Information pursuant to EU Regulation 2016/679 ("GDPR")
Last updated [24-05-2018]
1WHO TREATS YOUR DATA?
Holder of the treatment
The Taverna del Castello, in the personal of its lawyer, is represented by Fontanelli Alessandro, via castelfalfi castello 57, Montaione 50050, p.iva 06694310480, CF fntlsn79b08i046t.
Responsible for the protection of personal data (DPO)
We have appointed a Data Protection Officer pursuant to art37 of the General Data Protection Regulation n2016/679 ("GDPR")We remind you that you can contact the DPO at any time and send any question or request regarding your personal data and respect for your privacy by writing to the following email address firstname.lastname@example.org
Your personal data may be brought to the attention of our employees or collaborators, belonging to the categories of administrative, commercial, legal, accounting or IT system administrators, depending on the treatment, who, operating under our direct authority, are appointed as data processors and receive adequate operating instructions in this regardThe recipients of your data also include third party service providers relating to payments, shipments, marketing services, hosting providers and information systems engineering services providers, IT companies or companies specialized in market research and data processing with which we enter into agreements that require them to adopt appropriate technical and organizational measures for the protection of your personal dataYour data may also be passed on to the police and judicial and administrative authorities in accordance with the law.
We can also transfer your personal data in the case of sale or transfer in whole or in part of our business or assets (also in the event of reorganization, spin-off, dissolution or liquidation).
In no case do we transfer or sell your personal data.
2WHAT TYPES OF DATA DO WE COLLECT?
Personal data means all information relating to the user that allows us to identify him, such as name, contact details, payment details and information on his access to the Site.When you register on our site, create an account, use our services or contact our support service, we collect some of your personal dataSome of the aforementioned data are provided voluntarily by the user himself while others collect them automatically.
Data provided voluntarily by the user
The Site offers users the opportunity to voluntarily provide personal information through, for example, the creation of an account, the purchase / sale of products through our Site, the insertion of a review or comment, the compilation of the return service. , the compilation of the contact forum or the use of the messaging and chat service with our customer service or how much you contact us to leave us your comments or opinionsIn case you need to contact us by phone, we record the call for training and improvement of our services and we take notes in relation to your callWe remind you that you can register on the Site and create an account also using an account of a social network, such as a Facebook accountIn the event that you register through this method by releasing the authorizations requested during registration, we will receive information from your social network account, such as for example name and surname, position, basic personal data.
When I use the Site as a Seller, the contents and images inserted in your online showcase will also be visible to other users; in the same way, when you leave comments and reviews in the appropriate sections of the Site, the contents of your reviews, your name and your photo (if uploaded) will be visible to those who access the Site.
We do not process sensitive data, or details on physical health or mental health, on the alleged commission of crimes or criminal convictions, however, in the event that you spontaneously have to share any of this information with us, we will process this data only with your explicit consent.
Third party data
If you decide to provide third party data make sure that these subjects have been previously and adequately informed on the methods and purposes of treatment indicated hereIn relation to this hypothesis, you position yourself as an independent data controller, assuming all legal obligations and responsibilities.
Data of minors under 16
In this regard, we remind you that if you are under 16 you cannot provide us with any personal data, and in any case we do not take any responsibility for any false statements you provide.If we become aware of the existence of false declarations, we will proceed with the immediate cancellation of any personal data acquired.
We collect the following data through the services you use:
- technical data: This category of data includes the IP addresses or domain names of the computers you use when you connect to the Site, the addresses in URI (Uniform Resource Identifier) notation of the requested resources, the time of the request, the method used in the submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to your operating system and the IT environmentThese data are used only for statistical information (therefore they are anonymous), to check the correct functioning of the Site and are deleted immediately after processingThe data could be used to ascertain responsibility in case of hypothetical computer crimes against the site: except for this eventuality, the data on web contacts do not persist for more than 7 days.
- data collected using cookies or similar technologies: for more information, please visit the "Cookies" section.
3FOR WHAT PURPOSE DO WE PROCESS YOUR DATA?
a) To guarantee access to our site and use of our services
When you use our site and related services, we will use your personal data to allow you to register on the site and create a personal account, to verify your identity as a user of the site, to allow you to buy / sell products and, where appropriate, make the products purchased, to provide customer service and to resolve any problems you report, to send you necessary communications (such as confirming the purchase order or confirming the successful payment or remembering products on your cart) as well as for provide you with all the additional services described in the General Conditions.
b) For information regarding products, services, events and for other promotional purposes
If you have expressly given us your consent or if we have a legitimate interest (pursuant to applicable legislation), we will use your data to update you on the products and services we offer as well as to inform you about the Company's promotional, commercial and advertising activities or third-party commercial partners via e-mail, sending SMS or whatsapp; only if you are a professional could we notify you of these promotions and events by phone call via operator or customer care service consisting of offering dedicated services during sales and after salesFurthermore, always with your consent or if we have a legitimate interest (pursuant to the applicable legislation), we may use your data in the context of carrying out market research and surveys for the detection of your satisfaction, by e-mail, sending SMS or whatsapp, in order to improve our services and the relationship with our users
c) To offer you a personalized service
If you have expressly given your consent , we use your data to analyze your consumption habits and choices, in order to offer you a personalized service in line with your interests and to improve our commercial offer.
d) To improve the services we offer through the Site
We will use the data provided to improve the services we offer through the Site and your product purchase / sale experienceIn particular, we will be able to analyze the use and measure the effectiveness of our Site and our services for a better understanding of how it is used in order to improve it and to involve and retain users.
e) To guarantee our rights, ownership or data security
We may also use personal data in connection with the use of our Site to prevent or detect fraud, abuse, illegal use, violations of our General Conditions, and to comply with court orders, government requests or fulfill applicable legal provisions.
4WHAT IS THE LEGAL BASIS OF THE TREATMENT?
We will only process your personal data in cases where we have a legal basis for doing so.
In most cases we will process your data to guarantee access to the Site and the services offered thereIn addition, we may process your data for one or more of the following reasons:
▪ With your explicit consent (for example to inform you about our products, services, events and for other promotional purposes, as well as to offer you a personalized service)
▪ To ensure compliance with legal obligations, regulations and community rules (for example, to comply with court orders, government requests or to comply with applicable legal provisions)
▪ For our legitimate interest (for example to improve the services we offer through the Site or to guarantee the ownership and security of the data we process).
5IS THE PROVIDING OF DATA COMPULSORY?
The provision of personal data is mandatory only for the processing necessary to guarantee access to our site and to the services we offer through it.Any refusal to provide personal data requested for this purpose makes it impossible to register on the Site and use the related servicesAll other provisions of your information are optional, but providing them allows us to offer you a better experience.
6HOW DO WE PROCESS YOUR DATA AND FOR HOW LONG?
The storage of personal data will take place in paper and / or electronic form and for the time strictly necessary to pursue the purpose referred to in point 3 above ("For what purposes do we process your data?").
In particular, when you register on the Site and create an account, we process and store most of your information in our possession for as long as you actively use the services we offer through the Site.Following the closure of your account, we will keep your personal information for a maximum period of 24 months from the date of cancellation of the account for defense purposes and / or to assert our right in court and / or out of court in case of disputes. legal to the execution of our services; your further personal information relating to transactions made through the Site is kept for 10 years pursuant to the law (including tax obligations).
For direct marketing and profiling purposes, we keep your data for a maximum period equal to that provided for by the applicable legislation, respectively equal to 24 and 12 months from the last interaction, of any kind on your part with the Site.
For analysis purposes aimed at improving the service, the user's personal data will be subject to a maximum retention period of 24 months from the date of their registration.
At the end of the maximum retention period, personal data as provided for in this section will automatically delete your data or anonymize them permanently and irreversibly.
We remind you that in the event that you do not exercise any active action (such as, use of the services offered by the Site, navigation, searches and / or any other way of using the Site) for a continuous period of 36 months, you will be classified as an inactive user and, upon written communication concerning the deactivation of your account, we will keep your personal data for the maximum retention period provided therein.
7HOW CAN YOU EXERCISE YOUR RIGHTS?
Consistent with the provisions of the GDPR, you have the right to request, at any time, access to your personal data, the correction or cancellation of the same, to object to their treatment or to exercise the right to portabilityThe applicable legislation on the protection of personal data also allows you to exercise the right to request the limitation of treatment in the cases provided for by art18 of the GDPR, as well as obtaining the data concerning you in a structured format, commonly used and readable by an automatic device, in the cases provided for by art20 of the GDPR.
Requests can be sent to the email address email@example.com
In particular, if you want to authorize the activities referred to in letters b) (Marketing purposes) in the previous point 3 ("For what purposes do we process your data?") And subsequently do not wish to receive further communications from us or want to limit the methods with to be contacted, you can interrupt these communications at any time by simply clicking on the appropriate "unsubscribe" link at the bottom of each communication.
Finally, we remind you that you always have the right to lodge a complaint with the competent supervisory authority (Guarantor for the Protection of Personal Data), pursuant to art77 of the GDPR, if you believe that the processing of your data is contrary to the legislation in force.
8HOW DO WE GUARANTEE THE PROTECTION OF YOUR DATA?
Your personal data are processed by the subjects indicated in the previous point 1 ("Who processes your data?"), In accordance with the provisions of current legislationIn particular, to ensure the security of your data taking into account the state of the art and implementation costs, as well as the nature, object, context and purposes of the processing, as well as the risk of varying probability and seriousness for the rights and freedoms of natural persons, we have adopted adequate technical and organizational measures to ensure an adequate level of security to the risk.
9WHEN WAS THIS NOTICE UPDATED?
This information was published on the date indicated in the header and may undergo changes over time also related to the possible entry into force of new sector regulations, to the updating or provision of new services or to technological innovationsIn this case, the joint controllers will notify you giving evidence of these updates.
If the "Work with us" page is active on our website, you can consult our open professional positions or send your spontaneous application.
The curricula received, following the communication through the Site of our open professional positions or if you decide to send us your curriculum, will be kept for a maximum period of 6 months from the date of receipt for the sole purpose of evaluating your application or for re-evaluated for subsequent searches for professional positions compatible with your profile provided they are activated during the maximum retention period of your dataYou can object to the processing of your personal data at any time by writing to firstname.lastname@example.org
If you apply, remember to include in your curriculum vitae the declaration with which you consent to the processing of personal data for the purpose of selection and avoid entering sensitive personal data (such as health status, religious, philosophical or political beliefs ) not relevant to the job offer.
(b) Third party links
11DO YOU HAVE MORE QUESTIONS?
If you wish to provide feedback or if you have questions or concerns, please contact our DPO or send an email to email@example.com