Privacy & Data Protection

EventsCitta Privacy Policy

Compliant with Regulation (EU) 2016/679 (GDPR), the Italian Privacy Code (Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018), and applicable Italian & European data protection laws.

Effective Date01/08/2026 Last Updated01/08/2026 JurisdictionItaly / EU

Contents

  1. Introduction
  2. Data Controller
  3. Categories of Personal Data Collected
  4. Sources of Personal Data
  5. Legal Bases for Processing
  6. Purposes of Processing
  7. Event Organizer Privacy Commitment
  8. Disclosure of Personal Data
  9. International Data Transfers
  10. Data Retention
  11. Cookies and Tracking Technologies
  12. Data Security
  13. Your Rights Under GDPR
  14. Exercising Your Rights
  15. Complaints
  16. Children's Privacy
  17. Automated Decision-Making
  18. Personal Data Breaches
  19. Third-Party Websites
  20. Changes to this Policy
  21. Contact Information

1Introduction

EventsCitta ("EventsCitta", "we", "our", or "us") is committed to protecting the privacy and personal data of all individuals using our platform.

This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when individuals use our website, mobile applications, and related services.

This Privacy Policy has been prepared in accordance with:

This Privacy Policy satisfies the information obligations under Articles 13 and 14 GDPR.
↑ Back to contents

2Data Controller

Pursuant to Article 4(7) GDPR, the Data Controller is:

EventsCitta

Where required by law, EventsCitta may appoint a Data Protection Officer (DPO). If appointed, the DPO's contact details will be published on our website.

↑ Back to contents

3Categories of Personal Data Collected

EventsCitta only collects personal data necessary to provide its services.

3.1 Event Organizer Information

When organizers register, create events, or communicate with us, we may collect:

3.2 Ticket Buyers and Attendees

We may collect:

Payment card numbers are never stored by EventsCitta when payments are processed through PCI DSS-compliant third-party payment providers.

3.3 Website Visitors

When visiting our website, we automatically collect certain technical information:

3.4 Account Information

Registered users may provide:

3.5 Communications

When contacting EventsCitta we may process:

↑ Back to contents

4Sources of Personal Data

Personal data may be obtained:

↑ Back to contents

5Legal Bases for Processing (Article 6 GDPR)

EventsCitta processes personal data only where a lawful basis exists.

A. Contract Performance (Article 6(1)(b))

Processing is necessary to:

B. Legal Obligations (Article 6(1)(c))

Processing is necessary to comply with:

Relevant legislation may include:

C. Legitimate Interests (Article 6(1)(f))

EventsCitta has legitimate interests in:

These interests are balanced against users' rights and freedoms.

D. Consent (Article 6(1)(a))

Consent is obtained where legally required, including for:

Consent may be withdrawn at any time without affecting the lawfulness of prior processing.

↑ Back to contents

6Purposes of Processing

EventsCitta processes personal data to:

↑ Back to contents

7Event Organizer Privacy Commitment

EventsCitta values the confidentiality of organizer information.

EventsCitta does not:

Organizer information is used solely for legitimate operational, contractual, security, and legal purposes.

↑ Back to contents

8Disclosure of Personal Data

Personal data may be shared only where necessary.

8.1 Service Providers (Data Processors)

EventsCitta may engage carefully selected processors providing:

Each processor is bound by Article 28 GDPR through a written Data Processing Agreement (DPA).

8.2 Event Organizers

Where necessary for event administration, organizers may receive limited attendee information, such as:

Organizers act as independent Data Controllers for their own processing activities and must comply with applicable privacy laws.

8.3 Authorities

Personal data may be disclosed where required by:

↑ Back to contents

9International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), EventsCitta ensures compliance with Chapter V GDPR.

Transfers occur only where supported by:

↑ Back to contents

10Data Retention

Personal data is retained only for as long as necessary.

Typical retention periods include:

Data is securely deleted or anonymized after applicable retention periods expire.

↑ Back to contents

11Cookies and Tracking Technologies

EventsCitta uses cookies in accordance with:

Where required, users will be asked to provide consent before non-essential cookies are placed on their device.

↑ Back to contents

12Data Security

EventsCitta implements appropriate technical and organizational measures under Article 32 GDPR, including:

While we strive to protect personal data, no electronic transmission or storage method can guarantee absolute security.

↑ Back to contents

13Your Rights Under GDPR

Users have the following rights under Articles 15–22 GDPR:

These rights may be subject to legal limitations under GDPR and Italian law.

↑ Back to contents

14Exercising Your Rights

Requests may be submitted to:

Email: info@eventscitta.com

Please include:

EventsCitta may verify identity before fulfilling requests.

Responses will generally be provided within one month, as required by Article 12 GDPR, unless an extension is permitted.

↑ Back to contents

15Complaints

If you believe your personal data has been processed unlawfully, you have the right to lodge a complaint with:

Garante per la Protezione dei Dati Personali (Italian Supervisory Authority)

You may also seek judicial remedies as provided under Articles 77–79 GDPR and the Italian Privacy Code.

↑ Back to contents

16Children's Privacy

EventsCitta does not knowingly collect personal data from children below the minimum age permitted under applicable law without appropriate parental or legal authorization.

If we become aware that such data has been collected unlawfully, we will delete it without undue delay.

↑ Back to contents

17Automated Decision-Making

EventsCitta does not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects, except where authorized by law or with appropriate safeguards under Article 22 GDPR.

↑ Back to contents

18Personal Data Breaches

In the event of a personal data breach, EventsCitta will act in accordance with Articles 33 and 34 GDPR by:

↑ Back to contents

19Third-Party Websites

Our platform may contain links to third-party websites.

EventsCitta is not responsible for the privacy practices or content of external websites. Users are encouraged to review the privacy policies of those third parties before providing personal data.

↑ Back to contents

20Changes to this Privacy Policy

EventsCitta reserves the right to amend this Privacy Policy to reflect:

The updated version will always be published on the EventsCitta website, and the "Last Updated" date will be revised accordingly.

↑ Back to contents

21Contact Information

For questions regarding this Privacy Policy or the processing of personal data, please contact:

EventsCitta Privacy Team

Where applicable, you may also contact our Data Protection Officer (DPO) using the contact details published on our website.

↑ Back to contents

Governing Legal Framework

This Privacy Policy has been prepared in accordance with, including but not limited to: