INFORMATION ON THE PROCESSING OF PERSONAL DATA EX ART. 13 OF REGULATION (EU) 679/2016
General Data Protection Regulation - GDPR
This information describes how the personal data of users who consult the website www.proteggendo.it (hereinafter "site") or who use the services made available through it by Proteggendo.it (hereinafter "Society"). In compliance with the principles recognized by the European Regulation 679/2016 (hereinafter "Regulation"), this information provides the user, as an interested party, with all the necessary information to ensure the maximum correctness and transparency of the processing operations of your personal data. This information does not concern other sites, pages or online services that can be reached via links that may be published on this site, such as redirects to social pages (facebook, youtube, etc.).
1. Data Controller
The data controller is HD casa s.r.l. based in Via Eduardo De Filippo 24 Olevano Sul Tusciano (SA). VAT number IT 05688500650
The contact details of the Data Protection Officer is firstname.lastname@example.org.
2. Types of data processed, purpose and legal basis of the processing
Following consultation of this site or use of the services made available through it, the following types of users' personal data may be processed:
a) Navigation data
The computer systems and software procedures used to operate the site acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected to be associated with identified interested parties, but which by their very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of the computers used by users who connect to the site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the user's IT environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the Site and to check its correct functioning, to identify anomalies and / or abuses, and are deleted immediately after processing. The data could be used to ascertain responsibility in case of hypothetical computer crimes against the site or third parties: except for this possibility, the data on web contacts do not currently persist for more than seven days
b) < strong> The personal data provided freely and voluntarily by the users of this site concern respectively:
1. Necessary for the conclusion of e-commerce transactions, in the context of online purchases. The payment management services allow this site to process payments by credit card, bank transfer, PayPal and cash on delivery. The data used for payment are acquired directly by the manager of the requested payment service without being processed in any way by the company (eg. PayPal is a payment service provided by PayPal Inc., which allows the user to make payments online using the your PayPal credentials).
2. Those inserted in the forms present in some sections of the site (eg: in the "Contacts" section), or sent via e-mail messages to the e-mail addresses indicated on the Site, or the data entered for the purpose of registering on the website or for sending the newsletter, to the extent necessary to provide feedback to the user's requests.
c) The personal data provided freely and voluntarily by users are collected and processed for the following purposes:
• supply of products requested by the user and management of related payments;
• registration on the site;
• registration and sending of newsletters via email;
• response to requests for information ;
• statistical purposes.
The legal basis of the processing for the aforementioned purposes is represented not only by the need to execute the contract of which the user is a party, or to respond to his requests, also the need to fulfill the obligations of law to which the Company is subject.
For the processing carried out for the purpose of sending direct advertising material or commercial communications in relation to products or services similar to those already requested by users, the Company may use the addresses of e-mail and paper mail pursuant to and within the limits permitted by the provision of the Guarantor Authority for the protection of personal data of 19 June 2008, as the legal basis of such processing is represented by the pursuit of one's own legitimate interest. In any case, pursuant to art. 21 of the Regulations, the user has the possibility to oppose this treatment at any time, initially or during subsequent communications, easily and free of charge, also by writing to the Data Controller or the Personal Data Protection Officer at the addresses indicated above, as well as to obtain immediate feedback confirming the interruption of this treatment.
Regarding the statistical purposes, the data will be treated in an anonymous and aggregate form.
3. Compulsory or optional nature of providing users' personal data
The provision of personal data to the Data Controller, in particular the personal data, the e-mail address, the postal address for the shipment of the products and the telephone number is necessary with regard to the conclusion of the purchase contract of products on the site or of the registration phase.
Any refusal to indicate personal data marked with an asterisk could make it impossible to conclude the registration phase or to execute the purchase contract for products on the site, or to use the services available on the site. < / p>
4. Recipients of users' personal data
The personal data of users who consult this site or use the services made available through it will be communicated:
• to the personnel of Proteggendo.it specifically authorized for processing pursuant to art. 29 of the Regulations as part of their respective duties and to the extent necessary to allow the performance of activities strictly related to the provision of the requested services;
• to Improntae S.r.l. as manager, for the performance of site development and installation services;
• to Serverplan S.r.l. as the person responsible for the provision of hosting services for the proteendo.it site;
• to Codice S.r.l. as responsible for the provision of maintenance and technical assistance services;
• to 7Pixel S.r.l., in the person of the legal representative, is appointed responsible for the processing of the User's data (email address) for the management of requests of comments in the context of the Trusted Program of the website www.trovaprezzi.it
• to couriers for managing the delivery of products ;.
• to subjects, authorities or bodies to whom it is mandatory to communicate personal data by virtue of legal provisions or orders of the competent authorities;
Users' personal data will not be transferred abroad, to countries or international organizations not belonging to the European Union that do not guarantee an adequate, recognized level of protection, pursuant to art. 45 of the Regulation, based on an adequacy decision of the EU Commission. In the event that it is necessary for the provision of services, the transfer of personal data to countries or international organizations outside the EU will be carried out in compliance with Articles. 45-49 of the Regulation.
5. Retention of users' personal data
The personal data provided voluntarily by users will be stored in a form that allows the identification of the data subjects for the time strictly necessary to pursue the purposes for which the data were collected and subsequently processed and, in any case, within the limits of law.
Personal data related to the purchase of products online will be kept for 10 years.
6. Rights of the interested party
Articles 15-22 of the Regulations give the interested party the following rights:
• ask for confirmation of the existence or otherwise of their personal data (Article 15 par 1);
• obtain information about the purposes of the processing, the categories of personal data, the recipients or categories of recipients to whom the personal data have been or will be communicated, and when possible, the retention period (Article 15 paragraph 1 letter a, c);
o obtain the rectification and deletion of data (articles 16 and 17);
• obtain the limitation of processing (article 18);
• obtain information on the recipients from the Data Controller to whom the personal data have been transmitted and any corrections or cancellations or limitations of processing; (art. 19)
• obtain data portability, ie receive them from a Data Controller, in a structured format, commonly used and readable by an automatic device, and transmit them to another data controller without impediments (art .20)
• oppose an automated decision-making process relating to natural persons, including profiling (articles 21 and 22);
• If the processing is based on consent, you can revoke it at any time (art .7 paragraph 3);
• When the violation of personal data is likely to present a high risk for the rights and freedoms of natural persons, the data controller communicates the violation to the interested party without undue delay (art 34);
Interested parties may contact the data protection officer for all matters relating to the processing of their personal data and the exercise of their rights deriving from this regulation by sending an email to the following address. Address email@example.com
Users who believe that the processing of their personal data, carried out through this site, is in violation of the provisions of current legislation on the protection of personal data have the right to lodge a complaint with the Supervisory authority pursuant to art. 77 of the Regulations, or to take appropriate judicial offices.