<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=2358479414501997&amp;ev=PageView&amp;noscript=1">
A A A

 

1.      Introduction

At COLPOFER we are committed to protecting the privacy and personal data of individuals with whom we interact in the context of our institutional and statutory activities.

This Privacy Policy explains how COLPOFER collects, uses, stores and protects your personal data, as well as the rights of data subjects in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – “GDPR”) and applicable data protection laws.

By interacting with COLPOFER, including through membership, participation in events, working groups, communications or other institutional activities, you acknowledge that your personal data may be processed as described in this Privacy Policy.

 

2.      Definitions

  • Personal Data: Any information that can be used to identify you, directly or indirectly, such as your name, contact details, email address, or other identifiers.
  • Processing: Any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
  • Data Controller: COLPOFER (as defined in the applicable data protection laws).

 

3.      What personal data We collect

Depending on the nature of your relationship with COLPOFER and the relevant activities, COLPOFER may process the following categories of personal data:

  • identification and contact details (e.g. name, surname, professional role, organisation, business address, email address, telephone number);
  • data related to dietary restrictions for the participation in COLPOFER events;
  • professional information related to membership, participation in events, committees or working groups;
  • payment and invoicing details, where required for administrative purposes;
  • technical and usage data related to the use of COLPOFER’s websites or digital platforms (e.g. IP address, browser type, cookies).

COLPOFER does not intentionally process special categories of personal data pursuant to Article 9 GDPR, except where strictly necessary and required by applicable law.

 

4.      How We Collect Your Data

We collect your personal data in the following ways:

4.1      Directly from You

  • When you register for our services, events, or newsletters.
  • When you contact us via email, phone, or postal mail.
  • When you complete surveys, forms, or provide feedback.
  • When you use our website or mobile applications.

Note: We will not collect personal data from individuals under the age of 16 unless we have prior consent from an adult guardian.

4.2     Indirectly from Other Sources

  • Publicly available information (e.g., LinkedIn, business directories).
  • Third-party service providers (e.g., event organizers, IT vendors, payment processors).
  • Partners or collaborators with whom we work.

When we receive data from third parties, we ensure they have obtained your consent or are legally authorized to share your information.

 

5.      Legal Basis for Processing Your Data

We process your personal data based on the following legal grounds:

  • Your Consent: For marketing, surveys, or non-essential services.
  • Performance of a Contract: To deliver services, products, or event access you have requested.
  • Legal Obligation: To comply with applicable laws, regulations, or governmental requests.
  • Legitimate Interest: To improve our services, prevent fraud, or communicate with you about updates.

 

6.      How We Use Your Data

We use your personal data for the following purposes:

  • Service Delivery: To provide access to COLPOFER’s deliverables, events, or platforms.
  • Communication: To send you updates, newsletters, or event invitations.
  • Customer Support: To address your inquiries, complaints, or feedback.
  • Marketing: To promote COLPOFER’s services (with your explicit consent).
  • Compliance: To meet legal obligations or prevent fraudulent activities.
  • Analytics: To improve our website, user experience, and business operations.

 

7.      Data Security

We implement robust technical and organizational measures to protect your data, including:

  • Hosting services on secure servers compliant with ISO 27001 and ISO 14001 standards.
  • Encryption of sensitive data during transmission and storage.
  • Regular training for employees on data protection practices.
  • Access controls to restrict unauthorized access.

 

8.      Data Retention

We will delete or anonymize your personal data completely and irreversibly:

  • as soon as the goal for which your personal data have been collected and processed is fully achieved and/or
  • at your specific request (see in this respect section 10 below on your rights with regards to the processing of your personal data).

Unless we are required to keep your personal data longer to:

  • meet any applicable law, regulation, legal process or enforceable governmental request.
  • detect, prevent, or otherwise address fraud, security or technical issues.
  • protect against harm to the legal rights and interests of COLPOFER or its members and stakeholders as required or permitted by law.

Retention periods vary based on the type of data:

General Data: Retained for 5 years after your last interaction.

  • Transaction data: Retained for 10 years (as required by law).
  • Account data: Retained until you request deletion or for 3 years post-termination.
  • Marketing data: Retained while you are subscribed or for 2 years post-unsubscribe.
  • Legal Obligations: Retained as required by applicable laws (e.g., tax, audit, or regulatory requirements).

 

9.      Sharing Your Data

We may share your data with:

  • Service Providers: For IT support, event management, or payment processing.
  • Third Parties: With your consent or as required by law (e.g., law enforcement, regulators).
  • Affiliates or Partners: To collaborate on projects or services.

Note: We will not sell your data for commercial purposes without your explicit consent.

9. Data Transfers

If we transfer your data to countries outside the EU/EEA, we ensure:

  • Adequate safeguards (e.g., standard contractual clauses, Privacy Shield).
  • Compliance with the General Data Protection Regulation (GDPR) and other applicable laws.

 

10.      Your Rights

You have the following rights under data protection laws:

  • Access: Request a copy of your personal data.
  • Correction: Update or rectify inaccurate information.
  • Deletion: Request erasure of your data (subject to legal obligations).
  • Restriction: Limit processing of your data in specific cases.
  • Portability: Obtain your data in a structured, reusable format.
  • Objection: Object to processing for legitimate interests or marketing. To exercise these rights, contact our Data Protection Officer (see Section 12).

 

11.      Cookies and Tracking Technologies

Each time you access and browse our website as a visitor and/or to use the services we offer through our website, we automatically collect personal data from you through the use of cookies.

A cookie is a small piece of data stored in your web browser while you are browsing on our website. When you browse the website again in the future, the data stored in the cookie can be retrieved to notify us of your previous activity.

Our cookies do not store personal information such as your name or your address. We use cookies to enhance the functionality of our website by storing your preferences, for example. We also use cookies to improve the performance of our website in order to provide you with a better user experience.

For more information about the cookies we use, the different types of cookies we use and the way you can manage them, please see our cookie policy at Cookie Policy.

 

12.      Contact Us

For questions, concerns, or requests related to this Privacy Policy:

Data Protection Officer (DPO):

Email: privacycolpofer@fsitaliane.it

 Address:

COLPOFER-Union International des Chemins de fer

c/o Ferrovie dello Stato Italiane SpA

Piazza della Croce Rossa, 1

00161 Roma

Phone: Tel: +39 0644102580

General Inquiries: colpofer@fsitaliane.it or www.colpofer.org

 

13.      Changes to This Policy

We may update this Privacy Policy periodically to comply with any changes in existing applicable legislation, decisions, recommendations, guidelines and best practices issued by the European Data Protection Board and/or other competent authorities with regard to the implementation or interpretation of applicable legislation. The revised version will be posted on our website, and we will notify you of significant changes via email or other communication channels.