Your data, no mysteries
Privacy policy
What information the portal uses, why it is needed and which choices always remain in your hands.
Last updated: 20 July 2026
Minimal data
Account, preferences and technical information required by the service.
GPS is not stored
If allowed, location is used only to guide you on the map.
No advertising
The prototype does not install advertising profiling tools.
Who processes data and scope
This notice covers this demonstration smart guide for the Banditaccia necropolis. It does not represent the Cerveteri and Tarquinia Archaeological Park and does not replace notices on the official website or external ticketing services.
The prototype contact is demo@necropoli-cerveteri-guide.it. Before production, the actual controller's identity, address and contacts — and any data protection officer — must be provided.
Data that may be processed
We collect only what is needed for accounts, preferences and requested features.
- email, nickname and technical account identifiers; passwords are handled by the authentication provider and cannot be read by portal administrators
- language preference, session settings and content saved to a profile
- technical logs, IP address, device type and security information produced by hosting and authentication
- device location only when permitted for the map: it is used during the session and not saved in the portal database
Why data is used
Data is used to create and protect accounts, maintain sessions, remember language, provide requested features and prevent abuse or unauthorised access.
- performance of the requested service and pre-contract steps for registration, login and profile
- legitimate interests in security, error diagnosis and service continuity
- consent, where required, for optional features such as device location
- compliance with legal obligations or competent authority requests
Providers and transfers
The prototype uses a MySQL database and the application framework's own authentication and session handling, running on whichever infrastructure it is deployed to. Any hosting provider may process technical data as a processor, depending on configuration.
Before production, hosting regions, data-processing terms, subprocessors and safeguards for transfers outside the European Economic Area must be checked.
Retention and security
Account data remains available while the account is active or as needed to handle deletion. Technical logs follow configured provider retention periods and should not be kept longer than necessary.
The project uses encrypted connections, access controls, database authorisation rules and separation of public and admin areas. No system is risk-free, and safeguards must be reviewed before public release.
Your choices and rights
You may request access, correction, deletion, restriction, objection or portability where applicable, and withdraw consent without affecting earlier processing.
- write to demo@necropoli-cerveteri-guide.it with enough information to identify the account
- you may lodge a complaint with the Italian Data Protection Authority
- you may deny location access in the browser and still browse the map without positioning