WHY THIS NOTICE
THE DATA CONTROLLER
The data controller is MPWEB S.r.l., Tax ID No. and VAT ID No. 04146240272, acting through its pro tempore legal representative, based in Dolo (VE), Via Serraglio No. 30/A, who also assumes the role of data supervisor.
DATA PROCESSING PLACE
The processing connected to the web services of this website takes place at the company's operating office, located in Italy, Mirano (VE), Via Castellantico No. 17, and are only handled by the office staff in charge of the processing. The electronic data referred to in the following point "TYPES OF DATA PROCESSED" are instead stored at the hosting server provider OVH SAS (OVH S.r.l, based in Via Leopoldo Cicognara, 7 - 20129, Milan). The data related to profiling are collected and processed by third parties, specifically by Google LLC, Facebook Ltd, also as regards Instagram, as well as Ad Spray S.r.l. The electronic data relating to the newsletter are kept by Mailchimp - The Rocket Science Group LLC and by Ad Spray S.r.l.
TYPES OF DATA PROCESSED
The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected to be associated with identified interested parties, but which - by their very nature - could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of the computers used by users when connecting to the website, the addresses in the URI (Uniform Resource Identifier) notation of the requested resources, the time of the request, the method used to submit the request to the server (successful conclusion, error, etc. ...) and other parameters related to the user's operating system and computer environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the website and checking the correct functioning of the latter, and are deleted immediately after processing. The data could be used to ascertain responsibility in the event of any hypothetical computer crimes committed against the website.
Moreover, user data are indirectly collected by third parties, through Hotjar (provided by HOTJAR Ltd), Ad Spray S.r.l., as well as by Google LLC and Zender, either for statistical purposes or for the use of the website and its qualitative and quantitative performance (see “PURPOSE OF THE PROCESSING”).
Data provided voluntarily by the user
The optional, explicit and voluntary sending of electronic mail to the addresses indicated on this website, or the entering by the user of the data in the contact form, for the purpose of purchase, involves the subsequent acquisition of such data, required to respond to requests, process them and allow the purchase and shipping of the products. We collect or obtain directly from the user/customer the name, surname, address, e-mail address, telephone number, company name – if any - and VAT ID number, purchase data, such as order number, details regarding the goods purchased, data on the method of payment, communications and messages in relation to purchases (e.g. withdrawal statements, complaints and communications to the customer service), supply and payment status, return status and data on third-party service providers involved in the performance of the contract (which, in case of mail order sales, could be the courier service delivery number), as well as payment details, such as IBAN and BIC, or account number and bank code, as well as credit card or PayPal service details. The user can also provide his e-mail, name, surname and any other personal data in a chat. Specific summary statements and collections of the related consent will be progressively provided or displayed on the website pages for particular services. These data are stored indefinitely in the data controller’s databases.
PURPOSE OF THE PROCESSING
Processing is aimed at the request for contact from the user who accesses the website, to send the purchased products and/or send commercial communications, invoicing documents or informative reports or, mainly, to keep compliance of the purchase contract concluded. Moreover, the data provided are used for the purpose of users’ behavioural analysis as well as for their profiling through, and only through, the services provided by third parties (go to next paragraph “DATA COMMUNICATION”).
METHODS OF PROCESSING OF PERSONAL DATA
The processing is carried out through operations executed with the aid of electronic tools and consists of the collection, registration, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blockage, communication, cancellation and destruction of data. The processing is performed by the data controller and the persons in charge of the processing expressly authorized by the data controller for the time strictly necessary to achieve the purposes for which they were collected. Specific security measures are observed to prevent data loss, illicit or incorrect use and unauthorized access.
The data being processed may be known by the data controller and persons in charge of the processing and may be communicated to internal or external collaborators, such as accounting, logistic and technical companies, payment service providers, warehouses, packaging and order shipping companies.
Part of the navigation data referred to above can be partially processed on the systems of the Google LLC provider (currently Google Analytics, Google Conversion Tracking, Google Adwords, Google Remarketing), Zendesk Inc, which, however, declare to use systems that offer guarantees of adequacy with respect to the GDPR Regulation and to the legislation concerning the protection of personal data. Finally, the data can be communicated in case of request to the competent authorities to fulfil the obligations arising from mandatory legal provisions.
DATA SUBJECT’S RIGHTS
The data subject has the right to:
- access, correct, cancel, limit and oppose the processing of data;
- obtain data from the data controller without any impediments in a structured format of common use and readable by an automatic device to transmit them to another data controller;
- revoke the consent to the processing, without prejudice to the lawfulness of the processing based on the consent acquired before the revocation;
- propose a complaint to the Data Protection Authority responsible for the protection of personal data .
In the event that you decide to exercise the aforementioned rights, you need to send a prior notification:
by e-mail at firstname.lastname@example.org
Collection and processing of personal data
We provide below a list of the specific purposes and methods of processing for which the Customers’ personal data are intended.
a. Purchase order: Sognidicristallo collects and processes the Customer’s personal data for the collection and dispatch of purchase orders, for any complaints subsequent to the purchase and to provide the Customer with the available services. These data are necessary for the management of purchase orders, also with commercial partners (i.e. suppliers of logistics services, couriers, banks, etc.).
It is advisable to enter a delivery address and a correct telephone number to place a purchase order and allow Sognidicristallo to proceed with its prompt and correct execution. A telephone number is also necessary in order to allow Sognidicristallo to contact the Customer for any questions or requests for clarification and to allow the commercial partners of Sognidicristallo to proceed with the prompt and correct execution of the purchase orders placed by the Customer. Also, the e-mail address is needed by Sognidicristalllo in order to be able to communicate to the Customer the confirmation of receipt of the purchase order and for any other communications. Finally, the e-mail address is used at the time of the Customer’s identification to allow him to access his account.
b. Restricted Area - Customer's Login: the Customer's personal data and those regarding his purchase orders are saved in the system of Sognidicristallo, but they will not be freely accessible for security reasons. Sognidicristallo guarantees each customer access to a restricted area by means of a protected password. In said area, the Customer can view all the data concerning the purchase orders dispatched and those in progress and can also manage his personal data, any bank details and those related to the subscription to the newsletter service. The Customer is required to treat the access data in a responsible manner and in compliance with the regulations in force, without disclosing them to any third parties. Sognidicristallo will not be in any way responsible for any incorrect or improper use of the password by the Customer.
c. Advertising: Sognidicristalllo may use the Customer's data for promotional purposes, to send information on the items offered on the website www.sognidicristallo.com. The Customer's e-mail address will only be used within the limits prescribed by the applicable law or, when necessary, after the express consent of the Customer. The Customer will receive promotional e-mails on a regular basis. It is possible to interrupt the sending of the above-said promotional messages free of charge, by sending an e-mail request to email@example.com or by calling on 3921805153 or, alternatively, by clicking on the option "unsubscribe from the newsletter" available in each promotional e-mail.
d. Market research and public opinion surveys: the Customer’s personal data are also processed with the aim of conducting market research and public opinion surveys. Their use is takes place anonymously and exclusively with the purpose of compiling statistics for Sognidicristallo. The Customer has the right to object to the processing at any time. The answers provided by the Customer in the framework of such market research and opinion surveys are neither disclosed to third parties nor made public in any way. The answers to our survey questions are not stored together with the corresponding e-mail address.
e. Subscription to the newsletter: in the newsletters, the Customer will find information about advantageous offers from time to time. Sognidicristallo invites the Customer to enter personal data (for example, his name) in the newsletter settings as well, so as to allow Sognidicristallo to personally contact the Customer. Of course, the Customer may contact Sognidicristallo also anonymously or using a nickname (for example, through a free e-mail address that does not reveal his name). Sognidicristallo processes the data collected as part of the newsletter service in order to customize and adapt the services to the Customer’s interests and preferences, as well as for promotional purposes and market studies. Sognidicristallo archives the data collected for long periods of time, it being understood that such data will in any case be used solely for the purposes referred to in this privacy statement.
f. Consultation of websites and newsletters: when the Customer visits the website www.sognidicristallo.com, even accessing it from a link included in a newsletter, some data are collected and stored. The domain name or IP address of the access computer is temporarily saved for security reasons and deleted after a maximum of 7 (seven) days. Other data may also be saved, such as the access date, the http response code and the website from which the re-addressing to the website www.sognidicristallo.com took place as well as the amount of data (bytes) that were transmitted. The analysis of the data takes place only in a strictly anonymous form.
1.2 Saving personal data through cookies
The Customer allows the registration of the username and password in cookies after the logging off from the browsing session and their activation at the time of the next visit. The Customer can revoke this authorization at any time, with effects on the future, by selecting the specific browser parameters that allow you to exclude the activation of cookies, according to the following steps.
1. Select "Tools" menu, then "Options"
2. Click on "Privacy"
Microsoft Internet Explorer:
1. Select "Tools", then " Internet Options"
2. Click on "Privacy" (or "Confidentiality")
3. Choose the desired privacy level using the slider.
1. "Tools", then "Settings"
2. Click on "Show advances settings"
3. In the "Privacy" section, click on "Content Settings".
1. Select "File", then "Preferences"
2. Click on "Privacy".
1.3 Secure transfer of personal data. The Customer's personal data are transferred in encrypted form. This applies to both the placement of purchase orders and the Customer’s restricted access to his account.). Although it is not possible to guarantee absolute protection, Sognidicristallo has taken security measures for its systems against any loss, destruction, access, modification or disclosure of customer data by unauthorized third parties.