Privacy Policy

Privacy Policy - Our policy for the processing of personal data

Browsing the shop.uovodastrapazzo.com website is free and can be carried out by the user without any indication of personal data; however, if a data subject wishes to use our services, such as sending us an email, registering for our newsletter or purchasing a product through our website, it is necessary for the user to report their personal data according to the service requested.

If the processing of personal data is necessary and there is no other legal basis that legitimizes such processing, we generally ask for the [data subject's] consent.

The processing of personal data, such as a data subject's name, address, email address, or telephone number by us complies with the rules and principles set forth in the General Data Protection Regulation (GDPR) No. 679/2016 and the Italian legislation applicable to shop.uovodastrapazzo.com as a company based in Italy.

By means of this data protection notice, provided pursuant to Article 13 of Regulation No. 679/2016 (GDPR), our company wishes to inform the general public about the nature, scope, methods and purpose of the processing of personal data that we collect, use and process and to inform data subjects about their rights regarding the data we process and how to exercise them.

As the Data Controller, shop.uovodastrapazzo.com has implemented appropriate technical and organizational measures to ensure the most complete protection of personal data processed through this site. However, Internet-based data transmissions may, in principle, have security gaps, so absolute protection may not be guaranteed.

1. Definitions

Shop.uovodastrapazzo.com's privacy policy is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). In our notice we will try to use simple, readable and understandable language for all, for our customers, suppliers and business partners as recommended by European legislator. To ensure this, we would first like to explain the terminology used.

In this Disclosure, we use, among others, the following terms:

a) Personal Data

Personal data means any information relating to an identified or identifiable natural person [data subject]. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social appearance of that natural person.

b) Subject

A data subject is an identified or identifiable natural person whose personal data are processed by the Data Controller.

c) Processing

Processing of personal data is any operation or set of operations performed on personal data or personal data sets, including by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

d) Limitation of treatment

Restriction of processing is a right that the data subject can exercise, by requesting the restriction, the Data Controller marks the stored personal data by restricting its processing in the future.

e) Profiling

Profiling: any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to an individual, particularly to analyze or predict aspects concerning the individual's performance at work, economic situation, health, personal preferences , interests, reliability, behavior, location, or movements.

f) Pseudonymization

Pseudonymization is the processing of personal data in such a way that personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is stored separately and is subject to technical and organizational measures to ensure that personal data is not attributed to an identified or identifiable natural person.

g) Data controller

The controller is the natural or legal person, public authority, agency or other body which, alone or in cooperation with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by the law of the Union or the Member State, the controller or the specific criteria for his or her appointment may be provided for by the law of the Union or the Member State.

h) Data controller

Data controller is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the Data Controller.

i) Recipient

The Receiver is a natural or legal person, public authority, agency or other entity, to whom personal data are disclosed, whether a third party or not.

j) Consensus

The data subject's consent is a free, specific, informed, and unambiguous indication of the data subject by which he or she, by means of a statement or clear affirmative action, expresses authorization for the processing of personal data concerning him or her.

This Privacy Policy is made pursuant to Article 13 of Regulation No. 679/2016 on the processing of personal data. In addition to this Comprehensive Personal Data Notice, the user of the site may view specific informational texts on the site prior to the collection of such data.

2. Data controller

a) Name and address of the data controller

The Data Controller, for the purposes of the General Data Protection Regulation (GDPR), is:

Pallo Design di Alessia Rossi

P.IVA 13214411004

Email: shop@uovodastrapazzo.com

Website: shop.uovodastrapazzo.com

To receive more information on the processing of personal data carried out through this website, to exercise their rights in relation to the processed data or to propose complaints, the User may contact us at the following email address shop@uovodastrapazzo.com.

 

3. Personal data processed

a) Browsing data automatically collected by the site 

The website shop.uovodastrapazzo.com collects automatically, since the User's access to it, information not directly identifying the User which, if associated with other information, could still allow his/her identification; this is the so-called browsing data that are collected by any web application when a person browses a site.

This data and general information is stored in server log files. The following may be collected: (1) the types of browsers and versions used, (2) the operating system used by the access system, (3) the Web site from which an access system reaches our Web site (so-called referrers), (4) the sub -websites, (5) the date and time of access to the Internet site, (6) an Internet protocol address (IP address), (7) the Internet service provider of the access system, and (8) any other similar data and information that may be used in the event of attacks on our computer systems.

When using these general data and information, shop.uovodastrapazzo.com does not draw any conclusions about the User. Rather, this information is necessary to (1) properly provide the content of our website, (2) optimize the content of our website and its advertising, (3) ensure the long-term proper functioning of our computer systems and website technology, and (4) provide the authorities in charge with the information necessary for prosecution in the event of a cyber attack. Therefore, shop.uovodastrapazzo.com statistically analyzes anonymously collected data and information in order to increase data protection and data security and ensure an optimal level of protection of processed personal data. Anonymous data from server log files are stored separately from all personal data provided by a data subject.

 

b) User identification data

When the User registers on the site to create an account to make a purchase, or decides to send an inquiry, filling out the contact form, contacts us by sending an email, calling us by phone, he/she may voluntarily provide us with his/her own personal identifying data, such as name, address, email, phone number, any additional data that he/she intends to share with us, in this case, we will only process identifying data to respond to the inquiries, to provide the requested service, enable him/her to purchase on our online shop site.

If the User, as part of his communication, decides to share personal data of third parties with us, for example, by entering such personal data of third parties in an email or contact form, registering on the site to send us a purchase order, he assumes full responsibility for such communication, thus guaranteeing that he has the right to communicate the aforementioned data and releasing the Controller from any liability to third parties.

4. Ability to contact by filling out the form or sending email

The website of shop.uovodastrapazzo.com contains forms that enable quick remote contact with our company, as well as direct communication with us, which also includes an e-mail address (shop@uovodastrapazzo.com). If a data subject contacts the Data Controller by email or via the contact form, the personal data transmitted by the data subject is automatically stored. Such personal data transmitted on a voluntary basis by the data subject to the Data Controller are stored for the purposes of contacting the data subject again and providing the response, service or information requested by the data subject.

There is no transfer of this personal data to third parties.

5. Subscribe to our newsletter

On the website of shop.uovodastrapazzo.com, users have the opportunity to subscribe to our company newsletter. The input mask used for this purpose identifies which personal data are transmitted, as well as when the newsletter subscription is made by the user.

shop.uovodastrapazzo.com regularly informs its customers and business partners through a newsletter about company offers. The company newsletter can only be received by the data subject if (1) the data subject has a valid email address, (2) the data subject has registered for the newsletter, thus expressing his or her willingness to receive it, (3) the data subject has purchased on our website, in which case on the basis of our legitimate interest we will send our newsletter as the user has expressed his or her interest in our products, always granting the possibility to unsubscribe from the newsletter in the manner better specified later. A confirmation e-mail will be sent to the e-mail address of the user registering for the first time for the newsletter, for legal reasons, which require double acceptance. This confirmation e-mail is used by us to prove that the Data Controller has been authorized by the User to send the newsletter to him/her.

During newsletter registration, we also store the IP address of the computer system assigned by the Internet Service Provider (ISP) and used by the data subject at the time of registration, as well as the date and time of registration. The collection of this data is necessary to enable us to understand whether there has been any misuse (if any) of a data subject's email address at a date subsequent to registration, and is therefore necessary for the Data Controller for security purposes and to defend a right of the Data Controller in any legal proceedings.

Personal data collected when registering for the newsletter will only be used to send our newsletter to the user who has requested it. In addition, data collected when the user registers for the newsletter may be used to inform newsletter subscribers by e-mail, about the operation of the newsletter service or about a registration in question, for example in case of changes to the newsletter, or in case of a change in technical circumstances. There will be no transfer of personal data collected by the newsletter service to third parties. The subscription to our newsletter can be terminated by the data subject at any time. Consent to the storage of personal data, which the data subject has provided for sending the newsletter, can be revoked at any time. For the purpose of revoking consent, a corresponding link to exercise is found in each newsletter. You can also unsubscribe from the newsletter at any time directly by email to the following address: shop@uovodastrapazzo.com

The sending of the shop.uovodastrapazzo.com newsletter is managed by Squarespace acting as our Data Processor and contains so-called tracking pixels. A tracking pixel is a thumbnail graphic embedded in such emails, which are sent in HTML format to allow logging and log file analysis. This allows statistical analysis of the success or failure of online marketing campaigns. Based on the embedded tracking pixel, shop.uovodastrapazzo.com can see if and when an email was opened by a subscriber and which links in the email were retrieved.

Such personal data collected in the tracking pixels contained in newsletters are stored and analyzed by the Data Controller in order to optimize the delivery of the newsletter, as well as to improve its content.

Data subjects have at any time the right to revoke the respective separate declaration of consent issued through the double acceptance procedure. After a revocation, these personal data will be deleted by the Controller. shop.uovodastrapazzo.com automatically considers a cancellation from the receipt of the newsletter as a revocation of consent; following cancellation the data subject will no longer receive our newsletter, in any case, cancellation upon receipt of the newsletter does not mean cancellation of the account from the site if the user has registered for the same in order to make a purchase.

6. Purpose of processing

shop.uovodastrapazzo.com, through the website, collects and processes only the personal data necessary to fulfill the purpose of the collection; in fact, we do not ask the User to provide us with data superfluous to those strictly necessary to respond to your requests, provide the requested service, place a purchase order, subscribe to the newsletter. In the contact form, for example, we only ask for name, email contact, telephone number, message to forward the request, basic information without which it would be difficult for us to be able to respond to what the User has asked, likewise during the registration phase to make a purchase order we only ask for the data necessary to allow us to send him the selected products and allow the user to log into his account in the future using the credentials he has entered to make other purchases without having to re-enter his data each time.

Specifically, the personal identifying information voluntarily disclosed by the User through this site is collected and processed by us solely:

  1. to respond to requests for information, assistance or other requests made by the User regarding the products sold by us and/or services related to the products sold by us, events or other initiatives organized by the Owner, following voluntary completion of the contact form and subsequent forwarding of data, sending of email or telephone contact by Users (legal basis: execution of pre-contractual measures taken at the request of the same, art. 6 lett. b GDPR);

  2. to enable the User to send us a purchase order, make payment for the selected product and ship the purchased product to the User (legal basis: contractual performance, art. 6 lett. b. GDPR);

  3. for compliance with the law, tax and administrative regulations, in connection with a purchase made on the site (legal basis: fulfillment of a legal obligation of the Owner, art. 6 lett. c GDPR);

  4. for information security reasons, if cybercrimes or attacks on the site have occurred and/or for the possible defense of our rights in or out of court (legal basis: legitimate interest of the Owner, protection of its organization, defense of a right in court art. 6 lett. f GDPR);

  5. only if you have given your consent by subscribing to the newsletter (legal basis: consent of the data subject, art. 6 lett. a GDPR) or, in case you are a customer of ours who has already bought from us, on the basis of our legitimate interest (legal basis legitimate interest art. 6 lett. f GDPR), we may process your personal data in order to send you commercial communications referring to products similar to those purchased, assuming that you are interested in staying in contact with us and receiving our offers, as our customer; in any case, it is allowed to the User who has voluntarily subscribed to our newsletter and the customer who has purchased on our website at any time to easily exercise their right to object or withdraw the consent given;

  6. only if you have given your specific and express consent we may share such data with our business partners (legal basis: consent of the data subject, Art. 6 lett. a GDPR).

a) Mandatory or optional nature of providing data

The User can freely consult our website without any provision of personal identifying information; the provision of personal data to request information, assistance, to subscribe to the newsletter is also optional, as well as the registration to the site to make purchases, however, in the absence of such communication we would be unable to provide the response to the requests made by the User while, in the case of non-registration to the site we can still process a purchase order, although it is incumbent on the user to release those personal data necessary to enable us to ship the product, receive payment of the price and fulfill the obligations of accounting and administrative nature.

b) Method of processing and security of processed data

shop.uovodastrapazzo.com processes personal data by means of computerised, telematic and manual tools and uses technical and organisational security measures that are appropriate and proportionate to the type of processing carried out, the nature of the data processed, the context, the assett used and the purposes of processing. The security measures employed are aimed at the best protection of personal data in order to prevent their accidental or malicious destruction, accidental loss, alteration, unauthorized communication or access; only authorized individuals, specially trained and required to maintain confidentiality obligations on the information processed can access the personal data we collect and process.

Although we make every effort to ensure the security of personal data, we remind you that the Internet by its very nature cannot be fully secure, so we recommend users to use appropriate security measures, such as up-to-date antivirus, firewalls and anti-spam filters to best protect their browsing devices and the Internet, so we also recommend obtaining assurances from your Internet Service Provider, who is also required to take appropriate measures to ensure the security of data transmission over the network.

The User, by browsing this site therefore accepts the risks associated with online browsing and therefore cannot hold shop.uovodastrapazzo.com responsible for any violation of processed data except caused by its negligence.

c) To whom we disclose personal data

The data subject's data may be disclosed to:

  • parcel shipping service to enable us to send the purchased products to the customer;

    online payment service provider, if you choose this payment option during the purchase process;

    non-identifying data collected through cookies may be disclosed to Google, which provides the website analytics service to us by sending us data on an anonymous aggregate and statistical basis in relation to users' visits to the website;

    judicial authorities, police forces, security organs, if necessary for the defense of our rights in court or for the reporting of any crimes or offenses for purposes of investigation or repression of the same and only in the cases provided for by law.

Where necessary, the subjects to whom we communicate your data are appointed as Data Processors. To receive more information about the subjects to whom we disclose your data, please write to us at the following email address: shop@uovodastrapazzo.com.

Personal data collected and processed will not be disseminated.

d) Period of data retention

Personal data collected through the site are used only for the purposes previously indicated and for the time necessary to carry out the same activities, except, in some cases, to keep them dutifully stored for longer periods necessary for the fulfillment of regulatory obligations. Thus, if the User sends a request for information, his/her data will be processed only for the time necessary to provide the response to what was requested. If, otherwise, a User has requested the supply of our products or one of our services, by registering and proceeding to make a purchase on our Site we will process your personal data for the period necessary to properly execute the purchase order and thereafter retain it for administrative accounting purposes and to allow you subsequent access to your account and facilitate future purchases by entering only your login credentials.

The Controller may be obliged to retain personal data for a longer period than the execution of the purpose of collection, in compliance with a legal obligation or by order of an authority.

In the event that you no longer intend to use our services, the prerequisites being met, your data will be deleted from our databases, upon your request, in which case we will confirm such deletion, notifying the duty to do the same also to the parties we use to whom the personal data in relation to which a request for deletion has been received by us, if any, and ensuring that they have properly performed it, except that we must maintain the retention of personal data for legal obligations.

Finally, personal data may also be retained until the time allowed by Italian law for the exercise of our right of defense in court.

In the different case in which the processing is based on the consent of the data subject, at the moment referred to only in connection with the sending of our newsletter, we may process your personal data until that consent is revoked.

e) Rights of the data subject

Data subjects may exercise certain rights with regard to personal data processed by the Data Controller.

In particular, the data subject has the right to:

  1. request information The data subject has the right to request and obtain information on whether or not there is any processing referring to his or her Personal Data at the Data Controller;

  2. access their Data The data subject has the right to obtain information about the Data processed by the Controller, about certain aspects of the processing and to receive a copy of the processed Data in a form readable by common devices.

  3. verify and request rectification The data subject may verify the correctness of his or her Data and request that it be updated or corrected.

  4. revoke consent at any time The data subject may revoke any consent to the processing of his or her Personal Data that may have been given; it should be noted that the revocation of consent does not in any case affect the lawfulness of the processing based on the consent given before the revocation;

  5. object to the processing of one's Data A data subject may object to the processing of his or her Data, even when it is done on a legal basis other than consent. More details on the right to object are provided in the section below.

  6. Obtain restriction of processing When certain conditions are met, the data subject may request restriction of the processing of his or her Data. In this case, the Data Controller will not process the Data for any purpose other than its preservation.

  7. obtain the deletion or removal of their Personal Data When certain conditions are met, the data subject may request that their Data be deleted by the Data Controller.

  8. receive his or her Data or have it transferred to another data controller (right to portability) The data subject has the right to receive his or her Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred unimpeded to another data controller. This provision is applicable when the Data is processed by automated means and the processing is based on the consent of the data subject, a contract to which the data subject is a party or contractual measures related thereto;

  9. propose complaint For any issues or complaints about the processing it is a good idea to contact the Data Controller, in any case, the data subject may propose a complaint Garante della Privacy competent (for more information please consult the institutional site of the Garante garanteprivacy.it) or take legal action.

f) Details of the right to object

You may at any time object to the processing of your personal data when a special situation arises by sending a reasoned email to the Data Controller at shop@uovodastrapazzo.com.

You may object at any time and without justification to the processing of your personal data carried out for direct marketing purposes (sending our newsletter). In this specific case, you may exercise this right, by clicking on the appropriate button in the newsletter, the deletion of your data and your email address from our mailing list will take place automatically, in any case, your personal data may be maintained in our database if you have registered on our site by creating a personal account to make purchases or a contractual relationship with us is in place.

g) How to exercise rights

For information about the processing or to exercise rights, the data subject may address his/her request to the email address shop@uovodastrapazzo.com. Requests are submitted free of charge and processed by the Controller as soon as possible, in any case within one month.

 

7. Modification / update of this policy 

The Data Controller reserves the right to modify and/or update, in whole or in part, this policy.

Changes referring to personal data processed by us because of an existing contractual relationship between us and the user will be specially forwarded by email; changes referring in general to users of the site will be made known by updating this web page. We therefore recommend that you periodically review its contents.

Last updated: July 2024