Privacy Policy
Last updated: 23 September 2026
This policy explains what personal data is processed when you visit viadelleabbazie.com (Italian, English and Spanish versions), for what purposes, on what legal basis, and what rights you have. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003 (the “Italian Privacy Code”), as amended by Legislative Decree 101/2018.
This is a translation provided for convenience. In case of discrepancy, the Italian version prevails.
1. Data controller
The data controller is Andrea Bariselli, a private individual, who created and runs the “Via delle Abbazie” project.
Via delle Abbazie is an amateur, non-profit project whose only aim is to share knowledge: the site sells no products or services, and the data collected is not used for marketing.
For any question about this policy, or to exercise your rights, write to thaleaproject@gmail.com.
No Data Protection Officer (DPO) has been appointed, as one is not required for this kind of processing.
2. What data we process and why
2.1 Technical browsing data (hosting)
This is a static website hosted by Netlify, Inc. Like any web server, Netlify's infrastructure automatically logs some technical data about each request: IP address, date and time, page or file requested, response code, browser and operating system, referring page.
- Purpose: to deliver the pages, keep the service secure and prevent abuse or cyber attacks.
- Legal basis: the controller's legitimate interest in providing a working, secure website (Art. 6(1)(f) GDPR).
- Retention: for the limited period set by the hosting provider for technical and security purposes. The controller does not use this data to identify visitors.
2.2 Project updates form
If you fill in the project updates form, you give us your name, email address, route of interest (Ponente, Centro or Levante), approximate travel period and preferred language. The form is handled through Netlify Forms; notifications of new sign-ups are sent to the controller's email inbox.
- Purpose: solely to send you updates about the project (development and publication of the tracks, the opening planned for 2027, any free group get-togethers) and to understand, in aggregate, which routes and periods people are most interested in. No commercial, promotional or marketing purpose.
- Legal basis: your consent (Art. 6(1)(a) GDPR), given by ticking a dedicated box that is not pre-ticked.
- Is it mandatory? No. Your name and email address are needed for us to write to you; the other fields help us send you relevant information.
- Retention: until you withdraw your consent, or until the project ends if that happens first. After withdrawal your data is deleted, except for what is needed to show that we honoured your request.
- Withdrawal: you can withdraw your consent at any time, at no cost, via the link included in every message or by writing to thaleaproject@gmail.com. Withdrawal does not affect the lawfulness of processing carried out before it.
Form data is not used for profiling or for any commercial purpose, is not passed on, and is not shared with third parties for their own purposes.
The form is intended for people aged 14 or over (Art. 2-quinquies of the Italian Privacy Code). If you are under 14, please ask a parent to sign up for you.
2.3 Email enquiries
If you write to us (for example as an abbey, accommodation provider, guide or public body), we process the data contained in your message (name, email address, any organisation you belong to, and whatever you tell us).
- Purpose: to reply and to manage your request or any resulting collaboration, always on a non-commercial basis.
- Legal basis: steps taken at your request prior to or under a contract (Art. 6(1)(b) GDPR) and our legitimate interest in handling correspondence (Art. 6(1)(f)).
- Retention: for as long as needed to handle the request and any resulting relationship; messages are then deleted, unless the law requires otherwise.
2.4 Visitor statistics (Google Analytics 4), only with your consent
We use Google Analytics 4 to understand, in aggregate, how many people visit the site, which pages they read and which countries they come from. The tool is only switched on if you click “Accept” in the cookie banner.
- Before consent: Google Consent Mode v2 is set to “denied” for every category; no analytics cookies are stored and no data is sent to Google.
- After consent: Google Analytics sets the
_gaand_ga_E7JGXSFGLScookies (see the cookie policy) and collects pseudonymous usage data: pages visited, visit duration, device and browser type, approximate location (country or city). According to Google, for visitors in the European Union the IP address is used only to derive approximate location and is then discarded without being logged. - What we don't do: we do not enable advertising features, Google Signals or data sharing with Google for marketing purposes; the
ad_storage,ad_user_dataandad_personalizationsignals always remain “denied”. - Legal basis: your consent (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code).
- Retention: usage data is kept in Google Analytics for 14 months and then deleted automatically.
- Withdrawal: you can change your mind at any time via the “Manage cookies” link at the bottom of every page.
2.5 Interactive maps
The maps use map images (“tiles”) provided by Esri, Inc. (ArcGIS Online). To show you a map, your browser downloads the tiles directly from Esri's servers, so Esri receives your IP address and the technical data of the request (browser, referring page), as happens with any web content. The site sets no cookies for the maps and sends no other data to Esri.
- Legal basis: legitimate interest in providing route maps, an essential feature of the site (Art. 6(1)(f) GDPR).
- Esri processes the technical request data under its own privacy statement: esri.com/privacy.
2.6 Fonts, photos and libraries
The fonts, photographs and JavaScript libraries used by the site are served by the site itself: your browser does not contact third-party servers to display them, and no third-party cookies are set.
2.7 GPX tracks, PDF guides and credential
GPX files, PDF guides and the pilgrim credential are generated directly in your browser. Any name, date or route you type into the credential stays on your device: we do not receive or store it.
2.8 Links to external sites
The site links to external services (for example Instagram or the newsletter on Substack). These services only receive your data if you click the link, and they process it as independent controllers under their own policies.
3. Who receives the data
Data is processed by the controller and, on his behalf, by the technical providers that are strictly necessary. They act as processors (Art. 28 GDPR) under their data processing agreements:
- Netlify, Inc. (San Francisco, USA): website hosting and handling of the project updates form;
- Google Ireland Ltd and Google LLC (USA): Google Analytics 4, only with your consent, and the Gmail service the controller uses to receive messages and notifications.
Esri, Inc. (Redlands, USA) receives the technical data of the map tile requests described in section 2.5 and processes it under its own privacy statement.
komoot GmbH (Potsdam, Germany): on the stage pages the Komoot route only loads if you click "Show the route on Komoot". Only then does your browser connect to Komoot's servers, which receive your IP address and technical data and may use their own cookies, under their privacy policy: komoot.com/privacy. The "Open on Komoot" links take you to Komoot's website.
Data is not published or sold. It may be disclosed to authorities only where required by law.
4. Transfers outside the European Union
Netlify, Google and Esri are based in, or have servers in, the United States. Transfers rely on the European Commission's adequacy decision of 10 July 2023 on the EU-U.S. Data Privacy Framework (Art. 45 GDPR): Netlify, Inc., Google LLC and Esri, Inc. appear as certified on the official list at dataprivacyframework.gov. Where applicable, the providers also use the Standard Contractual Clauses approved by the Commission (Art. 46 GDPR).
5. Your rights
You can exercise the rights set out in Articles 15 to 22 GDPR at any time:
- access to your data and to information about the processing (Art. 15);
- rectification of inaccurate or incomplete data (Art. 16);
- erasure (Art. 17);
- restriction of processing (Art. 18);
- portability of the data you provided, in a commonly used format (Art. 20);
- objection to processing based on legitimate interest (Art. 21);
- withdrawal of consent at any time, without affecting the lawfulness of earlier processing (Art. 7(3)).
We do not make decisions based solely on automated processing, including profiling, that produce legal effects on you or similarly significantly affect you (Art. 22).
To exercise your rights, write to thaleaproject@gmail.com. We will reply without undue delay and in any case within one month of your request, which may be extended in the cases provided for by Art. 12(3) GDPR. We may ask for information to verify your identity.
6. Right to lodge a complaint
If you believe the processing of your data infringes the GDPR, you can lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy, www.garanteprivacy.it (Art. 77 GDPR), or with the supervisory authority of the EU country where you live or work or where the alleged infringement took place.
7. Security
The site is served only over an encrypted connection (HTTPS). We collect only the data needed for the purposes described, and access to form data is limited to the controller.
8. Changes to this policy
We may update this policy, for example if we add new services. The date of the latest update is shown at the top. If changes affect consent-based processing, we will ask for your consent again where needed.
Legal references
- Regulation (EU) 2016/679 (GDPR), in particular Arts. 6, 7, 12-22, 28, 44-46 and 77.
- Italian Legislative Decree no. 196 of 30 June 2003 (Personal Data Protection Code), as amended by Legislative Decree no. 101 of 10 August 2018, in particular Arts. 2-quinquies and 122.
- Italian Data Protection Authority (Garante), “Guidelines on cookies and other tracking tools”, 10 June 2021 (doc. web no. 9677876).
- Commission Implementing Decision of 10 July 2023 on the adequate level of protection of personal data under the EU-U.S. Data Privacy Framework.