Data Controller

Giorgia P. SRL
via E. A. Paterno 5 86036 Montenero di Bisaccia (CB)
CF / VAT number 01651020701

Email address of the Owner: info@giorgiastella.com
Types of Data collected

Among the Personal Information collected by this Website, either independently or through third parties, there are: Cookies, Usage data, email, name, surname, telephone number, geographic location, address, username, password, Fiscal Code, Match VAT, postal code, city, billing address, shipping address and house number.

Full details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed before the data are collected.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Website.
Unless otherwise specified, all the Data requested by this Website are mandatory. If the User refuses to communicate them, it may be impossible for this Website to provide the Service. In cases where this Website indicates some Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or on its operation.
Users who have doubts about which data are mandatory, are encouraged to contact the owner.
Any use of Cookies – or other tracking tools – by this Website or by third party service providers used by this Website, unless otherwise specified, is intended to provide the Service requested by the User, in addition the additional purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Website and warrants that he has the right to communicate or disseminate them, freeing the Owner from any liability to third parties.

Mode and place of processing of collected data
Method of treatment

The Controller takes appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data.
Processing is carried out using IT and / or telematic tools, with organizational methods and with logic strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the organization of this Website (administrative, commercial, marketing, legal, system administrators) or external subjects (as suppliers of third party technical services, postal carriers) may have access to the Data. , hosting providers, IT companies, communication agencies) also appointed, if necessary, Data Processors by the Data Controller. The updated list of Managers can always be requested from the Data Controller.
Legal basis of the processing

The Holder processes Personal Data relating to the User in the event one of the following conditions exists:

the User has given consent for one or more specific purposes; Note: in some jurisdictions the Owner may be authorized to process Personal Data without the User’s consent or another of the legal bases specified below, as long as the User does not object (“opt-out”) to this treatment. However, this is not applicable if the processing of Personal Data is regulated by European legislation regarding the protection of Personal Data;
the processing is necessary for the execution of a contract with the User and / or the execution of pre-contractual measures;
the processing is necessary to fulfill a legal obligation to which the Data Controller is subject;
the processing is necessary for the performance of a task carried out in the public interest or for the exercise of public authority vested in the Holder;
the processing is necessary for the pursuit of the legitimate interest of the owner or third parties.

In any case, it is always possible to ask the Owner to clarify the concrete legal basis of each treatment and in particular to specify whether the treatment is based on the law, provided for by a contract or necessary to conclude a contract.
Place

The Data are processed at the operational headquarters of the Data Controller and in any other place where the parties involved in the processing are located. For more information, contact the owner.
The User’s Personal Data may be transferred to a country other than that in which the User is located. To obtain further information on the processing site, the User can refer to the section concerning the processing of Personal Data.

You have the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization of public international law or consisting of two or more countries, such as the UN, as well as regarding the security measures taken by the Data Controller to protect the Data.

The User can check whether one of the transfers described above takes place by examining the section of this document regarding the details on the processing of Personal Data or requesting information from the Data Controller by contacting him at the opening dates.
Retention period

The Data are processed and stored for the time required by the purposes for which they were collected.

Therefore:

Personal Data collected for purposes related to the execution of a contract between the Owner and the User will be retained until the execution of the contract is completed.
Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained until such interest is met. The User can obtain further information regarding the legitimate interest pursued by the Owner in the relevant sections of this document or by contacting the Data Controller.

When the processing is based on the consent of the User, the Data Controller may retain the Personal Data for a longer period until such consent is revoked. Furthermore, the Data Controller may be obliged to keep Personal Data for a longer period in compliance with a legal obligation or an order of an authority.

At the end of the retention period the Personal Data will be deleted. Therefore, at the end of this term the right of access, cancellation, rectification and the right to data portability can no longer be exercised.

Purposes of the processing of collected data

The Data concerning the User is collected to allow the Owner to provide its Services, as well as for the following purposes: Analytics, Contacting the User, Tag Management, Displaying content from external platforms, Registration and authentication, Protection from SPAM, Location-based interactions and Payment management.

To obtain further detailed information on the purposes of the processing and on the Personal Data concretely relevant to each purpose, the User can refer to the relevant sections of this document.
Details on the processing of Personal Data

Personal Data is collected for the following purposes and using the following services:

Contact the user
Mailing list or newsletter (this Website)

By registering with the mailing list or the newsletter, the User’s email address is automatically added to a list of contacts to which email messages containing information, including commercial and promotional information, relating to this Website may be transmitted. User’s email address could also be added to this list as a result of registering with this Website or after making a purchase.

Personal Data collected: email and name.
Contact form (this Website)

By filling out the contact form with their Data, the User consents to their use to respond to requests for information, quotes, or any other kind indicated by the form header.

Personal Data collected: surname, email address, first name and phone number.
Payment management

The payment management services allow this Website to process payments by credit card, bank transfer or other instruments. The data used for payment are acquired directly by the payment service provider requested without being in any way handled by this Website.
Some of these services may also allow the sending of messages to the User, such as emails containing invoices or notifications regarding payment.
PayPal (Paypal)

PayPal is a payment service provided by PayPal Inc., which allows the User to make payments online.

Personal Data collected: various types of Data as specified in the privacy policy of the service.

Place of processing: Consult the Paypal privacy policy – Privacy Policy.
Stripe (Stripe Inc)

Stripe is a payment service provided by Stripe Inc.

Personal Data collected: various types of Data as specified in the privacy policy of the service.

Place of processing: United States – Privacy Policy. Person adhering to the Privacy Shield.

Tag management

This type of service is functional to the centralized management of the tags or scripts used on this Website.
The use of these services involves the flow of User Data through them and, if necessary, their retention.
Google Tag Manager (Google LLC)

Google Tag Manager is a tag management service provided by Google LLC.

Personal Data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Person adhering to the Privacy Shield.
Location-based interactions
Geolocation (this Website)

This Website may collect, use and share data relating to the geographical location of the User, in order to provide services based on the position itself.
Most browsers and devices provide default tools to deny geographic tracking. If the User has expressly authorized this possibility, this Website may receive information on its actual geographical position.

Personal Data collected: geographic position.
Protection from SPAM

This type of service analyzes the traffic of this Website, potentially containing Personal Data of Users, in order to filter it from parts of traffic, messages and contents recognized as SPAM.
Google reCAPTCHA (Google LLC)

Google reCAPTCHA is a SPAM protection service provided by Google LLC.
Use of the reCAPTCHA system is subject to Google’s privacy policy and terms of use.

Personal Data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Person adhering to the Privacy Shield.

Registration and authentication

By registering or authenticating the User allows the Application to identify it and give it access to dedicated services.
Depending on the following, the registration and authentication services may be provided with the help of third parties. If this happens, this application will be able to access some data stored by the third party service used for registration or identification.
Facebook Authentication (Facebook, Inc.)

Facebook Authentication is a registration and authentication service provided by Facebook, Inc. and connected to the Facebook social network.

Personal Data collected: various types of Data as specified in the privacy policy of the service.

Place of processing: United States – Privacy Policy. Person adhering to the Privacy Shield.
Google OAuth (Google LLC)

Google OAuth is a registration and authentication service provided by Google LLC and connected to the Google network.

Personal Data collected: various types of Data as specified in the privacy policy of the service.

Place of processing: United States – Privacy Policy. Person adhering to the Privacy Shield.
Direct registration (this Website)

The User registers by filling in the registration form and providing his Personal Data directly to this Website.

Personal Data collected: ZIP code, city, Fiscal Code, surname, address, billing address, shipping address, name, house number, VAT number, password and username.
Statistics

The services contained in this section allow the Data Controller to monitor and analyze traffic data and are used to keep track of User behavior.
Google Analytics (Google LLC)

Google Analytics is a web analytics service provided by Google LLC (“Google”). Google uses Personal Information collected for the purpose of evaluating the use of this Website, compiling reports and sharing them with other services developed by Google.
Google may use the Personal Data to contextualise and personalize the advertisements of its advertising network.

Personal Data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy – Opt Out. Person adhering to the Privacy Shield.

Displaying content from external platforms

This type of service allows you to view content hosted on external platforms directly from the pages of this Website and to interact with them.
In the event that a service of this type is installed, it is possible that, even if the Users do not use the service, the same collect traffic data relating to the pages in which it is installed.
Instagram Widget (Instagram, Inc.)

Instagram is an image visualization service managed by Instagram, Inc. that allows this Website to integrate such content within its pages.

Personal Data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy.
Google Fonts (Google LLC)

Google Fonts is a service of visualization of styles of character managed by Google LLC that allows this Web Site to integrate such contents within its pages.

Personal Data collected: Usage data and various types of Data as specified in the privacy policy of the service.

Place of processing: United States – Privacy Policy. Person adhering to the Privacy Shield.
Google Maps widget (Google LLC)

Google Maps is a map visualization service managed by Google LLC that allows this Website to integrate such contents within its pages.

Personal Data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Person adhering to the Privacy Shield.
YouTube Video Widget (Google LLC)

YouTube is a video content visualization service managed by Google LLC that allows this Website to integrate such content within its pages.

Personal Data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Person adhering to the Privacy Shield.

User Rights

Users may exercise certain rights with reference to the Data processed by the Data Controller.

In particular, the User has the right to:

withdraw consent at any time. The User can withdraw consent to the processing of their Personal Data previously expressed.
oppose the processing of your data. You may object to the processing of your data when it occurs on a legal basis other than consent. Further details on the right of opposition are indicated in the section below.
access your data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing and to receive a copy of the Data processed.
verify and request rectification. The User can verify the correctness of his Data and request its updating or correction.
obtain treatment limitation. When certain conditions are met, the User may request the limitation of the processing of their Data. In this case, the Data Controller will not process the Data for any other purpose other than their conservation.
obtain the cancellation or removal of their Personal Data. When certain conditions are met, the User can request the cancellation of their Data by the Owner.
receive your data or have it transferred to another holder. You have the right to receive your data in a structured format, commonly used and readable by automatic device and, where technically feasible, to obtain the transfer without hindrance to another holder. This provision is applicable when the Data are processed with automated tools and the processing is based on the User’s consent, on a contract of which the User is a party or on contractual measures connected to it.
propose a complaint. The User can lodge a complaint with the competent personal data protection authority or act in court.

Details on the right of opposition

When Personal Data is processed in the public interest, in the exercise of public authority to which the Holder is invested or to pursue a legitimate interest of the Owner, Users have the right to oppose the processing for reasons related to their particular situation.

Users are reminded that, if their data are processed for direct marketing purposes, they can oppose the processing without providing any reasons. To find out if the Owner deals with data for direct marketing purposes, Users can refer to the respective sections of this document.
How to exercise the rights

To exercise the rights of the User, Users can direct a request to the contact details of the Owner indicated in this document. The requests are deposited free of charge and processed by the Owner as soon as possible, in any case within a month.

More information on treatment
Defense in court

The User’s Personal Data may be used by the Owner in court or in the preparatory stages of its possible establishment for the defense against abuse of the use of this Website or the related Services by the User.
The User declares to be aware that the Data Controller may be obliged to disclose the Data by order of the public authorities.
Specific information

At the request of the User, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.
System logs and maintenance

For needs related to operation and maintenance, this Website and any third party services used by it may collect system logs, which are files that record the interactions and which may also contain Personal Data, such as the User IP address.
Information not contained in this policy

Further information in relation to the processing of Personal Data may be requested at any time to the Data Controller using the contact details.
Response to “Do Not Track” requests

This Website does not support “Do Not Track” requests.
To find out if any third-party services used support them, the User is invited to consult their respective privacy policies.
Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by informing Users on this page and, if possible, on this Website as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details held by the Holder. Please therefore consult this page regularly, referring to the date of the last modification indicated at the bottom.

If the modifications concern treatments whose legal basis is consent, the Controller will collect the User’s consent again, if necessary.

Definitions and legal references
Personal Data (or Data)

It constitutes personal data any information that, directly or indirectly, also in connection with any other information, including a personal identification number, makes a physical person identified or identifiable.
Usage Data

This information is collected automatically through this Website (also from third party applications integrated into this Website), including: IP addresses or domain names of the computers used by the User that connects to this Website, the addresses in URI (Uniform Resource Identifier) ​​notation, the time of the request, the method used in forwarding the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (good order, error, etc. .) the country of origin, the characteristics of the browser and the operating system used by the visitor, the various temporal connotations of the visit (for example the time spent on each page) and the details relating to the itinerary followed within the Application, with particular reference to the sequence of the pages consulted, to the parameters relating to the operating system and the IT environment of the User.
User

The individual who uses this Website that, unless otherwise specified, coincides with the interested party.
Interested

The natural person to whom the Personal Data refers.
Data Processor (or Manager)

The natural person, legal person, public administration and any other entity that processes personal data on behalf of the Owner, as set out in this privacy policy.
Data Controller (or Holder)

The natural or legal person, public authority, service or other body which, individually or together with others, determines the purposes and means of the processing of personal data and the tools adopted, including the security measures related to the operation and use of this Website. The Data Controller, unless otherwise specified, is the owner of this Website.
This Website (or this Application)

The hardware or software tool through which the Personal Data of Users are collected and processed.
Service

The Service provided by this Website as defined in the relevant terms (if any) on this website / application.
European Union (or EU)

Unless otherwise specified, any reference to the European Union contained in this document shall be extended to all current member states of the European Union and the European Economic Area.
Cookie

Small portion of data stored in the User’s device.
Legal references

This privacy statement is drawn up on the basis of multiple legislative systems, including articles 13 and 14 of Regulation (EU) 2016/679.

Unless otherwise specified, this privacy statement applies exclusively to this Website.

Scarica l’Informativa dipendenti in materia di protezione dei dati personali