Privacy Policy

Information notice on the processing of personal data, provided pursuant to arts. 13 and 14 of Regulation (EU) 2016/679 (GDPR) to users of the website excerpta.unict.it.


1. Data Controller

[TO BE COMPLETED: full name, registered office, certified email and telephone number of the Data Controller — University of Catania]


2. Data Protection Officer (DPO)

[TO BE COMPLETED: name or office, email address and certified email of the University DPO]


Data subjects may contact the DPO on any matter relating to the processing of their personal data and the exercise of the rights granted by the GDPR.


3. Nature of the website and data not collected

This website is a portal for the consultation of documentary and manuscript material. It has no user registration or authentication, no contact forms, no newsletter subscription, no restricted areas and no payment functions.


No personal data voluntarily provided by users is therefore collected. No special categories of personal data (art. 9 GDPR) and no data relating to criminal convictions (art. 10 GDPR) are processed.


4. Data processed, purposes and legal basis

4.1 Browsing data and technical logs

The computer systems and software procedures used to operate this website acquire, during their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols: IP address, browser and operating system type and version (user agent), URL of the requested resources, date and time of the request, and parameters relating to the user's operating system and computing environment.


  • Purpose: to deliver the requested service, ensure the security of the website and establish liability in the event of computer crimes against the website.
  • Legal basis: art. 6(1)(e) GDPR — performance of a task carried out in the public interest, connected with the University's institutional purposes of research and dissemination of knowledge.

This data is not used to identify users and is not combined with other information.


4.2 Error reporting and performance monitoring

The website uses the Sentry service to detect application errors and monitor performance. The service is configured not to transmit identifying data (the sendDefaultPii option is disabled) and collects only technical information about the error: the page on which it occurred, the type of error and data about the browser environment.


  • Purpose: to identify and fix malfunctions and maintain the efficiency of the service.
  • Legal basis: art. 6(1)(e) GDPR.

The website does not use session recording tools (session replay).


4.3 Language preference

The language selected by the user is stored in a technical cookie. Please refer to the Cookie Policy.


  • Legal basis: art. 6(1)(e) GDPR; technical cookies require no consent under art. 122 of Italian Legislative Decree 196/2003.

4.4 Content search

The manuscript and transcription search functions process the terms entered by the user for the sole purpose of returning relevant results. Search terms are not associated with the user's identity and are not retained in individual profiles.


  • Legal basis: art. 6(1)(e) GDPR.

5. No profiling and no automated decision-making

The website carries out no user profiling and applies no automated decision-making within the meaning of art. 22 GDPR. No analytics, advertising or tracking tools are in use.


6. Recipients of the data

Data may be processed by entities appointed as processors pursuant to art. 28 GDPR, in their capacity as providers of the technical services required to operate the website:


| Provider | Service | |---|---| | Vercel Inc. | Website delivery infrastructure | | DigitalOcean LLC | Content management system infrastructure | | Functional Software Inc. (Sentry) | Application error reporting |


Data may also be disclosed to the competent authorities where required by law or necessary to establish liability in the event of computer crimes.


Data is never disseminated or transferred to third parties for commercial purposes.


7. Transfers outside the European Economic Area

The providers listed in section 6 are established in the United States of America. Transfers of data to them take place on the basis of the standard contractual clauses adopted by the European Commission pursuant to art. 46(2)(c) GDPR, supplemented by the additional measures set out in the agreements concluded with each provider.


[TO BE VERIFIED with the DPO: references of the agreements in place and whether the providers are certified under the EU-U.S. Data Privacy Framework]


8. Retention period

[TO BE COMPLETED: retention periods for application and infrastructure logs and for error events, according to University policy and the providers' retention settings]


Once those periods have elapsed, the data is deleted automatically.


9. Nature of the provision of data

The provision of the browsing data referred to in section 4.1 is inherent in the use of Internet protocols and does not depend on a choice by the user: the website cannot be consulted without such data being transmitted. No other provision of data is required.


10. Rights of the data subject

Data subjects have the right to:


  • obtain access to their personal data (art. 15 GDPR)
  • obtain the rectification of inaccurate data (art. 16 GDPR)
  • obtain the erasure of their data (art. 17 GDPR)
  • obtain the restriction of processing (art. 18 GDPR)
  • object to the processing on grounds relating to their particular situation (art. 21 GDPR)

The right to data portability (art. 20 GDPR) does not apply, as the processing is based neither on consent nor on a contract.


Requests should be addressed to the Data Controller or to the DPO at the contact details given in sections 1 and 2. The Data Controller will respond within one month of receipt of the request, extendable by two months in particularly complex cases.


11. Right to lodge a complaint

Data subjects who consider that the processing of their data infringes the GDPR have the right to lodge a complaint with the Italian Data Protection Authority, Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome, Italy — www.garanteprivacy.it), pursuant to art. 77 GDPR, or to bring proceedings before the competent courts (art. 79 GDPR).


12. Changes to this notice

The Data Controller reserves the right to update this notice in the event of changes to the website, to the services used or to applicable legislation. The version in force is always the one published on this page.


Last updated: [TO BE COMPLETED: publication date]