Legal

Privacy Policy

Notice on the processing of personal data under Regulation (EU) 2016/679.

1. Definitions

Customer
An adult natural person or a legal entity which, through its legal representative for the time being, uses or intends to use the Service offered by the Controller.
Cookie
Text files, made up of letters and/or numbers, containing packets of information stored on the User’s computer or mobile device when they visit a website through a browser. On each subsequent visit, the browser sends the cookies back to the site that created them or to another site. Cookies may be stored for the duration of the visit only (session cookies) or for a longer period independent of the session (persistent cookies).
Personal Data
Any information relating to an identified or identifiable natural person, directly or indirectly, including by reference to a name, an identification number, location data, an online identifier or to characteristic features of their physical, physiological, genetic, mental, economic, cultural or social identity.
Notice
This document concerning the processing of Personal Data.
Profiling
Any form of automated processing of Personal Data intended to evaluate or predict the Customer’s preferences and interests.
Regulation
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
Ancillary Services
The services offered through the Site, such as, by way of example, contact or information requests, newsletter subscription, quotation requests, bookings, payments, purchase of goods and/or services, indication of a delivery address and exchange of documents.
Service
The supply and/or sale of the goods and services offered by the Controller.
Site
This website.
Processing
Any operation or set of operations performed on Personal Data, such as collection, organisation, structuring, storage, alteration, retrieval, consultation, use, disclosure, alignment, restriction, erasure and destruction.
Users
The users of the Site, including Customers, the Controller’s potential customers and any other natural person browsing the Site.

2. Data controller

The data controller is GARDINI TECHNIK S.r.l., with registered office at Via Giuseppe Dozza 66, 40069 Zola Predosa (BO), Italy, tax code and VAT number 03484191204.

Any request concerning the processing of your Personal Data, including the exercise of the rights described in section 9, may be sent to the Controller:

3. Types of data processed and purposes of processing

3.1 Data provided voluntarily by the User

The User may voluntarily provide the Controller with their Personal Data, in particular personal details, e-mail address and other contact data:

  • by sending messages to the e-mail addresses shown on the Site;
  • by completing online forms and contact forms to request information or assistance;
  • by subscribing to the periodic newsletter service.

The data provided in this way is collected, processed and stored in order to:

  • reply to the messages received;
  • handle requests for assistance or information;
  • provide the Ancillary Services requested;
  • send, subject to consent where required, newsletters and other informational or promotional material relating to the Controller’s products and services.

Personal Data is processed for as long as necessary to achieve the purposes for which it was collected and is subsequently erased or irreversibly anonymised, without prejudice to the retention obligations laid down by law.

Providing the data required to deliver the Ancillary Services is essential in order to fulfil the User’s request. A refusal to provide it means the requested service cannot be used.

Processing carried out to send informational or promotional communications is based on the User’s freely given consent, expressed by a statement or a clear affirmative action on the Site. Consent may be withdrawn at any time in the manner set out in section 9.

In the cases permitted by Article 130(4) of Italian Legislative Decree 196/2003, commercial communications sent by e-mail regarding products or services similar to those already purchased may be sent without fresh consent. The data subject may object to such communications at any time.

3.2 Browsing data

The computer systems that operate the Site acquire, during their normal operation and for the duration of the connection, certain data whose transmission is implicit in the use of Internet communication protocols. This information is not collected in order to be associated with identified data subjects, but it could allow Users to be identified through processing and matching with data held by third parties.

This category includes, by way of example, IP addresses or domain names of the devices used, the URIs of the resources requested, the time and method of the request, the size of the file received in response, the numeric code indicating the status of the response, browser characteristics and other parameters relating to the User’s operating system and computing environment.

This data is used solely to obtain anonymous statistical information about use of the Site, to check that it is working correctly and to establish liability in the event of possible computer offences. Save for that possibility, browsing data is erased after processing and is not retained for more than seven days.

3.3 Cookies

The processing carried out through cookies is described in the Cookie Policy published on the Site, which we recommend you read.

4. Legal basis for processing

  • Browsing the Site: performance of the technical functions required for browsing and, where requested, the User’s consent.
  • Registration on the Site: performance of a contract to which the data subject is party, or pre-contractual measures taken at their request.
  • Ancillary Services and contact: performance of a contract or pre-contractual measures taken at the data subject’s request.
  • Informational or promotional communications: the User’s express consent, except in the cases permitted by applicable law.

5. How data is collected

The Controller collects Personal Data in the following ways:

  • Data entered on the Site: information provided by Users or Customers in order to browse, register and access the Ancillary Services or the Service offered by the Controller.
  • Data communicated directly, including offline: information provided, for example, to customer service, or collected during events and initiatives organised by the Controller.
  • Data collected automatically: browsing data and information collected through cookies or similar tools, as described in the Cookie Policy.

6. Categories of recipients of Personal Data

Personal Data is processed by the Controller and/or by selected third parties chosen on the basis of reliability and competence, to whom it may be disclosed where necessary or appropriate for the purposes described in this Notice.

In particular, the data may be processed by or disclosed to:

  1. employees and collaborators of the Controller authorised to carry out the processing;
  2. providers of services required to operate the Site, including hosting and IT support services;
  3. providers of services required to deliver the Service, such as technical suppliers and carriers;
  4. providers of browsing-data analysis services;
  5. subject to consent where required, providers of newsletter, commercial communication, marketing, promotion and preference-analysis services.

7. Personal Data retention period

  • Use of the Service: up to 10 years.
  • Ancillary Services and commercial purposes: up to 24 months.

Personal Data is retained for the time strictly necessary to achieve the purposes for which it was collected, save for the exercise of the rights to withdraw consent or to object, and without prejudice to statutory obligations.

The Controller may retain, in whole or in part, the necessary data for a maximum period of 10 years from collection, in order to comply with legal, tax and accounting obligations and for the possible establishment, exercise or defence of legal claims. At the end of the applicable period the data is erased or irreversibly anonymised.

8. Transfer of Personal Data outside the EEA

Personal Data may be transferred to suppliers located outside the European Economic Area only in compliance with Chapter V of the Regulation. Depending on the case, the transfer takes place on the basis of an adequacy decision of the European Commission under Article 45 of the Regulation, or by means of appropriate safeguards under Articles 46 et seq., ensuring that data subjects have enforceable rights and effective legal remedies.

9. Rights of the User and the Customer

The User may exercise their rights by writing to info@gardinitechnik.com. The Controller will respond without undue delay and in any case within one month of receiving the request, save for the extensions provided for by the Regulation.

Within the limits and under the conditions laid down by the Regulation, every User has the right to:

  1. withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal (Article 7);
  2. obtain access to their Personal Data and to information about the processing, as well as a copy of the data (Article 15);
  3. obtain the rectification or completion of inaccurate or incomplete data (Article 16);
  4. obtain the erasure of Personal Data in the cases provided for (Article 17);
  5. obtain the restriction of processing in the cases provided for (Article 18);
  6. object at any time to the processing in the cases provided for, including processing for direct marketing purposes (Article 21);
  7. be informed, where provided for, of a Personal Data breach likely to result in a high risk to their rights and freedoms (Article 34);
  8. lodge a complaint with the competent supervisory authority of the Member State where they reside or work, or where they believe the infringement occurred (Article 77).

For further information you may consult the text of Regulation (EU) 2016/679 or contact the Controller in the ways set out in section 2.

Download a complete copy of this notice as a PDF.

Download