Your data, no mysteries
Privacy policy
What information the portal uses, why it is needed and which choices always remain in your hands.
- Minimal data
- Account, preferences and technical information required by the service.
- GPS is not stored
- If allowed, location is used only to guide you on the map.
- No advertising
- The prototype does not install advertising profiling tools.
Last updated: 16 July 2026
This is a demonstration portal and not the official Bioparco di Roma website. Before a real launch, the controller, providers, retention periods and contacts must be verified and completed.
01
Who processes data and scope
This notice covers Bioparco Roma Interactive, a demonstration project for planning a park visit. It does not represent Bioparco di Roma and does not replace notices on the official website or external ticketing services.
The prototype lists no contact address: the portal is an independent concept, not operated by Fondazione Bioparco di Roma. Before production, the actual controller’s identity, address and contacts—and any data protection officer—must be provided.
02
Data that may be processed
We collect only what is needed for accounts, preferences and requested features.
- email, nickname and technical account identifiers; passwords are hashed and cannot be read by portal administrators
- language preference, session settings and content saved to a profile
- technical logs, IP address, device type and security information produced by hosting and authentication
- device location only when permitted for the map: it is used during the session and not saved in the portal database
03
Why data is used
Data is used to create and protect accounts, maintain sessions, remember language, provide requested features and prevent abuse or unauthorised access.
- performance of the requested service and pre-contract steps for registration, login and profile
- legitimate interests in security, error diagnosis and service continuity
- consent, where required, for optional features such as device location
- compliance with legal obligations or competent authority requests
04
Providers and transfers
The prototype uses a MySQL database and a PHP application server for content and authentication. Depending on configuration, they may process technical data as processors or independent providers.
Before production, hosting regions, data-processing terms, subprocessors and safeguards for transfers outside the European Economic Area must be checked.
05
Retention and security
Account data remains available while the account is active or as needed to handle deletion. Technical logs follow configured provider retention periods and should not be kept longer than necessary.
The project uses encrypted connections, access controls, content authorisation rules and separation of public and admin areas. No system is risk-free, and safeguards must be reviewed before public release.
06
Your choices and rights
You may request access, correction, deletion, restriction, objection or portability where applicable, and withdraw consent without affecting earlier processing.
- use the data controller’s contact, which will be provided before any real use of the portal, with enough information to identify the account
- you may lodge a complaint with the Italian Data Protection Authority
- you may deny location access in the browser and still browse the map without positioning