I – INFORMATION ABOUT THE WEBSITE’S PRIVACY POLICY
Below we provide some information that you need to be aware of, not only to comply with legal obligations, but also because transparency and fairness towards data subjects whose personal data we process are a fundamental part of our business.
On this page we explain our privacy policy in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and with the Italian Personal Data Protection Code (Legislative Decree 30 June 2003, no. 196), as amended by Legislative Decree 10 August 2018, no. 101 and subsequent modifications.
The following notice is part of Tecnoserie’s commitment to ensuring complete transparency for data subjects regarding how we process their data.
This notice applies only to www.tecnoserie.com and not to other websites that the user may consult via links contained therein.
This notice may be modified due to the introduction of new regulations on the subject, and users are therefore invited to review this page periodically.
The purpose of this document is to provide guidance on the methods, timing and nature of the information that Data Controllers must provide to users when they connect to the web pages of www.tecnoserie.com, regardless of the purpose of the connection, in accordance with Italian and European legislation.
If the user is under 16 years of age, pursuant to Art. 8, para. 1 of EU Regulation 2016/679, consent must be validly given through authorization from the parents or legal guardians.
II – DATA PROCESSING
Data Controller
The Data Controller is the natural or legal person, public authority, service or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data and the tools adopted, including the security measures related to the operation and use of this website.
With regard to this website, the Data Controller is: Tecnoserie S.r.l., acting on behalf of the company Tecnoserie S.r.l. – Via Lazio, 15 — Zona Industriale Gello, 56025 Pontedera (PI), Italy.
VAT No. – 01754840500
Company Registration No. – P.152243 REA
For any clarification or to exercise the user’s rights, the Data Controller can be contacted via email at info@tecnoserie.it or by phone at +39 0587 291692.
Data Processor
The Data Processor is the natural or legal person, public authority, service or other body that processes personal data on behalf of the Data Controller.
Pursuant to Article 28 of EU Regulation no. 2016/679, and as appointed by the Data Controller in accordance with this privacy policy, the Data Processor for the website www.tecnoserie.com is: Michele Panichi.
Types of data collected
Among the personal data collected by this application and listed in this privacy policy page, either autonomously or through third parties, are: cookies and usage data.
Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or in specific information notices displayed before the data are actually collected.
Personal data may be freely provided by the user or, in the case of usage data, collected automatically while using this application. All data requested by this application are mandatory and, if they are not provided, it may be impossible for the application to deliver the service. In cases where this application explicitly indicates that certain data are optional, users are free to refrain from providing such data without affecting the availability or operation of the service.
Users who are uncertain which data are mandatory are encouraged to contact the Data Controller. Any use of cookies or other tracking tools by this application or by the owners of third‑party services used by this application, unless otherwise specified, is intended to provide the service requested by the user, as well as for the additional purposes described in this document and in the cookie policy, if available.
The user assumes responsibility for personal data of third parties published or shared through this application and guarantees that they have the right to communicate or disseminate such data, thereby releasing the Data Controller from any liability towards third parties.
Methods and place of processing of collected data
Processing methods
The Data Controller processes users’ personal data by adopting appropriate security measures aimed at preventing unauthorized access, disclosure, modification or destruction of personal data. Processing is carried out using IT and/or telematic tools, with organizational methods and logics strictly related to the purposes indicated.
In addition to the Data Controller, in some cases, categories of authorized persons involved in the organization of the site (administrative, sales, marketing, legal, system administration staff) or external parties (such as third‑party technical service providers, mail carriers, hosting providers, IT companies, communication agencies) may have access to the data, and may also be appointed, if necessary, as Data Processors by the Data Controller.
An updated list of Data Processors can always be requested from the Data Controller.
Legal basis of processing
The Data Controller processes personal data relating to the user if one of the following conditions exists:
- The user has given consent for one or more specific purposes. Note: in some jurisdictions the Data Controller may be authorized to process personal data without the user’s consent or another legal basis as specified below, until the user objects (“opt‑out”) to such processing. This does not apply where the processing of personal data is governed by European data protection legislation.
- Processing is necessary for the performance of a contract with the user and/or for pre‑contractual measures.
- Processing is necessary to comply with a legal obligation to which the Data Controller is subject.
- Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller.
- Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by third parties.
It is always possible to ask the Data Controller to clarify the specific legal basis that applies to each processing operation, and in particular to specify whether the processing is based on a law, provided for by a contract, or necessary to enter into a contract.
User rights
Users may exercise certain rights with regard to the data processed by the Data Controller.
In particular, the user has the right to:
- Withdraw consent at any time. The user may withdraw consent to the processing of their personal data previously given.
- Object to the processing of their data. The user may object to the processing of their data when it is carried out on a legal basis other than consent. Further details on the right to object are provided in the section below.
- Access their data. The user has the right to obtain information regarding the data processed by the Data Controller, certain aspects of the processing, and to receive a copy of the data processed.
- Verify and request rectification. The user may verify the accuracy of their data and request that it be updated or corrected.
- Obtain restriction of processing. When certain conditions are met, the user may request restriction of the processing of their data. In this case, the Data Controller will not process the data for any purpose other than their storage.
- Obtain erasure or removal of their personal data. When certain conditions are met, the user may request that the Data Controller erase their data.
- Receive their data or have it transferred to another controller. The user has the right to receive their data in a structured, commonly used and machine‑readable format and, where technically feasible, to obtain the transfer of such data without hindrance to another controller. This provision applies when the data are processed by automated means and the processing is based on the user’s consent, on a contract to which the user is party, or on contractual measures connected thereto.
- Lodge a complaint. The user may lodge a complaint with the competent personal data protection supervisory authority or take legal action. Italian Data Protection Authority (Garante per la Privacy) – link to the Authority’s page.
Place
Data are processed at the operating offices of the Data Controller and in any other place where the parties involved in the processing are located. For further information, contact the Data Controller.
The user’s personal data may be transferred to a country other than the one in which the user is located. To obtain further information about the place of processing, the user may refer to the section containing details on the processing of personal data.
The user has the right to obtain information concerning the legal basis for the transfer of data outside the European Union or to an international organization governed by public international law or belonging to two or more countries, such as the UN, as well as information on the security measures adopted by the Data Controller to protect the data.
If any of the transfers described above take place, the user may refer to the relevant sections of this document or request information from the Data Controller by contacting them at the addresses given at the beginning of this notice.
Retention period
Data are processed and stored for as long as required by the purposes for which they were collected.
Therefore:
- Personal data collected for purposes related to the performance of a contract between the Data Controller and the user will be retained until such contract has been fully performed.
- Personal data collected for purposes related to the Data Controller’s legitimate interests will be retained until those interests have been satisfied. The user may obtain further information regarding the legitimate interests pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
When processing is based on the user’s consent, the Data Controller may retain personal data for a longer period until such consent is withdrawn. Furthermore, the Data Controller may be obliged to retain personal data for a longer period in compliance with a legal obligation or by order of an authority.
Once the retention period has expired, personal data will be deleted. Therefore, upon expiry of this period, the rights of access, erasure, rectification and data portability can no longer be exercised.
Details on the right to object
When personal data are processed in the public interest, in the exercise of official authority vested in the Data Controller, or for the purposes of the legitimate interests pursued by the Data Controller, users have the right to object to the processing on grounds relating to their particular situation.
Users are reminded that, where their data are processed for direct marketing purposes, they may object to such processing without providing any justification. To find out whether the Data Controller processes data for direct marketing purposes, users may refer to the relevant sections of this document.
How to exercise rights
To exercise their rights, users may send a request to the contact details of the Data Controller indicated in this document. Requests are submitted free of charge and processed by the Data Controller as soon as possible, and in any case within one month.
III – DATA PROCESSED
Methods of data processing
Like all websites, this site uses log files in which information collected automatically during users’ visits is stored. The information collected may include:
- Internet Protocol (IP) address
- Type of browser and parameters of the device used to connect to the site
- Name of the Internet Service Provider (ISP)
- Date and time of the visit
- Referring and exit web page
- Possibly the number of clicks
The above information is processed automatically and collected exclusively in aggregate form for the purpose of verifying the correct operation of the site and for security reasons. This information is processed on the basis of the Data Controller’s legitimate interests.
For security purposes (spam filters, firewalls, virus detection), automatically recorded data may also include personal data such as the IP address, which may be used, in accordance with applicable law, to block attempts to damage the site itself or to harm other users, or in any case to prevent harmful or criminal activities. Such data are never used to identify or profile the user, but only to protect the site and its users. This information is processed on the basis of the Data Controller’s legitimate interests.
Data sent by email remain stored in the email archive and in the website database. The hosting and mail server service is provided by Aruba srl.
Purposes of processing of collected data
User data are collected to allow the Data Controller to provide its services, as well as for the following purposes: access to accounts on third‑party services, interaction with social networks and external platforms, viewing content from external platforms, and optimization and distribution of traffic.
User data are collected for security purposes (spam filters, firewalls, virus detection). Automatically recorded data may also include personal data such as the IP address, which may be used, in accordance with applicable law, to block attempts to damage the site itself or to harm other users, or in any case to prevent harmful or criminal activities. Such data are never used for user identification or profiling, nor combined with other data, nor disclosed to third parties, but used solely to protect the site and its users (as of May 25, 2018, this information is processed on the basis of the Data Controller’s legitimate interests).
Data collected by the site during its operation are used solely for the purposes indicated above and retained for the time strictly necessary to carry out the specified activities.
In any case, personal data collected by the site will never be disclosed to third parties for any reason, unless there is a legitimate request by judicial authorities and only in the cases provided for by law. However, data may be provided to third parties when this is necessary to provide a specific service requested by the user (e.g. comment management), or to perform security checks or optimize the site.
This site may share some of the data collected with services located outside the European Union. In particular, with Google, Facebook and Microsoft (LinkedIn) via social plugins and the Google Analytics service. The transfer is authorized on the basis of specific decisions of the European Union and the Italian Data Protection Authority, in particular Decision 1250/2016 (Privacy Shield – see the information page of the Italian Data Protection Authority), and therefore no additional consent is required. The above‑mentioned companies guarantee their adherence to the Privacy Shield.
If the site allows users to post comments or in the case of specific services requested by the user (via the Contacts section), the site automatically detects and records certain user identification data, including email address and nickname. These data are understood to be voluntarily provided by the user at the time the service is delivered and are processed on the basis of consent. By posting a comment or other information, the user expressly accepts this privacy notice and in particular agrees that the posted content may be freely visible to other visitors.
The data received will be used exclusively to provide the requested service and only for the time necessary to deliver the service.
Information that users choose to make public through the services and tools made available to them on the site is provided by the user knowingly and voluntarily, and the site is exempt from any liability regarding any legal violations. It is the user’s responsibility to verify that they have permission to submit personal data of third parties or content protected by national or international laws.
IV – ADDITIONAL INFORMATION ABOUT DATA PROCESSING
Further information about processing
Defense in legal proceedings
The user’s personal data may be used by the Data Controller in legal proceedings or in the preparatory stages thereof for the defense against misuse of this website or related services by the user. The user acknowledges that the Data Controller may be required to disclose data by order of public authorities.
Specific notices
Upon the user’s request, in addition to the information contained in this privacy policy, this website may provide the user with additional and contextual notices regarding specific services, or the collection and processing of personal data.
System logs and maintenance
For operation and maintenance purposes, this website and any third‑party services it uses may collect system logs, i.e. files that record interactions and may contain personal data such as the user’s IP address.
Information not contained in this policy
Further information regarding the processing of personal data may be requested at any time from the Data Controller using the contact details provided.
Definitions and legal references
Personal data (or data)
Personal data means any information which, directly or indirectly, including in connection with any other information, such as a personal identification number, identifies or makes identifiable a natural person.
Usage data
Usage data are information collected automatically through this website (or third‑party applications integrated into this website), including: IP addresses or domain names of the computers used by users connecting to this website; URI (Uniform Resource Identifier) addresses; the time of the request; the method used to submit the request to the server; the size of the file obtained in response; the numerical code indicating the status of the server’s response (successful, error, etc.); the country of origin; the characteristics of the browser and operating system used by the visitor; the various time details of the visit (e.g. time spent on each page); and the details relating to the path followed within the application, with particular reference to the sequence of pages viewed, and parameters regarding the user’s operating system and IT environment.
User
The individual who uses this website and who, unless otherwise specified, coincides with the data subject.
Data subject
The natural person to whom the personal data refer.
Data Processor
The natural or legal person, public administration and any other entity that processes personal data on behalf of the Data Controller, as described in this privacy policy.
Data Controller
The natural or legal person, public authority, service or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data and the tools adopted, including the security measures relating to the operation and use of this website. Unless otherwise specified, the Data Controller is the owner of this website.
This website (or this application)
The hardware or software tool through which users’ personal data are collected and processed.
Service
The service provided by this website, as described in the relevant terms (if available) on this site/application.
European Union (or EU)
Unless otherwise specified, any reference to the European Union in this document is intended to include all current Member States of the European Union and the European Economic Area.
Cookie
A small piece of data stored on the user’s device.