PRIVACY POLICY
This privacy policy is intended to inform users of this website about how it is managed with regard to the processing of their personal data, as required by Articles 13 and 14 of European Regulation No. 679/2016 – General Data Protection Regulation. This information notice also respects and fully complies with Recommendation no. 2/2001 that the European authorities for the protection of personal data, brought together in the Group established by Article 29 of Directive no. 95/46/EC, adopted on 17 May 2001 to identify certain minimum requirements for the collection of personal data online and, in particular, the methods, timing and nature of the information that data controllers must provide to users when they connect to web pages, regardless of the purpose of the connection. By consulting this website, data relating to identified or identifiable persons may be processed.
It is specified that the consent mechanisms will be clear, brief and easily understood; if the original conditions for which consent was sought change, for example, if the purpose of the data processing changes, further consent will be required in accordance with European Regulation 679/2016. It is also specified that all consents collected will be the subject of documentation kept separately from any other company documents.
Data Controller
Your personal data will not be disseminated and you are entitled to exercise your rights under Articles 11-20 of European Regulation No. 679/2016 by writing to:
Tarta
Via del Castello, 73
33043 Cividale del Friuli (UD) Italy
Email address of the Data Controller: info@tartadesign.it
The processing operations connected to the web services of this website take place at the aforementioned premises and at the premises of the service provider of the website and are carried out only by the staff of the company, or by any persons appointed to carry out occasional maintenance operations.
Types of Data Collected
Among the Personal Data collected by this Application, either independently or through third parties, are: Cookie, Usage Data, first name, last name and email.
Full details on each type of data collected are provided in the dedicated sections of this privacy policy or by means of specific information texts displayed before the data are collected.
Personal Data may be freely provided by the User or, in the case of Usage Data, automatically collected during the use of this Application.
Unless otherwise specified, all Data requested by this Application are mandatory. If the User refuses to communicate them, it may be impossible for this Application to provide the Service. In the cases in which this Application indicates certain Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or its operation.
Users who may have doubts on which Data are mandatory are encouraged to contact the Data Controller.
The possible use of Cookies – or of other tracking tools – by this Application or by the owners of third-party services used by this Application, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Application and guarantees that he has the right to communicate or disseminate them, releasing the Data Controller from any liability towards third parties.
Method and place of processing of collected data
Data processing methods
The Data Controller adopts appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of Personal Data.
The processing is carried out by means of computer and/or telematic tools, with organisational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other subjects involved in the organisation of this Application (administrative, commercial, marketing, legal, system administrators) or external subjects (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller, may have access to the Data. The updated list of Data Processors can always be requested from the Data Controller.
Legal basis for the data processing
The Data Controller processes Personal Data relating to the User if one of the following conditions exists:
- the User has given consent for one or more specific purposes; Note: in some jurisdictions, the Data Controller may be allowed to process Personal Data without the User’s consent or another of the legal bases specified below, until the User objects (“opts out”) of such processing. However, this does not apply where the processing of Personal Data is governed by European legislation on the protection of Personal Data;
- processing is necessary for the performance of a contract with the User and/or the performance of pre-contractual measures;
- the processing is necessary for the performance of a legal obligation to which the Data Controller is subject;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of public powers vested in the Data Controller;
- the processing is necessary for the pursuit of the legitimate interest of the Data Controller or of third parties.
However, it is always possible to ask the Data Controller to clarify the concrete legal basis of each processing operation and in particular to specify whether the processing is based on law, provided for by a contract or necessary to conclude a contract.
Place
The Data are processed at the operational headquarters of the Data Controller and at any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one where the User is located. For further information on the location of the processing, please refer to the section on details of the processing of Personal Data.
The User is entitled to obtain information on the legal basis for the transfer of Data outside the European Union or to an international organisation under public international law or formed by two or more countries, such as the UN, as well as on the security measures adopted by the Data Controller to protect the Data.
In the event that one of the transfers just described takes place, the User may refer to the respective sections of this document or request information from the Data Controller by contacting him at the aforementioned contact details.
Period of retention
The Data are processed and stored for the time required by the purposes for which they were collected.
Therefore:
- Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the performance of that contract is completed.
- Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User may obtain further information on the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
When the processing is based on the User’s consent, the Data Controller may keep the Personal Data longer until such consent is revoked. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, the Personal Data will be deleted. Therefore, at the end of this period the right of access, deletion, rectification and the right to data portability can no longer be exercised.
Purposes of Data Collection
The User’s Data are collected to allow the Data Controller to provide its Services, as well as for the following purposes: Statistics and Contacting the User.
To obtain further detailed information on the purposes of the processing and on the Personal Data concretely relevant for each purpose, the User may refer to the relevant sections of this document.
Details on the processing of Personal Data
Personal Data are collected for the following purposes and using the following services:
Contact form (this Application)
The User, by filling in the contact form with his/her Data, consents to their use in order to respond to requests for information, quotes or any other nature indicated in the header of the form.
Personal Data collected: surname, email and name.
Mailing list or newsletter (this Application)
By registering to the mailing list or newsletter, the User’s e-mail address is automatically included in a list of contacts to whom e-mail messages containing information relating to this Application, including information of a commercial and promotional nature, may be sent. The User’s email address may also be added to this list as a result of registering with this Application or after making a purchase.
Personal data collected: city, surname, date of birth, email, name and profession.
Statistics
The services contained in this section allow the Data Controller to monitor and analyse traffic data and serve to keep track of the User’s behaviour.
Google Analytics (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google uses the Personal Data collected in order to track and examine the use of this Application, compiling reports and sharing them with other services developed by Google.
Google may use the Personal Data to contextualise and personalise the advertisements of its advertising network.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy (https://policies.google.com/privacy) – Opt-Out. Subject adhering to the Privacy Shield.
Managing contacts and sending messages
This type of service allows us to manage a database of email contacts, telephone contacts or any other type of contact used to communicate with the User.
These services may also collect data about the date and time you view messages, as well as your interaction with them, such as information about clicks on links in messages.
MailChimp (The Rocket Science Group, LLC.)
MailChimp is an email address and message sending management service provided by The Rocket Science Group, LLC.
Personal Data collected: surname, email and name.
Place of processing: United States – Privacy Policy (https://mailchimp.com/legal/privacy/). Subject adhering to the Privacy Shield.
User Rights
Users may exercise certain rights with reference to the Data processed by the Data Controller.
In particular, the User has the right to:
- revoke consent at any time. Users may revoke their consent to the processing of their Personal Data as described above.
- object to the processing of their data. Users may object to the processing of their Data when it is done on a lawful basis other than consent. More details on the right to object are given in the section below.
- access their data. Users have the right to obtain information on what data is processed by the Data Controller and on particular aspects of the processing, as well as to obtain a copy of any data processed.
- verify and request rectification. Users may check that their data is correct and ask for it to be updated or corrected.
- obtain limitation to processing. In certain circumstances, users may ask for restrictions to be set on the processing of their data. In this eventuality, the Data Controller may not process the data for any purpose other than for its storage.
- have their personal data removed or erased. When certain conditions are met, Users may request the deletion of their data by the Data Controller.
- receive the personal data concerning them or transfer it to another Data Controller. Users have the right to receive their data in a structured, commonly used and machine-readable format, where technically feasible, and to have it transferred without hindrance to another Data Controller. This provision is applicable when the data is processed by automated means and the processing is based on the User’s consent, on a contract to which the User is a party or on contractual measures related thereto.
- lodge a complaint. Users may lodge a complaint with the competent supervisory authority responsible for personal data protection, or take legal action.
Details on the right of objection
When Personal Data are processed in the public interest, in the exercise of public powers vested in the Data Controller or in pursuit of a legitimate interest of the Data Controller, Users have the right to object to the processing on grounds relating to their particular situation.
Users are reminded that where their Data is processed for direct marketing purposes, they may object to the processing without giving any reason. To find out whether the Data Controller processes data for direct marketing purposes, Users may refer to the respective sections of this document.
How to exercise rights
In order to exercise their rights, Users may address a request to the Data Controller at the contact details indicated in this document. Requests are filed free of charge and processed by the Data Controller as soon as possible and in any case, within one month.
Further information on data processing
Legal defence
The User’s Personal Data may be used by the Data Controller in legal proceedings or in the preparatory stages for defending against the User’s misuse of this Application or related Services.
Users declare that they are aware that the Data Controller may be obliged to disclose the data by order of public authorities.
Specific information
At the User’s request, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific Services or the collection and processing of Personal Data.
System logs and maintenance
For operational and maintenance purposes, this Application and any third-party services used by it may collect System Logs, i.e. files recording interactions and which may also contain Personal Data, such as the User’s IP address.
Information not contained in this policy
Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the aforementioned contact details.
Response to “Do Not Track” requests
This Application does not support “Do Not Track” requests.
To find out whether any third-party support services have been used, Users are invited to consult the respective privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by informing Users on this page and, if possible, on this Application and, where technically and legally feasible, by sending a notification to Users through one of the contact details held by the Data Controller. Please consult this page regularly and check the date of the latest change, which is indicated at the bottom of the page.
Where changes involve processing on the legal grounds of consent, the Data Controller will seek to obtain the User’s consent again, if necessary.
Last Update: 25 May 2018
Definitions and legal references
Personal Data (or Data)
Given the objective complexity of identification of tracking technologies, Users are invited to contact the Data Controller if they wish to receive further information on the use of such technologies on this Website.
Usage Data
This is personal data collected automatically through the Application (or by third-party applications that it uses), including: IP addresses or domain names of the computers used by Users to connect to the Application, Uniform Resource Identifiers (URIs), time of request, method used to submit the request to the server, size of the file obtained in reply, numerical code indicating status response from the server (successful, error, etc.), country of origin, characteristics of the User’s browser and operating system, various temporal aspects of the visit (for example, time spent on each page) and details of the path followed within the Application, with particular reference to the sequence of pages visited, parameters related to the User’s operating system and IT environment.
User
The individual using this Application who, unless otherwise specified, is the same as the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural person, legal person, public administration and any other entity that processes personal data on behalf of the Data Controller, as set out in this privacy policy.
Data Controller (or Owner)
The physical or legal person, public authority, agency or other body, which alone or jointly with others, determines the purposes and means of personal data processing and the instruments to be used, including any security measures relating to the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.
This Application
The hardware or software tool through which Personal Data of Users are collected and processed.
Service
The Service provided by this Application as defined in the relevant terms (if any) on this website/application.
European Union (or EU)
Unless otherwise specified, any reference to the European Union contained in this document is intended to be extended to all current member states of the European Union and the European Economic Area.
Cookies
A small packet of data stored on the User’s device.
Legal references
This Privacy Policy is drafted on the basis of multiple legislative provisions, including Articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy policy applies exclusively to this Application.