- TO WHOM DOES THIS POLICY APPLY TO?
This policy is applicable to all platform users, regardless of whether they are CARAPELLI customers or not, (hereinafter, and indiscriminately, "user" or "users") who are considered natural persons. As such, when referring to personal data, we refer to all types of information concerning an identified or identifiable natural person. If you are already a CARAPELLI customer, and have signed a contract with us, you must also refer to the information regarding our specific Terms of Privacy contained therein.
- IF YOU NAVEGATE OR USE OUR WEB PLATFORM, WHO IS THE CONTROLLER OF YOUR PERSONAL DATA?
We are your personal data processing controllers, namely: Full name of the Company: CARAPELLI FIRENZE, S.p.A.. Registered Office: Via Leonardo da Vinci n.º 31 – 50028 Tavarnelle Val di Pesa (FI), Italy Physical location/headquaters: Rivas-Vaciamadrid (Madrid), Calle Marie Curie 7, Edificio Beta (Parque Empresarial Rivas Futura), Spain Email address: email@example.com Please send any issue relating to the protection of your personal information to the following email address: firstname.lastname@example.org
- WHAT TYPE OF DATA DO WE PROCESS?
The processing of your data is necessary as it enables you to have access to the contents and/or features of the Platform or to be sent information or to be provided with the services arranged therein, should you so require it. In this regard, we maintain a firm commitment to processing your personal data in a legitimate and consistent manner, pursuant to the principles and legal obligations outlined in current Personal Data Protection Provisions. When you browse our Platform you should be aware of the cookies that are installed on your data terminal or device, since this involves the processing of your personal data, pursuant to the classification of cookies reported and their specific purposes (see our Cookies Policy). When you enter on our Platform for the first time, a Cookies acceptance banner appears with two different options to select one. These options consist on (1) accepting the use of essential cookies (technical cookies which help the platform to work) on your browser or on (2) accepting all cookies used (essential and analytical cookies) on our Platform. By selecting one of the options of the Cookies acceptance banner, you give your explicit consent on the use of those cookies on your browser. Additionally, the banner includes a link to this Policy and to our Cookies Policy, where you can find full information on Cookies used on our Platform and how to configure or delete the use of those Cookies on your browser.
- WHAT DO WE USE YOUR DATA FOR?
- Making it possible for you to browse our Platform, thereby allowing you access to the information and content contained therein;
- Addressing your requests or claims, according to the forms or claims you send to us;
- Clarifying your doubts about our services in a streamlined and efficient way, via the different channels available for this purpose (email, telephone, chat, etc.);
- Allowing and managing your user registration, should you so require it. You can unsubscribe from such registration, whenever you deem fit, by writing to email@example.com.
- Allowing uses associated with the cookies of the Platform, as described in our Cookies Policy;
- Establishing as many applicable protection measures as possible, pursuant to the legal provisions currently in force, including the potential anonymisation of your personal data, which is done by applying the appropriate techniques available to this end. Therefore, in the event, the anonymisation and pseudonymisation processes can also be carried out in order to provide the highest-level of personal data protection;
- Applying the relevant security, technical and/or organisational measures to your personal data, with a view to prevent existing risks at any time, including the pseudonymisation or encryption of your personal data through our Platform.
- WHAT BASIS DO WE HAVE TO PROCESS YOUR PERSONAL DATA LEGITIMATELY?
|Processing purposes||Legitimate processing basis|
|Make it possible for you to browse our Platform, thereby allowing you access to the information and content contained therein.||Your consent and, as the case may be, satisfaction of a legitimate interest, be it our own or of third parties, associated with the adequate management, maintenance, carrying out and evolution of the platform, its tools, network and associated information systems, which enabling proper functioning thereof, as well as the features contained therein, access to its content and services, and the general security of all the aforesaid.|
|Address the requests or claims, according to the forms or claims you send to us;||Your consent.|
|Solve your doubts about our services in a streamlined and efficient way||Your consent and, as the case may be, the carrying out of pre-contractual measures at the request of the user/interested party.|
|Allow and manage your registration as a user, should you require it.||Your consent.|
|Should you accept the use of analytical cookies on our Platform by accepting our Cookies acceptance banner, , you thus accept the processing procedures associated therewith to be carried out and, thus, agree to the carrying out of the relevant analysis derived from your web browsing for analytical and/or statistical purposes.||Your consent.|
|Establish as many applicable protection measures as possible, pursuant to the legal provisions currently in force, including the pseudonymisation or anomysation of your personal data through our platform||Compliance with the legal obligations set forth in REGULATION (EU) 2016/679, of the European Parliament and of the Council, of 27th April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter, "General Data Protection Regulation" or "GDPR"). In the case of processing data designed to guarantee the protection of the platform, the web, and information systems associated therewith, where appropriate, this is done in order to satisfy the legitimate interests of CARAPELLI or, where appropriate, of a third party (Recital 49 of the GDPR).|
|Apply the relevant security, technical and / or organisational measures on your personal data with a focus on the existing risk at each moment||Compliance with the legal obligations set forth in REGULATION (EU) 2016/679,of the European Parliament and of the Council, of 27th April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter, "General Data Protection Regulation" or "GDPR") In the case of processing data to guarantee the protection of the platform, the web, and information systems associated therewith, where appropriate, this is done in order to satisfy the legitimate interests of CARAPELLI or, where appropriate, of a third party (Recital 49 of the GDPR).|
When you give consent for your personal data to be processed, with the aforesaid legitimate processing basis, we remind you that you have the right to revoke your consent at any time, free of charge, by simply sending an email to firstname.lastname@example.org.
- HOW LONG ARE YOUR PERSONAL DATA STORED?
|Personal data associated with the processing purposes reported||Personal Data storage periods or criteria|
|Address requests or claims according to the forms or claims you send us.||-The amount of time required to correctly respond to your requests and/or specific claims according to each case.|
|Solve your doubts about our services in a streamlined and efficient way||-The amount of time that is strictly required to resolve or process the aforementioned requests and/or specific claims.|
|Allow and manage your registration as a user if you require it.||-Until you request the effective withdrawal of your registration. If you are a CARAPELLI customer, the personal data retention periods described in these cases may be applied as indicated below.|
|Establish as many measures of protection are applicable in accordance with current legal provisions.||The user’s personal data are processed, including the storage of such data for the legal terms set out regardless of the legitimate processing basis for CARAPELLI.|
|Apply relevant security, technical and/or organisational measures to your personal data, with a view to prevent existing risks at any time.||The user’s personal data are processed, including the storage of such data during the legal terms outlined, regardless of the legitimate processing basis for CARAPELLI uses.|
In any case, and notwithstanding the foregoing, the user is also informed of the following:
- Pursuant to current Personal Data Protection Legal Provisions, in any matter concerning the correct processing of personal information by CARAPELLI, the Company may also securely store this information for three years from its collection (prescription period for breaches in this sphere);
- Regarding the storage time of cookies, the user is advised to consult our Cookies Policy (see the section regarding the permanence of cookies);
- In general, when the personal data are no longer necessary for the processing purposes that they were collected for, the aforesaid data shall be blocked, and shall only remain available to the competent authorities responsible for the possible determination of legal responsibilities during the processing thereof, always pursuant to the applicable legal provisions and the aforesaid data cannot be used for any other purposes. After the corresponding legal deadlines have elapsed, in case of data blockage, the relevant personal data shall be erased pursuant to the applicable legal provisions, and may also, if applicable, be securely anonymised by CARAPELLI (anonymised/non-personal data).
- WHAT CONSEQUENCES SHALL ENSUE IF YOU DO NOT PROVIDE US WITH YOUR PERSONAL DATA?
We try to request or use the minimum amount of essential information when processing personal data, as may be necessary to carry out the purposes of our Corporate object and purposes. All this pursuant to the applicable legal provisions. However, if you fail to provide your personal data this could lead to the impossibility to: 1) use our website properly (non-acceptance of technical or session cookies); 2) access certain content or services; 3) process your requests or specific claims (for example, due to the lack of information or insufficient completion of the corresponding form or application). The information and personal data that you provide, according to each case, must be in any event:
- Sufficient, although adjusted, limited and proportionate to the legitimate purposes of processing reported in each case, with the utmost respect for the principles of purpose limitations and of minimisation of personal data;
- Accurate, up-to-date and truthful, in order to be able to adequately verify the identity, legal capacity and, where appropriate, representation, as well as being able to apart, in each case, the data processing tailoring it to your specific needs and your current situation. This is done pursuant to principles of personal data accuracy.
Users shall be fully responsible for all data and personal information that they provide to the Client, within the platform and, where appropriate, for demanded or contracted services.
- DO WE SHARE YOUR PERSONAL DATA WITH THIRD PARTIES?
In general, we neither sell, offer nor share your data with third parties. Notwithstanding, your personal data may be shared with other companies in the Group of Companies to which CARAPELLI belongs for purely internal and administrative purposes in accordance with the provisions of Recital 48 of the RGPD. Similarly, it is possible that certain third parties can access your personal information when carrying out the services they provide to CARAPELLI. For example, in the case of third party cookies that are applied in the platform (see our Cookies Policy). CARAPELLI has several personal data processors under its supervision, and, acting as trusted providers, they are allowed access to the aforesaid data only on strictly need- to know basis for the provision of the services contracted with them. Such data processors operate under a service contract that complies with the terms, conditions and guarantees set forth in Article 28 of the GDPR, with CARAPELLI carrying out the controls, inspections and corresponding audits in this area to verify that the aforesaid processors strictly comply with the contracts signed to this end, and with the applicable legal provisions.
- ARE INTERNATIONAL TRANSFERS CARRIED OUT WITH YOUR PERSONAL DATA?
We inform you that, in general, international transfers of your personal data are not expected, and CARAPELLI uses the necessary measures and guarantees in this area with pursuance to the current Personal Data Protection legal provisions. Notwithstanding the foregoing, our Cookies Policy informs you of possible international transfers of personal data, pursuant to the services provided by certain companies (third-party cookies). All international transfers are fully guaranteed pursuant to the applicable legal provisions (see our Cookies Policy).
- WHAT RIGHTS DO YOU HAVE, WHAT DO THEY MEAN AND HOW CAN YOU EXERCISE THEM?
|Your rights||What does it mean?||How can it be exercised?|
|Right of information||The right to be provided by CARAPELLI with appropriate information, both when your personal data have been collected (whether obtained from you or through a third party), or later regarding the processing of your personal data. You decide on your personal information. Refer to Articles 12 to 14 of the GDPR.||CARAPELLI seeks to provide you with all the necessary information regarding the processing of your personal data pursuant to Articles 12 to 14 of the GDPR. However, if you have any question or doubt about our privacy policies and cookies, please do not hesitate to write to us, via: email@example.com and we shall address your additional request for information.|
|Right of access||The right to obtain from CARAPELLI confirmation of whether or not your personal data are being processed, and basic information related to such processing (Article 15 of the GDPR), as well as to obtain a copy of the personal data that are being processed.||Address a communication in writing via email to firstname.lastname@example.org with the Ref. "Exercising of Rights" accompanying the email your registration email and, if necessary, to prove your identity, including a copy of your national identity document or equivalent identification document (passport, NIE etc.).|
|Right of rectification||Right to obtain the rectification of your personal data, without delay, by CARAPELLI pursuant to Article 16 of the GDPR.||Address a communication in writing via email email@example.com with the Ref. "Exercising of Rights" accompanying the email your registration email and, if necessary, to proving your identity, including a copy of your national identity document or equivalent identification document (passport, NIE, etc.).|
|Right of erasure||Right to obtain the erasure of your personal data, without undue delay, by CARAPELLI pursuant to the terms of Article 17 of the GDPR.||Address a communication in writing via email firstname.lastname@example.org with the Ref. "Exercising of Rights" accompanying the email your registration email and, if necessary, to proving your identity, including a copy of your national identity document or equivalent identification document (passport, NIE, etc.).|
|Right to limitation of processing||The right to secure the limitation of the processing of your data from CARAPELLI, if: - The accuracy of your personal data is affected, during a period that allows CARAPELLI to verify their accuracy. -The processing of your personal data is unlawful and you object to their suppression (and instead, request the limitation thereof). -CARAPELLI no longer needs your personal information, but you need it in order to formulate, carry out or defend a claim. The carrying out thereof shall be limited to what is outlined in Article 18 of the GDPR.||Address a communication in writing via email email@example.com with the Ref. "Exercising of Rights" accompanying the email your registration email and, if necessary, to proving your identity, including a copy of your national identity document or equivalent identification document (passport, NIE, etc.).|
|Right to data portability||Right to receive any personal data referring to you and which you have provided us in a structured format, for common use and systematic reading, or to transmit them to another controller when technically possible pursuant to the provisions of Article 20 of the GDPR.|
|Right of objection||Right to object to, at any time, the processing of your personal data, including profiling, if this is based on the satisfaction of the legitimate interest of CARAPELLI or a third party as described under Article 21 of the GDPR.|
|Right not to be the subject of a decision based solely on automated processing (including profiling)||The right not to be the subject of a decision based solely on automated processing, including profiling, that produces legal effects or significantly affects you in a similar way, pursuant to the provisions of Article 22 of the GDPR.||Address a communication in writing via email firstname.lastname@example.org with the Ref. "Exercising of Rights" accompanying the email your registration email and, if necessary, to proving your identity, including a copy of your national identity document or equivalent identification document (passport, NIE, etc.). .|
|Right to revoke the consent granted||You shall have the right to withdraw your consent at any time. Revocation of consent shall not affect the lawfulness of the processing performed by the Client based on your consent prior to the withdrawal thereof.||You communicate this by sending an email to: email@example.com so that your right can be duly implemented, as laid out in the applicable legal provisions.|
|Right to file a claim with the competent supervisory authority||It implies the possibility of recourse to the control authority in case you believe of your rights to the protection of personal data have been breached (Articles 13 and 14 of the GDPR)||We recommend that before submitting any complaint or claim to the French Commission Nationale de l'Informatique et des Libertés (CNIL), you kindly contact us to analyse the specific situation and try, if necessary, to find an effective and amicable solution. The aforesaid notwithstanding, if you wish, you can also refer to the web page of the Commission Nationale de l'Informatique et des Libertés https://www.cnil.fr/en/home|
- ARE MEASURES FOR THE SECURITY AND PROTECTION OF YOUR PERSONAL DATA IMPLEMENTED?
Taking into account the nature, scope, context and the purposes indicated of the data processing, as well as the wide variety and gravity of the possible risks that might affect your rights and freedoms, CARAPELLI applies (and shall apply) the appropriate technical and organisational measures in order to guarantee the due security and protection of your personal data, pursuant to privacy criteria imbedded in the design and by default, as well as by applying a system to approach concurrent risks, which shall be reviewed and updated by CARAPELLI if and when necessary. The use of the Hyper-Text Transfer Protocol (HTTPS) in our platform is a reinforced guarantee for the security of your personal data.
- DO YOU NEED TO CONTACT US?
- COMPETENCE AND APPLICABLE JURISDICTION