Privacy Policy
Pursuant to Article 13 of the GDPR General Data Protection Regulation Dear Customer, we wish to inform you that "European Regulation 679/2016 on the protection of individuals with regard to the processing of personal data, as well as on the free movement of such data" (hereinafter GDPR) provides for the protection of persons and other subjects with regard to the processing of personal data. Stegip 4 Communication srl (hereinafter also referred to as the "Company") as Data Controller, pursuant to Article 13 of the GDPR, therefore provides you with the following Information:
Types of data: The company may collect and use different types of personal data depending on the specific purposes pursued and described below: a) Personal information: name, surname, gender, age/date of birth, country of origin and other personal data that current regulations allow to collect. b) Contact information: address, email address, telephone or mobile number, any fax number and other contact information that current regulations allow to collect;
- Origin of data: Data collected automatically. The computer systems and applications dedicated to the functioning of this website detect, during their normal operation, some data (the transmission of which is implicit in the use of Internet communication protocols) potentially associated with identifiable users. The data collected includes IP addresses and domain names of the computers used by users who connect to the site, URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system, the browser and the IT environment used by the user. This data is processed, for the time strictly necessary, for the sole purpose of obtaining statistical information on the use of the site and to check its regular operation. The provision of such data is mandatory as it is directly linked to the web browsing experience. Data provided voluntarily by the user. Your contact and account data. We will store the contact information you provide us (e.g., name, surname, address, phone number, email, country of residence, phone number) when you create an account on the site, buy a product and/or participate in our contests or promotions and/or call for assistance. Your payment and billing data. We will store the payment and billing data you provide us (e.g., credit card number, postal code and address when you purchase a product, for the purpose of managing your purchase orders and shipping products). If requested, we may also store payment and billing data to facilitate future product purchases. Information on site usage. Your use of the site implies the processing of data on the browser and device you are using and your IP address (this is the number that identifies a specific device on the internet and that is necessary for your device to communicate with sites); Cookies. The site uses technical/profiling first-party/third-party cookies that may collect users' browsing data, the provision of which is mandatory for technical cookies to allow browsing while it is optional and occurs through the expression of free and informed consent for profiling and third-party cookies. Cookies operate to analyze the effectiveness of the site and make it easier and more intuitive over time. Data Controller: Stegip 4 Communication srl with registered office in Rome (Rm) Via della Giustiniana, 990 Contact details: The Data Controller can be contacted at the email address: info@fim-merchandising.com ;
-
Data Processing: In this Privacy Policy, the term "Personal Data" refers to any information that allows the Company to identify the data subject, directly or indirectly. The processing of personal data will take place in accordance with Regulation (EU) 2016/679. The Company reserves the right to carry out further data processing, where required by law or in the context of criminal or other investigations or proceedings. Purposes of data processing and legal basis: The processing of your data, collected and stored, has your consent as its legal basis and is carried out for the following purposes:
- Responding to requests for information/quotes;
- Providing assistance and support for the use of purchased products and/or services;
- Newsletter/Mailing-list subscription;
- Sending training, informational and commercial communications;
- Management of commercial profiling activities;
- Statistical analysis, market research. Furthermore, your data may be collected, processed and stored based on a legal or contractual obligation or because it is a necessary requirement for the conclusion of a contract for the purchase of products or for a service requested by you. Recipients of the data: Within the limits relevant to the indicated processing purposes, your data may be communicated to associated, controlled or owned or affiliated companies of Stegip 4 Communication srl, consulting companies, private companies, appointed as Data Processors by the Data Controller. Only the category of such recipient subjects is indicated, as they are subject to frequent updates and revisions. Therefore, data subjects may request an updated list of recipients by contacting the data controller through the channels indicated above. Your data will not be disseminated in any way. The current Data Processors and Persons in Charge are specifically identified in the Privacy Document, updated periodically and available upon request. Data security and confidentiality: The Company has implemented appropriate measures to protect the data subject's personal data from accidental loss and from unauthorized access, use, modification and disclosure. In the unlikely event that the Company believes that the security of the data subject's personal data in its possession or under its control has been or may have been compromised, it will inform the data subject of the incident in accordance with the provisions of current law, using the methods prescribed by it. Retention period: The collected data will be kept for a period not exceeding the achievement of the purposes for which they are processed ("storage limitation principle" art.5, GDPR) or based on the deadlines set by law. The verification of the obsolescence of the data stored in relation to the purposes for which they were collected is carried out periodically.
- Data subject's rights: You may always exercise the right to request the Data Controller, at any time: a) access to your personal data (to obtain confirmation as to whether or not personal data concerning you is being processed. In this case, receive the following information: the purposes, the categories of data, the recipients, the retention period, the right to lodge a complaint with a supervisory authority, the right to request rectification or erasure or restriction of processing or objection to processing, as well as the existence of automated decision-making); b) rectification or erasure of the same or restriction of processing concerning you; c) to object to the processing and profiling of data concerning you for reasons related to your particular situation. The controller will refrain from any further processing of personal data, unless there are legitimate reasons that override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defense of a right in court. d) to request data portability: in the case of automated processing carried out on the basis of consent or in execution of a contract, to receive the data concerning you in a structured, commonly used and machine-readable format e) to withdraw consent to processing by asserting these rights provided for by the GDPR through a simple written communication to the Controller. The exercise of this right does not in any way affect the lawfulness of the processing carried out before the withdrawal. f) to lodge a complaint pursuant to art. 77 GDPR with a supervisory authority, based on your habitual residence, place of work or place of infringement of your rights; for Italy, the Garante per la protezione dei dati personali (Data Protection Authority) is competent, contactable through the contact details reported on the website http://www.garanteprivacy.it The aforementioned rights may be exercised by sending a specific request to the Data Controller through the contact channels indicated above. Requests relating to the exercise of your rights will be processed without undue delay and, in any case, within one month of the request; this period may be extended by another two months, if necessary, taking into account the complexity and number of requests. Data Processing Methods: The personal data you provide will be subject to processing operations in compliance with the aforementioned legislation and the confidentiality obligations that inspire the Controller's activity. The data will be processed both with IT tools and on paper and on any other suitable type of support, in compliance with adequate technical and organizational security measures provided for by the GDPR.