Thank you for reading this post, don't forget to subscribe!
PRIVACY POLICY – INFORMATION FOR THE PROCESSING OF PERSONAL DATA
Following the entry into force of the new European Regulation (EU) 2016/679 (GDPR) regarding privacy and considering the importance we place on protecting your personal data, we have updated our privacy notice based on the principle of transparency and all elements required by the GDPR. For completeness, compliance with legal requirements, and operational functionality, we have drafted a preparatory document for the implementation of the regulatory principles and detailed rules, which is the Internal Regulation, which can also be consulted in relation to identifying the various roles of the Data Controller, Data Processors, External Processors, and External Authorized Persons.
This Website collects some Personal Data of its Users. The information is provided in relation to Articles 13 and 14 of EU Regulation 2016/679.
Data Controller
The Data Controller is Portico Rodriguez – Via Chiesa 3, 84060 Abatemarco (SA) – email: info@porticorodriguez.it
Types of Data Collected
Among the Personal Data collected by this Website, either independently or through third parties, are: name, surname, email, cookies, and usage data. Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific informative texts displayed before collecting the data. Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Website. Unless otherwise specified, all Data requested by this Website is mandatory. If the User refuses to provide such data, it may be impossible for this Website to provide the Service. In cases where this Website indicates some Data as optional, Users are free to refrain from communicating such Data without affecting the availability of the Service or its operation. Users who are unsure about which Data are mandatory are encouraged to contact the Data Controller. The use of cookies – or other tracking tools – by this Website or by the third-party services used by this Website, unless otherwise specified, serves to provide the Service requested by the User, in addition to other purposes described in this document and in the Cookie Policy. The User assumes responsibility for third-party Personal Data obtained, published, or shared through this Website and guarantees that they have the right to communicate or disseminate them, freeing the Data Controller from any liability towards third parties.
Methods, Legal Basis, Location of Data Processing, Retention Period, and Purposes of Data Processing
Data Processing Methods
The Data Controller takes appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data. Processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other subjects involved in the organization of this Website (administrative, commercial, legal personnel, system administrators) or external subjects (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) may have access to the Data, appointed as Data Processors by the Data Controller if necessary. The updated list of Data Processors can always be requested from the Data Controller.
Legal Basis for Processing
The Data Controller processes Personal Data related to the User if one of the following conditions exists:
- The User has given consent for one or more specific purposes;
- Processing is necessary for the performance of a contract with the User and/or the execution of pre-contractual measures;
- Processing is necessary to fulfill a legal obligation to which the Data Controller is subject;
- Processing is necessary for the performance of a task of public interest or for the exercise of official authority vested in the Data Controller;
- Processing is necessary for the legitimate interests pursued by the Data Controller or by third parties.
It is always possible to request the Data Controller to clarify the specific legal basis for each processing and, in particular, to specify if the processing is based on the law, a contract, or necessary to conclude a contract.
Location
The Data is processed at the Data Controller’s operational offices and at any other location where the parties involved in the processing are located. For further information, please contact the Data Controller. The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain more information on the location of the processing, the User can refer to the section regarding details of Personal Data processing. The User has the right to obtain information about the legal basis for transferring Data outside the European Union, as well as regarding the security measures adopted by the Data Controller to protect the Data.
Retention Period
The Data is processed and stored for the time required by the purposes for which it was collected.
Therefore:
- Personal Data collected for purposes related to the execution of a contract between the Data Controller and the User will be retained until the execution of that contract is completed.
- Personal Data collected for legitimate interest purposes will be retained until such interest is satisfied. The User can obtain further information on the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
- When processing is based on the User’s consent, the Data Controller may retain the Personal Data for a longer period until the consent is withdrawn. Additionally, the Data Controller may be obligated to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
After the retention period ends, the Personal Data will be deleted. Therefore, upon the expiration of this period, the right to access, erase, rectify, and the right to data portability can no longer be exercised.
Purposes of Data Processing
The User’s Data is collected to allow the Data Controller to provide their Services. For further detailed information on the purposes of processing and the specific Personal Data relevant to each purpose, the User can refer to the relevant sections of this document.
Personal Data is collected for the following purposes and using the following services:
Contacting the User
- Contact form and newsletter request The User, by filling in the contact form or the newsletter request form, consents to the use of their Data to respond to information requests, quotes, or any other nature indicated by the headings of the forms. Collected Personal Data: those requested in the form fields.
This type of service allows the management of a database of email contacts, phone contacts, or any other type of contact used to communicate with the User. These services could also allow the collection of data related to the date and time the messages were viewed by the User, as well as the User’s interaction with them, such as information on clicks on links in the messages.
Rights of the Data Subject
Users can exercise certain rights with respect to the Data processed by the Data Controller. The reference articles are 15, 16, 17, 18, 20 of EU Regulation 2016/679.
In particular, the User has the right to:
- Withdraw consent at any time. The User can withdraw consent for the processing of their Personal Data previously given.
- Object to the processing of their Data. The User can object to the processing of their Data when it is carried out on a legal basis other than consent. Further details on the right to object are provided in the section below.
- Access their Data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing, and to receive a copy of the processed Data.
- Verify and request rectification. The User can verify the accuracy of their Data and request updates or corrections.
- Obtain restriction of processing. When certain conditions are met, the User can request the restriction of their Data processing. In such cases, the Data Controller will not process the Data for any other purpose except for its storage.
- Obtain deletion or removal of their Personal Data. When certain conditions are met, the User can request the complete deletion of their Data by the Data Controller (right to be forgotten).
- Receive their Data or transfer them to another controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to obtain its transfer without hindrance to another controller. This provision applies when Data is processed through automated tools, and the processing is based on the User’s consent, a contract to which the User is a party, or contractual measures related to it.
- File a complaint. The User can file a complaint with the competent personal data protection authority or take legal action.
Details on the Right to Object
When Personal Data is processed in the public interest, for the exercise of official authority vested in the Data Controller, or for the pursuit of the legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their specific situation.
Users are also informed that, if their Data is processed for direct marketing purposes, they can object to the processing without providing any justification. To find out whether the Data Controller processes data for direct marketing purposes, Users can refer to the respective sections of this document.
How to Exercise Rights
To exercise the User’s rights, Users can send a request to the contact details of the Data Controller indicated in this document. Requests are free of charge and will be fulfilled by the Data Controller as soon as possible, in any case, within one month.
Further Information on Processing
Defense in Legal Proceedings
The User’s Personal Data may be used by the Data Controller in legal proceedings or in the preparatory stages of any potential lawsuit to defend against abuses in using this Website or its associated Services by the User. The User acknowledges that the Data Controller may be required to disclose Data by order of public authorities.
Specific Notices
Upon the User’s request, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual notices regarding specific Services or the collection and processing of Personal Data.
System Logs and Maintenance
For operational and maintenance purposes, this Website and any third-party services it uses may collect system logs, i.e., files that record interactions and may also contain Personal Data, such as the User’s IP address.
Information Not Contained in This Policy
Further information on the processing of Personal Data may be requested at any time from the Data Controller using the contact details.
Modifications to this Privacy Policy
The Data Controller reserves the right to make changes to this privacy policy at any time by informing Users on this page and, if technically and legally feasible, notifying Users through one of the contact details the Data Controller holds. Please check this page regularly, referring to the date of the last modification indicated at the bottom.
Definitions and Legal References
Personal Data (or Data)
Any information that, directly or indirectly, allows the identification of a natural person, such as a name, email address, location, or any other piece of information.
Usage Data
Information collected automatically through this Website (or third-party services used by this Website), which may include: IP addresses or domain names of the computers used by the User who connects with this Website, the URI (Uniform Resource Identifier) addresses, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numeric code indicating the status of the server’s response (successful, error, etc.), the country of origin, the browser and operating system characteristics used by the User, the various time details per visit (e.g., time spent on each page within the application), and other parameters about the User’s operating system and IT environment.