1. Personal data collected by the Application
The Data Controller collects the following types of Personal Data:
- Content and information provided voluntarily by the User
- Contact data and contents: these are Personal Data that the User voluntarily provides to the Application during its use, such as personal data, contact details, access credentials to the services and / or products provided, personal interests and preferences and other contents personal, etc.
Failure by the User to provide Personal Data, for which there is a legal or contractual obligation or if they constitute a necessary requirement for the use of the service or for the conclusion of the contract, will make it impossible for the Owner to provide in all or in part its own services.
The User who communicates the Personal Data of third parties to the Data Controller is directly and exclusively responsible for their origin, collection, processing, communication or dissemination.
- Data and contents acquired automatically during the use of the Application:
- Technical data: the computer systems and software procedures used to operate this Application may acquire, during their normal operation, some Personal Data whose transmission is implicit in the use of internet communication protocols. This is information that is not collected to be associated with identified Users, but which by their very nature could, through processing and association with data held by third parties, allow Users to be identified. This category includes IP addresses, or domain names used by Users who connect to the Application, the addresses in URI (Uniform Resource Identifier) notation of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained, etc.
- Usage data: Personal Data relating to the use of the Application by the User may also be collected, such as the pages visited, the actions performed, the functions and services used.
- Geolocation data: the Application may collect Personal Data on the User’s location which may be GNSS data (Global Navigation Satellite System, for example GPS data), in addition to data that identify the nearest repeater, Wi-Fi and bluetooth hotspots , communicated when you enable location-based products or features.
- Personal data collected through cookies or similar technologies:
The Personal Data collected may be used for the execution of contractual and pre-contractual obligations and for legal obligations as well as for the following purposes:
- User registration and authentication: to allow the User to register on the Application to access and be identified.
- Support and contact with the User: to respond to the User’s requests and help in case of problems.
- Comment and feedback: to allow the User to post reviews or comments.
- External management of payments by credit card, bank transfer or other tools: to manage User payments through external platforms that acquire payment data without the Application owner having access. Personal Data is disclosed to PayPal, www.paypal.com/it/webapps/mpp/ua/privacy-full ; Stripe, https://stripe.com/it/privacy
- Internal management of payments by credit card, bank transfer or other tools: to manage payments by acquiring payment data directly from the User.
- Technical monitoring of the infrastructure for maintenance, troubleshooting and performance improvement: to identify and resolve any technical problems and improve performance.
- Archiving, hosting and backend infrastructure management: to manage the technical infrastructure for storing User data.
- Traffic optimization and distribution: to more efficiently manage and improve the performance of the technical infrastructure.
- User database management: to organize, access and modify User data. Personal Data is disclosed to SiteGround, https://it.siteground.com/viewtos/privacy_policy?scid=3
- Monitoring, analysis and tracking of User behavior: to monitor and analyze how the User behaves on the Application. Personal Data is disclosed to Google Inc., www.google.com/privacy
- User profiling: to automatically group and analyze the characteristics or behavior of the User and provide him with personalized services or messages. Personal Data is disclosed to Google Inc., www.google.com/privacy ; Facebook, https://www.facebook.com/policy.php
- Sending emails or newsletters and mailing list management: to contact the User with emails containing commercial and promotional information relating to the Application. Personal Data is communicated to MailChimp, https://mailchimp.com/legal/terms/
- Advertising and remarketing targeting: to show advertisements that are more relevant to the User based on his surfing behavior and preferences. Personal Data is disclosed to Google Inc., www.google.com/privacy ; Facebook, https://www.facebook.com/policy.php
3. Processing methods
The processing of Personal Data is carried out using IT and / or telematic tools, with organizational methods and with logic strictly related to the purposes indicated.
In some cases, subjects involved in the organization of the Data Controller may also have access to Personal Data (such as, for example, personnel management personnel, sales personnel, system administrators, etc.) or external subjects (such as IT companies, suppliers of services, postal couriers, hosting providers, etc.). If necessary, these subjects may be appointed as Data Processors by the Data Controller, as well as access the Personal Data of the Users whenever necessary and will be contractually obliged to keep the Personal Data confidential.
The updated list of Managers can be requested via email at email@example.com .
4. Legal basis of the processing
The processing of Personal Data relating to the User is based on the following legal bases:
- the consent given by the User for one or more specific purposes;
- the processing is necessary for the execution of a contract with the User and / or for the execution of pre-contractual measures
- the processing is necessary to fulfill a legal obligation to which the Data Controller is subject
- the processing is necessary for the execution of a task of public interest or for the exercise of public authority vested in the Data Controller
- the processing is necessary for the pursuit of the legitimate interest of the Data Controller or third parties
- the processing is necessary for the pursuit of a vital interest of the owner or third parties.
However, it is always possible to ask the Data Controller to clarify the legal basis of each treatment at firstname.lastname@example.org .
Personal Data are processed at the Data Controller’s operating offices and in any other places where the parties involved in the processing are located. For more information, contact the Data Controller at the following e-mail address email@example.com or at the following postal address Via Sant’Eligio 2, Calimera 73021 Italy.
6. Security measures
The processing is carried out in a manner and with suitable tools to guarantee the security and confidentiality of the Personal Data, having the Data Controller adopted adequate technical and organizational measures that guarantee, and allow to demonstrate, that the Processing is carried out in compliance with the relevant legislation.
7. Data retention period
Personal Data will be kept for the period of time necessary to fulfill the purposes for which they were collected.
In particular, the Personal Data will be kept for the entire duration of the contractual relationship, for the execution of the related and consequent obligations, for compliance with the applicable legal and regulatory obligations, as well as for own or third party defensive purposes.
If the processing of Personal Data is based on the User’s consent, the Data Controller may keep the Personal Data until the consent is revoked.
Personal Data may be kept for a longer period if necessary to fulfill a legal obligation or by order of an authority.
All Personal Data will be deleted or stored in a form that does not allow identification of the User within 30 days from the end of the retention period. At the expiry of this term, the right of access, cancellation, rectification and the right to the portability of Personal Data can no longer be exercised.
8. Automated decision-making processes
All Personal Data collected will not be subject to any automated decision-making process, including profiling, which may produce legal effects for the person or which may significantly affect him.
9. User rights
Users can exercise certain rights with reference to the Personal Data processed by the Data Controller. In particular, the User has the right to:
- withdraw consent at any time;
- oppose the processing of their Personal Data;
- access their Personal Data;
- verify and request rectification;
- obtain the limitation of the processing;
- obtain the cancellation of their Personal Data;
- receive their Personal Data or have them transferred to another owner;
- lodge a complaint with the supervisory authority for the protection of Personal Data and / or take legal action.
To exercise their rights, Users can direct a request to the contact details of the Owner indicated in this document. Requests are made free of charge and processed by the Data Controller as soon as possible, in any case within 30 days.