San GeminiUmbria
IT|EN|DE
Legal

Privacy Policy

Independent travel portal visitsangemini.com, pursuant to Regulation (EU) 2016/679 (GDPR), Italian Legislative Decree 196/2003 (Privacy Code) and the Italian Data Protection Authority's resolution of 10 June 2021 (cookies).

Last updated: 4 September 2026
This website is an independent, unofficial travel portal with no connection to the Municipality of San Gemini, the Carsulae archaeological park, the Terme di San Gemini and their managing companies, present and future, or the Sangemini brand. This notice describes how the personal data of visitors and partner businesses is managed.
Courtesy translation: this document is provided in English for convenience. In the event of any discrepancy, the Italian version shall prevail.

Contents

  1. Data Controller
  2. Types of data collected
  3. Purposes of processing
  4. Legal basis of the processing
  5. Cookies and tracking
  6. Recipients of the data
  7. Transfers outside the EU
  8. Data retention
  9. Data subject rights
  10. Protection of minors
  11. Data breaches
  12. Changes to this notice
  13. Detail by data category

1. Data Controller

Pursuant to Article 13 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 ("Privacy Code"), this notice describes how the personal data of users who visit the website visitsangemini.com and use the Horizon Studio publishing platform, together with its related services (subscriptions for local businesses, content publishing, public author page), is processed.

Data Controller:
Made by West · Dylan Succi
VAT number: 04229770369
Registered office: Via Verica 150, 41026 Pavullo n/F (MO), Italy
Email: support@visitsangemini.com
Website: visitsangemini.com

For any question regarding this notice or the processing of your personal data, you can contact the Controller at the details indicated. The Controller has not appointed a Data Protection Officer, as it does not fall within the mandatory cases provided for by Article 37 GDPR.

2. Types of data collected

2.1 Data provided or configured by the user

  • Account data: email address, name and country, automatically received from the payment provider Creem upon activation of a plan (see sec. 2.4), as well as the password chosen by the user during the guided procedure, stored in encrypted form.
  • Business data: business name, categories (up to 5), website, social profiles, contacts (phone/WhatsApp, optional), avatar, cover image, bio, business address (optional, see sec. 2.3).
  • Billing data: VAT number, tax code, billing address and payment details, processed by the provider Creem in its capacity as Merchant of Record. Payment details (card, e-wallet) are never stored on this website.
  • Generated content: articles, posts, services and offers published through the platform, uploaded images, PDF documents attached to content, configuration of your author page (blocks, colours, fonts, call-to-action). Upload limits for images and documents are shown during the upload procedure.
  • Email contacts: name, email, subject and message sent voluntarily to support@visitsangemini.com. The data is delivered directly to the Controller's inbox, without passing through third-party services or third-party cookies.

2.2 Data collected automatically

  • Navigation data: IP address, browser type, operating system, device type, pages visited, referrer, processed in server logs exclusively for technical operation and security.
  • View counter: the count of views of articles and author pages is automatic. Major crawlers are excluded via the User-Agent, which is read in memory and never stored.
  • Likes: the state of article likes is stored locally in the browser (localStorage) solely to prevent multiple likes from the same device. No personal data is transmitted to external servers for this feature.
  • Technical cookies: exclusively technical cookies of WordPress and the platform (see sec. 5).
  • Usage statistics: measured with a self-hosted instance of Umami, an open-source cookieless platform: aggregate and anonymous data, anonymised IP addresses, no cookies, no sharing with third parties for advertising purposes (see sec. 5.3).
  • Content indexing: published content is publicly accessible and, as such, may be indexed by search engines, web crawlers and artificial intelligence agents according to the normal dynamics of the web.

2.3 Public profile and business directory

  • Visibility in the directory ("page visible to everyone"): the appearance of your page in the public business directory is opt-in and off by default. On first activation, explicit consent is requested and acceptance is recorded with date and time, which is also shown back to the user ("visible since…"). Consent can be withdrawn at any time from your member area. Legal basis: consent (Art. 6(1)(a) GDPR).
  • Business address (optional): if filled in, it is shown on the public page with a "Directions" button that opens Google Maps. Opening the map is a user-initiated action: address/coordinates and IP address are sent to Google's servers (see sec. 6). The feature does not use the device's GPS or geolocation.
  • Acceptance of the Terms: on first opening the platform you are asked to accept the Terms and Conditions; acceptance is recorded with date and time and kept for the life of the account (legal basis: performance of the contract, Art. 6(1)(b)).

2.4 Data received from the payment provider (Creem)

  • Sole source of third-party data: the data necessary to create and manage the account (such as, where applicable, email address, name, country, plan subscribed, status, subscription renewals and cancellations, and subscription identifier) is automatically received via the Creem (Merchant of Record) APIs within the purchase process initiated by the user. No other personal data is received from third parties.

3. Purposes of the processing

3.1 Contractual and service provision purposes

  • Provision of the service: business subscription, author page/landing page, publication of articles, services and offers;
  • User account management and authentication;
  • Management of subscriptions and payments through the provider Creem;
  • Technical support and customer assistance;
  • Handling of contact requests sent voluntarily by email;
  • Service communications and notices (changes to the Terms, maintenance, service status, platform announcements) via banner in the dashboard and, where necessary, email. These communications are operational in nature and not commercial.

3.2 Purposes based on legitimate interest

  • Technical operation and security of the website: prevention of unauthorised access, abuse and fraud;
  • Aggregate and anonymous usage statistics (Umami);
  • Establishment or defence of legal rights in court.

3.3 Marketing purposes (with consent)

  • Possible sending of newsletters and promotional communications, only with express consent, withdrawable at any time.

3.4 Nature of provision

Providing data for the purposes referred to in point 3.1 is necessary in order to use the service: refusal makes it impossible to activate the subscription and the business page. Provision of data for marketing purposes is optional.

4. Legal basis of the processing

The processing of personal data is based on the following legal bases pursuant to Article 6 GDPR:

  • Art. 6(1)(a) · Consent: visibility in the public directory (opt-in) and any marketing purposes;
  • Art. 6(1)(b) · Performance of the contract: provision of the service, management of the account, the subscription and the published content;
  • Art. 6(1)(c) · Legal obligation: tax and accounting obligations and those required by law;
  • Art. 6(1)(f) · Legitimate interest: technical operation and security of the website, aggregate and anonymous statistics, prevention of fraud and abuse, establishment or defence of legal rights.

4.1 Automated decision-making and profiling (Art. 22 GDPR)

The Controller declares that the platform does not use fully automated decision-making processes, including profiling, that produce legal effects or significantly affect users, within the meaning of Article 22 GDPR.

5. Cookies and tracking

No banners, no tracking. This website does not use profiling cookies, third-party analytics cookies, advertising cookies or social pixels, and therefore no prior consent is required and no banner is shown. Only the technical cookies described below are set; statistical measurement is entrusted to a self-hosted instance of Umami, cookieless and anonymous analytics.

5.1 Technical cookies (necessary)

The website is hosted on WordPress: only technical cookies are used, essential to its operation and not disableable. They do not require consent pursuant to Article 122 of the Privacy Code.

TypePurposeRetentionConsent
Session and authenticationMaintaining the login session (WordPress / Horizon Studio) and CSRF protection.SessionNot required
Security and preferencesTechnical platform features and storage of interface preferences.Session / localNot required

5.2 Absence of tracking cookies

The website does not use third-party analytics cookies, marketing, advertising or remarketing cookies (including Google Ads, conversion tags), or social media pixels (Facebook, Instagram or similar). No targeted advertising based on browsing is carried out. Should tools subject to consent be activated in the future, this page will be updated and consent will be requested in advance using methods compliant with the law, including any consent banner.

5.3 Statistics: self-hosted Umami (cookieless)

The website's statistics are entrusted to a self-hosted instance of Umami, an open-source web analytics platform managed directly by the Controller on its own servers within the European Union: it uses no cookies or persistent identifiers, collects no personal data, does not track users across sites and does not share data with third parties for advertising purposes. It collects only aggregate and anonymous statistical data (pages visited, traffic source, browser, country) and anonymises IP addresses. Since no cookies or tracking technologies are used and the data cannot be linked to identified or identifiable persons, statistical analysis does not require prior consent under Article 122 of the Privacy Code. More information: umami.is.

5.4 Technical features without tracking

  • Likes: state stored only in the user's browser (localStorage);
  • View counter: crawler exclusion read in memory, without storing the User-Agent;
  • Login security: after 5 failed attempts, access is blocked for 10 minutes per username, without tracking the IP address; honeypot anti-bot protection; direct access to wp-login.php and xmlrpc.php blocked;
  • Comments and pingbacks disabled across the whole site, to protect visitors' privacy.

5.5 Google Fonts and images

All typefaces used by the portal and the platform (public website, login page included, and fonts selectable by businesses for their own page) are loaded from Google Fonts: the HTTP request may include the user's IP address in Google's server logs. Notice: Google Privacy Policy. The portal's images are local files hosted directly on the visitsangemini.com domain; full attributions are available on the Image credits page.

5.6 Managing cookies through your browser

You can block or delete cookies directly from your browser settings:

  • Chrome: Chrome cookie management
  • Firefox: Firefox cookie management
  • Safari: Safari cookie management
  • Edge: Edge cookie management

Legal references

  • Regulation (EU) 2016/679 (GDPR), in particular Article 13;
  • Legislative Decree of 30 June 2003, no. 196 (Personal Data Protection Code);
  • Resolution of the Italian Data Protection Authority of 10 June 2021, "Guidelines on cookies and other tracking devices".

6. Recipients of the data

Personal data may be processed, to the extent necessary for the service, by the following recipients:

  • Euronodes (hosting): hosting provider with servers located in the European Union, acting as processor pursuant to Article 28 GDPR. Data Processing Agreement: Euronodes GDPR Agreement;
  • Creem (payments and subscriptions): Merchant of Record handling online payments, subscriptions and invoices, PCI-DSS compliant and legally responsible for international VAT and sales tax management. Payment data is processed directly by Creem as an independent controller and is not stored on this website; through the Creem APIs the platform receives the data necessary to manage the account and subscription (sec. 2.4);
  • Google LLC: font loading (Google Fonts); for businesses that fill in their address, the "Directions" action opens Google Maps, sending coordinates and IP address;
  • Umami: the website's anonymous and aggregate statistics are processed through a self-hosted instance of Umami on the Controller's infrastructure (EU servers): this is not a communication to a third party and no cookies are used nor personal data collected (sec. 5.3);
  • Consultants and professionals: accountants, lawyers and tax consultants, to the extent necessary for their respective engagements;
  • Public authorities: where required by law or by orders of the competent authorities.

The complete and up-to-date list of processors is available on request by contacting the Controller. A Data Processing Agreement pursuant to Article 28 GDPR has been entered into with each processor (or, for platform services, accepted). Data is never sold or transferred to third parties for marketing purposes.

7. Transfers of data outside the EU

The servers used to host the website are located within the European Union: personal data is not transferred outside the EU for the main processing. For third-party services possibly located outside the EU (e.g. Google Fonts/Maps, Creem), transfers take place in compliance with the safeguards provided by Articles 44–49 GDPR, including adequacy decisions and Standard Contractual Clauses (SCCs).

8. Data retention

  • Contractual, accounting and tax data (invoices, billing data, receipts): for 10 years where required by law; these documents are managed mainly by Creem as Merchant of Record;
  • Subscription data received from Creem (plan, status, renewals and cancellations, identifier; sec. 2.4): for the life of the account;
  • Navigation and log data: for a maximum of 14 months, as provided for by the Italian Data Protection Authority's resolution of 8 May 2014;
  • Support requests and contacts: for the time necessary to handle them and in any case no later than 24 months after closure of the case;
  • Marketing data: until consent is withdrawn;
  • Consent records (Terms, directory visibility): for the life of the account.

Account and content after subscription expiry

From cancellation or expiry of the subscription, the platform and all its features become completely inaccessible and the content (articles, images, page settings) is retained for a maximum of 30 days:

  • Renewal within 30 days: the deletion process is automatically cancelled and the account returns fully active, with all content restored;
  • After 30 days without an active subscription: account and content are permanently and irreversibly deleted. From that moment there is nothing left to restore: any new subscription starts from scratch, with no way to recover previous content.

We therefore recommend saving a copy of your content before expiry. At the end of the retention periods, data is deleted or irreversibly anonymised, unless otherwise provided by law.

9. Data subject rights

Pursuant to Articles 15–22 GDPR, data subjects have the right to exercise the following rights against the Controller:

9.1 Right of access (Art. 15)

The data subject has the right to obtain confirmation as to whether personal data concerning them is being processed and, if so, access to that personal data and the information relating to the processing. Profile data can be viewed directly from the member area.

9.2 Right to rectification (Art. 16)

The data subject has the right to obtain the rectification of inaccurate personal data and the completion of incomplete data; profile and business data can be amended independently from the member area.

9.3 Right to erasure (Art. 17)

The data subject has the right to obtain erasure of data in the cases provided for by law. Account deletion occurs by cancelling or letting the subscription lapse, with definitive elimination after the 30-day grace period (sec. 8); early deletion can be requested by writing to the Controller.

9.4 Right to restriction of processing (Art. 18)

The data subject has the right to obtain restriction of processing in the cases provided for by law.

9.5 Right to data portability (Art. 20)

The data subject has the right to receive the personal data concerning them in a structured, commonly used and machine-readable format, and to transmit it to another controller without hindrance.

9.6 Right to object (Art. 21)

The data subject has the right to object at any time to processing based on legitimate interest, unless compelling legitimate grounds overriding the interests, rights and freedoms of the data subject exist.

9.7 Right to withdraw consent (Art. 7)

The data subject may withdraw consent at any time (for example for directory visibility or marketing purposes) without affecting the lawfulness of processing based on consent prior to its withdrawal.

9.8 Right to lodge a complaint (Art. 77)

The data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali): Piazza Venezia 11, 00187 Rome, Italy · garante@gpdp.it · www.garanteprivacy.it.

9.9 How to exercise your rights (in practice)

  • Access and rectification: directly from the profile settings in the member area;
  • Erasure: cancellation or expiry of the subscription, with deletion after the 30-day grace period (sec. 8), or an early request to the Controller;
  • Portability, restriction and objection: by writing to support@visitsangemini.com.

The Controller replies within 30 days of receiving the request, extendable by a further 60 in particularly complex cases, with appropriate notice to the data subject.

10. Protection of minors

The publishing service and subscriptions are reserved for adults (18+). The Controller does not knowingly collect personal data of children under 16; should it become aware of such data, it will promptly delete it. If you are a parent or guardian and believe a minor has provided personal data without consent, write to support@visitsangemini.com.

11. Notification in the event of a data breach

In accordance with Articles 33 and 34 GDPR, in the event of a breach of personal data likely to present a risk to the rights and freedoms of data subjects, the Controller undertakes to notify the breach to the Italian Data Protection Authority within 72 hours of becoming aware of it, to communicate it to the data subjects without undue delay where the risk is high, and to document every breach (facts, effects, corrective actions). The Controller has adopted appropriate technical and organisational measures to prevent breaches and minimise the impact of any incidents.

12. Changes to this notice

This notice may be updated to reflect regulatory, technological or organisational changes. Changes take effect upon publication on this page, with the date of the last update indicated; material changes will be communicated to the users concerned via a notice in the platform or by email.

13. Detail of processing by data category

The following table summarises the categories of data processed, with their purposes, legal bases and retention periods.

Data categoryPurposeLegal basis (Art. 6 GDPR)Retention
Authentication and security: email, password (stored in encrypted form), acceptance of the Terms and directory consent recorded with date and timeAuthentication, account management, securityContract and legitimate interest (lett. b and f); consent for the directory (lett. a)Life of the account; deletion within 30 days of closure
Subscription (received from Creem): plan, status, renewals and cancellations, subscription identifier; email, name and country where applicable (sec. 2.4)Creation and management of the account and subscriptionContract (lett. b)Life of the account
Profile and business data: business name, categories, website, social, optional contacts (phone/WhatsApp), avatar, cover image, bio, optional address with "Directions" button (sec. 2.3)Public author page and business presentationContract (lett. b)Life of the account; can be amended or deleted at any time from the member area
Generated content: articles, posts, services, offers, uploaded images, attached PDF documents, author page configuration (blocks, colours, fonts, call-to-action)Publishing and managing content through the platformContract (lett. b)Life of the account and up to a maximum of 30 days after closure, then irreversible deletion; can be deleted at any time
Navigation and log data: IP address, browser, operating system, pages visitedTechnical operation and securityLegitimate interest (lett. f)Maximum 14 months
Access security: failed login attempts monitored per account, without IP address trackingPrevention of unauthorised accessLegitimate interest (lett. f)Counters reset at the end of the temporary block
San GeminiIndependent travel portal

An independent guide to the village of waters, Cesi and Carsulae. For local businesses, a subscription SaaS platform: landing pages, web editor, 13 languages.

Explore

  • The Waters
  • What to see
  • Carsulae
  • History
  • Events
  • For businesses

Contact

  • support@visitsangemini.com

This is an independent, unofficial travel portal, not affiliated with the Municipality of San Gemini, the Carsulae archaeological park, the Terme di San Gemini and their managing companies, present and future, the Sangemini brand or any of the bodies and operators mentioned: every reference is purely informative and implies no partnership or commercial relationship, unless explicitly stated. The portal neither manages nor sells spa, spring or park services. Trademarks belong to their respective owners. Opening hours and dates may vary: please check official sources.

© visitsangemini.com · VAT no. IT04229770369 · 41026 Pavullo n/F (MO), ItalyPrivacy Policy · Terms and Conditions · Refund Policy · Image creditsPayments by CreemPowered by Made by West · Made in Verica
Vai al contenuto principale