Privacy
1. The data controller
Name: Raffaele Sebastiani
Address: Georg Kaneider Str. 19, 39031 Bruneck
Email: hello@raffaelesebastiani.com
Telephone: +39 3401685430
2. Categories of processed personal data
Navigation data / Usage data
Information collected during the user's website visit (e.g., IP address, URI notation addresses, browsing history, information about interactions with the website, information about the user's computer environment, browser type and language, operating system, location, date and time of the request). This information is not collected to be associated with identified data subjects, but due to the nature of its processing and association with data held by third parties, it could allow for the identification of users.
Data voluntarily provided by the user
Personal data that the user voluntarily provides via special forms on the website (e.g., voucher request/order, contact, etc.). This information may include, among other things: identification data (first name, last name, tax identification number, etc.), personal image, contact and location data (email address, telephone number and postal address, etc.);
Sensitive data
so-called “special categories of personal data” pursuant to Article 9 of the Regulation, i.e. personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or sex life or sexual orientation of a person;
Localization or tracking data (or mobility data)
Information that specifies the geographic location (latitude, longitude, altitude, direction of movement, time of location recording) of the terminal device (e.g. smartphone, PC) of a user of the website service.
3. Purpose of data processing
The controller uses the personal data collected via this website for the following purposes:
Contract fulfillment
Processing of personal data for the performance of contracts to which the user is a party (e.g., service contracts, product sales, registrations, subscriptions, participation in interactive services, etc.). This purpose involves the processing of data necessary to maintain the contractual relationship with the user, to provide the services offered on the website, and to fulfill the resulting obligations.
Fulfillment of legal obligations
Processing of personal data to comply with legal requirements to which the controller is subject (e.g. tax obligations, occupational health and safety regulations, document retention regulations, anti-money laundering regulations, civil liability, data protection regulations, etc.);
Compliance with legal obligations
Processing of personal data when this is necessary to fulfill the aforementioned legal obligations;
Security and fraud prevention
Processing of personal data to protect the security of data, information systems and the controller's technological platform, as well as to prevent, detect and combat fraudulent activities, abuse, cyberattacks and all other illegal activities;
Contact with the affected person
Processing of personal data to contact the data subject via various communication channels (e.g. email, telephone, SMS, WhatsApp) for various purposes, e.g. requesting feedback, answering inquiries, service communications, technical support, etc.;
4. Legal basis for processing
The processing of personal data is permitted on the basis of the following legal grounds, as provided for in Article 6 of the Regulation:
Contract fulfillment
Article 6(1)(b) of the Regulation – The data are necessary for the performance of a contract to which the data subject is a party;
Compliance with legal obligations
Article 6(1)(c) of the Regulation – Processing is necessary for compliance with a legal obligation to which the controller is subject;
Berechtigte Interessen
Article 6(1)(f) of the Regulation – Processing is necessary for the purposes of the legitimate interests pursued by the controller;
Protection of vital interests
Article 6(1)(d) of the Regulation – Processing is necessary to protect the vital interests of the data subject or of another natural person;
Fulfillment of tasks in the public interest
Article 6(1)(e) of the Regulation – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority;
Approval
Article 6(1)(a) of the Regulation – The data subject has consented to the processing of his or her personal data;
5. Processing methods
The processing is carried out by manual and/or automated means, including the use of information and computer technologies (e.g., CRM, administrative software and mailing list services), subject to the application of appropriate technical and organizational security measures to ensure the security, integrity and confidentiality of personal data in order to minimize the risk of destruction, loss, unauthorized access, alteration and unauthorized disclosure, in accordance with Articles 6 and 32 of the GDPR.
6. Transfer of personal data outside the EU/EEA
The controller does not intend to transfer personal data outside the European Economic Area. However, should it become necessary to meet organizational/production-related requirements (through the use of providers and/or cloud services that require the transfer of data abroad, not merely as examples), appropriate safeguards for the transfer of personal data to a third country will be identified. These safeguards may include, depending on the circumstances: verification of the existence of adequacy decisions by the European Commission, implementation of standard contractual clauses and/or binding corporate rules, and verification of the adoption of supplementary measures implementing Recommendation 01/2020 EDPB.
Anbieter | Datenschutzrichtlinie |
|---|---|
Microsoft | https://privacy.microsoft.com/en-us/privacystatement |
YouTube | https://policies.google.com/privacy |
Google Advertising Products | https://business.safety.google/privacy/ |
Facebook | https://www.facebook.com/policy/cookies |
7. Data retention periods
The data controller retains personal data only for the periods necessary to pursue the purposes specified in this document or for the timeframes provided for in certain regulations.
Personal data processed for the purpose of "providing the service" will be kept for a period of no more than 10 years;
Personal data processed for the purpose of "payments and billing" will be kept for a period of no more than 10 years (Art. 2220 cc)
Personal data processed for direct marketing purposes will be kept for a period of no more than 2 years, or until the data subject objects to the processing.
The duration of the persistence of individual cookies is stated in the "Cookie Policy";
Notwithstanding the possibility for the controller to retain personal data for the period provided for and permitted under Italian law for the purpose of "legal protection" of its interests (Articles 2946 and 2947 c1, c.3 cc).
After such retention periods have expired, personal data will be deleted or anonymized unless it is retained for further purposes on the basis of appropriate legal grounds.
8. Recipient
Personal data collected by the controller may be disclosed or made accessible to the following categories of persons for the purposes of carrying out the objectives stated above:
Employees and staff who assist the controller in processing operations, subject to explicit authorization for processing and possibly under confidentiality agreements;
Persons providing outsourcing services on behalf of the controller, acting as processors: cloud computing service providers, freelancers, companies or professional firms providing assistance and consulting services to the controller, or persons engaged in hosting and technical maintenance work, including software maintenance, network equipment and electronic communication networks;
Independent data controllers to whom the transfer of data is necessary in order to provide the service requested by the data subject.
Independent data controllers pursuing their own purposes (subject to the consent of the data subject);
Public authorities, if such notification is required by law.
After such retention periods have expired, personal data will be deleted or anonymized unless it is retained for further purposes on the basis of appropriate legal grounds.
9. Rights of the data subject
The data subject can access their personal data at any time and request its rectification, erasure, restriction of processing, and data portability. They can also object to the processing, in whole or in part, and have the right not to be subject to automated decision-making concerning them, including profiling.
To exercise the rights set out in Articles 15-22 of the GDPR, the data subject may contact the controller as indicated in the "Contact" section (see Article 10). The controller must respond to the request within one month or inform the data subject of any potential delays in responding, particularly in cases of numerous and/or complex requests (this extension may not exceed two months). In any event, the data subject always has the right to lodge a complaint with the competent supervisory authority (data protection authority) pursuant to Article 77 of the Regulation if they believe that the processing of their personal data infringes applicable regulations.
