PRIVACY POLICY FOR WEBSITE VISITORS

Pursuant to EU Regulation 2016/679, this Privacy Policy is intended to describe how the website owned by ASSOCIAZIONE “ARCHIVIO OSCAR PIATTELLA ETS”, accessible at www.archiviopiattella.it, is managed with regard to the processing of the personal data of users/visitors who consult it.

This policy applies only to the website referred to above and not to any other websites that the user may visit through specific links.

ASSOCIAZIONE “ARCHIVIO OSCAR PIATTELLA ETS” guarantees compliance with legislation on the protection of personal data. Users/visitors are therefore invited to read this Privacy Policy carefully before submitting any kind of personal information and/or completing any electronic form on the website.

Data Controller is ASSOCIAZIONE “ARCHIVIO OSCAR PIATTELLA ETS” C.F. 02760330411, with registered office in Cantiano, Via Dante Alighieri, 24, 61044 Cantiano (Pesaro e Urbino).

EMAIL: info@archiviopiattella.it

In addition, any partner websites that from time to time take part independently in data-processing activities may act as independent data controllers.

 

Subject of processing

Following navigation of the website, the Association will process personal data that may be summarised as follows:

  1. Browsing data

The information systems and software procedures used to operate this website acquire, in the course of their normal operation, certain personal data which are then implicitly transmitted through the use of Internet communication protocols.

By their nature, this information could, through association and processing with data held by third parties, make it possible to identify users/visitors (for example IP addresses, domain names of computers used by users/visitors connecting to the website, etc.).

These data are used only for static information and to check the proper operation of the website.

Data relating to web contacts are not, in any event, retained for more than seven days, except where required for investigations into computer crimes against the website.

No data deriving from the web service will be communicated or disseminated.

  1. Data voluntarily provided by users/visitors

If users/visitors, while connected to this website, send their personal data in order to access specific services, they are aware that this entails the acquisition by the Data Controller of the sender’s address and/or any other personal data, which will be processed exclusively for the provision of the service.

Personal data provided by users/visitors will be communicated to third parties only where such communication is necessary to comply with the requests of the users/visitors themselves or is required by law.

  1. Cookies

In addition to the data expressly provided to the Data Controller, other data arising from the user’s navigation of the website may be recorded: when the user accesses the website, the website may send the user a “cookie”. A “cookie” is a small text file that the website may automatically send to the user’s computer when the user views our pages. “Cookies” are used to make navigation more convenient, as well as to obtain information on the individual user’s navigation within the website and to enable certain services that require identification of the user’s path across different pages of the website. For every access to the website, regardless of the presence of a “cookie”, the website records the type of browser (e.g. Internet Explorer, Chrome, Firefox), the operating system (e.g. Windows, Macintosh), the host and source URL of the user-browser, as well as data relating to the requested page. These data may be used in aggregated and anonymous form for statistical analyses of website usage.

While browsing a website, the user may also receive on their computer cookies from websites or web servers other than the one they are visiting (so-called “third-party” cookies).

For complete management of cookies, users/visitors are invited to consult the “Cookie Policy” page of this website.

 

Processing methods

Processing is carried out using automated tools (e.g. electronic procedures and media) and/or manually (e.g. on paper) for the time strictly necessary to achieve the purposes for which the data were collected and, in any event, in accordance with the applicable legal provisions.

 

Purposes of processing

In addition to the purposes indicated in the individual notices that precede completion of forms in the various sections of the website, the purposes of processing carried out by the Data Controller are as follows:

  1. Processing the personal data provided and those inferred from navigation of the website in order to provide a service consistent with the information supplied during use of the service;
  2. Providing the services requested from time to time (for example: “do you need a shipment”, “log in”, “register”);
  3. Managing the contractual relationship and implementing contractual and pre-contractual measures aimed at purchasing our products, and responding to and satisfying requests for assistance or information; communications between the parties during the relationship may take place by email, SMS and/or telephone using the contact details provided by the user;
  4. Allowing the creation and management of a personal account (register);
  5. Fulfilling any obligations provided for by applicable laws, regulations or EU legislation;
  6. Purposes connected with the performance of our activities, such as:
  • Sending commercial communications concerning products and services similar to those purchased (Soft Spam).
  • Marketing: sending commercial/promotional communications concerning products and services by telephone call, SMS, email, messaging services (e.g. WhatsApp), paper mail, social networks and digital channels, newsletters.

Finally, any interactions between the user and social networks may also be processed in accordance with the principles of lawfulness, fairness and transparency. In this regard, the Data Controller may use marketing and targeting services made available from time to time by such third-party platforms, including social media (such as, for example, Facebook).

  1. Prevention of fraud committed through the use of the website and the services offered by the Data Controller, and to allow the Data Controller to protect its rights in legal proceedings.

 

Legal basis for processing

The legal basis for the processing of Customers’ data carried out by the Data Controller through the website referred to above is the Data Controller’s legitimate interest in freedom of economic initiative under Article 41 of the Italian Constitution, as well as Article 6(1)(b) of the Regulation (“…processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract”).

With regard to additional purposes requiring consent (marketing), consent will be requested in the appropriate section and must likewise be regarded as a valid legal basis for the additional processing of the data. Providing data for these purposes is entirely optional and does not affect use of the services. The user/visitor is free to withdraw consent given for these purposes and to object at any time by contacting the Data Controller.

The processing of personal data for Soft Spam purposes constitutes lawful processing under the applicable legislation in force on the protection of personal data and does not require consent. The user/visitor may object to processing for this purpose both when requesting the products/services available on the website and when receiving subsequent communications from the Data Controller, by writing to the contact details indicated above, by using the link at the bottom of each communication sent by email, or by withholding consent for marketing purposes.

 

Recipients

In addition to the Data Controller, in some cases the following recipients may have access to the data:

  • Parties that typically act as data processors, including, by way of example:
  • Individuals, companies or professional firms providing assistance and consultancy to the Data Controller in accounting, administrative, legal, financial and debt-recovery matters in relation to the provision of services and management of the relationship;
  • Parties with whom it is necessary to interact in connection with the provision of services and management of the relationship (for example hosting providers, providers of services supporting marketing activities, as well as providers of related services
  • Or parties appointed to carry out technical maintenance activities (including maintenance of network equipment and electronic communications networks).
  • For marketing purposes, the Association may process personal data in order to use marketing and targeting services made available by third-party platforms, including social media (such as, for example, Fecebook and Google). Use of such services may make it necessary for the Data Controller to communicate personal data to those third-party platforms.
  • Parties, entities or authorities to whom personal data must be communicated pursuant to legal provisions or orders issued by authorities, or in order to prevent and/or identify possible fraudulent activities or abuses in the use of the website and the services offered by the Data Controller.
  • Persons authorised by the Data Controller to process personal data as necessary to carry out activities strictly related to the provision of services, who have undertaken to maintain confidentiality or are subject to an appropriate legal obligation of confidentiality (e.g. employees and/or collaborator).

 

Transfer to a third country

For the services offered by the website, the Data Controller uses servers located in the EU.

The data processed by the Data Controller will never be disseminated.

OR

For the services offered by the website, the Data Controller uses servers located on infrastructure with facilities outside the EU. The data collected may therefore be transferred to third-party service providers (mentioned above) for the purposes described in this Privacy Policy. When the user/visitor provides personal data, they consent to such transfer. Although the Association is aware that the Court of Justice of the European Union has invalidated the Privacy Shield adequacy decision, the Association undertakes to ensure that the third-party service provider offers appropriate safeguards and adopts adequacy decisions, imposing protection and security obligations equivalent to those guaranteed by the Data Controller.

To learn more about our third-party service providers located outside the EU and their privacy policies, please consult the following addresses:

  • Hosting company: keliweb

The privacy link https://www.keliweb.com/privacy.php is provided, setting out its policy regarding the protection of data entrusted to it from the EU.

 

Data retention times and location

Data are processed for the time necessary to provide the service requested by the User and are then destroyed using secure destruction methods, such as paper shredders for hard-copy documents and wiping for data stored on electronic media.

If an account is created (“register” section), personal data will be retained and processed for as long as the account remains active.

For marketing and soft spam purposes, data will be processed and stored by the Data Controller until the user/visitor withdraws consent or until the user/visitor exercises the right to erasure of personal data by writing to the contact details indicated above or through the “contact” section of the website, or by withholding consent for Marketing purposes in the forms on the website.

 

Optional or mandatory provision of data

Apart from the browsing data specified above, which are acquired automatically, users/visitors are free to provide or not provide their personal data.

Failure to provide such data may only make it impossible to obtain what has been requested.

 

Rights of the data subject

As a Data Subject and in relation to the processing described in this Notice, the user/visitor has the rights set out in Articles 7, 15 to 21 and 77 of the GDPR and, in particular:

  • right of access – Article 15 GDPR: the right to obtain confirmation as to whether or not personal data concerning the Customer are being processed and, where that is the case, access to those personal data, including a copy thereof;
  • right to rectification – Article 16 GDPR: the right to obtain, without undue delay, rectification of inaccurate personal data concerning the Customer and/or completion of incomplete personal data;
  • right to erasure (right to be forgotten) – Article 17 GDPR: the right to obtain, without undue delay, erasure of personal data concerning the Customer;
  • right to restriction of processing – Article 18 GDPR: the right to obtain restriction of processing where: the Data Subject contests the accuracy of the personal data, for the period necessary for the Data Controller to verify the accuracy of those data; the processing is unlawful and the Data Subject opposes erasure of the personal data and requests restriction of their use instead; the personal data are required by the Data Subject for the establishment, exercise or defence of legal claims; the Data Subject has objected to processing pursuant to Article 21 GDPR, pending verification as to whether the legitimate grounds of the Data Controller override those of the Data Subject;
  • right to object – Article 21 GDPR: the right to object at any time, on grounds relating to the User’s particular situation, to processing of personal data concerning the User based on the lawful grounds of legitimate interest or the performance of a task carried out in the public interest or in the exercise of official authority, including profiling, unless there are compelling legitimate grounds for the Data Controller to continue processing which override the interests, rights and freedoms of the Data Subject, or for the establishment, exercise or defence of legal claims. In addition, the right to object at any time to processing where personal data are processed for direct marketing purposes, including profiling to the extent that it is related to such direct marketing;
  • right to withdraw consent – Article 7 GDPR: the Customer has the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal;
  • right to lodge a complaint – Article 77 GDPR: the Customer has the right to lodge a complaint with the Italian Data Protection Authority by sending a registered letter with acknowledgement of receipt to: Piazza Venezia n. 11, 00187 ROME; or a certified email (PEC) to protocollo@pec.gpdp.it.

The user/visitor may exercise their rights at any time by sending a registered letter with acknowledgement of receipt to: ASSOCIAZIONE “ARCHIVIO OSCAR PIATTELLA ETS”, Via Dante Alighieri, 24, 61044 Cantiano (Pesaro e Urbino), or by sending an email to: info@archiviopiattella.it

 

Final provisions

In view of the current state of development of legislation on the protection of personal data, please note that this Privacy Policy may be subject to updates.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.