With this policy we want to inform the users of this site regarding its management methods relative to the processing of their personal data, as prescribed by Art. 13 and 14 of European Regulation no. 679/2016 – General Data Protection Regulation. This disclosure respects and complies fully also with Recommendation no. 2/2001 that the European Authorities for the Protection of Personal Data, meeting in the Group established by Art. 29 of Directive no. 95/46/EC, adopted on 17 May 2001 to identify certain minimum requirements for the collection of personal data online and, in particular, the methods, times and nature of the information that the Data Controllers must provide the users when they connect to web pages, regardless of the purposes of the connection. By consulting this site, data relative to individuals identified or identifiable may be processed.
We wish to specify that the mechanisms of consent will be obvious, brief and easy to understand. If the original conditions for which we requested the consent should undergo changes, for example should the purpose of the data processing change, additional consent will be requested in accordance with European Regulation no. 679/2016. Furthermore, we specify that all the consents collected will be documented and kept separate from any other company document.
Data Controller of the processing
Your personal data will not be disclosed and you may exercise the rights pursuant to Articles 11-20 of European Regulation no. 679/2016 by writing to:
La Fabrique srl
Via San Daniele, 11
Indirizzo email del Titolare del trattamento: firstname.lastname@example.org
The processing connected to the web services of this site takes place at the aforementioned offices and at the offices of the service provider of the site, and is handled only by the personnel of the company, or by any individuals assigned for occasional maintenance operations.
Types of Data collected
Among the Personal Data collected by this Application, autonomously or through third parties, are: Cookies, Usage Data, First Name, Last Name and E-mail.
The Personal Data can be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application.
Unless specified otherwise, all the Data requested by this Application are compulsory. If the User refuses to communicate the data, it may be impossible for this Application to provide the Service. Should this Application indicate that certain Data are optional, the Users are free to refrain from communicating that Data without there being any consequence regarding the availability of the Service or its operation.
The Users who may have doubts regarding what Data are compulsory, are encouraged to contact the Data Controller.
The User assumes the responsibility for the Personal Data of third parties obtained, published or shared through this Application and guarantees that he/she has the right to communicate or disclose them, releasing the Data Controller from any liability towards third parties.
Processing methods and location of the Data collected
The Data Controller adopts the appropriate security measures aimed at preventing the unauthorized access, disclosure, modification or destruction of the Personal Data.
The processing is carried out with computer and/or electronic instruments, with organizational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in certain cases, other individuals involved in the organization of this Application (administrative, commercial, marketing, legal personnel and system administrators) or outside subjects (such as third party technical services providers, postal couriers, hosting providers, IT companies, communication agencies) appointed also, if necessary, as Processors by the Data Controller may have access to the Data. The updated list of the Processors may always be requested from the Data Controller.
Legal basis of the processing
The Data Controller processes Personal Data relative to the User should one of the following conditions exist:
- the User has provided their consent for one or more specific purposes; Note: in some legislations, the Data Controller can be authorized to process Personal Data without there having to be the consent of the User or another one of the legal bases specified below, until the User objects (“opt-out”) to that processing. This is however not applicable if the processing of the Personal Data is regulated by the European legislation regarding the Protection of Personal Data;
- The processing is necessary for the implementation of a contract with the User and/or the implementation of pre-contractual measures;
- The processing is necessary to fulfil a legal obligation to which the Data Controller is subject;
- The processing is necessary for the implementation of a task of public interest or for the exercise of public authority with which the Data Controller is vested;
- The processing is necessary to pursue the legitimate interest of the Data Controller or third parties.
It is however always possible to ask the Data Controller to clarify the actual legal basis of every processing action and in particular to specify whether the processing is based on the law, required by a contract or necessary to conclude a contract.
The Data are processed at the operational sites of the Data Controller and in any other place in which the parties involved in the processing are located. For additional information, please contact the Data Controller.
The Personal Data of the User could be transferred to a country other than the one in which the User is located. For additional information on the processing location, the User can refer to the section relative to the details on the processing of the Personal Data.
The User has the right to obtain information regarding the legal basis of the transfer of Data outside the European Union or to an international organization established under international public law or composed of two or more countries, such as for example the UN, as well as regarding the security measures adopted by the Data Controller to protect the Data.
If one of the transfers just described takes place, the User may refer to the respective sections of this document or ask for information from the Data Controller by contacting him/her at the contact information provided at the beginning.
The Data are processed and stored for the time required by the purposes for which they were collected.
- The Personal Data collected for purposes connected to the implementation of a contract between the Data Controller and the User will be kept until the implementation of that contract has been completed.
- The Personal Data collected for purposes attributable to the legitimate interest of the Data Controller will be kept until that interest has been satisfied. The User can obtain additional information regarding the legitimate interest pursued by the Data Controller in the relative sections of this document or by contacting the Data Controller.
When the processing is based on the consent of the User, the Data Controller may keep the Personal Data for longer until such time as that consent is revoked. Furthermore, the Data Controller may be obliged to keep the Personal Data for a longer period of time in compliance with a legal obligation or by order of an authority.
At the end of the storage period, the Personal Data will be deleted. Therefore, at the expiry of that deadline the right of access, erasure, rectification and the right to the portability of the Data may no longer be exercised.
Purpose of the Processing of the Data collected
The User’s Data are collected to allow the Data Controller to provide his/her Services, as well as for the following purposes: Statistics and Contacting the User.
To obtain additional detailed information on the purposes of the processing and the Personal Data actually significant for every purpose, the User can refer to the relative sections of this document.
Details on the processing of the Personal Data
The Personal Data are collected for the following purposes and by using the following services:
Contact Form (this Application)
The User, by completing the contact form with his/her Data, consents to their use to respond to the requests for information, estimate, or any other kind indicated in the heading of the form.
Personal Data collected: last name, e-mail and first name.
Mailing list or newsletter (this Application)
By registering for the mailing list or newsletter, the e-mail address of the User is automatically entered in a list of contacts to which e-mail messages may be sent containing information, also of a commercial and promotional nature, relative to this Application. The e-mail address of the User may also be added to this list as a result of the registration to this Application or after having made a purchase.
Personal Data collected: city, last name, date of birth, e-mail, first name and profession.
The services contained in this section allow the Data Controller to monitor and analyse the traffic data and are used to track the User’s behaviour.
Google Analytics (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google uses the Personal Data collected to track and review the use of this Application, compile reports and share them with the other services developed by Google.
Google may use the Personal Data to contextualize and customize the advertisements of its own advertising network.
Personal Data collected: Cookies and Usage Data.
Management of contacts and sending of messages
This type of service makes it possible to manage a database of e-mail contacts, telephone contacts or contacts of any other kind, used to communicate with the User.
These services could also permit the collection of data relative to the date and time the messages were viewed by the User, as well as the User’s interaction with them, such as the information regarding the clicks on links included in the messages.
MailChimp (The Rocket Science Group, LLC.)
MailChimp is a service for management of addresses and the sending of e-mail messages provided by The Rocket Science Group, LLC.
Personal Data collected: last name, e-mail and first name.
Rights of the User
The Users may exercise certain rights with reference to the Data processed by the Data Controller.
In particular, the User has the right to:
- revoke the consent at any time. The User can revoke the consent to the processing of his/her Personal Data previously expressed.
- Object to the processing of his/her Data. The User can object to the processing of his/her Data when it is carried out on a legal basis different than the consent. Additional details on the right of objection are indicated in the following section.
- Access his/her Data. The User has the right to obtain information on the Data processed by the Data Controller, regarding certain aspects of the processing and to receive a copy of the Data processed.
- Check and request rectification. The User can check the accuracy of his/her Data and request their update or rectification.
- Obtain the restriction of the processing. When certain conditions are met, the User can request the restriction of the processing of his/her Data. In that case, the Data Controller will not process the Data for any other purpose except their storage.
- Obtain the erasure or removal of his/her Personal Data. When certain conditions are met, the User can request the erasure of his/her Data by the Data Controller.
- Receive his/her Data or have them transferred to another Data Controller. The User has the right to receive his/her Data in a structured, commonly used format legible from automatic device and, if technically feasible, to obtain the transfer without impediment to another Data Controller. This provision is applicable when the Data are processed with automated instruments and the processing is based on the User’s consent, in a contract of which the User is part or by contractual measures connected to him/her.
- File complaint. The User may file a complaint to the Competent Supervisory Authority for the Protection of Personal Data or file in court.
Details on the right to object
When the Personal Data are processed in the public interest, in the exercise of public authority with which the Data Controller is vested or to pursue a legitimate interest of the Data Controller, the Users have the right to object to the processing for reasons connected to their particular situation.
It is pointed out to the Users that, should their Data be processed for purposes of direct marketing, they can object to the processing without providing any reason. To discover whether the Data Controller is processing data for direct marketing purposes, the Users can refer to the respective sections of this document.
How to exercise the rights
To exercise the rights of the User, the Users can send a request to the contact information of the Data Controller provided in this document. The requests are filed free of charge and dealt with by the Data Controller as quickly as possible, in any case within one month.
Additional information on the processing
Defence in court
The Personal Data of the User may be used by the Data Controller in court or in the phases preparatory to a possible court case for the defence against abuses in the use of this Application and the related Services by the User.
The User declares that he/she is aware that the Data Controller could be obliged to reveal the Data by order of the public authorities.
System Log and Maintenance
For needs connected to the operation and maintenance, this Application and the possible third party services used by it could collect System Logs, in other words files that record the interactions and which could also contain Personal Data, such as the User IP address.
Information not included in this policy
Additional information relative to the processing of the Personal Data may be requested at any time from the Data Controller by using the contact information.
Response to the “Do Not Track” requests
This Application does not support “Do Not Track” requests.
To discover if any third party services used support them, the User is asked to consult the respective privacy policies.
Should the changes involve processing the legal basis of which is consent, the Data Controller will arrange to obtain the User’s consent once again, if necessary.
Last update: 25 May 2018
Definitions and Legal References
Personal Data (or Data)
Personal data are any information which, directly or indirectly, also in connection with any other information, including a personal identification number, identifies an individual or makes them identifiable.
This is information collected automatically through this Application (also from applications of third parties integrated with this Application), including: the IP addresses or domain names of the computers used by the User who connects to this Application, the URI (Uniform Resource Identifier) addresses, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response from the server (successful conclusion, error, etc.), the country of origin, the characteristics of the browser and the operating system used by the visitor, the various time notations of the visit (for example the time stayed on every page) and the details relative to the itinerary followed within the Application, with particular reference to the sequence of the pages consulted, the parameters relative to the operating system and the computer environment of the User.
The individual who uses this Application who, unless specified otherwise, coincides with the Data Subject.
The natural person to whom the Personal Data refer.
Data Controller (or Controller)
The natural person or legal entity, the public authority, the service or other body which, individually or with others, determines the purposes and the processing means of the personal data and the instruments adopted, including the security measures relative to the operation and use of this Application. The Data Controller, unless specified otherwise, is the owner of this Application.
The hardware or software instrument through which the Personal Data of the Users are collected and processed.
The Service provided by this Application as defined in the relative terms (if included) on this site/application.
European Union (or EU)
Unless specified otherwise, any reference to the European Union included in this document is intended extended to all the current member states of the European Union and the European Economic Area.
Small portion of data stored in the User’s device.
This privacy disclosure is drafted based on multiple legislative regulations, including Articles 13 and 14 of European Regulation no. 2016/679.
If not specified otherwise, this privacy disclosure exclusively concerns this Application.