Privacy Policy
- Home
- Privacy Policy
Privacy Policy
This page describes how the site is managed with regard to the processing of the personal data of users who consult it. Processing is always based on principles of lawfulness and fairness in compliance with Legislative Decree 196/2003 (“Privacy Code”) and Regulation (EU) 2016/679 (“GDPR”), and appropriate security measures are adopted to protect the data.
This privacy policy is also provided as a short information notice pursuant to Art. 13 of Legislative Decree 196/03 and Articles 13 and 14 of EU Reg. 2016/679.
You will also find answers to questions such as:
- Who is the Data Controller?
- On what legal basis is the data collected?
- What types of data are collected?
- For what purposes is the data collected?
- Who will process your data?
- To whom may your data be disclosed?
- How long do we keep your data?
- Where is your data processed and/or transferred?
- What are your rights?
- How can you exercise your rights? (Whom to contact to withdraw consent or exercise the right to erasure?)
- How do we protect your data? What happens in the event of a breach?
N.B. This information applies only to the website www.giemmepack.comand does not concern other sites, pages, or online services reachable via hypertext links that may be published on the site but refer to resources external to the domain.
Data Controller
Giemme Cut Srl Via Ancona 38, Tavullia (PU), Italy. +39 0721 476660 – info@giemmepack.com The Data Processor is the Legal Representative, reachable at the company’s headquarters. For requests regarding personal data protection, privacy, and security, you may send an email to: info@giemmepack.com
Legal Basis for Processing
The Controller processes Personal Data relating to the User if one of the following conditions applies:
- The User has given consent for one or more specific purposes; Note: In some jurisdictions, the Controller may be authorized to process Personal Data without the User’s consent or another of the legal bases specified below, until the User objects (“opt-out”) to such processing. This is not, however, applicable where the processing of Personal Data is governed by European legislation on personal data protection;
- Processing is necessary for the performance of a contract with the User and/or for the execution of pre-contractual measures;
- Processing is necessary for compliance with a legal obligation to which the Controller is subject;
- Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
- Processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party.
It is always possible to ask the Controller to clarify the specific legal basis of each processing activity and, in particular, to specify whether the processing is based on law, provided for by a contract, or necessary to conclude a contract.
Types of Data Processed
Navigation Data
The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This data is used for the sole purpose of obtaining anonymous statistical information on the use of the site and to check its correct functioning, and is deleted immediately after processing. The data could be used to ascertain responsibility in the event of hypothetical computer crimes against the site.
Data provided voluntarily by the user
The optional, explicit, and voluntary sending of e-mails to the addresses indicated on this site involves the subsequent acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data included in the message (and its attachments) or in specific forms. For further information, please refer to the following paragraph “Details on the processing of personal data”.
Cookies and other tracking systems
No cookies are used for user profiling, nor are other tracking methods employed. Instead, session cookies (non-persistent) are used in a manner strictly limited to what is necessary for the safe and efficient navigation of the sites. The storage of session cookies in terminals or browsers is under the user’s control, whereas on the servers, at the end of HTTP sessions, information relating to cookies remains recorded in the service logs, with retention times not exceeding seven days, similar to other navigation data.
Purposes of Data Processing
Personal data is collected for the following purposes using the services listed below:
Contact Form
By filling in the contact form with their Data, the User consents to its use to respond to requests for information, quotes, or any other nature indicated by the user in the body of the message. Data collected: email, name.
Platform and Hosting Services
These services are intended to host and operate key components of this Website, making it possible to deliver this Website from a single platform. These platforms provide the Controller with a wide range of tools such as, for example, analytical tools, user registration management, comment and database management, e-commerce, payment processing, etc. The use of such tools involves the collection and processing of Personal Data. Some of these services operate through servers geographically located in different places, making it difficult to determine the exact location where Personal Data is stored. The server on which the site resides is managed by Aruba S.p.a., based in Via San Clemente 53, Ponte San Pietro (BG), Italy.
Content on External Platforms
These services allow you to view content hosted on external platforms directly from the pages of this Site and interact with them. If such a service is installed, it is possible that, even if Users do not use the service, it may collect traffic data relating to the pages where it is installed. Specifically regarding this site:
- Google Fonts (Google Inc.): A typeface visualization service provided by Google Inc. that allows this Site to incorporate such content into its pages.
- Personal Data collected: Usage Data.
- [Read Google’s Privacy Policy]
- Google Maps (Google Inc.): A maps visualization service provided by Google Inc. that allows this Site to incorporate such content into its pages.
- Personal Data collected: Usage Data.
- [Read Google’s Privacy Policy]
Cookies
For full details, please refer to the dedicated Cookie Policy page on our website.
Data Recipients
We care deeply about your privacy and do everything to protect you. For this reason, we share your data only when strictly necessary and only with those who help us offer a better service every day. In addition to the Controller, in some cases, categories of appointees involved in the organization of the site may have access to the data. For example, administrative and public relations staff, IT system management staff, partners, agents, marketing staff, data processors, and their collaborators, only if processing is necessary for the performance of their duties and only carrying out the operations necessary to satisfy the user’s requests.
Parties to whom data may be communicated
In some cases, we may communicate your data without your express consent for service purposes. For example:
- To judicial authorities, upon their request;
- To all other subjects to whom it is necessary to communicate it, by law or by contract, to allow the fulfillment of the purposes described above (e.g., third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies), also appointed, if necessary, as Data Processors by the Controller. Alternatively, these subjects will process your data in their capacity as independent data controllers. In any case, we want to reassure you that your data will not be disseminated without reason. The updated list of Processors may always be requested from the Data Controller.
Data Retention Period
Data is processed and stored for the time required by the purposes for which it was collected.
- In the case of data entered in the contact form, it will be kept for the time necessary to satisfy the requests made by the user at the time of contact.
- Any statistical data collected in an anonymous and aggregated form will be deleted after a maximum period of 24 months.
- For information on the duration of cookies, please refer to the cookie policy.
Personal Data collected for purposes related to the legitimate interest of the Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller. When processing is based on the User’s consent, the Controller may keep the Personal Data longer until such consent is revoked. Furthermore, the Controller may be obliged to keep Personal Data for a longer period in compliance with a legal obligation or by order of an authority. At the end of the retention period, Personal Data will be deleted. Therefore, upon expiration of this term, the right of access, erasure, rectification, and the right to data portability can no longer be exercised.
Location of Data Storage
Data is processed at the Controller’s operating offices and in any other place where the parties involved in the processing are located. For further information, contact the Controller. The User’s Personal Data may be transferred to a country other than the one in which the User is located. For more information on the place of processing, the User can refer to the section relating to details on the processing of Personal Data. If, for technical and/or operational reasons, it is necessary to use entities located outside the European Union, we inform you that such entities will be appointed as Data Processors pursuant to Article 28 of the Regulation, and the transfer of your Personal Data to these entities, limited to the performance of specific processing activities, will be regulated in accordance with the provisions of Chapter V of the Regulation. All necessary precautions will be adopted to ensure the total protection of your Personal Data, basing such transfer on: (a) adequacy decisions of the third countries expressed by the European Commission; (b) adequate safeguards expressed by the third-party recipient pursuant to Article 46 of the Regulation; (c) the adoption of binding corporate rules (BCR).
User Rights
Users may exercise certain rights regarding the Data processed by the Controller. In particular, the User has the right to:
- Withdraw consent at any time: The User can withdraw consent to the processing of their Personal Data previously expressed.
- Object to the processing of their Data: The User can object to the processing of their Data when it occurs on a legal basis other than consent.
- Access their Data: The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing, and to receive a copy of the Data processed.
- Verify and request rectification: The User can verify the correctness of their Data and request its update or correction.
- Obtain the restriction of processing: Under certain conditions, the User can request the restriction of the processing of their Data. In this case, the Controller will not process the Data for any purpose other than its storage.
- Obtain the erasure or removal of their Personal Data: Under certain conditions, the User can request the erasure of their Data by the Controller.
- Receive their Data or have it transferred to another controller: The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to obtain its transfer without hindrance to another controller. This provision is applicable when the Data is processed by automated means and the processing is based on the User’s consent, on a contract to which the User is a party, or on contractual measures connected to it.
- Lodge a complaint: The User can lodge a complaint with the competent personal data protection supervisory authority or take legal action.
Details on the right to object
When Personal Data is processed in the public interest, in the exercise of public authority vested in the Controller, or to pursue a legitimate interest of the Controller, Users have the right to object to the processing for reasons related to their particular situation. Users are informed that, should their Data be processed for direct marketing purposes, they can object to the processing without providing any reason.
Request for Information, Withdrawal of Consent, Right to be Forgotten
For requests for information on data, for the total or partial withdrawal of consent, to obtain the erasure of data (right to be forgotten), or in general to exercise the rights mentioned in the previous paragraph, simply contact the Data Controller using the contact channels listed at the beginning of this Policy. Regarding the deletion of any cookies, please refer to the specific [Cookie Policy] information notice.
Data Protection
We process user data with appropriate security measures aimed at preventing unauthorized access, disclosure, modification, or destruction of Personal Data. Processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In the event of a personal data breach, the Controller will inform the data subject within 72 hours of becoming aware of it. Notification will only occur if the Controller assesses that there are risks to the user.
Policy revised as of 05/25/2018
