Information on the processing of personal data. Effective from 25/09/24
INTRODUCTION
This information takes into account the provisions of Regulation (EU) 2016/679 of the European Parliament and Council of April 27, 2016 (GDPR) and the Privacy Code (Legislative Decree No. 196 of June 30, 2003). The document has also been drafted in accordance with the Guidelines of the Data Protection Authority (especially the Guidelines for combating spam issued by the Data Protection Authority on July 4, 2013).
Data Controller:
Castelveder Agricultural Company
VAT No. 03011870981
REA BS - 497558
Via Belvedere 4,
25040 Monticelli Brusati, Brescia
Website to which this privacy policy refers:
https://castelveder.it (Site)
https://shop.castelveder.it (Site).
The Data Controller has not appointed a DPO (Data Protection Officer). Therefore, you can send any requests for information directly to the Data Controller.
GENERAL INFORMATION
This document describes how the Data Controller processes your personal data provided on the Site.
The main processing activities of your personal data are described below. In particular, the legal basis for processing is explained, whether the provision of data is mandatory, and the consequences of not providing personal data. To better describe your rights, where necessary, we have specified if and when a specific processing of personal data does not take place.
Registration on the Site
The information and data required for registration will be used to allow you to access the reserved area of the Site and to use the online services offered by the Data Controller to registered users. The legal basis for processing is the necessity for the Data Controller to take pre-contractual measures adopted at the request of the data subject. Providing the data is optional. However, your refusal to provide the data will result in the inability to register on the Site.
Purchases on the Site
Your personal data will be processed to allow you to make purchases on the Site. In the case of placing an online purchase order, to allow the conclusion of the purchase contract and the proper execution of operations related to it (and, where necessary under sector regulations, to fulfill tax obligations). This processing of personal data also includes the possibility of sending communications (e.g., tracking and order information) through automated tools such as SMS and/or WhatsApp. The legal basis for processing is the obligation of the Data Controller to execute the contract with the data subject or to comply with legal obligations. Regardless of the above (and therefore of your consent), the Data Controller may process your data for the purposes of so-called "soft spam," governed by Article 130 of the Privacy Code. This means that limited to the email you provided in the context of a purchase through the Site, the Data Controller will process the email to allow direct offers of similar products/services, as long as you do not oppose such processing in the manner provided by this information. The legal basis for processing is the legitimate interest of the Data Controller to send this type of communication. This legitimate interest can be considered equivalent to the interest of the data subject in receiving "soft spam" communications. The Data Controller may send emails to remind the user to complete a purchase. The legal basis for this processing is the legitimate interest of the Data Controller in sending this type of communication.
Responding to Your Requests
Your data will be processed to respond to your requests for information. Providing data is optional, but your refusal will result in the Data Controller's inability to respond to your questions. The legal basis for processing is the legitimate interest of the Data Controller in following up on user requests. This legitimate interest is equivalent to the user's interest in receiving a response to communications sent to the Data Controller. The Data Controller may process your personal data for the purpose of managing support tickets. The legal basis for processing is the legitimate interest of the Data Controller in responding to the request of the data subject. This interest is equivalent to that of the data subject in receiving a response. Personal data will be retained for this purpose until the necessary time to manage the ticket.
Generic Marketing
With your consent, the Data Controller may process the personal data you provide for the purpose of sending you advertising material and/or newsletters related to its own or third-party products. The legal basis for this processing is your consent. Providing personal data for this purpose is merely optional. Failure to consent to the processing of data for marketing purposes will result in your inability to receive advertising material related to products/services of the Data Controller and/or third parties as well as the inability for the Data Controller to conduct market surveys, including those aimed at assessing user satisfaction, as well as to send you newsletters. The sending of these communications will be to the email you provided on the Site.
Profiling
With your consent, the Data Controller may process your personal data for profiling purposes, i.e., to analyze your consumption choices through the identification of the type and frequency of purchases you have made, in order to send you advertising material and/or newsletters related to its own or third-party products of specific interest to you. The legal basis for this processing is your consent. Providing data for this purpose is merely optional. Failure to consent to the processing of your personal data for profiling purposes will result in the Data Controller's inability to develop your commercial profile, through the detection of your choices and purchasing habits as well as to send you advertising material related to products of the Data Controller and/or third parties of specific interest to you. These communications will be sent to the email you provided on the Site.
Data Transfer
The Data Controller does not transfer your personal data to third parties.
Geolocation
The Site does not implement tools for geolocating the user's IP address.
Curriculum Vitae
It is not possible to send curriculum vitae through the Site. Therefore, your data will not be processed for these purposes.
Appointment Booking
There are no active third-party appointment booking systems with the Data Controller on the Site. Therefore, your data will not be processed for this purpose. However, you can always contact the Data Controller using the contact information provided above.
Photographs and Videos
The Data Controller does not request the publication of photographs and/or videos depicting you. Therefore, your data will not be processed for these purposes.
Web Scraping
The use of any automated process or system to access, acquire, copy, or monitor any part of our website, including, but not limited to, web scraping, crawling, or spidering techniques, is expressly prohibited. The Data Controller reserves the right to take all necessary measures, including legal actions, to prevent and prosecute any unauthorized scraping activity.
By using the Site, you or any third party agree not to: (i) use automated systems, such as bots, scrapers, or spiders, to access or interact with the Site; (ii) collect content, data, or other information present on the Site without explicit written permission; (iii) distribute, display, publish, or otherwise use content obtained through scraping techniques without consent. Any violation of this clause will be considered a substantial breach of the terms of use of the Site and will lead to appropriate measures, including possible suspension of access to the site and the initiation of legal actions to protect the interests of the Data Controller.
Communication of Personal Data
In the course of its ordinary activities, the Data Controller may communicate your personal data to certain categories of subjects. In Article 2 you can find the list of subjects to whom the Data Controller communicates your personal data. To facilitate the protection of your rights, Article 2 may specify in some cases when your data is not communicated to third parties.
The "communication" to third parties of personal data is different from "transfer" (regulated in the previous section). In fact, in communication, the third party to whom the data is transmitted can only use it for the specific purposes described in the relationship with the Data Controller. In transfer, instead, the third party becomes an autonomous Data Controller of the personal data. Furthermore, your consent is always required to transfer your personal data to third parties.
Notwithstanding the above, it is understood that the Data Controller may still use your personal data to properly fulfill the obligations set forth by the laws in force.
SPECIFIC PRIVACY POLICY
Art. 1 Processing methods
1.1 The processing of your personal data will primarily be carried out using electronic or automated means, according to methods and with tools suitable for ensuring the security and confidentiality of personal data.
1.2 The information acquired and the methods of processing will be relevant and not excessive in relation to the type of services rendered. Your data will also be managed and protected in secure IT environments suitable for the circumstances.
1.3 Through the Site, "special data" is not processed. Special data are those that may reveal racial and ethnic origin, religious, philosophical, or other beliefs, political opinions, membership in parties, unions, associations, or organizations of a religious, philosophical, political, or union nature, health status, and sexual life.
1.4 Through the Site, judicial data is not processed.
Art. 2 Communication of Personal Data
The Data Controller may communicate your personal data to specific categories of subjects. Below are the subjects to whom the Data Controller reserves the right to communicate your data:
- The Data Controller may communicate your personal data to all those subjects (including Public Authorities) who have access to personal data based on regulatory or administrative provisions.
- Your personal data may also be communicated to all public and/or private subjects, individuals and/or legal entities (legal, administrative, and tax consultancy firms, Judicial Offices, Chambers of Commerce, Labor Chambers and Offices, etc.), when the communication is necessary or functional to the correct fulfillment of legal obligations.
- The Data Controller makes use of employees and/or collaborators in any capacity. For the correct functioning of the Site, the Data Controller may communicate your personal data to these employees and/or collaborators.
- In its ordinary management activities of the Site, the Data Controller employs companies, consultants, or professionals tasked with the installation, maintenance, updating, and, in general, management of the hardware and software of the Data Controller or that the latter uses for the provision of its services. Therefore, only for these purposes, your data may also be processed by these subjects.
- For sending its communications, the Data Controller uses external companies responsible for sending this type of communications (CRM platforms). Your personal data (particularly email) may therefore be communicated to these companies.
- The Data Controller does not use external companies to provide customer care services.
- The Data Controller employs banking institutions and companies that manage national and international payment circuits for online payments of products and services purchased through the Site.
- The personal data of the purchaser may be communicated to postal offices, couriers, or shippers responsible for delivering the Products purchased through the Site.
The Data Controller reserves the right to modify the above-mentioned list based on its ordinary operations. Therefore, you are invited to regularly access this notice to check to which subjects the Data Controller communicates your personal data.
Art. 3 Storage of Personal Data
3.1 This article describes how long the Data Controller reserves the right to keep your personal data.
- For marketing purposes, personal data will be retained until consent is revoked. For inactive users, personal data will be deleted after one year from the sending of the last email possibly viewed.
- For the purpose of executing the sales contract, data will be retained for 10 years from the date of receipt of the purchase order. This allows the Data Controller to exercise its right of defense and to demonstrate that it has correctly executed the contract.
- Through the Site (or by requesting the Data Controller), it is possible to delete the user account. In this case, all stored personal data will be deleted and will not be retained by the Data Controller for any purpose.
3.2 Without prejudice to the provisions of article 3.1, the Data Controller may retain your personal data for the time required by specific regulations, as modified from time to time.
Art. 4 Transfer of Personal Data
4.1 The Data Controller is based in a country that presents an adequate level of security from a regulatory point of view. If the transfer of your personal data takes place in a non-EU country for which the European Commission has expressed an adequacy judgment, the transfer is considered safe from a regulatory point of view in any case. This article 4.1 indicates from time to time the countries to which your personal data may be transferred and where the European Commission has expressed an adequacy judgment.
- Therefore, users are invited to regularly access this article to verify if the transfer of their personal data occurs in a country with these characteristics.
4.2 Without prejudice to what is indicated in article 4.1, your data may also be transferred to non-EU countries for which the European Commission has not expressed an adequacy judgment. You are therefore invited to regularly review this article 4.2 to ascertain in which of these countries your data may be transferred.
4.3 In this article, the Data Controller indicates the countries to which it may specifically direct its activity. This circumstance may imply the application of the legislation of the country of reference, in addition to the legislation governing the relationship with the user based on what is indicated in the Premise.
- At the user's request, the Data Controller will apply the potentially more favorable data protection legislation provided by the national legislation of the user.
Art. 5. Rights of the Data Subject
The Data Controller informs you that you have the right to:
- request the Data Controller access to your personal data and the correction or deletion of the same or the limitation of processing concerning you or to object to their processing, as well as the right to data portability
- revoke consent at any time without affecting the lawfulness of the processing based on the consent granted before the revocation
- lodge a complaint with a supervisory authority.
The above rights can be exercised by requesting without formalities the contacts indicated in the Premise.
Art. 6. Amendments and Miscellaneous
The Data Controller reserves the right to make changes to this notice at any time, providing adequate publicity to the users of the Site and ensuring, in any case, an adequate and similar protection of personal data. In order to view any changes, you are invited to regularly consult this notice. In the event of substantial changes to this privacy notice, the Data Controller may also communicate this via email.