1. Data controller
The data controller is ALuArts S.r.l., operating through the Rome Opera Concerts brand.
Company: ALuArts S.r.l.
Registered office: Via Gaspare Aselli 46, 00189 Roma, Italia
VAT number: 18330731003
Privacy email: privacy@romeoperaconcerts.com
2. Personal data processed
Technical browsing data
The IT systems and services required to operate the website may collect the IP address, date and time of the request, requested page, browser and device type, operating system, diagnostic data and security logs. These data are used to provide the website, protect its security and identify anomalies or misuse.
Data provided voluntarily
When a user submits the contact form, we may process their full name, email address, optional phone number, subject, message content and any other information voluntarily entered. Users are asked not to submit special-category or unnecessary data.
Booking data
Online bookings and payments are completed through the FareHarbor interface. The Rome Opera Concerts website does not directly collect full payment-card details. ALuArts S.r.l. may nevertheless receive through FareHarbor the booking data needed to organize and provide the purchased service, such as the customer’s name, contact details, number of participants, event date and operational requests.
Analytics and marketing data
Google Analytics 4, Google Ads and any Meta or similar tools are activated only after the user consents to the corresponding category. Without consent, the relevant scripts are not loaded by the website.
Cloudflare Turnstile and anti-spam protection
The contact form uses Cloudflare Turnstile, a security tool that helps distinguish real users from automated submissions and protects the website from spam and abuse.
To perform the verification, Cloudflare may process technical signals such as IP address, User-Agent, TLS fingerprint, sitekey and associated origin. The website uses Turnstile solely for security and form protection, not for advertising purposes.
3. Purposes and legal bases
Personal data are processed only for specified purposes and on the basis of one of the conditions established by Regulation (EU) 2016/679.
| Purpose | Data | Legal basis |
|---|---|---|
| Website delivery, security and maintenance | Technical data and logs | The controller’s legitimate interest in the security and proper operation of the service; compliance with legal obligations where applicable. |
| Responding to information requests and managing contacts | Identification data, contact details and message content | Taking pre-contractual steps at the data subject’s request and the legitimate interest in managing communications. |
| Protecting the contact form against spam, bots and abuse | Technical signals required for anti-bot verification | The controller’s legitimate interest in website security, abuse prevention and protection of contact channels. |
| Managing the booking and providing the purchased concert or experience | Booking data received through FareHarbor | Performance of the contract and compliance with administrative, tax and accounting obligations. |
| Measuring website usage | Online identifiers and analytics browsing data | Consent, which may be withdrawn at any time. |
| Conversion tracking, remarketing and personalized advertising | Online identifiers, interactions and advertising data | Consent, which may be withdrawn at any time. |
4. Bookings and payments through FareHarbor
FareHarbor provides the external infrastructure used to display availability, collect bookings and manage payment. When users enter data in the booking flow or Lightframe, they use a FareHarbor service integrated into or linked from the website.
ALuArts S.r.l. processes the booking data required to perform the contract with the customer. FareHarbor and any payment service providers process data in accordance with their respective roles, contractual terms and privacy notices. Rome Opera Concerts does not directly store full payment-card details.
5. Recipients and service providers
To the extent necessary, data may be disclosed to:
- authorized ALuArts S.r.l. staff and collaborators;
- hosting, maintenance, security and email service providers;
- FareHarbor and providers involved in booking and payment;
- Cloudflare, as provider of the Turnstile service used for anti-bot protection of the contact form;
- Google, when the user consents to analytics or marketing tools;
- Meta or other advertising providers, only if such tools are activated and the user gives consent;
- administrative, tax or legal advisers and public authorities where required by law.
Providers processing personal data on behalf of ALuArts S.r.l. are appointed as processors when required by Article 28 of the GDPR.
6. Transfers outside the European Economic Area
Some technology providers may also process data in countries outside the European Economic Area. In such cases, according to the providers’ statements and where applicable, transfers are based on adequacy decisions, standard contractual clauses or other safeguards provided for by Articles 44 and following of the GDPR.
7. Retention periods
- Technical data and logs: for as long as needed to operate and secure the website, without prejudice to investigations into misuse or incidents.
- Contact requests: for the time needed to respond and, normally, no longer than 12 months after the request is closed, unless a dispute or further obligation applies.
- Contractual, administrative and tax data relating to bookings: for the periods required by applicable law, normally up to 10 years.
- Cookie preferences: stored in the browser for a maximum of 180 days, unless the policy changes or the user deletes them earlier.
- Data processed on the basis of consent: until consent is withdrawn and, in any event, according to the periods stated by the relevant providers and in the Cookie Policy.
- Turnstile token and response: used only to verify the submission and not retained by the website beyond the time needed to complete the check; any technical signals processed by Cloudflare are handled according to the provider’s notice.
8. Data subject rights
Where provided for by the GDPR, the data subject may request:
- access to their personal data;
- rectification of inaccurate data and completion of incomplete data;
- erasure of data;
- restriction of processing;
- portability of data provided, where applicable;
- objection to processing based on legitimate interests;
- withdrawal of consent, without affecting the lawfulness of processing carried out before withdrawal.
The data subject may also lodge a complaint with the Italian Data Protection Authority or contact the competent supervisory authority in their own country.
9. Security, minors and updates
ALuArts S.r.l. adopts proportionate technical and organizational measures to protect data against unauthorized access, loss, alteration or improper disclosure. However, no online system can guarantee absolute security.
The website and booking services are not specifically directed at minors. Bookings must be made by persons with legal capacity to enter into the contract or by a person exercising parental responsibility.
This notice may be updated following legal, organizational or technical changes. The current version is published on this page together with its update date.
10. Contact for exercising your rights
For questions about the processing of personal data or to exercise rights under the GDPR, please write to: