Privacy Notice
Contact Forms and Participation in B.I.S.A. – La Biagiola International School of Archaeology
This notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”) to individuals who contact Associazione “Cultura e Territorio” and to applicants to B.I.S.A. – La Biagiola International School of Archaeology.
Last updated: September 25, 2026
1. Data Controller
The data controller is:
Associazione “Cultura e Territorio” (ACT)
Italian tax code: 97687910014
Registered office: Via Baretti 25, 10125 Turin, Italy
Email: presidente@culturaterritorio.org
Website: https://www.culturaterritorio.org
Within the Association, full access to personal data is limited to its President and legal representative.
Questions about the processing of personal data or requests to exercise GDPR rights may be sent to presidente@culturaterritorio.org.
2. Personal Data We Process
2.1 Contact Form
The contact form may collect:
- first and last name;
- email address;
- message topic and subject;
- message contents;
- any other information voluntarily provided by the user.
Users should not include health information or other particularly sensitive information unless it is strictly necessary.
2.2 B.I.S.A. Applications
The following information may be collected to evaluate an application:
- completed application form;
- first and last name and contact information;
- curriculum vitae;
- information about the applicant’s education, experience, and language skills;
- motivations and academic interests;
- requested session or module;
- organizational or dietary requirements;
- other information voluntarily provided by the applicant.
2.3 Documents Required After Acceptance
Accepted applicants may be required to provide:
- proof of tetanus vaccination;
- a certificate of physical fitness for the planned activities;
- proof of any required insurance coverage, for which evidence that the premium has been paid is sufficient;
- information needed to arrange accommodations, meals, local transportation, and activities;
- administrative and payment information relating to participation.
Applicants must declare that they possess a passport or other document valid for entry into and residence in Italy when required based on their nationality. ACT does not collect or retain copies of passports or other identity documents. Participants must present their documents directly to their accommodations provider for the provider’s own legal requirements.
3. Purposes and Legal Bases for Processing
3.1 Contact Requests
Information submitted through the contact form is used exclusively to read and answer the request and, when necessary, continue the related correspondence.
The legal basis is taking steps at the request of the data subject or, for general inquiries, ACT’s legitimate interest in responding to communications it receives.
3.2 Application Review
Information contained in the application form and curriculum vitae is used exclusively to:
- evaluate the application;
- determine whether the applicant’s background is compatible with the training activities;
- communicate acceptance or denial;
- request any necessary additional information.
The legal basis is taking pre-contractual steps at the applicant’s request.
3.3 Organization of Participation
If an applicant is accepted, personal data is used exclusively to:
- organize archaeological and educational activities;
- arrange accommodations, meals, and local transportation;
- communicate with the participant;
- administer enrollment and payments;
- prepare and send the final certificate;
- comply with applicable administrative, accounting, and tax obligations.
The legal bases are performance of the participant’s agreement with ACT and compliance with ACT’s legal obligations.
3.4 Health-Related Information
Proof of tetanus vaccination, the certificate of physical fitness, and any information concerning allergies, dietary requirements, or conditions relevant to participant safety constitute health-related information under Article 9 of the GDPR.
This information is processed exclusively to:
- verify that participation requirements have been met;
- conduct activities safely;
- make any necessary arrangements;
- respond appropriately in an emergency.
The legal basis is the data subject’s explicit consent under Article 9(2)(a) of the GDPR.
ACT does not request medical records, detailed diagnoses, or health information beyond what is strictly necessary.
3.5 Retention of the Final Certificate
ACT retains a copy of the final certificate in its internal records to document the training it has provided.
The legal basis is the Association’s legitimate interest in maintaining its institutional records. Retention of a copy does not create an obligation for ACT to issue a replacement certificate at a later date.
4. Required and Optional Information
Information identified as mandatory is necessary to receive a response, submit an application, or participate in B.I.S.A.
Failure to provide required ordinary personal data may make it impossible to evaluate the application or organize participation.
Health-related information is processed on the basis of explicit consent. Without that consent, ACT cannot process the documents needed to verify participation requirements, and completion of admission may therefore be impossible.
5. Processing Methods and Access
Personal data is processed primarily in electronic form in accordance with the principles of lawfulness, fairness, transparency, data minimization, storage limitation, and confidentiality.
Within ACT, full access to the documentation is limited to the President and legal representative.
Staff members involved in the Field School may receive only the information strictly necessary to perform their duties or protect participant safety. They are not given the original documentation.
Health-related documentation is stored separately from other personal data or is otherwise subject to specifically restricted access.
ACT does not sell, disclose, or use personal data for commercial, advertising, profiling, or other purposes unrelated to the Field School.
6. Recipients and Technical Service Providers
Personal data may be technically processed by service providers needed to operate:
- the website and its hosting;
- online forms;
- email services;
- any storage and backup systems;
- administrative and accounting services.
When required, these providers act as data processors under Article 28 of the GDPR and may not use the data for their own purposes.
Personal data may also be disclosed, only to the extent strictly necessary, to:
- administrative, tax, or legal advisors;
- insurance companies when necessary;
- medical or emergency services;
- public authorities when required by law.
Personal data is not disseminated or made publicly available.
7. International Data Transfers
ACT does not directly transfer personal data outside the European Economic Area.
If a technical service provider processes data in a third country, the transfer must comply with Articles 44 and following of the GDPR and be based on an adequacy decision by the European Commission, Standard Contractual Clauses, or another safeguard recognized under applicable law.
8. Retention Periods
ACT retains personal data only for as long as necessary for the purposes for which it was collected.
In particular:
- data relating to denied or withdrawn applications is deleted promptly after the decision or withdrawal has been communicated;
- proof of vaccination, the physical fitness certificate, insurance documentation, and any other health-related information are deleted at the end of the session and, in all cases, within fifteen days;
- the application form, curriculum vitae, contact information, and other organizational data are deleted after the final certificate has been prepared and sent and, in all cases, within thirty days after it is sent;
- email messages containing participant documentation are deleted within the same periods;
- a copy of the final certificate is retained in ACT’s internal records for ten years from its date of issue;
- receipts, payment records, and administrative, accounting, and tax documentation are retained for the period required by law, normally ten years;
- contact form requests are deleted when the correspondence has ended and, in all cases, within six months after the last message.
Personal data may be retained longer only when necessary to comply with a legal obligation, address an accident or insurance claim, or establish, exercise, or defend the rights of the Association or the data subject.
9. Photographs and Video
This Privacy Notice does not authorize ACT to use identifiable photographs, video, or audio recordings of participants for promotional or communications purposes.
Any use of a participant’s image or voice will be covered by a separate release. Consent to promotional use is optional, and refusal does not affect participation in B.I.S.A.
10. No Marketing or Automated Decision-Making
Personal data is not used to:
- send advertising or commercial communications;
- automatically subscribe individuals to newsletters;
- conduct profiling;
- make decisions based solely on automated processing;
- provide names or contact information to other organizations.
Applications are evaluated directly by the individuals responsible for the Field School.
11. Data Subject Rights
Where provided by the GDPR, data subjects may request:
- confirmation that their personal data is being processed;
- access to and a copy of their data;
- correction of inaccurate data;
- deletion of their data;
- restriction of processing;
- objection to processing based on legitimate interests;
- data portability;
- withdrawal of consent to the processing of health-related information.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. If health-related documentation is necessary to complete admission, withdrawal may make participation impossible.
Requests may be sent to:
presidente@culturaterritorio.org
Data subjects also have the right to file a complaint with the Garante per la protezione dei dati personali, the Italian Data Protection Authority, as explained at https://www.garanteprivacy.it.
12. Cookies and Browsing Data
Information about cookies and other technologies used by the website is provided in the separate Cookie Policy.
13. Updates
This Privacy Notice may be updated following organizational, technical, or legal changes. The current version is the version published on the website with its most recent revision date.
