Molino Naldoni’s Privacy Policy
Your privacy and the security of your personal data are very important for us. Therefore, we collect and manage your personal data with the utmost care and take specific measures to keep them safe.
Below you shall find the main information on the processing of our personal data related to your browsing on the website and the use of the services offered. For detailed information on how we handle your personal data, please read our entire Privacy Policy.
Users may be subject to different levels of protection. Some Users therefore enjoy superior protection. Further information on the protection criteria can be found in the applicability section.
Data Controller
Molino Naldoni Srl, Via Pana 156, 48018 FAENZA
Email address of the Data Controller: naldoni@molinonaldoni.it
Types of Data collected
Among the Personal Data collected from this Website, either independently or through third parties, there are: name, surname, company, phone, mail, cookie, Usage data and various types of Data.
Full details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed before the data are collected.
Full details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed before the data are collected.
Unless otherwise specified, all the Data requested by this Website is mandatory for the execution of the services (Contact Request and / or Newsletter Subscription). If the User refuses to communicate them, it may be impossible for this Website to provide the Service. In cases where this Website indicates some Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or on its operation.
Users who have doubts about which data are mandatory, are encouraged to contact the Data Controller.
Any use of Cookies – or other tracking tools – by this Website or by third party service providers used by this Website, unless otherwise specified, is intended to provide the Service requested by the User, in addition the additional purposes described in this document and in the Cookie Policy, if available.
It is specified that, for no reason, the data provided by the user, collected on this site or at the user himself, will be transmitted to third parties for different purposes (e.g. Marketing or commercial communications) from those specified in this statement.
The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Website and warrants that he has the right to communicate or disseminate them, freeing the Data Controller from any liability to third parties.
Mode and place of processing the collected data
Method of processing
The Data Controller takes appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data.
The processing can be carried out both through computer and / or telematics and analogical tools, with organizational methods and with logic strictly related to the purposes indicated.
In addition to the Data Controller, in some cases, other subjects involved in the organization of the Data Controller (administrative, commercial, marketing, legal, system administrators) or external subjects (as suppliers of third party technical services, mail carriers, hosting providers, IT companies, communication agencies) also named, if necessary, Data Processors by the Data Controller.
The updated list of Managers can always be requested from the Data Controller.
Legal basis of the processing
The Data Controller processes Personal Data relating to the User in the event one of the following conditions exists:
- the User has given consent for one or more specific purposes; Note: in some jurisdictions the Data Controller may be authorized to process Personal Data without the User’s consent or another of the legal bases specified below, as long as the User does not object («opt – out «) to this processing. However, this is not applicable if the processing of Personal Data is regulated by European legislation regarding the protection of Personal Data;
- the processing is necessary for the execution of a contract with the User and / or the execution of pre-contractual measures;
- the processing is necessary to fulfil a legal obligation to which the Data Controller is subject;
- the processing is necessary for the performance of a task carried out in the public interest or for the exercise of public authority vested in the Holder;
- the processing is necessary for the pursuit of the legitimate interest of the Data Controller or third parties (e.g. deriving from customer / supplier / partner relationship)
It is however always possible to ask the Data Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on the law, provided for by a contract or necessary to conclude a contract.
Place
Data are processed at the operational headquarters of the Data Controller and in any other place where the parties involved in the processing are located. For more information, contact the Data Controller.
The User’s Personal Data may be transferred to a country other than that in which the User is located. To obtain further information on the processing site, the User can refer to the section concerning the processing of Personal Data.
In the case of further protection, the User has the right to obtain information on the legal basis for the transfer of data outside the European Union or to an international organization of international public law or consisting of two or more countries, such as the UN, as well as about the security measures taken by the Data Controller to protect the Data.
If one of the transfers described above takes place, the User can refer to the respective sections of this document or request information from the Data Controller by contacting him at the contact details above.
Data retention period
Data are processed and stored for the time required by the purposes for which they were collected.
Therefore:
- Personal Data collected for purposes related to the execution of a contract between the Data Controller and the User will be retained until the execution of the contract is completed.
- Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained until such interest is met. The User can obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
When the processing is based on the consent of the User, the Data Controller may retain the Personal Data for a longer period until such consent is revoked. Furthermore, the Data Controller may be obliged to keep Personal Data for a longer period in compliance with a legal obligation or an order of an authority.
At the end of the retention period the Personal Data will be deleted. Therefore, at the end of this term the right of access, cancellation, rectification and the right to data portability can no longer be exercised.
Purposes of the processing of collected data.
The Data concerning the User is collected to allow the Data Controller to provide its Services, as well as for the following purposes:
- Address management and sending of email messages,
- Contact the User,
- Statistics,
- Interaction with social networks and external platforms,
- Interaction with data collection platforms and other third parties,
- Protection from SPAM,
- Data transfer outside the EU and site hosting and back-end infrastructure.
To obtain further detailed information on the purposes of the processing and on the Personal Data concretely relevant to each purpose, the User can refer to the relevant sections of this document.
Details on the processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
Mailing List or Newsletter ( collected through this Website and / or at the user, exhibition or event)
By registering with the mailing list or the newsletter, the User’s email address is automatically added to a list of contacts to which email messages containing information, including commercial and promotional information, relating to this Website may be transmitted. The User’s email address may also be added to this list as a result of registering with this Website or after making a purchase.
Personal Data collected: name , surname, company, phone, email
Contact form (via this Website and / or at the user, exhibition or event)
The User who has filled out the contact form with his own Data both on the site and at the user itself or on other occasions, for example exhibitions or events, consents to their use to respond to requests for information, quotes, or any other nature indicated by the form header.
Personal Data collected: name , surname, company, phone, email,
Contact by phone (via this Website and / or at the user, exhibition or event)
Users who have provided their phone number either on the site or directly by voice or by email, may be contacted for commercial or promotional purposes connected to this Website, as well as to satisfy requests for support.
Personal Data collected: phone number.
- Address management and sending of email messages
This type of service allows you to manage a database of email contacts, phone contacts or contacts of any other type, used to communicate with the User.
These services may also allow us to collect data relating to the date and time the messages are displayed by the User, as well as to the User’s interaction with them, such as information on clicks on the links inserted in the messages.
Responsible for the processing of these services are:
E-MIND Via Ugo Lambertini, 1 Imola
E-MIND is a service that provides domains and management of sending, receiving and storing e-mail
Personal Data collected: E-mail
Place of processing: ITALY –Privacy PolicyMailChimp (The Rocket Science Group, LLC.)
MailChimp is an address management and e-mailing service provided by The Rocket Science Group, LLC.
Personal Data collected: email, name
Place of processing: USA – Privacy Policy.
- Hosting and infrastructure backend
This type of service has the function of hosting data and files which allow Website operation, allow distribution and provide a ready-to-use infrastructure to provide specific features of this Website.
Some of these services work through geographically dispersed servers in different locations, making it difficult to determine the exact location where Personal Data is stored.
OVH
Personal Data collected: Cookies, Usage Data and various types of Data as specified in the privacy policy of the service.
Place of processing: https://www.ovh.it/aproposito/datacenter.xml
- Interaction with data collection platforms and other third parties
This type of service allows Users to interact with data collection platforms or other services directly from the pages of this Website in order to save and reuse data.
In the event that one of these services is installed, it is possible that, even if the Users do not use the service, the same collect usage data related to the pages in which it is installed.
MailChimp widget (The Rocket Science Group, LLC.)
The MailChimp widget allows the User to interact with the email adresses managing and sending MailChimp services messages provided by The Rocket Science Group LLC.
Personal Data collected: name, surname, company, email
Place of processing: United States – Privacy Policy. Person adhering to the PrivacyShield.
- Interaction with social networks and external platforms
This type of services allow to make interactions with social networks, or other external platforms, directly from the pages of this Website.
The interactions and information acquired from this Website are in any case subject to the User’s privacy settings relating to any social network.
If an interaction service with social networks is installed, it is possible that, even if the Users do not use the service, the same collect traffic data relating to the pages in which it is installed.
Facebook Like button and social widget ( Facebook , Inc.)
Facebook «Like button» and social widget are Facebook social network interaction services , provided by Facebook, Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy.
- Protection from SPAM
This type of service analyses the traffic of this Website, potentially containing Personal Data of Users, in order to filter it from parts of traffic, messages and contents recognized as SPAM.
Akismet (Automattic Inc.)
Akismet is a SPAM protection service provided by Automattic Inc .
Personal Data collected: various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
- Statistics
The services contained in this section allow the Data Controller to monitor and analyze traffic data and are used to keep track of User behavior.
Google Analytics (Google Inc.)
Google Analytics is a web analytics service provided by Google Inc . (“Google”). Google uses Personal Information collected for the purpose of evaluating the use of this Website, compiling reports and sharing them with other services developed by Google.
Google may use the Personal Data to contextualise and personalize the advertisements of its advertising network.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy – Opt Out.
- Data transfer outside the EU
The Data Controller may transfer Personal Data collected within the EU to third countries (ie, all countries not belonging to the EU) only in accordance with a specific legal basis. Therefore, such data transfers are performed according to one of the legal bases described below.
The User can request information from the Data Controller regarding the applicable legal basis applicable to each individual service.
Transfer of Data from the EU and / or Switzerland to the United States on the basis of Shield Privacy (this Website)
When this is the legal basis, the transfer of Personal Data from the EU or Switzerland to the United States is based on the Shield EU – US or Switzerland – US Privacy Agreement.
In particular, Personal Data are transferred to subjects who have self-certified themselves under the Shield Privacy Policy and therefore guarantee an adequate level of protection for the Data transferred. The services involved in the transfer of data are listed in the respective sections of this document. Among them, those who adhere to the Privacy Shield can be identified by consulting the relative privacy policy or verifying the status of their registration on the official Privacy list Shield .
Users’ rights under the Privacy Shield are described in an updated form on the website of the United States Department of Commerce. The transfer of Personal Data from the EU or Switzerland to the United States to persons not (more) registered in the Privacy Shield is only admissible under another valid legal basis. The User can request information from the Data Controller regarding the applicable legal basis.
Personal Data collected: various types of Data.
Transfer of Data to countries that guarantee European standards (this Website)
When this is the legal basis, the transfer of Personal Data from the EU to third countries takes place on the basis of an adequacy decision adopted by the European Commission.
The European Commission adopts adequacy decisions with reference to individual third countries which it considers to guarantee a level of protection of Personal Data comparable to that established by European legislation regarding the protection of Personal Data. The User can view the updated list of adequacy decisions on the website of the European Commission.
Personal Data collected: various types of Data.
User rights
Users may exercise certain rights with reference to the Data processed by the Data Controller.
In case of superior protection, the User can exercise all the rights listed below. In any other case, the User can contact the Data Controller to find out what rights are applicable in his case and how to exercise them.
In particular, the User has the right to:
- revoke the consent at any time. The User may withdraw your consent to the processing of your Personal Data previously expressed.
- oppose the processing of his data. The User may object to the processing of your data when it occurs on a legal basis other than consent. Further details on the right of opposition are indicated in the section below.
- access to his data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing and to receive a copy of the Data processed.
- verify and ask for rectification. The User can verify the correctness of his Data and request its updating or correction.
- obtain the processing limitation. When certain conditions are met, the User can request the limitation of the processing of his Data. In this case, the Data Controller will not process the Data for any other purpose other than its conservation.
- obtain the cancellation or removal of their Personal Data. When certain conditions are met, the User may request the Data to be deleted from the Data Controller.
- receive your data or have them transferred to another holder. The User has the right to receive his data in a structured format, commonly used and readable by automatic device and, where technically feasible, to obtain the transfer without obstacles to another holder. This provision is applicable when the Data are processed with automated tools and the processing is based on the User’s consent, on a contract of which the User is a party or on contractual measures connected to it.
- propose a complaint. The User can lodge a complaint with the competent personal data protection authority or act in court.
Details on the right of opposition
When Personal Data is processed in the public interest, in the exercise of public authority to which the Holder is invested or to pursue a legitimate interest of the Data Controller, Users have the right to oppose the processing for reasons related to their particular situation.
Users are reminded that, if their data are processed for direct marketing purposes, they can oppose the processing without providing any reasons. To find out if the Data Controller deals with data for direct marketing purposes, Users can refer to the respective sections of this document.
How to exercise the rights
To exercise the rights of the User, Users can direct a request to the contact details of the Data Controller indicated in this document. The requests are deposited free of charge and processed by the Data Controller as soon as possible, in any case within a month.
Applicability of the upper level of protection
While most of the provisions of this document apply to all Users, some are expressly subject to the applicability of a higher level of protection to the processing of Personal Data.
This higher level of protection is always guaranteed when the processing:
- is performed by a Data Controller located in the EU; or
- concerns Personal Data of Users located in the EU and is functional to the supply of goods or services for consideration or free of charge to such Users; or
- concerns Personal Data of Users located in the EU and allows the Data Controller to monitor the behaviour of such Users to the extent that such behaviour takes place within the Union.
Information security
The Data Controller, in line with the provisions of Recital 49 of the GDPR, treats, also through its suppliers (third parties and / or
recipients), the personal data of the interested party relating to traffic to the extent strictly necessary and proportionate to ensure
network and information security, i.e. the ability of a network or information system to resist, to a
security level, unforeseen events or illicit or malicious acts that compromise availability, authenticity, integrity and
the confidentiality of personal data stored or transmitted.
The Data Controller will promptly inform the Interested parties, if there is a particular risk of violation of their data without prejudice to
obligations deriving from the provisions of art. 33 of the GDPR concerning notifications of violation of personal data.
Cookie Policy
This Website uses cookies. To learn more and to read the detailed information, the User can consult and the cookie policy
More information on processing
Defence in court
The User’s Personal Data may be used by the Data Controller in court or in the preparatory stages of its possible establishment for the defence against abuse of the use of this Website or the related Services by the User.
The User declares to be aware that the Data Controller may be obliged to disclose the Data by order of the public authorities.
Specific information
At the request of the User, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.
System logs and maintenance
For needs related to operation and maintenance, this Website and any third party services used by it may collect system logs, which are files that record the interactions and which may also contain Personal Data, such as the User IP address.
Information not contained in this policy
Further information in relation to the processing of Personal Data may be requested at any time to the Data Controller using the contact details.
Response «Do Not Track” requests
This Website does not support «Do Not Track » requests, ie those that require data collection to be suspended by a user browsing the site.
To find out if any third-party services used support them, the User is invited to consult their respective privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by informing Users on this page and, if possible, on this Website as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details held by the Data Controller. Please therefore consult this page regularly, referring to the date of the last modification indicated at the bottom.If the modifications concern processing whose legal basis is consent, the Controller will collect again the User’s consent, if necessary.
Definitions and legal references
Personal Data (or Data)
It constitutes personal data any information that, directly or indirectly, also in connection with any other information, including a personal identification number, makes a physical person identified or identifiable.
Usage Data
This information is collected automatically through this Website (also from third party applications integrated into this Website). It includes: IP addresses or domain names of the computers used by the User that connects to this Website, the addresses in URI notation ( Uniform Resource Identifier ), the time of the request, the method used in forwarding the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response from the server (good order, error, etc.) the country of origin, the browser and operating system characteristics used by the visitor, the various temporal connotations of the visit (for example the time spent on each page) and details of the itinerary followed within the Application, with particular reference to the sequence of pages consulted, to the parameters related to the operating system and to the IT environment of the user.
User
The individual who uses this Website or otherwise provides data to the Data Controller, unless otherwise specified, coincides with the Data Subject.
The interested party
The interested party is the natural person to whom the Personal Data refers.
Data Processor (or Manager)
The natural person, legal person, public administration and any other entity that processes personal data on behalf of the Data Controller, as set out in the present privacy policy.
The Data Controller of the processing
The natural or legal person, public authority, service or other body which, individually or together with others, determines the purposes and means of the processing of personal data and the tools adopted, including the security measures related to the operation and use of this Website. The Data Controller, unless otherwise specified, is the Data Controller of this Website.
This Website (or this Application)
The hardware or software tool through which the Personal Data of Users are collected and processed.
The Service
The Service provided by this Website as defined in the relevant terms (if any) on this website / application.
European Union (or EU)
Unless otherwise specified, any reference to the European Union contained in this document shall be extended to all current member states of the European Union and the European Economic Area.
Cookie
Small portion of data stored in the User’s device.
Legal references
This privacy statement is drawn up on the basis of multiple legislative systems, including articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy statement applies exclusively to this Website.
Last edit: 25th May 2018