Information pursuant to Article 13 of Legislative Decree 196/03 – EU Regulation 2016/679 GDPR (General Data Protection Regulation)
Personal Data Protection Code
Your personal data will be processed in compliance with the law in order to process orders, provide the services for which registration is required and for the other purposes indicated in this policy; processing will be based on the principles of correctness, lawfulness and transparency and the protection of your privacy. The processing methods envisage the use of manual, computerised and telematic tools (including fax, telephone, even without operator assistance, e-mail, SMS and other computerised and/or automated communication systems) and are in any case such as to ensure the security and confidentiality of the data. Users/visitors must read this Privacy Policy carefully before submitting any personal information and/or filling in any electronic form on the aforementioned access points.
Data Controller
F.lli Napolitano
Contrada Cioffi, 114 | 84025 Eboli (SA)
Tel. +39 0828 347395
e-mail: info@fratellinapolitano.it Website: www.fratellinapolitano.it
VAT IT02271200657
Types of Data Collected
Among the Personal Data collected by this website, either independently or through third parties, are: Cookie, Usage Data, First Name, Last Name and Email. Full details on each type of data collected are provided in the dedicated sections of this privacy policy or by means of specific information texts displayed prior to the collection of such data.
Personal Data may be freely provided by the User or, in the case of Usage Data, automatically collected during the use of this website.
Unless otherwise specified, all Data requested by this website are mandatory. If the User refuses to provide it, it may be impossible for this website to provide the Service. Where this website indicates certain Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or its operation.
Users in doubt as to which Data are mandatory are encouraged to contact the Data Controller.
Any use of Cookies – or of other tracking tools – by this website or by the owners of third party services used by this website, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy.
The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this website and guarantees that he/she has the right to communicate or disseminate them, releasing the Owner from any liability towards third parties.
Method and location of data processing
Treatment modes
The Controller processes the Personal Data of the Users by taking appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of the Personal Data.
The processing is carried out using computer and/or telematic instruments, with organisational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, categories of people involved in the organisation of the site (administrative, sales, marketing, legal, system administrators) or external subjects (such as third party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller, may have access to the Data.
Legal basis for processing
The Controller processes Personal Data relating to the User if one of the following conditions is met:
- the User has given consent for one or more specific purposes; Note: in some jurisdictions, the Controller may be allowed to process Personal Data without the User’s consent or any of the other legal bases specified below, until the User objects (“opts-out”) to such processing. However, this does not apply where the processing of Personal Data is governed by European legislation on the protection of Personal Data;
- the processing is necessary for the performance of a contract with the User and/or the execution of pre-contractual measures;
- processing is necessary to comply with a legal obligation to which the Controller is subject;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
- processing is necessary for the pursuit of the legitimate interest of the Controller or of third parties.
However, it is always possible to ask the Controller to clarify the concrete legal basis of each processing operation and in particular to specify whether the processing is based on law, required by a contract or necessary to conclude a contract.
Place
The Data are processed at the Controller’s premises and in any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one where the User is located. For further information on the location of the processing, the User may refer to the section on Personal Data processing details.
The User has the right to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organisation under public international law or consisting of two or more countries, such as the UN, as well as about the security measures taken by the Data Controller to protect the Data.
Should one of the transfers just described take place, the User may refer to the respective sections of this document or request information from the Controller by contacting him at the contact details given at the beginning.
Storage period
Data are processed and stored for the time required by the purposes for which they were collected.
Therefore:
- Personal Data collected for purposes related to the performance of a contract between the Controller and the User will be retained until the performance of that contract is completed.
- Personal Data collected for purposes related to the legitimate interest of the Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.
When processing is based on the User’s consent, the Controller may keep the Personal Data for a longer period until such consent is revoked. In addition, the Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, the Personal Data will be deleted. Therefore, at the expiry of this period, the right of access, cancellation, rectification and the right to Data portability can no longer be exercised.
Purposes of Data Processing
The User Data are collected to enable the Controller to provide its services, as well as for the following purposes: Statistics, Advertising, Hosting and backend infrastructure, Interaction with social networks and external platforms and Displaying content from external platforms.
The types of Personal Data used for each purpose are indicated in the specific sections of this document.
In particular, Navigation Data are processed exclusively:
- for the operational management of navigation;
- for the processing of statistical data on access and consultation;
- for Data Security Management.
As for the Personal Data provided voluntarily by the User, they are processed for the following purposes, in addition to those set out below:
- for the processing of anonymous and aggregated usage statistics;
- protection or defence of rights in court;
- fulfilment of obligations under applicable laws or regulations, including in accounting and tax matters;
- fulfilment of the specific purposes for which such Data have been provided by the User (provision of a service, answering specific questions submitted via contact forms, requests for assistance, etc.);
- management of User registration and/or access to any restricted areas available on the site;
- sending newsletters to the User, subject to the latter’s consent;
- the User’s participation in initiatives, in compliance with the rules governing such activities or any regulations published on the site.
In order to pursue the processing purposes described above, F.lli Napolitano makes use of the following services, listed by processing purpose.
Details of Personal Data Processing
Personal Data are collected for the following purposes and using the following services:
- Hosting and back-end infrastructure
The purpose of these types of services is to host data and files that allow F.lli Napolitano to function, enable their distribution and provide a ready-to-use infrastructure to deliver specific F.lli Napolitano features.
Some of these services operate through servers located geographically in different places, making it difficult to determine the exact location where Personal Data are stored. - Aruba Business ( Aruba Business S.r.l. )
Aruba Business is a hosting service provided by Aruba Business S.r.l.
Personal Data collected: various types of Data as specified by the privacy policy of the service.
Place of data processing: Italy (Milan) – Privacy Policy - Interaction with social networks and external platforms
This type of service allows you to interact with social networks, or other external platforms, directly from the pages of F.lli Napolitano.
Interactions and information acquired by F.lli Napolitano are in any case subject to the User’s privacy settings for each social network.
In case a social network interaction service is installed, it is possible that, even if Users do not use the service, it collects traffic data related to the pages where it is installed.
+1 button and social widgets of Google+ (Google Inc.)
The +1 button and Google+ social widgets are services for interaction with the Google+ social network, provided by Google Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy
PolicyFacebook Like button
and social widgets (Facebook, Inc.)
The Facebook “Like” button and social widgets are services for interaction with the social network Facebook, provided by Facebook, Inc.
Personal data collected: Cookies and Usage Data.
Place of processing: USA – Privacy PolicyTwitter
Tweet button and social widgets (Twitter, Inc.)
The Tweet button and Twitter social widgets are services for interaction with the social network Twitter, provided by Twitter, Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing : USA – Privacy Policy
- Interaction with data collection platforms and other third partiesThis type of service allows Users to interact with data collection platforms or other services directly from the pages of this website in order to save and re-use data.
If one of these services is installed, it is possible that, even if Users do not use the service, it will collect Usage Data related to the pages where it is installed.
MailChimpwidget (The Rocket Science Group, LLC.)
The MailChimp widget enables interaction with the MailChimp email address management and messaging service provided by The Rocket Science Group LLC.
Personal data collected: surname, email, first name and phone number.
Place of processing: United States – Privacy Policy. Privacy Shield adherent. - Traffic optimisation and distributionThis
type of service allows this Application to distribute its content via servers located throughout the territory and to optimise its performance.
The Personal Data processed depends on the characteristics and mode of implementation of these services, which by their nature filter communications between this Application and the User’s browser.
Given the distributed nature of this system, it is difficult to determine the places to which content is transferred, which may contain the User’s Personal Data.
CloudFlare(Cloudflare)
CloudFlare is a traffic optimisation and distribution service provided by CloudFlare Inc.
The way in which CloudFlare is integrated means that it filters all the traffic of this Application, i.e., communications between this Application and the User’s browser, also enabling the collection of statistical data about it.
Personal Data collected: Cookies and various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
Advertising
These types of services allow the use of User Data for commercial communication purposes in different forms of advertising, such as banners, videos, etc. This does not mean that all Personal Data is used for this purpose. Data and conditions of use are set out below.
- Statistics
The services contained in this section allow the Data Controller to monitor and analyse traffic data. F.lli Napolitano uses this service in order to perform aggregate analysis on its Users in an anonymous way and, thus, improve the performance of the F.lli Napolitano website
Google Analytics (Google Inc.)Google
Analytics is a web analysis service provided by Google Inc. (“Google”). Google uses the Personal Data collected in order to track and examine the use of this Application, compile reports and share them with other services developed by Google.
Google may use the Personal Data to contextualise and personalise the advertisements of its advertising network.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy- Opt Out. Privacy Shield adherent. Google Analytics with anonymized IP (Google Inc.)
Google Analytics is a web analytics service provided by Google Inc. (“Google”). Google uses the Personal Data collected in order to track and examine the use of this Application, compile reports and share them with other services developed by Google.
Google may use the Personal Data to contextualise and personalise the advertisements of its advertising network.
This Google Analytics integration anonymises your IP address. The anonymisation works by shortening the IP address of Users within the borders of the member states of the European Union or in other countries which are parties to the Agreement on the European Economic Area. Only in exceptional cases will the IP address be sent to Google’s servers and abbreviated within the United States.
Personal data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy – Opt Out. Privacy Shield adherent. - Managing contacts and sending messagesThese
types of services allow the management of a database of email contacts, telephone contacts or any other contacts used to communicate with the User.
These services may also collect data about the date and time the User views messages, as well as the User’s interaction with them, such as information about clicks on links in messages.
MailChimp(The Rocket Science Group, LLC.)
MailChimp is an address management and email messaging service provided by The Rocket Science Group, LLC.
Personal Data Collected: First Name,Last Name, Email Address.
Place of processing: United States – Privacy Policy. Privacy Shield adherent - Displaying content from external platforms
This type of service allows you to view content hosted on external platforms directly from the pages of F.lli Napolitano and interact with them.
If a service of this type is installed, it is possible that, even if Users do not use the service, it collects traffic data relating to the pages where it is installed.
YouTube video widget (Google Inc.)
YouTube is a video content display service operated by Google Inc. that allows F.lli Napolitano to integrate such content into its pages.
Personal Data collected: Cookie and Usage Data.
Place of processing: USA – Privacy PolicyWidget
Instagram (Instagram, Inc.)
Instagram is an image display service operated by Instagram, Inc. that allows F.lli Napolitano to integrate such content within its pages.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy PolicyWidget
Google Maps (Google Inc.)
Google Maps is a map display service operated by Google Inc. that allows F.lli Napolitano to integrate such content into its pages.
Personal Data collected: Cookie and Usage Data.
Place of processing : USA – Privacy Policy - Interaction with live chat platformsThis type of service allows interaction with live chat platforms, managed by third parties, directly from the pages of this Application. This allows the User to contact the support service of this Application or this Application to contact the User while he is browsing its pages.
If a service for interacting with live chat platforms is installed, it is possible that, even if Users do not use the service, it may collect Usage Data relating to the pages on which it is installed. In addition, live chat conversations may be recorded.
Smartsupp (Smartsupp.com, s.r.o.)
The Smartsupp Widget is a service for interacting with the Smartsupp live chat and session recording platform, provided by Smartsupp.com, s.r.o.
Personal Data collected: Cookies, Data disclosed during use of the service, Usage Data and various types of Data as specified by the privacy policy of the service.
Place of processing: Czech Republic – Privacy Policy. - Payment processing
Payment handling services allow this Application to process payments by credit card, bank transfer or other means. The data used for payment are acquired directly by the operator of the payment service requested without being processed in any way by this Application.
Some of these services may also allow the scheduled sending of messages to the User, such as emails containing invoices or payment notifications.
PayPal(Paypal Inc.)PayPal
is a payment service provided by PayPal Inc. that allows the User to make online payments.
Personal Data collected: various types of Data as specified by the privacy policy of the service.
Privacy Policy.
Stripe (Stripe Inc.)Stripe
is a payment service provided by Stripe Inc.
Personal Data collected: various types of Data as specified by the privacy policy of the service.
Place of processing: USA – Privacy Policy
Further information on Personal Data
Sharing functionality via social networks
On F.lli Napolitano the social network sharing feature is available. This feature allows Users to send invitations, news or other types of communication and/or share contents present or actions taken by the User (e.g. sharing comments etc.) on the Website in use, through the use of social networks external to F.lli Napolitano (e.g. Facebook, Twitter, Google+ etc.). In such cases, the User must be aware that the Personal Data eventually conferred could be processed also by third parties owners of such social networks according to their privacy policy and without any possibility for the Data Controller to exercise any kind of control or influence on such subsequent processing modalities.
The User is invited to read and accept the privacy policies of such third parties available for consultation at the links provided in the section dedicated to each of these services within this document.
Sale of goods and services
onlinePersonal Data collected is used to provide services to the User or to sell products, including payment and possible delivery. The Personal Data collected to finalise payment may be that relating to the credit card, bank account used for the transfer or other payment instruments provided. The Payment Data collected by this Application depends on the payment system used.
Additional Rights of Users
We never, under any circumstances, sell or rent User Data to third parties. The only uses of Data are those highlighted in this policy. Users are the sole owners of their Data and may request its modification or deletion at any time.
Rights of the data subject
The User, as an interested party, may contact the Controller at any time, without any formality, to assert his/her rights, as provided for in Article 7 of the Privacy Code, which for the User’s convenience is set out below in its entirety:
- The data subject has the right to obtain confirmation of the existence or non-existence of personal data concerning him/her, even if not yet recorded, and its communication in intelligible form.
- The person concerned has the right to be informed:
- the origin of personal data;
- the purposes and methods of processing;
- the logic applied in the event of processing carried out with the aid of electronic instruments;
- the identification details of the data controller, data processors and the designated representative pursuant to Article 5(2) (of the Privacy Code);
- of the entities or categories of entity to whom or which the personal data may be communicated or who or which may become aware of them in their capacity as designated representative(s) in the territory of the State, data processor(s) or person(s) in charge of processing.
- The data subject has the right to obtain:
- updating, rectification or, when interested, integration of the data;
- the cancellation, transformation into anonymous form or blocking of data processed in breach of the law, including data whose storage is not necessary in relation to the purposes for which the data were collected or subsequently processed;
- certification that the operations referred to in points a) and b) have been brought to the attention, also as regards their content, of those to whom the data have been communicated or disseminated, except where this proves impossible or involves a manifestly disproportionate effort compared to the right protected.
- The data subject has the right to object, in whole or in part:
- for legitimate reasons to the processing of personal data concerning him/her, even if pertinent to the purpose of collection;
- the processing of personal data concerning him/her for the purposes of sending advertising or direct sales material or for carrying out market research or commercial communication’.
Methods of exercising rights
You may exercise your rights at any time by sending a communication:
- by e-mail, at: info@fratellinapolitano.it
- or by post A.R., to: F.lli Napolitano | Contrada Cioffi, 114 | 84025 Eboli (SA)