Updated: October 9, 2018
The following summary provides you with a quick overview of the processing activities that are undertaken on our website. You will find more detailed information under the indicated sections below:
We will only use the personal data gathered on this website or the services provided (hereinafter collectively referred to as the “Platform”), as set out in this policy, specifically, from any computer, application, mobile device, platform or any other mode of access.
Below you will find information on how we use your personal data on the Platform, for which purposes your personal data is used, with whom it is shared and what control and information rights you may have.
The General Data Protection Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, in particular articles 13 of the Regulation, (hereinafter referred to as the 'Regulation' and/or ‘GDPR’)) aims to ensure that data processing is carried out in respect of fundamental rights and freedoms, as well as the dignity of individuals, with specific regard to confidentiality and personal identity.
We strongly advise you to read the privacy policies of any third party sites you may visit to see how your personal data is treated.
In this regard, we cannot be held liable for the possible management of personal data by third-party websites and for the management of login credentials provided by third parties.
Fondazione Golinelli, with registered office in Bologna (BO), Via Paolo Nanni Costa n. 14, with fiscal code 03939010371, email address: firstname.lastname@example.org (hereinafter referred to as the Data Controller) – is the Data Controller of the personal data disclosed on the Platform.
You may contact us by sending an email to email@example.com.
When you visit our Platform for informational reasons without setting up an account, only limited personal data will be processed to provide you with the Platform itself. In case you register for one our services or subscribe to our newsletter, further personal data will be processed in the scope of such services.
In particular, we may process your data according to the following:
This is all personal data that you freely give us on the Platform, for example, by requesting information about a particular service using a form, or by writing to one of our e-mail addresses. Your personal data will not be disclosed to third parties, nor will it be used for profiling for behavioral advertising.
The processing of this personal data will be carried out solely for the purpose of responding to your request.
Data provided voluntarily may be:
• information concerning how the Platform is being used
• information such as name, telephone number, email address or information voluntarily disclosed using a form present on the Platform
• information provided upon subscribing to the newsletter, as well as browsing data while using the Platform, including technical/computer data that may be processed for non-identifying profiling purposes collected by cookies
• contact details such as name, telephone number, email address disclosed for the purposes of using specific services or event registration
The legal basis for this processing is Art. 6 sec. 1 sent. 1 lit. of GDPR and represents our legitimate interest (Art. 6 sec. 1-f of GDPR).
Some of the services provided on our Platform require you to set up an account. With regard to the registration of an account and its subsequent use, we process:
• your name
• your email address
• language/s spoken
• your fiscal code
• your telephone number
• your home address
Your account retains your personal data for future activities or services provided on the Platform. Where requested, you will have to provide a username and password to access the Platform. You can delete the personal data as well as the account in your account’s settings. This processing is based on Article 6 sec. 1 sent. 1 lit. b.
HOW WILL YOUR DATA BE USED?
After receiving your consent, the data required to access our services with the account you have set up on the Platform will be used for the following activities:
• to invoice requested services or products that require payment
• for all purposes set out in successfully providing the services we offer on our Platform
You will not be able to use the services offered on our Platform if you do not disclose the required data.
We will also use your data:
• only if you provide specific consent by checking the item “I consent to the processing of my personal data for advertising and direct/indirect marketing purposes” – to send you updates regarding our activities, namely services and events, surveys and/or opinion polls and other types of communication related to services and the processing of statistical research studies – and present ads that meet your interests.
This processing is based on Article 6 sec. 1 sent. 1 lit. f GDPR and represents our legitimate interest to improve your website experience and to promote our products and services.
Your consent to this type of data processing is optional (and completely amendable even after giving your consent, by simple request to firstname.lastname@example.org or different modes indicated by the Data Controller). Please be aware that a withdrawal of your consent to this type of data processing does not affect access to our Platform and related services.
The computer systems and software procedures used to operate the Platform acquire, during their normal operation, some personal data whose transmission is inherent in the communication protocols of the Internet.
This category of data includes:
• IP addresses
• type of browser used
• operating system
• domain name and addresses of websites from which access or exit has been made
• information on the pages visited by users within the website
• access time
• stay duration on the individual page
• analysis of the internal path and other parameters regarding the operating system and computer environment
The legal basis for this processing is Art. 6 sec. 1 sent. 1 lit. f GDPR and represents our legitimate interest to analyze our website’s traffic to improve the user’s experience and to optimize the website in general.
HOW WILL YOUR DATA BE USED?
We collect your browsing data solely for the purpose of obtaining anonymous statistical information in regards to how the Platform is being used in order to improve its performance. However, because of the nature of the data collected, along with data collected by third parties, it may be possible to determine your identity.
HOW WILL YOUR DATA NOT BE USED?
Your browsing data will, under no circumstances, be used for behavioral advertising or profiling, market research studies or commercial purposes – and will only be kept temporarily for the purposes set out above.
If you do not provide us with the necessary information required to subscribe to our newsletter, we will not be able to provide the service. The legal basis for this processing is Article 6 sec. 1 sent. 1 lit. a GDPR.
We ensure that all data collected via the Platform will be solely processed to provide you with the requested services and to improve and optimize your experience on our Platform.
The Platform is not directed at persons under 18 years of age and our content and other services are not written, intended, or designed for persons under 18 years of age. We do not intend to collect any personally identifiable information from such individuals. By law, only a parent or guardian of persons under 18 years of age can provide consent to have their data processed.
The processing of the personal data you have disclosed is carried out mainly using procedures and electronic media for the time strictly necessary. Personal data will be processed by the data controller to the extent strictly needed for the pursuit of the main purpose. In particular, personal data will be processed for a period of time equal to the minimum necessary required by law.
Your data will not be disseminated or distributed to any external entities, without prejudice to obligations imposed by statutory requirements.
Your personal data may be also shared with:
• subjects, public and private individuals that, if strictly determined by law, will be able to access the data under legal provisions, within the limits provided by the same regulations (including but not limited to: tax authorities, etc.)
• subjects who need to access your data to conduct ancillary activities for the relation between the Data Subject and the Data Controller, within the limits strictly necessary to carry out the ancillary tasks entrusted to them
• appointed personnel of the Data Controller, who have the duty of confidentiality and security of the processing of personal data
• any supplier of the Data Controller, with whom it may establish relations for the administration, communication or management of the working relationship
In any case, your personal data will not be subject to dissemination, and will only be shared as indicated above.
You may request the full list of data processors at any time by sending us an email to email@example.com.
Your personal data is stored within the European Economic Agreement (EEA), specifically in servers located in Italy.
Within the scope of our information sharing activities, your personal data may be transferred to other countries (including countries outside the EEA) which provide an adequate level of data protection.
We have reasonable state of the art security measures in place to protect against the loss, misuse and alteration of personal data under our control, we also perform the periodic backup of stored information, to protect the integrity and confidentiality of your data.
We strive to keep our processing activities with respect to your personal data as limited as possible, retaining your personal data only for as long as required by statutory retention requirements.
Your personal data will thus be retained, as provided by law, for a period of time not exceeding which is necessary to achieve the purposes for which they are processed, in particular:
• the collected data shall be retained only for as long as strictly necessary for the management of the above mentioned purposes
• the collected data you have provided for services that require registration, including the newsletter, shall be retained for as long as registration and subscription to such services are maintained active
• the collected data, contingent upon your freely given consent to the specific option of processing your data for advertising and direct/indirect marketing purposes, shall be retained only as long as is strictly necessary for the management of the above mentioned purposes. In the absence of specific rules providing for different periods of time regarding data retention, and without a newly freely given consent by you within the following deadlines, the collected data shall be used for advertising and direct/indirect marketing purposes for a maximum period of 24 months and then subsequently deleted
All care will be applied to avoid an excessive retention of your data, proceeding periodically to verify your interest and consent to process your data only for related promotional purposes via automated delivery system such as an email.
As data subject, you have the right to request that it be corrected and updated, if incomplete or incorrect, request its cancellation if it was collected in violation of a law or regulation, as well as oppose processing for legitimate and specific reasons.
In particular, below is a list of all the rights that can be exercised, at any time:
• Right of access: the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed.
• Right to rectification: the right to obtain the rectification of inaccurate personal data concerning him or her.
• Right to erasure: the right to obtain the erasure of personal data concerning him or her without undue delay, where applicable grounds apply under the Regulation
• Right to restriction of processing: the data subject has the right to obtain the restriction of processing, where applicable grounds apply under the Regulation.
• Right to data portability: the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided.
• Right to object: the right to object at any time to the processing of his or her personal data if they are processed for purposes of direct marketing, including profiling to the extent that it is related to such direct marketing.
AUTOMATED DECISION MAKING
We do not use your personal data for automated decision making which produces legal effects concerning you or similarly significantly affects you (unless such activity is necessary to conclude and execute an agreement between you and the Data Controller, is authorized by Union or Member State law) – or is based upon your explicit consent.
You may exercise the above mentioned rights at any time by submitting a simple request to firstname.lastname@example.org or to the physical address indicated in the paragraph Data Controller.
We will contact you as soon as possible, within 30 (thirty) days from the date of your request.
If you believe that the personal data protection legislation has been violated with regard to the processing of your data, you also have the right to lodge a complaint before the local authority for the protection of personal data within the European Economic Area. You may find the references of the individual authorities, depending on the country where you are located, by clicking on this link http://www.garanteprivacy.it/web/guest/home/footer/link.