FOREWORD
This notice takes into account the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (GDPR) and the Privacy Code (Legislative Decree No. 196 of June 30, 2003). The document has also been prepared in accordance with the Guidelines of the Privacy Guarantor (especially the Guidelines on Countering Spam issued dl Privacy Guarantor on July 4, 2013).
Data Controller: Crespi Milano Srl – Via Verdi, 23 23844 Sirone (LC) Italy – PI: IT 06576050964 – Email: info@crespimilano.com
Site to which this privacy policy refers: https://www.crespimilano.com/(Site).
The Data Controller has not appointed a DPO (Data Protection Officer). Therefore, you may send any inquiries directly to the Data Controller.
GENERAL INFORMATION
This document describes how the Data Controller processes your personal data provided on the Site.
The main processing of your personal data is described below. In particular, the legal basis of the processing, whether the provision is mandatory, and the consequences of not providing personal data are explained. To better describe your rights, if necessary, we have specified if and when a certain processing of personal data is not carried out. On the Site you have the opportunity to enter personal data of third parties. In this case you guarantee that you have obtained consent from these parties to the inclusion of this personal data. Therefore, you agree to indemnify and hold harmless the Data Controller from any liability.
Site Registration
The information and data requested in the case of registration will be used to allow you both to access the restricted area of the Site and to use the online services offered by the Data Controller to registered users. The legal basis for the processing is the Data Controller’s need to execute pre-contractual measures taken at the request of the data subject. The provision of data is optional. However, your refusal to provide the data will result in the inability to register on the Site.
Purchases on the Site
Your personal data will be processed to enable you to make purchases on the Site. In the case of placing an online purchase order, to enable the conclusion of the purchase contract and the proper execution of the transactions related to the same (and, if necessary under industry regulations, to fulfill tax obligations). This processing of personal data also includes the possibility of sending communications (e.g.: tracking and order information) via automated tools such as sms and/or WhatsApp. The legal basis for the processing is the obligation of the Data Controller to perform the contract with the data subject or to fulfill legal obligations. Regardless of the above (and therefore of your consent), the Data Controller may process your data purposes of so-called “soft-spam,” governed by Article 130 of the Privacy Code. This means that limited to the email you provide in the context of a purchase through the Site, the Data Controller will process the email to enable direct offers from similar products/services, provided that you do not object to such processing in the manner set forth in this Policy. The legal basis for processing is the legitimate interest of the Data Controller in sending this type of communication. This legitimate interest may be considered equivalent to the data subject’s interest in receiving “soft-spam” communications. The Data Controller may send emails to remind the user to complete a purchase. The legal basis for this processing is the legitimate interest of the Data Controller to send this type of communication.
Responding to your requests
Your data will be processed to respond to your inquiries. Providing it is optional, but your refusal will make it impossible for the Data Controller to answer your questions. The legal basis for the processing is the legitimate interest of the Data Controller in fulfilling your requests. This legitimate interest is equivalent to the user’s interest in receiving responses to communications sent to the Data Controller.
Generic marketing
Subject to your consent, the Data Controller may process the personal data you provide for the purpose of sending you advertising material and/or newsletters relating to its own or third party products. The legal basis for this processing is your consent. The provision of personal data for this purpose is purely optional. Failure to consent to the processing of data for marketing purposes will result in the impossibility for you to receive advertising material relating to products/services of the Data Controller and/or third parties as well as the impossibility for the Data Controller to carry out market surveys, also aimed at assessing the degree of user satisfaction, as well as to send you newsletters. The sending of these communications will take place to the e-mail you have given on the Site.
Profiling
Subject to your consent, the Data Controller may process your personal data for profiling purposes, i.e. for the analysis of your consumption choices through the revelation of the type and frequency of purchases made by you, in order to send you advertising material and/or newsletters relating to its own or third-party products of your specific interest. The legal basis for this processing is your consent. The provision of data for this purpose is merely optional. Failure to consent to the processing of your personal data for profiling purposes will result in the impossibility for the Data Controller to process your commercial profile, through the detection of your purchasing choices and habits as well as to send you advertising material, related to products of the Data Controller and/or third parties, of your specific interest. These communications will be sent to the e-mail you conferred on the Site.
Data transfer
The Data Controller does not transfer your personal data to third parties.
Geolocation
The Site does not implement tools to geolocate the user’s IP address.
Curriculum Vitae
Through the Site it is not possible to send resumes. Therefore, your data will not be processed for these purposes.
Appointment booking
No third-party appointment booking systems are active on the Site with the Data Controller. Therefore, your data will not be processed for this purpose. In any case, you can always contact the Data Controller at the contacts listed in the epigraph.
Disclosure of personal data
As part of its ordinary business, the Data Controller may disclose your personal data to certain categories of individuals. In Article 2 You can find the list of subjects to whom the Data Controller communicates your personal data. To facilitate the protection of your rights, Article 2 may specify in some cases when your data is not disclosed to third parties.
“Communication” of personal data to third parties is different from “transfer” (regulated in the preceding point). In fact, in communication the third party to whom the data is transmitted can use it only for the specific purposes described in the relationship with the Data Controller. In the transfer, on the other hand, the third party becomes an autonomous Data Controller of the personal data. Moreover, to transfer your personal data to a third party, your consent is always required.
Notwithstanding the foregoing, it is understood that the Data Controller may still use your personal data to properly fulfill its obligations under applicable laws.
SPECIFIC PRIVACY POLICY
Art. 1 Method of treatment
1.1 The processing of your personal data will be mainly carried out with the help of electronic or otherwise automated means, in the manner and with the tools suitable to ensure the security and confidentiality of personal data.
1.2 The information acquired and the manner of processing will be relevant and not excessive in relation to the type of services rendered. Your data will also be managed and protected in secure computer environments appropriate to the circumstances.
1.3 No “special data” are processed through the Site. Particular data are those that may reveal racial and ethnic origin, religious, philosophical or other beliefs, political opinions, membership in parties, trade unions, associations or organizations of a religious, philosophical, political or trade union nature, health status and sex life.
1.4 No judicial data are processed through the Site.
Article 2 Disclosure of personal data
The Data Controller may disclose your personal data to certain categories of individuals. The Data Controller wishes to inform users that, as part of your use of the YouTube service (operated and owned by Google LLC), certain personal data may be collected and shared. This data collection is essential to provide and improve the user experience on our Site and to enable the viewing of video content integrated through the YouTube API. In detail, when a user views video content via the YouTube API on our Site, the following information may be collected: IP Address: Used to connect the user’s device to YouTube for transmission of the video. Behavioral Data: Includes information about how the user interacts with videos, which videos are viewed, and for how long. Location Information: Used to provide relevant content based on the user’s geographic location. This data is automatically collected by the system and, in some cases, may be retained to improve user experience and for internal YouTube analytical purposes. Please note that our Site uses YouTube’s API services, and by viewing content through these APIs, you agree to YouTube’s Terms of Service viewable at https://www.youtube.com/t/terms. For further details on Google LLC’s handling of data, we encourage users to consult Google LLC’s privacy policy at http://www.google.com/policies/privacy and YouTube’s privacy policy at https://www.youtube.com/intl/ALL_it/howyoutubeworks/our-commitments/protecting-user-data/. Details on the use of User-Related API Data User-Related API Data: When a user interacts with YouTube videos embedded on our Site, data such as viewing preferences, history of videos viewed, and interactions with video content (likes, comments, shares) may be collected. This data is made available through the YouTube API and helps to understand how users interact with video content. Data access via the Client API: Our Site may use specific API calls to request and receive data from YouTube. This could occur when a user views a video, with the system automatically recording relevant information. Data Collection: Data is automatically collected by YouTube’s system as users interact with YouTube videos on our Site. This process is essential to provide a smooth and personalized user experience. Data Retention: The collected data is securely stored in YouTube’s systems for a period not exceeding the need for use. YouTube takes all necessary security measures to protect this data from unauthorized access or misuse. Data Use: YouTube uses this data for several purposes, including: Internal Analytics: To better understand users’ interactions with video content and improve the quality of YouTube services. Content Personalization: To provide users with a more personalized experience based on their preferences and interaction history. Improvement of User Experience: To identify and resolve any technical problems and optimize the usability of video content. The following are the parties to whom the Data Controller reserves the right to disclose your data:
The Data Controller reserves the right to change the above list in accordance with its ordinary operations. Therefore, you are encouraged to regularly access this notice to check to which entities the Data Controller discloses your personal data.
Art. 3 Retention of personal data
3.1 This article describes how long the Data Controller reserves the right to keep your personal data.
3.2 Notwithstanding Article 3.1, the Data Controller may retain your personal data for as long as required by specific regulations, as amended from time to time.
Article 4 Transfer of personal data
4.1 The Data Controller is based in a country with an adequate level of security from a regulatory point of view. If the transfer of Your Personal Data takes place in a country outside the EU and for which the European Commission has issued an adequacy finding, the transfer is deemed to be safe from a regulatory point of view in any event. This Article 4.1 indicates from time to time the countries to which your personal data may possibly be transferred and where the European Commission has issued an adequacy opinion.
4.2 Notwithstanding Article 4.1, your data may also be transferred to countries outside the EU and for which the European Commission has not issued an adequacy finding. You are therefore invited to regularly review this Article 4.2 to ascertain to which, if any, of these countries your data is transferred.
4.3 In this article, the Data Controller indicates the countries where, if any, it specifically directs its activities. This circumstance may imply the application of the regulations of the country of reference, together with those governing the relationship with the user as indicated in the Foreword.
Art. 5. Rights of the data subject
The Data Controller informs you that you have the right to:
The above rights may be exercised by request addressed without formalities to the contacts indicated in the Foreword.
Art. 6. Amendments and Miscellaneous
The Data Controller reserves the right to make changes to this policy at any time, giving appropriate publicity to the users of the Site and ensuring in all cases an adequate and similar protection of personal data. In order to view any changes, you are encouraged to consult this policy on a regular basis. In the event of material changes to this privacy policy, the Data Controller may also notify you by email.