Version: 2 - Policy date: 15/10/2018
Disclaimer for WEB SITE
art. 13-14 of EU Reg. 2016/679
The disclaimer is a general obligation that must be fulfilled before or at the latest when initiating the direct collection of personal data. In the case of personal data not collected directly from the interested party, the information must be provided within a reasonable time, or at the time of communication (not registration) of the data (to third parties or to the interested party). Pursuant to the General Regulations for the Protection of Personal Data of Individuals (GDPR - Reg. (EU) 2016/679), the undersigned organization, data controller, informs of the following:
SOURCES AND CATEGORIES OF PERSONAL DATA
The personal data held by the undersigned organization are collected directly from the interested parties.
The computer systems and software procedures used to operate the website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified interested parties, but which by their very nature could, through processing and association with data held by third parties, allow to identify users. This category of data includes IP addresses or domain names of the computers used by users connecting to the site, the addresses in the Uniform Resource Identifier (URI) notation of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (success, error, etc.) and other parameters relating to the operating system and the user's computer environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the site and to check its correct functioning and are deleted immediately after processing. The data could be used to ascertain responsibility in case of hypothetical computer crimes against the site.
Profiling data are directly acquired regarding the user's habits or consumption choices. It is also possible that through links, or by incorporating third-party elements, such information is acquired from autonomous or separate subjects. See the section of third-party cookies in this regard.
As others, this website saves cookies on the browser used by the user concerned for the transmission of personal information and to enhance the experience. In fact, cookies are small text strings that the sites visited by the user send to his terminal (usually to the browser), where they are stored, sometimes even with features of wide temporal persistence, to be then retransmitted to the same sites at the next visit. As explained below, it is possible to choose which and which cookies to accept, bearing in mind that refusing their use may affect the ability to perform certain transactions on the site or the accuracy and adequacy of some customizable content proposed or the ability to recognize the user from a visit to the next one. If no choice is made in this regard, default settings will be applied and all cookies will be activated: however, at any time, you can communicate or change the decisions in this regard.
In particular, so-called session cookies are used, which are not stored permanently on the user's computer and disappear when the browser is closed and whose use is strictly limited to the transmission of session identifiers (consisting of random numbers generated by the server) necessary for the safe and efficient exploration of the site. Session cookies avoid the use of other technologies that could compromise the privacy of users' browsing and do not allow the acquisition of personal identification data. Also analytics cookies are used, that help to understand how visitors interact with the contents of the site, collecting information (geographic and web origin, technology used, language, pages of entry, visit, exit, time spent, etc.) and generating website usage statistics without personal identification of individual visitors. All these are to be considered technical cookies, for which, as it is not necessary to give consent, the opt-out mechanism is in force. Technical cookies are not disclosed to third parties as necessary or useful for the operation of the site; therefore, they are processed only by qualified persons, as persons in charge, data processors or system administrators.
Third- party cookies
Finally, the site incorporates cookies and other elements (tags, pixels, etc.) of third parties (autonomous and on which the owner has no responsibility) that also perform profiling activities and for which you refer to the cookies disclaimer page.
Data provided voluntarily by users
The optional, explicit and voluntary sending of electronic mail to the addresses indicated on the site entails the subsequent acquisition of the sender's address, necessary to respond to requests, as well as any other personal data included in the email. Even the explicit and voluntary sending of the forms that can be filled in on the website containing the data of the subject entails their processing in order to comply with the pre-contractual obligations or the execution of the services expected by sending the forms. Such information in the forms may concern personal data, contact details, telephone numbers, e-mail addresses of the interested parties and identified and identifiable third parties assignee with the user of the site. However, specific summary information will be progressively reported or displayed on the pages of the site prepared for particular services on request.
Newsletter and Mailing-list
The e-mail contacts used to send communications from the site come from voluntary registration by the recipient to whom a confirmation request is always submitted, as well as information obtained in a context of sale of products or services of the owner or otherwise similar. This includes the sending of information, promotional communications and material. It is emphasized that contacts are not acquired by public subscriber directories. In the event that communications are not of interest to the recipient, it is possible to avoid any further contact by clicking the appropriate link contained in each message, or by writing to the addresses at the bottom, exercising their right to be cancelled from the newsletter.
Work with us
It is possible to send your candidacy for a work position sending your data and your CV updated inclusive of authorization to the processing of sensitive data.
The payment system expected the comunication ofsome data to the supplier of payment service (paypal). The required data are freely provided by the person: some of them ( name, surname, e-mail) are necessary; the others are optional (note, causal, etc).
It's about the data processed for the manegment of carts, orders. eventual profile of registred user and they include personal date, adresses, purchase lists, reportings and notes.
The personal data provided through the third delegates (society for the home delivery, for the mailing and for the data entry) for the administrative managment of the orders and of the purchases as well; the managment of eventual attendances to loyalty programs; the elaboration of anonymous statistics to the survey of action of puchase; sending of advertising material related to protucts and offerts through eventually by mail or phone messages.
The informations (text, video, images) that the user loads on the reserved area are protectid by encryption sistem and authentication and are accessible to only to authorized users.
Such information are not object to diffusion operations.
PURPOSES AND LEGAL BASIS OF TREATMENT
Personal data are used (ref. Artt.6 (b) of the GDPR):
a) to allow navigation on the site and
b) possibly to perform the service or provision requested in the normal activity performed by OMPS2 SRL
Furthermore, all personal data can be processed:
c) for purposes related to obligations under the law, as well as provisions issued by authorities legitimated by the law (see articles 6 (c) and 9 (b, g, h) of the GDPR);
d) for the assessment, exercise or defense of a right in court and out-of-court (legitimate interest) of the undersigned organization (see articles 6 (f) and 9 (f) of the GDPR);
e) for direct marketing purposes according to the legitimate interest of the owner; in particular: about cookies, for advertising ids used to display advertisements and ads; about e-mail addresses, for sending the newsletter; about navigation and usage logs, for protecting site and service from cyber-attacks; in these cases the interested party can always refuse consent so that the Data Controller will abstain from processing (see Article 6 (f) of the GDPR);
f) for purposes that are functional to the activity, for which the interested party has the right to express or not the consent, such as for example subscription to the newsletter in order to receive informational, promotional and commercial messages about products and services; satisfaction surveys, communication of data to third parties for receiving information, promotional and marketing communications (GDPR art.6 (a));
g) with the consent of the interested party, by profiling the subject himself (ref. art.6 (a) of the GDPR).
The signing up to the newsletter appens only by prepared form on Mailchimp site. the form of signing up is achivable by the button in the end of the page "subscribe to uor newsletter".
CONSEQUENCES OF THE REFUSAL OF CONFERRING THE DATA
The provision of data collected from the interested party is optional but essential in order to process them for the purposes in letters a) and b). In the event that the parties do not communicate their necessary data and do not allow the processing, it will not be possible to carry out and put in place the proposed services and to follow the contractual obligations undertaken, with a consequent prejudice for the correct fulfillment of regulatory obligations, such as accounting, tax, administrative, etc.
Apart from that specified for navigation data, the user is free to provide personal data for cookies and specific requests via forms, for example on products and/or services. Failure to provide such data may make it impossible to obtain what has been requested. For all non-essential data, the conferment is optional. In absence of consent or incomplete or incorrect conferment of certain data, the required obligations may be so incomplete as to cause injury or in terms of penalties or loss of benefits, both due to the impossibility of ensuring the adequacy of the processing itself for the obligations for which it is performed, both for the possible mismatch of the results of the processing itself for the obligations imposed by the law to which it is addressed, intending the undersigned organization exonerated from any liability for any sanctions or afflictive provisions.
DATA PROCESSING METHOD
The treatments connected to the web services of the site are processed with automated tools for the time strictly necessary to achieve the purposes for which they were collected; they take place at the server in EU(the server where hosted the site is in Germany) and are only handled by technical staff in charge of processing, or by persons in charge of maintenance and administration. Specific security measures are observed to prevent data loss, illicit or incorrect use and unauthorized access and loss of confidentiality. The structure is equipped with anti-intrusion devices, firewall, log and disaster recovery. Specific mechanisms of encryption and segregation of data and authentication and authorization of users are used. Data processing means the collection, recording, organization, storage, processing, modification, cancellation and destruction or the combination of two or more of these operations. In relation to the aforementioned purposes, the processing of personal data takes place using manual, computerized and telematic tools, with logic strictly related to the purposes themselves and, in any case, in order to guarantee the security and confidentiality of personal data, that will therefore be processed in compliance with the methods indicated in art. 5 EU Reg. 2016/679, which moreover provides that the data are: processed lawfully and fairly, collected and recorded for specific, explicit and legitimate purposes, exact and if necessary updated, relevant, complete and not excessive in relation to the purposes of the processing, respecting the fundamental rights and freedoms, as well as the dignity of the person concerned, with particular reference to privacy and personal identity, through measures of protection and security. The undersigned organization has prepared and will further improve the security system for accessing and storing data.
The names involved to receive newsletter and sign up to our system (on Mailchimp platform), depending on the consent expressed may receive promotional comunications (point F of "PURPOSES AND LEGAL BASIS OF TREATMENT") and/or automatic comunication by profiling (point G of "PURPOSES AND LEGAL BASIS OF TREATMENT") for example comunication that select recipients depending on habits of opening of passed comunications or of their signing up to the newsletter in italian or english version.
EXTRA UE TRANSFER
Treatment does not take place in non-EU and no-EEA countries, when the connection to the site originate from these countries ( by request of person that is there)
The site is hosted on server in Germany. the name storege system and managment of newsletter is based in USA. for all other used services that release cookies the nation is indicated on the Cookies disclaimer page.
The personal data will be kept, in general, as long as the purposes of the processing persist according to the category of data processed.
CATEGORY OF ADDRESSEES
The data (only the indispensable ones) are communicated
- to persons in charge of processing, both internal to the undersigned organization, and external, who perform specific tasks and operations (site administration, analysis of navigation data, traffic, profiling, management of e-mails and forms sent voluntarily by the user, fulfillment of e-commerce requests and orders, etc.);
- in the cases and to the subjects foreseen by the law.
The data will not be disseminated, unless otherwise required by law or prior to anonymization. Except as specified for cookies and elements of third parties, without the prior general consent of the party to communications to third parties, it will be possible to run exclusively to services that do not provide such communications. In case of necessity, specific and precise consents will be required and the subjects who will receive the data will use them as autonomous owners.
In some cases (not objective of the ordinary management of this site) the Authority may request news and information, for the purpose of monitoring the processing of personal data. In these cases the answer is mandatory under penalty of administrative sanction.
RIGHTS OF THE INTERESTED
At any time will be able to: exercise your rights (access, rectification, cancellation, limitation, portability, opposition, absence of automated decision-making processes) when provided to the data controller, pursuant to art. from 15 to 22 of the GDPR (link to the Regulation); to propose a claim to the Guarantor (www.garanteprivacy.it); if the treatment is based on consent, revoke the consent given, taking into account that the withdrawal of consent does not affect the lawfulness of the treatment based on consent before revocation.
Deactivation of cookies
Almost all browsers offer the possibility to manage and not enable cookies, in order to respect user preferences. In some browsers it is possible to set rules to manage cookies site by site, an option that offers a more precise control on the user's privacy; another function available on some browsers is the anonymous mode, so that all cookies created in this mode are deleted after closing.
Consult the following instructions for managing cookies in their browser:
The data controller is OMPS2 SRL in the person of its legal representative.
The company is located in VIA MATTEOTTI 343. CAP 25063. GARDONE VAL TROMPIA (BS) – Italy.
Contact details are: telephone: + 39 030832176; fax + 39 0308349903; e-mail firstname.lastname@example.org
The complete list of data processors is available on request.