In this page you can find information on the methods of personal data collection and processing when users (registered or not) visit the website www.bonaitispa.com, property of Bonaiti S.p.A..
This document contains information to the users in observance of the provisions of the EU Regulation 2016/679, it is valid only for the above mentioned website and not for other websites you can visit through the links which it contains.
We clarify that the term “Personal Data” is used in reference to any information that allows Bonaiti S.p.A. Company to identify the user (or a third subject whom data is supplied by the user), directly or indirectly, including possible information related to the purchase of goods or services, or that the user chooses to disclose to the Company or to share with the Company, or third parts, during the website surfing.
1. CONTROLLER OF THE TREATMENT
We inform that the “Controller” of the treatment is Bonaiti S.p.A., a company with headquarters in via Galileo Galilei 27 – Mestrino 35035 (PD) Italy. The controller can be contacted at the e-mail address email@example.com, or the Certified Electronic Mail firstname.lastname@example.org.
2. TYPE OF TREATED DATA and PURPOSE OF THE TREATMENT
The Company treats some of the personal data of the users who interact with the information systems and software procedures of the website. The Company especially treats navigation data which the IT systems automatically collect during the use of the website, such as the IP address, domain names and type of browsers. This navigation data do not contain any further personal information. This data is used to collect anonymous statistical information on the use of the website, to control the modalities of use of the website, as well as to ascertain responsibility in case of possible computer crimes.
Data supplied voluntarily by the user
The optional dispatching of electronic mail to the addresses indicated in this website entails the acquisition of the sender’s address, and of any other personal data contained in the message. In the pages of the website concerning the services on request there are specific synthetic information documents.
Personal data which are required by the form are processed:
a) With no consent, for the following purposes:
- registration to the website;
- fulfilment of pre-contractual, contractual and fiscal obligations arising from the relationship;
- fulfilment of accounting and fiscal obligations;
- fulfilment of obligations deriving from laws, regulations, EU legislation or order of authorities;
- prevention or discovery of fraudulent activities or damaging abuses to the website;
- exercise of the Controller’s rights, such as defence before the courts.
b) Only with your consent, for the following purposes:
- to send out newsletters;
- to send commercial communications and/or promotional material on products and services offered by the Controller;
- information related to means of payment;
- information on habits and profiling, such as data regarding purchases, information on activities and initiatives related to the management of the relationship with clients, purchase habits and preferences, other information (information on job, education, hobbies, lifestyle) which the applicable law allows to collect.
Your data can be treated also with the purpose of: fulfilling tax and accounting obligations, compliance with obligations of any sort imposed on the Controller of the treatment and required by the applicable law.
3. LEGAL BASE
The users’ personal data is processed if:
- the subject has given consent for one or more purposes, and only in reference to the purposes for which the consent is given;
- the data processing is necessary for the execution of the contract with the subjects.
The personal data collected on the website can be processed by other subjects who are involved in different ways in the company organization, and specially:
- those who have access to, and process, personal data under the controller’s authority (referent/authorized staff);
- natural or legal persons who treat personal data on behalf of the controller (data processing managers).
In any case, the subject can ask the controller for the updated list of the data processing managers, by email.
Except for the above mentioned possibilities, the subject’s personal data shall not be disclosed to third parties, unless:
- the user has given express consent to the disclosure;
- the disclosure is necessary to supply products or services requested by the same subject;
- it is required by the Judicial Authority or by the Public Safety Authorities.
5. DATA PROCESSING METHODS
Personal data isn’t collected with completely automated processes and manually, but the consent of the subject who supplies their data to the form on the website is always necessary.
The website uses some cookies. In the section dedicated to cookies, there is an explanation of what they are and the possibility to disable them.
7. DATA STORAGE
Personal data will be processed and stored for the time period which is necessary to the purpose for which it was collected.
- for the purposes related to the management of the contract: data will be stored for the time period which is necessary to the execution of the service required and, after this, for the time in which the controller is subject to mandatory data retention for tax purposes or other purposes required by law or regulations. Data is stored, anyhow, for the time necessary for the prescription of possible responsibility actions (10 years);
- for marketing and profiling purposes: 48 months from the date of collection, with the possibility for the subject to modify and/or revoke the consent;
- for the newsletter: 48 months from the date of collection, with the possibility for the subject to modify or revoke the consent.
8. SUBJECT’S RIGHTS
The subject has the right to ask the controller if personal data treatment regarding them is underway, and if so, gain access to the following information:
- purpose of the treatment;
- type of data treated;
- recipients of the personal data;
- planned retention period, if possible;
- existence of the right to modify or delete the personal data, or to limit the treatment;
- receive the personal data related to the subject in a structured format of common use and which can be read by automatic devices, and request their transmission to another controller, if this is possible from a technical point of view.
- existence of the right to lodge a complaint to a control authority (personal data protection Authority – www.garanteprivacy.it;
- if the data is not collected at the subject’s place, all the information on the origin;
- if personal data is transferred to a third country or to an international organization, the subject has the right to be informed on adequate safeguards of the transfer.
9. EXERCISING THE SUBJECT’S RIGHT, METHOD
It is at any time possible to exercise one’s rights by sending:
- a registered letter with acknowledgment of receipt to Bonaiti S.p.A. – via Galileo Galilei 27 Mestrino 35035 (PD) Italy
- an e-mail to the address email@example.com
- a certified e-mail to the address firstname.lastname@example.org