Rotary · EME Rotary 2027 — Bari, Italia
EN IT

Home · Privacy notice

Privacy notice

Last updated 4 September 2026

This privacy notice concerning the processing of personal data is prepared and provided by Summit EME 2027 Srls, in its capacity as Data Controller, pursuant to Article 13 of EU Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data (hereinafter also the “Regulation” or the “GDPR”), to users (i.e. data subjects) who visit the website available at http://www.rotarysummitbari.org or through its third-level domains (hereinafter also referred to simply as the “website”), unless otherwise expressly stated.

Data Controller and contact details

Summit EME 2027 Srls, with registered office at Via Poli 21/A, Bari (BA), Italy, certified email (PEC): summit_eme_2027@pec.it, email: info@rotarysummitbari.org, VAT no.: 09204130729.

Methods of processing personal data

The Data Controller processes personal data provided and/or collected from users by means of paper-based, IT and/or electronic tools, adopting appropriate security measures designed to prevent unauthorised access to its systems and thereby reduce the risk of the data being altered, disclosed or destroyed.

Personal data may also be processed in aggregate form, using organisational methods and procedures strictly appropriate to the purposes set out in this notice.

On certain occasions, the data may be processed by categories of persons authorised by the Data Controller and involved in organising the provision of services connected with the website, or by external parties (third-party technical service providers and hosting providers) appointed as Data Processors. Data subjects may request the up-to-date list of Data Processors and authorised persons at any time; it is also available at the Data Controller’s registered office.

Personal data is processed at the operating offices of the Data Controller and the Data Processors, as well as at any other location where the parties involved in the processing are established.

Personal data is not subject to automated processing.

Purposes of processing

The purposes for which personal data collected through the website is processed are set out below, together with the categories of personal data collected, the categories of data subjects, the conditions for lawful processing, the legal bases where these must be specified, and the relevant retention periods.

Sending information about the event

Categories of data subjects: website users.

Categories of data collected: first name, surname, email address, country of residence, role within Rotary, Rotary Club membership and Rotary District membership.

Lawfulness condition: consent.

Legal basis: GDPR.

Retention period: for twenty-four months following registration. After this period, the data will be deleted automatically.

Responding to user requests

Categories of data subjects: website users.

Categories of data collected: first name, surname, email address and telephone number.

Lawfulness condition: performance of a contract or pre-contractual measures.

Legal basis: GDPR.

Retention period: for as long as necessary to fulfil data subjects’ requests. The data is retained for twelve months after its collection.

Website access statistics

Categories of data subjects: website users.

Categories of data collected: IP address.

Lawfulness condition: consent.

Legal basis: GDPR.

Retention period: for twenty-four months following registration. After this period, the data will be deleted automatically.

Data transfers

The Data Controller does not transfer the data collected for the purposes described above to countries outside the European Union.

Should such a transfer ever be considered necessary, the Data Controller will obtain users’ prior consent to the transfer pursuant to Articles 44 et seq. of the GDPR.

In any event, users are also invited to consult this website’s Cookie Policy to verify whether any transfers are connected with traffic analytics tools and/or other tracking technologies.

Rights of data subjects

Users, as data subjects, may exercise the rights granted to them under the GDPR, namely:

  • the right of access;
  • the right to rectification of data;
  • the right to erasure and the right to be forgotten;
  • the right to restriction of processing;
  • the right to object to processing;
  • the right to data portability.

These rights may be exercised by submitting an informal request to the Data Controller, who will respond within thirty (30) days of receipt. This period may be extended by a further sixty (60) days if fulfilling the request is particularly burdensome for the Data Controller.

The Data Controller informs users that, if no response is provided within the time limits indicated, if the response is unsatisfactory, or if users believe that their rights have been infringed, they may lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) in accordance with the procedures set out on the Authority’s website at http://www.gpdp.it.

Changes to this Privacy Policy

The Data Controller reserves the right to make any changes to this full privacy notice by publishing notice of them on this page.

The date of the latest amendment will be shown at the end of this notice so that changes may be tracked. A copy of each version of this notice is available to data subjects at the Data Controller’s registered office.

If a data subject does not accept the changes made, they may ask the Data Controller to delete their personal data.

Bari (BA), 4 September 2026

The Data Controller

Summit EME 2027 Srls