Last updated: 20 July 2026
1. About this website
The website Heritage Links, available at https://heritage-links.hsh.it, is a digital information and WEB-GIS platform developed within the HERITAGE LINKS – Cross Border World Heritage Itineraries project, co-funded under the Interreg VI-A Greece–Italy 2021–2027 Programme.
The platform provides an interactive cultural-route map, information about cultural and historical places, visitor resources, accessibility information and content supporting sustainable tourism, with particular reference to Corfu and Zagori.
2. Data Controller
The Data Controller is:
[FULL LEGAL NAME OF THE ORGANISATION]
Registered office: [FULL ADDRESS]
Email: [PRIVACY EMAIL]
Certified email/PEC: [PEC, IF APPLICABLE]
Telephone: [TELEPHONE, IF APPLICABLE]
Data Protection Officer, where appointed:
[NAME OR OFFICE OF THE DPO]
Email: [DPO EMAIL]
3. Personal data processed
Browsing and technical data
When users access the website, the systems supporting the service may automatically process technical information such as:
- IP address;
- date and time of access;
- requested pages and resources;
- browser and device information;
- operating system;
- referral address;
- response status and technical error data;
- security and server logs.
These data are normally necessary to deliver the website and WEB-GIS, maintain security, diagnose technical problems and prevent misuse.
Data voluntarily provided by users
The website may process personal data voluntarily submitted by users when they:
- contact the project by email;
- submit a contact or feedback form;
- request information;
- register for an event or project activity;
- send communications to project partners.
Depending on the request, these data may include name, surname, email address, organisation, telephone number and the information included in the message.
Users should not submit special categories of personal data unless strictly necessary and expressly requested.
Interactive map data
The WEB-GIS may process technical information generated through interaction with the map, such as selected layers, filters, displayed locations and map configuration.
Unless a specific function states otherwise, map interactions are not intended to identify individual users or create behavioural profiles.
Geolocation
The platform may offer functions that use the location provided by the user’s browser or device.
Precise geolocation will be accessed only after the user has actively authorised it through the browser or operating-system settings. The user can withdraw this authorisation at any time through the device settings.
4. Purposes and legal bases
Personal data may be processed for the following purposes:
Operation of the website and WEB-GIS
Data are processed to deliver pages, map resources and digital services requested by the user, as well as to ensure technical operation, availability and security.
Legal basis: [performance of a task carried out in the public interest under Article 6(1)(e) GDPR / legitimate interest under Article 6(1)(f) GDPR — SELECT THE CORRECT BASIS].
Responding to requests
Contact information is processed to answer questions, provide information and manage communications submitted by users.
Legal basis: Article 6(1)(b), 6(1)(e) or 6(1)(f) GDPR, depending on the nature of the request and the status of the Data Controller.
Project events and activities
Where users voluntarily register for events, workshops or other project initiatives, their data are processed to manage participation and organisational communications.
The applicable legal basis will be specified in the information notice presented with the relevant registration form.
Optional communications and newsletters
Promotional communications or newsletters will be sent only where the user has given specific consent. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Cookies and similar technologies
The website may use technical cookies and comparable technologies necessary for navigation, security, language preferences and the operation of the WEB-GIS.
Technical cookies do not require consent, although users must still receive appropriate information. Any profiling, advertising or non-exempt analytics technologies must remain disabled until the user has provided consent through an appropriate consent-management mechanism.
A detailed list of cookies and external services will be provided in the separate Cookie Policy or in the cookie-preference panel.
6. Recipients and service providers
Personal data may be accessed, where necessary, by:
- authorised personnel of the Data Controller;
- project partners involved in the relevant request or activity;
- website hosting providers;
- technical maintenance and cybersecurity providers;
- WEB-GIS, mapping, tile, geocoding or infrastructure providers;
- suppliers appointed to support events or project communications;
- public authorities where disclosure is required by law.
External suppliers processing personal data on behalf of the Data Controller will be appointed as processors where required by Article 28 GDPR.
The current technical service provider is:
[NAME OF THE TECHNICAL PROVIDER, ROLE AND CONTACT INFORMATION]
7. External map and media services
The interactive map may request cartographic resources from external providers. When external map, video, social-media or embedded-content services are activated, the provider may receive technical connection information, including the user’s IP address.
The final version of this section must list each provider actually used by the website, its purpose and a link to its privacy information.
8. Transfers outside the European Economic Area
Personal data are not transferred outside the European Economic Area unless this is necessary because of a service provider used by the website.
Where a transfer takes place, it will be based on an adequacy decision, appropriate safeguards or another transfer mechanism permitted by the GDPR.
9. Data retention
Personal data are retained only for the period necessary for the relevant purpose.
Indicatively:
- server and security logs: [NUMBER OF DAYS];
- contact requests: [FOR EXAMPLE, 12 MONTHS] after completion of the request;
- event registrations: for the period necessary to manage and document the event and fulfil applicable administrative obligations;
- consent records: for the period necessary to demonstrate compliance;
- data required for legal claims or statutory obligations: for the period required by applicable law.
After the applicable period, the data will be deleted or anonymised.
10. Data security
Appropriate technical and organisational measures are adopted to protect personal data against unauthorised access, accidental loss, alteration, disclosure or destruction.
Access to administrative and technical systems is restricted to authorised personnel and service providers according to their respective responsibilities.
11. Rights of data subjects
Under the GDPR, data subjects may request, where applicable:
- access to their personal data;
- rectification of inaccurate data;
- erasure of data;
- restriction of processing;
- data portability;
- objection to processing;
- withdrawal of consent at any time.
Requests may be sent to [PRIVACY EMAIL].
Data subjects also have the right to lodge a complaint with the competent supervisory authority, including the Italian Data Protection Authority where applicable. The exercise of GDPR rights is generally free of charge, subject to the limited exceptions established by the Regulation.
12. Third-party websites
The website may contain links to websites managed by project partners, public institutions, cultural organisations or external services.
The Data Controller is not responsible for the privacy practices of independent third-party websites. Users should consult the privacy information provided by each external website.
13. Changes to this Privacy Policy
This Privacy Policy may be updated following changes to the platform, the WEB-GIS, the services used or applicable legislation.
The current version and its last-update date will always be published on this page.
