Privacy Policy | Comboni Missionary Sisters
Last updated: August 10, 2025
In compliance with General Data Protection Regulation (GDPR) 2016/679

1. Introduction

This Privacy Policy describes how Istituto Pie Madri della Nigrizia - Comboni Missionary Sisters collects, uses, stores, and protects your personal information when you visit our website or interact with our services.

We are committed to protecting your privacy and complying with all applicable data protection laws, including the European Union's General Data Protection Regulation (GDPR).

2. Data Controller

Controller Information

Organization: Istituto Pie Madri della Nigrizia - Comboni Missionary Sisters
Address: Via S. Maria in Organo, 1
37129 Verona, Italy
Phone: +39 045 4950110
Contact Email: [email protected]
Fiscal Code: 00524770237

3. Types of Data We Collect

Data Type Description Purpose Legal Basis
Identification Data Name, surname, email, phone Contact and communication Consent / Legitimate interest
Navigation Data IP, browser type, pages visited Website analysis and improvement Legitimate interest
Communication Data Messages sent, inquiries made Respond to inquiries Consent
Technical Data Session cookies, site preferences Website functionality Legitimate interest

3.1 Data we DO NOT collect

Important: We do not collect sensitive data such as health information, specific religious beliefs, political orientation, or biometric data. We also do not collect information from minors under 16 without parental consent.

4. Purposes of Processing

We use your personal data for the following purposes:

  • Institutional communication: Inform about our mission, activities, and charitable works
  • Response to inquiries: Address your questions and information requests
  • Service improvement: Analyze website usage to improve user experience
  • Legal compliance: Comply with applicable legal and regulatory obligations
  • Interest protection: Protect our legal rights and prevent fraudulent activities

5. Legal Basis for Processing

We process your personal data based on the following GDPR legal bases:

  • Article 6(1)(a) - Consent: For email communications and newsletters
  • Article 6(1)(b) - Contract performance: To provide requested services
  • Article 6(1)(f) - Legitimate interest: For website analysis and security
  • Article 6(1)(c) - Legal obligation: To comply with legal requirements

6. Data Sharing

6.1 Who we share your data with

We may share your personal data only with:

  • Technical service providers: Hosting, web maintenance, email services
  • Legal consultants: When necessary for legal advice
  • Competent authorities: When required by law
  • Other Comboni organizations: For coordinated missionary activities (only with consent)

6.2 International transfers

If we transfer data outside the European Economic Area (EEA), we ensure adequate safeguards exist such as:

  • European Commission adequacy decisions
  • EU-approved standard contractual clauses
  • Approved certifications and codes of conduct

7. Data Retention

Data Type Retention Period Justification
Contact data (forms) 3 years from last contact Response to inquiries and follow-up
Navigation data 12 months Statistical analysis and improvements
Emails and communications 5 years or until consent revocation Institutional communication history
Legal/litigation data 10 years Legal requirements and statute of limitations

8. Your Rights Under GDPR

Your Fundamental Rights

As a data subject, you have the following rights that you can exercise at any time:

  • Right of Access (Art. 15): Obtain information about what data we have about you
  • Right of Rectification (Art. 16): Correct inaccurate or incomplete data
  • Right of Erasure (Art. 17): Request deletion of your data ("right to be forgotten")
  • Right of Restriction (Art. 18): Restrict processing under certain circumstances
  • Right of Portability (Art. 20): Receive your data in structured format
  • Right of Objection (Art. 21): Object to processing based on legitimate interest
  • Rights related to automated decisions (Art. 22): Not be subject to decisions based solely on automated processing

How to exercise your rights

To exercise any of these rights, you can:

  • Send an email to: [email protected]
  • Write to our postal address indicated above
  • Use our contact form on the website

Response time: We will respond to your request without undue delay and, in any case, within one month.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data against:

  • Unauthorized or unlawful access
  • Accidental loss, destruction, or damage
  • Unauthorized alteration, disclosure, or access

9.1 Security measures implemented

  • Encryption: HTTPS/SSL connections for all communications
  • Access control: Limited access only to authorized personnel
  • Backups: Regular encrypted backups
  • Updates: Regular maintenance of systems and software
  • Training: Staff training in data protection

10. Cookies and Similar Technologies

We use cookies and similar technologies as described in our separate Cookie Policy. Cookies help us to:

  • Ensure basic website functionality
  • Remember your preferences
  • Analyze traffic and site usage (WordPress Stats)
  • Improve user experience

11. Minors

Protection of minors: We do not intentionally collect personal data from minors under 16 without parental consent. If we discover that we have collected data from a minor without consent, we will delete that information immediately.

12. Changes to this Policy

We may update this Privacy Policy occasionally to reflect changes in our practices or for legal reasons. When we make significant changes:

  • We will update the "last updated" date at the top
  • We will notify through our website
  • In cases of substantial changes, we will send email notification

13. Complaints and Supervisory Authority

If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority:

Supervisory Authorities

Italy (Garante): Garante per la protezione dei dati personali
www.gpdp.it
Spain (AEPD): Agencia Española de Protección de Datos
www.aepd.es

14. Contact for Privacy Matters

Data Protection Officer (DPO)

For any queries related to data protection or this privacy policy:

Email: [email protected]
Subject: "Privacy Inquiry - GDPR"
Response: Within 72 business hours