Disclosure pursuant to EU Regulation 679/2016
1. Preliminary remarks
Pursuant to articles 13 et seq. of EU Regulation 679/2016 ("GDPR"), Promemoria srl ("Company" or the "Owner") provides below the information regarding the processing of personal data of users ("User / Users") in the context of consultation and / or use of the services of the website: www.archiviomagazine.com ("Site").
The information is provided only for the Site and not for other websites that may be consulted by the User through links on the Site.
2. Data controller
The Data Controller is Promemoria s.r.l., with registered office in Turin, Via Pomba 1. E-mail: firstname.lastname@example.org Telephone: 011.19694875.
3. Data Protection Officer
The Company has appointed a Data Protection Officer (DPO). For all questions relating to the processing of personal data and/or to exercise the rights provided for in the Regulations, the User may contact the DPO at the following email address: email@example.com.
4. Types of data processed
4.1 Navigation data
The computer systems and software procedures used to operate the Site acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols.
This information is not collected to be associated with identified subjects, but by its very nature could allow users to be identified.
This category of data includes (i) IP addresses or domain names of computers used by users connecting to the Site, (ii) URI (Uniform Resource Identifier) of requested resources, (iii) the time of the request, (iv) the method used to submit the request to the server, (v) the size of the file obtained in response, (vi) the numerical code indicating the status of the response from the server (successful, error) and (vii) other parameters relating to the operating system and computer environment of the user.
These data are used only to obtain anonymous statistical information on the use of the Site and to check its proper functioning and are deleted immediately after processing.
For the processing of data using cookies, please read the relevant policy, available at the following link.
4.3 Data provided voluntarily by the User:
a) The optional, explicit and voluntary sending of e-mails to the e-mail addresses indicated on the Site entails the acquisition and processing by the Owner of such data and any other information contained in such communications for the purposes indicated in the following paragraph;
b) the request by the User to receive the newsletter implies, with the consent of the interested party, the processing of the following data: e-mail address;
c) the purchase of a product, involves the processing of payment and shipping data, such as: name, surname, address, e-mail, telephone (optional).
4.4 Purpose and legal basis of the processing
The processing of the User's personal data by the Owner is aimed at:
1. to pursue, in accordance with art. 6.1, letter f) of the GDPR, its own legitimate interest, consisting in guaranteeing the security of the Site and of the information exchanged on it, i.e. the ability of this Site to withstand, at a given level of security, unforeseen events or unlawful or malicious acts that compromise the availability, authenticity, integrity and confidentiality of the personal data stored or transmitted and the security of the related services offered or made available;
2. to send the newsletter;
3. to allow the User to communicate with the email addresses indicated on the Site;
4. to allow the User to purchase a product available on the platform.
5. Compulsory or optional nature of data provision and consequences of a refusal to respond
The nature of the provision of data by the User is mandatory for the data controller to provide the services requested. In case of refusal it will be impossible to carry out the activities required for registration to the platform or activation of the Gift Card and for the execution of the service purchased.
6. Processing methods and storage times of personal data
Personal data are processed by manual, computer and automated systems. For the purposes of the correct processing of data, it is necessary that the person concerned promptly notifies any changes. The data relating to the online payment of the services purchased will be processed by PayPal in a protected and secure environment and will not be acquired and processed in any way by Promemoria srl.
It should be noted, in particular, that the User's personal data are processed by persons duly appointed to perform these tasks, constantly identified and / or appointed, properly instructed and made aware of the constraints imposed by law, as well as through the use of security measures to ensure the protection of confidentiality and to avoid the risks of loss or destruction, unauthorized access, processing not allowed or not in accordance with the purposes mentioned above. Security measures are constantly improved in line with technological developments.
7. Communication of data to third parties
Personal data will be processed by the data controller, by the data processors appointed by him and by the processors strictly authorized. They may be communicated to the companies that own the data processing, if appointed.
The data may also be communicated following inspections or checks, if requested to the Company, to all inspection bodies responsible for checks and controls concerning the regularity of legal obligations.
The Owner guarantees the utmost care so that the communication of personal data to the aforementioned recipients concerns only the data necessary for the achievement of the specific purposes for which they are intended.
Personal data are stored in the databases of the Owner and will be processed only by authorized personnel. The latter will be provided with specific instructions on the methods and purposes of processing. Such data will also not be disclosed to third parties, except as provided above and, in any case, within the limits indicated therein, as well as will not be disclosed, except in the cases described above and / or required by law.
8. Duration of processing and storage of personal data
The User's personal data will be processed by the Owner only for the period of time necessary to achieve the purposes of the treatment after which they will be kept only in compliance with the legal obligations in force on the subject, for administrative purposes and / or to assert or defend their rights in case of litigation and pre-litigation.
9. Existence of an automated decision-making process
There is no automated decision-making process.
10. Intention of the holder of the personal data treatment
The Data Controller will not transfer Users' personal data to a third country or international organisation.
11. Rights of the data subject
As an interested party, the User may exercise, at any time, against the Holder, the rights under Art. 7 of the Privacy Code and Art. 15 of the GDPR listed below, by sending a written request to the following email address: firstname.lastname@example.org.
In the same way, the User may at any time revoke the consents expressed in this policy.
The User has the right to:
- to obtain confirmation of the existence or not of personal data concerning him, even if not yet recorded, and their communication in intelligible form;
- obtain information on: a) the source of the personal data; b) the purposes and methods of processing; c) the logic applied in the event of processing carried out with the help of electronic means; d) the identification data concerning the data controller, data processors and the representative designated pursuant to Article 5(2) of the Privacy Code and Article 3(1) of the GDPR; e) the entities or categories of entity to whom or which the personal data may be communicated and who or which may get to know said data in their capacity as designated representative(s) in the State's territory, data processor(s) or person(s) in charge of the processing;
- obtain: a) the updating, rectification or, when interested, integration of data; b) the cancellation, transformation into anonymous form or blocking of data processed unlawfully, including data whose retention is unnecessary for the purposes for which the data were collected or subsequently processed; c) certification to the effect that the operations as per letters a) and b) have been notified, as also related to their contents, to the entities to whom or which the data were communicated or disseminated, unless this requirement proves impossible or involves a manifestly disproportionate effort compared with the right that is to be protected;
- oppose, in whole or in part: a) for legitimate reasons to the processing of personal data concerning him, even if pertinent to the purpose of collection; b) the processing of personal data concerning him for the purpose of sending advertising materials or direct selling or for carrying out market research or commercial communication, through the use of automated calling systems without the intervention of an operator by e-mail and / or traditional marketing methods by telephone and / or mail. It should be noted that the right of opposition of the person concerned, as set out in point b) above, for direct marketing purposes by means of automated methods extends to the traditional ones and that, in any case, the possibility for the person concerned to exercise the right of opposition even in part remains unaffected. Therefore, the interested party may decide to receive only communications by traditional means or only automated communications or neither of the two types of communication.
Where applicable, he also has the rights under Articles. 16-21 GDPR (Right of rectification, right to be forgotten, right to limitation of processing, right to data portability, right of opposition), as well as the right of complaint to the Guarantor Authority.
*** *** ***