ASTOLFI PRIVACY POLICE

This privacy notice, addressed to all individuals navigating this website (hereinafter referred to as the “Website”), is issued pursuant to Article 13 of Regulation (EU) No. 2016/679 (hereinafter referred to as the “GDPR”).

1. Identity and contact details of the data controller

The data controller is ASTOLFI 1963 S.R.L., Strada Geronima 2, Sacile (PN), email info@astolfi1963.com (hereinafter referred to as the “Controller”).

2. Types of data processed

a. Browsing data

During their normal operation, the IT systems and software procedures responsible for the functioning of the Website acquire certain information whose transmission is implicit in the use of Internet communication protocols. This category of information includes IP addresses or domain names of the computers and terminals used by users, URI/URL (Uniform Resource Identifier/Locator) addresses of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (success, error, etc.), and other parameters related to the user’s operating system and IT environment.

Such data, necessary for the use of web services, are also processed for the purpose of:

– obtaining statistical information on the use of services (most visited pages, number of visitors by time slot or day, geographic areas of origin, etc.);

– monitoring the proper functioning of the services offered.

Browsing data is not retained for more than four months (except in cases where it may be necessary to investigate crimes by judicial authorities).

b. Data provided voluntarily by the user

To access certain services, the provision of personal data is necessary, for which reference is made to the specific information provided at the time of collection.

c. Handling and responding to requests

The data may be processed to respond to requests for information or assistance related to the services of this Website. The legal basis for the processing is the performance of pre-contractual measures at the request of the data subject. The data will be retained for the time necessary to fulfill the request and, in any case, no longer than 2 years (unless a subsequent contract is established, in which case reference is made to the specific information provided at that time).

d. Improvement of services

The data may be processed for monitoring and improving services (e.g., interaction via chat with operators and virtual assistants). The data will be retained for the time technically necessary to anonymize it. The legal basis for the processing is the Controller’s legitimate interest in providing an efficient request management service.

e. Information processed through cookies

The Website uses cookies. For more information, please refer to the cookie policy available at the following link: https://astolfi1963.com/astolfi-privacy-policy/

3. Provision of data

Browsing data is necessary to execute IT and telematic protocols.

Additionally, there are other data necessary for the provision of the related service; therefore, failure to provide such data will result in the inability to use the requested service.

As for additional data (provided voluntarily and related to requests), their provision is entirely optional.

As for cookies, they are necessary to execute IT and telematic protocols if they are technical or equivalent. For other types of cookies and tracking tools, their activation is optional and subject to the user’s consent.

 

4. Recipients

The processing related to the web services of this Website is carried out by personnel expressly authorized for processing who have received appropriate operational instructions.

The data may also be processed, on behalf of the Data Controller, by third parties designated as Data Processors pursuant to Article 28 of the GDPR, such as individuals and/or legal entities performing activities essential to the purposes indicated above, for example, the company responsible for the management and maintenance of the Website.

The data may be disclosed to independent data controllers, such as authorities and supervisory and control bodies authorized to request/receive the data.

Where data is transferred to countries outside the European Union (EU) or the European Economic Area (EEA) that have not been deemed adequate by the European Commission, “transfer tools” under Article 45 of the GDPR will be used, assessing the possible implementation of “supplementary measures” to ensure a level of protection substantially equivalent to that required under European Union law. For more information, refer to the links to the privacy policies of third parties indicated in the cookie policy.

 

5. The rights of data subjects

With regard to the processing of personal data carried out by the Data Controller, the data subject, in addition to what is indicated in the previous paragraph, may exercise the rights set out in Articles 15 to 22 of the GDPR, where applicable. In particular, the data subject may request access to their data and the information referred to in Article 15 (purposes of processing, categories of personal data, etc.), the deletion of data in cases provided for by Article 17, the rectification of inaccurate data, the integration of incomplete data, the restriction of processing in cases provided for by Article 18, as well as data portability (i.e., to receive their data in a structured, commonly used, and machine-readable format, and, if technically feasible, to transmit it to another controller without obstacles) if the processing is based on consent or a contract and is carried out using automated tools.

To exercise their rights, the data subject may contact the Data Controller using the contact details provided in section 1.

The data subject has the right to lodge a complaint with the supervisory authority of the Member State where they habitually reside or work, or of the State where the alleged violation occurred.