Privacy

Information on the processing of personal data pursuant to art. 13 of EU Regulation 2016/679

Costa Edutainment SpA hereby informs you of the processing of your personal data provided during registration on this website (hereinafter referred to as "the Site") and during the subsequent purchase, receipt, and use of the products and services marketed through it. This processing of your personal data may also occur using computerized and electronic means.

Data Controller
The Data Controller of your personal data is the company Costa Edutainment SpA , with registered office in 47839 Riccione (RN), via Ascoli Piceno n.6, Fiscal Code / VAT number 03362540100, in the person of its legal representative pro tempore (hereinafter for brevity referred to as “the Data Controller” or “the Company”).

Contact details of the Data Protection Officer (DPO)
The Data Protection Officer appointed by the Company can be reached at the email address: dpo@costaedutainment.com or by regular mail by writing to the administrative headquarters of the same in Genoa, Area Porto Antico – Ponte Spinola Ambrogio sn GE, for the attention of the same.

Categories of data subject to processing
The Data Controller will process, by way of example and not limited to, the following categories of personal data provided by you during registration on the Site, during the purchase of products and services, and during order processing and provision of the purchased services:
• personal data (e.g. name, surname, date of birth, tax code, residential address);
• contact details (e.g. telephone number, email address);
• access credentials to the personal area created following registration on the Site (e.g. username and password);
• data relating to the products or services purchased;
• data relating to the payment system used;
• data acquired by the Data Controller during the execution of the product purchase contract;
• data acquired by the Data Controller during the provision of the purchased service;
• the result of your profiling based on your purchase history, where you have given your consent to such processing.

Purpose of data processing
Your personal data will be processed by the Data Controller for the following purposes:
1) to allow you to register on the Site and use the services associated with registration, such as a personal space where you can monitor your orders and purchases, express your satisfaction with the services offered by the Data Controller, and access the provision of additional services offered by the same;
2) to allow you to proceed with the purchase of products and services offered by the Data Controller through the Site;
3) to allow the Data Controller to manage any claims that may occur to you while using the services, or any complaints you may have;
4) to allow the Data Controller to send you communications on activities and promotions relating to services or products that are the same or similar to those already used and/or relating to offers or promotions related to them, limited to the use, for this purpose, of the personal data represented by your email address provided by you during the conclusion of the contract;
5) to send you, with your prior consent, commercial information, including by newsletter, relating to products and/or services offered by the Data Controller, also using contact details other than your email address (e.g., mobile phone number, home or residential address);
6) for profiling and/or market analysis purposes, so that the Data Controller can create, with your consent, a profile of you to send you commercial communications selected based on your preferences, or other behavioral aspects of yours, as emerged from the profiling activity;
7) so that the Data Controller may disclose your personal data to third parties, with your consent, so that they can send you commercial information regarding their products or services. The third parties to whom your data may be disclosed are companies controlled, affiliated, or in which the Data Controller has a stake, or other third-party companies operating in the entertainment sector, which promotes quality leisure time, combining culture, science, education, entertainment, and nature;
8) so that the Data Controller can send you a "reminder" communication to inform you of the imminent cancellation of your account and the data you have saved through it, a circumstance that will require you to register again to access the related services;
9) so that the Data Controller can protect his rights both in and out of court;
10) to allow the Data Controller to fulfill the legal obligations to which he is subject.

Legal basis for processing
The legal basis for the processing of your personal data for the purposes referred to in point 1) above is the execution of the Site registration contract.
The legal basis for processing your personal data for the purposes referred to in point 2) above is the performance of the contract for the purchase of goods or services or the implementation of pre-contractual measures adopted at your request.
The legal basis for the processing of your personal data for the purposes referred to in point 3) above is the Data Controller's legitimate interest in managing any claims that may arise during the use of the service, or any complaints related to the products or services it markets. If managing the claim involves the processing of your sensitive data (e.g., health data), the legal basis will be the Data Controller's need to ascertain, exercise, or defend legal claims.
The legal basis for the processing of your personal data for the purposes referred to in point 4) above is the provisions of Article 130, paragraph 4, of Legislative Decree 196/2003 and subsequent amendments and additions.
The legal basis for the processing of your personal data for the purposes referred to in points 5), 6), and 7) above is your consent. Providing consent for these purposes is optional, meaning that failure to provide it will in no way limit your registration on the Site, the purchase of products and services, or your use of them. Please note that failure to provide the required consent, or its subsequent revocation, will prevent the Data Controller from carrying out the processing activities for which such consent is requested.
The legal basis for the processing of your personal data for the purposes referred to in point 8) above is the Data Controller's legitimate interest in ensuring that the account on which the loyalty relationship with the user is based is not deleted, balanced with the user's interest in continuing to use the related services without having to re-register and in not losing the data previously saved through their account, an interest deemed to prevail over the consequent restriction of their rights that such processing entails.
The legal basis for the processing of your personal data for the purposes referred to in point 9) above is the Data Controller's legitimate interest in protecting its rights, both in and out of court, in the event of any contractual breaches by you or damages caused by you to the Data Controller's assets or to third parties. If the Data Controller's protection of its rights involves the processing of your sensitive data (e.g., health data), the legal basis will be the Data Controller's need to ascertain, exercise, or defend its rights in court.
The legal basis for the processing of your personal data for the purposes referred to in point 10) above is the Data Controller's need to comply with legal obligations to which it is subject.

Consequences of failure to provide data
Providing your personal data is necessary to enable your registration on the Site and to subsequently purchase the Data Controller's products and services through the Site. Failure to provide your personal data will prevent you from registering on the site and subsequently purchasing the Data Controller's products or services.

Data retention period
Your personal data processed for the purposes referred to in point 1) will be retained for the entire duration of your registration on the Site. Please note that, in any case, after 6 years from your last purchase on your account, it will be automatically deactivated, resulting in the deletion of your account and any associated data. Before the expiration of the effective deletion period, you will be sent a reminder to keep your registration on the Site active.
Your personal data processed for the purposes referred to in point 2) will be retained for the entire duration of the purchase process for the goods and services and, subsequently, until the order or service has been fully processed.
Your personal data processed for the purposes referred to in point 3) will be retained for the entire duration of the claim or complaint management and until its resolution.
Your personal data processed for the purposes referred to in points 4), 5), 6), 7), and 8) will be retained for the entire duration of your registration on the Site, unless you expressly request the deletion of your data, which you can exercise at any time according to the methods set out in the section of this notice dedicated to the exercise of your rights.
Please note that, in any case, after 6 years from your last purchase, your account will be automatically deactivated, resulting in the deletion of the account itself and any data associated with it.
Your personal data processed for the purposes referred to in point 9), and in particular data relating to the stipulation and execution of contracts with the Data Controller, will be retained for 10 years from the stipulation of the relevant contract. After this period, they may be retained further if necessary for ongoing legal proceedings.
Your personal data processed for the purposes referred to in point 10) will be retained for the entire duration necessary for the Data Controller to fulfill its legal obligations (e.g., 10 years for data contained in accounting documentation).

Data recipients
Your personal data may be disclosed to third-party companies that offer or manage, on behalf of the Data Controller, support services for the online sales of the Data Controller's products or services.
Your personal data may be disclosed, with your consent, to other third parties so that they can send you commercial information regarding their products or services. The third parties to whom your personal data may be disclosed are affiliated, affiliated, and/or controlled companies of the Data Controller, third-party companies operating in the entertainment sector aimed at promoting quality leisure time, combining culture, science, education, entertainment, and nature, as well as companies controlled or affiliated by the Data Controller.
Your personal data may also be disclosed to other third parties, such as lawyers, consultants, and insurance companies.
Third-party companies that offer or manage, on behalf of the Data Controller, services related to the management of the website, registration on the same, and companies providing CRM or similar applications may have access to your personal data, limited to these purposes and subject to their appointment as data processors, pursuant to Article 28 of EU Regulation 2016/679.
The list of data controllers, which by its nature is subject to change, may be requested from the Data Controller at any time by writing to privacy@costaedutainment.com .
Company employees, designated as data processors, may also have access to your personal data if their duties require it. Each data processor is specifically identified, authorized, and trained, and acts on the basis of specific instructions provided by the Company regarding the purposes and methods of processing, and the security measures to be adopted to protect personal data.

Image acquisition for souvenir photos
Interested parties are advised that, in order to purchase a souvenir photo of their visit to the facility managed by the Data Controller, photos may be taken, which they will subsequently be offered for purchase. Image acquisition is automatic and, therefore, necessarily involves all individuals accessing the facility.
The souvenir photos in question will under no circumstances be published and/or distributed. The legal basis for processing the images is the Data Controller's legitimate interest in selling the souvenir photos, balanced with the visitor's interest in purchasing them as a memento of their experience, given the limited impact of such processing on their rights and freedoms. This impact is mitigated by not disseminating or displaying the images and by retaining them for a limited period of time, as indicated below.
The acquired images will be kept for 24 hours from their acquisition in order to allow the user to proceed with their purchase if interested.
Souvenir photos may be purchased in analog format with immediate delivery to the facility. In this case, the images will be kept only for the aforementioned period.
Souvenir photos can also be purchased in digital format. In this case, the user will be given a code to enter in a dedicated area of the Data Controller's website where they can download them. To ensure the photos are available to the user for an adequate period of time, allowing them to download them, the images will be retained for 30 days from their acquisition.

Only those responsible for managing the photography service offered by the Data Controller and those responsible for selling the photos will have access to the images. Each data processor is specifically identified, authorized, and trained, and acts on the basis of specific instructions provided by the Company regarding the purposes and methods of processing, and the security measures to be adopted to protect personal data.



Rights of the interested party
You, as the data subject, have the right, pursuant to Article 15 et seq. of EU Regulation 2016/679, and within the limits prescribed therein, to:
• obtain data and information on the processing, in particular in relation to the type of personal data processed, the purposes for which the personal data are processed, the period of processing and the subjects to whom the data are communicated ( so-called right of access );
• obtain the rectification or integration of inaccurate personal data concerning you ( so-called right of rectification );
• obtain the erasure of your personal data in the following cases: (i) the personal data are no longer necessary for the purposes for which they were collected; (ii) you have withdrawn your consent to the processing of your personal data, if they are processed on the basis of such consent; (iii) you have objected to the processing of your personal data if they are not processed for a legitimate interest of the Data Controller; (iv) the processing of your personal data is unlawful. However, the retention of your personal data by the Data Controller is lawful if it is necessary to allow the Data Controller to comply with a legal obligation or to ascertain, exercise or defend a right in court ( so-called right to erasure );
• obtain that the personal data concerning you are only stored without any other use being made of them in the following cases: (i) you contest the accuracy of the personal data, for the period necessary to allow the Data Controller to verify the accuracy of such personal data; (ii) the processing of personal data is unlawful and you oppose, in any case, the erasure of personal data by the Data Controller; (iii) the personal data are necessary for the establishment, exercise or defence of a right in court; (iv) you have objected to the processing and are awaiting verification as to whether the legitimate reasons of the Data Controller for the processing prevail over yours ( so-called right to limitation );
• object at any time to the processing of data and in particular to the processing of data processed for direct marketing purposes, including in relation to services identical to those already provided by the Data Controller, and for profiling purposes ( so-called right to object );
• receive, in a commonly used, machine-readable and interoperable format, the personal data concerning you, if they are processed pursuant to a contract or on the basis of your consent, and/or transmit the data to another data controller, if feasible ( so-called right to portability ).
• withdraw consent at any time to the processing for which it is required. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
• ask the Data Controller at any time not to send you any more commercial information relating to services that are the same or similar to those already used and/or relating to offers or promotions relating to them (so-called “soft spam” pursuant to Art. 130 paragraph 4 of Legislative Decree 30 June 2003, no. 196).
The aforementioned rights may be exercised upon your request to this effect, to be sent to the dedicated email address privacy@costaedutainment.com or by writing by regular mail to the company Costa Edutainment SpA , at the company's administrative headquarters in Genoa, Area Porto Antico – Ponte Spinola Ambrogio sn GE.

Right to complain
If you believe that the processing of your personal data by the Data Controller violates the provisions of EU Regulation 2016/679, you have the right to lodge a complaint with the Office of the Italian Data Protection Authority (by email to garante@gpdp.it, or by post to the Italian Data Protection Authority, located in Rome, Italy, at Piazza Venezia 11 Scala B, CAP 00187), pursuant to Article 77 of EU Regulation 2016/679, or to take legal action pursuant to Article 79 of EU Regulation 2016/679.

Welcome to the world of Costa Edutainment
  • © Italia in Miniatura - CF/P.IVA 03362540100 - REA: GE-337946