This Privacy Policy outlines how Tourist Point S.r.l. uses and processes your personal data when you use our services, including through our website conetpass.com. It also informs you of your rights concerning your personal data and how to contact us.
If you reside in the United States, please refer to Section 18 – Rights of U.S. Residents to understand your specific rights.
1. Data Controller and Contact Information
The Data Controller for users’ personal data in accordance with Regulation (EU) 2016/679 (GDPR) is:
Tourist Point S.r.l.
Via del Gonfalone 3, 20123 Milan (MI) – VAT IT09167390963
PEC: [email protected]
The Data Controller has appointed a Data Protection Officer (DPO), who is your point of contact for all information and requests relating to data protection: [email protected].
Any data processing by service providers that offer or promote their services on the Tourist Point S.r.l. platform is subject to their respective privacy policies. These service providers act independently as data controllers.
1.1. Purpose of This Document and Target Audience
The Data Controller commits to respecting the identity and dignity of every individual and the fundamental freedoms guaranteed by the Italian Constitution and the EU Charter of Fundamental Rights in relation to the processing of personal data. The company will continually maintain this commitment within the scope of the accountability principle by implementing adequate technical and organisational measures to ensure that processing is carried out in compliance with the GDPR and Italian Legislative Decree No. 196/2003 (Privacy Code), as amended by Legislative Decree No. 101/2018.
This document is addressed to users of the website conetpass.com (the “Site”). Access to certain sections of the Site and/or requests for information or services may require the entry of personal data relating to natural persons, which will be processed in compliance with the GDPR and applicable Italian legislation. Where necessary, specific consent will be requested for the processing of personal data. This document applies solely to the Site and not to other websites that users may visit via links referred to on this Site.
2. Automated Data Collection
When you visit our website or use our mobile apps, we automatically collect certain information. The following data are saved separately from any other information that you may transmit to us:
- URL of the accessed page
- Geographic area
- Date and time
- Information about your device’s hardware and software (such as the operating system, browser used, software or application version data, and language settings)
- Information on clicks and which pages were shown to you
We store this data for the following purposes:
- To ensure the security of our IT systems, including defence against specific attacks and recognition of attack patterns;
- To ensure the proper operation of our IT systems, including where errors occur that can only be rectified by saving the IP address;
- To allow for criminal prosecution, danger prevention, or legal action in cases of specific indications of criminal activity.
Your IP address is encrypted to ensure confidentiality and is accessible only when absolutely necessary. It is retained for a period of 45 days.
If you use a mobile device, we collect data that identifies the device, as well as data on its settings and specific features. Processing in this context is carried out to ensure security in accordance with Article 32 GDPR and based on our legitimate interest in protecting our service from abuse (Article 6(1)(f) GDPR).
3. Customer Service
3.1. Processing of Requests
If you contact our customer service team or reach us through other means such as our social media channels, your request is processed by us in order to respond to your enquiry. The legal basis for this processing is Article 6(1)(b) GDPR where the request relates to a service or booking, or Article 6(1)(f) GDPR (legitimate interest in responding to general enquiries) in all other cases.
3.2. Improvement of Customer Service
In order to continuously improve our customer service, we analyse requests based on certain parameters and keywords. Although personal data is not analysed as a basic principle, it cannot be excluded that, in individual cases, personal data may be processed within this context. Such processing serves our legitimate interest and that of our customers in the continuous improvement of our customer service (Article 6(1)(f) GDPR).
3.3. Translations
In some cases, it is necessary to translate incoming requests into a specific language. This may involve the processing of personal data to protect our legitimate interest in providing international customer service (Article 6(1)(f) GDPR). For this purpose, we use the services of OpenAI, Inc. (USA). As there is no adequacy decision by the EU Commission for the United States, we have concluded Standard Contractual Clauses approved by the EU Commission with OpenAI under Article 46(2)(c) GDPR.
4. Technical Service Providers
4.1. Hosting
We use hosting and other services required for the website from technical service providers. Data processing therefore takes place on the servers of these service providers. They process data only in accordance with our explicit instructions and are required to ensure sufficient technical and organisational measures to protect data, acting as data processors under Article 28 GDPR. For hosting our website, we use the services of Aruba Business, based in Italy. When you interact with our website or provide personal data, this data is processed on Aruba Business servers located exclusively within the European Union.
4.2. Email System
For sending emails, we use the service of Aruba Business, based in Italy.
5. Communications
You may register on our website to receive our communications. With our newsletter, we will send information about offers or special promotions as personalised as possible. By registering for our newsletter, you consent to the processing of your email address for the purpose of sending the newsletter. The legal basis for such processing is Article 6(1)(a) GDPR.
You may revoke your consent at any time by unsubscribing from our newsletter, either by using the unsubscribe link contained in each email or by contacting us at [email protected].
When registering to receive our communications, we save the IP address, date, and time of registration. The processing of such data is necessary to demonstrate that consent was provided, in accordance with Article 6(1)(c) jointly with Article 7(1) GDPR.
If you have purchased a service through our website, we may send our newsletter based on our legitimate interest in promoting similar services (Article 6(1)(f) GDPR), in accordance with Article 130(4) of the Italian Privacy Code (Legislative Decree No. 196/2003), unless you have objected to such use.
If cookies are used for the personalisation of the newsletter, your separate consent will be requested. You may object at any time by clicking the unsubscribe link in the relevant emails.
For sending our communications and personalising content, we use the services of TeamSystem S.p.A. – MailUp, based in Italy.
6. Bookings and Payments
6.1. Bookings
When you book one of our services on our website, we collect the data necessary to perform the service. This generally includes: full name, email address, number of participants, and the date and time of the service. Depending on the type of service booked, additional information may be required, such as the age of participants.
Processing in relation to bookings is based on Article 6(1)(b) GDPR. Where necessary, we will transfer your data to the provider responsible for the service, who will process the personal data as indicated in their own privacy policy as an independent data controller. Where data must be transferred outside the European Economic Area, this is based on Article 49(1)(b) and (c) GDPR.
6.2. Booking Confirmations
In order to keep you informed regarding your bookings, we will send booking confirmations, reminders, and updates (for example, changes to times or meeting points) to ensure you have all the necessary information to participate in the booked services. Booking confirmations are sent to your email address and/or via SMS to the phone number provided during the booking process and/or through push notifications from the Tourist Point S.r.l. app. Where you have an account, you can choose how to receive notifications via the “Settings” → “Notifications” section of your profile. Processing is based on Article 6(1)(b) GDPR.
6.3. Payments
You have various options for paying for the booking. We process the data necessary for the selected payment method, based on Article 6(1)(b) GDPR.
6.3.1. Payments by Credit Card
For processing credit card payments, we use the services of Nexi S.p.A. (“Nexi”), based in Italy. The data provided during payment will be forwarded by Nexi to the relevant banks or financial institutions for the purpose of processing the payment. We only receive information about whether the payment was made or not, together with the first and last four digits of the credit card number. We do not have access to the full credit card number.
7. Fraud Prevention
In order to protect ourselves and activity providers from fraudulent bookings, we evaluate the information you provide during the booking process, including data technically transmitted by your device. This processing is based on our legitimate interest and that of activity providers in ensuring the reliability of bookings (Article 6(1)(f) GDPR). For this purpose, we use the services of Nexi S.p.A., based in Italy, acting as data processor under Article 28 GDPR.
8. Protection Against Bots
To protect ourselves from bots and similar technologies, a Web Application Firewall (WAF) is installed and configured on the server provided by Aruba Business. Aruba Business uses the data automatically transmitted by your device to determine whether a request is likely to originate from a human being. No further data storage takes place.
Processing is carried out to ensure security in accordance with Article 32 GDPR and based on our legitimate interest in protecting our service from abuse (Article 6(1)(f) GDPR).
9. Cookies and Other Online Tracking Technologies
We use cookies and other online tracking technologies to provide certain functions of our website, to optimise the use of our website and apps, and to execute our marketing and advertising strategy. For detailed information about the cookies we use and your rights in this regard, please visit our Cookie Policy.
10. Customer Research and Visitor Path Recordings
10.1. Customer Surveys
At the end of the payment process, we make available to you a survey form with questions aimed at offering additional services tailored to customer needs. The processing of data collected through surveys is based on our legitimate interest in improving our services and tailoring our offer to customer needs (Article 6(1)(f) GDPR).
10.2. Visitor Path Recordings
We use the thermal mapping services of Hotjar Ltd., Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian’s STJ 3141, Malta. These services record areas of a page where visitors most frequently move the mouse or click, in order to identify points of interest and improve our website and services. Recording takes place only on certain pages and for a limited daily number of random visitor sessions. Recordings are stored for a period of 365 days and then automatically deleted.
Processing is based on your consent (Article 6(1)(a) GDPR). To opt out of Hotjar recording, visit: Hotjar.com.
11. Marketing and Remarketing Services
11.1. Google Services
We use the services of Google Ireland Limited, Gordon House, 4 Barrow Street, Dublin D04 E5W5, Ireland (“Google”). Google may process some personal data in the United States through Google LLC, certified under the EU-U.S. Data Privacy Framework. Google Ireland Limited relies on this framework to transfer personal data originating in the EEA to the United States.
For general information on how Google processes personal data, visit: Policies Google.
You have the following opt-out options with Google:
- Disable personalised advertising from Google: adssettings.google.com
- Disable personalised advertising on a per-device basis: support.google.com/ads/answer/1660762
- Disable personalised advertising through the browser: The Nai
11.2. Matomo
We use Matomo (On-Premises version) installed on our own servers for web analytics. Matomo collects pseudonymised data on the use of our website, including your truncated IP address, through first-party cookies. This information is stored exclusively on our servers and is not transmitted to third parties. We do not use the data for profiling purposes. The legal basis for this processing is our legitimate interest in understanding how our website is used in order to improve it (Article 6(1)(f) GDPR). You may opt out at any time through your browser settings or the opt-out mechanism described in our Cookie Policy.
11.3. Google Ads Campaign Management
If you have given your consent, we use Google’s advertising products. We use cookies and client tags to record and share your behaviour on our website and app, in order to display interest-based advertising for our products on other pages within the Google advertising network, including Google Search, YouTube, and other sites managed by Google and its partners.
Information such as masked identifiers and browsing activity is transmitted to Google and its partners. Further processing of data by Google will only take place if you have given your consent to Google to link your browsing history to your Google account and use that information to personalise the ads you see on the web. Processing is based on your consent (Article 6(1)(a) GDPR).
11.4. Email Remarketing
We carry out email remarketing activities for users who have completed or not completed a payment and who have given consent to such processing. If you have not completed a payment, you will receive a maximum of 4 emails within 7 days following the purchase attempt.
Processing is based on your consent (Article 6(1)(a) GDPR). You may withdraw your consent at any time by contacting us at [email protected] or by clicking the Unsubscribe link in any of our emails. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
12. CRM System
In order to manage our relationships with customers, we store your personal data in our CRM system. This allows us to respond to requests in a targeted manner and to send you relevant communications to the extent permitted. Processing is based on our legitimate interest in managing the relationship with our customers (Article 6(1)(f) GDPR).
13. Personalisation of Website Content
We process your data to show personalised content on our website. The legal basis is our legitimate interest in showing you tours and activities relevant to your preferences (Article 6(1)(f) GDPR).
14. Transmission of Data
In addition to the cases described above, your personal data will be transmitted without your explicit consent only in the following circumstances:
- Where necessary to address unlawful use of our services or for legal action, personal data may be forwarded to law enforcement agencies and, if necessary, to affected third parties. This occurs only where there are specific indications of illegal or abusive behaviour.
- We are legally obliged to provide information on request to certain public authorities, including law enforcement agencies, authorities prosecuting administrative offences, and tax authorities. Such disclosures are based on our legitimate interest in combating abuses and enforcing legal claims (Article 6(1)(f) GDPR) or on a legal obligation (Article 6(1)(c) GDPR).
- We disclose personal data to auditors, accountants, lawyers, banks, tax consultants, and similar bodies where necessary for the provision of our services (Article 6(1)(b) GDPR), the proper management of our business (Article 6(1)(f) GDPR), or where we are legally required to do so (Article 6(1)(c) GDPR).
- We rely on third-party data processors for the provision of services. These processors are carefully selected and regularly reviewed. They may only use data for the purposes specified by us and are contractually bound to process data in accordance with this Privacy Policy and applicable data protection law, under Article 28(1) GDPR.
- As part of the further development of our business, the structure of Tourist Point S.r.l. may change through modifications to its legal form, or the purchase or sale of subsidiaries or parts of the company. In such transactions, customer data may be transferred as part of the relevant business unit. Any such transfer is justified by our legitimate interest in adapting our corporate structure to economic and legal circumstances (Article 6(1)(f) GDPR).
15. Automated Decision-Making and Profiling
We do not use automated processing for individual decision-making or profiling as defined by Article 22 GDPR.
16. Retention and Deletion of Your Data
We delete and anonymise your personal data as soon as it is no longer necessary for the purposes for which it was collected or used, in accordance with the sections above. We continue to retain data where we are legally obliged to do so (including under Italian fiscal and civil law obligations) or where data is necessary for criminal proceedings or for the establishment, exercise, or defence of legal claims. Where data is retained for legal reasons, its processing will be restricted and it may not be used for other purposes. Retention beyond the contractual relationship is based on our legitimate interests (Article 6(1)(f) GDPR) and applicable legal obligations (Article 6(1)(c) GDPR).
17. Your Rights as a Data Subject
You have the following rights concerning the processing of your personal data. To exercise these rights, you may contact the Data Controller at [email protected] or the Data Protection Officer at [email protected]. The Data Controller will respond within 30 days of receipt of the request. In complex cases or where a large number of requests are received simultaneously, this period may be extended to a maximum of 90 days, with prior notification to you.
17.1. Right of Access
You have the right to receive information about your personal data processed by us, in accordance with Article 15 GDPR.
17.2. Right to Rectification
You have the right to request the timely correction of any inaccurate personal data concerning you (Article 16 GDPR).
17.3. Right to Erasure
You may request the deletion of personal data concerning you under the conditions set out in Article 17 GDPR, including where data is no longer necessary for the purposes for which it was collected, where processing is unlawful, or where an obligation to delete exists under applicable law.
17.4. Right to Restriction of Processing
You have the right to request restriction of processing under Article 18 GDPR, including where the accuracy of data is disputed, where processing is unlawful but you oppose erasure, where the data is no longer needed by us but is required by you for legal claims, or where an objection is pending.
17.5. Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller, under Article 20 GDPR.
17.6. Right to Object
You have the right to object at any time to the processing of your personal data based on Article 6(1)(e) or (f) GDPR, in accordance with Article 21 GDPR. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims.
17.7. Right to Withdraw Consent
Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to the withdrawal (Article 7(3) GDPR).
17.8. Right Not to Be Subject to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you (Article 22 GDPR). As stated in Section 15, we do not currently use automated decision-making or profiling of this nature. Should this change, you will be informed and your rights under Article 22 GDPR will be fully respected.
17.9. Right to Lodge a Complaint
You may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), Piazza Venezia 11, 00187 Rome, website: www.gpdp.it, or with another competent supervisory authority in the EU Member State of your habitual residence.
17.10. Data Processing in the Exercise of Rights
We process the personal data you provide when exercising your rights under Articles 15–22 GDPR for the purpose of fulfilling such rights and providing the necessary evidence. Processing is based on Article 6(1)(c) GDPR, together with Articles 15–22 GDPR.
18. Rights of U.S. Residents
18.1. Disclosure
If you reside in certain U.S. states, including California, Colorado, Connecticut, or Virginia, you may have specific privacy rights. This section describes those rights and how to exercise them. It does not apply to publicly available information. The California Consumer Privacy Act of 2018 (“CCPA”), the California Privacy Rights Act of 2020 (“CPRA”), and the privacy laws of other states provide certain U.S. residents with specific rights regarding personal information.
For details on how we collect, use, and process personal information, please refer to the following sections of this Privacy Policy:
- Customer assistance: Section 3
- Technical service providers: Section 4
- Newsletter and communications: Section 5
- Bookings and payments: Section 6
- Fraud prevention: Section 7
- Protection against bots: Section 8
- Cookies: Section 9
- Marketing and remarketing: Section 11
- CRM system: Section 12
- Product development: general business purposes
18.2. Access to Specific Information
You have the right to request disclosure of certain information about how we have collected and used your personal information. Upon receipt of a valid request, we will inform you, to the extent permitted by law, of: the categories of personal information collected; the sources of that information; the business or commercial purpose for collecting, selling, or sharing it; the categories of third parties with whom it is shared; and, where applicable, the categories of personal information disclosed for business purposes.
18.3. Right to Deletion
If you reside in a state that provides this right, you may request that we delete your personal information, subject to exceptions established by applicable law. For more details, see Section 17.3.
18.4. Right to Correction
If you reside in a state that provides this right, you may request the correction of inaccurate personal information we hold about you, subject to exceptions established by applicable law. For more details, see Section 17.2.
18.5. No Discrimination
We will not discriminate against you for exercising any of your privacy rights.
18.6. Do Not Sell or Share My Personal Information
You may change your cookie preferences at any time and request to deactivate the sharing of your personal information with third parties, subject to exceptions established by applicable law. With “sharing,” we refer to the processing of personal data as described in Section 9 (Cookies) and Section 11 (Marketing and Remarketing Services).
18.7. Opt-Out of Targeted Advertising
Some data collection and processing on our website for interest-based advertising may be considered “targeted advertising” or a “sale” or “sharing” of personal information under certain state laws, such as the Consumer Data Protection Act (Virginia). Depending on your cookie preferences and to the extent permitted by law, we may disclose your personal information to our trusted partners for targeted advertising. You may request to stop such use by contacting us at [email protected].
18.8. Do Not Share or Disclose My Sensitive Personal Information
You have the right to limit how your sensitive personal information is disclosed or shared with third parties. To exercise this right, please contact us at [email protected].
18.9. Exercising Your Rights
To exercise any of the rights described in this section, please contact us at [email protected] with sufficient detail to allow us to respond appropriately. We will take reasonable steps to verify your identity before responding. If you reside in California, you or an authorised agent registered with the California Secretary of State may submit a request on your behalf. If you reside in Connecticut or Colorado, you may designate an authorised agent to submit a request. You may also submit a verifiable consumer request on behalf of your minor child.
Depending on your cookie preferences, we may “share” categories of personal information as defined by California law, for cross-context behavioural advertising. We do not “sell” personal information as defined by the CPRA or the Consumer Data Protection Act (Virginia). We do not knowingly “share” the personal information of minors under the age of 16.
19. Changes to This Privacy Policy
The Data Controller reserves the right to update this Privacy Policy at any time to reflect changes in applicable law or in the processing activities described herein. The current version is always accessible on this page at conetpass.com/privacy/.
Where changes affect processing operations that require consent, you will be informed and asked to provide fresh consent where required by applicable law.
Tourist Point S.r.l.
Via del Gonfalone 3, 20123 Milan (MI) – VAT IT09167390963
Last updated: 31 March 2026