Privacy Notice pursuant to Articles 13–14 of Regulation (EU) 2016/679 (“GDPR”)
The data controller is Avora s.r.l., with registered office at Via dei Serragli 3/R, 50124 Florence (FI), Italy, e-mail: info@cuculia.it (the “Controller”).
Purposes and legal bases of processing
Your personal data are processed for the following purposes:
Provision of services
handling information requests;
managing registrations to the website and reserved areas (if any);
managing bookings, purchases, payments and deliveries;
exchanging documents and communications with you.
Legal basis: performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).
Marketing purposes (optional)
sending commercial and promotional communications by e-mail and/or SMS concerning the Controller’s services.
Legal basis: your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Legal obligations and protection of rights
compliance with legal obligations;
management and defence of legal claims.
Legal basis: legal obligation and legitimate interest of the Controller (Art. 6(1)(c) and (f) GDPR).
Use of cookies and other online identifiers
to ensure the proper functioning and security of the website (technical and security cookies);
subject to your consent, to obtain aggregate statistics on the use of the site (third-party analytics cookies).
See the Cookie Policy below for details.
Methods of processing and recipients
Data are processed by electronic and, where necessary, paper means, by personnel expressly authorised by the Controller.
Data may be communicated to third parties that provide services to the Controller (such as IT and hosting providers, website developers and maintainers, consultants, couriers and logistics providers, etc.), acting as processors pursuant to Article 28 GDPR. These subjects may be located in the EU or in countries offering an adequate level of data protection. An updated list of processors is available upon request to the Controller.
Data retention
Data necessary to provide services: kept for the duration of the contractual relationship and for the time required to comply with legal obligations.
Data processed for marketing: kept until the withdrawal of consent or your request for erasure.
Data collected via cookies: kept for the periods indicated in the Cookie Policy below.
Your rights
You may exercise, at any time, the rights provided for in Articles 15–22 GDPR by writing to info@cuculia.it, including:
right of access to your personal data;
rectification or updating of inaccurate or incomplete data;
erasure of data (“right to be forgotten”), where the conditions are met;
restriction of processing;
data portability;
objection to processing based on legitimate interest;
withdrawal of consent for marketing communications.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) if you believe that your rights have been infringed.
Cookie Policy
This website uses:
technical and security cookies: necessary for the correct functioning of the website and to store your cookie preferences;
preference cookies: to remember the language chosen by the user;
third-party analytical cookies (Google Analytics): used, with your consent, to obtain anonymous, aggregated statistics on the use of the site (pages visited, time spent, etc.).
No profiling cookies are used for behavioural advertising based on your browsing history.
What cookies are
Cookies are small text files sent by websites and stored on the user’s device, to be transmitted back to the same sites on the next visit. They allow the website to function correctly, remember user preferences, and provide anonymised statistical information to the site owner.
Types of cookies used on this site
1. Technical and security cookies (necessary)
These cookies are necessary for the operation and security of the site and are installed without your prior consent.
Examples:
PHPSESSID
Type: technical session cookie (first party)
Purpose: maintains the user’s browsing session.
Duration: session.
wordpress_test_cookie
Type: technical (first party)
Purpose: checks whether the browser accepts cookies.
Duration: session.
wordpress_logged_in_*
Type: technical (first party)
Purpose: keeps the user logged in during the session.
Duration: session (or until logout).
wordpress_sec_*
Type: technical / security (first party)
Purpose: improves security of login and user sessions.
Duration: session.
wp-settings-6, wp-settings-time-6
Type: technical (first party)
Purpose: store settings and preferences related to the WordPress user/account (e.g. for registered users / administrators).
Duration: up to 1 year.
wfwaf-authcookie-*
Type: security (first party)
Purpose: used by the site’s security system (e.g. firewall) to verify logged-in users and prevent malicious access.
Duration: typically 1 day or less.
Cookie consent and preference cookies (used by the cookie banner):
CookieLawInfoConsent
cookielawinfo-checkbox-advertisement
cookielawinfo-checkbox-analytics
cookielawinfo-checkbox-functional
cookielawinfo-checkbox-necessary
cookielawinfo-checkbox-non-necessary
cookielawinfo-checkbox-others
cookielawinfo-checkbox-performance
viewed_cookie_policy
moove_gdpr_popup
Type: technical (first party)
Purpose: store the fact that the cookie banner has been shown and your choices regarding the various categories of cookies, so that the banner is not shown again at each visit.
Duration: up to 12 months.
2. Preference cookies
pll_language
Type: preference cookie (first party)
Purpose: stores the language selected by the user to display the website.
Duration: up to 12 months.
3. Third-party analytical cookies
These cookies are installed only if you give your consent through the cookie banner or settings.
_ga
_ga_4M98XD3KB2
Provider: Google LLC (Google Analytics service)
Type: third-party analytics
Purpose: collect information, in aggregated and anonymised form, on how visitors use the site (number of visitors, pages visited, time spent on the site, navigation paths).
Duration: up to 24 months.
Data generated by Google Analytics may be processed by Google as a processor on behalf of the Controller, in accordance with terms set by Google. You can disable these cookies via the cookie banner and through your browser settings.
Managing consent to cookies
When you first visit the site, a cookie banner appears, allowing you to:
accept all cookies;
reject non-necessary cookies;
select in a granular way which categories of cookies to enable (e.g. enable or disable analytics cookies).
You can change your choices at any time by:
using the dedicated link/button (e.g. “Cookie settings” or similar) available on the site; and/or
adjusting your browser settings to block or delete cookies.
Disabling only non-necessary cookies does not affect basic website functionality; blocking technical cookies may impair or prevent proper operation of some parts of the site.
Managing cookies via browser
In addition to the banner, you can configure your browser to:
block the installation of all or some cookies;
delete cookies already stored on your device.
The procedure differs depending on the browser used (e.g. Chrome, Firefox, Safari, Edge). For more information, please refer to the “Help” section of your browser.
