PRIVACY POLICY FOR ITALIACOLLEZIONA.COM (REV. 23/12/2019)
General information
This document describes the purposes and methods of the processing of personal data of users and/or visitors to the website https://www.italiacolleziona.com/ (hereinafter referred to as the “Website“). The document does not apply to the processing of personal data carried out on other websites that may be consulted by the user via links present on the Website. This is a document of a general nature that provides information about the criteria for the correct processing of personal data carried out on or through the Website.
Pursuant to the articles, regulations, and norms (Italian and European):
- Art. 13 of Legislative Decree no. 196/2003 containing the “Personal Data Protection Code“;
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data;
as data controller, you are informed that the acquired personal data with reference to the relationships established will be subject to processing in compliance with the regulations referred to and cited above. The processing of data is carried out in compliance with the rights of fundamental freedoms, as well as the dignity of the data subject, with particular reference to confidentiality, personal identity, and the right to the protection of personal data. Pursuant to the aforementioned rules, therefore, we provide you with the following information.
Navigation data
The computer systems and software procedures used to operate the Website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected to be associated with identified data subjects, but which by its very nature could, through processing and association with data held by third parties, allow users to be identified.
This category of data includes IP addresses or domain names of computers used by users connecting to the Website, the URI (Uniform Resource Identifier) notation addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.), and other parameters relating to the user's operating system and computer environment.
These data are used for the sole purpose of obtaining anonymous statistical information on the use of the Website and/or to check its correct functioning. The data could be used to ascertain responsibility in the event of hypothetical computer crimes against the Website: except for this possibility, web contact data are not permanently stored, unless requested by the user, such as: access to their own pages on the Website summarizing the services used, information requested, etc.
Sensitive data
The Website does not request or collect sensitive personal data from users and/or visitors, such as information suitable for revealing:
- racial or ethnic origin;
- political, philosophical or religious beliefs;
- sexual habits;
- health data.
Data processing methods
The processing of data will take place using suitable tools to guarantee security and confidentiality and will be carried out through automated tools (IT, electronic, telematics) designed to store, manage, and transmit the data themselves.
The data will be processed in the following ways:
- Data collection via Single-Opt-in mode;
- Data collection via Double Opt-in mode;
- Organization of archives in automated form.
Specific security measures are observed to prevent data loss, illicit or incorrect use, and unauthorized access. To learn more about the topic of security, it is recommended to continue reading the policy.
Data scanning and verification
The Website data: articles, pages, images or any other form of content present in the Website's web space, are subjected to regular daily antivirus/malware scanning.
Furthermore, after the update phases of the various Website components (especially the more demanding ones), all the functionalities offered by the Website are re-verified to prevent any potential incompatibilities, crashes, or problems arising during the update phases. Should these events occur, the non-functioning or incompatible component will be deactivated until the problem is resolved, or directly replaced with another version.
All this is to keep the navigation component as secure as possible for users and/or visitors of the Website, as well as to preserve and protect the data themselves, and to prevent attacks on the Website's infrastructure.
Data backup
Just as scans are performed for security, data is subjected to an automatic daily backup to prevent any loss of Website content. In addition, an extraordinary overall backup (database, software components, etc.) is carried out, especially in anticipation of important updates and/or prior to the cleaning and optimization of the Website's databases and files.
The backups are archived in the web space of the Website for a total of 30 days: once this time has elapsed, the oldest ones are automatically deleted to be replaced by the most recent ones.
Data retention period
CONTACTS:
If you use the contact form, the data sent through it are retained for an indefinite period.
COMMENTS:
If you leave a comment, the comment and its metadata are retained for an indefinite period.
NEWSLETTER:
If you subscribe to the Website's newsletter, the data are retained for an indefinite period. This is how the Website is able to recognize and send newsletters to registered users and/or visitors.
Data retention period [Third party]
GOOGLE ANALYTICS:
The analysis and statistical data acquired by Google Analytics are retained for 14 months.
Data analysis and statistics
The Website uses the analysis and statistics system offered by Google Analytics, with an adjustment of the tracking code to make the IP address anonymous for users and/or visitors of the Website during navigation.
Checking the acceptance checkbox
In any form that requests personal information from the user and/or visitor, the checkbox for acceptance of the processing of personal data is not checked by default.
This is because default consent is not considered valid and adequate under current personal data protection standards, in addition to the matter of transparency demonstrated towards users and/or visitors.
It must be the user and/or visitor who validates the box, on their own initiative and in an explicit manner before sending the data. If the user and/or visitor does not check the validation box, they will not succeed in the data submission operation.
Encrypted connection with https protocol
As a further security measure, the Website has been completely migrated to the https:// version, thus with a secure and encrypted connection. Each page has been optimized and made 100% in https, avoiding mixed content. Every present and future resource will open directly in https.
This can be verified by the presence of the lock icon located next to the website URL in the address bar, present in all web browsers: both mobile and desktop.
Purposes of processing and mandatory or optional nature of providing data
The mandatory data will be appropriately highlighted with a specific wording or symbology. Failure to provide them could solely result in the impossibility of obtaining what was requested. Users and/or visitors will also be free to optionally provide their personal data. Failure to provide them does not affect the success of what was requested, as they are in addition to the mandatory data. Data may be collected for one or more of the following purposes:
|
Related to |
Function |
Mandatory nature |
Optional nature |
Opt-in / Data submission |
Retention period |
|
Contacts |
Contact |
Name – Email of the user and/or visitor |
Direct submission of data with explicit |
Indefinite |
|
|
Comments |
Comment |
Name – Email of the user and/or visitor |
Country and/or City of the user and/or visitor |
Direct submission of data with explicit |
Indefinite |
|
Comments |
Be notified via email |
Email of the user and/or visitor |
Direct submission of data with explicit |
Indefinite |
|
|
Newsletter |
Subscribe to the newsletter |
Email of the user and/or visitor |
Name of the user and/or visitor |
Double Opt-in |
Indefinite |
|
Newsletter |
Be notified via email |
Email of the user and/or visitor |
Name of the user and/or visitor |
Double Opt-in |
Indefinite |
Information and resources on Plug-ins and web hosting
In this section of the policy, all information relating to data processing regarding the Plug-ins with which it is possible to interact and the web hosting service will be listed.
Social Share Buttons
The Plug-in does not collect any personal data from users and/or visitors.
Newsletter
The Plug-in collects personal data as described on this page.
Ergonet
The web hosting service Ergonet has its own privacy policy.
Personal data of third parties
The user and/or visitor of the Website acknowledges and accepts that any indication of personal data of any third party represents a processing of personal data with respect to which they themselves act as an independent Data Controller, assuming all obligations and responsibilities provided for by current regulations regarding the processing of personal data.
In this sense, the user and/or visitor guarantees to the Website owner that any data of third parties that will be so indicated by the user and/or visitor (and which will consequently be processed as if the third party had provided their own informed consent to the processing) has been acquired by the user themselves in full compliance with current regulations.
On this point, the user and/or visitor grants the broadest indemnity with respect to any dispute, claim, and/or request for compensation for damage from processing that may reach the Website owner from any interested third party, due to the provision of the data indicated by the user in violation of the applicable rules on the protection of personal data.
Entities to whom data may be communicated
The collected data will in no way be communicated to third parties, but by their very nature could, through processing and association with data and/or systems held and managed by third parties, allow users and/or visitors to be identified.
The comments of users and/or visitors may be checked through an automated spam detection service.
Breach notification
By breach notification is meant the procedure that occurs if the data processor or data controller ascertains the loss, misplacement, and/or undue disclosure of data due to a cyber attack or unauthorized access to the Website.
Should this inconvenience occur, a page or other suitable tool to notify users will be promptly established within this Website, containing the notice regarding the loss or disclosure of data.
Rights of data subjects
The individuals to whom the personal data refer have the right at any time to request to receive an exported file from the Website containing their personal data, including the data provided to us. They can also request the deletion of all personal data concerning them. This does not include data that the Website is obliged to keep for administrative, legal, or security purposes. Below are the operations:
- obtain confirmation as to whether or not the data exist;
- know their content and origin;
- verify their accuracy;
- request their integration or update;
- request their portability;
- request their rectification;
- request their deletion;
- request their transformation into anonymous form;
- request their blocking;
- object in any case, for legitimate reasons, to their processing.
The operations mentioned above can be carried out via a specific button (Delete my data / Download my data) by accessing the personal page on the Website.
Data Controller and Data Processor
The Data Controller is the website www.italiacolleziona.com.
The person responsible for the exercise of rights and responding to the data subject is Mr. Vincenzo Masselli, who also indicates the following email address: info@italiacolleziona.com.
For any request of yours relating to clarifications, information, or the exercise of the rights recognized under the regulations cited above, please send an email to the address indicated above, or alternatively use the contact form.
References on pages
This page is visible via a link at the bottom of all pages of the Website.
Sources used
Italian Data Protection Authority (Garante per la protezione dei dati personali)
- Home page of the Italian Data Protection Authority
- Personal Data Protection Code – Art. 13 of Legislative Decree no. 196/2003
EUR-Lex