WHY THIS NOTICE
In this page we describe how to manage the website in relation to the processing of personal data of the users who visit it. This is a privacy policy statement provided pursuant to articles 13 and 14 of EU Regulation No. 679/2016, also known by the acronym GDPR (i.e. General Data Protection Regulation), concerning the protection of natural persons with regard to the processing and free flow of personal data, as well as to the regulations for adaptation to those who interact with the website of the data controller MPWEB Srl, accessible electronically from the address http://sognidicristallo.it, which corresponds to the home page of the official e-commerce website of the data controller.
This privacy policy statement is provided only for the website of the data controller and not for other websites that may be possibly visited by the user through links.
The privacy policy is also inspired by Recommendation No. 2/2001 that the European authorities for the protection of personal data, gathered in the Group established in accordance with art. 29 of Directive No. 95/46/EC, adopted on 17th May 2001 with the aim of identifying certain minimum requirements for the collection of personal data online and, in particular, the methods, timing and nature of the information that data controllers are required to provide to the users when the latter access web pages, regardless of the purpose of the access.
THE DATA CONTROLLER
The data controller is MPWEB S.r.l., Tax ID No. and VAT ID No. 04146240272, acting through its pro tempore legal representative, based in Dolo (VE), Via Serraglio No. 30/A, who also assumes the role of data supervisor.
DATA PROCESSING PLACE
The processing connected to the web services of this website takes place at the company's operating office, located in Italy, Mirano (VE), Via Castellantico No. 17, and are only handled by the office staff in charge of the processing. The electronic data referred to in the following point "TYPES OF DATA PROCESSED" are instead stored at the hosting server provider OVH SAS (OVH S.r.l, based in Via Leopoldo Cicognara, 7 - 20129, Milan). The data related to profiling are collected and processed by third parties, specifically by Google LLC, Facebook Ltd, also as regards Instagram, as well as Ad Spray S.r.l. The electronic data relating to the newsletter are kept by Mailchimp - The Rocket Science Group LLC and by Ad Spray S.r.l.
TYPES OF DATA PROCESSED
Navigation data
The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected to be associated with identified interested parties, but which - by their very nature - could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of the computers used by users when connecting to the website, the addresses in the URI (Uniform Resource Identifier) notation of the requested resources, the time of the request, the method used to submit the request to the server (successful conclusion, error, etc. ...) and other parameters related to the user's operating system and computer environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the website and checking the correct functioning of the latter, and are deleted immediately after processing. The data could be used to ascertain responsibility in the event of any hypothetical computer crimes committed against the website.
Moreover, user data are indirectly collected by third parties, through Hotjar (provided by HOTJAR Ltd), Ad Spray S.r.l., as well as by Google LLC and Zender, either for statistical purposes or for the use of the website and its qualitative and quantitative performance (see “PURPOSE OF THE PROCESSING”).
Data provided voluntarily by the user
The optional, explicit and voluntary sending of electronic mail to the addresses indicated on this website, or the entering by the user of the data in the contact form, for the purpose of purchase, involves the subsequent acquisition of such data, required to respond to requests, process them and allow the purchase and shipping of the products. We collect or obtain directly from the user/customer the name, surname, address, e-mail address, telephone number, company name – if any - and VAT ID number, purchase data, such as order number, details regarding the goods purchased, data on the method of payment, communications and messages in relation to purchases (e.g. withdrawal statements, complaints and communications to the customer service), supply and payment status, return status and data on third-party service providers involved in the performance of the contract (which, in case of mail order sales, could be the courier service delivery number), as well as payment details, such as IBAN and BIC, or account number and bank code, as well as credit card or PayPal service details. The user can also provide his e-mail, name, surname and any other personal data in a chat. Specific summary statements and collections of the related consent will be progressively provided or displayed on the website pages for particular services. These data are stored indefinitely in the data controller’s databases.
Cookie Policy
For information on the cookies used on the company’s portal http://sognidicristallo.com, please refer to the specific Cookie Policy through the link.
PURPOSE OF THE PROCESSING
Processing is aimed at the request for contact from the user who accesses the website, to send the purchased products and/or send commercial communications, invoicing documents or informative reports or, mainly, to keep compliance of the purchase contract concluded. Moreover, the data provided are used for the purpose of users’ behavioural analysis as well as for their profiling through, and only through, the services provided by third parties (go to next paragraph “DATA COMMUNICATION”).
METHODS OF PROCESSING OF PERSONAL DATA
The processing is carried out through operations executed with the aid of electronic tools and consists of the collection, registration, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blockage, communication, cancellation and destruction of data. The processing is performed by the data controller and the persons in charge of the processing expressly authorized by the data controller for the time strictly necessary to achieve the purposes for which they were collected. Specific security measures are observed to prevent data loss, illicit or incorrect use and unauthorized access.
DATA COMMUNICATION
The data being processed may be known by the data controller and persons in charge of the processing and may be communicated to internal or external collaborators, such as accounting, logistic and technical companies, payment service providers, warehouses, packaging and order shipping companies.
Part of the navigation data referred to above can be partially processed on the systems of the Google LLC provider (currently Google Analytics, Google Conversion Tracking, Google Adwords, Google Remarketing), Zendesk Inc, which, however, declare to use systems that offer guarantees of adequacy with respect to the GDPR Regulation and to the legislation concerning the protection of personal data. Finally, the data can be communicated in case of request to the competent authorities to fulfil the obligations arising from mandatory legal provisions.
DATA SUBJECT’S RIGHTS
The data subject has the right to:
- access, correct, cancel, limit and oppose the processing of data;
- obtain data from the data controller without any impediments in a structured format of common use and readable by an automatic device to transmit them to another data controller;
- revoke the consent to the processing, without prejudice to the lawfulness of the processing based on the consent acquired before the revocation;
- propose a complaint to the Data Protection Authority responsible for the protection of personal data .
In the event that you decide to exercise the aforementioned rights, you need to send a prior notification:
by e-mail at info@sognidicristallo.it
by registered letter with return receipt to the address: MPWEB S.r.l., Via Castellantico 17 - 30035 Mirano, Venice.
P3P
The complete privacy policy referred to in this statement is available for automatic consultation with the most recent browsers implementing the P3P standard P3P (“Platform for Privacy Preferences Project”) proposed by the World Wide Web Consortium (www.w3c.org). Every effort will be made in order to make the functions of this website as interoperable as possible with the automatic privacy control mechanisms available in some products used by users. Considering that the improvement status of the automatic control mechanisms does not make them free from errors and malfunctions, it should be noted that this document, published at enter link to the page constitutes a “Privacy Policy”, which will be subject to updating. The current version was prepared in May 2018.
COOKIES POLICY
Collection and processing of personal data
We provide below a list of the specific purposes and methods of processing for which the Customers’ personal data are intended.
a. Purchase order: Sognidicristallo collects and processes the Customer’s personal data for the collection and dispatch of purchase orders, for any complaints subsequent to the purchase and to provide the Customer with the available services. These data are necessary for the management of purchase orders, also with commercial partners (i.e. suppliers of logistics services, couriers, banks, etc.).
It is advisable to enter a delivery address and a correct telephone number to place a purchase order and allow Sognidicristallo to proceed with its prompt and correct execution. A telephone number is also necessary in order to allow Sognidicristallo to contact the Customer for any questions or requests for clarification and to allow the commercial partners of Sognidicristallo to proceed with the prompt and correct execution of the purchase orders placed by the Customer. Also, the e-mail address is needed by Sognidicristalllo in order to be able to communicate to the Customer the confirmation of receipt of the purchase order and for any other communications. Finally, the e-mail address is used at the time of the Customer’s identification to allow him to access his account.
b. Restricted Area - Customer's Login: the Customer's personal data and those regarding his purchase orders are saved in the system of Sognidicristallo, but they will not be freely accessible for security reasons. Sognidicristallo guarantees each customer access to a restricted area by means of a protected password. In said area, the Customer can view all the data concerning the purchase orders dispatched and those in progress and can also manage his personal data, any bank details and those related to the subscription to the newsletter service. The Customer is required to treat the access data in a responsible manner and in compliance with the regulations in force, without disclosing them to any third parties. Sognidicristallo will not be in any way responsible for any incorrect or improper use of the password by the Customer.
c. Advertising: Sognidicristalllo may use the Customer's data for promotional purposes, to send information on the items offered on the website www.sognidicristallo.com. The Customer's e-mail address will only be used within the limits prescribed by the applicable law or, when necessary, after the express consent of the Customer. The Customer will receive promotional e-mails on a regular basis. It is possible to interrupt the sending of the above-said promotional messages free of charge, by sending an e-mail request to info@sognidicristallo.it or by calling on 3921805153 or, alternatively, by clicking on the option "unsubscribe from the newsletter" available in each promotional e-mail.
d. Market research and public opinion surveys: the Customer’s personal data are also processed with the aim of conducting market research and public opinion surveys. Their use is takes place anonymously and exclusively with the purpose of compiling statistics for Sognidicristallo. The Customer has the right to object to the processing at any time. The answers provided by the Customer in the framework of such market research and opinion surveys are neither disclosed to third parties nor made public in any way. The answers to our survey questions are not stored together with the corresponding e-mail address.
e. Subscription to the newsletter: in the newsletters, the Customer will find information about advantageous offers from time to time. Sognidicristallo invites the Customer to enter personal data (for example, his name) in the newsletter settings as well, so as to allow Sognidicristallo to personally contact the Customer. Of course, the Customer may contact Sognidicristallo also anonymously or using a nickname (for example, through a free e-mail address that does not reveal his name). Sognidicristallo processes the data collected as part of the newsletter service in order to customize and adapt the services to the Customer’s interests and preferences, as well as for promotional purposes and market studies. Sognidicristallo archives the data collected for long periods of time, it being understood that such data will in any case be used solely for the purposes referred to in this privacy statement.
f. Consultation of websites and newsletters: when the Customer visits the website www.sognidicristallo.com, even accessing it from a link included in a newsletter, some data are collected and stored. The domain name or IP address of the access computer is temporarily saved for security reasons and deleted after a maximum of 7 (seven) days. Other data may also be saved, such as the access date, the http response code and the website from which the re-addressing to the website www.sognidicristallo.com took place as well as the amount of data (bytes) that were transmitted. The analysis of the data takes place only in a strictly anonymous form.
1.2 Saving personal data through cookies
It is not necessary to accept the use of cookies while browsing the website www.sognidicristallo.com. The website www.sognidicristallo.com uses cookies. Cookies are text files recorded on a computer support that allow recording certain parameters and data communicated to the computer system of Sognidicristallo through the browser used by the Customer, thus making it possible to analyze his habits in the use of a specific website. This saving allows Sognidicristallo to adapt its websites to the Customer’s needs in addition to facilitating their use (for example, by memorizing some requests, it is not necessary to enter them at each visit). Many of the cookies used are automatically deleted from the hard drive of the Customer’s computer at the end of each browsing session (whence the name "session cookies"). On the contrary, there are cookies that remain stored on your hard drive. Their permanence is quite long (a few years) for reasons of greater practicality.
Once the website has been visited for the first time, the system will be able to recognize at each subsequent visit that the Customer already visited that website before and will therefore retrieve the Customer’s requests and preferred data (long-lasting cookies). These cookies will make it possible for the Customer to avoid being obliged to re-enter his password and fill in forms upon each new access. Browsers generally limit the use of cookies, although the latter allow accessing more freely to the offers available on the website www.sognidicristallo.com. Cookies can also be deactivated. The website www.sognidicristallo.com uses the service "Google Analytics", a service of the company Google Inc. ("Google"). Google makes use of cookies. The information obtained through cookies on the Customer's habits in using websites (including the IP address) are transferred to a Google server located in the United States, where they are stored. Google complies with the data protection provisions set out in the 'Safe Harbor Principles' and participates in the 'Safe Harbor' programme of the US Department of Commerce. Google uses this information in order to analyze the use habits of the website by the Customer, provide Sogni di Cristallo with reports on visits to the website www.sognidicristallo.com and for other communications regarding the use of this website as well as, more generally, of the Internet. Google transmits this information to third parties whenever it is so provided for by law or in the event that third parties process such data at the order and on behalf of Google. In no event will Google put the Customer's IP address in connection with other Google data. The Customer can refuse the installation of cookies by selecting the corresponding parameters in the specific browser options. It should be noted, however, that in this way the Customer cannot take full advantage of some features of the website. Through the use of this website, the Customer agrees to the processing of data collected by Google in the manner and for the purposes described above.
The Customer allows the registration of the username and password in cookies after the logging off from the browsing session and their activation at the time of the next visit. The Customer can revoke this authorization at any time, with effects on the future, by selecting the specific browser parameters that allow you to exclude the activation of cookies, according to the following steps.
Mozilla Firefox:
1. Select "Tools" menu, then "Options"
2. Click on "Privacy"
Microsoft Internet Explorer:
1. Select "Tools", then " Internet Options"
2. Click on "Privacy" (or "Confidentiality")
3. Choose the desired privacy level using the slider.
Chrome:
1. "Tools", then "Settings"
2. Click on "Show advances settings"
3. In the "Privacy" section, click on "Content Settings".
Opera:
1. Select "File", then "Preferences"
2. Click on "Privacy".
1.3 Secure transfer of personal data. The Customer's personal data are transferred in encrypted form. This applies to both the placement of purchase orders and the Customer’s restricted access to his account.). Although it is not possible to guarantee absolute protection, Sognidicristallo has taken security measures for its systems against any loss, destruction, access, modification or disclosure of customer data by unauthorized third parties.