PRIVACY POLICY is the official portal of “BuyFood Toscana”, an event by the Region of Tuscany and the Chamber of Commerce of Florence, organized by Fondazione Sistema Toscana and PromoFirenze, to promote international knowledge of the excellent agri-food products of the Tuscany region. was created and is managed by the Fondazione Sistema Toscana (FST), a legally recognized private entity and in-house provider of the Region of Tuscany, and a tool for carrying out the following institutional aims:

a) development of digital communication for the valorization and promotion of cultural heritage and activities, research and innovation, information society and knowledge;
b) promotion of the integration between cultural offerings and tourism offerings;
c) promotion and diffusion of film and audiovisuals and educational initiatives;
d) film commission activities;
e) promotion and valorization of Tuscan identity and development of youthful policies and rights.


Privacy Information

In compliance with national legislation (Legislative Decree 30 June 2003 n.196, Code regarding the protection of personal data) and community law (European regulation for the protection of personal data n. 679/2016, GDPR) and subsequent amendments, this site respects and protects the privacy of visitors and users, making every possible and proportionate effort not to infringe upon the rights of users.

This privacy policy is valid only for visitors / users and for the online activities of this website and does not apply to information collected through different channels. The purpose of the privacy policy is to provide maximum transparency regarding the information that the site collects and how it uses it.


Data Controller and Data Processor

The Data Controller pursuant to the laws in force is:

Regione Toscana – Giunta regionale
Piazza Duomo, 10
50122 Firenze

The Data Processor, responsible for the processing of the data, by appointment of the Data Controller, pursuant to the laws in force is:

Fondazione Sistema Toscana
Via Duca d’Aosta, 9
50129 Firenze


Data Protection Officer

The Data Protection Officers (DPOs) of the Data Controller and of the Data Processor can be reached at the following e-mail addresses:

Data Protection Officer of the Regione Toscana – Giunta regionale (regional council):

Data Protection Officer of Fondazione Sistema Toscana:


Legal basis for the data processing

Legal basis of the data processing is the Regional Law 22/2016, art. 2 paragraph 2, letter b).

The provision of data is optional, and the user can also request the deletion of data. However, failure to provide data may make it impossible to provide some services and the browsing experience on the site may be compromised.


Collected data and purposes

If the site requests the provision of data, for the purpose of registering for events or surveys, the provision of data is optional; however, it should be noted that participation in the events will not be possible without registration.

Type of data processed: common data (eg. personal and contact details).

Possible categories of interested:  Italian and foreign journalists, operators in the agricultural and agri-food sector, consortia and associations for the protection of the agricultural and agri-food sector, operators of different bodies / associations / institutions (eg. Private Institutions and Sponsors, Universities, organizations of the Chamber system, trade associations etc.), citizens (only if there are initiatives that provide for the management of such data – eg. management of registrations to participate in events).

The processing of personal data, carried out with the aid of electronic means, can be carried out by means of operations such as collection; data registration and organization; consultation, use, processing and interconnection of data; conservation and modification. uses also log files which conserve data collected automatically during a visit to the website. The data collected could be the following:

  • Internet Protocol address (IP);
  • Browser type and parameters of the device used to access the website;
  • Name of the internet service provider (ISP);
  • Date and time of visit;
  • Webpage the visitor connected from (referral), as well as the subsequent page upon exiting;
  • The number of clicks

To ensure security (antispam filters, firewall, survey of viruses), the data registered automatically could be used, in accordance with the relevant current laws, to block attempts to damage the website or other users, as well as damaging or criminal activities. Such data are never used for identifying and profiling the user but are only intended to safeguard the website and its users.

The data collected from the website during its operation are used exclusively for the aims indicated and are conserved for the time necessary for carrying out precise activities or, if applicable, until there is a cancellation request for accounts registered to the website. The data collected from the website will never be passed to third parties for any reason unless there is a legitimate request from judicial authorities and only in cases allowed by law.

By accessing and navigating the website, users accept that the aforementioned data are processed for the written above purposes of IT security and preventing illegal activities. The user can request that their data be cancelled and/or exercise their rights as protected by current laws.


Place of data processing

The data can be processed at the Data Center ex TIX (Tuscany Internet Exchange), Via San Piero a Quaracchi n. 250 – Florence, now part of the Sistema Cloud della Toscana (SCT – Tuscany Cloud System) and at Hetzner Online GmbH, Industriestr. 25 – 91710, Gunzenhausen, Germany. In compliance with community law (European Regulation for the protection of personal data 2016/679,  Art. 28, par. 3), organizations who process personal data on behalf of Data Controller or Data Processor have been appointed as Data (Sub-)Processors,  to ensure compliance with the requirements of the Regulation.

The data relating to any registration, subscription, questionnaire or survey, can be stored at the offices of the Data Controller or Data Processor for strictly the necessary time needed to achieve the purposes for which they were collected. They will then be stored in accordance with the rules on the conservation of administrative documentation and processed exclusively for archiving purposes in the public interest, for scientific research or for statistical purposes in compliance with the principle of data minimization in accordance with art. 89, paragraph 1.

The processing of the data collected will be carried out by authorized personnel of the Data Controller and/or the Data Processor, manually and electronically.

The data provided may be disclosed to other third parties, who collaborate with Regione Toscana and Fondazione Sistema Toscana in the creation of BuyFood Toscana and related events, such as those in the Chamber of Commerce, Assocamere Estero, ICE, the Municipalities of Tuscany, ANCI and producers’ consortia, only if necessary for organizational purposes and in compliance with the requirements of the Regulation.


Content brings together texts and multimedia (texts, images, sounds, video clips, graphics, logos, audiovisuals, etc., henceforth known as “content”) for above written purposes.

The content is produced by:

  • Staff at Fondazione Sistema Toscana (FST)
  • Third parties (content providers, responsible for communications, relators, photographers, videomakers, bloggers, etc.), who grant Fondazione Sistema Toscana permissions for the use of their own textual and multimedia content

All content providers, participating in the event – BuyFood Toscana -, expressly accept the following legal conditions:

  1. They declare and guarantee that they are the sole owners of the authors’ rights to the content (either because they themselves are the authors of the content or because they purchased the rights to use and reproduce it from its legitimate owners); they therefore guarantee FST the content provided, as concerns the legitimacy, veracity, accuracy and legitimate provenance regarding the rights of industrial and/or intellectual property or the laws related to privacy.
  2. They declare and guarantee that the content does not contain images that are offensive, disrespectful or harmful to human dignity and a common sense of decency or that they bear prejudice towards someone or something (including in the form of suspicion or threat). The content must not be discriminatory or incite among the public illegal acts, violence or hate based on religion, skin colour or national or ethnic origin. FST is held harmless of any adverse consequence connected to a violation of this ban.
  3. They declare and guarantee that the content does not include specific information regarding health, race, ethnicity, etc. and that they are submitted with the full responsibility of the providers, with FST limited – for content not produced by its own staff – to simply checking the legitimacy in protection of personal dignity and freedom.

All the content is protected by current laws regarding authors’ rights and intellectual property, and, therefore, unauthorized reproductions, use of content and/or making the content available to the public (even through file-sharing) is not allowed. Anyone who violates this ban is subject to civil and criminal penalties in accordance with the law.


Viewing content from external platforms

This type of service allows you to view and interact with content hosted on external platforms directly from the pages of this site.
If a service of this type is installed, it is possible that, even if users do not use the service, it collects traffic data relating to the pages in which it is installed.

Google Fonts (Google, Inc.)
Google Fonts is a font style visualization service managed by Google, Inc. that allows this site to integrate such content within its pages.
Personal Data collected: Usage data and various types of data as specified in the privacy policy of the service.
Place of date processing: United States – Privacy Policy.

Font Awesome (Fonticons, Inc.)
Font Awesome is a font style visualization service managed by Fonticons, Inc. that allows this site to integrate such content within its pages.
Personal Data collected: Usage data and various types of data as specified in the privacy policy of the service.
Place of date processing: United States –  Privacy Policy.

Widget Google Maps (Google, Inc.)
Google Maps is a map display service managed by Google, Inc. that allows this site to integrate such content within its pages.
Personal Data collected: Cookies and Usage Data.
Place of data processing: United States – Privacy Policy.


Link may contain links to other websites or social media that are not necessarily under the control of the Data Controller and of the Data Processor.

The user is encouraged to carefully read the conditions and terms of operation and use of these sites. The Data Controller and the Data Processor do not assume responsibility either for the unauthorized use of user’s data or for any further monitoring or profiling that may be carried out by the aforementioned sites.


Cookies: management and consent to their use can make use of cookies, small strings of texts that allow for the website to conserve data regarding users’ preferences to improve the site’s operation, simplify navigation by automating processes (ex. login, language) and analyze site use.

Session cookies are essential for distinguishing connected users and are useful for ensuring that a requested function not be provided to the wrong user, as well as for security purposes so as to avoid damaging attacks on the website. Session cookies do not contain personal data and last only as long as the session does, that is, until the browser is closed. Consent is not needed for them.

Functionality cookies used by the website are strictly necessary for operating the site; they are those connected to a user’s request for a specific function (like login).

Statistics, marketing/tracking and social media cookies are described in detail in following sections.


Third-party cookies are, by default, deactivated. The first time an user / visitor accesses the website he can manage consent settings and decide which cookies to accept.


User / visitor can also change the settings in subsequent accesses.


Deleting and disabling cookies

Deleting cookies does not preclude use of the site.

Users / visitors can set the computer browser to accept / reject all cookies or display a warning every time a cookie is proposed, to evaluate whether to accept it or not.

By default, almost all web browsers are set to automatically accept cookies.
Users / visitors can still change the default setting, or disable cookies (i.e., block them permanently), by setting the highest level of protection in the browser, however, disabling them can compromise the use of site functions.

In any case, it remains possible to delete or remove cookies from your device, using the appropriate functions present in the browser. Deleting the cookies does not preclude the use of the site, but involves the repetition of the authentication procedure, or the re-submission of the access credentials.

There are also components (plugins) for the most popular browsers that allow:
• the management (display, cancellation, block) of cookies
• disabling third party JavaScript pages
• visualization of the technologies used by the site
• the visualization and (selective) blocking of the different tracking mechanisms

Cookies can be disabled directly from the browser used, thus denying / revoking consent for the use of cookies. It should be noted that disabling cookies can impede upon the correct use of some functions on the website.


Google Analytics / Tag Manager may include the tools Google Analytics and Tag Manager for monitoring access to the website (number of accesses, new users, number of sessions, visualizations of a page, type of device and browser, etc.) and receiving information regarding user behavior on the website (referral, duration of sessions, bounce rate, etc.) for statistical and market study purposes. FST does not collect users’ personal data because the information related to accessing the website and user behavior are provided by Google Analytics and Tag Manager in an aggregated and non-personalized/anonymous form. However, FST does not respond to the processing of data collected by Google Inc. through Analytics and Tag Manager. Google could use, unbeknownst to FST, personal data for contextualizing and personalizing advertisements on their marketing network. Information about the two Google tools, used only if user enables third-party cookies, are as follows:

  • Google Analytics (Google, Inc.) – Google Analytics is a web analysis service provided by Google, Inc. (“Google”). Google uses the personal data collected for the purposes of tracing and examining site use, compiling reports and sharing them with other services developed by Google.
    Personal data collected: Cookies and usage data
    Processing location: USA – Privacy PolicyOpt Out
  • Google Tag Manager (Google, Inc.) – Google Tag Manager is a statistics service provided by Google, Inc.
    Personal data collected: Cookies and usage data
    Processing location: USA – Privacy Policy


Cookies from Social Networks can use cookies from social networks, to allow for sharing content on social networks. These plugins are programed so as to not register cookies when accessing the page, safeguarding the user’s privacy. The cookies are registered, if allowed by the social networks, only when the user effectively and voluntarily uses the plugin. It should be kept in mind that if the user navigates when logged into the social network, they already consented to the use of cookies transmitted through this website when registering with the social network.

The collection and use of data obtained via the plugin are regulated according to the related privacy policies of the social networks, which users are advised to refer to.

  • Like button and Facebook and Instagram photo social media widgets (Facebook Inc.) – The “Like” button and Facebook social media widgets are services for interacting with Facebook, provided by Facebook Inc.
    Personal Data collected: Cookies and Usage Data.
    Processing location: USA – Privacy Policy.
  • Youtube videos (Google, Inc.) – YouTube is a video viewing service managed by Google, Inc. that allows this application to integrate its content into its pages.
    Personal data collected: Cookies and Usage Data
    Processing location: USA – Privacy Policy


Facebook Pixel

If user enables third-party cookies,’s code may use Facebook Pixel, a tool for collecting statistical data that allows website managers to measure the effectiveness of their advertising by understanding the actions people take on their websites.

Facebook installs cookies for analyzing and improving advertising through remarketing activities to send users messages in line with their interests. Remarketing helps reach users who have visited the website.

  • Facebook Remarketing (Facebook, Inc.) – Facebook Remarketing is a remarketing and behavioral targeting service provided by Facebook, Inc. which connects actions on this website with Facebook’s advertising network.
    Personal data collected: Cookies and Usage Data
    Processing location: United States – Privacy Policy 
  • Facebook Custom Audience (Facebook, Inc.) – Facebook Custom Audience is a remarketing and behavioral targeting service provided by Facebook, Inc. which connects actions on this website with Facebook’s advertising network.
    Personal data collected: Cookies and email address
    Processing location: United States – Privacy PolicyOpt Out.
  • Facebook Analytics for Apps (Facebook, Inc.) Facebook Analytics for Apps is a statistics tool provided by Facebook, Inc.
    Personal data collected: Usage data and various types of data according to what is specified in the service’s privacy policy.
    Processing location: United States – Privacy Policy
  • Conversion tracking of Facebook Ads (Facebook, Inc.)
    Conversion tracking of Facebook Ads is a statistics service provided by Facebook, Inc. that connects the data coming from the social media site’s advertising network with the actions carried out on
    Personal data collected: Cookies and Usage Data
    Processing location: United States – Privacy Policy.


Data sent by external forms

This website may refer to content hosted on external platforms for the management of forms to be filled in for requesting services.

Google Forms (Google, Inc.)
Google Forms is a Google (Google, Inc.) App that allows this site to manage  within its pages questionnaires, quizzes and surveys directly on the Google platform.
Personal Data collected: Usage data and various types of data as specified in the privacy policy of the service.
Place of date processing: United States – Privacy Policy.


E-mail communications

Visitors / users filling out any dedicated forms accept to periodically receive updates about the news as specified in the form itself.
Personal data collected: common data and e-mail addresses
Communications are sent via e-mail to those who specifically fill out the dedicated form and authorize FST to process users’ personal data. Providing this data is optional, but by refusing to provide personal data, the user will be unable to send content via form.


Consenting data processing

First access: when accessing the website for the first time, users will see a message that gives them the option of accepting or refusing the use of technical necessary cookies and third-party cookies on the part of Accepting / enabling cookies, users authorize FST to use the tools listed in this policy for the purposes described and for the type of personal data indicated.

Contact form: by filling in their personal data on contact forms accessible on, users authorize their use for the purposes of responding to requests for information or anything else indicated in the form’s header. In all cases, the user fully accepts the policy of and all the websites/subdomains attributable to  


Security measures

This site processes user data in compliance with legal requirements, taking appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of data. The data processing is carried out using IT and / or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In addition to the Data Controller and Data Processor, in some cases, categories of employees (administrative, commercial, marketing, legal, system administrators) or external subjects (such as third-party technical service providers, hosting providers, IT companies, communication agencies) appropriately appointed in compliance with current regulations, may have access to the data.


User rights

In accordance with EU Regulation 679/2016 (GDPR) and national legislation, users can, within the procedures and limits provided by current law, exercise the following rights:

  • request the confirmation of the existence of personal data regarding him/herself (right to access);
  • be informed of their origin;
  • receive comprehensible communication about them;
  • receive information about the reason, procedures and aims of their processing;
  • request an update, modification, integration, cancellation, transformation into anonymity and blocking of data processes that are in violation of the law, including those no longer necessary for carrying out the aims for which they were collected;
  • in cases of consent-based processing, receive the data provided to the Data Controller, in a structured and legible manner, from a data processor and in a format commonly used by an electronic device;
  • address a complaint to the Supervisory Authority (Warranty Policy);

As well as, more generally, exercise all rights that are recognized by current law.

Requests, including the right to oppose processing, can be addressed to the Data Controller and the Data Processor.



This privacy policy is updated as of August 26, 2022 

BuyFood Toscana è un evento di

Organizzato da Fondazione Sistema Toscana e PromoFirenze

Media Partner