<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=24251303304461540&amp;ev=PageView&amp;noscript=1"> Policy on the wireless Station Internet Service

(Pursuant to art. 13 of European Regulation n. 679/2016)

RFI S.p.A invites you to read this privacy policy carefully before acquiring your personal data to enable you to register for the wireless internet service, access Wi-Fi connectivity and view information about the services available at the station.

I. Data Controller and Data Protection Officer

This section provides the details of our Data Controller and DPO

  • RFI S.p.A., the Data Controller, is represented by the Chief Executive Officer, with registered office in Piazza della Croce Rossa, 1 - 00161 (Rome), who can be contacted at titolaretrattamento@rfi.it.
  • The Data Protection Officer can be contacted by email at: protezionedati@rfi.it.

II. Personal Data Categories 

This section outlines the types of data we ask you for

Below is a list of the personal data processed through the website, within the limits of the purposes defined in this policy:

  • Data acquired directly from the data subject via click-through: mobile phone number.  By means of click through: telephone number;
  • Data acquired automatically while browsing: 
    • The wifistation.it website uses so-called technical cookies which are strictly necessary for the website to function and display correctly. While you are browsing, technical and IT-related information is collected, which is used in an aggregated and anonymous form for the sole purpose of making browsing and using the website faster and more efficient. The data subject’s consent is not required for using these cookies. In any case, you can choose to browse without cookies by disabling them in your browser settings. 
    • We also collect information obtained from the location of hotspots, the mac-address, and browsing data.

During browsing and authentication, technical and IT-related information is collected, which the operator retains solely to comply with legal obligations regarding data that may be requested by the judicial authorities.

Personal data may be processed using manual and computerised methods to ensure that appropriate security and confidentiality measures are in place.

III. Purpose of the Processing

In this section we explain why we are asking you for your data

Your personal data will be processed for the following purposes:

  • Data acquired directly from data subjects via click-through: authentication data is required to grant access to the service (legal basis: contractual).
  • Data acquired automatically while browsing: the mac-address and information obtained from the location of hot-spots are collected to enable you to access the Wi-Fi service at stations (legal basis: contractual).

The data collected may be processed in order to comply with the obligations laid down by current legislation. For example, RFI may use the data collected to handle requests from judicial and/or police authorities (legal basis: Legal).

IV. Data Recipients 

This section describes who will process your data and to whom the data will be disclosed

For the pursuit of the purposes in point III, the personal data acquired will be processed by the following entities:

Scope attributable to RFI S.p.A.

Your personal data shall be made accessible only to those who need to access it due to the task they perform or the hierarchical position they hold. These persons will be appropriately instructed in order to avoid loss, access to the data by unauthorised third-parties or processing that does not conform to the purposes.

In addition, data may be used by the following categories of entities carrying out instrumental activities on behalf of RFI S.p.A.:

  • Service companies (also IT companies) 
  • Companies within the same Group to which RFI S.p.A. belongs

These companies act as Data Processors on behalf of RFI S.p.A. and have signed a special contract that precisely regulates the processing entrusted to them and their data protection obligations.

Scope not attributable to RFI S.p.A.

Your personal data may also be disclosed to other independent data controllers in accordance with statutory or regulatory provisions (e.g. judicial and/or police authorities for the purpose of investigating potential criminal offences). 

The updated list of data recipients is available by contacting the Data Protection Officer at protezionedati@rfi.it.

V. Data Dissemination 

In this section we guarantee that your data will not be disclosed

Your personal data will never be published, exposed or made available to/viewed by unspecified persons, unless required by Law. Certain strictly anonymous information may be used - in aggregated form - to carry out statistical analyses of the number of users and how the service is used, including for the purpose of improving the service itself.

VI. Data Storage

In this section, we indicate how long we will retain your data

RFI will process your data for only the period strictly necessary to achieve the purposes set out and described in paragraph III, and will retain them: 

  • Point III.1, for three months.
  • Point III.2, for a period of 12 months as provided for in Article 132 of the Data Protection Code, subject to a further extension of up to 72 months for the investigation and prosecution of offences - as provided for by current legislation (Article 24 of Law 167/2017) - following the last access to the Wi-Fi network, with the adoption of appropriate security measures to ensure their protection.

VII. Rights of the Data Subjects

In this section we specify the rights we ensure

The EU Regulation 2016/679 (articles from 15 to 23) grants the data subjects the exercise of specific rights. In particular, in relation to the processing of your personal data, you have the right to request Rete Ferroviaria Italiana S.p.A.:

  • Access: the data subject may request confirmation as to whether or not personal data concerning them are being processed, as well as further information about the processing activities described in this Privacy Notice (Art. 15);

  • Rectification: the data subject may request the correction or completion of the personal data provided, where such data are inaccurate or incomplete (Art. 16);

  • Erasure: the data subject may request the deletion of their personal data where such data are no longer necessary for the purposes indicated above, where consent has been withdrawn or the data subject has objected to the processing, where the processing is unlawful, or where there is a legal obligation to erase the data (Art. 17);

  • Restriction of processing: the data subject may request that their personal data be processed solely for storage purposes, excluding other processing activities, for the period necessary to verify or rectify the data; where the processing is unlawful and the data subject opposes erasure; where the data are required for the establishment, exercise or defence of legal claims; or where the data subject has objected to the processing and a verification is pending regarding whether the legitimate grounds of RFI S.p.A. override those of the data subject (Art. 18);

  • Data portability: the data subject may request to receive their personal data, or have them transmitted to another data controller designated by them, in a structured, commonly used and machine-readable format (Art. 20);

  • Objection: the data subject may object at any time to the processing of their personal data, unless there are compelling legitimate grounds for the processing which override their interests, rights and freedoms, such as the establishment, exercise or defence of legal claims by the Company (Art. 21).

At any time you may request to exercise your rights to Rete Ferroviaria Italiana S.p.A. (Data controller), which can be contacted at privacy-dci@rfi.it, or by contacting the Data Protection Officer at protezionedati@rfi.it, or writing to the address P.zza della Croce Rossa n. 1 – 00161 Roma.

Furthermore, in case you consider that your rights have been infringed, you may file a complaint against the Supervisory Authority, which in Italy is the Italian Data Protection Authority.