Your data, no mysteries

Privacy policy

What information the portal uses, why it is needed and which choices always remain in your hands.

Minimal data
Account, preferences and technical information required by the service.
GPS is not stored
If allowed, location is used only to guide you on the map.
No advertising
The prototype does not install advertising profiling tools.

Last updated: 16 July 2026

This is a demonstration portal and not the official Bioparco di Roma website. Before a real launch, the controller, providers, retention periods and contacts must be verified and completed.

01

Who processes data and scope

This notice covers Bioparco Roma Interactive, a demonstration project for planning a park visit. It does not represent Bioparco di Roma and does not replace notices on the official website or external ticketing services.

The prototype lists no contact address: the portal is an independent concept, not operated by Fondazione Bioparco di Roma. Before production, the actual controller’s identity, address and contacts—and any data protection officer—must be provided.

02

Data that may be processed

We collect only what is needed for accounts, preferences and requested features.

  • email, nickname and technical account identifiers; passwords are hashed and cannot be read by portal administrators
  • language preference, session settings and content saved to a profile
  • technical logs, IP address, device type and security information produced by hosting and authentication
  • device location only when permitted for the map: it is used during the session and not saved in the portal database

03

Why data is used

Data is used to create and protect accounts, maintain sessions, remember language, provide requested features and prevent abuse or unauthorised access.

  • performance of the requested service and pre-contract steps for registration, login and profile
  • legitimate interests in security, error diagnosis and service continuity
  • consent, where required, for optional features such as device location
  • compliance with legal obligations or competent authority requests

04

Providers and transfers

The prototype uses a MySQL database and a PHP application server for content and authentication. Depending on configuration, they may process technical data as processors or independent providers.

Before production, hosting regions, data-processing terms, subprocessors and safeguards for transfers outside the European Economic Area must be checked.

05

Retention and security

Account data remains available while the account is active or as needed to handle deletion. Technical logs follow configured provider retention periods and should not be kept longer than necessary.

The project uses encrypted connections, access controls, content authorisation rules and separation of public and admin areas. No system is risk-free, and safeguards must be reviewed before public release.

06

Your choices and rights

You may request access, correction, deletion, restriction, objection or portability where applicable, and withdraw consent without affecting earlier processing.

  • use the data controller’s contact, which will be provided before any real use of the portal, with enough information to identify the account
  • you may lodge a complaint with the Italian Data Protection Authority
  • you may deny location access in the browser and still browse the map without positioning