Policy on the processing of personal data
Pursuant to Art. 13 of EU GDPR 2016/679 “Regulation (UE) of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data”.
With reference to the provision of data through the website of www.acquaeco.com.
Dear Data Subjects,
pursuant to Articles 13 of the EU GDPR 2016/679 (new European Regulation on the protection of personal data), please be informed that, as defined in Art. 4 of the Privacy Code, the Data Controller, Acqua&Co S.r.l. (hereinafter the “Controller”), having its registered office in Via G. Augera 5/A, Cadelbosco di Sopra (Reggio nell’Emilia, Italy), tax and VAT n. 01544070350, being represented by its legal representative, holds and processes personal data protected under Regulation (EU) 2016/679.
Types of data collected
Data in connection with website browsing
Information systems and software procedures used to operate this website acquire, during the normal course of operation, some personal data whose transmission is implicit in the communication protocols of the Internet. This category of data includes IP addresses, the type of browser used, the operating system, the name of the domain and the addresses of the websites from which access was gained, information on the pages the users have visited on the website, the time spent on each single page, internal path analysis, and other parameters concerning the operating system and the IT environment of the user.
Data are not collected for the purpose of matching them with identified data subjects. However, if they were cross-referenced with other information or data, including data held by third parties, they may help identify the user.
Data used in aggregate form are stored for a period of 12 months to gather statistics on the use of the website. The provision of such data is automatic and necessary to correctly provide the services available on the website. Processing of these data is lawful as it is required to fulfil the users’ demands.
Data provided by the user deliberately
Optional, explicit and deliberate sending of emails to the email addresses available on the website automatically results in the acquisition of the personal data that appear in the message and in the email address. Such data shall exclusively be used to give the users the replies they expect.
Providing a reply to the optional, explicit and deliberate requests submitted via the contact form available on the website shall cause the acquisition of personal data with the data subject’s consent. The data shall only be used to provide the necessary replies.
Data required to subscribe to the newsletter
Any data provided by the user to receive our Newsletter shall also be used by the Controller to send promotional and advertising material on products and services after receiving the data subject’s consent. Data shall be processed until the consent is withdrawn.
Data required to sign in to the reserved website area
Any data given by the data subject to sign in to the reserved area of the website are exclusively used to identify the data subject via computer authentication. Such data are acquired after receiving the data subject’s consent. Data shall be processed until the consent is withdrawn.
Purpose of processing and legal base
Data are processed for the purpose of managing and maintaining the website www.acquaeco.com.
|To provide the service required by the user, i.e. website browsing, to manage the contracts signed by the user, to fulfil administrative, accounting, fiscal and legal obligations, and to respond to the requests deliberately submitted by the user via email to the addresses available on the website.
|Processing put in place for the purposes above are necessary to comply with the contractual obligations and they do not require any specific consent by the data subject.
|To respond to the requests that are submitted through the “Contacts” page of the website.
|Sending of the Newsletter and other commercial notifications after the user has registered in the mailing list from the website.
|To give access to the reserved area in the website where information is stored about the products and the services offered by the company.
|To track the user’s experience as regards the use of the website and to ensure that both the web pages and their contents work correctly.
|Processing for these purposes are based on the Controller’s legitimate interest.
What are cookies? Cookies are small text files that the websites send to the visitor’s device (to the Internet browser): they store some data persistently which will be used at a later stage in the same browsing session or in the following sessions. While visiting a website, the visitor can also receive cookies (third-party cookies) from other websites in one single browsing session which can collect information to be disclosed to third parties.
Cookies can have multiple purposes, based on which they may be technical, analytics, and profiling cookies. Technical cookies are intended to provide for some functions of the website (i.e. they identify the language chosen to visit the website or verify correct user’s authentication). Analytics cookies, on the other hand, collect information on the web pages visited and on the most frequently used parts of the website for the purpose of creating website statistics. Profiling cookies are intended to profile website visitors in order to offer them customised ads based on their preferences, as identified during their visit to the website.
This website uses technical cookies, i.e. cookies used to facilitate “the transmission of a communication over an electronic communication network or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user” (ref. Art. 122, para. 1, of the Privacy Code), as well as third-party analytics cookies, i.e. cookies intended to collect information in aggregate form concerning the number of users and how they visit the website using an analysis service offered by a third-party organization.
Methods for the processing of personal data and tools used
All processing shall be performed using electronic procedures and media, and for as long as strictly required to fulfil the purposes for which data were collected. Suitable safety measures have been put in place to prevent data losses, unauthorised accesses, and unlawful, unfair use and misuse.
Scope of data flow
Any data collected shall not be disseminated or shared with external entities, except where strictly necessary to:
– fulfil a legal obligation, where required;
– pursue scams, frauds or misuse of the website or parts thereof.
No data shall be disclosed to other external entities. Data shall in no case be transferred outside the European Union.
Automated decision-making (users’ profiling)
No automated system for the profiling of the data subjects shall be used to process data collected from and managed by the website www.acquaeco.com.
The collected data shall not be used for any kind of marketing, except for the mailing of the Newsletter or commercial notifications prior consent of the data subject.
Storage of data
The collected data shall be stored for as long as strictly necessary for their use, except where storage is required by law. The logs of the email server and website shall be stored for a maximum time of 12 months.
Rights of data subject
The subjects to whom the personal data above refer (i.e. the “data subjects”) shall be entitled to exercise their rights as required and within the limits laid down in the existing privacy regulations. With specific reference to their personal data, the data subjects shall be entitled to request the following from the Controller:
access – the data subject shall have the right to obtain confirmation as to whether or not personal data concerning him or her are being processed, as well as further clarifications on the information provided in this Policy, and to receive his/her data for as much as reasonable;
rectification – the data subject shall have the right to obtain the rectification or supplementation of the personal data s/he has given us or in our possession where such data are not correct;
erasure/right to be forgotten – the data subject shall have the right to obtain erasure of his/her personal data that the Controller may have either acquired or processed where the personal data are no longer necessary to our purposes or no objections or controversies are in place, where consent was withdrawn or processing was objected to, where personal data have been used unlawfully, or finally where the personal data have to be erased to comply with a legal obligation;
restriction – the data subject shall have the right to obtain restriction of processing of his/her personal data where one of the conditions laid down in Art. 18 of the GDPR applies. In this case, the data subject’s data shall not be processed, other than for the purpose of storage, without his/her consent, with the exception of the provisions in the above-mentioned article, para. 2;
objection – the data subject shall at any time have the right to object to the processing of his/her personal data based on our legitimate interest, unless we have legitimate grounds for the processing which override the data subject’s rights, such as the establishment, exercise or defence of legal claims. The data subject’s objection shall in any case override our legitimate interest;
portability – the data subject shall have the right to receive his/her personal data or to have them transmitted to a new controller s/he shall specify, in a structured, commonly used and machine-readable format.
Pursuant to Art. 7, para. 3, of the GDPR, the data subject shall have the right to withdraw his or her consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. Finally, the data subject shall have the right to lodge a complaint with a supervisory authority, which shall be the Italian Data Protection Supervisor in this specific case.
The Data Controller specified below should be addressed to exercise the above-mentioned rights, to report any problems or to ask for clarifications on the processing of personal data:
This document was last updated on 24/08/2018.