minus
minus
minus
plus

Privacy Policy

Last updated: June, 2026

This Privacy Policy describes how RAMA Travel

collects, uses, and shares the personal data of users who use the website https://newtuscany.com (hereinafter the “Service”).

Table of Contents
plus
minus
By using the Service, the user accepts the practices described in this Privacy Notice. If you do not wish to consent, please do not use the Service.NOTICE PURSUANT TO ARTICLES 13 AND 14 OF EU REGULATION 679/2016 AND THE PRIVACY CODE AS AMENDED BY LEGISLATIVE DECREE 101/2018

INTRODUCTION

With this notice, drawn up pursuant to Article 13 of EU Regulation No. 679/2016 (hereinafter, the “Regulation” or “GDPR“), R.A.M.A. S.p.A. (hereinafter also referred to as the “Data Controller” or “Company“), as Data Controller, provides you with the following information regarding the processing of your personal data (hereinafter the “Data“) carried out when browsing the Company’s Website.

DATA CONTROLLER AND DPO

The Data Controller is R.A.M.A. S.p.A., with registered office at Via Trieste 4, 58100 Grosseto (GR), VAT No. 00081900532.Contact details: a) Tel. 0564 080510, b) Certified email (PEC): segreteria@pec.griforama.it.The Data Protection Officer (DPO) can be contacted by data subjects for all matters relating to the processing of personal data and the exercise of the rights granted under applicable law, at the following address: dpo@rama1913.it.

CATEGORIES OF DATA PROCESSED

For the purposes indicated below, the following categories of Data may be processed:
  • common or “identification” data, such as, by way of example: first name, last name, residential address, contact details: email and telephone, IP address, tax data, billing data, identity document number, payment data.

PURPOSES AND LEGAL BASIS OF PROCESSING

Your Data may be processed for the purposes listed below:

Purpose of processing

Legal basis for processing

a.

Browsing of the Website, obtaining anonymous statistical information on its use, as well as monitoring its proper functioning and identifying any malfunctions and/or abuses.

Legitimate interest of the Data Controller (Art. 6(1)(f) GDPR).

c.

Managing your contact request.

Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).

d.

Establishing, exercising or defending a right of the Data Controller.

Legitimate interest of the Data Controller (Art. 6(1)(f) GDPR).

e.

Sending Newsletter communications.

Consent (Art. 6(1)(a) GDPR).

f.

Profiling.

Consent (Art. 6(1)(a) GDPR).

g.

Management of quizzes and lead generation.

Consent (Art. 6(1)(a) GDPR).

h.

Sale and management of travel packages.

Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).

i.

Compliance with the legal obligations to which the Data Controller is subject.

Compliance with legal obligations (Art. 6(1)(c) GDPR).

With regard to cookies, please refer to the specific Cookie Policy available in the dedicated section of the Website.

MANDATORY OR OPTIONAL NATURE OF DATA PROVISION

The provision of personal data is optional, but necessary in order to browse the Data Controller’s Website, to perform the contract and to fulfil your contact request; any refusal will result in the impossibility of providing the requested services.Once personal data has been provided for the purposes set out above, processing is also carried out in order to comply with the regulatory obligations to which the Data Controller is subject.The provision of Data solely for the purposes referred to in points e), f) and g) of par. 4 is also optional, but in this case, failure to provide it does not affect the establishment and/or continuation of the contractual relationship.For these purposes, consent may be withdrawn at any time by contacting the Data Controller at the contact details indicated above. Withdrawal of consent does not affect the lawfulness of processing based on consent given before its withdrawal.

METHODS OF PROCESSING AND COMMUNICATION OF DATA TO THE CONTROLLER

The Data will be processed in accordance with the regulations referred to above, using electronic and manual tools, ensuring the use of adequate organizational and technical measures.The Company adopts adequate and preventive organizational and technical security measures aimed at safeguarding the confidentiality, integrity, completeness and availability of the data subject’s personal data.Technical, logistical and organizational measures are put in place with the aim of preventing damage, including accidental loss, alteration, improper and unauthorized use of the data processed.

RECIPIENTS OF THE DATA

The following categories of parties may have access to personal data:
  1. Within the Data Controller’s organizational structure, within the limits and in accordance with the methods of their respective duties and exclusively where necessary to pursue the purposes indicated above, persons identified as Designated Persons for processing pursuant to Art. 2-quaterdecies of Legislative Decree 196/2003, i.e. persons authorized to process data pursuant to Art. 29 GDPR. Such persons act on the basis of specific instructions provided by the Data Controller in order to process your personal data securely;
  2. Parties identified as Data Processors pursuant to Art. 28 GDPR, who carry out personal data processing on behalf of the Data Controller in relation to specific purposes. Such parties act on the basis of a specific contract aimed at ensuring secure processing of your personal data (e.g. suppliers of products and services).
The Data is also transmitted to parties acting as Independent Data Controllers (e.g. payment platform managers).You may request the complete list of such parties by contacting the Data Controller at the contact details indicated in this notice.

TRANSFER OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA (EEA)

The Data Controller does not transfer your personal data to countries outside the EEA.Should any third parties be based in, or use Cloud services located in, countries outside the European Union, please be informed that such countries offer an adequate level of data protection, as established by specific decisions of the European Commission.The transfer of personal data to third parties resident or located in countries outside the European Union that do not ensure adequate levels of protection will only be carried out with the consent of the data subject or following the conclusion, between the Data Controller and such parties, of specific agreements containing safeguard clauses and appropriate guarantees for the protection of personal data, known as “standard contractual clauses”, also approved by the European Commission, or where the transfer is necessary for the conclusion and performance of the contract between the Data Controller and the data subject or for the management of their requests.

DATA RETENTION PERIOD

Personal data will be retained for the time necessary to pursue the purposes indicated above, in compliance with applicable law.In particular, for administrative, accounting, tax and contractual purposes, the Data will be retained for a period of 10 years from the end of the contractual relationship.Personal data processed for the purposes referred to in points e) and g) of par. 4 will be retained for a period of 24 months from the giving of consent, unless consent is renewed or deletion is requested.Personal data processed for the purposes referred to in point f) of par. 4 will be retained for a period of 12 months from the giving of consent, unless consent is renewed or deletion is requested.Once the above retention period has elapsed, the data will be deleted or anonymized, unless further retention is required by legal obligations or is necessary to protect the rights of the Data Controller.

RIGHTS OF THE DATA SUBJECT

Pursuant to Articles 15-22 of the Regulation, the data subject has the right to exercise the following rights in relation to the personal data covered by this notice, as provided for and guaranteed by the Regulation:
    1. Right of access and rectification (Articles 15 and 16 GDPR): you have the right to access your personal data and to request that it be corrected, modified or supplemented. If you so wish, we will provide a copy of the data we hold about you.
    2. Right to erasure of data (Art. 17 GDPR): in the cases provided for by applicable law, you may request the deletion of your personal data. Once your request has been received and reviewed, we will cease processing and delete your personal data, where the request is found to be legitimate.
    3. Right to restriction of processing (Art. 18 GDPR): you have the right to request the restriction of the processing of your personal data in the event of unlawful processing or contestation of the accuracy of the personal data by the data subject.
    4. Right to data portability (Art. 20 GDPR): you have the right to request to obtain, from the Data Controller, your personal data in order to transmit it to another data controller, in the cases provided for by the referenced article.
    5. Right to object (Art. 21 GDPR): you have the right to object at any time to the processing of your personal data carried out on the basis of our legitimate interest, explaining to us the reasons justifying your request; before granting it, the Data Controller will need to assess the reasons for your request.
    6. Right to lodge a complaint (Art. 77 GDPR): you have the right to lodge a complaint with the competent Data Protection Authority if you believe that a violation of your rights in relation to the processing of your personal data has occurred or is occurring.
    7. Right to withdraw consent given (Art. 7 GDPR): for personal data processing based exclusively on your consent, you have the right to withdraw your consent at any time by contacting the Data Controller. Withdrawal of consent does not affect the lawfulness of processing based on consent given before its withdrawal.
To exercise these rights, the data subject may contact the Company at the contact details indicated above.

CHANGES TO THIS NOTICE

This privacy notice may be subject to changes and additions over time, as necessary due to new regulatory developments concerning the protection of personal data, or to changes/developments in the Data Controller’s operations.In such cases, the Data Controller undertakes to provide you with the updated notice.