Pursuant to art. 13 and 14 Regolamento Europeo 2016/679 (European Regulation 2016/679), we communicate to you the following: the company Antiche Fonti di Cottorella SpA, with its registered office in Via di Fonte Cottorella – 02100 Rieti (Italy), VAT number 00042030577, email firstname.lastname@example.org, PEC email@example.com, telephone +39 0746.271640, recognises Matilde Eloisa Pitorri as the person responsible for the processing of data collected through the website www.cottorella.net.
2. Which personal data we collect and why we collect it
Personal data is information that may be used to directly or indirectly identify the user. Personal data also includes anonymous information connected to usable information to directly or indirectly identify the user. Personal data does not include information that can be irreversibly rendered anonymous or grouped in such a way as to prevent us from identifying, directly or indirectly, the user.
Below, there is a description of the types of personal data that we may collect and the way in which we may use it.
Personal data that we collect
Depending on the products and services used, we collect different types of personal data from or about the user.
- Information provided: We collect the user’s personal data, such as, name, username or email address, when the user uses our products and services, creates an account, contacts us, writes a comment on our website or purchases a product on our e-commerce platform.
- Payment information: When the user completes a purchase, the personal data connected to the purchase is collected. This data includes account information and authentication and billing information, shipping and contact information.
- Information on the use of our products and services: When the user visits our website, we may collect information on the type of device used, on the identification number of the device, the device’s IP address, on the operating system, on the type of Internet browser used, information on use, diagnostic information, browsing information, session summary information, file characteristics (including photo, video, music and document characteristics) and location information from or on the computer, smartphone or other devices on which the user installs or from which the user accesses our products and services. Some of this information may be acquired automatically.
- Information from third-parties: The data collected by us is under no circumstances transferred to third-parties. We use data provided by third-parties (Google and Facebook) to activate certain features (sharing buttons) or to collect useful statistical information to improve the performance of the site itself (Google Analytics).
How is the user’s personal data used
In general, we use personal data to provide, improve and develop our products and services, to communicate with the user, to offer targeted advertising messages and services, and to protect us and the user themself.
As a data controller, Antiche Fonti di Cottorella SpA. collects, processes and determines how the user’s personal data is processed for the following purposes:
- Provision, improvement and development of our products and services: We use personal data to be able to provide, improve and develop our products, services and advertising material. This includes the use of personal data for internal purposes such as data analysis, research and verifications. This processing is based on our legitimate interest in offering products and services to the user and to ensure business continuity. If the user makes a purchase, it is registered on the website, or they send us an email with a request for information, we may use the personal data that they have provided us for administrative purposes.
- Communication with the user: Subject to explicit consent from the user, we may use their personal data to send them marketing communications related to products and services of Antiche Fonti di Cottorella SpA, to send them communications regarding their account, on transactions or requests for information, furthermore to inform them about our policies and conditions.
If the user no longer wants to receive marketing email communications, please contact us to request to stop receiving them. We can use the user’s information to process and respond to their contact requests. For all uses of the data described above that require the user’s prior consent, the user can withdraw their consent by contacting us, or by requesting the deletion of data from the control panel.
Promotion of security: We use your personal data to help verify your account and activity, as well as promote security, for example by checking for fraud attempts and investigating suspicious or potentially illegal activity or violations of our terms of sale and use of the site. These procedures are based on our legitimate interest in ensuring the safety of our products and services.
You can remove or reject the cookies from the browser or device settings , however this may compromise the user’s ability to use our products and services.
Content incorporated by other websites
Below is a list of services provided by third parties for the proper functioning of some site features or for the collection of statistical information:
- Google Analytics
Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google uses the Personal Data collected for the purpose of tracking and examining website usage, compiling reports and sharing them with other services developed by Google.
Google may use the Personal Data to contextualise and personalise the adverts of its own advertising network.
Personal Data collected: Cookies and Data usage
- Like Button and Facebook social widgets (Facebook, Inc.)
The Like Button and Facebook social widgets are interactive services with the social network Facebook, provided by Facebook, Inc.
Personal Data collected: Cookies and Data usage
3. Who do we share your data with
Antiche Fonti di Cottorella SpA does not normally share any data collected through its own website. In the event of a purchase, only some necessary data will be provided (name and surname, address and any telephone contact number) to the shipper so the order can be delivered.
4. How long do we store your data
If you leave a comment, the comment and its metadata will be stored indefinitely.
This is how we can automatically recognize and approve any subsequent comments instead of keeping them in a moderation queue.
For users who sign up to our website (if entered), we also store personal information that they provide in their user profile. All the users can see, modify, or delete their personal information at any time (except their username which cannot be changed). The website administrators can also see and modify this information.
The data retention times are normally:
- contact form entries for six months
- statistics record for one year
- customer purchase records for five years
5. How the data is processed
The Data Controller processes the Personal Data of Users by adopting appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of Personal Data. The processing is carried out using I.T and/or telematic systems, with organisational methods and with logic strictly related to the purposes indicated. In addition to the Data Controller, in some cases, categories of representatives involved in the organisation of the site (administrative, commercial, marketing, legal, system administrators) or external entities (such as suppliers of third party technical services, postal couriers, hosting providers, IT companies, communication agencies) may have access to the Data, and also be appointed, if necessary, as Data Processors by the Data Controller.
6. What rights do you have over your data
The user, as the party of interest, may contact the Data Controller, at any time, without any formalities, to assert their rights, as provided for by articolo 7 del Codice Privacy (Article 7 of the Privacy Code), which for the User’s convenience can be read below in its entirety:
1. The interested party has the right to obtain the confirmation of the existence or not of personal data that concerns them, even if they are not yet registered, and their communication is in an intelligible form.
2. The interested party has the right to obtain the indication:
- of the origin of their personal data;
- of the purposes and methods of processing;
- of the logic applied whereby processing is carried out with the aid of electronic systems;
- of the personal details of the owner, of those responsible and the representative appointed under Article 5, paragraph 2;
- of the entities or the categories of entities to whom the personal data may be communicated or who can learn about it as designated representatives of the State, those responsible or in charge.
3. The interested party has the right to obtain:
- updates, corrections or, when they are interested, the integration of data.
- the cancellation, the anonymous transformation or blocking of data processed in violation of the law, including data which need not be kept for the purposes for which it was collected or subsequently processed;
- certification that the operations referred to in a) and b) have been brought to the attention of, also regarding their content, those to whom the data has been communicated or distributed, except in the case where this fulfilment proves impossible or involves the use of means that are manifestly disproportionate to the protected right.
4. The interested party has the right to oppose to, completely or in part:
- for legitimate reasons, to the processing of personal data concerning him, even if pertinent to the purpose of the collection;
- to the processing of personal data concerning him for the purpose of sending advertising or direct sales material or for carrying out market research or commercial communication.