Privacy Policy

Subject and Scope

This Privacy Policy (“Policy”) applies to anyone (“User/s,” “Client/s,” “you,” or “data subject”) using the applications and Services (“Application”) to request travel booking services provided by independent or affiliated third-party transportation providers (Third-Party Transport Provider).

The data protection regulations for the protection of the data subject’s rights arise primarily from the EU General Data Protection Regulation (EU Regulation 2016/679; hereinafter referred to as “GDPR”). To the extent that we determine the purposes and means of data processing alone or jointly with others, this includes the obligation to inform the user transparently about the type, scope, purpose, duration, and legal basis of processing (see Articles 13 and 14 of the GDPR).

The purpose of this privacy policy (hereinafter: “policy”) is to inform the user about our methods of processing their personal data.

Definitions

Data Controller

The entity responsible for processing the User’s personal data (Article 4(7) of the GDPR) is:

AZIENDA METROPOLITANA TRASPORTI E SOSTA CATANIA S.p.A.

Address: XIII Strada, Zona Industriale

95121 Catania, Italy

Email address: pubblicherelazioni@amt.ct.it

Further information about our company is available at https://www.amts.ct.it/

Data Protection Officer

Our Data Protection Officer is available at any time to answer all the User’s questions and to act as a contact point regarding data protection.

Their details are:

Edisonweb Srl

Dr. Riccardo D’Angelo

Address: Via Ignazio Silone 21

95040 Mirabella Imbaccari (CT), Italy

Email address: admin@edisonweb.com

Legal Basis for Data Processing

The processing of personal data is permitted if at least one of the legal bases listed below is met:

Duration of Data Storage and Deletion of Data

The duration of the storage of personal data collected depends on the purpose of processing. Data will be stored for as long as necessary to achieve the intended purpose.

If no explicit retention period is specified below, the User's personal data will be deleted or blocked as soon as the purpose or legal basis for retention is no longer applicable. However, retention may continue beyond the indicated time in the case of one or more legal disputes (imminent) with the User or if other legal proceedings are initiated or if retention is required by legal provisions to which we are subject as Data Controllers. If the retention period prescribed by legal provisions expires, personal data will be blocked or deleted, unless further retention is necessary on our part and there is a legal basis for such extension.

Data Protection Principles

We are committed to following the following data protection principles:

User Rights

These rights consist of the ability to access, rectify, erase, restrict, object to processing, and process data, including in automated form. Data subjects have the right to withdraw consent to the processing of their personal data at any time and obtain portability in an accessible format. In general, the right to information is guaranteed, i.e., to know if personal data is being processed, what data is collected, from which source it is obtained, the purpose, and the parties that carry out the processing.

User Rights to Modify and Delete Data

The User may modify account-related information at any time by logging into their online account or within the App. If you wish to delete your account, exercise other rights regarding processing, or view/change detailed privacy settings, we offer control through personal settings. For all features not yet available through personal settings or for specific requests, please open a ticket through our support center. Please note that we may, in some cases, retain certain User information as required by law or for legitimate business purposes within the limits permitted by law. For example, if the User has a permanent credit or debt on their account, or if we believe the User has committed fraud or violated our Terms, we may seek to resolve the issue before deleting the information.

Types of Data Collected

Information Collected Provided by the User

We collect information directly provided by the User, for example, when creating or modifying an account, for on-demand services, through customer service contact, or during other communications with us. Such information may include: name, email, phone number, postal address, profile picture, payment method, and other information that the User chooses to provide.

Information Collected Automatically and Through Service Use

When the User uses our Services, we collect information about them in the following general categories:

Platform Permission Information

Most mobile device platforms (iOS, Android, etc.) have defined the types of device data that applications cannot access without consent. These platforms have different authorization systems to obtain consent from the User. The iOS platform will inform the User the first time the mobile application requests permission to access certain types of data, giving the opportunity to consent or not consent to the request. Android devices will inform the User of authorization requests before the first use of the mobile application, and using it will equate to consent.

Use of Personal Data

We use the information collected to:

We process and/or use personal data in order to comply with obligations arising from the law. We reserve the right to anonymize personal data collected and use such data, even outside the scope of this privacy policy, only when it is anonymized. We retain billing information and other related information for as long as necessary for accounting purposes or other legal obligations, but no longer than 10 years.

We may process personal data for additional purposes not mentioned here but compatible with the original purpose for which the data was collected. To do this, we will ensure that:

In any case, we will inform Users of any further processing and purposes.

Sharing of Information

In general, we do not share the information we collect about Users with unrelated third parties. In some cases, we may share information with our trusted partners, subsidiaries, or affiliates, including licensed or franchised companies of the Application, in order to enable the provision of the service or improve the user experience, as described in this Policy.

Sharing via our Services

We may share information regarding Users:

Other Important Shares

We may share information regarding Users:

Social Sharing Features

The Services may integrate with social sharing features and other related tools that allow sharing actions taken on our Services with other applications, sites, or communication means, and vice versa. The User's use of such features enables sharing information with their friends or the public, based on the settings of the social sharing service. Please refer to the privacy policies of the aforementioned social sharing services for more information on how they manage the data provided or shared by the User.

Cookies

For the parts relating to interaction with our web services, please refer to our Cookie Policy, published on www.mvmant.com, for further information regarding choice freedom related to cookies and related technologies.

Changes to the Policy

We reserve the right to modify this Policy at any time. If we make significant changes to the way we process personal information, or to the Policy, we will notify the User through the Services or any other means, for example via email. Continued use of the Services after receiving such notification constitutes consent to the changes made. We encourage the User to periodically review this Policy for updated information.