INFORMATIVE NOTICE ON THE PROCESSING OF YOUR PERSONAL DATA PURSUANT TO ARTICLE 13 OF EUROPEAN REGULATION 679/2016
This informative notice is provided by Ecostar S.r.l., data controller of the web site www.eco-star.it pursuant to Article 13 of European Regulation 679/2016 (GDPR) in consideration of the decision of the Data Protection Authority of 8 May 2014 “Simplified procedures for cookie notices and consent” (published in the Gazzetta Ufficiale (Official Gazzette) 126 of 3 June 2014). This informative notice applies only to the web site in question and not to other web sites that the user may consult via links.
Data controller. The data controller is Ecostar S.r.l., with registered office at Via Leonardo da Vinci, 3 Sandrigo (VI), tax code and VAT no. 02668250240, in the person of its pro tempore legal representative, Mr. Domenico Cappozzo, who can be contacted by telephone on +39 044 475 0942, fax +39 044 475 0942, certified email: firstname.lastname@example.org or email: email@example.com
Purpose of processing. The data will be processed in relation to the Personal Data collected and used by our website www.eco-star.it based on your activity and/or operations on the site.
TYPES OF COLLECTED DATA
The Personal Data collected by this website, independently or through third parties, include: Cookies, usage data, email, given name, surname, phone number and city.
Personal Data may be freely given by the User. Usage Data are collected automatically during website use.
Unless stated otherwise, all data requested by this Website are mandatory. The Website may be unable to provide the service if the User refuses to share his/her Personal Data. Users are free to refrain from communicating data identified as optional, without this having any effect on the availability or the operation of the service.
Users are encouraged to contact the Data Controller if they have questions about which data are required.
The User assumes responsibility for third-party Personal Data obtained, published or shared via this Website and declares to have the right to communicate or disclose them, holding the Data Controller harmless from any liability toward third parties.
MEANS AND PLACE OF COLLECTED DATA PROCESSING
Means of processing
The Data Controller takes appropriate security measures to prevent unauthorised access, disclosure, alteration or destruction of Personal Data.
Processing is done by computer or web tools, with organisational means and logic closely correlated to the purposes indicated. In addition to the Data Controller, other persons involved in the organisation of this Website (administrative, commercial, marketing, legal, system administrator staff) or external parties (supplying third-party technical services, postal couriers, hosting provider, computer companies, communication agencies) may have access to data, and may also be appointed, if necessary, as Data Processors by the Data Controller. The updated list of Data Processors may be requested from the Data Controller.
Legal basis of processing
The Data Controller processes the User’s Personal Data under one of the following conditions:
- the User has consented to one or more specific purposes. N.B.: in some jurisdictions, the Data Controller may be authorised to process Personal Data without the User’s consent or another of the legal bases specified below, until the User opposes (“opt out”) processing. However, this is not applicable where Personal Data processing is governed by European Personal Data protection legislation;
- processing is necessary to execute a contract with the User and/or execute pre-contractual provisions;
- processing is necessary to fulfil a legal obligation to which the Data Controller is liable;
- processing is necessary to perform a task in the public interest or in the exercise of official authority vested in the holder;
- processing is necessary to pursue the Data Controller’s legitimate interests or those of third parties.
You can always ask the Data Controller to clarify the legal basis of any processing and in particular to specify whether processing is based on the law, covered by a contract or necessary to conclude a contract.
The Data are processed at the Data Controller’s operational sites and at any other place at which the parties involved in processing are located. Contact the Data Controller for more information.
The User’s Personal Data may be transferred to a country other than that of the User. For more information on the place of processing, please see the section on Personal Data processing.
Users have the right to obtain information on the legal basis for transferring Data outside the European Union or to an international organisation under public international law or constituted by two or more countries, such as the UN, including as regards the security measures taken by the Data Controller to protect the Data.
Should the Data be transferred as described, the User is invited to see the specific sections of this document or request information from the Data Controller via the contact information provided at the beginning of this document.
The Data are processed and stored for the time required by the purposes for which they were collected.
- Personal Data collected for purposes related to the execution of a contract between the Data Controller and the User will be kept until complete execution of the contract.
- Personal Data collected for purposes related to the Data Controller’s legitimate interest will be kept until satisfaction of such interest. The User can obtain further information on the Data Controller’s legitimate interest in the specific sections of this document or by contacting the Data Controller.
When processing is based on the User’s consent, the Data Controller may keep the Personal Data for a period until said consent has been withdrawn. Furthermore, the Data Controller may be required to keep the Personal Data for a longer period in order to comply with a legal requirement or by an order of an authority.
The Personal Data will be deleted at the end of the retention period. Therefore, upon expiry of this time limit, the right of access, cancellation and correction, and the right to data portability can no longer be exercised.
Purpose of the Processing of the collected Data
User Data are collected to allow the Data Controller to provide its Services and for the following purposes: statistics, interaction with social media and external platforms, advertising, and to contact the User.
For more detailed information on the purposes of Processing and on Personal Data with specific regard to each purpose, please see specific sections of this document.
Details on Personal Data Processing
Personal Data are collected for the following purposes and using the following services:
To contact the User
Contact form (this Website): by entering their Data in the contact form, Users consent to their use to respond to requests for information, quotes, or any other type of request indicated by the form header.
Collected Personal Data: city, surname, email, given name and phone number.
Interaction with social media and external platforms
This type of service enables interactions with social media or with other external platforms directly from this Website’s pages.
The interactions and information acquired by this Website are subject to the User’s privacy settings specific to each social network.
- YouTube (Google Inc.) button and widgets
The YouTube button and social widgets are services to interact with YouTube, supplied by Google Inc.
Collected Personal Data: Usage data
- LinkedIn button and widgets
The LinkedIn button and social widgets are services to interact with LinkedIn, supplied by Microsoft.
Collected Personal Data: Usage data
- Facebook (Facebook Inc.) Like button and social widgets
The Facebook Like button and social widgets are services to interact with Facebook, supplied by Facebook, Inc.
Collected Personal Data: Cookies and Usage data
This type of service uses User Data for commercial communication in various promotional forms such as banners, including in relation to the User’s interests.
This does not mean that all Personal Data are used for this purpose. The Data and conditions of use are indicated below.
Direct Email Marketing (DEM) for this Website.
This Website uses the User’s Data to send commercial proposals relating to products and services supplied by third parties or not related to the product or service provided by this Website.
Collected Personal Data: email address
Services contained in this section allow the Data Controller to monitor and analyse traffic data and are used to track User behaviour.
- Google Analytics (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google uses the collected Personal Data to track and examine the use of this Website, compile reports and share them with other services developed by Google.
Google may use your Personal Data to contextualise and personalise advertisements on its advertising network.
Collected Personal Data: Cookies and Usage data
- Google Tag Manager (Google Inc.)
Google Tag Manager is a statistics service provided by Google Inc.
Collected Personal Data: Cookies and usage data
Users may exercise certain rights with regard to the Data processed by the Data Controller. In particular, Users have the right to:
- withdraw consent at any time. Users may withdraw previously given consent to Personal Data processing.
- oppose the processing of their Personal Data. Users may oppose the processing of their Data when it is done on a legal basis different from that of consent. Further details on the right of opposition are provided in the section below.
- access their Data. Users have the right to obtain information on the Data processed by the Data Controller, on certain aspects of processing and to receive a copy of the processed Data.
- check and request correction. Users can verify the correctness of their Data and ask to have them updated or corrected.
- obtain limitation of processing. Under certain conditions, Users can request that processing of their Data be limited. In this case, the Data Controller will not process the Data for any other purpose except for their retention.
- have their Data deleted or removed. Under certain conditions, User can request that the Data Controller delete their Data.
- receive their Data or have them transferred to another Data Controller. Users have the right to receive their Data in a structured, commonly used format that can be read by an automatic device and, where technically feasible, to have them transferred without obstacles to another Data Controller. This provision is applicable when the Data are processed by automated tools and the processing is based on the User’s consent, on a contract to which the user is party or on related contractual measures.
- lodge a complaint. Users can complain to the data protection authority or take action in a court of law.
Details on the right of opposition
When Personal Data are processed in the public interest, in the exercise of official powers vested in the Data Controller or to pursue a legitimate interest of the Data Controller, Users have the right to oppose processing for reasons related to their particular situation.
Users are informed that when their Data are processed for direct marketing purposes, they may oppose processing without having to give any reason. To determine whether the Data Controller processes data for direct marketing purposes, please see the specific sections of this document.
How to exercise these rights
To exercise their rights, Users may submit a request via the Data Controller’s contact details indicated in this document. Requests can be submitted free of charge and are answered as quickly as possible by the Data Controller, and in any case within one month.
MORE INFORMATION ON PROCESSING
Defence before the courts
Users’ Personal Data may be used by the Data Controller in court or in preparatory phases to proceedings to defend itself against abusive use of this Website or related Services by the User.
The User declares to be aware that the Data Controller may be required to disclose the Data by order of the public authorities.
System log and maintenance
For operation and maintenance needs, this Website and any third-party services used by it may collect the system log, i.e. files recording interactions and that may contain Personal Data such as the User’s IP address.
Information not contained in this policy
Users may request more information in relation to the processing of Personal Data at any time from the Data Controller, at the contacts provided.
Response to “Do Not Track” requests
This Website does not support “Do Not Track” requests.
To determine whether any third-party services support them, please consult their respective privacy policies.
DEFINITIONS AND LEGAL REFERENCES
Personal Data (or Data)
Any information that, also in connection with any other information, including a personal identification number, directly or indirectly identifies or makes it possible to identify a physical person.
Information collected automatically through this Website (including third-party applications integrated into this Website), including the IP addresses or domain names of the computers used by the User connecting to this Website, URI (Uniform Resource Identifier), the time of request, the method used to send the request to the server, the size of the file obtained in reply, the numerical code indicating the status of the response from the server (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the times of the visit (e.g., time spent on each page) and details of the route followed inside the Application, with particular reference to the sequence of pages viewed, the parameters related to the User’s operating system and computer environment.
The person using this Website who is the Interested Party, unless otherwise specified.
- Interested Party
The natural person to whom the Personal Data refer.
- Data Processor (or Processor)
- Data Controller (or Controller)
The natural or legal person, public authority, service or any other body that, alone or jointly with others, determines the purposes and means of Personal Data processing and the instruments adopted, including security measures relating to the operation and use of this Website. Unless otherwise specified, the Data Controller is the owner of this Website.
- This Website (or this Application)
The hardware or software through which User Personal Data are collected and processed.
The Service provided by this Website as defined in the terms (if present) on this site/application.
- European Union (or EU)
Unless otherwise specified, any reference to the European Union contained in this document is understood as extended to all current Member States of the European Union and the European Economic Area.
Small piece of data stored on in the User’s device.