INFORMATION ON THE PROTECTION OF PERSONAL DATA PURSUANT TO EUROPEAN REGULATION 679/16
Azienda Veneziana della Mobilità S.p.A. (hereinafter AVM) manages and provides the urban public transport service of the municipalities of Venice and Chioggia, the extra-urban transport service of the southern-central area of the metropolitan city of Venice, as well as the private and integrated mobility services of the municipality of Venice (car parks, car parks, bike sharing, docks, etc.).
It is the parent company of the AVM Group and controls the companies ACTV s.p.a. and Ve.La. s.p.a.
To provide these services, AVM issues the customer with travel tickets or other forms of ticketing, also through the website www.avmspa.it, www. www.actv.it, www.veneziaunica.it and the AVM Venezia Official App.
AVM is, therefore, the data controller of the personal data collected.
HOW WE COLLECT YOUR PERSONAL DATA
AVM collects and processes your personal data in the following circumstances:
• if you purchase any of the services provided, by entering into a contract with AVM;
• if you register on the website to use its features;
• if you contact us to request information, make a complaint or report, request a refund regarding the services provided;
• if you agree to be contacted for marketing purposes or market research, surveys and statistical purposes;
• if other companies of the AVM Group or business partners lawfully disclose their personal data to AVM.
Please help us keep your personal information up to date by informing us of any changes. Any changes in the personal residence data must be promptly communicated to AVM to avoid problems regarding the use of the services provided.
WHAT PERSONAL DATA CONCERNING HIM MAY BE COLLECTED
The following categories of personal data concerning you may be collected:
Personal and contact information - information about your name, place and date of birth, tax code, address, telephone number, place of work, email address and, if you connect to our sites or app, through social login (i.e. a social account you have registered with), also information that is visible in that social according to the privacy settings you have set.
Use of the Website - Information about how you use the Website, open or forward our communications, including information collected through cookies (you can find our Cookies Policy)
Data collected through RFID technology - information regarding ticketing and validation of travel tickets, if you have signed a contract for the Venezia Unica card and the local public transport service.
FOR WHAT PURPOSES YOUR PERSONAL DATA MAY BE USED
The processing of personal data by European data protection legislation must be subject to one of the various legal requirements, and we are obliged to indicate these requirements for each processing operation described, as you can read below:
a) Establishment and execution of contractual relations and consequent obligations, including communication regarding services
AVM may process your personal data to establish and execute contractual relationships, providing the services requested and responding to reports and complaints.
AVM may also use its contact details, and in particular, its email address, to provide you with information relating to the service, informing you when circumstances arise that may modify the service itself or compromise its correct and efficient performance (e.g. tidal conditions, strikes...).
Prerequisite for treatment: fulfilment of contractual obligations.
The provision of data is required to manage the contractual relationship.
b) Operational management and purposes strictly connected to it for accessing the Site, in particular, the reserved areas thereof.
AVM collects your personal data in order to allow you to access the site and provide you with the services available therein, also by accessing your Personal Area in order to: (i) download from your Personal Area documents relating to the services you have purchased (for example, tax receipts); (ii) process other requests made through the website.
Prerequisite for treatment: fulfilment of contractual obligations.
The provision of data is required to respond to your requests.
c) Customer Satisfaction Surveys
AVM may use its contact data to conduct institutional surveys aimed at measuring the level of customer satisfaction with the service provided.
A precondition for processing: legitimate interest
With this activity, the owner complies with the contractual obligations assumed under the service contract in force with the awarding body and carries out all useful activities to improve, implement and make more efficient the service itself.
(d) Marketing to meet your needs and to provide you with promotional offers
AVM collects its contact data for marketing and advertising communication purposes, aimed at informing you about sales promotional initiatives, carried out through automated means of contact (e-mail, SMS and other massive messaging tools, etc.) and traditional methods of contact (such as telephone calls with operators).
Prerequisite for treatment: consent is required.
Consent may be revoked at any time through the privacy form on the website.
(e) Compliance with legally binding requirements to comply with legal obligations, regulations or orders of a judicial authority
AVM collects your personal data to comply with the law.
Prerequisites for treatment: legal obligations.
HOW WE KEEP YOUR PERSONAL DATA SAFE
AVM uses a wide range of security measures to improve the protection and maintenance of the security, integrity and accessibility of its personal data.
Although at present, as you know, no one can guarantee the security of data transmission intrusions that occur on the Internet and on websites, we, our suppliers and business partners are committed to ensuring physical, electronic and procedural safeguards to protect your personal data by the law and with the utmost responsibility.
All of your personal information is stored on our secure servers (or secure paper copies), or those of our suppliers or business partners, and is accessible and usable by our security standards and policies (or equivalent standards for our suppliers or business partners).
Let us adopt, among other measures, measures such as:
• the strict restriction of access to your personal data, on a need-to-know basis and for the sole purpose communicated;
• perimeter security systems to prohibit unauthorised access from the outside
• the permanent monitoring of access to information systems to detect and stop the abuse of personal data.
• six-monthly penetration tests
• aimed at highlighting any leaks in perimeter security
• tracking of access to your personal data by internal staff and verification of the purpose
• Transactions on our websites that require your personal data to be entered are encrypted using Secure Socket Layer (SSL) technology
Where we have provided you (or you have chosen) with a password that enables you to access certain parts of our website or other portals, applications or services provided by us, you shall be responsible for the confidentiality of such password and for compliance with any other security procedures that we have notified you of.
Please do not share your password with anyone.
HOW LONG WE RETAIN YOUR INFORMATION
We store your personal data only for the time necessary to achieve the purposes for which it was collected or for any other legitimate purpose related to it. Therefore, if personal data are processed for two different purposes, we will retain those data until the purpose expires with the longer term, but we will no longer process personal data for that purpose for which the retention period has expired. We restrict access to your personal data only to those who need to use it to perform their duties.
Your personal data, which is no longer needed or for which there is no longer a legal basis for its storage, is anonymised irreversibly (and in this way can be stored) or securely destroyed.
Below are the storage times for the different purposes listed above:
Fulfilment of contractual obligations: the data processed to fulfil any contractual obligation may be kept for the entire duration of the contract as well as for the next 10 years (in the case of the Venezia Unica card, for 1 year after expiry of the card), in order to verify any outstanding matters or for compliance with legal obligations (e.g. accounting documentation).
We would point out that, for data collected using RFID technology only (validation of travel tickets), the data is deleted after 24 hours.
Operational management and purposes strictly connected to this for access to the website: the data processed for this purpose may be stored for 1 year following the duration of the underlying contract for which access was made.
Purpose of customer satisfaction surveys: the data processed for this purpose may be kept for 3 years from the date of the survey.
Marketing Purposes: Personal data processed for marketing purposes may be retained for 2 years from the date on which we obtained your last consent for such purposes (except for the opposition to receive further communications).
Disputes: If it is necessary to defend ourselves or to act or also to make claims against you or any third party, we may retain personal data that we reasonably deem necessary to process for such purposes, for as long as such claim can be pursued.
WITH WHOM WE MAY SHARE YOUR PERSONAL INFORMATION
Your personal data may be accessed by employees of AVM, as well as by suppliers and collaborators, duly appointed data processors, who provide support for the provision of services, and by companies in the AVM group (including Actv S.p.A., which carries out the TPL service operationally, and Ve.La. S.p.A. that deals with the marketing of travel tickets and marketing activities).
If you have any questions regarding our processing of your personal data, please use the web form "privacy" in the "contacts" section of the site ww.avmspa.it or contact the telephone number 0412722111, asking the secretariat of the Legal and Corporate Affairs. We would also like to inform you that the Company has appointed an external data protection officer (DPO), whose contact details are email@example.com, to whom you may apply in general for matters relating to the protection of personal data and related rights.
YOUR DATA PROTECTION RIGHTS AND YOUR RIGHT TO LODGE COMPLAINTS WITH THE SUPERVISORY AUTHORITY
• You have the right to ask us under the legal conditions:
• access to your personal data
• the portability of the personal data you have provided us with
• rectification of the data in our possession
• the deletion of any data for which we no longer have any legal basis for processing
• the revocation of his consent, where the processing is based on consent and is related to direct marketing activities
• the limitation of the way in which we process your personal data, in the cases provided for by law.
Also, you may exercise your right to object in the case of data processed for legitimate interest, in particular in the case of customer satisfaction.
The exercise of all these rights is subject to certain exceptions aimed at safeguarding the public interest (e.g. prevention or identification of crimes) and our interests (i.e. legitimate and compelling reasons). If you exercise any of the above rights, it is our responsibility to ensure that you are entitled to exercise them, and we will normally provide you with feedback within one month.
If you are not satisfied with the way in which we process your personal data or with our feedback, you have the right to lodge a complaint with the supervisory authority, the contact details of which can be found on the website www.garanteprivacy.it