1Introduction
EventsCitta ("EventsCitta", "we", "our", or "us") is committed to protecting the privacy and personal data of all individuals using our platform.
This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when individuals use our website, mobile applications, and related services.
This Privacy Policy has been prepared in accordance with:
- Regulation (EU) 2016/679 ("GDPR")
- Legislative Decree No. 196 of 30 June 2003 ("Italian Privacy Code")
- Legislative Decree No. 101 of 10 August 2018 (which harmonizes Italian law with the GDPR)
- Guidelines issued by the European Data Protection Board (EDPB)
- Guidance issued by the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali)
This Privacy Policy satisfies the information obligations under Articles 13 and 14 GDPR.
↑ Back to contents
2Data Controller
Pursuant to Article 4(7) GDPR, the Data Controller is:
EventsCitta
Owned and operated by: W. SHENEL A. KURERA
Country: Italy
Where required by law, EventsCitta may appoint a Data Protection Officer (DPO). If appointed, the DPO's contact details will be published on our website.
↑ Back to contents
3Categories of Personal Data Collected
EventsCitta only collects personal data necessary to provide its services.
3.1 Event Organizer Information
When organizers register, create events, or communicate with us, we may collect:
- Full name
- Business or company name
- VAT Number (Partita IVA), Tax Code (Codice Fiscale), where applicable
- Registered business address
- Country of establishment
- Email address
- Telephone number
- Identity verification information
- Bank or payout details
- Event information
- Organizer profile information
- Communications with customer support
- Compliance documentation where legally required
3.2 Ticket Buyers and Attendees
We may collect:
- Full name
- Email address
- Telephone number (optional unless required)
- Billing information
- Ticket purchase history
- Event attendance records
- QR codes or digital ticket identifiers
- Refund history
- Customer support communications
Payment card numbers are never stored by EventsCitta when payments are processed through PCI DSS-compliant third-party payment providers.
3.3 Website Visitors
When visiting our website, we automatically collect certain technical information:
- IP address
- Browser type
- Device identifiers
- Operating system
- Language preferences
- Date and time of access
- Pages visited
- Referring URLs
- Cookies and similar technologies
- Security logs
3.4 Account Information
Registered users may provide:
- Username
- Password (encrypted)
- Profile photographs (optional)
- Notification preferences
- Marketing preferences
- Saved events
- Wishlist or favorites
3.5 Communications
When contacting EventsCitta we may process:
- Emails
- Contact forms
- Customer support requests
- Chat conversations
- Complaint information
- Feedback
- Survey responses
↑ Back to contents
4Sources of Personal Data
Personal data may be obtained:
- Directly from users
- During account registration
- During ticket purchases
- During event creation
- Through customer support interactions
- Through cookies
- Through analytics technologies
- Through payment providers
- Through fraud prevention partners
- From publicly available business registers where legally permitted
↑ Back to contents
5Legal Bases for Processing (Article 6 GDPR)
EventsCitta processes personal data only where a lawful basis exists.
A. Contract Performance (Article 6(1)(b))
Processing is necessary to:
- Create accounts
- Manage events
- Sell tickets
- Deliver digital tickets
- Process refunds
- Manage organizer dashboards
- Provide customer support
B. Legal Obligations (Article 6(1)(c))
Processing is necessary to comply with:
- Italian tax legislation
- Accounting obligations
- Anti-money laundering requirements where applicable
- Consumer protection legislation
- Requests from competent judicial or administrative authorities
Relevant legislation may include:
- Italian Civil Code
- Italian Tax Laws
- Presidential Decree No. 633/1972 (VAT)
- Presidential Decree No. 600/1973
- Legislative Decree No. 231/2007 (Anti-Money Laundering), where applicable
C. Legitimate Interests (Article 6(1)(f))
EventsCitta has legitimate interests in:
- Fraud prevention
- Cybersecurity
- Platform monitoring
- Abuse prevention
- Service improvement
- Internal reporting
- Customer support
- Defending legal claims
These interests are balanced against users' rights and freedoms.
D. Consent (Article 6(1)(a))
Consent is obtained where legally required, including for:
- Marketing emails
- Promotional newsletters
- Optional cookies
- Personalized recommendations (where applicable)
Consent may be withdrawn at any time without affecting the lawfulness of prior processing.
↑ Back to contents
6Purposes of Processing
EventsCitta processes personal data to:
- Operate the EventsCitta platform
- Verify organizer accounts
- Review and approve events
- Issue electronic tickets
- Process payments and refunds
- Prevent fraudulent transactions
- Communicate service updates
- Send security notifications
- Respond to customer inquiries
- Improve platform performance
- Generate aggregated analytics
- Comply with legal obligations
- Protect legal rights
↑ Back to contents
7Event Organizer Privacy Commitment
EventsCitta values the confidentiality of organizer information.
EventsCitta does not:
- Sell organizer personal data
- Rent organizer information
- Share organizer data with advertisers for independent marketing
- Commercialize organizer contact information
Organizer information is used solely for legitimate operational, contractual, security, and legal purposes.
↑ Back to contents
8Disclosure of Personal Data
Personal data may be shared only where necessary.
8.1 Service Providers (Data Processors)
EventsCitta may engage carefully selected processors providing:
- Cloud hosting
- Payment processing
- Email delivery
- SMS notifications
- Customer support software
- Security monitoring
- Analytics
- Backup services
Each processor is bound by Article 28 GDPR through a written Data Processing Agreement (DPA).
8.2 Event Organizers
Where necessary for event administration, organizers may receive limited attendee information, such as:
- Name
- Ticket number
- Email address (where required for event management)
- Check-in status
- Ticket category
Organizers act as independent Data Controllers for their own processing activities and must comply with applicable privacy laws.
8.3 Authorities
Personal data may be disclosed where required by:
- Courts
- Judicial authorities
- Law enforcement agencies
- Tax authorities
- Regulatory bodies
- Italian Data Protection Authority (Garante)
↑ Back to contents
9International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), EventsCitta ensures compliance with Chapter V GDPR.
Transfers occur only where supported by:
- European Commission Adequacy Decisions
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules (where applicable)
- Other safeguards recognized under Articles 44–49 GDPR
↑ Back to contents
10Data Retention
Personal data is retained only for as long as necessary.
Typical retention periods include:
- Customer accounts: while active and for a reasonable period after closure
- Financial records: 10 years, where required by Italian accounting and tax laws
- Support communications: up to 5 years
- Security logs: according to operational needs
- Marketing consent records: until consent is withdrawn or no longer required
Data is securely deleted or anonymized after applicable retention periods expire.
↑ Back to contents
11Cookies and Tracking Technologies
EventsCitta uses cookies in accordance with:
- Article 122 of the Italian Privacy Code
- The ePrivacy Directive (Directive 2002/58/EC)
- Guidelines issued by the Italian Data Protection Authority (Garante) on cookies and other tracking tools
Where required, users will be asked to provide consent before non-essential cookies are placed on their device.
↑ Back to contents
12Data Security
EventsCitta implements appropriate technical and organizational measures under Article 32 GDPR, including:
- Encryption where appropriate
- Password hashing
- Multi-factor authentication where available
- Secure HTTPS communications
- Access controls
- Role-based permissions
- Monitoring systems
- Vulnerability management
- Backup and disaster recovery procedures
- Staff confidentiality obligations
While we strive to protect personal data, no electronic transmission or storage method can guarantee absolute security.
↑ Back to contents
13Your Rights Under GDPR
Users have the following rights under Articles 15–22 GDPR:
- Right of Access (Article 15)
- Right to Rectification (Article 16)
- Right to Erasure ("Right to be Forgotten") (Article 17)
- Right to Restriction of Processing (Article 18)
- Right to Data Portability (Article 20)
- Right to Object (Article 21)
- Rights relating to Automated Decision-Making and Profiling (Article 22)
- Right to Withdraw Consent (Article 7)
These rights may be subject to legal limitations under GDPR and Italian law.
↑ Back to contents
14Exercising Your Rights
Requests may be submitted to:
Email: info@eventscitta.com
Please include:
- Full name
- Account email address
- Description of the request
- Supporting information where necessary
EventsCitta may verify identity before fulfilling requests.
Responses will generally be provided within one month, as required by Article 12 GDPR, unless an extension is permitted.
↑ Back to contents
15Complaints
If you believe your personal data has been processed unlawfully, you have the right to lodge a complaint with:
Garante per la Protezione dei Dati Personali (Italian Supervisory Authority)
You may also seek judicial remedies as provided under Articles 77–79 GDPR and the Italian Privacy Code.
↑ Back to contents
16Children's Privacy
EventsCitta does not knowingly collect personal data from children below the minimum age permitted under applicable law without appropriate parental or legal authorization.
If we become aware that such data has been collected unlawfully, we will delete it without undue delay.
↑ Back to contents
17Automated Decision-Making
EventsCitta does not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects, except where authorized by law or with appropriate safeguards under Article 22 GDPR.
↑ Back to contents
18Personal Data Breaches
In the event of a personal data breach, EventsCitta will act in accordance with Articles 33 and 34 GDPR by:
- Investigating the incident
- Mitigating risks
- Notifying the Italian Supervisory Authority where required
- Informing affected individuals when legally necessary
- Maintaining internal breach records
↑ Back to contents
19Third-Party Websites
Our platform may contain links to third-party websites.
EventsCitta is not responsible for the privacy practices or content of external websites. Users are encouraged to review the privacy policies of those third parties before providing personal data.
↑ Back to contents
20Changes to this Privacy Policy
EventsCitta reserves the right to amend this Privacy Policy to reflect:
- Changes in applicable law
- Regulatory guidance
- New technologies
- Platform improvements
- Business developments
The updated version will always be published on the EventsCitta website, and the "Last Updated" date will be revised accordingly.
↑ Back to contents
21Contact Information
For questions regarding this Privacy Policy or the processing of personal data, please contact:
EventsCitta Privacy Team
Where applicable, you may also contact our Data Protection Officer (DPO) using the contact details published on our website.
↑ Back to contents
Governing Legal Framework
This Privacy Policy has been prepared in accordance with, including but not limited to:
- Regulation (EU) 2016/679 (GDPR)
- Legislative Decree No. 196/2003 (Italian Privacy Code)
- Legislative Decree No. 101/2018
- Articles 13 and 14 GDPR (Transparency Requirements)
- Articles 15–22 GDPR (Data Subject Rights)
- Articles 32–34 GDPR (Security and Personal Data Breaches)
- Articles 44–49 GDPR (International Data Transfers)
- Article 122 of the Italian Privacy Code (Cookies and Electronic Communications)
- Relevant guidelines of the European Data Protection Board (EDPB)
- Relevant guidelines and decisions of the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali)