Privacy Policy EN
Dear User, pursuant to Articles 12 et seq. of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation, “Regulation” or “GDPR”), and generally in compliance with the principle of transparency provided for by the Regulation itself, we hereby provide the following information on the processing of personal data (i.e., any information relating to an identified or identifiable natural person: “Data Subject”) carried out in connection with browsing the website www.prpguarnizioni.it and the relative interaction by the User (please note that this privacy policy does not apply to other websites that may be consulted by the user via links present on the Website).
DATA CONTROLLER AND DATA PROTECTION OFFICER
The Data Controller (i.e., the entity that determines the purposes and means of the processing of personal data, “Data Controller” or “Controller”) is P.R.P. di Pievani S. & C. s.n.c., Via Provinciale, 4/G – 24060 Adrara San Martino (BG), Tel +39 035933450, email: info@prpguarnizioni.it. [1]
1. USER BROWSING DATA
The IT systems and software programs used to operate the Website collect certain personal data, the transmission of which is implicit in the use of Internet communication protocols (e.g., IP addresses or domain names of computers used by users connecting to the Website, the URI – Uniform Resource Identifier – addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server – success, error, etc. – and other parameters related to the user’s operating system and computer environment). Although this information is not collected to be associated with identified data subjects, by its very nature, through processing and association with data held by third parties, it could allow users to be identified.
These data are used for the sole purpose of obtaining anonymous statistical information on the use of the Website and to check its correct functioning, and they are deleted immediately after processing. The data could be used to ascertain liability in the event of hypothetical cybercrimes against the Website.
Therefore, the legal basis for the processing is the legitimate interest in the functioning and security of the Website.
2. COOKIES
Browsing Data
This website implicitly acquires, using internet communication protocols, for and during its normal operation, certain personal data of users accessing the website itself, such as the IP address, the domain names of the computers from which the user accesses, the MAC addresses assigned by the manufacturers of the network cards, wireless, etc.
This information is not collected to identify users, but it could be through association and processing, including cross-referencing with third-party data; from these data, statistical information on the use of the website and its operation is obtained, as well as further information in case of liability assessment regarding cybercrimes.
What are cookies?
Cookies are small text strings that websites visited by the user install on their terminal; these strings are subsequently retransmitted to the site that installed them upon a subsequent visit by the user. If the user, while browsing the website, also receives cookies sent by different websites or web servers, these are referred to as third-party cookies.
Cookies are installed for various purposes, which may include the possibility of performing computer authentication, monitoring browsing sessions, and choosing the language.
Types of cookies
- Technical cookies: These are normally installed directly by the website operator and are cookies that allow communication between the website and the user. They can also be called “browsing” or “session” cookies, or even “essential cookies” or “necessary cookies”, and are designed to guarantee normal navigation and use of the website, usually lasting for the duration of the browsing session on the website. Since these cookies are necessary for the operation of the website, their installation on the user’s terminal does not require prior consent.
- Functionality cookies: These cookies allow advanced features and personalizations to be provided to the user, as well as remembering the preferences indicated during previous visits, or changes made by the user in previous visits to customize the website. This category includes, for example, cookies that allow the user to choose the language or save products selected in the shopping cart.
- Performance cookies: These cookies are also called “analytics cookies” and allow the analysis of how the user uses the website, in order to improve the browsing experience and resolve issues related to navigation. These cookies allow, for example, counting visits and traffic sources, or tracking the most viewed pages. They do not usually allow the individual user to be identified, as they contain aggregated and therefore anonymous data. One of the most famous tools for obtaining such statistical reports is Google Analytics, a service provided by Google Inc.
- Profiling cookies: These are also known as “advertising cookies” and are used to track a user’s preference and offer them advertising messages based on the preferences obtained.
3. DATA VOLUNTARILY PROVIDED BY THE USER THROUGH THE WEBSITE, WITHIN THE SCOPE OF CONTACTS WITH THE CONTROLLER
No provision of personal data by the user is required to consult the website.
However, any contact with the Data Controller, or the optional, explicit, and spontaneous sending of messages, electronic or traditional mail, to the Controller’s contact details indicated on the website entails the subsequent acquisition of the sender’s address (including email address), necessary to reply to requests, as well as any other personal data included in the relative communications. These data will be used for the sole purpose of following up on the user’s request and may be communicated to third parties only if necessary for this purpose.
The consent of the Data Subject is not required for data processing for these purposes, as the processing is necessary for the performance of a contract to which the data subject is a party or for the performance of pre-contractual measures adopted at their request (Art. 6, paragraph 1, letter b) of the Regulation), as well as, where applicable, to comply with a legal obligation (Art. 6, paragraph 1, letter c) of the Regulation).
The processing of personal data will be carried out by personnel trained and authorized by the Data Controller using appropriate procedures, technical, and IT tools to protect the confidentiality and security of the data.
These personal data are kept for the time strictly necessary to provide the Data Subject with the answers to the requests made and during the validity period of the quotation, without prejudice to further retention obligations provided for by law. Upon the eventual conclusion of the contract, the specific privacy policy on the processing of personal data will be promptly provided.
Personal data will not be disseminated.
4. PROCESSING METHODS AND COMMUNICATION OF DATA TO THIRD PARTIES
The data are not subject to dissemination and may be communicated to collaborators and suppliers of the Data Controller, within the scope of their respective duties and/or contractual obligations relating to the execution of the contractual relationship with the Data Subjects; among the suppliers of the Data Controller, by way of example, are banking and credit institutions, insurance companies, legal consultants, software providers and related technical assistance, entities performing shipping and deliveries, as well as the financial administration and other Bodies for which mandatory communications are required. Processing will be carried out:
- Through the use of manual and automated systems;
- By individuals or categories of persons authorized to fulfill the relative tasks;
- With the use of appropriate measures to guarantee data confidentiality and prevent access to the same by unauthorized third parties.
Without prejudice to what is stated in the specific sections above, within the scope of its activities and for the purposes indicated above, the Data Controller may use services provided by third parties operating either as autonomous controllers or on behalf of and according to the instructions of the Controller, as data processors pursuant to Art. 28 of the Regulation. These are entities that provide processing or instrumental services to the Data Controller.
In general, the Data Subject may request a complete and updated list of the entities appointed as data processors by contacting one of the Data Controller’s contact details.
Furthermore, access to data may be granted to all entities whose right of access to such data is recognized by virtue of regulatory provisions.
5. RIGHTS OF THE DATA SUBJECT
The GDPR grants the Data Subject the exercise of the following rights with reference to personal data concerning them (the brief description is indicative; for the full statement of rights, including their limitations, please refer to the Regulation, and in particular to Articles 15-22):
- Access to personal data: (The Data Subject has the right to receive free information regarding their personal data held by the Data Controller and the relative processing, as well as to obtain a copy in an accessible format);
- Rectification of personal data: (Upon notification by the Data Subject, correction or integration of incorrect or inaccurate personal data – which do not express evaluative elements –, including those that have become inaccurate because they are not updated);
- Erasure of personal data (Right to be forgotten): (For example, the data are no longer necessary in relation to the purposes for which they were collected or processed; they have been processed unlawfully; they must be erased to comply with a legal obligation; the Data Subject has withdrawn consent and there is no other legal ground for the processing; the Data Subject objects to the processing, provided that the conditions are met);
- Restriction of processing: (In certain cases – dispute of the accuracy of data, for the time necessary for verification; dispute of the lawfulness of the processing with opposition to erasure; necessity of use for the establishment, exercise or defense of legal claims by the Data Subject, while they are no longer useful for the purposes of processing; if there is an objection to the processing, while the necessary verifications are carried out – the data will be stored in such a way that they can eventually be restored, but, in the meantime, they cannot be consulted by the Data Controller except in relation to verifying the validity of the restriction request by the Data Subject, or with the Data Subject’s consent, or for the establishment, exercise or defense of legal claims in court, or to protect the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State);
- Objection: In whole or in part, for reasons related to the particular situation of the Data Subject, to processing carried out on the basis of legitimate interest (and the Data Subject may in any case object to the processing of their personal data for direct marketing purposes, including profiling to the extent that it is connected to such direct marketing);
- Data portability: (If the processing is based on consent or on a contract and is carried out by automated means, upon request, the Data Subject will receive the personal data concerning them in a structured, commonly used, and machine-readable format, and may transmit them to another Data Controller without hindrance from the Data Controller to whom they were provided and, if technically feasible, may obtain that said transmission be carried out directly by the latter);
- Withdrawal of consent: (If the processing is based on consent expressed by the Data Subject, they may withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal);
- Lodging a complaint: With the supervisory authority (Garante per la protezione dei dati personali – Italian Privacy Authority). The Italian Data Protection Authority can be contacted through the contact details indicated on the Authority’s website: www.garanteprivacy.it.
EXERCISE OF RIGHTS:
The Data Subject may exercise their rights by sending a request to the Data Controller at the following addresses:
- By mail: P.R.P. di Pievani S. & C. s.n.c., Via Provinciale 4/G, 24060 Adrara San Martino (BG)
- By email: info@prpguarnizioni.it [1]
The Data Controller may modify or update its content in whole or in part, also taking into account any changes in personal data protection regulations. Data Subjects are therefore invited to regularly consult this page so as to be aware of matters relating to processing operations.
