Paolo Scafora SRL and FILOBLU S.p.A.
Paolo Scafora SRL (hereinafter “Paolo Scafora”) and FiloBlu S.p.A. (hereinafter “FiloBlu”), are concerned about protecting your personal data and respecting your privacy.
Here is how we do it:
Our duty and your privacy:
This information concerns you if you are already a customer of ours, if you are registered on our site, if you have signed up to our newsletter, or if you are visiting our website.
TABLE OF CONTENTS:
- About us
- Our responsibility
- Your commitment
- When and how we collect your personal data
- The kind of data we collect
- What we collect your data for
- Use of the site and management of services
- Customer support
- What we mean by legal basis
- How we process your data
- Your choices and rights
- Where your data is kept
- How long we keep your data for
- Third parties who may process your data
As regards the management of your data concerned with registering with the site and the sale of products, the data controllers are Paolo Scafora Tax ID Code/VAT No. 05051861218, with registered offices in Via Tavernola, 8, 80025 Casandrino (Napoli), Italy and FiloBlu, Tax ID Code and Vat No. 04274870288 with registered offices in Santa Maria di Sala (Ve) Via Caltana 116/c - Italy, which jointly handle your data on the basis of specific agreements about whose essential contents we will gladly provide you with more information, should you require it.
As regards the management of your data regarding promotional and marketing activities, the data controller is Paolo Scafora which avails itself of Filoblu as the processor of these operations.
If you are already a customer, you are registered with or are simply visiting the https://www.paoloscaforanapoli.com site, or you have signed up to our newsletter, we inform you that your data will be legitimately processed according to our decisions regarding the procedures and aims of that processing.
We would only ask you to read this policy carefully in order to be fully informed about how we process your personal data.
When and how we collect your personal data:
As soon as you begin to interact with https://www.paoloscaforanapoli.com/, we start to collect your data. It may be collected through a specific communication from you and also automatically during your use of the website.
This is how it is collected:
DATA YOU PROVIDE US WITH
DATA WE COLLECT AUTOMATICALLY
Your identification data (first name, surname, date of birth, address and email)
Browsing the website
Your telephone number
X (only if provided by you spontaneously)
Use of https://www.paoloscaforanapoli.com/
Conclusion of purchase orders
X (only the order number)
Marketing communications (newsletter, etc.)
X (only following your explicit consent)
The kind of data we collect:
Your first name and surname, delivery and billing address, telephone number, email address;
Your IP address, your login data, browser type and version, time zone setting, plug-in types, geopositioning information regarding your probable position, operating system and related versions, etc.
Data relating to the use of https://www.paoloscaforanapoli.com/
Your browsing path through the website https://www.paoloscaforanapoli.com/ (Clickstream analysis), your displaying of products and services, load times and page responsiveness, download errors, browsing time, behaviour and other actions, etc.
And what about sensitive data?
We do not collect any sensitive data that could concern you (i.e. personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or sex life or sexual orientation).
What we collect your data for
We process your data only for specific purposes and, nevertheless, always when there is a legal basis that will enable us to do so. Here is why we process your data:
Use of the site and management of services:
Your data is processed to allow registration on the Website, access to and supply of the services reserved to users registered on the Website and sending via the Website of a purchase order for the products available on the Website, with the consequent conclusion of the related contract of sale with FiloBlu, including any administrative and accounting formalities. In this case, the legal basis is the contract and the legitimate interest.
Communicating changes to our services, customer support via live chat, phone or email, including the correction of any bugs. In this case, the legal basis is the contract.
Your data is processed in order to send advertising material and newsletters, to provide commercial information by telephone, SMS, email, and also using traditional methods (e.g. sending catalogues by post), about promotional and sales initiatives of Paolo Scafora, to conduct market research and surveys on customer satisfaction. In this case, the legal basis is your consent.
With the sole aim of offering things, as far as possible, in line with your interests, we will perform certain analyses on aggregate data but without conducting any profiling on your specific habits. In this case, the legal basis is legitimate interest.
In any case there is absolutely no automatic decision-making process concerning you.
What we mean by legal basis:
This is the authorisation to process your personal data for a specific purpose.
You can change your mind whenever you like!
You can withdraw your consent at any time, by sending us an email to the following address: email@example.com, or by clicking on the opt-out key.
If you decide to withdraw your consent and there are no other reasons that authorise us to process your personal data, we will stop processing it. Conversely, if another legal basis were to authorise us, we would continue to process your data, still in compliance with your rights.
Processing your data is essential for gathering information prior to a purchase and for the performance of the relevant contract.
The processing of your data is possible on the basis of our legitimate interests or those of third parties, provided that these do not predominate over your rights and your freedoms. Legitimate interests may concern:
gathering information from the way you behave on our website and/or applications;
delivering, developing and improving our services;
allowing us to improve, customise or modify our services and offerings;
checking on the effectiveness of our marketing campaigns;
improving data protection.
How we process your data:
Data is processed mainly using electronic means, with the exception of product shipping operations which may also be performed using manual procedures.
Your choices and rights:
You can decide not to provide us with your data
In this case, you can continue to browse our website, but we will not be able to provide you with any services without your personal data.
You can disable cookies by changing your browser settings
You can ask us not to use your data for marketing purposes
Before starting to process your data, we will inform you about our intention (if any) to use your data for marketing purposes, and (where appropriate) of the involvement of any third parties. You can withdraw your consent to receiving promotional messages by clicking on the appropriate link you will find in all our communications or by sending an email to the following address firstname.lastname@example.org
You can always exercise your rights by sending us an email to the following address: email@example.com
You have the right to access the information about you
This includes the right to ask us for further information about:
the categories of data we process;
the purposes of the processing;
the categories of any recipients who may be provided with your data;
the period that the data will be stored, or if that is not possible, the criteria used to determine that period;
the other rights regarding the use of your data.
We will provide you with the information within one month of receiving your request, unless this adversely affects the rights and freedoms of other parties (e.g. the confidentiality of another person or intellectual property) or if there are legal obligations that prevent us from doing so. We will inform you if we are unable to meet your request for these reasons.
You have the right to have your personal data rectified if it is inaccurate or not up to date
You have the right to have your personal data erased (right to be forgotten)
You can ask us at any time to erase your personal data in our possession, if the storage of your personal data is no longer required for processing purposes.
You have the right to transmit your data to another operator (data portability)
We will provide you with a copy of your data in an appropriate usable format, if you wish to transfer it to another operator. If you request it and it is technically feasible, we will directly transfer your data to the new operator. We will not make any transfer, in the event that the portability of your data also involves the disclosure of personal data to other individuals.
You have the right to object to us processing your personal data
You can at any time refer to the Supervisory Authorities to lodge any complaints you may have. But before doing that, try contacting us first! We will be pleased to resolve any issues regarding the processing of your personal data.
You have the right to object to the use of your data through automated decisions, including profiling
We might use your data to identify information that may potentially be relevant for you (for example, sending you customised e-mails based on your preferences that we have detected). Otherwise, we will use your information solely to provide you with our services.
We guarantee your rights even if we process your personal data on behalf of third parties
If we process your personal data on behalf of third parties, we guarantee that any requests made regarding the exercise of your rights will be provided to them without undue delay.
What level of security do we adopt in order to process your data?
We guarantee that your data is processed with the utmost security: we have, in fact, adopted physical, IT and organisational measures to ensure the protection of your data.
Nevertheless, we should remind you that:
You provide us with your data at your own risk. We do everything within our power but, unfortunately, as the way things stand, there is no 100% secure means of data transmission.
You need to keep your username and password safe at all times: you are the only one who knows them.
If you feel that you have suffered a data breach, we would ask you to contact us immediately at firstname.lastname@example.org
Where is your data stored?
Your data is processed within the European Union and in the other data structures managed by the third parties identified below.
As soon as you provide us with your personal data, you consent to it being transferred, stored and processed by us.
If we needed to transfer and/or store your personal data outside the EU, you will be properly informed of this. Also in this event, we will adopt all the appropriate measures to ensure maximum data protection.
How long will we keep your data for?
We will stop active processing of your data within 12 months from the last use of the service or the closure of your account, unless there are legal obligations (e.g. sales invoices) that require us to keep your data for a longer period. As regards promotional activities targeted at you (which you may ask us to stop at any time), we will keep your data for a maximum of 24 months from the date you registered with the service.
Third parties who may process your data:
In some cases, in order to finalise your purchase, it may be necessary to carry out some additional checks with a view to preventing fraud and, therefore, you may receive communications, also by email from our dedicated account (…….), in which we will ask you to send us the authorisation code, a copy of your identity document and the credit card used for the purchase, on which we ask you to obscure the eight central digits. The data collected in this way will be retained for 1 (one) year from the time of their collection for evidentiary purposes, to cooperate with the judicial authorities and to deal with any disputes that may arise in this regard. In this case the legal basis is the contract and the legitimate interest of the Controller. We guarantee that the data collected in this way will be processed in full compliance with the regulations in force for the safeguard and protection of personal data and may have to be shared with third parties who process credit or debit card payments and perform anti-fraud checks, banks, judicial authorities.
For further information, contact us at this address email@example.com
Thank you for reading this policy which we have tried to keep as simple, clear and transparent as possible. All the same, we are always trying to improve, so if you have any suggestions to make, please write to us at firstname.lastname@example.org
This policy may change in the future: you will be notified of any changes via email, so that you can have the fullest possible control over your data.