PRIVACY POLICY
INFORMATION ON THE PROCESSING OF PERSONAL DATA
pursuant to Article 13 of EU Regulation 2016/679 (GDPR)
Updated on 2024-07-07
This page describes the methods and logic of processing the personal data of users who visit the website: www.dedolio.it (hereinafter the “Website”). This is information provided pursuant to Article 13 of EU Regulation 2016/679 ‘General Data Protection Regulation’ (hereinafter GDPR) and current Italian legislation for the protection of personal data, Legislative Decree 196/2003 and subsequent amendments, in particular those introduced by Legislative Decree no. 101/2018, to those who interact with the website starting from the address www.dedolio.it and not for other external websites that may be linked.
1. DATA CONTROLLER
The controller of personal data processing (hereinafter the “Controller”) is
Dedamiani Angelo
via Borgo San Francesco 62
70032 Bitonto (Ba)
VAT no. 08186710722 | Tax Code DDMNGL81P19A893R
email dedolio.bitonto@gmail.com
2. TYPE AND METHOD OF COLLECTION OF DATA PROCESSED
The personal data that the Data Controller collects, processes, records, stores and/or transfers to third parties are those identifying natural persons (by way of example only and not exhaustively, this refers to names, surnames, addresses, tax codes, telephone/mobile numbers, dates or places of birth, etc.).
Personal data may be provided by the Data Subject on a voluntary basis or on a mandatory basis. This second case concerns data that is essential to enable the Controller to provide the requested service or whose acquisition is connected to the protection of legitimate interests of the Controller or to matters of a judicial nature. Failure to provide the data deemed necessary to obtain the service/product requested from the Controller will result in the impossibility of its provision. In such case, no liability may be attributed to the Controller.
Data collected through access to the website may be on a voluntary basis (for example, completion of the contact form on the Website) or involuntary as occurs during the browsing phase on the website.
Browsing data
The computer systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.
This category of data includes IP addresses or domain names of computers and terminals used by users, addresses in URI/URL (Uniform Resource Identifier/Locator) notation of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the user’s computer environment.
Such data, necessary for the use of web services, are also processed for the purpose of:
- obtaining statistical information on the use of services (most visited pages, number of visitors by time slot or daily, geographical areas of origin, etc.);
- checking the correct functioning of the services offered.
Data provided by the user
The optional, explicit and voluntary sending of messages to the contact addresses of the Website, the completion of contact forms on the Website, entails the acquisition of the sender’s contact data, necessary to respond, as well as all personal data included in the communications.
Cookies and other tracking systems
No cookies are used for user profiling, nor are other tracking methods employed.
Session cookies (non-persistent) are used in a strictly limited manner to what is necessary for safe and efficient navigation of the websites. The storage of session cookies in terminals or browsers is under the user’s control, whereas on servers, at the end of HTTP sessions, information relating to cookies remains recorded in service logs, with retention times not exceeding seven days, like other browsing data.
3. PURPOSE OF PROCESSING
The personal data collected are processed by the Controller for the following purposes:
a. To fulfill pre-contractual, contractual and tax obligations arising from existing or newly established relationships;
b. to enable the proper conduct of business activities (keeping of registers and accounts, office management, personnel management, etc.)
c. To carry out marketing activities, consisting of sending newsletters and/or commercial/marketing communications and/or advertising material, relating to services/products offered by the Controller;
d. to monitor the interests and preferences of data subjects;
e. to improve and optimize the services offered by the Controller;
f. to obtain anonymous statistical information on the use of the website and check its correct functioning;
g. To be able to ascertain, exercise or defend a right in court.
4. LEGAL BASIS OF PROCESSING
The Controller processes Personal Data relating to the User if one of the following conditions exists:
- the User has given consent for one or more specific purposes; in some jurisdictions the Controller may be authorized to process Personal Data without the User’s consent or another of the legal bases specified below having to exist, until the User objects (“opt-out”) to such processing. However, this is not applicable where the processing of Personal Data is governed by European legislation on the protection of Personal Data;
- processing is necessary for the performance of a contract with the User and/or for the execution of pre-contractual measures;
- processing is necessary to comply with a legal obligation to which the Controller is subject;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
- processing is necessary for the purposes of the legitimate interests of the Controller or third parties.
It is always possible to request the Controller to clarify the specific legal basis of each processing and in particular to specify whether the processing is based on law, provided for by a contract or necessary to conclude a contract.
5. DURATION OF PROCESSING
Personal data will be processed for the time strictly necessary to achieve the purposes for which they were collected and in compliance with all necessary precautions to prevent their loss, unlawful or incorrect use and to prevent unauthorized access.
Specifically, personal data will be processed for no more than 10 years from the termination of the relationship for the purposes referred to in points 3a and 3b and for no more than 5 years for the purposes referred to in points 3c, 3d and 3e unless it is believed, in good faith, that the law or other regulations allow and/or require retention for a longer period.
Data collected for the purposes referred to in point 3g will be retained for the time necessary for judicial requirements.
After these terms, your personal data will be deleted from our systems in compliance with regulations.
6. RECIPIENTS OF PERSONAL DATA
The data collected by the Controller may be communicated, within the limits strictly relevant to the purposes indicated above in point 3 “PURPOSE OF PROCESSING”, also to the following subjects or categories of subjects:
employees of the Controller, who will process them as persons authorized by the Controller under its precise and careful direction;
collaborators of the Controller who will process the data on behalf of the Controller as data processors pursuant to Article 28 of the GDPR;
public/private entities to whom communication is required by law, by regulation or by national or EU legislation as well as for the performance of contractual obligations;
legal, accounting, labor consultants for the purpose of studying and resolving any legal problems relating to the existing contractual position;
external firms specialized in consulting for the management of accounting and tax aspects;
technicians responsible for hardware and software assistance.
All data acquired in any way by the Controller for the purposes referred to in the previous point 3) may also be communicated, if necessary, to the Judicial Authority or to those subjects to whom communication is mandatory by law.
With the exception of the subjects referred to in letters a) and b), the others will process the data in their capacity as independent data controllers.
7. METHOD OF PROCESSING
Personal data are subject to processing exclusively for the purposes indicated above using manual, computer or telematic tools and stored in databases.
The Controller has implemented adequate security measures in order to maintain the integrity and security, as well as prevent the destruction, loss, accidental or unlawful alteration, unauthorized disclosure, or access to Personal Data transmitted, stored or otherwise processed.
Should the data subject suspect any improper use or loss of or unauthorized access to their personal data, they are invited to immediately notify the Controller using the contact details indicated in point 1 of this information notice.
8. PLACE OF DATA PROCESSING AND POSSIBLE TRANSFER
All data collected are processed on paper or with automated tools at the business premises of the Data Controller indicated on the website www.dedolio.it as well as at the premises of the hosting and/or website management company. Currently the servers are located in Italy.
Should data be transferred outside the European Economic Area or EEA (i.e. the Member States of the European Union plus Norway, Iceland and Liechtenstein), the Controller ensures from now on that the transfer will take place in accordance with the applicable legal provisions from time to time, entering into, if necessary, agreements that guarantee an adequate level of protection and/or adopting the standard contractual clauses provided by the European Commission.
9. USER RIGHTS
The GDPR guarantees data subjects a series of rights regarding their personal data processed by the Data Controller.
Users may exercise certain rights with reference to the Data processed by the Controller.
In particular, the User has the right to:
- withdraw consent at any time. The User may withdraw consent to the processing of their Personal Data previously expressed.
- object to the processing of their Data. The User may object to the processing of their Data when it occurs on a legal basis other than consent. Further details on the right to object are indicated in the section below.
- access their Data. The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing and to receive a copy of the Data processed.
- verify and request rectification. The User may verify the correctness of their Data and request its updating or correction.
- obtain restriction of processing. When certain conditions occur, the User may request restriction of the processing of their Data. In such case, the Controller will not process the Data for any purpose other than their storage.
- obtain erasure or removal of their Personal Data. When certain conditions occur, the User may request erasure of their Data by the Controller.
- receive their Data or have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used and machine-readable format and, where technically feasible, to obtain its transfer without hindrance to another controller. This provision is applicable when the Data are processed with automated tools and the processing is based on the User’s consent, on a contract to which the User is party or on contractual measures connected to it.
- lodge a complaint. The User may lodge a complaint with the competent supervisory authority for the protection of personal data or take legal action.
Users are informed that, if their Data were processed for direct marketing purposes, they may object to the processing without providing any justification. To find out whether the Controller processes data for direct marketing purposes, Users may refer to the respective sections of this document.
10. EXERCISE OF RIGHTS
To exercise User rights, Users may address a request to the Controller’s contact details indicated in this document. The Controller undertakes to provide a response within 30 days and, in case of impossibility to meet these deadlines, to justify any extension of the prescribed terms.
