- Personal Data collected by the Application
The Data Controller collects the following types of Personal Data:
- Content and information voluntarily provided by the User
- Contact data and contents: Personal Data that the User voluntarily provides to the Application during its use, such as personal data, contact details, access credentials to services and/or products provided, personal interests and preferences and other personal content, etc.
- Sensitive Data: Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, as well as genetic data, biometric data intended to uniquely identify a natural person, Data relating to health or sex life or sexual orientation of the person.
Failure by the User to provide Personal Data, for which there is a legal or contractual obligation or if they are a necessary requirement for the use of the service or for the conclusion of the contract, will make it impossible for the Data Controller to provide all or part of its services.
The User who communicates to the Owner Personal Data of third parties is directly and exclusively responsible for their origin, collection, treatment, communication or diffusion.
- Data and contents acquired automatically during the use of the Application:
- Technical data: the computer systems and software procedures used to operate this Application may acquire, during their normal operation, some Personal Data whose transmission is implicit in the use of internet communication protocols. This information is not collected in order to be associated with identified Users, but by its very nature could, through processing and association with Data held by third parties, allow Users to be identified. This category includes IP addresses, or domain names used by Users connecting to the Application, URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained, etc.
- Usage Data: Personal Data relating to the use of the Application by the User may also be collected, such as the pages visited, the actions performed, the functions and services used.
- Geolocation data: the Application may collect Personal Data on the User’s position, which may be GNSS (Global Navigation Satellite System, such as GPS) data, as well as data identifying the nearest repeater, Wi-Fi and Bluetooth hotspots, communicated when enabling location-based products or functionalities.
- Personal data collected through cookies or similar technologies:
The Personal Data collected may be used for the performance of contractual and pre-contractual obligations and for legal obligations as well as for the following purposes:
- User registration and authentication: to allow the User to register on the Application to access and be identified .
- Support and contact with the User: to respond to the User’s requests and help him in case of problems.
- External management of payments by credit card, bank transfer or other means: to manage Users’ payments through external platforms that acquire payment data without the owner of the Application having access.
- Statistics only with anonymous data: to perform statistical analysis based on aggregate data or data that do not allow the User to be identified.
Personal Data are communicated to Google Inc.
- Profiling of Users: to group and analyze in an automated way the characteristics or behaviors of the User and provide personalized services or messages.
Personal Data is communicated to Facebook Inc, https://www.facebook.com/policy.php Google Inc www.google.com/privacy
- Sending emails or newsletters and mailing list management: to contact the User with emails containing commercial and promotional information about the Application.
Personal Data are communicated to MailChimp, https://mailchimp.com/legal/privacy/
- Advertising targeting and remarketing: to show more relevant advertisements to the User based on his/her browsing behavior and preferences.
Personal Data is disclosed to MailChimp, https://mailchimp.com/legal/privacy/, Facebook Inc, https://www.facebook.com/policy.php Google Inc www.google.com/privacy
- Processing methods
The processing of Personal Data is carried out by means of computer and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated.
In some cases, subjects involved in the organization of the Data Controller (such as, for example, personnel management personnel, sales staff, system administrators, etc.) or external subjects (such as IT companies, service providers, postal couriers, hosting providers, etc.) may also have access to Personal Data. These subjects, if necessary, may be appointed as Data Processors by the Data Controller, as well as have access to the Personal Data of the Users whenever necessary and will be contractually obliged to keep the Personal Data confidential.
The updated list of Data Processors can be requested by email at email@example.com.
- Legal basis of processing
The processing of Personal Data relating to the User is based on the following legal bases:
- consent given by the User for one or more specific purposes;
- the processing is necessary for the performance of a contract with the User and/or the execution of pre-contractual measures;
- the processing is necessary to comply with a legal obligation to which the Data Controller is subject;
- the processing is necessary for the performance of a task of public interest or for the exercise of public powers vested in the Controller
- the processing is necessary for the pursuit of the legitimate interest of the Controller or of third parties
- the processing is necessary for the pursuit of a vital interest of the Controller or of third parties.
However, it is always possible to ask the Data Controller to clarify the legal basis of each processing at firstname.lastname@example.org.
Personal Data is processed at the Controller’s operational headquarters and in any other place where the parties involved in the processing are located. For further information, please contact the Data Controller at the following email address email@example.com or at the following postal address Piazza G.Poggi 1, 50125 Firenze – Italia.
- Security measures
The Processing is carried out according to methods and with instruments suitable to guarantee the security and confidentiality of Personal Data, the Data Controller having adopted adequate technical and organizational measures that guarantee, and allow to demonstrate, that the Processing is carried out in compliance with the reference legislation.
- Data Retention Period
Personal Data will be kept for the period of time necessary to fulfill the purposes for which they were collected.
In particular, Personal Data will be retained for the entire duration of the contractual relationship, for the performance of the inherent and consequent fulfilments thereof, for the compliance with the applicable legal and regulatory obligations, as well as for its own or third parties’ defensive purposes.
If the processing of Personal Data is based on the User’s consent, the Data Controller may keep the Personal Data until the consent is revoked.
Personal Data may be kept for a longer period if necessary to comply with a legal obligation or by order of an authority.
All Personal Data will be deleted or stored in a form that does not allow the User to be identified within 30 days of the end of the storage period. Upon expiration of this period, the right of access, deletion, rectification and the right to portability of Personal Data may no longer be exercised.
- Automated decision-making processes
All Personal Data collected will not be subject to any automated decision-making process, including profiling, which may produce legal effects for the person or which may significantly affect the person.
- User Rights
Users may exercise certain rights with respect to Personal Data processed by the Data Controller. In particular, the User has the right to:
- revoke consent at any time;
- object to the processing of their Personal Data;
- access their Personal Data;
- check and ask for rectification;
- obtain the limitation of the treatment;
- obtain the deletion of your Personal Data;
- receive their Personal Data or have them transferred to another data controller;
- to lodge a complaint with the data protection supervisory authority and/or take legal action.
To exercise their rights, Users may address a request to the contact details of the Data Controller indicated in this document. Requests are made free of charge and processed by the Data Controller as soon as possible, in any case within 30 days.
- Holder of the Treatment
The Data Controller is Luxdoma, with registered office in Piazza G. Poggi 1, 50125 Florence, – Italy, Tax Code/VAT Number 06378970484 , e-mail address firstname.lastname@example.org
Last update: 14/01/2022