Information on the processing of personal data
Pursuant to Article 13 of the EU Regulation 2016/679
1. Data Controller’s identity and contacts
The data controller is Matilde Brockhaus, located in Via Malaga, 6 20143 Milano; e-mail firstname.lastname@example.org
2. Purposes of the processing
Your personal data will be processed for the following purposes:
a) Provision of services requested by the user;
b) Use of the website
c) Analysis of the use of the site by users
3. Categories Of Personal Data
The information systems and software procedures relied upon to operate this web site acquire personal data as part of their standard functioning; the transmission of such data is an inherent feature of Internet communication protocols.
This data category includes the IP addresses and/or the domain names of the computers and terminal equipment used by any user, the URI/URL (Uniform Resource Identifier/Locator) addresses of the requested resources, the time of such requests, the method used for submitting a given request to the server, returned file size, a numerical code relating to server response status (successfully performed, error, etc.), and other parameters related to the user’s operating system and computer environment.
These data are necessary to use web-based services and are also processed in order to:
extract statistical information on service usage (most visited pages, visitors by time/date, geographical areas of origin, etc.);
check functioning of the services.
Data can be used where judicial authorities need such data for establishing the commission of criminal offence.
Data communicated by users:
Sending messages, on the basis of the user’s free, voluntary, explicit choice, to the Data Controler’s contact addresses, or sending private messages to the social media pages and profiles entail the acquisition of the sender’s contact information – which is necessary to provide a reply – as well as of any and all the personal data communicated in that manner.
4. Data Recipients
As part of the indicated purposes, your data may be communicated to companies and professional operators that provide electronic data processing and software and IT consulting services as well as management of information services relating to the foregoing.
5. Data Transfer to other countries
Furthermore, user data may be transferred to third parties indicated in the art. 4 of this disclosure established in countries not belonging to the European Union, all in compliance with the principles indicated in the art. 45 and 46 of the GDPR relating to the existence of an adequacy decision by the European Commission or to adequate guarantees.
6. Data Retention
Personal data will be kept for the time strictly necessary to achieve the specific purposes of the processing and, specifically:
a. For the purposes indicated to point a) of Article 2 for the time necessary to fulfill the request and, in any case, no later than 10 years from the time of collection of your data for the fulfillment of regulatory obligations and , in any case, no later than the terms established by law for the limitation of rights;
b. For the purposes referred to in point b) and c) of art. 2 data (such as IP address) are kept for 30 days. The data for analytics purposes are kept for 24 months.
We have implemented additional transparency and access controls in our Privacy Center and Privacy Settings to help users take advantage of those rights. As available and except as limited under applicable law, the rights afforded to individuals are:
Right of Access – the right to be informed of and request access to the personal data we process about you;
Right to Rectification – the right to request that we amend or update your personal data where it is inaccurate or incomplete;
Right to Erasure – the right to request that we delete your personal data;
Right to Restrict – the right to request that we temporarily or permanently stop processing all or some of your personal data;
Right to Object –
the right, at any time, to object to us processing your personal data on grounds relating to your particular situation;
the right to object to your personal data being processed for direct marketing purposes;
Right to Data Portability – the right to request a copy of your personal data in electronic format and the right to transmit that personal data for use in another party’s service; and
Right not to be subject to Automated Decision-making – the right to not be subject to a decision based solely on automated decision making, including profiling, where the decision would have a legal effect on you or produce a similarly significant effect.
Requests relating to the exercise of user rights will be processed without undue delay and, in any case, within one month of the request; only in cases of particular complexity and in the number of requests can this term be extended by an additional 2 (two) months.
The aforementioned rights may be exercised by sending a request to the Data Controller using the contact channels indicated in art. 1 of this statement.
7. Communication and provision of data
The provision of data by the user is mandatory as necessary to provide the service requested. Therefore, any refusal by the user to provide the data may result in the non-provision of the service, to the extent that such data are necessary for such purposes.