Information pursuant to Articles 13 and 14 of EU Regulation 2016/679

(rev. 0 of 24/07/2026)

EU Regulation 2016/679 (hereinafter, the “Regulation” or “GDPR”) lays down the rules relating to the
protection of natural persons with regard to the processing of personal data and to the free movement of
such data, and protects the fundamental rights and freedoms of natural persons and, in particular, their
right to the protection of personal data.

This notice is issued by Fondazione Roma – Salus (hereinafter, for brevity, the “Foundation”) pursuant to
Article 13 of the Regulation, in relation to the processing of personal data carried out through this website
(www.villaggiofondazioneroma.it) of the facility known
as Villaggio Fondazione Roma, located in Rome, Via Ernesto Calindri no. 40 (hereinafter, for brevity, the
“Village”) of the Foundation.

Data processing is carried out to the extent compatible with the purposes described in this notice and is
based on the principles of fairness, lawfulness and transparency, in compliance with security measures.

1. WHY THIS INFORMATION

The Foundation pays particular attention to privacy and wishes visitors to this website to feel safe, both
while browsing and should they decide to provide their personal data in order to make use of the services
or features available on the site.

This document constitutes the “Privacy Policy” and “Cookie Policy” of this website and is intended to
describe the purposes and methods by which the site is managed with regard to the processing of personal
data.

This notice applies exclusively to the website
www.villaggiofondazioneroma.it, in accordance with the
applicable sector regulations. This information does not cover external sites or services that may be
reached via links present on the site.

In relation to specific processing activities, the Controller may also provide additional notices and,
where necessary, request the user’s consent through clear and transparent means.

The Controller, depending on the specific nature of the processing, may provide additional notices beyond
this one and, where necessary, request the user’s consent through clear and transparent means.

2. DATA CONTROLLER

The Controller of personal data (hereinafter the “Controller”) for the facility known as “Villaggio
Fondazione Roma” is Fondazione Roma – Salus, with registered office in Rome (00138), Via Ernesto Calindri
no. 40.

Contact details:

3. DATA PROTECTION OFFICER (DPO)

The Data Protection Officer (DPO) is Maurizio Belli of Associazione Università del Lavoro ETS. The DPO can
be contacted at: dpo_fr@unilavoro.org.

4. PURPOSES OF PROCESSING

Personal data are processed for the following purposes:

  • to ensure the operation, management, maintenance and security of the site, preventing misuse or fraudulent activity;
  • to handle contact and information requests and any further voluntary communication from the user through the contact form and the email addresses provided on the site’s pages;
  • to manage the services provided through the website, such as requests for admission to the Village, submitted using the form provided for that purpose;
  • to manage unsolicited job applications and applications submitted in response to personnel searches via the “Work with us” page;
  • to comply with legal or regulatory obligations;
  • to assert or defend a right in court, where and if necessary;
  • to manage administrative activities connected with and instrumental to the purposes set out above.

5. LEGAL BASIS FOR PROCESSING

The processing of personal data is lawful on the following grounds:

  • the necessity to perform contractual or pre-contractual obligations to which the data subject is party, such as managing the contact form, information requests, the provision of services and the management of the site’s features (Article 6(1)(b) GDPR);
  • compliance with legal obligations to which the Controller is subject under applicable laws or regulations (Article 6(1)(c) GDPR);
  • the Controller’s legitimate interest, such as the management, optimization, monitoring and security of the site (Article 6(1)(f) GDPR);
  • the data subject’s consent to the processing of personal data (where required); in such cases, arrangements are put in place for obtaining explicit, transparent and voluntary consent (Article 6(1)(a) GDPR).

6. TYPES OF PERSONAL DATA

6.1 BROWSING DATA

The computer systems and software procedures used to operate this website acquire, in the course of their
normal operation, certain personal data whose transmission is implicit in the use of Internet communication
protocols. This information is not collected in order to be linked to identified data subjects, but by its
very nature could, through processing and association with data held by third parties, enable users to be
identified.

This category of data includes the IP addresses or domain names of the computers used by users connecting
to the site, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the
request, the method used to submit the request to the server, the size of the file obtained in response,
the numerical code indicating the status of the response given by the server (success, error, etc.) and
other parameters relating to the user’s operating system and computing environment.

This data is used solely to obtain general, anonymous statistical information on the use of the site and to
check that it is functioning correctly, and is generally deleted after processing. It is not used to
identify users, for profiling purposes, or for purposes other than those stated. Such data could be used to
establish liability in the event of hypothetical computer crimes against the site; in such circumstances,
requests made by the Judicial Authority will be complied with.

Browsing data is not retained for more than seven days, except where required for the investigation of offences by the Judicial Authority.

6.2 DATA VOLUNTARILY PROVIDED BY THE USER

6.2.1 Data provided by the user via email

The optional and voluntary sending of messages and communications to the email addresses shown on the site
results in the Controller acquiring the user’s email address (the sender of the message) and any other
personal data voluntarily included by the user in the communication. Such data will be processed solely to
handle the request received and to provide a response to the user. Processing and retention are strictly
limited to the management of the request and will not, in any event, exceed the periods prescribed by
applicable laws, regulations and measures.

Messages voluntarily sent by users are handled through email accounts and/or databases accessible only to
persons authorized by the Controller as personnel authorized to process data or as processors pursuant to
Article 28 GDPR.

6.2.2 “Contact” form

Users may also submit personal data and information through the “Contact” form available on the site.
Users who choose to use the “Contact” form are aware that they must provide their name, email address,
telephone number and the content of the message they wish to send. The name and email address fields are
mandatory, as they are necessary for the Foundation to respond to the request voluntarily submitted by the
user.

6.2.3 “Work with us” page

The “Work with us” page allows users to submit unsolicited applications or to apply for positions
advertised by the Foundation. Users who decide to submit an application via the dedicated page are aware
that they must provide their name, email address, telephone number, the content of the message they wish
to send, and their curriculum vitae.

6.2.4 Further processing of personal data

Any further processing carried out through this site may be subject to additional notices beyond this
policy; users will be able to view these on the relevant pages, where and if applicable.

6.3 Cookies and other tracking tools

6.3.1 What cookies are

Cookies are small text strings that sites visited by the user send to their terminal (usually the browser),
where they are stored and then re-transmitted to the same sites on the user’s next visit. While browsing a
site, a user’s terminal (computer, smartphone, tablet, etc.) may also receive cookies sent by different
sites or web servers (so-called “third parties”), on which certain elements present on the site being
visited may reside (such as images, maps, sounds, or specific links to pages on other domains).

Cookies, which are usually present in very large numbers in users’ browsers and sometimes have significant
temporal persistence, are used for various purposes, such as performing computer authentication, monitoring
sessions, and storing information about the specific configurations of users accessing the server.

Cookies therefore serve to enable the functionality of web pages, to improve the user’s browsing experience,
and to provide site owners with certain information necessary to optimize functionality.

By using a site, users generally accept that “first-party” and “third-party” cookies (where present) will
be installed on their device. The storage of cookies can be disabled in whole or in part; in such
circumstances, the navigability of the site (or of certain sections of it) may be compromised or limited
due to the absence of certain features linked to the disabled cookies.

6.3.2 Types of cookies

Technical cookies: these are used solely for the transmission of a communication over an
electronic communications network, or as strictly necessary for the provider of an information society
service explicitly requested by the subscriber or user to provide that service. They are not used for any
further purposes and are normally installed directly by the site’s owner or operator.

They can be divided into:

Browsing or session cookies: these ensure normal browsing and use of the website (allowing,
for example, authentication to access restricted areas) and are essential for the site to function
correctly; without these cookies, certain features may be impaired and access to content may be limited.

Analytics cookies, treated in the same way as technical cookies where used directly by the
site operator to collect information, in aggregate form, on the number of users and how they visit the
site; these cookies are used to understand whether users are new or returning, how they use the site, how
they navigate between pages, how long they remain on pages and on the site, and the geographic area from
which they accessed the site. This data does not identify the user as an individual and is aggregated
anonymously by the analytics tools. Disabling these cookies does not in any way compromise the functionality
offered by the site.

Functionality cookies: these allow users to browse according to a set of selected criteria
in order to improve the service provided to them. This type of cookie may include personal information.
Without these cookies, certain features and navigation between pages may be impaired.

Prior user consent is not required for the installation of these cookies.

Profiling cookies: these are designed to create user profiles and are used to send
advertising messages in line with preferences expressed by the user while browsing the web. Given the
particularly intrusive nature these devices can have on users’ private sphere, prior user consent is
required for their installation.

These cookies are installed to show site visitors content related to their preferences. They can therefore
be used to display advertising content targeted to the individual’s interests. Cookies of this type operate
in conjunction with third-party sites and can track past browsing on pages located on different domains.
Cookies of this type usually track, among other things, the user’s IP address, along with other
information, some of which may be personal in nature.

Another type of profiling cookie is the social widget cookie (third party); some widgets made available by
social networks (such as Facebook, Twitter, YouTube, Google Maps, etc.) may use their own cookies.

Disabling such cookies does not compromise use of the site, except in sections where widgets (for example,
for embedding videos or maps) and elements containing profiling cookies may be installed.

Other features characterizing cookies include:

  • duration, according to which cookies can be distinguished as session cookies
    (temporary files stored until the site is left or the browser is closed) and persistent cookies
    (files that are stored and retained even after leaving the site and closing the browser, and are deleted
    after the expiry date indicated in the cookie itself);
  • the parties involved, according to which cookies can be distinguished as
    first-party cookies (cookies installed on the user’s device directly by the operator of
    the site being browsed – the Controller) and third-party cookies (cookies installed by
    external sites through the site being browsed; examples include those installed by social plugins or
    visit-analysis cookies).
6.3.3 Cookies used on this site

The Foundation uses only technical cookies (browsing or session cookies), necessary for safe and efficient
browsing. No personal data is acquired or retained through such cookies. The site:

  • does not use profiling cookies;
  • does not use persistent cookies for personal purposes;
  • does not use tracking methods;
  • allows the use of third-party cookies only for analytics purposes treated in the same way as technical cookies.

Technical and session cookies: session cookies are temporary and are deleted when the
browser is closed. Technical cookies, necessary for the site to function, may also include persistent
cookies and are retained for a maximum of seven days.

Analytics cookies: used to collect anonymous information on how the site is used
(statistics, browsing flows, performance). The service used is Google Analytics, provided by Google Inc.,
which processes aggregated data for statistical analysis and site improvement purposes. Google may also use
such data to personalize advertisements within its own advertising network.

Third-party cookies: set by sites other than the Controller’s, these are used to collect
information on how the site is used by visitors. The relevant controllers process such data independently
and have their own privacy and cookie policies, separate from that of this site. The Controller is not
responsible for processing carried out by such third parties. For further details on third-party cookies
involving data transfers, please refer to the respective privacy and cookie policies.

6.3.4 Cookies present on the site
Cookie Duration
_ga_42JJT8DNH5 1 year 1 month
_ga 1 year 1 month
pll_language 1 year 1 month
cmplz_banner-status 1 year
cmplz_consented_services 1 year
cmplz_functional 1 year
cmplz_marketing 1 year
cmplz_policy_id 1 year
cmplz_preferences 1 year
cmplz_statistics 1 year
6.3.5 Third-party plugins

In order to ensure the management and functionality of the site, some pages may include plugins also
managed by third parties. As with cookies, these tools may involve the processing of personal data,
including the transfer of such data to third parties in the event of interaction with other websites. In
other cases, plugins are necessary for technical functions essential to the operation of the site.

6.3.6 Disabling cookies

The site works best with cookies enabled. Disabling certain types of cookies does not affect the general
use of the site, but disabling all cookies, including technical cookies, may mean that some features are
not fully available.

Most browsers accept cookies automatically. Users can change their browser settings at any time to
restrict or block cookies, accept them all, receive a warning when they are activated, or refuse them
entirely. Since each browser uses different procedures, it is advisable to consult the “Help” section of
the browser in use. For convenience, links for managing cookies in the most widely used browsers are
provided below:

7. RECIPIENTS OF PERSONAL DATA

Data collected through the Site is processed by 1•618® S.r.l. (www.1-618.it – privacy@1-618.it), appointed by the Controller as Processor pursuant to Art. 28 GDPR and as system
administrator, for the management of servers, databases, the platform, cloud services, updates, support,
maintenance, development, design, performance monitoring and security of the Site, backup of web space and
content management of the Site, as well as for the management of the services provided through the site.
The personal data collected is also processed by Foundation personnel who act on the basis of specific
instructions in their capacity as authorized personnel. Any further recipients may include public bodies or
authorities to which disclosure is mandatory by law. The data is not disclosed to the public.

8. PLACE OF PROCESSING

Processing takes place at the Controller’s premises and at the premises of the Processors. In particular,
the Site’s technical infrastructure, managed by 1•618® S.r.l., is hosted on servers located in Italy, at
Tier IV-certified data centers, which ensure high standards of security, redundancy and operational
continuity.

9. TRANSFER OF DATA TO A THIRD COUNTRY

Personal data is not transferred outside the European Union: the servers hosting the Site and the related
data, managed by 1•618® S.r.l., are located in Italy at Tier IV-certified data centers. Any future
transfers to non-EU countries will take place only in compliance with applicable law, ensuring adequate
levels of protection through European Commission adequacy decisions, contractual safeguards pursuant to
Art. 46 GDPR, or binding corporate rules. Data subjects will be informed promptly.

10. DATA RETENTION PERIOD

Browsing data is retained for seven days and then automatically deleted. Other personal data is retained
in accordance with applicable law, in compliance with the principle of proportionality and for the time
necessary to achieve the purposes of processing. Please refer to the retention periods indicated in the
preceding paragraphs relating to the type of personal data processed and the list of cookies.

11. CONSEQUENCES OF REFUSING TO PROVIDE DATA

For certain purposes, such as browsing the site, its operation, technical cookies, and security management,
the processing of data is necessary and essential, as it is aimed at the operation of the site and its full
usability by the user.

With regard to services and voluntary communications, however, users are free to provide their data by
choosing whether or not to make use of the features offered through this portal. With regard to cookies,
please refer to the specific paragraph and to the banner for managing consent to the processing of personal
data, as specified in the relevant paragraph.

We are required to inform users that failure to provide personal data, even in part, may result in the
objective impossibility of receiving a response from the Foundation, of handling requests submitted by the
user, or, in cases of objection to all processing, the impossibility of making use of the features and
browsing capabilities of the site.

12. METHODS OF PROCESSING

Data is processed in accordance with applicable sector regulations and is stored in such a way as to
ensure its confidentiality, to prevent its destruction or use by unauthorized third parties, and in
compliance with specific security measures. Processing is carried out using paper-based, IT and electronic
means, solely by authorized personnel.

13. RIGHTS OF DATA SUBJECTS

In relation to the processing of personal data described above, the Regulation establishes the rights of
data subjects set out in Articles 15, 16, 17, 18, 19, 20, 21 and 22, and in particular:

  • Art. 15 – Right of access: data subjects have the right to obtain confirmation as to whether or not personal data concerning them is being processed and, if so, to obtain access to the personal data, together with information on its origin, the purposes and methods of processing, the recipients to whom the data will be disclosed, and the logic applied in the case of processing carried out with the aid of electronic tools.
  • Art. 16 – Right to rectification: data subjects have the right to obtain, without undue delay, the rectification of inaccurate personal data concerning them.
  • Art. 17 – Right to erasure: data subjects have the right to obtain the erasure or anonymization of personal data concerning them (where the specific grounds set out in Art. 17 of the Regulation apply).
  • Art. 18 – Right to restriction of processing: data subjects have the right to obtain restriction of the processing of personal data concerning them (where the specific grounds set out in Art. 18 of the Regulation apply).
  • Art. 19 – Right to notification of rectification, erasure or restriction: the Controller is required to communicate any rectification, erasure or restriction of processing carried out pursuant to Articles 16, 17 and 18 to each recipient to whom the personal data has been disclosed, unless this proves impossible or involves disproportionate effort.
  • Art. 20 – Right to data portability: data subjects have the right to receive personal data concerning them in a structured, commonly used and machine-readable format, and to have the personal data transmitted directly from one controller to another, where technically feasible.
  • Art. 21 – Right to object: data subjects have the right to object to processing (where the specific grounds set out in Art. 21 of the Regulation apply), and the Controller must refrain from further processing the personal data in question, except in certain cases as set out in that same article.
  • Art. 22 – Right not to be subject to a decision based solely on automated processing: data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

Pursuant to Art. 7 of the Regulation, the right to withdraw consent given is also among the rights of data
subjects. Withdrawal of consent does not affect the lawfulness of processing based on consent given before
its withdrawal.

Data subjects also have the right to lodge a complaint (Art. 77 GDPR) or to bring proceedings before the
competent courts (Art. 79 GDPR) if they believe that processing has taken place in violation of the GDPR.

The exercise of the rights set out above is subject to the limits, rules and procedures set out in EU
Regulation 679/2016. Furthermore, in accordance with Article 12(3), the Controller will provide the data
subject with information on the action taken without undue delay and, in any event, at the latest within
one month of receipt of the request. This period may be extended by two further months, where necessary,
taking into account the complexity and number of requests. The Controller will inform the data subject of
any such extension, and of the reasons for the delay, within one month of receipt of the request.

To exercise their rights, data subjects may contact the details provided below, using the form available
on the website of the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali,
GPDP), also accessible via the following link: garanteprivacy.it – forms

Controller’s contact details for exercising the rights provided for under the Regulation:

14. CHANGES TO THIS PRIVACY POLICY

This Privacy & Cookie Policy is subject to periodic updates. The Controller reserves the right to
amend it at any time, informing users on this page. Users are encouraged to regularly review this document
to stay up to date on any changes.