Privacy

Information on the processing of personal data under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Last updated 30 September 2026 · Cookie policy

Data controller

Associazione Turistica Pro Loco Luras APS, Via Municipio 12, 07025 Luras (SS). Certified email (PEC) associazioneprolocoluras@pec.it, email associazioneprolocoluras@gmail.com. The association has not appointed a Data Protection Officer, as it is not required for its activities: for any question, use the contacts above.

What data we process, why and on what legal basis

Visiting the website. The server records technical data (IP address, page requested, date and time, browser type) for security and operation. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). We do not use analytics or profiling tools.

Contact form, email and certified email. Name, email and message content, so that we can reply. Official correspondence is recorded in the association’s register. Basis: your request and our legitimate interest in keeping proper records (Art. 6(1)(b) and (f)).

Membership. Personal details, tax code, address, contact details, a copy of your ID document and payment receipt; fees paid; notices, attendance and proxies at general meetings. Used to manage membership and keep the registers required by law (members’ register, minutes book). Basis: membership relationship, legal obligations and the statute (Art. 6(1)(b) and (c)). Minutes of general meetings may be consulted by other members, as provided by the Italian Third Sector Code.

Membership renewal. We email last year’s members an invitation to renew. Basis: membership relationship and legitimate interest; you can ask not to receive it at any time.

Digital membership card. The card in the members’ area has a QR code: whoever scans it (for example a partner business) sees only your first name, the initial of your surname, your card number and whether it is valid for the current year.

Registration for events and activities. Details of the participant or contact person, contact details and any attachments, to organise the event. Minors must be registered by a person with parental responsibility. Basis: your request (Art. 6(1)(b)).

Volunteers. Regular volunteers are entered in the volunteers’ register (name, place and date of birth, address, start and end of activity) and notified to the insurance company for the mandatory cover. Basis: legal obligation (Arts. 17 and 18 of the Italian Third Sector Code).

Administration. Data contained in invoices, bank transactions, grants and financial statements, for accounting, tax and transparency obligations. Basis: legal obligations (Art. 6(1)(c)).

Photos and videos at events. We take photos and videos at our events and publish them on the website and social media to show the association’s activities. Basis: legitimate interest. We avoid unnecessary close-ups and take particular care with minors; if you appear in a photo and want it removed, write to us and we will remove it.

Management system (restricted area). Email, encrypted password, optional two-step verification and a log of operations, to keep data secure. Basis: legitimate interest and the obligation to adopt security measures (Art. 32 GDPR).

Is providing data mandatory?

To become a member, register for an event or receive a reply, the fields marked as required in the forms are necessary: without them we cannot process your request. Other data are optional.

Who can see the data

Only authorised people within the association (president, office, board), each with the permissions their role requires; access to the most sensitive data is logged. Data may be processed, as processors or recipients, by: the website hosting provider (servers in the European Union); the certified email provider; the association’s email provider; the bank for payments; the volunteers’ insurance company; the accountant and advisers; public bodies where required by law (for example the Third Sector Register or bodies granting funds). Data are never sold or used for advertising.

Transfers outside the European Union

The association’s email account is provided by a company that may transfer data to the United States under the EU-US Data Privacy Framework or standard contractual clauses. If you choose to display the map, your browser downloads map images from OpenStreetMap servers (United Kingdom, recognised as adequate by the European Commission), which receive your IP address.

How long we keep data

Members’ data and statutory registers: for the duration of membership and ten years after. Copy of ID document: only as long as needed to check the application. Volunteers’ register and accounting and tax records: ten years. Event registrations and messages: no longer than two years, unless recorded in the register. Backups: rotated within twelve months. Server technical logs: for the period set by the hosting provider for security purposes.

Your rights

You can request access to your data, rectification, erasure, restriction of processing, data portability, and object to processing based on legitimate interest, by writing to associazioneprolocoluras@gmail.com or to the certified email associazioneprolocoluras@pec.it. We reply within one month. If you believe the processing breaches the GDPR, you can lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

We do not take decisions about you based solely on automated processing.