AS Roma Privacy Policy

SUMMARY INFORMATION ON THE PROCESSING OF PERSONAL DATA

PURSUANT TO REGULATION (EU) 2016/679

Last update: effective as of March 16th, 2026 

This page describes how AS Roma manages the website https://www.asroma.com/ (“Website”) with regard to the processing of personal data of users who access and browse the team’s web page and who use the services offered through the Website and platforms (“AS Roma Platforms”) of AS Roma S.r.l. and Soccer S.r.l., as joint controllers ("Joint Controllers," "Companies," "We" or jointly "AS Roma Entities"). This policy is provided only for the Site and the AS Roma Platforms and not for other websites and platforms that may be consulted by the user.

Following consultation of the Website and use of the Platforms, data relating to identified or identifiable persons may be processed. We may also receive personal information from the user through the contact details on our Website, for the purposes and in the manner specified below.

The data will be processed in full compliance with the legislation on the protection of personal data referred to in Regulation (EU) 2016/679 ("GDPR") and Directive 2002/58/EC ("e-Privacy Directive").

Our AS Roma Platforms include: myASR, AS Roma Mobile App, Official Online Store, Contests, Fanselfie, AS Roma Business Club App.

HOW DO WE COLLECT AND USE PERSONAL DATA?

This Website and Our Platforms acquire Personal Data ("Personal Data" or "Data") as part of their normal operation, the transmission of which is an integral part of Internet communication protocols and the operation of the Platforms themselves. Depending on how the user interacts with the Website and the Platform, this Data may include: profile information, contact information, browsing preferences and interests, and information about the user's location.

 Data collected through the Website and AS Roma Platforms 

  • Data collected during navigation

The Website and AS Roma Platforms may automatically identify the user when browsing by collecting certain personal information such as the IP addresses or domain names of the computers used by users who connect to the Website or use the AS Roma Platforms, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, a numerical code indicating the status of the response given by the web server (successful, error, etc.) and other parameters relating to the user's operating system and IT environment.

  • Data provided voluntarily by the user

We may acquire users' Personal Data through the voluntary submission of requests by the data subjects.

For more information on the types of Data collected and how it is processed, please read our extended privacy policy.

PURPOSE OF PROCESSING

We use the Personal Data collected for multiple purposes, including, but not limited to: to provide information about our services and to enable the purchase of team products, to execute our contracts and subscriptions, to manage the selection process on our website, to allow access to and use of our AS Roma platforms, to carry out promotional activities, send newsletters, market activities, and profiling in accordance with the methods described in our policy .

The purposes are listed in more detail in the table below.

Purpose of processing  

Legal basis for processing

Pre-contractual negotiations and execution of contracts

We may use users' Personal Data to execute a contract or to fulfill pre-contractual obligations (for example, to allow the user to purchase a ticket, the AS Roma Card, a gift card, a season ticket, or a product on the Website in Our shop or on Our AS Roma Platforms, to open a personal account and take advantage of exclusive services—such as VIP Hospitality or the Stadium Experience—offered by AS Roma, or to allow the user to participate in a contest).

In these cases, the processing of Personal Data is based  on our contractual and pre-contractual obligations  (e.g., for registration on the season ticket waiting list) to provide the requested services and process the related payments. If the user refuses to provide such information, we may not be able to execute the contract and provide the requested services or supply certain products.

Management of the selection process

We may collect the Personal Data of users who apply on the Joint Controllers' Website and send their CV to manage the selection process and possible recruitment.

The Data is processed  on the basis of pre-contractual negotiations aimed at managing the user's application  . Failure to provide Personal Data will prevent the application from being considered and the selection process from continuing.

We do not collect Special Data as part of this preliminary activity.

Response to specific requests and information from users

We may collect the Personal Data of users who write to us by filling out specific forms on the Website and/or on our AS Roma Platforms to receive information about our services, the functioning of the Website or the AS Roma Platforms, or to ask questions about products, services, exclusive benefits, and offers that we promote from time to time. We may provide information about our soccer school, team matches, and our sports centers.

Data processing is based on  Our pre-contractual and contractual obligations to provide information about Our services  . If you refuse to provide such information, We may not be able to assist you with your requests.

Access to myASR

If you wish to use the myASR system, we may collect certain personal information to allow you to register for the service. For registration purposes, you will be asked for your first name, last name, email address, password, date of birth, residence, and gender. We may also request information about the payment method you intend to use and your billing and shipping address.

The processing is based on the contract in place with the user for the management of services that allow them to quickly purchase tickets and/or products, participate in competitions, and watch highlights, videos, interviews, and footage of the team. If the user refuses to provide this information, we may not be able to execute the contract and provide the requested services or certain products.

AS Roma app – Il Mio Posto

The "AS Roma – Il Mio Posto" app, which can be downloaded from the main app stores, allows users to use the "Il Mio Posto" service via their my ASR credentials, viewing information about their ticket, transferring their ticket or season ticket, or purchasing additional services.

Users can add their own tickets/season tickets, as well as tickets belonging to other family members or friends.

 Processing is carried out in accordance with the contract  in place with the user who downloads the app.

Use of AS Roma Business Club

If the user wishes to become a member of the AS Roma Business Club, we may ask them to fill out the membership application form on our website.

Personal Data (first name, last name, company name, contact details, and message) will be processed  in accordance with our pre-contractual and contractual obligations  in order to provide information about the service and proceed with club membership.

Use of the "AS Roma Fan Zone" service

AS Roma Fan Zone is a section on our website where you can register to access all the activities in the village - and stay informed about all the upcoming events and news regarding AS Roma.

Users who wish to participate in the activities can sign up by providing their personal data (first name, last name, email address, password, date of birth, residence and gender of the user for registration).

The Data will be processed in accordance with  our pre-contractual and contractual obligations  in order to allow data subjects to participate in the selected activity.

"Fanselfie" experience

Our fans can take a photo/selfie and send it to AS Roma by visiting fanselfie.me/asroma or by scanning the QR code displayed on Sundays on the stadium's big screens.

The best photos will be selected and displayed on our social media channels.

The service is voluntary. By taking the photo and sending the selfie to the channels specifically set up by the Joint Controllers or by following the instructions on the QR Code, the user consents to the processing of data relating to their image, including through publication on our social media channels. 

Use of the "È nato un romanista" service

Our fans have the opportunity to register their children or minors for whom they exercise parental responsibility for the "A Romanista is born" service by filling out a specific form with some of the minor's personal data.

The service is voluntary and both parents or guardians must consent to the communication of the minor's Data to the Club. Failure to provide the Data and failure to obtain authorization from the parents or guardians will prevent registration for the service.

Information about our Academy

In the "AS Roma International Academy" section, we provide all the information about AS Roma's soccer schools for boys and girls aged 5 to 17. These soccer schools offer the opportunity to learn the team's training methods and techniques.

Users can contact us by sending a request with their personal details (first name, last name, and message for the Academy) to the email address youthdevelopment@asroma.it. In the case of minors, only requests from those with parental responsibility will be considered.

We may also provide information about our summer camps and activities organized by the Club for young people.

The Data will be processed to comply  with our pre-contractual and contractual obligations  and to provide all the information requested by the user concerned.

Participation in competitions

We may collect Personal Data to allow the user to participate in our competitions. For registration purposes, the user's first name, last name, email address, and password will be requested.

Processing is  based on the contract and the conditions that will be indicated from time to time by the Joint Controllers based on the characteristics of the competition. If the user refuses to provide such information, we may not be able to execute the contract.

Promotional activities

We may send newsletters, promotional communications relating to our services, updates on our products, events organized by the Companies, and other commercial activities managed by us, subject to the user's explicit consent. We may contact you by email, instant messaging tools, push notifications, telephone calls, and market research. We will verify that you have given the Joint Controllers prior authorization to carry out these activities and ensure that the operations are carried out in accordance with current privacy legislation.

You are free to withdraw your consent at any time  .

Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal. The provision of Data is optional and, in case of refusal, there will be no prejudice to the contract and the provision of services and/or products by the Companies.

Promotional activities reserved for ticket and/or season ticket purchasers

We may contact users who have purchased a ticket and/or season ticket by telephone to promote extra services in relation to the ticket/season ticket purchased (for example, purchase of parking spaces or stadium experiences during matches, discounts for other events in addition to those purchased).

The processing is based on our legitimate interest in keeping our customers up to date on the services and events offered by the Companies. 

Users may always object to the processing of their personal data in accordance with the procedures indicated in this policy in Paragraph 8 - RIGHTS OF DATA SUBJECTS, Right to object to processing. 

Soft marketing

If you are already a customer of ours and have used the Companies' services, we may  send you  promotional  communications, exclusively by email,  relating to offers similar to those in which you have already shown interest.

 The processing is based on our legitimate interest in keeping our customers up to date with the latest news promoted by the Companies. 

 The user is free to unsubscribe from the newsletter service at any time by clicking on the appropriate link at the bottom of our emails and to object to the processing of their Data. 

Profiling

We may use users' Personal Data to better understand their tastes and interests in certain services and/or products we offer in order to ensure that our offerings are tailored to their preferences.

As part of our services, we may create groups of users with common characteristics to improve the shopping experience (e.g., Customer Personas).

This is a profiling activity that we can only carry out with the user's consent. 

This activity allows us to tailor our communications and make them more relevant and interesting to individual users' preferences.

We may contact the user by email, instant messaging tools, and telephone for market research purposes. We will verify that the user has given prior authorization to the Joint Controllers to carry out such activities and ensure that the operations are carried out in accordance with current privacy legislation.

We do not use Personal Data to make decisions based solely on automated processing that produce legal effects or significantly affect the user in a similar way.

 The user is free to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal. The provision of Data is optional and, in the event of refusal, there will be no prejudice to the contract and the provision of services and/or products by the Companies. 

Compliance with legal obligations

To comply with our legal obligations, orders from government authorities, which may also include measures from government authorities outside your country of residence, when we reasonably believe that we are obliged to make such disclosures, and when the disclosure of your Personal Data is strictly necessary to comply with the aforementioned legal obligations or government orders.

The processing of Data is based on the  legal obligations provided for by European and international law and regulations  to which we are subject. The provision of Data is mandatory in the case of specific regulatory provisions.

Prevention of fraud and abuse

To investigate, verify, deter, report, and protect ourselves from fraudulent, unauthorized, or illegal activities. For example, when you purchase tickets, we may perform checks to prevent credit card fraud. We may also perform preliminary checks and controls prior to refunding you and for the purposes of retaining accounting records.

We are also subject to legal obligations regarding health and safety, which require us to ensure that certain individuals who have been banned from attending sporting events do not take part in our events and sporting events. We are also required to monitor access and ensure security at certain events and gatherings organized by the Companies.

This may involve the processing of Personal Data and the disclosure of information to the police, state authorities, and other bodies, where required by law.

The processing of Personal Data is  based on our legitimate interest in ensuring the security of the services provided and of our organization  . If the user refuses to provide such information, we may not be able to guarantee access to and use of our services.

Technical operation of the Website and AS Roma Platforms

We collect and use your Personal Data to technically administer the Website and AS Roma Platforms to ensure that they function properly. We may use the personal information you provide to respond to reports or complaints regarding the proper functioning of the Website and/or AS Roma Platforms.

Data processing is  based on the legitimate interest of the Companies in ensuring the proper functioning of IT systems and electronic platforms  . If you refuse to provide such information, we may not be able to guarantee the functioning of all services and our systems.

Integration of the user's calendar with team events via ECAL

Users can add events organized by the Companies to their calendars without the Companies being able to access the fan's personal information.

The processing is based on the consent provided by the user when filling out and submitting the form to update their calendar with the events of the AS Roma Women's and AS Roma Men's first teams

Service improvement

We may collect users' Personal Data to allow them to access Our Site and the AS Roma Platforms, preserving their quality, and analyze their use in order to improve the quality of Our offering. We may use aggregated and anonymous data and may provide such information to third parties. It is understood that this information does not allow individual users to be identified.

 The processing is based on Our legitimate interest in ensuring the service and improving Our offerings  . If the user refuses to provide such Data, We may not be able to guarantee an improvement in services.

Updates and news on the team blog

We may collect the Personal Data of users who browse the Site and use the AS Roma Platforms to provide updates, news, and information about the team's activities and to allow users to share their fan experiences in "Fan Stories" on the Site by sending their photos/images and/or videos to be included in the team's fan gallery.

The processing is based on  our legitimate interest in keeping users informed about the team's activities through the blog, which can be accessed from the Website and the AS Roma Platforms. 

Following the spontaneous submission by our fans of images and audiovisual content for "Storie di tifo," we may publish such Data on the Website and on the AS Roma Platforms. We will only process information voluntarily provided by our fans and will not collect any Data other than that submitted by the user.

Update of the Roma "Community" section

We may process your Personal Data in the "Community" section, where news is collected about the activities we carry out for our fans in collaboration with institutions, Roma clubs, associations, schools, and parishes. Here, every Giallorossi fan can find information about initiatives taking place in their area. The Data is processed  based on our legitimate interest in keeping fans up to date on the activities carried out by the Joint Controllers  .

In this context, audiovisual content collected in a public setting or during events and activities organized by the team may be published.

Updating of the terms and conditions of use of the Website and AS Roma Platforms

To send information about changes to the terms and conditions of use of the Website and/or AS Roma Platforms and to provide this Privacy Policy.

The processing of Data is  based on our legitimate interest in informing the user well in advance of the entry into force of such changes  .

Protection of our rights and interests

We may process users' Personal Data to enforce our contractual terms and conditions, to protect our business operations, our rights, our privacy, our security, or our property rights, and to enable us to pursue all legal remedies available to us or limit any damages we may incur, where necessary.

The processing of Data is  based on Our legitimate interests in protecting Our business organization in accordance with the provisions of the law  .

In cases where the processing of your Personal Data is based on one of the legitimate interests described above, we will carry out a case-by-case assessment before proceeding to ensure that the processing in question is actually necessary and that your rights do not override our legitimate interests. You may object to the processing of your Personal Data in accordance with the procedures set out in paragraph 8 of the Extended Privacy Policy.

WITH WHOM DO WE SHARE YOUR INFORMATION?

The Personal Data provided may be disclosed to our suppliers and business partners for the maintenance and updating of this Website and the AS Roma Platforms, as well as for the purposes described above. These companies:

  • may also have offices outside Europe;
  • will never directly use the Personal Data communicated by the Companies without the user's specific consent.

For more information on the recipients of Personal Data, please refer to our Extended Privacy Policy.

WHAT ARE YOUR RIGHTS?

As data subjects, users have the right at any time to obtain confirmation of the existence or otherwise of Personal Data being processed and to know its content and origin, verify its accuracy or request its integration, updating, or correction (Articles 15 and 16 of the Regulation).

Pursuant to Articles 17, 18, and 21 of European Regulation 2016/679 – GDPR, every user has the right to request the deletion, restriction of processing, transformation into anonymous form, or blocking of Data processed in violation of the law, as well as to oppose its processing in any case, for legitimate reasons. Users also have the right to lodge a complaint with the supervisory authority for the protection of Personal Data, pursuant to Article 77 of the GDPR.  The data subject has the right to withdraw their consent at any time, where this constitutes the legal basis for processing. Withdrawal of consent does not affect the lawfulness of processing based on consent prior to withdrawal. 

For more information on your rights and how to exercise them, we invite all users to read our extended Privacy Policy below. 

QUESTIONS ABOUT OUR PRIVACY POLICY?

For more information about our privacy policy, we invite all users to read our extended Privacy Policy below. 

If you have any questions, please contact us at: e-mail:  privacy@asroma.it 

The Companies have appointed a Data Protection Officer ("DPO") pursuant to Article 37 of the Regulation, who can be contacted at the following email addresses:  dpo@asroma.it  or by regular mail at the following address: P.le Dino Viola n. 1, 00128, Rome (RM).


EXTENDED INFORMATION ON THE PROCESSING OF PERSONAL DATA

PURSUANT TO REGULATION (EU) 2016/679

Last updated : March 16th, 2026

This information on the processing of personal data on the AS Roma website ("PrivacyPolicy") is governed by Regulation (EU) 2016/679 ("Regulation" or "GDPR") and Legislative Decree no. 196 of June 30, 2003, as amended ("Privacy Code"). The GDPR and the Privacy Code guarantee that personal data is processed in accordance with human dignity, fundamental rights, and freedoms, with particular reference to confidentiality, personal identity, and the right to protection of personal data.

This Privacy Policy describes the purposes and methods of processing personal data ("Personal Data" or simply "Data") of users who access and browse the website and platforms of AS Roma S.r.l. and Soccer S.r.l., as joint controllers ("Joint Controllers," "Companies", "We" or jointly "AS Roma Entities").

The Joint Controllers have signed an internal agreement, pursuant to Article 26 of the GDPR, in which they have transparently defined their respective responsibilities regarding compliance with the obligations arising from the Data ProtectionRegulation. You can request a copy of the extract of the agreement by sending a request to the contact details indicated in this Privacy Policy.

Contact details of the Joint Controllers and the DPO

  • AS Roma S.r.l., with registered office in Rome, Italy, at , P.le Dino Viola n. 1 , - Tax Code and registration number with the Rome Companies Register n. 03294210582, VAT number n. 01180281006;
  • Soccer S.r.l., with registered office in Rome, Italy, Via Emilia 47 - Tax Code, VAT number and registration number with the Rome Companies Register no. 09305501000.

The Companies have appointed a Data Protection Officer ("DPO") pursuant to Article 37 of the Regulation, who can be contacted at the email address  dpo@asroma.it or by regular mail at the address P.le Dino Viola no. 1, 00128, Rome (RM).

1.  SUBJECT OF THE PRIVACY POLICY

This Privacy Policy applies to the processing of Personal Data of users who access and browse this website (hereinafter the "Site"), social media profiles and pages of the Joint Controllers, or use apps and/or services related to AS Roma Entities that refer to this Privacy Policy (hereinafter the "AS Roma Platforms").

2.  WHAT PERSONAL DATA WE PROCESS

AS Roma Entities collect and process Personal Data in various ways:

  • Personal Data provided voluntarily by the user:we collect personal information about the user when it is actively provided.
  • Personal Data collected through the use ofthewebsite and AS Roma Platforms: we automatically collect certain personal information when you browse and use the website and AS Roma Platforms.

Types of Personal Data collected:

  1. Personal details: first name, last name, username or identifier (e.g., nickname), date and place of birth, gender, and identity document number.
  2. Contact details: email address, telephone number, residential address/domicile.
  3. Payment method information: billing details, bank details, and information on the payment method used in our shop section, as well as other details on the products and services purchased by the user on the Website and AS Roma Platforms.
  4. Technical data: IP address (Internet Protocol), login details, browser type and version, time zone setting and location, types of cookies, widgets, pixels, web beacons, embedded scripts, location identification technologies and similar technologies, and browser plug-in versions, operating system and platform used, and other information about the devices used to access the Website and AS Roma Platforms.
  5. User profile data: username and password, purchases or orders made through the Site and the Company's Platforms, any feedback and responses to surveys conducted based on activity on the user's profile.
  6. Information relating to tickets, season tickets purchased, any gift cards, and information for transferring your seat at the stadium.
  7. Personal Data provided for unsolicited applications or open positions: Data and information relating to educational background and work experience contained in CVs sent to the Careers section of the Companies' website.
  8. Browsing and usage data: technical information relating to access, browsing, and use of the Website and AS Roma Platforms, log data, information relating to cookies activated by the user on the Website and AS Roma Platforms.
  9. Profiling data: with the user's consent, we may collect information relating to the user's tastes and preferences in relation to our offers and services and those of our commercial partners on the Website and on our AS Roma Platforms.
  10. Other Data: other information that the user may voluntarily provide us with, such as images, audiovisual content (audio/photos/videos), personal information voluntarily provided during events, competitions, contests, and activities organized by the Joint Controllers, requests sent by email or using the channels on the Website and AS Roma Platforms, etc.

Some of the Personal Data requested on the Website and on the AS Roma Platforms, such as name and surname, telephone number, and email address, may be indicated as "mandatory" [for example, when marked with a (*)] as they are necessary to access the services of the AS Roma Platforms that you wish to use (for example, if you place an order). Failure to provide Data marked as "mandatory" will make it impossible to provide the requested service. Failure to provide Data marked as "optional" will have no consequences.

3.  HOW WE COLLECT DATA

We collect users' Personal Data in various ways, as described below.

Data provided directly by the user:

We collect information when the user:

  1. accesses and browses the Companies' Website;
  2. registers on our Platforms (including through social media profiles such as Facebook and Google+), accesses their myASR account, or makes changes to their profile;
  3. registers for our services or agrees to receive promotional communications from us via the Website or our Platforms;
  4. activates our push notifications or requests to use the stadium seat reservation service or decides to use the Ecal service to remember an AS Roma event in their calendar;
  5. purchase our products or services via the e-commerce system (e.g., purchase gift cards or Stadium Experience);
  6. access the ticketing service and purchase tickets for one or more matches or purchase and/or renew your season ticket;
  7. you enter a competition on one of the AS Roma Platforms;
  8. interacts with our social media profiles;
  9. sign up for our newsletter;
  10. contact us using one of our communication channels (by phone, email, direct mail, live chat, or social media messaging);
  11. download our Apps;
  12. submit your application for a job position.

Personal Data received from third parties:

 We collect information about you from third parties, such as commercial and media partners of AS Roma Entities and suppliers of the Companies, when: 

  1. you enter into a contract with such third parties that provides for the disclosure of Personal Data to the Companies; and/or
  2. you register with such third parties and consent to receiving commercial communications from us.

Data that is collected automatically:

When you visit our Website or AS Roma Platforms or download our Apps, AS Roma Entities automatically receive and record information about your computer in their database, based on your browsing activity on our servers. The Companies may collect information regarding, by way of example but not limited to, the web browser software, the IP (Internet Protocol) address that identifies the user's computer, our cookies depending on the type of tracking activated by the user, the referring website, and the requested page. The Companies may also collect information about the user's location and online activity on the AS Roma Platforms. Please refer to Paragraph 10 for more details regarding our use of cookies.

4. PURPOSE AND LEGAL BASIS OF PROCESSING

Personal Data may be used in various ways, depending on your interaction and use of the Website and AS Roma Platforms, as specified below.

  1. To execute a contract

    We may use users' Personal Data to perform a contract or to fulfill pre-contractual obligations (for example, to allow the user to purchase a ticket, the AS Roma Card, a gift card, a season ticket, or a product on the Website in Our shop or on Our AS Roma Platforms, to open a personal account and take advantage of exclusive services—such as VIP Hospitality or the Stadium Experience—offered by AS Roma, or to allow the user to participate in a contest).

    In these cases, the processing of Personal Data is based on our contractual and pre-contractual obligations (e.g., to register on the waiting list for season tickets) to provide the requested services and process the related payments. If the user refuses to provide such information, we may not be able to execute the contract and provide the requested services or supply certain products.

  2. To manage the selection process

    We may collect the Personal Data of users who apply on the Joint Controllers' Website to manage the selection process and possible recruitment. The processing of Data is based on pre-contractual negotiations aimed at managing the user's application. Failure to provide Personal Data will prevent the application from being considered and the selection process from continuing.

  3. To allow the user to contact the Companies 

    We may collect Personal Data from users who write to us by filling out specific forms on the Website and/or on Our AS Roma Platforms to receive information about Our services, the functioning of the Website or the AS Roma Platforms, or to ask questions about products, services, exclusive benefits, and offers that We promote from time to time. We may provide information about our soccer school, team matches, and our sports centers. Data processing is based on our pre-contractual and contractual obligations to provide information about our services. If the user refuses to provide such information, we may not be able to assist the user with their requests.

  4. To access myASR

    If you wish to use the myASR system, we may collect certain personal information to allow you to register for the service. For registration purposes, you will be asked for your first name, last name, email address, password, date of birth, residence, and gender. We may also request information about the payment method you intend to use and your billing and shipping address. The processing is based on the contract in place with the user for the management of services that allow you to quickly purchase tickets and/or products, participate in competitions, and watch highlights, videos, interviews, and footage of the team. If you refuse to provide this information, we may not be able to execute the contract and provide the requested services or certain products.

  5. AS Roma App – Il Mio Posto

    If the user downloads the AS Roma App – My Seat and authenticates themselves through the myASR system, we may collect certain personal information to allow for the management of their seat at the stadium. For registration purposes, the user will be asked to provide their first name, last name, date of birth, and reference to the ticket purchased or season ticket subscribed to with the Company. Users can add their own tickets/season tickets, as well as tickets belonging to other family members or friends.

    The processing is based on the contract in place with the user who downloaded the app. If the user refuses to provide this information, we may not be able to execute the contract and provide the requested services or certain products.

  6. To join the "AS Roma Business Club" 

    If the user wishes to become a member of the AS Roma Business Club, we may ask them to fill out the membership application form on our website. Personal Data (first name, last name, company name, contact details, and message) will be processed in accordance with our pre-contractual and contractual obligations in order to provide information about the service and proceed with club membership.

  7. For the "AS Roma Fan Zone" service

    AS Roma Fan Zone is a section on our website where you can register to access all the activities in the village - and stay informed about all the upcoming events and news regarding AS Roma.

    Users who wish to participate in the activities can sign up by providing their personal data (first name, last name, email address, password, date of birth, residence and gender of the user for registration).

    The Data will be processed in accordance with our pre-contractual and contractual obligations in order to allow data subjects to participate in the selected activity.

  8. For the "Fanselfie" experience

    Our fans can take a photo/selfie and send it to AS Roma by visiting fanselfie.me/asroma or by scanning the QR code displayed on Sundays on the stadium's big screens. The best photos will be selected and displayed on our social media channels.

    The service is voluntary. By taking the photo and sending the selfie to the channels specifically set up by the Joint Controllers or by following the instructions on the QR code, the user consents to the processing of data relating to their image, including through publication on our social media channels.

  9.  For the "è nato un romanista" service 

    Our fans have the opportunity to register their children or minors for whom they exercise parental responsibility for the "A Romanista is born" service by filling out a specific form with some of the minor's Personal Data. The service is voluntary, and both parents or guardians must consent to the communication of the minor's Data to the Companies. Failure to provide the data and obtain authorization from those exercising parental responsibility will prevent registration for the service.

  10. To provide information about our Academy

    In the "AS Roma International Academy" section, we provide all the information about AS Roma's soccer schools for boys and girls aged 5 to 17. These soccer schools offer the opportunity to learn the team's training methods and techniques. Through our website, users can view the international locations and visit the web pages of the individual Academies.

    Users can contact us by sending a request with their personal data (first name, last name, and message for the Academy) to the email address youthdevelopment@asroma.it. In the case of minors, only requests from those exercising parental responsibility will be considered. The data will be processed to comply with our pre-contractual and contractual obligations and to provide all the information requested by the user concerned.

    We may also provide information about our summer camps and activities organized by the Companies for young people.

  11. To allow participation in team competitions 

    We may collect Personal Data to allow the user to participate in our competitions. For registration purposes, we will request the user's first name, last name, email address, date of birth, information regarding the user's residence/domicile, and user password. Processing is based on the contract and conditions that will be indicated from time to time by the Joint Controllers based on the characteristics of the competition. If you refuse to provide this information, we may not be able to execute the contract.

  12. To carry out promotional activities

    The legal basis for the processing of Data for promotional purposes—including through tracking technologies—is identified in Article 6, paragraph 1), letter a) of the Regulation, as processing is possible with the user's consent. The provision of Personal Data is optional. Refusal to provide such information will make it impossible for the Joint Controllers to carry out the aforementioned processing activities.

    We will verify that the user has previously authorized the Joint Controllers to carry out these activities and ensure that the operations are carried out in accordance with current privacy legislation.

    The user is free to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal. The provision of Data is optional and, in case of refusal, there will be no prejudice to the contract and the provision of services and/or products by the Companies.

    We may send newsletters, promotional communications relating to our services, updates on our products, events organized by the Companies, and other commercial activities managed by us. We may contact you by email, instant messaging tools, push notifications, telephone calls, and market research (also using tracking technologies).

    In the context of marketing activities carried out through electronic communications, certain information may be collected automatically when you interact with these communications via your smartphone, computer, or mobile device.

    In such circumstances, we may automatically collect information about how you access and use our communications, as well as information about the device you use. We generally collect this information through a variety of tracking technologies, including cookies, pixels, web beacons, embedded scripts, location identification technologies, and similar technologies (collectively, "tracking technologies").

    You can accept or decline these technologies by changing your privacy preferences in your browser or mobile device settings. The information we collect automatically may be combined with other personal information we collect directly from the recipients of such communications. The information we may collect automatically through our communications includes:

    • Personal Data relating to interactions with our communications (e.g., whether you click on an image or link);
    • Information about the devices used to access and interact with us (e.g., this allows us to know whether you are using a computer, tablet, or smartphone, your screen resolution, operating system, Wi-Fi connection, Internet browser, and IP address, and server log file information).
    • Behavioral data: information derived from the combination of device ID and system events that can be used to identify trends and behavioral patterns to improve our service.

    The legal basis for the processing of Data for promotional purposes—including through tracking technologies—is identified in Article 6, paragraph 1), letter a) of the Regulation, as processing is possible with the user's consent. The provision of Personal Data is optional. Refusal to provide such information will make it impossible for the Joint Controllers to carry out the aforementioned processing activities.

    We will verify that the user has previously authorized the Joint Controllers to carry out these activities and ensure that the operations are carried out in accordance with current privacy legislation.

    The user is free to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal. The provision of Data is optional and, in case of refusal, there will be no prejudice to the contract and the provision of services and/or products by the Companies.

  13. Promotional activities reserved for ticket and/or season ticket purchasers

    We may contact users who have purchased a ticket and/or season ticket by telephone to promote extra services in relation to the ticket/season ticket purchased (e.g., purchase of parking spaces or stadium experiences during matches, discounts for other events in addition to those purchased). The processing is based on our legitimate interest in keeping our customers up to date with the services and events offered by the Companies.

    Users may always object to the processing of their Personal Data in accordance with the procedures indicated in this policy. When contacting users, we will always inform them of the location from which the call is being made and the reasons why we are contacting them.

  14. To carry out soft marketing activities 

    If you are already a customer of ours and have used the Companies' services, we may send you promotional communications via email regarding offers similar to those you have already shown interest in. Processing is based on our legitimate interest in keeping our customers up to date with the latest news promoted by the Companies. You are free to unsubscribe from the newsletter service at any time by clicking on the link at the bottom of our emails and to object to the processing of your Data.

  15. To carry out profiling activities 

    We may use users' Personal Data to better understand their tastes and interests in certain services and/or products we offer in order to ensure that our offerings are tailored to their preferences. This is a profiling activity that we can only carry out with the user's consent. This activity allows us to tailor our communications and make them more relevant and interesting to individual users' preferences (e.g., Customer Personas).

    We may contact the user by email, instant messaging tools, and telephone, including for market research purposes. We will verify that the user has given prior consent to the Joint Controllers to carry out such activities and ensure that the operations are carried out in accordance with current privacy legislation.

    We do not use Personal Data to make decisions based solely on automated processing that produce legal effects or significantly affect the user in a similar way.

    The user is free to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal. The provision of Data is optional and, in case of refusal, there will be no prejudice to the contract and the provision of services and/or products by the Companies.

  16. To comply with legal obligations

    To comply with our legal obligations, orders from government authorities, which may also include measures from government authorities outside your country of residence, when we reasonably believe that we are obliged to make such disclosures and when the disclosure of your Personal Data is strictly necessary to comply with the aforementioned legal obligations or government orders. The processing of Data is based on the legal obligations provided for by European and international law and regulations to which we are subject. The provision of Data is mandatory in the case of specific regulatory provisions.

  17. To prevent fraud and abuse

    To investigate, verify, deter, report, and protect ourselves from fraudulent, unauthorized, or illegal activities. For example, when you purchase tickets, we may perform checks to prevent credit card fraud. We may also perform preliminary checks and controls prior to refunding you and for the purposes of retaining accounting records.

    We are also subject to legal obligations regarding health and safety, which require us to ensure that certain individuals, whose presence at sporting events has been prohibited, do not take part in our events and sporting events. We are also required to monitor access and ensure security at certain events and gatherings organized by the Companies.

    This may involve the processing of Personal Data and the disclosure of information to the police, state authorities, and other bodies, where required by law. The processing of Personal Data is based on our legitimate interest in ensuring the security of the services provided and of our organization. If you refuse to provide such information, we may not be able to guarantee access to and use of our services.

  18. To ensure the technical functioning of the Website and the AS Roma Platforms 

    We collect and use your Personal Data to technically administer the Website and AS Roma Platforms to ensure that they function properly. We may use the personal information you provide to respond to reports or complaints regarding the proper functioning of the Website and/or AS Roma Platforms. The processing of Data is based on the legitimate interest of the Companies in ensuring the proper functioning of IT systems and electronic platforms. If you refuse to provide such information, we may not be able to guarantee the functioning of all services and our systems.

  19. Integration of the user's calendar with team events via ECAL

    Users have the option of adding events organized by the Companies to their calendars. The service provided will automatically update the user's calendar with events involving the AS Roma Women's and AS Roma Men's first teams. Companies cannot access fans' personal information stored on their mobile devices. Processing is based on the consent provided by the user when filling out and submitting the form to update their calendar with events involving the first teams of AS Roma Femminile and AS Roma Maschile.

  20. To analyze the use of the Website and AS Roma Platforms and improve services

    We may collect users' Personal Data to allow them to access Our Site and the AS Roma Platforms, preserving their quality, and analyze their use in order to improve the quality of Our offering.

    We may use aggregated and anonymous data and may provide such information to third parties. It is understood that this information does not allow individual users to be identified.

    Processing is based on Our legitimate interest in ensuring the service and improving Our offerings. If the user refuses to provide such Data, We may not be able to guarantee an improvement in services.

  21. To provide news and updates on the team blog

    We may collect the Personal Data of users who browse the Site and use the AS Roma Platforms to provide updates, news, and information about the team's activities and to allow users to share their fan experiences on "Storie di tifo" (Fan Stories) on the Site by sending their photos/images and/or videos to be included in the team's fan gallery. The processing is based on our legitimate interest in keeping users informed about the team's activities through the blog, which can be accessed from the Website and the AS Roma Platforms.

    Following the spontaneous submission by our fans of images and audiovisual content for "Storie di tifo," we may publish such Data on the Website and on the AS Roma Platforms. We will only process information voluntarily provided by our fans and will not collect any Data other than that submitted by the user.

  22. To ensure that the Roma "Community" section is kept up to date

    We may process your Personal Data in the "Community" section, where news is collected about the activities we carry out for our fans in collaboration with institutions, Roma clubs, associations, schools, and parishes. Here, every Giallorossi fan can find information about initiatives taking place in their area. The processing of Data is based on our legitimate interest in keeping fans up to date on the activities carried out by the Joint Controllers.

    In this context, audiovisual content collected in a public setting or during events and activities organized by the team may be published.

  23. To inform users of changes to the terms and conditions of use of the Website and AS Roma Platforms and to provide this Privacy Policy

    To send information about changes to the terms and conditions of use of the Website and/or AS Roma Platforms and to provide this Privacy Policy. The processing of Data is based on our legitimate interest in informing the user well in advance of the entry into force of such changes.

  24. To protect our rights and interests

    We may process users' Personal Data to enforce our contractual terms and conditions, to protect our business operations, our rights, our privacy, our security, or our property rights, and to enable us to pursue all legal remedies available to us or limit any damages we may incur, where necessary. The processing of Data is based on Our legitimate interests in protecting Our business organization in accordance with the provisions of the law.

    In cases where the processing of your Personal Data is based on one of the legitimate interests described above, we will carry out a case-by-case assessment before proceeding to ensure that the processing in question is actually necessary and that your rights do not override our legitimate interests. You may object to the processing of your Personal Data in accordance with the procedures set out in paragraph 8 of this Privacy Policy.

    5. COMMUNICATION AND DISCLOSURE OF PERSONAL DATA

    Within the structure of the Joint Controllers, Personal Data may be processed exclusively by authorized personnel and in accordance with the instructions provided by the Companies.

    We may communicate users' Personal Data to the following parties outside the company organization.

    • Service providerswho perform activities on our behalf, such as professional consultants, technical suppliers, and hosting companies; companies that support us in managing ticketing services (e.g., VivaTicket) and exclusive services for team fans; companies that offer advertising and social media management services (e.g., SalesManago for promotional activities, social media, and management of the "my seat" service); Communication agencies; marketing agencies; analytics companies; companies that offer payment services (e.g., Shopify, PayPal, or Worldline); companies that offer credit verification and anti-fraud services; Ecal for managing the fan events calendar; companies that provide us with services instrumental to our personnel selection activities.
    • Data service providers, which help the Companies to segment and better understand our users by providing information about their browsing and use of the Website and AS Roma Platforms.
    • External advertisers(such as Facebook or Google) to help us identify customers with characteristics similar to our users or to display relevant advertisements on third-party websites. The information shared with these advertisers is pseudonymized to protect users' Personal Data.
    • Business partnerswho have signed an agreement or have a contractual relationship with the Joint Controllers (e.g., Seyu for the "Fanselfie" service).
    • Postal police and state authorities, in particular to carry out security or administrative checks in relation to places or events organized by the Company for which there is a need to control and verify access.
    • Legal, tax,and fiscal professionalswho can support the Companies in verification and control operations in relation to illegal activities, suspected fraud, emergency situations, or breach of contractual obligations, as well as in other cases where required by law.
    •  Third parties specifically identified on the basis of orders or injunctions issued by judicial authorities  .

    AS Roma Entities will not sell, make available, or otherwise transfer the Personal Data of data subjects to third parties for reasons other than the purposes for which the Data was originally collected or for other purposes authorized by law.

    We may analyze users' interactions with communications, content, and services (including emails, digital platforms, and online purchases) in order to measure performance, improve services, personalize communications, and evaluate the effectiveness of marketing activities. Such analysis may include, but is not limited to, the evaluation of interactions with emails and digital content, response rates, unsubscription actions, and purchasing behavior. Where necessary, we will always proceed by requesting the prior consent of the data subject, as specified in paragraph 4 of this Privacy Policy.

    The communication of Data will be carried out in full compliance with current legislation on the protection of Personal Data, signing, where necessary, specific agreements on the processing of Data pursuant to Article 28 of the GDPR.

    A complete list of recipients of Personal Data may always be requested by data subjects by sending an email to the address indicated in this Privacy Policy.

    6. TRANSFER OF PERSONAL DATA

    We may disclose some of your personal data and information to our suppliers and, for the processing operations mentioned above, we may use business partners, providers, distributors, and companies that collaborate with us located outside the European Union. In these circumstances,  will adequately protect our users' Personal Data, in accordance with the provisions of Articles 45 et seq. of the GDPR, stipulating, where necessary, standard clauses on data transfer ("Standard Contractual Clauses" or "SCCs"). 

    7. DATA STORAGE AND RETENTION PERIOD

    In general, Personal Data will be retained for as long as the user uses our services, as well as in accordance with contractual provisions and to comply with legal obligations imposed by law. For marketing activities, the user's Personal Data will be stored in the Companies' CRM for a period not exceeding 24 months. In the case of profiling, the Data will be stored for a maximum period of 12 months from collection. It is understood that before the expiry of the term, the user will have the opportunity to renew their consent.

    Personal Data may be stored for a period longer than that indicated if there is a need to defend the rights and interests of AS Roma Entities in a dispute or litigation.

    In determining the retention periods for Personal Data, we will take into account factors such as:

    • our contractual obligations and rights in relation to the services provided and products sold;
    • legal obligations regarding the retention of Data under applicable law;
    • statutes of limitations as provided for by law (corresponding to the period during which contractual disputes may be raised);
    • our legitimate interests as indicated in paragraph 4 of this Privacy Policy;
    • pending litigation and disputes involving the Companies;
    • guidelines issued by the competent supervisory authorities on the protection of Personal Data.

    8. RIGHTS OF DATA SUBJECTS

    Pursuant to the Regulation, users concerned by the processing have the right to access their Personal Data, to obtain confirmation of its existence or otherwise at any time, and to know its content, origin, geographical location, and request a copy. The data subject also has the right to verify its accuracy or request its integration and/or updating, correction. The data subject has the right to restrict the processing, erasure, anonymization, or blocking of Data processed in violation of the law. The data subject has the right, in any case, to object to the processing of their Personal Data and may request the portability of the same, as specified in the table below.

    As a data subject, the user may always lodge a complaint with the Personal Data Protection Authority.

    Rights

    What does this entail?

    Right to object to processing

    The user's right to object to certain types of processing of Personal Data, including processing based on the legitimate interest of the Companies or processing carried out for direct marketing purposes (when you no longer wish to be contacted with potential offers and purchasing opportunities).

    In most cases, you can easily unsubscribe from newsletters and commercial communications via email by clicking on the unsubscribe link at the bottom of the newsletter or, alternatively, by changing your account settings and preferences if you have a user profile on one of our AS Roma Platforms.

    Right to be informed

    The right to receive clear, transparent, and easily understandable information about how we use Personal Data and about your rights. For this reason, we have created this Privacy Policy.

    Right of access to personal data

    The right to access your Personal Data (to the extent that it is processed by AS Roma Entities) and additional information (similar to that included in this Privacy Policy).

    This allows you to stay informed and verify that we are using your Personal Data in accordance with current privacy legislation.

    Right to update and modify

    The right to obtain the rectification of your Personal Data if it is inaccurate or incomplete.

    In general, you can modify, correct, or update your Personal Data at any time by accessing your account on any AS Roma Platform on which it has been entered and/or on the Companies' website. In any case, you may choose to send us a written request to that effect at any time.

    Right to erasure

    It allows the user to request the deletion or removal of Personal Data where there are no binding reasons that determine the need for the Companies to process it. An absolute right to deletion is not guaranteed, as specific conditions are provided for by law.

    If the user has a personal profile on one or more AS Roma Platforms, they can delete their Personal Data at any time by accessing their account. In any case, the user can choose to send us a written request to this effect at any time.

    If the user wishes to unsubscribe from the newsletter service, they can do so directly via the link at the bottom of the promotional email or by sending an explicit request to the contacts indicated in this Privacy Policy.

    Right to restrict processing

    Users have the right to "block" or restrict the further use of their Personal Data. If processing has been restricted, the Companies may still store Personal Data, but may not process it further. We will prepare specific lists containing the names of individuals who have requested to "block" the further use of their Personal Data to ensure that the restriction is respected.

    Right to portability

    You have the right to obtain and reuse your Personal Data for your own purposes across different services.

     Right to lodge a complaint with the Supervisory Authority 

    You have the right to lodge a complaint with the competent supervisory authority for the protection of Personal Data regarding the way in which the Companies process or manage Personal Data.

    In this case, the Data Subject has the option of lodging a complaint with the Italian Data Protection Authority, which can be contacted at the website  https://www.garanteprivacy.it/  .

    Right to withdraw consent

    If the user has consented to the collection of Personal Data as a condition for processing, they will always have the right to withdraw their consent at any time (it being understood that this does not mean that the processing carried out up to that point is unlawful). This includes the right to withdraw consent to the use of Personal Data for marketing and profiling purposes at any time.

    You can exercise these rights by contacting us in writing (by email or regular mail) at the addresses listed below. In order to provide a timely response to the data subject, we may ask you to provide proof of your identity by providing us with certain personal information and/or documents (e.g., we may ask for a copy of an identification document).

    Email:  privacy@asroma.it 

    Post:

    AS ROMA S.r.l.
    Piazzale Dino Viola, 1
    00128, Rome (RM)
    Italy

    The deadline for responding to the Data Subject is thirty days, extendable to two months in particularly complex cases; in such cases, the Joint Controllers will provide at least one interim communication to the Data Subject within thirty days.

    The exercise of rights is, in principle, free of charge; the Companies reserve the right to request a contribution in the event of manifestly unfounded or excessive (including repetitive) requests, also in light of any indications that may be provided by the Italian Data Protection Authority.

    9. DATA SECURITY

    We want users to feel secure when using the AS Roma website and platforms. To this end, the Companies have defined and adopted appropriate technical and organizational measures to ensure the security of Personal Data, depending on the nature of the information processed and the context of the processing, with the aim of preventing (as far as possible and taking into account the state of the art) the destruction, loss, modification, unauthorized disclosure, or access to Personal Data (to ensure its confidentiality, integrity, and availability, respectively).

    The Companies use industry-standard SSL encryption to protect the transmission of Data. If the user communicates or interacts with the Companies in any format other than the AS Roma Platforms (e.g., via email), the secrecy of the Internet is not always guaranteed. By sending emails containing sensitive or confidential content or unencrypted information, the user accepts the risk of such uncertainty and the possible lack of online confidentiality.

    Identity theft and the practice currently known as "phishing" are of great concern to the Companies. Our goal is to protect information in order to help users protect themselves from identity theft. AS Roma entities do not and will never request data and information relating to users' credit cards, personal access systems, or national identification numbers in an unsecured or unsolicited email or during a telephone conversation.

    10. PRIVACY OF MINORS

    The Companies are particularly concerned with protecting the Personal Data of minors. The AS Roma Platforms and their content are not intended for minors under the age of fourteen (14).

    The AS Roma Entities undertake not to voluntarily collect Personal Data from individuals under the age of 14 (14). If a parent or guardian becomes aware that a minor (14 years of age) has registered as a user without their consent, they are required to delete the relevant account or, if this is not possible, to inform the Companies immediately. If the Companies become aware that a minor under the age of 14 (14) has registered as a user, access will be immediately denied and the account will be deleted as quickly as possible (along with all Personal Data associated with it).

    If you believe that the Companies may be in possession of Personal Data of minors in violation of the above, please notify us in writing by email to  privacy@asroma.it  or by regular mail to AS Roma S.r.l., P.le Dino Viola n. 1, Rome, Italy.

    11. LINKS TO OTHER SITES

    This Privacy Policy is provided only for this Website and for the AS Roma Platforms, and not for other websites that may be consulted by the user via links on the aforementioned Platforms. If the user chooses to visit an advertiser's website or clicks on another link referring to third parties, they will be directed to the website of those third parties. The Companies have no control over third-party websites and, therefore, we suggest that you review the privacy policies published on those websites to understand their processes for collecting, using, and disclosing Personal Data.

    12. CHANGES TO THE PRIVACY POLICY

    The Privacy Policy is available at any time in the appropriate section at the bottom of the Companies' Website homepage and on the AS Roma Platforms and is subject to change and updates from time to time.

    The most recent and updated version of the Privacy Policy will be available on the Website and on the AS Roma Platforms. Each AS Roma Platform may provide further information regarding changes made or other elements by displaying specific notifications or links to notices directed at the user, either in general or within the AS Roma Platforms.

    The user is required to review this Privacy Policy regularly. AS Roma Entities reserve the right to change the Privacy Policy at any time and without notice. In any case, we will disclose any significant changes made in relation to the protection of Personal Data.

    13. CONTACT US

    If you have any questions about how we process Personal Data and/or this Privacy Policy, please contact us at the addresses indicated in this policy.

    If you are not satisfied with our response, or if you believe there has been a breach of the Personal Data protection legislation, you can always lodge a complaint with the supervisory authority of the Member State in which you habitually reside, work, or the place where the alleged breach occurred.