Banner Palazzo Sciarra Colonna

Privacy & Cookie Policy

Privacy & Cookie Policy

Information pursuant to Articles 13 and 14 of EU Regulation 2016/679 – rev. 2 of 03/07/2026

This website promotes the project of the Museo del Corso – Museum Hub of the Fondazione Roma, in keeping with the principles of inclusion, commitment to the local area, and cultural enhancement that guide the Foundation’s action.

1. WHY THIS INFORMATION

Fondazione Roma protects the privacy of users and ensures that browsing on this website takes place under secure conditions. This notice constitutes the privacy and cookie policy of the website https://www.museodelcorso.com/ (“Site”) and provides users with the information required under Article 13 of Regulation (EU) 679/2016 (“Regulation” or “GDPR”) regarding the methods, logic and purposes of the processing of personal data, as well as the measures adopted for their protection.

The information contained herein refers exclusively to the Site indicated and does not concern any external services, pages or sites that may be reached via links. The Site is managed in compliance with current European and national legislation on the protection of personal data.

Depending on the processing carried out, users may find additional notices on the relevant pages of the Site. For certain activities, specific consent may be required, which will be collected through clear and transparent means.

2. DATA CONTROLLER

The Data Controller for the processing of personal data is Fondazione Roma, with registered office at Via Marco Minghetti 17, (00187) Rome – (telephone +39 06 697645113; email: fgabrielli@fondazioneroma.it).

3. DATA PROTECTION OFFICER

The Data Protection Officer (DPO) is Maurizio Belli of Associazione Università del Lavoro ETS. The DPO can be contacted at: dpo_fr@unilavoro.org.

4. PURPOSES OF PROCESSING

While browsing the site, data relating to identified or identifiable individuals may be processed. The Foundation collects and processes personal data when users browse or voluntarily use the Site’s services and features.

Data is processed for the following purposes:

  • to ensure the functioning and security of the site, preventing abuse or fraudulent activity;
  • to handle contact or information requests submitted by users via email;
  • to manage services provided through the website (for example, the sale of tickets for exhibitions and events);
  • to manage user subscriptions to the newsletter;
  • to fulfil legal or regulatory obligations;
  • to establish or defend a right in legal proceedings, where and if necessary;
  • to manage administrative activities connected to the purposes indicated above.

5. LEGAL BASIS FOR PROCESSING

The processing of personal data is lawful on the basis of:

  • the need to perform contractual or pre-contractual obligations to which the data subject is party, such as handling information requests, providing services and managing the Site’s features (Art. 6(1)(b) GDPR);
  • compliance with legal obligations to which the Controller is subject under applicable laws or regulations (Art. 6(1)(c) GDPR);
  • the legitimate interest of the Controller, such as the management, optimisation, monitoring and security of the Site (Art. 6(1)(f) GDPR);
  • the explicit consent of the data subject; in such cases, clear and transparent means are provided for the voluntary expression of consent (Art. 6(1)(a) GDPR), such as, for example, newsletter subscription, which may be withdrawn at any time.

6. TYPES OF PERSONAL DATA

6.1 Browsing data

The computer systems and software procedures used to operate this website acquire, in the course of their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected in order to be associated with identified data subjects, but by its nature could, through processing and association with other data, allow users to be identified.

This category of data includes the IP addresses or domain names of the computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s response (success, error, etc.), and other parameters relating to the user’s operating system and computing environment.

This data is used solely to derive general, anonymous statistical information on use of the site, in order to verify that it is functioning correctly, and is usually deleted after processing. It is not used to identify the user, for profiling, or for purposes other than those stated. The data may be used to establish liability in the event of hypothetical computer-related offences to the detriment of the site; in such cases, requests made by the Judicial Authority will be complied with.

Browsing data is not retained for more than seven days, except where the Judicial Authority needs to investigate offences.

6.2 Data voluntarily provided by the user

6.2.1 Data provided by the user via email

The optional and voluntary sending of messages and communications to the email addresses shown on the site results in the Controller acquiring the user’s email address (the sender of the message) and any other personal data spontaneously included by the user in the communication. The data will be processed solely to manage the request received and to provide a response to the user. Processing and retention are strictly limited to managing the request, and in any case do not exceed the periods prescribed by applicable laws, regulations and measures.

Messages spontaneously sent by the user are managed through email accounts and/or databases accessed only by persons authorised by the Controller as personnel in charge of processing, or as data processors under Art. 28 GDPR.

6.2.2 Newsletter subscription

Subscription to the newsletter is free and voluntary. To subscribe, the user must provide their name and email address. Newsletter subscription is aimed at the periodic sending of communications regarding the activities, initiatives and services of the Museum Hub.

The subscription form on the Site is managed by 1•618® S.r.l. (Piazza di Campitelli 2, Rome), appointed by the Controller as Data Processor under Art. 28 GDPR for the implementation, management and maintenance of the Site. The data processor 1•618® S.r.l. collects, on behalf of the Controller, the user’s email address and transmits it, solely for the purpose of sending periodic communications (the newsletter), to Civita Mostre e Musei S.p.A. (Piazza Venezia 11, Rome), likewise appointed by the Controller as a separate Data Processor under Art. 28 GDPR.

The relationships between the Controller, 1•618® S.r.l. and Civita Mostre e Musei S.p.A. are governed by specific appointment instruments, which set out the methods of data transmission and the security measures applicable to each party. The data is processed until consent is withdrawn, which may be exercised at any time via the unsubscribe link included in every newsletter.

Data provided by the user for booking services

Through this website, the Foundation encourages cultural outreach and offers users the possibility of independently booking activities and events available within the Museum Hub. The booking process and the specific details of events are described on the dedicated pages, where the user may view any further notices in addition to this policy.

Online ticketing and e-commerce services are provided through third-party platforms, accessible from the Site via dedicated links. These platforms operate independently of the Site and have their own separate privacy notices, to which reference should be made. Processing carried out on those platforms does not fall within the scope of this notice, consistent with what is already stated in point 1.

Any different arrangements for the provision of online ticketing and e-commerce services by suppliers acting on behalf of the Controller will be set out and described on the relevant pages.

6.3 Cookies and other tracking tools

6.3.1 What cookies are

Cookies are small text files that visited sites send to the user’s device (usually to the browser), where they are stored so as to be transmitted back to the same sites on the user’s next visit. While browsing a site, the user’s device may also receive cookies sent by different sites or web servers (third-party cookies).

You can change your cookie preferences click here.

6.3.2 Types of cookies

Cookies are classified according to:

  • duration: session cookies (deactivated when the browser is closed) or persistent cookies (active until expiry or manual deletion);
  • origin: first-party cookies (installed directly by the Site) or third-party cookies (installed by external domains);
  • purpose: technical, analytical or profiling cookies.

Technical cookies are necessary for the operation of the Site and do not require the user’s consent. Analytical and profiling cookies, on the other hand, require explicit consent, managed through the banner displayed when accessing the Site. The saving of cookies may be disabled in whole or in part; in such cases, some features may be affected.

6.4 Cookies used on this website

6.4.1 Technical cookies

Technical cookies are used solely to enable browsing and to allow use of the Site’s features. They are not used for any further purposes and do not require the user’s prior consent. Session cookies are deleted at the end of the browsing session; persistent technical cookies are retained for a maximum of seven days.

COOKIE DURATION
cmplz_banner-status 1 year
cmplz_consented_services 1 year
cmplz_functional 1 year
cmplz_marketing 1 year
cmplz_policy_id 1 year
cmplz_preferences 1 year
cmplz_statistics 1 year
pll_language 1 year
hashAccordionYmc 1 year
newsletter 1 year

6.4.2 Analytics cookies

Third-party cookies for collecting aggregate statistics on use of the Site. These require the user’s consent.

COOKIE DURATION
_ga_CNYNV6G85D 1 year 1 month
_ga 1 year 1 month

6.4.3 Third-party cookies and plugins

Third-party cookies are set by domains other than that of the Controller. The owner of such cookies uses the information independently and has its own notice on the processing of personal data. The Controller of this site is not responsible for processing carried out by third-party sites; for further information, please refer to their respective notices.

To ensure the functionality and management of the Site, some pages may contain plugins managed by third parties. By way of example, the plugins installed are: Polylang (multilingual management), Contact Form 7 (contact forms), Site Kit by Google (integration of Google services), Yoast SEO (search engine optimisation), YMC (search filters), Newsletter (manages newsletter subscription only).

7. COOKIE MANAGEMENT AND DISABLING

The Website works best with cookies enabled, but disabling some types does not completely prevent browsing. By disabling all cookies, including technical cookies, some functionalities may not be available. At any time, users can change cookie settings by clicking the button located at the bottom left of each page of the Website.

Users can manage cookies through their browser settings. Useful links for the most common browsers:

  • Chrome: https://support.google.com/chrome/answer/95647?hl=en
  • Firefox: https://support.mozilla.org/it/kb/Gestione%20dei%20cookie
  • Safari: https://support.apple.com/it-it/guide/deployment/depf7d5714d4/web
  • Edge/Explorer: http://windows.microsoft.com/it-it/windows-vista/block-or-allow-cookies
  • Opera: https://help.opera.com/en/latest/web-preferences/#cookies

For third-party cookies, please refer to the respective privacy policies of the providers. Disabling third-party cookies does not affect browsing on the Website.

8. SOCIAL MEDIA POLICY

The site offers the option of sharing content on social networks (Facebook, Instagram). Should the user decide to share content on social networks, those sites may access certain information from the user’s account. Data sharing with third-party applications can be disabled through the account settings. For further information, users are invited to consult the website of the relevant social network to which they are subscribed.

The Foundation’s official profiles for the Museo del Corso on social media are listed below:

Through its social media channels, the Foundation may share content and messages of public interest and usefulness, including content published by third parties. Any comments beneath the Foundation’s posts, and posts by users that mention the Foundation, represent the opinions of the individuals concerned and not those of the Foundation, which cannot be held responsible for content published by third parties.

Management

The institutional profiles on social media and messaging services are also managed by providers that supply services to the Foundation.

No prior moderation is carried out. For this reason, the Foundation asks users interacting with its social channels to observe a few simple but important rules:

  • Express opinions with courtesy, fairness, respect and appropriate language. Insults, vulgarity, offensive remarks, threats and, in general, violent or defamatory attitudes and conduct are not tolerated. It is understood that each individual is responsible, including legally, for the content they publish and the opinions they express.
  • Content and comments must be relevant to the Foundation’s activities and to personal data protection topics (on topic).
  • Anyone presenting data, news or opinions on specific facts or issues is invited to put forward well-founded, non-specious arguments and to refer to reliable, verifiable sources.
  • Published content must always respect the privacy of individuals. References to facts or details lacking public relevance and that infringe the personal sphere of third parties must in any case be avoided.
  • No form of advertising, spam, or promotion of private interests or of lawful or unlawful activities is permitted.
  • Content that infringes copyright, or the unauthorised use of registered trademarks, is not permitted.

Content

In any event, where possible, our organisation will remove all posts, comments or audio/video material that:

  • use inappropriate language and/or a threatening, violent, vulgar or offensive tone;
  • contain unlawful content or incitement to unlawful activity;
  • are intended to promote products and services;
  • disclose, directly or indirectly, personal data and information (names, email addresses, phone numbers, tax codes, bank account numbers, addresses, videos or photos of identifiable individuals, etc.) or that could in any way cause harm to, or infringe the privacy or reputation of, the individuals concerned;
  • report, directly or indirectly, information relating to minors;
  • contain content that is discriminatory on the basis of gender, race, ethnicity, language, religious belief, political opinion, sexual orientation, age, personal or social circumstances, or health;
  • are intended for spam purposes;
  • promote or support lawful or unlawful activities that infringe copyright or improperly use a registered trademark;
  • are, in general, inconsistent with the Foundation’s institutional communication purposes and with the communicative content of its social profiles (off topic).

Anyone violating these conditions may, at the Foundation’s discretion, be banned or blocked (where possible, after an initial warning) and, in more serious cases (for example, promotion or support of illegal activities, or the commission of any offence or harm to third parties), reported to the platform’s administrators and, where appropriate, to the competent authorities.

The Museo del Corso (Fondazione Roma) social channels may not be used to request personal information (via direct messages, comments, mentions, etc.). For such needs, reference should always be made exclusively to the official contact channels indicated on this site.

In general, a direct response to mentions, messages or comments is not guaranteed, and there are no minimum or maximum response times. Staff reserve the right to respond to comments and messages, or to take part in discussions, only when they consider it genuinely useful — including in terms of providing accurate information to the public — and after assessing the appropriateness of the communicative style adopted by the user.

If the Museo del Corso (Fondazione Roma) follows other users’ accounts, connects with them, adds them to its lists of interest, or comments on or “likes” their content, this does not imply that the Foundation shares the views of the users concerned or approves of all content published by them.

Protection of personal data

The processing of users’ personal data is subject to the policies in force on the platforms used. Personal or sensitive data included in comments or public posts within the Museo del Corso (Fondazione Roma) social media channels may be removed.

Data shared by users through private messages sent directly to channel administrators will be processed in compliance with applicable legislation on the protection of personal data.

9. RECIPIENTS OF PERSONAL DATA

Data collected on the Site is processed by 1•618® S.r.l. (www.1-618.it – privacy@1-618.it), appointed by the Controller as Data Processor under Art. 28 GDPR and as system administrator, for the management of servers, databases, the platform, cloud services, updates, support, maintenance, development, design, performance verification and security of the Site, backup of the web space, and content management of the Site, as well as for the collection — through the dedicated online form on the Site — of the email addresses of users requesting subscription to the newsletter.

The email addresses thus collected on behalf of the Controller are transmitted to Civita Mostre e Musei S.p.A. (Piazza Venezia 11, Rome), likewise appointed by the Controller as a separate Data Processor under Art. 28 GDPR, which is exclusively responsible for preparing and sending periodic communications to newsletter subscribers. The transfer of data between the two Processors is governed by the Controller through contractual clauses under Art. 28 GDPR applicable to each party.

Data is also processed by Foundation personnel in accordance with specific instructions and is not intended for disclosure. Any further recipients may be public bodies or authorities to which disclosure is mandatory by law.

10. PLACE OF DATA PROCESSING

Processing takes place at the Controller’s registered office and at the offices of the Data Processors. In particular, the Site’s technical infrastructure, managed by 1•618® S.r.l., is hosted on servers located in Italy, at Tier IV certified data centres, which ensure high standards of security, redundancy and operational continuity.

11. TRANSFER OF DATA TO THIRD COUNTRIES

Personal data is not transferred outside the European Union: the servers hosting the Site and its data, managed by 1•618® S.r.l., are located in Italy at Tier IV certified data centres. Any future transfers to non-EU countries will take place only in compliance with applicable legislation, ensuring adequate levels of protection through European Commission adequacy decisions, contractual safeguards under Art. 46 GDPR, or binding corporate rules. Data subjects will be promptly informed.

12. DATA RETENTION PERIOD

Browsing data is retained for seven days and then automatically deleted. Other personal data is retained in accordance with applicable legislation, in compliance with the principle of proportionality and for the time necessary to achieve the purposes of processing. Please refer to the retention periods indicated in the preceding paragraphs relating to the types of personal data processed and to the list of cookies.

13. CONSEQUENCES OF REFUSING TO PROVIDE DATA

For certain purposes, such as browsing the site, its operation, technical cookies, and security management, the processing of data is necessary and essential, as it is required for the site to function and to be fully usable by users.

With regard to services and the newsletter, however, users are free to provide their data, choosing whether or not to make use of the features made available through this portal.

With regard to cookies, please refer to the specific paragraph and to the banner for managing consent to the processing of personal data, as specified in the relevant paragraph.

We are required to inform users that failure to provide personal data, even in part, may make it objectively impossible to obtain a response from the Foundation, to manage requests received from the user, or, in cases of objection to all processing, to use the features of the site or browse it.

14. PROCESSING METHODS

Data is processed in compliance with sector-specific regulations and is kept in a manner that ensures its confidentiality, prevents its destruction or use by unauthorised third parties, and complies with specific security measures. Processing is carried out using computer and telematic tools, only by authorised personnel.

15. RIGHTS OF DATA SUBJECTS

Users may exercise the rights of access, rectification, erasure, restriction of processing, objection and withdrawal of consent (Arts. 15–22 GDPR) by contacting:

Fondazione Roma, Via Marco Minghetti 17, 00187 Rome; Controller’s email: fgabrielli@fondazioneroma.it; DPO email: dpo_fr@unilavoro.org.

Right to lodge a complaint: data subjects may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (Art. 77 GDPR) or bring proceedings before the competent courts (Art. 79 GDPR).

16. CHANGES TO THE PRIVACY POLICY

This Privacy & Cookie Policy is subject to periodic updates. The Controller reserves the right to amend it at any time, informing users on this page. Users are invited to check this document regularly to stay updated on any changes.