Privacy Notice on the Processing of Personal Data – IT Systems

In accordance with European Regulation No. 2016/679 and current legislation on the processing of personal data, the MAXXI Fondazione processes data fairly, lawfully and transparently, whilst respecting the interests, rights and fundamental freedoms of the data subject. Furthermore, the Fondazione processes only data that is relevant and limited to what is necessary for the purposes of the processing.

This privacy notice is provided pursuant to Article 13 of EU Regulation No. 2016/679.

DATA CONTROLLER
The data controller is:
Fondazione MAXXI, with registered office in Rome at Via G. Reni, 4A – 00196 Rome (e: privacy@fondazionemaxxi.it, t: 063201954, tax code 10587971002)

CATEGORIES OF DATA PROCESSED
The MAXXI Fondazione processes only the data of data subjects necessary to achieve the purposes set out below.
In particular, the Fondazione collects and processes the following personal data:

  • Browsing data: the IT systems and software procedures used to operate this website acquire, during their operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects but, by its very nature, could, through processing and association with data held by third parties, allow users to be identified. This category of data includes:
  • IP address
  • Browser type
  • Name of the internet service provider
  • Date and time of visit to the site
  • Pages visited
  • Parameters of the device used to connect to the website
  • The web page from which the visitor arrived and the page they exited to
  • This data is used in aggregate form solely to derive anonymous statistical information about website usage and to verify its proper functioning. The same data may be used to establish liability in the event of hypothetical cybercrimes against the website or its visitors
  • Data provided voluntarily by the user: the website may collect additional data when the user uses contact forms, makes online purchases, submits unsolicited applications, subscribes to newsletters, or purchases cards. The data collected will be used exclusively to provide the service. This category of data includes:
  • Personal details
  • Email and/or telephone contact details
  • Residential address
  • Tax code and other identification numbers
  • Account details required to carry out the transaction (bank details, card number, etc.)
  • Curriculum vitae
  • Occupation
  • Qualifications
  • Lifestyle habits
  • Images

PURPOSES AND LEGAL BASIS FOR THE PROCESSING OF DATA
Personal data provided by the data subject voluntarily, freely and of their own accord are collected and processed for the following purposes and on the following legal bases:

  • Statistical analysis: collection of data and information in an aggregated and anonymous form in order to verify the proper functioning of the website. None of this information is linked to the individual user of the website and does not in any way allow for their identification.
  • Managing the relationship with the data subject to fulfil contractual or pre-contractual obligations to which the data subject is a party: the data will be processed for the formalisation and management of the contractual relationship (for example, for invoicing online purchases, for the dispatch of goods, for the purchase of subscriptions, for making donations, etc.), including the management of any disputes, as well as for sending communications strictly related to the fulfilment of the respective contractual obligations, and therefore for the ongoing management of the services covered by the contract.
  • To comply with the legal obligations to which the Data Controller is subject: the data will be processed for the purpose of complying with legal obligations laid down by EU regulations, national laws or other regulatory sources. In particular, the Data Controller may process data to fulfil accounting and tax obligations (e.g. invoicing, issuing tickets online, issuing cards online, etc.).
  • To receive information on the Museum’s initiatives, subject to your explicit consent: With your consent, the Museum may process your personal data for the purpose of sending commercial, promotional and advertising communications regarding the Museum’s events and initiatives (direct marketing), as well as to carry out market surveys or research. The Data Controller will use automated means of contact (e.g. email, apps, etc.) and/or traditional methods (e.g. telephone calls with an operator and post) for these purposes. The Data Controller may process your personal data in order to identify and offer communications and initiatives best suited to your personal needs.
  • To comply with orders from the Authority: your data may be processed to fulfil obligations arising from an order issued by the Authority (for example, to investigate and prosecute an offence committed via the internet or against a user).
  • To establish, exercise or defend a legal claim: the Museum may process your data where necessary to defend or exercise its own rights.
  • CCTV surveillance: With regard to the installation of the CCTV system located in areas both inside and outside the museum premises, the purpose of the processing is to prevent unauthorised access and other unlawful conduct, to monitor museum areas during events with significant public attendance that may present challenges, including from the perspective of public order, the identification and prosecution of unlawful behaviour, the protection of the integrity of movable and immovable assets, and the facilitation of investigations by the judicial authorities. The images will be processed in accordance with the law and will not be disclosed except to fulfil legal obligations or orders from the authorities for the purposes of preventing crimes or other offences. The processing of images for these purposes is based on the pursuit of the Museum’s legitimate interests and the fulfilment of legal obligations to which the Data Controller is subject.

The processing of data necessary for the fulfilment of these obligations is required for the management of the relationship, and the provision of such data is mandatory in order to achieve the purposes set out above. Failure to provide, or the provision of incorrect, any of the mandatory information prevents the Data Controller from ensuring the appropriateness of the processing itself.

PERSONS AUTHORISED TO PROCESS DATA AND METHODS OF PROCESSING
The data will be processed exclusively by authorised staff of the MAXXI Fondazione in paper and/or electronic form (paper and electronic archives).

SCOPE OF DATA DISCLOSURE
Personal data collected by the MAXXI Fondazione may be disclosed to third parties, who may be appointed as Data Processors in accordance with the law. In particular, the data may be disclosed to:

  • Consultants and professionals, including those practising in a group
  • Public and/or private entities with which the Fondazione engages for the performance and management of the contractual relationship or to comply with the legal obligations to which it is subject
  • Credit institutions for the payment of fees due
  • Cultural institutions
  • Technicians responsible for the maintenance and management of IT systems and video surveillance systems

The Fondazione does not transfer data to countries outside the European Union.
The specific list of recipients of personal data is available upon request by the data subject. The Fondazione shall notify the recipients to whom the data subjects’ personal data are transmitted of any rectifications, erasures or restrictions on processing, unless this proves impossible or involves a disproportionate effort.