Privacy & Cookie Policy
The purpose of this document is to inform the natural person (hereinafter “Data Subject”) about the processing of his/her personal data (hereinafter “Personal Data”) collected by the data controller, Dante AI S.r.l., with registered office at Via Bocchetto, 6, 20123 Milano, Italy, VAT No. 03341790594, email dante[at]esplorando.ai (hereinafter “Data Controller”), via the application Esplorando (hereinafter “Application”).
Changes and updates will be effective as soon as they are published on the Application. In case of non-acceptance of the changes made to the Privacy Policy, the Data Subject shall stop using this Application and may ask the Data Controller to delete his/her Personal Data.
1. Types of Data Processed
- Contact and Account Data:First name, last name, e-mail address, phone number, authentication credentials (login), profile pictures, and any further personal information sent by the Data Subject during registration.
- Fiscal and Payment Data: Tax code, VAT number, credit card data, bank account details, and transaction history required to process purchases of tickets and vouchers within the Application.
- Data related to AI Interaction (Prompts and Preferences): Information, questions, text
inputs ("Prompts"), travel preferences, interests (e.g., art, food, history), and schedules voluntarily shared
by the Data Subject while interacting with the internal Chatbot.
Special Note: If the Data Subject voluntarily provides special categories of data (e.g., health data such as food allergies, motor disabilities for accessibility, or religious orientation for dietary requirements) within the chat, these will be processed solely to filter the internal database and provide the requested information or service.
The Data Controller processes the following types of Personal Data collected automatically:
- Technical Data:Personal Data produced by devices, applications, tools and protocols such as information about the device used, IP addresses, browser type, type of Internet provider (ISP), and operating system.
- Usage Data: Pages visited, number of clicks, actions taken, duration of sessions, and interaction history.
- Geolocation Data: Data relating to the exact location of the Data Subject (e.g., GPS coordinates). This data is collected only with the specific consent of the Data Subject to allow the App to provide location-based suggestions and services. The Data Subject may withdraw consent at any time via the device settings.
If the Data Subject decides not to provide Personal Data for which there is a legal or contractual obligation, it will be impossible for the Data Controller to establish or continue any relationship with the Data Subject.
2. Cookies, Identifiers and Third-Party Services
The Application uses local storage technologies (e.g., "Local Storage") and technical identifiers strictly necessary for the operation, security, and maintenance of the Data Subject's session (e.g., automatic login). Consent is not required for these technical tools:
Third-Party Services:
- Stripe: During the payment process, Stripe may use cookies or technical identifiers for security and fraud prevention purposes.
- External Links: By clicking on links to external platforms, the Data Subject leaves the Application. Such sites may install their own cookies; please refer to their respective Cookie Policies.
3. Legal basis and purpose of data processing
The processing of Personal Data is necessary:
- a. For the performance of the contract with the Data Subject:
- Provision of AI-Assisted Services: To process the Data Subject's inputs through the internal Chatbot in order to retrieve and organize information exclusively from the Data Controller's internal databases (e.g., itineraries, points of interest, schedules).
- Registration and Authentication: To allow the Data Subject to register and access the Application.
- Management of Payments and Orders: To process the purchase of tickets, vouchers, and services offered via the Application.
- Support: To answer the Data Subject's requests.
- b. On the basis of the Data Subject's consent:
- Geolocation Services: To detect the presence of the Data Subject in a specific place to offer real-time, location-based information retrieved from the internal database.
- Marketing and Notifications: To send push notifications, commercial/promotional materials, or to perform direct sales activities regarding the Data Controller’s products/services.
- Profiling for Marketing: To analyze the Data Subject's preferences (derived from interactions and usage) to provide customized advertisements or personalized offers.
- c. For the Legitimate Interest of the Data Controller:
- Security and Anti-fraud: To guarantee the security of the Application’s infrastructure.
- Service Optimization: Aggregated and anonymized data may be used to analyze interaction patterns to improve the relevance of the results provided by the Application.
- Legal Defense: To protect the Data Controller in judicial proceedings.
4. Data processing methods and receivers of Personal Data
The processing of Personal Data is performed via paper-based and computer tools with logic strictly related to the specified purposes. Personal Data are processed exclusively by:
- Persons authorized by the Data Controller committed to confidentiality (e.g., administration, support staff).
- Third-party Service Providers: Subjects designated as Data Processors acting on behalf of the Data Controller, including:
- Hosting and Cloud Providers: Companies providing the secure servers where the Application and its databases reside.
- Payment Processors: Stripe (for direct purchases of partner tickets, e.g., Arte&Musei), which processes payment data autonomously and securely.
- Affiliate Platforms: In the event of purchasing external services (e.g., tours via Viator), the user is redirected to the third-party platform which acts as an independent Data Controller.
- Subjects or bodies to whom it is mandatory to communicate Personal Data by law.
The subjects listed above are required to use appropriate measures and guarantees to protect Personal Data and may only access data necessary to perform their duties. User prompts and personal data are not shared with third-party AI training models.
5. Place of Processing
Personal Data are processed at the Data Controller's operating offices and in any other places where the parties involved in the processing are located. Personal Data are stored on servers located within the European Economic Area (EEA). Personal Data will not be transferred outside the EEA.
6. Personal Data storage period
Personal Data will be stored for the period required to fulfill the purposes for which it was collected:
- Contractual & Service Data: Stored for the duration of the relationship and for 10 years thereafter for administrative/tax obligations.
- Chat History & Interactions: Stored for the time necessary to provide the service (e.g., duration of the session or trip planning) and subsequently deleted or anonymized.
- Marketing & Profiling Data: Stored until consent is revoked.
- Geolocation Data: Processed in real-time and not stored permanently associated with the user identity, unless necessary for the continuity of the service requested.
6. Rights of the Data Subject
Data Subjects may exercise specific rights regarding the Personal Data processed by the Data Controller (Articles 15-22 GDPR). In particular, the Data Subject has the right to:
- Withdraw consent at any time.
- Access their Personal Data and request a copy.
- Verify and request rectification of their Personal Data.
- Obtain the restriction of processing.
- Obtain the erasure (Right to be Forgotten) of their Personal Data.
- Object to the processing of their Personal Data.
- Data Portability: Receive their data in a structured, commonly used format.
- Lodge a complaint with the competent supervisory authority.
To exercise these rights, Data Subjects may send a request to the following e-mail address: dante[at]esplorando.ai. Requests will be processed within 30 days.