GENERAL CONDITIONS OF USE PRIVACY POLICY
This privacy policy (or "privacy policy") is made in compliance with current legislation on the protection of personal data and, in particular, pursuant to Articles 13 and 14 of EU Regulation 2016/679 ("GDPR") with reference to the processing of personal data collected or otherwise processed through the site https://www.rome4runners.it/ ("Website" or "Site"). The Site is managed by Roma Appia Run (for company data see par. 1). This notice contains important information about the personal data that are processed through this Website, as a registered or unregistered user, and describes the ways in which these data are used. This document contains important information on the following
DATA CONTROLLER
PURPOSE OF THE PROCESSING
NATURE OF THE DATA CONTRIBUTION AND CONSEQUENCES OF ANY REFUSAL
TYPES OF DATA PROCESSED/SPECIFIC PROCESSING
DATA RETENTION PERIOD
RECIPIENTS/CATEGORIES OF RECIPIENTS OF PERSONAL DATA
Rights of data subjects
RIGHT OF REVOCATION AND OPPOSITION
Protection of children's privacy
MODALITY OF PROCESSING AND SECURITY AND CONFIDENTIALITY OF PERSONAL DATA
UPDATES OF THIS INFORMATION-COMMUNICATIONS
DATA CONTROLLER
For the purposes of this Privacy Policy and the data processing described here, it is specified that the data will be processed by Appia Run with registered office in Rome, Via Ostiense 106, p.iva? email info@appiarun.it, as an independent controller (as defined in Reg. (EU) 2016/679 ('GDPR')) of the data collected, Appia Run, hereinafter, also referred to as 'Owner'. For any comments or questions about this Privacy Policy and to speak with the local reference person in charge of handling requests related to data processing, you can also contact customer service at the email address respectively?
PURPOSE OF THE PROCESSING
Following the consultation of this Site and the use of one or more services related to it, data concerning identified or identifiable natural persons may be processed. Any personal data acquired—always in compliance with applicable regulations—will be processed solely for the following purposes: purposes connected with and instrumental to accessing and using the Site, its features, the requested services, and the services provided by the Data Controller, as well as, more generally, to browsing the Site itself; activities related to the organization, management, and documentation of sporting events indicated, advertised, and organized—including via the Website—as well as, more generally, operational and management needs of the Data Controller regarding the services and/or products offered through the Site, including direct marketing activities; fulfilling obligations established by law and applicable regulations; where expressly requested, providing the newsletter service and carrying out promotional and advertising activities for the Data Controller and/or third parties; responding to user requests and communications; in the case of data collected during registration for and use of any restricted areas of the Site, for: (i) registration for and management of restricted areas, (ii) purposes indicated in any data collection form, and (iii) sending commercial information, newsletters, special offers, and promotional material from the entities specifically indicated in the consent collection form, where necessary; and any other purpose indicated in specific notices provided at the time of collecting any additional data. Subject to the provision of explicit and optional consent where required, data collected for the purposes referred to in letters (a), (b), and (f) will also be processed for direct marketing purposes by the Data Controller, specifically for sending informational, commercial, or advertising material regarding the services and/or products offered by them.
I dati saranno trattati in modo lecito e secondo correttezza ed utilizzati solo per le finalità di cui alle lettere precedenti. Il trattamento avverrà mediante strumenti idonei a garantire la sicurezza e la riservatezza dei dati personali e potrà essere effettuato con strumenti cartacei e/o mediante strumenti automatizzati ed informatizzati atti a memorizzare, gestire e trasmettere i dati stessi.
NATURE OF THE DATA CONTRIBUTION AND CONSEQUENCES OF ANY REFUSAL
The provision of personal data is optional in nature. However, we remind you that failure to provide such data may not allow for proper navigation of the Site and the provision of any services or information requested. The provision of the additional personal data set out in the request forms to solicit the sending of information materials or other communications is optional. Failure to provide them could result in the inability to process requests and thus obtain information. It should be noted that, in any case, if the processing of your data is based on consent, this can be revoked at any time, as better specified below.
TYPES OF DATA PROCESSED/SPECIFIC PROCESSING and LEGAL BASIS OF PROCESSING
Depending on the service rendered, personal data of different types may be processed, as specified in this article.
4.1. Navigation data
The computer systems and software procedures used to operate this Site acquire, during their normal operation, certain personal data whose transmission is implicit in the use of web communication protocols. This information is not collected to be associated with identified individuals; however, by its very nature, it could—through processing and association with data held by third parties—allow users to be identified. This category of data includes IP addresses or domain names of the computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server's response, and other parameters regarding the user's operating system and computing environment. The aforementioned data are used solely to obtain anonymous statistical information on site usage and to check its proper functioning; they are deleted immediately after processing. The data could be used to ascertain liability in the event of hypothetical cybercrimes against the site; barring this possibility, web contact data do not currently persist for more than seven days. Access logs, which record user IP addresses directly on the servers, are retained for 12 months. The legal basis for processing such data lies in the necessity of providing the browsing service to the user. Should such data be used for profiling purposes, the legal basis for processing will be consent. Regarding cookies, please refer to the cookie policy.
4.2.1. Data provided voluntarily by the user (communications
The optional, explicit, and voluntary sending of communications via contact forms on the site or via email to the addresses listed on this Site entails the subsequent acquisition of the data provided by the sender—including their email address—in order to receive any responses to their requests. Personal data provided in this manner is used solely to fulfill or respond to the submitted requests and is disclosed to third parties only when necessary for that purpose. Specific notices regarding particular requested services will be provided on the relevant pages of the site. The legal basis for processing such data lies in the necessity to fulfill a user request or to implement pre-contractual measures taken at the user's request (Art. 6, paragraph 1, letter b) of the GDPR), or in the Data Controller's legitimate interest in handling user requests or promoting their business activities (Art. 6, paragraph 1, letter f) of the GDPR).
4.2.2. Data provided voluntarily by the user (to receive communications for marketing and/or commercial promotion purposes
Data subjects may voluntarily provide their personal data to the Data Controller to receive commercial or promotional communications—however designated—via digital or paper channels, whether originating from the Data Controller or third parties. The legal basis for such processing is consent, pursuant to Art. 6(1)(a) of the GDPR. In any event, every communication reminds the data subject that they may withdraw their consent at any time and without formality. Data is deleted upon the data subject's request, unless otherwise required by law. Solely in cases where an email address is provided by the data subject in the context of the sale of a product or service, that address may be used for the direct marketing of similar products or services—pursuant to EU Regulation 2016/679 (GDPR) and Legislative Decree 196/2003 (Personal Data Protection Code)—without the need for prior, express consent. In such instances, the legal basis for processing is the Data Controller’s legitimate interest, pursuant to Art. 6(1)(f) of the GDPR.
4.2.3. Data provided voluntarily by the user (to receive newsletters
The Owner's newsletter is sent by e-mail to those who subscribe to the newsletter. The legal basis for the processing will be found in the need to provide the service requested by users, as well as the Owner's legitimate interest in responding to its users' requests, pursuant to Article 6, paragraph 1, letters a) and f) GDPR. To stop receiving the newsletter, simply select the cancellation link at the end of each email. Cancellation is handled automatically, so you may receive additional newsletters that were scheduled to be sent before receiving the cancellation request, within a maximum of 72 hours.
4.2.4 Data voluntarily provided by the user (registration data to restricted areas of the Site and data provided in the context of sporting events organised by the Owner and sponsored and managed also through the Site
Registration data (required for signing up for any restricted areas of the Site) will be used for: (i) registration for and management of the restricted areas; (ii) the purposes indicated in any data collection form; and (iii) sending commercial information, newsletters, special offers, and promotional material by the parties specifically indicated in the consent collection form, where applicable. The legal basis for processing data required for registration in any restricted areas of the Site lies in the necessity of providing the service requested by users or taking pre-contractual measures at their request (Art. 6, paragraph 1, letter b) of the GDPR), or in the Data Controller’s legitimate interest in promoting its business (Art. 6, paragraph 1, letter f) of the GDPR). Data provided in connection with sporting events organized by the Data Controller—and sponsored and managed via the Website as well—including any images, will be used for: (i) registration, organization, management, and documentation of user participation in said events; (ii) the purposes indicated in any data collection form; and (iii) sending information and newsletters regarding similar events by the parties specifically indicated in the consent collection form, where applicable. The legal basis for processing lies in the necessity of performing the contract/providing the service requested by users or taking pre-contractual measures at their request (Art. 6, paragraph 1, letter b) of the GDPR), or in the Data Controller’s legitimate interest in promoting its business (Art. 6, paragraph 1, letter f) of the GDPR). Finally, the legal basis for processing any other data will be indicated on a case-by-case basis in the specific privacy notice.
4.3.1. Cookie
The Site uses technologies such as cookies to collect information relating to users' use of the Site. It should be noted that consent to the use of these technologies and the related data processing is optional, but it should be noted that if consent is not given, navigation and access problems to all or parts of the Site or limitations regarding its full functionality could arise. For more information and details about this, visit the Cookies Policy section.
Retention period
Except as expressly indicated in paragraph 4 above, the data conferred will be kept for the time strictly necessary to follow up the activities for which they were collected and, in any case, for the times prescribed by the applicable legal or regulatory rules and in any case for the time necessary to ensure the exercise of the Data Controller's rights.
CATEGORIES OF RECIPIENTS OF PERSONAL DATA
For the purposes indicated in Art. 2 of this document, data may be disclosed to third parties whose collaboration Appia Run may and/or must utilize to provide the services in question. Such third parties will act as external data processors pursuant to Art. 28 of the GDPR and will process the data for the same purposes set out in Art. 2 of this document. Please note that some entities to whom data may be disclosed may also act as independent data controllers, subject to the provision of an appropriate Privacy Policy pursuant to Art. 14 of the GDPR, unless otherwise provided by law. Data collected for the aforementioned purposes may also be disclosed to companies affiliated with or belonging to the same corporate group as the Data Controller, and to entities authorized to receive such data under statutory or European regulatory provisions, including in countries outside the European Union (e.g., Switzerland). In such cases, the Data Controller guarantees that the disclosure will take place in compliance with GDPR provisions. With specific regard to Switzerland, please note that the European Commission, via Decision No. 2000/518/EC of 26 July 2000, has recognized that the country ensures an adequate level of personal data protection. A list of the entities to whom the Data Controller discloses personal data collected for the aforementioned purposes is available to data subjects upon request submitted in writing to the Data Controller.
Rights of data subjects
The "data subject" is the identified or identifiable natural person to whom the personal data being processed relates. Please be advised that, as a data subject, you have the right to access the data concerning you and processed by the Data Controller at any time (right of access) in order to verify its accuracy and the lawfulness of the processing. You may also exercise all rights granted by applicable national and European personal data protection legislation, specifically under Articles 15 et seq. of EU Regulation 2016/679 (and subsequent amendments and additions). In particular, you may at any time request access to, correction of, or updates to incorrect or inaccurate data, as well as the restriction of processing or the deletion of such data (right to be forgotten) should any of the grounds set out in Article 17 of the GDPR apply. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) at the following address: Piazza Monte Citorio 121, Rome; email: garante@gdpr.it; telephone: 06.69677; or by fax to 06696773785. Finally, regarding personal data processed by automated means, you have the right to receive the data concerning you in a structured, commonly used format and, where applicable, to transmit that data to another data controller (right to data portability). To enable Appia Run to serve the user effectively, users are encouraged to regularly verify and update their personal data. Registered users may access and modify their personal data via their account settings on the Website; otherwise, they may contact us for assistance in updating their personal data. Any request regarding the processing of personal data and any communication concerning the exercise of your rights may be addressed by sending an email to: ? or by mail to: ?
RIGHT OF REVOCATION AND OPPOSITION
Each interested party shall also be granted the right to withdraw the consent given at any time, without prejudice to the lawfulness of the processing carried out by the Holder prior to such withdrawal as well as the possibility for the Holder to continue processing based on other legal bases of the processing. The data subject is also always granted the possibility of opposing the processing of data concerning him or her if it is carried out for direct marketing purposes as referred to in Article 2, letter b; in this case, his or her data will no longer be processed for such purposes (right to object).
Protection of children's privacy
This Website is aimed at a general public, however its services are intended for persons aged 14 years and over. Appia Run does not deliberately request, collect, use and disclose personal data provided by persons under the age of 14. If Appia Run learns that it has collected data from a child under 14, it will delete it. In the event that the user is not of the required age, please do not register and ask an adult (that is, your parents or guardian) to perform the necessary procedures. It should be noted that pursuant to Article 2-quinquies of Legislative Decree 196/2003, where Article 6, paragraph 1, letter a) applies, with regard to the direct provision of information services to minors, the processing of the minor's personal data is lawful where the minor is at least 14 years old.
MODALITY OF PROCESSING AND SECURITY AND CONFIDENTIALITY OF PERSONAL DATA
The processing of collected data will be carried out in compliance with the principles set forth in Article 5 of the GDPR. Processing for the identified purposes will be performed using both digital and manual methods—utilizing electronic tools or paper records—based on logic aligned with the purposes for which the data was collected, and in accordance with the confidentiality and security rules established by the GDPR and relevant national implementing regulations. In any event, pursuant to Article 32 of the GDPR, the Data Controller has adopted appropriate security measures to prevent risks associated with data processing, such as data destruction, loss, illicit use, or unauthorized access. Specifically, Appia Run has implemented suitable measures to protect the user's personal data against accidental loss and unauthorized access, use, modification, or disclosure. The management of this Website involves the use of password controls, firewall technology, and other technological and procedural security measures. Although Appia Run has implemented the aforementioned security measures for the Website, users should be aware that 100% security cannot be guaranteed. Therefore, users provide their personal data at their own risk; to the fullest extent permitted by applicable law, Infront shall not be held liable in any way for data disclosure resulting from errors, omissions, or unauthorized actions by third parties during or after transmission. Appia Run recommends that users periodically update software designed to protect data transmission over networks (e.g., antivirus software) and verify that their electronic communication service provider has adopted appropriate measures for secure network data transmission (e.g., firewalls and spam filters); keep their account username and password confidential and not share them with anyone; and change their password periodically. In the unlikely event that Appia Run determines that the security of the user's personal data in its possession or under its control has been, or may have been, compromised, the Data Controller will inform the user of the incident in accordance with applicable law and using the methods prescribed therein (by providing their email address to Appia Run, the user consents to receiving such communications in electronic format via that email address).
UPDATES TO THIS NOTICE - COMMUNICATIONS
Appia Run reserves the right, at its sole discretion, to change, modify, add, or remove portions of this Privacy Policy at any time by publishing the revised version on this page of the Website and updating the “Last modified” date indicated below. It is the user’s responsibility to review the Privacy Policy periodically to stay informed of any changes made. In certain cases, Appia Run may provide additional notifications regarding significant changes to this Privacy Policy by posting a notice on the Website’s homepage or, for registered users, by sending a notification email or posting a notice on their account page. By accepting the revised Privacy Policy—whether by clicking the “accept” button in such a notification email or in the notice posted on the account page (where required to comply with applicable regulations), or by using or submitting information to the Website after the revised Privacy Policy has been published—the user agrees to the revised Privacy Policy. Following any changes, and where required by applicable law, the user’s data will not be processed without the user’s explicit consent.
Google Chrome
Mozilla Firefox
Safari (Per gestire le impostazioni del browser clicca su “Aiuto” dal menù di Safari.”)





