Data may also be processed for the following purposes:
The Controller will process the Personal Data referred to in paragraph 2 where this is necessary to comply with obligations laid down by national or European Union law, and to follow up on any requests, measures or orders issued by the competent authorities.
This processing is carried out pursuant to Article 6(1)(c) of the Regulation, as it is necessary for compliance with a legal obligation to which the Controller is subject.
The Controller may process the Personal Data referred to in paragraph 2 in order to protect its rights and legitimate interests, including through the establishment, prevention, detection and countering of fraudulent, unlawful or abusive conduct connected with the services offered, and to manage any disputes or defence requirements in and out of court.
The processing is carried out pursuant to Article 6(1)(f) of the Regulation, on the basis of the Controller's legitimate interest in protecting its rights, ensuring the security of its services and preventing unlawful conduct.
For the pursuit of the purposes described in paragraph 3 of this Privacy Policy, your Personal Data may be communicated to, or made accessible to, the following categories of recipients (jointly, the "Recipients"):
As a general rule, the Controller processes Personal Data within the European Union and the European Economic Area. However, for requirements connected, for example, with hosting, electronic data storage, booking management, messaging or the use of IT services, certain Personal Data may be transferred to countries outside the European Economic Area or made accessible to parties established in such countries.
In such circumstances, the Controller ensures that the transfer and subsequent processing of the Personal Data take place in compliance with Articles 44 to 49 of the Regulation and, in particular, on the basis of an adequacy decision adopted by the European Commission, through the execution of the standard contractual clauses approved by the European Commission, or through the adoption of another of the safeguards provided for by the applicable legislation.
Where necessary, the Controller will also assess the adoption of supplementary measures of a contractual, technical or organisational nature, taking into account the guidance contained in Recommendations 01/2020 of the European Data Protection Board.
Further information on any transfers of Personal Data to third countries and on the safeguards adopted may be requested directly from the Controller using the contact details set out in paragraph 1 of this Privacy Policy.
The Personal Data processed for the purposes set out in paragraph 3, letters a) and b), of this Privacy Policy will be retained for the time strictly necessary to allow browsing and the proper functioning of the Site, to handle users' requests, to receive or amend bookings and to provide the requested services, in accordance with the principles of data minimisation and storage limitation set out in Article 5(1)(c) and (e) of the Regulation. The Controller specifies that such Personal Data will be retained for a period not exceeding 12 months from the date of the booking.
It is understood that, where the Personal Data processed for the purpose referred to in paragraph 3, letter b), constitute documents of contractual, administrative, accounting or tax relevance, they will be retained for the period required by the applicable legislation and, in particular, as a rule, for ten years.
The Personal Data processed for the purpose set out in paragraph 3, letter c), will be retained for the period established by the specific legal obligation or by the legislation applicable from time to time.
The Controller may also retain the Personal Data processed for the purpose set out in paragraph 3, letter d), for the time necessary to establish, exercise or defend its rights and interests, in or out of court, including any pre-litigation stages. In the event of disputes, investigations or proceedings, retention may continue until their final conclusion and until the expiry of the time limits for bringing the relevant actions or appeals.
Further information on the retention periods applied and on the criteria used to determine them may be requested from the Controller using the contact details set out in paragraph 1 of this Privacy Policy.
As a data subject, you may exercise at any time, within the limits and under the conditions laid down by the Regulation, the following rights:
Right of access (Article 15 of the Regulation) โ you may obtain from the Controller confirmation as to whether or not Personal Data concerning you are being processed and, where that is the case, obtain access to the data processed and to information regarding the processing.
Right to rectification (Article 16 of the Regulation) โ you may request the correction of inaccurate Personal Data concerning you, as well as the completion of incomplete data.
Right to erasure (Article 17 of the Regulation) โ where the conditions laid down by the applicable legislation are met, you may obtain the erasure of your Personal Data.
Right to restriction of processing (Article 18 of the Regulation) โ in the cases provided for by the Regulation, you may request that the processing of your Personal Data be restricted.
Right to data portability (Article 20 of the Regulation) โ where applicable, you may receive the Personal Data you have provided to the Controller in a structured, commonly used and machine-readable format, and request its transmission to another controller, where technically feasible.
Right to object (Article 21 of the Regulation) โ you may object, on grounds relating to your particular situation, to the processing of your Personal Data based on the Controller's legitimate interest. In that case, the Controller will refrain from further processing unless it demonstrates compelling legitimate grounds which override your interests, rights and freedoms, or that the processing is necessary for the establishment, exercise or defence of legal claims.
If you consider that the processing of your Personal Data infringes the applicable data-protection legislation, you also have the right, pursuant to Article 77 of the Regulation, to lodge a complaint with the competent supervisory authority in the Member State of your habitual residence or place of work, or of the place where the alleged infringement occurred. This is without prejudice to your right to bring proceedings before the competent judicial authority.
To exercise the rights set out above, you may contact the Controller using the contact details indicated in paragraph 1 of this Privacy Policy.
The Controller may amend, supplement or update this Privacy Policy, at any time and also in part, including in order to adapt its content to any legislative, technological or organisational developments.
Users are therefore invited to consult this section periodically, so as to review the most recent version of the Privacy Policy and remain informed about how Personal Data is collected and processed.
This English version is provided for convenience. In the event of any discrepancy, the Italian version shall prevail.