Privacy Policy
INFORMATION ON THE PROCESSING OF PERSONAL DATA ON THE WEB
Frantoio Tini s.a.s. (hereinafter “Company” or “Data Controller” or “Controller”), with registered office in Contrada Pizzannocca 1 – 64035 – Castilenti (TE) – Italy, Fiscal Code and VAT no. 01039230675, e-mail address info@frantoiotini.it, Certified E-mail (PEC) address tini@pec.it, dedicated privacy email: privacy@frantoiotini.it, as Data Controller, informs you, pursuant to Articles 13 and 14 of European Regulation 679/2016 concerning the protection of personal data (hereinafter “GDPR”), regarding the processing of your personal data.
The purpose of this document is to inform Users regarding the Personal Data collected by the websites *.frantoiotini.it (for example www.frantoiotini.it or shop.frantoiotini.it, hereinafter abbreviated as “webapp”).
The Data Controller may modify or simply update, in whole or in part, this Privacy Policy, informing Users. Changes and updates will be binding as soon as they are published on the webapp. The User is therefore invited to read the Privacy Policy at each access to the webapp.
In case of non-acceptance of the changes made to this Privacy Policy, the User must cease using this webapp and may request the Data Controller to remove their Personal Data.
1. Personal Data collected by the webapp
The Data Controller collects the following types of Personal Data:
A. Contents and information voluntarily provided by the User
Contact details and contents: these are the Personal Data that the User voluntarily provides to the webapp during its use, such as personal details, contact details, access credentials for services and/or products provided, personal interests and preferences, and other personal content, etc.
Failure by the User to provide Personal Data for which there is a legal or contractual obligation, or if they constitute a necessary requirement for using the service or concluding the contract, will make it impossible for the Data Controller to provide its services in whole or in part.
The User who communicates Personal Data of third parties to the Data Controller is directly and exclusively responsible for their origin, collection, processing, communication, or dissemination.
B. Data and content acquired automatically during the use of the webapp
Technical data: the computer systems and software procedures used to operate this webapp may acquire, during their normal operation, some Personal Data whose transmission is implicit in the use of internet communication protocols. This information is not collected to be associated with identified Users, but by its very nature, through processing and association with data held by third parties, it could allow Users to be identified. This category includes IP addresses or domain names used by Users connecting to the webapp, URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained, etc.
Usage data: Data relating to the User’s use of the webapp may also be collected, such as pages visited, actions performed, features and services used.
C. Personal data collected through cookies or similar technologies
This webapp uses cookies, web beacons, unique identifiers, and other similar technologies to collect Data on pages, visited links, and other actions you perform when using our Services, within advertising content or emails. They are stored to be then retransmitted to the same sites upon the next visit by the same User.
The User can view the complete Cookie Policy in the relevant dedicated section of this site.
2. Purposes
The Personal Data collected may be used for the execution of contractual and pre-contractual obligations and for legal obligations as well as for the following purposes:
– external management of payments via credit card, bank transfer, or other instruments. The Data used for payment are acquired directly by the manager of the requested payment service without being processed in any way by this webapp. Payments are provided by communicating Data to PayPal and/or braintreepayments.
– sending emails or newsletters and mailing list management
– storage, hosting, and backend infrastructure management by communicating Data to the chosen managers verifiable with whois queries (for example: http://whois.domaintools.com/frantoiotini.it)
– interaction with live chat
– statistics only with anonymous Data by communicating Data to Google LLC https://policies.google.com/privacy
– communication and/or assignment for promotional and commercial purposes of third parties by communicating Data to Google LLC https://policies.google.com/privacy ; Facebook Inc. https://www.facebook.com/privacy/explanation
– monitoring, analysis, and tracking of User behavior by communicating Data to LinkedIn Corporation https://www.linkedin.com/legal/privacy-policy ; Facebook Inc. https://www.facebook.com/privacy/explanation ;
– User registration and authentication
– electronic invoicing service, communication to the Exchange System (Sistema di Interscambio), and electronic preservation of invoices by communicating Data to accredited external professionals and requestable at the address: privacy@frantoiotini.it
– remarketing and behavioral targeting by communicating Data to Google LLC https://policies.google.com/privacy ; Facebook Inc. https://www.facebook.com/privacy/explanation ;
– comments and feedback
3. Processing methods
The processing of Personal Data is carried out using computer and/or telematic tools, with organizational methods and logics strictly related to the indicated purposes.
In some cases, persons involved in the organization of the Data Controller (such as personnel management staff, sales staff, system administrators, etc.) or external parties (such as IT companies, service providers, postal couriers, hosting providers, etc.) may also have access to Personal Data. These subjects may be appointed as Data Processors by the Data Controller if necessary, and they may access Users’ Personal Data whenever necessary and will be contractually obligated to maintain the confidentiality of Personal Data.
The updated list of Processors can be requested via email at privacy@frantoiotini.it
4. Legal basis for processing
The Data Controller processes Personal Data relating to the User if one of the following conditions exists:
– the User has given consent for one or more specific purposes
– the processing is necessary for the performance of a contract with the User and/or for the execution of pre-contractual measures
– the processing is necessary to comply with a legal obligation to which the Data Controller is subject
– the processing is necessary for the pursuit of the legitimate interest of the Data Controller or third parties
It is always possible to request the Data Controller to clarify the concrete legal basis of each processing.
5. Place
The Data are processed at the operational headquarters of the Data Controller and in any other place where the parties involved in the processing are located. For further information, contact the Data Controller at the following email address privacy@frantoiotini.it or at the following postal address Frantoio Tini s.a.s. – Contrada Pizzannocca 1 – 64035 – Castilenti (TE) – Italy.
Personal Data may be transferred to non-EU countries: USA and Singapore.
For these countries, an adequacy decision of the European Commission exists or, in the absence of such a decision, it is possible to request more information from the Data Controller regarding the appropriate safeguards adopted, as well as the means to obtain a copy of such Data or the exact place where they have been made available.
6. Security measures
Processing is carried out in ways and with tools suitable to guarantee the security and confidentiality of the Data themselves, the Data Controller having adopted appropriate technical and organizational measures that guarantee, and allow demonstrating, that the Processing is carried out in compliance with the relevant legislation.
7. Data retention period
The Data Controller will process Personal Data for the time necessary to fulfill the purposes connected with the execution of the contract between the Data Controller and the User, no longer than 11 years from the termination of the relationship with the User and in any case until the completion of the prescriptive term provided for by the regulations in force.
When the processing of Personal Data is necessary for the pursuit of a legitimate interest of the Data Controller, the Personal Data will be kept until such interest is satisfied.
If the processing of Personal Data is based on the User’s consent, the Data Controller may keep the Personal Data until it is revoked by the User.
Personal Data may be kept for a longer period if necessary to fulfill a legal obligation or by order of an authority.
All Personal Data will be deleted upon expiry of the retention period. At the expiration of this term, the right of access, erasure, rectification, and the right to data portability can no longer be exercised.
8. Automated decision-making processes
All collected Data will not be subject to any automated decision-making process, including profiling, which may produce legal effects for the person or significantly affect them.
9. User Rights
Users can exercise certain rights with reference to the Data processed by the Data Controller. In particular, the User has the right to:
– withdraw consent at any time;
– object to the processing of their Data;
– access their Data;
– verify and request rectification;
– obtain restriction of processing;
– obtain the erasure of their Personal Data;
– receive their Data or have them transferred to another controller;
– lodge a complaint with the personal data protection supervisory authority and/or take legal action.
To exercise their rights, Users can direct a request to the contact details of the Data Controller indicated in this document. Requests are made free of charge and processed by the Data Controller as quickly as possible.
—–
ONSITE PRIVACY POLICY
INFORMATION ON THE PROCESSING OF PERSONAL DATA AT THE COMPANY PREMISES
concerning the protection of natural persons with regard to the processing of personal data
Frantoio Tini s.a.s. (hereinafter “Company” or “Data Controller” or “Controller”), with registered office in Contrada Pizzannocca 1 – 64035 – Castilenti (TE) – Italy, Fiscal Code and VAT no. 01039230675, e-mail address info@frantoiotini.it, Certified E-mail (PEC) address tini@pec.it, dedicated privacy email: privacy@frantoiotini.it, as Data Controller, informs you, pursuant to Articles 13 and 14 of European Regulation 679/2016 concerning the protection of personal data (hereinafter “GDPR”), regarding the processing of your personal data.
1. Type of data processed
The Company is the data controller of the personal data communicated by the User to the writer and includes, by way of example but not limited to:
(i) identification, contact, and access data, such as Company Name/Surname and Name, Fiscal Code and other identification numbers, Address, E-Mail Address, GPS coordinates, telephone number, and any access credentials to services and/or products provided by the Company;
(ii) if services are used that require it, navigation data, such as IP addresses, log data or domain names, and other parameters relating to computers, operating systems, and the IT environment used;
(iii) product data, such as data relating to products and/or services provided by the Company, which the Data Subject has requested, has access to, or uses;
(iv) any data on preferences, such as data relating to preferences, activities, and spending habits of the Data Subject;
(v) payment and banking data, such as current account number or IBAN code;
(vi) data acquired from public sources, such as data of representatives and proxies collected through, for example, Chambers of Commerce or commercial information services;
(hereinafter jointly defined as “Data”).
2. Purpose of processing
The processing of Data is carried out by the Company in the performance of its economic and commercial activities for the following purposes:
a) allow the Data Subject to request, obtain, access, and use the services and/or products provided by the Company;
b) fulfill obligations deriving from law, regulations, or EU legislation (e.g., tax and accounting obligations);
(the purposes under letters a) and b) are jointly defined as “Contractual Purposes”)
c) to enforce and defend its rights, also within debt collection and debt assignment procedures, also through third parties;
d) for the analysis and improvement of the services and/or products offered;
e) to complete a potential merger, asset sale, sale of business or business unit by disclosing and transferring the Data to the involved third party/ies;
(the purposes from letter c) to e) are jointly defined as “Legitimate Business Interest Purposes”)
f) to provide the Data Subject, pursuant to Article 130 of Legislative Decree 196/2003 (the “Privacy Code”), with marketing communications via e-mail on services and/or products similar to those provided by the Company, it being understood that, at any time, they will have the possibility to object to the sending of such communications;
g) with the prior consent of the Data Subject, to provide them with marketing communications relating to products and services offered by the Company, to involve them in market research or other customer satisfaction initiatives through traditional communication channels such as paper mail and through automated communication tools such as email, automated messages, and other remote communication tools;
h) with the prior consent of the Data Subject, to provide them with marketing communications according to the modalities referred to in the previous letters f) and g) relating to the products and services of the company and/or commercial partners belonging to the distribution network and commercial channels, to whom the Data may be communicated and whose list is available by contacting the Company through the methods indicated in this privacy policy;
i) without prejudice to what is indicated in the following letter j), to perform, with the prior consent of the Data Subject, an analysis of the preferences, activities, and spending habits of the Data Subject, in order to send the marketing communications indicated above.
(the purposes from letter f) to i) are jointly defined as “Marketing Purposes”);
j) for carrying out, towards the Data Subject to whom it is possible to send communications for Marketing Purposes pursuant to this privacy policy, low-invasive forms of segmentation based, among other things, on membership categories such as the professional category to which they belong, the city/province/region where they are located, and the type of service and/or product provided by the Company.
(the purpose referred to in letter j) is defined as “Legitimate Marketing Interest Purpose”).
3. Legal basis for processing
The processing of Data is necessary with reference to Contractual Purposes as such Data are necessary in order to:
– provide the requested services and/or products regarding the cases referred to in Section 2, letter a);
– comply with the provisions of applicable legislation as provided for in Section 2, letter b).
Should the Data Subject decide not to provide the Data necessary for Contractual Purposes, the Company will be unable to provide the requested services.
The processing of Data for Legitimate Business Interest Purposes is carried out pursuant to Article 6, letter f) of the GDPR for the pursuit of the legitimate interest of the Company which is fairly balanced with the interests, rights, and freedoms of the Data Subject as the Data processing activity is limited to what is strictly necessary for the execution of the operations indicated therein. Processing for Legitimate Business Interest Purposes is not mandatory and the Data Subject may object to said processing in the manner referred to in this information notice, but should they decide to object to this processing, their Data cannot be used for Legitimate Business Interest Purposes, unless the Company demonstrates the presence of compelling legitimate reasons that prevail or the exercise or defense of a right pursuant to Article 21 of the GDPR.
The processing of Data for Marketing Purposes is based:
– with regard to Section 2 letter f), on Article 130 of the Privacy Code, which allows sending marketing communications via e-mail regarding similar services and/or products provided, to which the Data Subject may object at the time of data collection and in any subsequent communication;
– with regard to Section 2, letters from g) to i), on the consent of the Data Subject.
The processing of data for Marketing Purposes is not mandatory. Therefore, in case of objection to marketing communications or refusal to provide the relative consent, or withdrawal thereof, the Data Subject will not receive the marketing communications referred to in Section 2 from letters f) to i). In any case, the Data Subject may revoke consents to the processing of Data and object to the sending of all marketing communications at any time, through the methods provided for in this privacy policy.
Finally, the processing of Data for Legitimate Marketing Interest Purposes is functional to the pursuit of a legitimate interest of the Company adequately balanced with the interests, rights, and freedoms of the Data Subject in light of the limits imposed in Section 2 letter j). Also in this case, the processing for Legitimate Marketing Interest Purposes is not mandatory and the Data Subject may object to said processing in the manner referred to in this privacy policy, but should they object to such processing, they will no longer be able to receive the relevant communications, unless the Company demonstrates the presence of compelling legitimate reasons that prevail or the exercise or defense of a right pursuant to Article 21 of the GDPR.
4. Processing Methods
The Data will be processed by the Company with electronic and manual systems according to the principles of correctness, loyalty, and transparency provided for by the applicable legislation on the protection of personal data and protecting the confidentiality of the Data Subject through technical and organizational security measures to guarantee an adequate level of security.
5. Data retention
The Data will be kept for the period of time necessary for the pursuit of the purposes for which such Data were collected, as stated in this information notice. In any case, the following retention periods will apply with reference to Data processing for the purposes listed below:
a) for Contractual and Legitimate Business Interest Purposes, Data are kept for a period equal to the duration of the supply of services and/or products requested by the Data Subject and for the following 10 years after termination of the supply, without prejudice to any renewals and cases where retention for a subsequent period is required for any litigation, requests by competent authorities, or pursuant to applicable legislation;
b) for the Marketing Purposes referred to in Section 2, letters f) and g) and for Legitimate Marketing Interest Purposes, Data are kept for a period equal to the duration of the supply of services requested by the Data Subject and a period of 24 months following the last contact with the Data Subject, to be understood as, among others, participation in an event of the Company, the use of a product or service provided by the Company or the opening of a newsletter (jointly defined as the “Last Contact”);
c) for Marketing Purposes referred to in Section 2, letter h), Data are kept for a period of 12 months from registration;
d) for the Marketing Purposes referred to in Section 2, letter i), Data are kept by the Company for a period equal to the duration of the supply of services and/or products requested by the Data Subject and a period of 12 months following the Last Contact, while they are kept by third parties for a period equal to 12 months from registration.
6. Communication, dissemination, and transfer of Data
For Contractual Purposes, Data may be transferred to the following third parties that perform activities functional to those relating to the supply of services and/or products requested by you, located inside and outside the European Union:
(a) third-party providers of assistance and consulting services for the Company with reference to activities in the (by way of example only) technological, accounting, administrative, legal, insurance sectors;
(b) companies that may succeed the Company itself;
(c) in cases where the supply of services and/or products requested by the Data Subject requires the intervention of our commercial partners, the Company may share some Data with distributors, resellers, and partners belonging to the distribution chain of the Company’s products and services;
(d) subjects and authorities whose right of access to the Data is expressly recognized by law, regulations, or provisions issued by competent authorities.
For Legitimate Business Interest Purposes, Data may be transferred to the following categories of recipients, located inside and outside the European Union:
(a) third-party providers of assistance and consulting services for the Company with reference to activities in the (by way of example only) technological, accounting, administrative, legal, insurance sectors;
(b) companies that may succeed the Company itself;
(c) potential buyers of the Company and entities resulting from the merger or any other form of transformation concerning the Company;
(d) competent authorities.
For Marketing Purposes and for Legitimate Marketing Interest Purposes, Data may be transferred to the following categories of recipients, located inside and outside the European Union:
(a) third parties in charge of Data processing, providers of assistance and consulting services for the Company with reference to marketing communication sending activities;
(b) group companies of which the Company is part.
These recipients, depending on the case, process the Data Subject’s Data as independent controllers, processors, or persons in charge of processing. The complete and updated list of subjects processing Data as data processors is available on request to the Data Protection Officer, according to the contact methods indicated in this privacy policy.
The Data will be processed, within the limits of what is necessary, by authorized personnel, adequately instructed and trained, by the Controller as well as by the personnel of third parties providing services to the Controller and performing Data processing on behalf and under the instructions of the latter as data processors.
In case of communication to third parties, the recipients may also be:
Categories: suppliers, customers, carriers, freight forwarders, agents, software users, professionals we turn to in order to fulfill the required obligations, Ministry of Economy and Finance.
More generally, in the performance of its ordinary corporate activities, the Data may be communicated to subjects performing control, audit, and certification activities of the actions carried out by the Controller, consultants, and freelancers in the context of tax and legal assistance services and in case of corporate transactions for which it is necessary to evaluate company assets, public bodies and administrations, as well as to subjects legitimized by law to receive such information, Italian and foreign judicial authorities, and other public authorities, for purposes related to the fulfillment of legal obligations, or for the fulfillment of obligations assumed and arising from the contractual relationship, including for defense needs in court.
7. Transfer of data abroad
The Data may be freely transferred outside the national territory to countries located in the European Union, but could also be transferred outside the European Union and in particular to the United States. With reference to transfers outside the territory of the European Union to countries not considered adequate by the European Commission, the Company adopts suitable and appropriate security measures to protect the Data. Consequently, any transfer of Data to countries located outside the European Union will take place, in any case, in compliance with the appropriate and opportune safeguards for the transfer itself, such as standard contractual data protection clauses, pursuant to the applicable legislation and in particular Articles 45 and 46 of the GDPR.
8. What are the rights of the Data Subject
In relation to the processing of Data described in this information notice, the Data Subject can exercise at any time the rights provided for by the GDPR (Articles 15-21), including:
– receive confirmation of the existence of the Data and access their content (right of access);
– update, modify, and/or correct the Data (right to rectification);
– request the erasure or restriction of processing of Data processed in violation of the law, including those whose retention is not necessary in relation to the purposes for which the Data were collected or otherwise processed (right to be forgotten and right to restriction);
– object to processing (right to object);
– withdraw consent, where given, without prejudice to the lawfulness of processing based on consent given before withdrawal;
– lodge a complaint with the Supervisory Authority (Garante per la protezione dei dati personali www.garanteprivacy.it) in case of violation of the discipline on personal data protection;
– receive an electronic copy of the Data concerning them, to transfer them to themselves or to a different service provider, in cases where the Company processes such Data on the basis of their consent or on the basis of the circumstance that the processing is necessary for the provision of the requested services and/or products and the Data are processed through automated tools (right to data portability).
To exercise these rights, the Data Subject can contact the Data Protection Officer, who can be contacted by sending a request to the address privacy@frantoiotini.it, or by addressing the communication by post to:
Tini s.a.s. – Contrada Pizzannocca 1 – 64035 – Castilenti (TE) – c.a.: Responsabile della Protezione dei Dati
When contacting us, the Data Subject must ensure they include their name, email/postal address, and/or telephone number(s) to be sure that their request can be handled correctly.
9. Changes and updates
This information notice may be subject to changes, in whole or in part, also as a consequence of any changes and/or regulatory integrations, informing the data subjects. The text of the constantly updated information notice will be available on the websites: *.frantoiotini.it (for example: www.frantoiotini.it or shop.frantoiotini.it). Data subjects are therefore invited to read the relevant documentation by accessing the addresses indicated above.
In case of non-acceptance of the changes made to this documentation, the data subject can request the Data Controller to remove their Personal Data.