Privacy Policy
PRIVACY POLICY – SICILY RUN CARD
Last Updated: December 2025
1. DATA CONTROLLER AND DATA PROTECTION OFFICER (DPO)
The Data Controller is Sicily Run Card, with registered office at 8 Fawn Drive, Aldershot, GU12 4FW, United Kingdom - Email: card@sicilyrun.it. The Data Protection Officer (DPO) is Mr. Maurizio Vinciguerra, who can be reached for privacy-related matters at the registered office address or via the email address provided above.
2. TYPES OF DATA COLLECTED
Through our website and App, we collect:
Identity Data: First name, last name, date, and place of birth.
Contact Data: Email address, phone number, residential address.
Usage Data: Travel preferences, browsing data, and geolocation (optional and subject to explicit consent on your device).
3. PURPOSES AND LEGAL BASES
We process your data for the following reasons:
Card Issuance (Basis: Contract): To manage your registration, issue the discount card, and send technical or operational communications.
Legal Obligations (Basis: Legal Obligation): To comply with tax, civil, and insurance regulations.
Promotion and Profiling (Basis: Consent): To send newsletters, conduct profiling activities based on travel preferences, and transfer data to selected third-party partners (Hotels, Museums, Restaurants) for their independent marketing communications.
4. THIRD-PARTY AND INTERNATIONAL TRANSFERS
Personal data may be shared with technical service providers (IT, hosting) and, only with your explicit consent, with selected commercial partners. As our registered office is in the United Kingdom, data processing is carried out in accordance with the UK GDPR and EU Regulation 2016/679 (GDPR), ensuring the same high standards of protection for users residing in the European Economic Area (EEA).
5. SECURITY AND RETENTION
Data is protected using SSL encryption technology. Data related to card management is retained for 10 years (as per legal requirements). Data processed for promotional and profiling purposes will be retained until you withdraw your consent or request its deletion.
6. YOUR RIGHTS (ART. 15-22 GDPR / UK GDPR)
As a data subject, you have the right to:
Access your data and receive a copy of it.
Request the rectification or erasure of your data ("right to be forgotten").
Withdraw your consent at any time.
Object to direct marketing and profiling.
Lodge a complaint with the ICO (Information Commissioner’s Office) in the UK or the Garante per la Protezione dei Dati Personali in Italy.