The Company pays the utmost attention to the confidentiality, protection and security of personal data relating to the individuals with whom it comes into contact.
The Personal Data collected will be processed in compliance with the provisions of the combined provisions of national laws in force and the GDPR.
The provision of Personal Data is optional. However, failure to provide the Personal Data deemed mandatory (marked with the * sign) will prevent the proper registration to the Site, as well as the possibility of using the services reserved for registered users, and, in case of purchase, acceptance by the Company of the order proposal and the execution of the related contract.
Categories of personal data being processed
Data provided voluntarily by the User
The access to some sections of the Site and / or the use of some of the services offered by the same can entail a request to the User to provide their Personal Data (as an example and not exhaustive: name, surname, date of birth, postal address, e-mail address, telephone number).
In connection with the Site, the computer systems and software procedures used to operate the Website itself, during their normal operation, may indirectly acquire browsing data of the User, whose transmission is implicit in the use of communication protocols of the Internet (by way of example but not limited to: “IP” addresses, domain names of the devices used by the User accessing the Website, addresses in “URL” notation of the requested resources, time of requests and other parameters related to the operating system and to the User’s IT environment).
This information is not collected to be associated with identified users, but, by their very nature, could, through processing and association with data held by third parties, allow to identify them.
In any case, these data are used for the sole purpose of obtaining anonymous statistical information on the use of the Site, as well as to check its correct functioning. These data are not communicated to third parties or disseminated. Only if there are computer crimes against the Site, navigation data can be used to ascertain the related responsibilities.
The purposes of processing Personal Data may be as follows:
a) allow registration to the Site, necessary for access to particular sections of the same and for the provision of some of the services offered by it;
b) conclude purchase and sale contracts and complete the related obligations, aimed at implementing the contractual relationship established;
c) create professional profiles related to customers or suppliers;
d) fulfill contractual and legal obligations of an administrative nature (for example, accounting and tax obligations) and / or comply with requests of the Judicial Authority;
e) carry out market research, economic analyzes and statistics aimed at verifying the operation of the services offered by the Site and of its approval by the User;
f) to elaborate personalized information about the User’s consumption habits;
g) respond to requests from the User regarding the services offered by the Site;
h) subject to the User’s specific consent and until the revocation of the same, send e-mail newsletter, to inform the User of the promotional, commercial and marketing initiatives promoted by the Company;
i) subject to the User’s specific consent and until revocation of the same, proceed to analysis and profiling of customers, aimed at sending, by e-mail, promotional communications specifically dedicated to the User.
Except as specified with regard to navigation data, the provision of Personal Data collected for the purposes described is not mandatory, but failure to provide, partial or incorrect conferment of the same will make it impossible for the Company to fulfill the services requested by the User .
Personal Data may not be used for other purposes other than those for which it was given by the User.
Methods of processing and storage of data
Personal Data are processed in compliance with the provisions of the GDPR and other applicable privacy regulations.
The treatment is therefore based on the principles of lawfulness, fairness, transparency and will be carried out in compliance with fundamental rights and freedoms, as well as the dignity of the person concerned, with particular reference to privacy, personal identity and the right to personal data protection.
Personal Data collected are processed with the aid of paper and / or computerized procedures.
Appropriate security measures are observed to prevent the loss of such data, illicit or incorrect use and unauthorized access. The Personal Data provided by the User will not be disseminated.
Personal Data are kept for the time strictly necessary for the pursuit of the purposes for which they were conferred by the User, without prejudice to the need for an additional retention period imposed by law to perform contractual, administrative, tax obligations or accounting.
After these terms, the data will be deleted.
Data Controller and Persons authorized to process
The data controller (hereinafter the “Data Controller“) is: Water 22 S.r.l.s. with single shareholder – Via Andrea Maffei 1, 20135 Milan – VAT: 09450960969 – email: firstname.lastname@example.org
Personal Data are processed by the Data Controller and / or personnel properly designated by the Company, appropriately identified, instructed and formally appointed and operating under its direct authority and responsibility, for the sole purpose of satisfying the user’s request for use of the services offered by the Site.
The processing of Personal Data may also be carried out by third parties acting on behalf of the Company, appropriately instructed and appointed as Managers or Trustees of the processing, or, as the case may be, as independent Holders, who will process the data in accordance with the purpose for which they were originally collected.
These third parties may be natural or legal persons, in Italy or abroad, who, on behalf of and / or in the interests of the Company, lend:
assistance and consultancy activities for the Company itself;
specific processing services or related activities, instrumental or support to the pursuit of the purposes indicated above (by way of example and not exhaustively, courier for the delivery of products purchased, Customer Service, analysis and market research service, management of payments by credit card, maintenance of IT systems, etc.).
The updated list of managers appointed by the owner pursuant to art. 28 of the GDPR and of the persons authorized to be processed can be consulted at the Company’s registered office.
Personal Data are processed by the Owner within the territory of the European Union.
If for technical and / or operational reasons it is necessary to make use of individuals located outside the European Union, these will be suitably appointed as Data Processors pursuant to and for the purposes of article 28 of the GDPR and the transfer of Personal Data to such individuals, limited to the performance of specific processing activities, will be regulated in accordance with the provisions of Chapter V of the GDPR.
Also in these cases, all the necessary precautions will be taken to ensure the total protection of Personal Data basing this transfer on the assessment of appropriate guarantees (including but not limited to: adequacy decisions of third country recipients expressed by the Commission European, adequate guarantees expressed by the third party recipient pursuant to Article 46 of the GDPR.)
In any case, it will always be possible to request the most appropriate information from the Data Controller if the Personal Data have been processed outside the European Union, also requesting evidence of the specific guarantees adopted.
The user can exercise at any time the rights referred to in Articles 12 to 22 of the GDPR and those provided for by the applicable national legislation.
In particular, the User may:
obtain access to the following information: indication of the origin of the Personal Data, of the purposes and methods of the processing, of the identification details of the Data Controller and / or of any persons responsible and / or in charge of processing, of the recipients and / or categories of recipients to whom the Personal Data may be communicated or who may become aware of it as appointed representatives in the territory of the State, responsible and / or appointed, of the Treatment, of the retention period of the Personal Data;
request the updating, rectification, integration, portability, deletion, limitation, transformation into anonymous form of the Personal Data processed and be certified that the above operations have been brought to the attention of those to whom the data are been communicated, except in the case in which this fulfillment proves impossible or involves a use of means manifestly disproportionate to the protected right;
to oppose, in whole or in part, for legitimate reasons, to the processing of personal data concerning him/her, even if pertinent to the purpose of the collection, as well as to the sending of advertising or direct sales material or for carrying out market research or advertisement communication.
The User has the right to withdraw the consent to the processing of Personal Data at any time without prejudice to the lawfulness of the treatment based on the consent given prior to the revocation.
For all the aforementioned purposes, the User must send a written request to the Company to the legal e-mail address email@example.com enclosing a copy of an identity document.
The User also has the right to lodge a complaint with the Supervisory Authority of the member state of the European Union in which he / she normally resides, pursuant to art. 77 of the GDPR.