Skip to main content Skip to footer

Privacy

Privacy Policy - https://tickets.frasassi.com/

(pursuant to Regulation (EU) 2016/679 – “GDPR”)

This Privacy Policy describes how the personal data of users who access and use the website https://tickets.frasassi.com/ (hereinafter, the “Website”), dedicated to the online purchase of admission tickets to the Frasassi Caves, are processed.

For information regarding the use of cookies and similar technologies, please refer to the Website’s Cookie Policy.

1. Data Controller

The Data Controller of the personal data is:

Grotte di Frasassi Srl
Largo Leone XII, 1 – 60040 Genga (AN) – Italy
VAT No. 00222050429
E-mail: privacy@frasassi.com

The Data Controller processes personal data in accordance with Regulation (EU) 2016/679 (“GDPR”) and the applicable Italian legislation on the protection of personal data.

2. Parties involved in the processing

2.1 TicketOne S.p.A. – online ticketing platform (InHouse)

For the technical management of the online ticketing service, the Data Controller uses the “InHouse” system provided by:

TicketOne S.p.A.
Via Fabio Filzi, 29 – 20124 Milan – Italy
Website: www.ticketone.it – E-mail: privacy@ticketone.it TicketOne+1

TicketOne:

  • provides the software platform through which users register, select events and purchase tickets;

  • hosts and manages the databases connected to the ticketing service;

  • enables Grotte di Frasassi Srl operators to access the platform for managing bookings, admission tickets and customer support.

With regard to processing activities carried out on behalf of Grotte di Frasassi Srl (e.g. management of orders and customer records for the sale of tickets to the Caves), TicketOne is appointed as an external Data Processor pursuant to Article 28 of the GDPR.

For other processing activities independently carried out by TicketOne (e.g. management of its own databases, its own legal obligations, website security logs and any additional services provided), TicketOne may act as an independent Data Controller, as indicated in its privacy policy available on the website www.ticketone.it. TicketOne+1

2.2 Nexi Payments S.p.A. – electronic payments

Online payments made through the Website are processed through the electronic payment gateway provided by:

Nexi Payments S.p.A.
Corso Sempione, 55 – 20149 Milan – Italy - www.nexi.it.

When the user proceeds with payment, they are redirected to Nexi’s infrastructure or to a payment service managed by Nexi, within which:

  • payment card data (card number, expiry date, CVV, etc.) and other data necessary to complete the transaction are collected and processed;

  • Grotte di Frasassi Srl does not have access to the complete card details, but receives from Nexi only the information necessary to link the payment outcome to the order (outcome, amount, date, transaction reference).

For the processing of payment-related data, Nexi acts as an independent Data Controller. The relevant processing methods are described in Nexi’s privacy policies, available on the website www.nexi.it.

Grotte di Frasassi Srl, as Data Controller, has access to the Nexi dashboard solely for viewing payments associated with orders and managing any refunds / reversals of admission tickets purchased through the Website.

3. Types of data processed

3.1 Browsing data

The IT systems and software procedures used to operate the Website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols, such as:

  • IP address;

  • date and time of access;

  • pages visited (requested URLs);

  • type of browser and device used;

  • numerical code indicating the status of the response (e.g. successful completion, error);

  • other parameters relating to the operating system and the user’s IT environment.

Such data are processed exclusively to:

  • enable browsing on the Website;

  • obtain anonymous statistical information on the use of the Website;

  • monitor correct operation and ensure the security of the systems.

For further information on cookies and any third-party tools (e.g. analytics cookies), please refer to the Cookie Policy.

3.2 Platform registration data

To create an account on the Website and use the online ticketing services, the user may be asked to provide:

  • first name and surname;

  • e-mail address (username);

  • password (stored in encrypted form);

  • any additional contact details (e.g. telephone number);

  • preferred language or other account settings.

This data is necessary to enable the creation and management of the user account and access to the reserved area where orders and purchased tickets can be viewed.

3.3 Data relating to ticket purchases

For the purchase of admission tickets to the Frasassi Caves, the Website collects, among other things:

  • identification and contact data of the purchaser (first name, surname, e-mail, and, where applicable, telephone number);

  • order-related data (date, ticket type, number of tickets, visit date/time, amount paid);

  • any data relating to promotions/discounts (e.g. reduced-price tickets, coupons, promotional codes);

  • information necessary for the issuance and digital delivery of tickets (e.g. e-mail address for sending the e-ticket).

Where named tickets are required for specific reasons (security, traceability, sector regulations), additional identification data may be requested (e.g. date of birth, place of birth, tax identification number, etc.), as indicated in the purchase procedures and terms and conditions of sale.

3.4 Payment data

As indicated in section 2.2, payment card data and other data strictly necessary for transaction authorization are processed directly by Nexi Payments S.p.A., acting as an independent Data Controller.

Grotte di Frasassi Srl and TicketOne S.p.A. do not view or store complete card details, but receive from Nexi the transaction outcome, the transaction reference and the information necessary for order management (e.g. payment confirmation, reversal, refund).

3.5 Data provided through support requests

In the event of contact through the e-mail addresses, telephone numbers or other channels indicated on the Website for customer support, the following may be processed:

  • identification and contact data (first name, surname, e-mail, telephone number);

  • order/ticket data (order number, date, amount, etc.);

  • information contained in the text of the request (e.g. reasons for modification, technical problems, refund request).

This data is processed solely to respond to the request and manage the support case.

4. Purposes of processing.

Personal data collected through the Website are processed for the following purposes:

a) Website browsing and security

  • Purpose: enable the user to browse the Website, monitor the correct functioning of the services and ensure the security of the systems.

b) Account registration and management of the reserved area

  • Purpose: create and manage the user account, enable access to the reserved area, view order history and download purchased tickets.

c) Order management and ticket sales

  • Purpose: manage the entire ticket purchase process (product selection, shopping cart, payment, ticket issuance, confirmation communications, management of changes or refunds, admission checks).

d) Legal, accounting and tax obligations

  • Purpose: comply with legal, regulatory or national/EU obligations (e.g. accounting, tax, public security regulations or regulations applicable to events and access to the site).

e) Complaints, support and litigation management

  • Purpose: manage support requests, complaints and disputes, as well as exercise or defend a right in judicial proceedings or before the competent authorities.

f) Aggregated statistical analysis

  • Purpose: perform statistical analyses on the use of the Website and orders, in aggregated and anonymous form, to improve the offer and management of services.

g) Service communications

The e-mail address and contact details provided may be used to:

  • send order confirmations, tickets and operational information concerning the visit;

  • communicate any changes, cancellations, extraordinary closures, safety measures, access conditions, refunds or alternative arrangements.

These communications are strictly connected with the purchase and are not promotional in nature.

h) Sending promotional communications and newsletters (marketing)

  • Purpose: send the Customer, by e-mail or other contact channels indicated by them, informational and promotional communications relating to:

    • offers, promotions and discounts on admission tickets to the Frasassi Caves and related services (e.g. guided tours, special routes, events);

    • initiatives, events and activities organized or promoted by Grotte di Frasassi Srl;

    • any satisfaction surveys and market research aimed at improving the visitor experience and the services offered.

  • Data processed: identification and contact data (e.g. first name, surname, e-mail), basic information on purchases made (e.g. ticket type, visit date), without advanced profiling activities.

  • Failure to provide consent does not affect the possibility of registering on the Website or purchasing tickets.

5. Nature of providing the data

  • The provision of browsing data is necessary to access the Website; failure to provide such data may make it impossible to access or use the pages.

  • The provision of data required for registration and ticket purchases is necessary for the conclusion and performance of the sales contract: if such data is not provided, it will not be possible to proceed with the order.

  • The provision of data for any additional purposes (e.g. newsletter subscription, additional services) is optional and, where applicable, will be governed by specific privacy notices and consent requests.

6. Processing methods

Personal data are processed:

  • using computerized and telematic tools, with procedures strictly related to the purposes indicated;

  • by authorized personnel of the Data Controller and external Data Processors;

  • by adopting appropriate technical and organizational measures to ensure the security, confidentiality and integrity of the data, in accordance with Article 32 GDPR.

No fully automated decision-making process is envisaged that produces legal effects concerning the data subject or similarly significantly affects them, pursuant to Article 22 GDPR.

7. Data retention

Personal data will be retained for the time strictly necessary to achieve the purposes for which they were collected and, subsequently:

  • for the period required by civil, tax and accounting regulations (generally up to 10 years from the accounting recording of the transaction);

  • for the time necessary to manage any complaints, disputes or legal defenses (in compliance with the applicable limitation periods).

Data relating solely to technical and security logs are normally retained for a period not exceeding 30 days, unless further retention is necessary in the event of investigations into security incidents or requests by authorities.

Once the retention period has expired, the data will be deleted, anonymized or processed only in aggregated form that cannot be attributed to individual users.

8. Recipients of personal data

Within the limits of the purposes indicated above, data may be disclosed to:

  • duly authorized internal personnel of the Data Controller;

  • TicketOne S.p.A., as external Data Processor (and, for certain processing activities, as an independent Data Controller);

  • Nexi Payments S.p.A., as an independent Data Controller for payment data;

  • providers of IT, hosting, software maintenance and technical support services;

  • consultants and professionals (e.g. tax and legal advisors) assisting the Data Controller;

  • competent authorities (e.g. public security authorities, tax authorities, judicial authorities) in the cases and according to the procedures provided for by law.

Personal data will not be subject to indiscriminate disclosure, except where specifically required by law (e.g. security obligations, sector-specific regulations).

9. Transfers to non-EU countries

As a general rule, data processed by the Data Controller and its external Data Processors are stored on servers located within the European Economic Area (EEA).

Where, for technical or organizational reasons, certain categories of data (e.g. logs or information related to payment services or third-party tools) are transferred to non-EU countries:

  • the transfer will take place in compliance with Articles 44 et seq. of the GDPR;

  • where available, safeguards such as European Commission adequacy decisions, standard contractual clauses and supplementary measures suitable to ensure a level of data protection substantially equivalent to that provided in Europe will be used.

Further details can be found in the privacy policies of the individual providers (in particular TicketOne and Nexi).

10. Data subject rights

The user, as a data subject, may exercise at any time, against the Data Controller, the rights provided for by Articles 15–22 of the GDPR, including:

  • the right to obtain confirmation as to whether or not personal data concerning them exist;

  • the right of access to their data and information concerning the processing;

  • the right to request the rectification of inaccurate data or completion of incomplete data;

  • the right to request the erasure of data (“right to be forgotten”) in the cases provided for by the GDPR;

  • the right to request restriction of processing;

  • the right to object to processing based on legitimate interest;

  • the right to data portability (where applicable);

  • the right to withdraw any consent given, without affecting the lawfulness of processing carried out before the withdrawal.

Requests may be addressed to:

Grotte di Frasassi Srl
E-mail: privacy@frasassi.com

The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it), if they believe that the processing of their personal data is carried out in violation of applicable legislation.

11. Updates to this Privacy Policy

The Data Controller reserves the right to modify or update this Privacy Policy at any time, including as a result of changes in legislation or developments in the services offered through the Website.

Any changes will be published on this page; users are therefore invited to consult it periodically.

Last updated: 24/11/2025