PRIVACY · COOKIE
Your data, clearly explained.
This notice covers bookings, service communications and the audio guide on museofannyusellini.it. Updated 28 September 2026.
Who manages your data
The data controller is the Comune di Arona (Municipality of Arona), Via San Carlo 2, 28041 Arona (NO), Italy. The museum is at Via Trieste 10, Arona. For bookings and enquiries: museousellini@comune.arona.no.it.
The Municipality’s data protection officer (DPO) is Ing. Danilo Roggi: danilo@erregiservice.com. Municipal contacts and documentation.
What data we use and why
- Bookings: first and last name, email, telephone, home town or city for guided visits, party size, date and time, booking code and status, and acknowledgement of this notice. We use these to organise admissions, check availability and duplicates, issue PDF receipts, and retrieve or cancel bookings.
- Guided visits: also suggested dates, responses to proposals, attendance requests and service communications sent to your supplied email. The inauguration form does not send automatic confirmation emails. We do not send newsletters or advertising.
- Requested tour dates: only the date, time, number of requests (one vote per request) and total number of interested people are public. Form selections remain provisional until final confirmation. Names, email addresses, phone numbers and private messages are visible only to authorised staff. A request does not book a tour; bookings for published dates are immediate and can be cancelled up to 24 hours before. Confirmed visits receive confirmation and reminder emails 24 hours and one hour before, with a summary, estimated fee and personal ticket link. Requests for alternative dates do not receive these confirmations.
- Audio guide: first and last name to identify the request at reception, a technical device identifier, access code and duration, activations, revocations, track and language played, playback starts and activity signals. Staff see access and activity to operate the service; this does not measure physical attendance in the museum. Staff may associate a ticket reference with the permission.
- Security: session identifiers, timestamps and operations, attempt limits and protected hashes of contact details or IP addresses. The hosting server may record IP addresses, requested resources, dates, times and errors in its technical logs.
Required fields are necessary to handle your request; without them an online booking cannot be processed. Do not include health information, identity documents or other unnecessary information in messages. Keep your booking ID and surname private: they provide access to your booking.
Legal basis and decisions
Processing supports the public museum service and visitor requests (GDPR Article 6(1)(e)); Article 6(1)(b) applies to requested contractual or pre-contractual services. Legal obligations are covered by Article 6(1)(c). The acknowledgement checkbox records that you have read this notice; it is not consent to advertising.
Availability, duplicates and security limits are checked automatically. Staff publish bookable dates and grant audio-guide access; bookings for published dates are confirmed automatically subject to availability. We do not carry out commercial profiling or solely automated decisions producing legal effects under GDPR Article 22.
For the inauguration and guided visits, authorised staff may send a service message to the supplied address with a personal ticket link, without attaching the PDF. The QR identifies the booking and time slot. Staff scans record the entire group’s arrival, time and operator; exits are not recorded. Camera images are processed on the staff device and are not uploaded or stored. Sending records contain recipient, content, status and time and are retained, like bookings, for no more than six months from collection; authorised staff handle deletion, including private copies of these records.
Individual and group conversations in the web app are no longer active. The guide can propose a visit by email to people who have requested a date. Requests selected for sending are moved to private history, preserving the requested date, proposed date and email status. Staff-recorded arrivals are available in a separate list. Previously stored conversations remain subject to the retention periods below.
Access and external services
Data are accessible to authorised staff according to their role and to technical providers required for the service: Hostinger hosting and email. Visitors’ names are not published; the calendar displays aggregate counts. Operational emails may use a technical mailbox different from the Municipality’s public contact address.
Ticket.it handles ticket purchases on its own website: this web app does not collect payment-card data. The museum website, Ticket.it and Google Maps open only when you follow their links and have their own privacy notices. This app does not embed external maps, videos or advertising tools.
For details of processors, hosting location and any transfers outside the European Economic Area and the applicable safeguards, contact the Municipality or DPO using the details above.
Private feedback and reports
You may choose to submit a 1–5 star rating and an optional comment. Reviews are private and available only to the authorised guide and administrator. Guided-visit reviews are linked to the booking; audio-guide reviews to the device access pass. You may provide an optional email address for a reply. Do not include sensitive information or other people’s data in comments.
At your explicit request we can send one email invitation around two hours after the visit or access expires, unless you already submitted feedback. The option is voluntary and initially unchecked; you can withdraw it on the feedback page before sending starts. It does not subscribe you to a newsletter. Feedback and contact details are retained for at most six months from initial collection and then removed by the automatic process.
Internal reports show booking counts, recorded arrivals and average ratings, without names or contact details. Audio-guide starts and estimated playback seconds are measured using the signals already needed for the player. Daily summaries use a pseudonymous pass identifier without email, name or IP address to avoid duplicate counting within a period. These summaries are retained for up to six months; original technical logs retain their seven-day duration. They are not used for advertising or cross-site profiling. Staff manage downloaded reports under the same retention limits.
How long we keep data
- Bookings and conversations: no more than six months from collection. Archiving a request in the panel hides it from the main list but does not delete it; authorised staff handle deletion within the deadline, including exported copies and backups. A new message does not extend the retention of earlier messages.
- Audio-guide permissions, requests, names and logs: seven days; technical cleanup runs as the service is used. Permissions expire earlier according to the duration authorised by staff.
- Application security logs: normally 30 days; attempt limits: until the relevant interval expires. Hosting-provider logs follow the service settings, available from the controller.
- Specific legal obligations or the protection of a right may require longer retention of only the necessary data, with restricted access.
Your rights
You may request access, correction, erasure or restriction of your data and object to processing; portability applies where provided by the GDPR. Contact the museum or the Municipality’s protocol office with your request. A proportionate identity check may be required. protocollo@comune.arona.no.it.
You may also contact the DPO or lodge a complaint with the Garante per la protezione dei dati personali.