PRIVACY POLICY AND COOKIE POLICY
This policy sets out the procedures followed by
Andrea Decandia (hereinafter the “Data Controller”) in relation to the processing of personal data collected via the website https://www.nuovaluxuryolbia.it (hereinafter the “Website”).
Unless otherwise specified, this policy also serves as a privacy notice – pursuant to Article 13 of Legislative Decree No. 196/2003 (hereinafter the “Code”) and Article 13 of Regulation (EU) No. 2016/679 (hereinafter the “GDPR”) – provided to those who interact with the Website (hereinafter the ’User“).
Detailed privacy notices regarding the processing of personal data are provided, where necessary, on the pages relating to the individual services offered via the Website. These notices are intended to set out the limits and methods of personal data processing for each service, on the basis of which the user may freely give their consent, where necessary, and, where applicable, authorise the collection of data and its subsequent processing.
Data controller. Data processors.
The Data Controller is Andrea Decandia, with its registered office at Via Nuova, 5 07026 Olbia (SS), tel. +393470112321, email nuovasrls5@gmail.com . The up-to-date list of any data processors is available at the Data Controller’s registered office.
Data Protection Officer.
The Data Protection Officer, appointed by the Data Controller, can be contacted via:
– by post, to the following address: [postal address, for the attention of the Data Protection Officer];
– by telephone, on the number +393470112321;
– by email, to the address nuovasrls5@gmail.com
Types of data processed.
The following data may be collected and processed via the Website:
– browsing data;
– personal data provided voluntarily by the user via the forms on the Website.
Cookies.
Cookies are small text files that the websites you visit send to your device, where they are stored, and are then sent back to those same websites the next time you visit them.
The Website uses technical cookies, both first-party and third-party. As these cookies are technical in nature, they do not require the User’s prior consent to be installed and used.
Specifically, the cookies used on the Website fall into the following sub-categories:
– navigation or session cookies, which ensure that the Websites can be browsed and used normally. As they are not stored on the user’s computer, they are deleted when the browser is closed;
– analytics cookies, which are used to collect and analyse statistical information on the number of users and visits to the websites;
– social media widgets and plugins: some widgets and plugins provided by social media platforms may use their own cookies to facilitate interaction with the relevant website.
Listed below are the third-party cookies installed on the Website. For each one, a link is provided to the relevant privacy policy setting out the processing of personal data and how to disable the cookies used, if required. With regard to third-party cookies, the Data Controller is only obliged to include in this policy a link to the third party’s website. It is, however, the responsibility of that third party to provide the relevant information and to specify how users may give their consent to, and/or disable, the cookies.
– Google Analytics:
Further information is available at https://www.google.com/intl/it_ALL/analytics/learn/privacy.html
Opt out at
https://tools.google.com/dlpage/gaoptout/
Cookies can be disabled by the user by changing their browser settings in accordance with the
instructions provided by the relevant suppliers via the links listed below.
– Internet Explorer: http://windows.microsoft.com/it-IT/internet-explorer/delete-manage-cookies#ie=ie-11
– Mozilla Firefox: https://support.mozilla.org/it/kb/Attivare%20e%20disattivare%20i%20cookie
– Google Chrome: https://support.google.com/chrome/answer/95647-hl=it
– Apple Safari: https://support.apple.com/it-it/HT201265
– Opera: http://www.opera.com/help/tutorials/security/cookies/
Purpose and legal basis of the processing.
Personal data collected via the Website will be processed for the purpose of handling requests for information or documents submitted by the User.
The processing of personal data for the above purpose does not require the User’s consent, as the processing is necessary to fulfil specific requests made by the data subject pursuant to Article 24(1)(a).
(b) of the Code and Article 6(1)(b) of the GDPR.
Provision of data and consequences of failure to provide such data.
The provision of personal data for the above purpose is optional, and the sole consequence of failing to provide such data will be that the Data Controller will be unable to manage and process the data subject’s requests.
Methods of processing. Personal data will be processed using electronic means, including by entering and organising it in databases, in accordance with the provisions of the Code and the GDPR regarding security measures.
Recipients or categories of recipients.
Personal data may be made available to, brought to the attention of or disclosed to the following parties, who will be appointed, as appropriate, as data processors or persons authorised to process data:
– companies within the group to which the Data Controller belongs (parent companies, subsidiaries, associated companies), and employees and/or contractors of the Data Controller in any capacity; ;
– public or private entities, whether natural or legal persons, which the Data Controller engages to carry out activities necessary to achieve the aforementioned purpose, or to which the Data Controller is required to disclose personal data pursuant to legal or contractual obligations.
In any event, personal data will not be disclosed.
Shelf life.
Personal data will be retained for one year from the date of registration.
Rights of access, erasure, restriction and data portability.
Data subjects are entitled to the rights set out in Article 7 of the Code and Articles 15 to 20 of the GDPR. By way of example, each data subject may:
(a) to obtain confirmation as to whether or not personal data concerning him or her are being processed;
(b) where processing is taking place, to obtain access to personal data and information relating to the processing, and to request a copy of the personal data;
(c) to have inaccurate personal data rectified and incomplete personal data completed;
(d) to have personal data concerning him or her erased, where one of the conditions set out in Article 17 of the GDPR applies;
(e) to obtain, in the cases provided for in Article 18 of the GDPR, the restriction of processing;
(f) to receive personal data concerning them in a structured, commonly used and machine-readable format, and to request that such data be transmitted to another data controller, where technically feasible.
Right to object.
Every data subject has the right to object at any time to the processing of their personal data carried out in pursuit of a legitimate interest of the Data Controller. In the event of such an objection, your personal data will no longer be processed, unless there are legitimate grounds for processing that override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
Right to lodge a complaint with the Data Protection Authority.
Furthermore, any data subject may lodge a complaint with the Data Protection Authority if they consider that their rights under the Code and the GDPR have been infringed, in accordance with the procedures
as set out on the Data Protection Authority’s website, available at: www.garanteprivacy.it.
Updates. This Privacy Policy is subject to updates. The Data Controller therefore invites Users who wish to find out how personal data collected via the Websites is processed to visit this page from time to time.