European Regulation on the Protection of Personal Data No. 679/2016 (GDPR) and National Legislation – Legislative Decree No. 196 of 30 June 2003
This website, in compliance with the European Regulation on the protection of personal data No. 679/2016, known as GDPR, and with national legislation – Legislative Decree No. 196 of 30 June 2003 (commonly referred to as the “Privacy Code”), as amended, respects and protects the privacy of visitors and users, making every reasonable and proportionate effort not to infringe users’ rights.
The following privacy notice applies solely to online activities conducted via this website and is valid only for users or visitors of this site. It does not apply to any data collected through channels other than this website. The purpose of this privacy policy is to provide full transparency about the information collected by the site and how it is used.
1) Legal basis for processing
This website processes data based on user consent. By using or browsing this site, users and/or visitors explicitly agree to this privacy policy and consent to the processing of their personal data according to the methods and purposes outlined below, including potential disclosure to third parties if required for the provision of a service.
Providing personal data and therefore giving consent to its collection and processing is optional. Users may withhold or withdraw consent at any time (via the Contact link at the bottom of the page). Refusing consent may result in the inability to provide certain services and may compromise the browsing experience on the site.
From 10/07/2023 onwards, some data will be processed based on the legitimate interests of the Data Controller.
2) Purpose of data collection
Like all websites, this site uses log files in which information collected automatically during user visits is stored.
The data collected may include:
- Internet Protocol (IP) address;
- browser type and parameters of the device used to connect to the site;
- name of the Internet Service Provider (ISP);
- date and time of visit;
- referring and exit web pages;
- possibly the number of clicks.
This information is processed automatically and collected in aggregated form only, to verify the correct functioning of the site and, for security reasons, from 10/07/2023 this data will be processed based on the legitimate interests of the Data Controller.
For security purposes (spam filters, firewalls, virus detection), automatically recorded data may also include personal data such as the IP address, which may be used, in accordance with current laws, to block attempts to damage the site or other users, or in any case harmful or criminal activities. Such data is never used for user identification or profiling, but solely for the protection of the site and its users. From 10/07/2023 such data will be processed based on the legitimate interests of the Data Controller.
If the site allows for the posting of comments or if specific services are requested by the user, the site automatically detects and records some identifying data including the user’s email address. This data is voluntarily provided by the user at the time of the request to provide the service. By posting a comment or other information, the user expressly accepts this privacy policy, and in particular consents to the contents being made publicly available, including to third parties.
Data received will be used solely for the provision of the requested service and retained only for the time necessary to provide that service.
Any information that users choose to make public through the tools and services provided by the site is given voluntarily and knowingly by the user, who exempts this site from any liability regarding possible breaches of the law. It is the user’s responsibility to ensure they have the right to share third-party personal data or content protected by national and international laws.
The data collected by the site during its operation is used exclusively for the purposes stated above and stored for only as long as strictly necessary to perform the specified activities. In any case, data collected by the site will never be disclosed to third parties, unless it is a lawful request by judicial authorities and only in the cases provided by law.
3) Data processing location
Data collected by the site is processed at the headquarters of the Data Controller and at the web hosting data centre, which has been appointed as Data Processor. It processes data on behalf of the Data Controller and is located within the European Economic Area, acting in accordance with European regulations.
4) Cookies
This website, like all websites, uses cookies – small text files that store user preferences to improve the site’s functionality, simplify navigation by automating procedures (e.g. login, site language), and analyse site usage.
There are different types of cookies. Some are essential for browsing the site, while others serve different purposes such as ensuring internal security, administering the system, performing statistical analyses, identifying the most relevant sections for users, or providing a personalised experience.
Session cookies are essential for distinguishing between logged-in users and are useful to prevent a requested feature from being provided to the wrong user, as well as for security purposes to prevent cyber-attacks. Session cookies do not contain personal data and last only for the duration of the browsing session. No consent is required for these.
Functionality cookies used by the site are strictly necessary to deliver the services explicitly requested by the user (such as login), and no consent is required.
Disabling cookies
Cookies are linked to the browser used and can be disabled directly through the browser settings, thereby refusing or withdrawing consent to the use of cookies. Please note that disabling cookies may prevent some parts of the site from functioning properly.
Instructions for disabling cookies can be found on the following pages:
Mozilla Firefox – Microsoft Internet Explorer – Microsoft Edge – Google Chrome – Opera – Apple Safari.
Third-party cookies
This site also acts as an intermediary for third-party cookies, which are used to provide additional services and features to visitors and to improve the use of the site, such as social media buttons and embedded videos. This site has no control over third-party cookies, which are entirely managed by the respective providers. Therefore, information regarding the use of such cookies, their purposes, and how to disable them is provided directly by the third parties via the links below.
In particular, this site uses cookies from the following third parties:
– Google Analytics: a Google analysis tool that uses cookies (performance cookies) to collect anonymous, aggregated browsing data (IP addresses are anonymised) in order to examine how users interact with the website, compile reports on site activity, and provide other relevant services including visitor statistics and page views. Google may transfer this information to third parties where required by law or where such third parties process the information on Google’s behalf. Google does not associate IP addresses with other data held by Google. Data sent to Google is stored on servers in the United States.
Under a specific agreement with Google, which acts as a data processor, it undertakes to process data in accordance with the instructions of the Data Controller (see end of this policy). The advertising and data sharing settings respect the privacy preferences of the user.
For further details, visit Google Analytics Cookie Usage on Websites.
More information on how Google processes data can be found on Google’s dedicated page and in the page on How Google uses information from sites or apps that use its services.
– YouTube: a video-sharing platform owned by Google, which uses cookies to collect user and device information. Embedded videos on this site do not set cookies unless the user voluntarily plays the video, due to the “enhanced privacy mode (no cookie)” setting.
Social Network Plugins
This website also incorporates plugins and/or buttons for social networks to enable easy sharing of content on your favourite platforms. These plugins do not set cookies upon accessing the page, in order to protect user privacy. Cookies may be set – if so required by the social networks – only when the user actively uses the plugin. Please note that if you are logged into a social network, you have already agreed to the use of cookies conveyed through this site at the time of registration with the respective platform.
The collection and use of information obtained through plugins are governed by the privacy policies of the respective social networks, to which we refer:
Facebook – (cookie policy)
Twitter – (cookie policy)
LinkedIn – (cookie policy)
5) Data transfers outside the EU
This site may share some of the data it collects with services located outside the European Union, particularly with Google, Facebook, and Microsoft (LinkedIn) via social plugins and Google Analytics. Such transfers are authorised based on specific decisions of the European Union and the Italian Data Protection Authority, particularly Decision 1250/2016 (Privacy Shield – see the Italian Authority’s info page), meaning no further consent is required. The aforementioned companies adhere to the Privacy Shield framework.
6) Security measures
This site processes user data lawfully and fairly, employing appropriate security measures to prevent unauthorised access, disclosure, modification, or unauthorised destruction of data. Processing is carried out using computer and/or telematic tools, with organisational procedures and logic strictly related to the stated purposes. In addition to the Data Controller, in some cases, categories of personnel involved in the organisation of the site (administrative, commercial, marketing, legal, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) may have access to the data.
7) User rights
Under current regulations (EU Regulation 2016/679) and national legislation, users may, in accordance with applicable terms and limits, exercise the following rights:
- Request confirmation of the existence of their personal data (right of access);
- Know the origin of the data;
- Receive intelligible communication;
- Be informed about the logic, methods and purposes of processing;
- Request updates, rectification, integration, deletion, anonymisation, or blocking of data processed unlawfully, including data no longer necessary for the original purposes;
- In cases where processing is based on consent, receive their data in a structured, machine-readable format commonly used on electronic devices, at the sole cost of the medium;
- The right to lodge a complaint with the Supervisory Authority (Garante Privacy – www.garanteprivacy.it);
and, more generally, to exercise all rights granted by applicable laws.
Requests must be submitted to the Data Controller.
When data is processed based on legitimate interest, the rights of the data subject are still guaranteed (excluding the right to data portability, which is not provided for), particularly the right to object to processing, which can be exercised by contacting the Data Controller.
8) Data Controller
The Data Controller, pursuant to current legislation, is GRIF S.R.L., contactable via the CONTACT section.
Updates
This privacy policy is updated as of 23/10/2024