Privacy and Cookie Policy

Privacy and Cookie Policy

 

Cookie Policy

This information, pursuant to art. 13 of Legislative Decree 196/2003 (hereinafter, " Privacy Code ") describes the methods of management of this website owned by ChiaraLens in reference to the processing of personal data of users who consult it, also pursuant to what is requested from the Provision of the Privacy Guarantor of 05.05.2014 "Identification of the simplified procedures for the information and the acquisition of consent for the use of cookies" (hereinafter, " Provision ").


The information is provided only for the aforementioned website and not for other websites or sections / pages / spaces owned by third parties - possibly consulted by the user through specific links within the same.

1. TYPE OF DATA PROCESSED AND PURPOSE OF TREATMENT
1.1. Navigation data
The computer systems and applications dedicated to the functioning of this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols.
This information is not collected to be associated with identified interested parties, but by their very nature could, through processing and association with data held by third parties, allow the identification of users connecting to the site. The collected data includes the IP addresses or domain names of the computers used by the users, the URI (Uniform Resource Identifier) ​​addresses of the requested resources, the time of the request, the method used to submit the request to the server, the file size obtained in response, the numeric code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the user's computer environment.
These data are processed for the time necessary to achieve the purpose for which they were collected, for the sole purpose of obtaining anonymous statistical information on the use of the site (access to the same) and to check its regular operation.
The data could be used to ascertain responsibility in case of hypothetical computer crimes against the site.

1.2. Data provided voluntarily by the user
If users of this site are required, in order to access certain services, to provide their personal data, they will be released, in the pages relating to the individual services, a specific and detailed Information on the relative treatment pursuant to art. 13 of the Privacy Code which will specify the limits, purposes and methods of the processing itself.

1.3. Cookies
What are cookies?
Cookies are small text files that are sent by the website visited by the user on the user's device (usually the browser), where they are stored so that they can recognize this device at the next visit. In fact, at each subsequent visit, cookies are sent back by the user's device to the site.


Each cookie generally contains: the name of the server from which the cookie was sent; the deadline and a value, usually a unique number randomly generated by the computer The server of the website that transfers the cookie uses this number to recognize you when you return to visit a site or navigate from one page to another.


Cookies can be installed not only by the same site manager visited by the user ( first-party cookies ), but also by a different site that installs cookies through the first site ( third-party cookies ) and is able to recognize them . This happens because the visited site may contain elements (images, maps, sounds, links to web pages of other domains, etc.) that reside on servers other than the one of the site visited.
Depending on the purpose, cookies are divided into technical cookies and profiling cookies .


Technical cookies are those used for the sole purpose of “ transmitting a communication over an electronic communication network, or as strictly necessary for the provider of an information society service explicitly requested by the subscriber or user to provide this service "(see Article 122, paragraph 1 of the Privacy Code, as amended by Legislative Decree 69/2012). In particular, these cookies are usually used to allow an efficient browsing of the pages, to store the preferences (language, country, etc.) of the users, to carry out computerized authentication, to manage the shopping cart or to allow online purchases, etc. Some of these cookies (called essential or strictly necessary ) enable functions without which certain operations would not be possible. Pursuant to the aforementioned art. 122, co. 1 of the Privacy Code the use of technical cookies does not require the consent of the users.


Technical cookies are assimilated to cd cookies. analytics if used directly by the site manager to collect aggregate information on the number of users and how they visit the site. These cookies allow owners and / or website managers to understand how users interact with the site's content for the purpose of optimizing it.
Profiling cookies are used to track user navigation, analyze its behavior for marketing purposes and create profiles on its tastes, habits, choices, etc. in order to transmit targeted advertisements in relation to the interests of the user himself and online with the preferences expressed by them in online browsing. These cookies can be installed on the user's terminal only if they have given their consent with the simplified procedures indicated in the Measure.


Depending on their duration, cookies are divided into persistent cookies, which remain stored until they expire on the user's device, except for removal by the latter, and session , which are not stored permanently on the device user and disappear when the browser is closed.

What cookies are used by this site?
to. Technical cookies.  
This site uses technical cookies , installed by the site itself in order to monitor the operation of the site and allow efficient navigation on the site.
Below, for each technical cookie that could be used, the name, the purpose of use and the type / duration are reported.

FIRST NAME PURPOSE TYPE / LENGTH
PHPSESSID session cookies End of browser session
_icl_current_language = en language management End of browser session
wp_woocommerce_session_ session cookie e-commerce module End of browser session
of_current_opt CMS management cookie End of browser session
wp-settings-time- CMS management cookie 1 year
wp-settings- CMS management cookie 1 year
mc4wp_email CMS management cookie in relation to Mailchimp 1 year

The aforementioned cookies cannot be disabled using the functions of this website, but can be disabled through the settings of your browser at any time (in the manner indicated below). Their deactivation could   preclude the optimal use of some areas of the site .

b. Performance and analytics cookies  
Analytics cookies are also used in order to statistically analyze the traffic on the site, count accesses or visits to the site itself and allow the owner, also thanks to the estimates on numbers and consumption models, to improve the structure, the navigation logics and content, to adapt it to the interests of users, to speed up searches, etc.
Below, for each analytics cookie used, the name, purpose of use, type / duration and origin are reported.

FIRST NAME PURPOSE TYPE / LENGTH ORIGIN
GOOGLE ANALYTICS
_ga

Collect statistical information about the use of the site by users, in particular, know how many came back and where they came from, how many came from search engines, how many arrived directly to our URL, to know which pages they visited etc. .

2 years

Google
for more information on the Google Analytics service, see http://www.google.it/analytics and https://www.google.com/analytics/learn/privacy.html?hl=it

_gat 10 minutes
__utma 2 years from set / update
__utmt 10 minutes
__utmb 30 mins from set / update
__utmc End of browser session
__utmz 6 months from set / update
__utmv 2 years from set / update
__utmx 18 months
__utmxx 18 months
Piwik
_pk_id.

Collect statistical information about the use of the site by users, in particular, know how many came back and where they came from, how many came from search engines, how many arrived directly to our URL, to know which pages they visited etc. .

2 years from set / update

psmstats.com by Piwik
for more information on the Piwik service, see http://piwik.org/privacy/

_pk_ses. End of browser session
_pk_ref. 6 months from set / update
_pk_cvar. End of browser session

 

c. Profiling cookies .


Third-party profiling cookies
During navigation on this site, the user could receive on his terminal profiling cookies installed and managed by third parties in order to send advertising messages in line with the preferences expressed by the user during his web browsing. This happens because, as indicated above, the site may contain elements that reside on servers other than the one on which the site visited is located. Where third parties set cookies while you visit this site, they get information about the fact that users have visited it. More information on the use of cookies is available by accessing the link below indicated to the third party website. Refusal to consent to the use of third-party profiling cookies does not affect the ability to access the site.


Below, we list the name of third-party cookies that could be installed by the latter through the site, the purpose, the name of the third party and the link to the latter's website.

First name Purposes Part Three Link to the site where to view the privacy information of the third party
local

Facebook uses cookies for several reasons, for example to be able to show you more relevant content and ads, to improve products and services and to ensure security in the Services.

Facebook

For information and preferences management
https://www.facebook.com/help/cookies/

datr
xs
s
Mo
fr
csm
c_user
       
ServerPool

Tripadvisor uses cookies to understand how users use their services and how these can be improved.

Tripadvisor

For information and preferences management
http://www.tripadvisor.it/pages/privacy.html

TASSK
TAUnique
TATravelInfo
CM
TASession
TACds
       
__utma

Twitter uses these technologies to provide, evaluate and improve its services from different points of view.

Twitter

For information and preferences management: https://support.twitter.com/articles/20170519-uso-dei-cookie-e-di-altre-tecnologie-simili-da-parte-di-twitter

__utmv
__utmz
auth_token
guest_id
pid
remember_checked
remember_checked_on
secure_session
TWLL
dnt
eu_cn
external_referer
       
PREF

Google uses cookies to publish advertisements based on previous visits made by users on this website.

Google

For information on how to disable Google's use of cookies, view the Google Ads Preferences page at the URL http://www.google.com/settings/ads.
Alternatively, view the deactivation page of the Network Advertising Initiative http://www.networkadvertising.org/managing/opt_out.asp
Users who intend to prevent the installation on their terminal of cookies related to Google Analytics, can download and install at https://tools.google.com/dlpage/gaoptout the browser add-on for deactivating Google Analytics, developed by Google, following the instructions provided

lbcs
ACCOUNT_CHOOSER
APISID
SAPISID
HSID
AID
NID
SID
id
_zlcmid
_gat
_drt_
__gads
exchange_uid
FLC
_ga_mftool
TAID
OGPC
GAPS
       
uit

Addthis uses cookies to improve the quality of the site and provide targeted and relevant advertising.

Add This

For information and preferences management
http://www.addthis.com/privacy/

uvc
dt
of 2
bt
vc
UID
_conv_r
_conv_s
_conv_v
km_ab_cbp
km_ai
guest_id
__atuvc
UIDR
__atuvs
ro
pid
sess
uuid2
uuid
       
hcweb1_rc-hc

HolidayCheck uses third-party AdServers to insert advertisements on the Site.

Holiday Check

For information and preferences management
http://www.holidaycheck.it/

hc_agentuser
hc_agentagent
hcweb_branch
       
bcookie

Linkedin uses cookies to offer advertising on both the LinkedIn and non-LinkedIn sites, and to offer customized features to the user through LinkedIn plugins, such as the "Share" button

Linkedin

For information and management of preferences: https://www.linkedin.com/legal/cookie-policy?trk=hp-cookie

_qca
       
__utmb

Youtube also uses cookies when the user interacts with the services offered to partners, for example advertising services or Google functions (owner of Youtube) that could be displayed on other sites.

Youtube

For information and preferences management
https://www.youtube.com/?hl=it&gl=IT

__atuvc
       
__utma

Meteo.it (Mediaset) uses this type of information for statistical purposes, as an aid to improve the services offered to its users.

Meteo.it

For information and preferences management
http://www.meteo.it

__utmb
__utmc
wt_nbg_Q3
__utmt
__utmz
IMRID
wteid_245406294797569
wtsid_245406294797569
       
PHPSESSID Cookies are used to improve the User's overall navigation and present targeted advertising information based on the interests and behavior expressed by the User while browsing.

wildix.com

For information and preferences management
https://www.wildix.com/it/informativa-privacy/

       
__cfduid Zopim uses cookies to display personalized content and adequate advertising within the Service and on subsequent visits.

.zopim.com

For information and preferences management
https://www.zopim.com/privacy#cookie

__zlcid
__zprivacy
       
__utma

Soundcloud.com uses cookies to publish advertisements based on previous visits made by users on this website.

Soundcloud.com

For information and preferences management
https://soundcloud.com/pages/cookies

__utmb
__utmc
sc_anonymous_id
__utmt
__utmz
UID
UIDR
       
SSR

Shinystat uses cookies for the transmission of session identifiers necessary to allow a safe and efficient exploration of the site.

shinystat.com

For information and preferences management
http://shinystat.com/en/informativa_sito.html

SSP

It should be noted in any case that users can manage their preferences on online behavioral advertising (so-called "online behavioral advertising") through the site www.youronlinechoices.com/it , which lists the main behavioral advertising providers. Through these websites, users can deactivate or activate all companies or alternatively adjust their preferences individually for each company.

 

How do I disable cookies?
By default, almost all web browsers are set to automatically accept cookies. It is however possible to change this default configuration via the browser settings. However, disabling / blocking cookies or deleting them may prevent the optimal use of some areas of the site, prevent the use of some services and make browsing slower.


The configuration of cookie management depends on the browser used. Usually, the cookie configuration is carried out from the "Preferences", "Tools" or "Options" menu.
The following are links to the guides for managing the cookies of the main browsers:
Internet Explorer: http://support.microsoft.com/kb/278835 
Internet Explorer [versione mobile]: http://www.windowsphone.com/en-us/how-to/wp7/web/changing-privacy-and-other-browser-settings 
Chrome: http://support.google.com/chrome/bin/answer.py?hl=en-GB&answer=95647 
Safari: http://docs.info.apple.com/article.html?path=Safari/5.0/en/9277.html 
Safari [versione mobile]: http://support.apple.com/kb/HT1677 
Firefox: http://support.mozilla.org/en-US/kb/Enabling%20and%20disabling%20cookies 
Android: http://support.google.com/mobile/bin/answer.py?hl=en&answer=169022

2. METHOD OF TREATMENT
The processing of personal data is carried out through automated tools (for example, using electronic procedures and supports) and / or manually (for example on paper) for the time strictly necessary to achieve the purposes for which the data was collected and , in any case, in compliance with the regulations in force on the subject.

 

3. HOLDER OF THE TREATMENT
The data controller is Pietro Malerba, based in Termoli, Via Isole Baleari 8, CF MLRPTR82B01L113T, PI 01558120703, e-mail info@chiaralens.com, web chiaralens.com (hereinafter the Website).

 

4. RIGHTS OF INTERESTED PARTIES
The subjects to whom the personal data refer have the right, at any time, to obtain confirmation of the existence of the same data, to know its content and origin, verify its accuracy or request its integration or update, or rectification pursuant to art. 7 of the Privacy Code. Pursuant to the same article, the interested parties also have the right to request the deletion, transformation into anonymous form or blocking of data concerning them in violation of the law, as well as to oppose their processing for legitimate reasons.
For any information regarding the processing of data, as well as for the exercise of the rights ex. Article 7 of the Privacy Code , users can forward a specific request (also via e-mail) to the addresses indicated on line in the Contacts page accessible by the site footer.

 

EXTENDED DISCLOSURE PURSUANT TO ART. 12, 13 AND, REQUIRED, 14 DEL GDPR - REGULATION (EU) 2016/679 RELATIVE TO THE PROTECTION OF PHYSICAL PERSONS, REGARDING THE TREATMENT OF PERSONAL DATA (FOLLOWING THE GDPR)

The data controller reports the information pursuant to articles 12, 13 and, if necessary, 14 of the GDPR concerning the processing of personal data provided by the Customer / interested by filling in and signing the Contract to purchase the products / services offered for sale by the data controller himself, spontaneously uploading this website data personal (in particular by filling in forms) or simply browsing in it.

1. Data controller and contact details
The data controller is Pietro Malerba, based in Termoli, Via Isole Baleari 8, CF MLRPTR82B01L113T, PI 01558120703, e-mail info@chiaralens.com, web chiaralens.com (hereinafter the Website).

2. Principles applicable to processing
In accordance with the requirements of the GDPR, the data controller constantly strives to ensure that personal data is:

  1. processed lawfully, correctly and transparently;
  2. collected for specific, explicit and legitimate purposes, and subsequently processed in a way that is not incompatible with these purposes;
  3. adequate, relevant and limited to what is necessary with respect to the purposes for which they are processed;
  4. exact and, if necessary, updated;
  5. kept for a period of time not exceeding the achievement of the purposes for which they are processed;
  6. processed, through appropriate technical and organizational measures, so as to guarantee their safety;
  7. treaties, if by consensus, for a decision freely taken by the Client / interested party, based on a request presented in a clearly distinguishable way, in a comprehensible and easily accessible form, using simple and clear language.

The data controller adopts adequate technical and organizational measures in order to ensure the protection of personal data from the design stage and to ensure that, by default, only the data necessary for each specific processing purpose are processed.
The data controller collects and takes the utmost account of the indications, observations and opinions of the Customer / interested party forwarded to the contact details above, in order to implement a dynamic privacy management system that ensures effective protection of people, with regard to the processing of their data.
This Information Notice may undergo changes, consistent with the evolution of the reference legislation and the technical and organizational measures gradually adopted by the data controller; the Customer / interested party is therefore requested to periodically visit this section of the Website, to view the updates and the Information in the text from time to time in force.

3. Methods of processing personal data
The processing of personal data is carried out manually and with electronic means, with logic strictly related to the purposes indicated below and, in any case, in order to guarantee the security and confidentiality of the data.

4. Purpose of the processing of personal data

(4a) Purpose for which data processing is necessary
The personal data provided by the Customer / interested party are mainly processed for the execution of the Contract and the management of the credit and, more generally, of the relationship arising from the Contract itself.
The provision of data in the Contract or later, during the contractual relationship, for the purposes of processing in question is mandatory; therefore, the failure, partial or incorrect conferment of such data makes it impossible to stipulate and / or execute the Contract and, for the Customer / interested party, to use the products / services offered by the data controller, potentially exposing the Customer / interested person. to liability for breach of contract.
The personal data provided by the Customer / interested party may also be processed if this is necessary to fulfill a legal obligation to which the data controller is subject, to safeguard the vital interests of the Customer / interested party or another person physical, for the performance of a task of public interest or connected to the exercise of public powers vested in the data controller, or for the pursuit of the legitimate interest of the data controller or third parties, provided that they do not prevail the interests or rights and fundamental freedoms of the Customer / interested party; even in these cases, the provision of data is obligatory and, therefore, the failure, partial or inexact communication of data may expose the Customer / interested party to any liability and sanctions envisaged by the legal order.

 

(4b) Further purpose of the processing following the specific and explicit consent of the Customer / interested party
In addition to the aforementioned processing purposes, the personal data provided / acquired may be processed, subject to the consent of the Customer / interested party, to be expressed by checking the << Consent >> box on the Contract or on the Site (or using other applications social or web of the data controller), also for carrying out market surveys and for making commercial and promotional communications, by telephone (also using the mobile phone number provided) and automated contact systems (e-mail, sms, mms, fax, etc.), on products / services of the data controller or Group companies to which the data controller may belong.
Consent for the processing purposes referred to in this point (4b) is optional; therefore, following a possible refusal, the data will be processed only for the purposes indicated in the previous point (4a), except as specified below with reference to the legitimate interests of the data controller or third parties.


5. Categories of personal data processed
The data controller mainly deals with identification / contact data (name, surname, address, type and number of identification documents, telephone numbers, e-mail addresses, tax / billing addresses, except for others) and, if they are provided commercial transactions, financial data (of a banking nature, in particular identification of current accounts, credit card numbers, except for other ones connected with the aforementioned commercial transactions).
The processing that the data controller carries out, both for the execution of the Contract and by virtue of the express consent of the Customer / interested party, does not generally concern particular categories of personal data, known as sensitive (which reveal the racial or ethnic origin) , political opinions, religious convictions, state of health or sexual orientation, etc.), nor genetic and biometric data or so-called judicial data (relating to criminal convictions and crimes).
However, it cannot be excluded that the data controller, in order to perform the obligations deriving from the Contract, must keep and / or have the need to process sensitive data, genetic and biometric or judicial, of the Customer / interested party or third parties, of which the Customer / interested party arranges as a data controller; in the case in question, the processing by the data controller is carried out under the conditions and within the limits of the appointment of the data controller to the data controller, by the Customer / interested party.
The data controller treats, as data controller with reference to the Website, and potentially as the data processor responsible for the processing (in the terms mentioned above) by the Customer / interested party, also the so-called navigation data. The computer systems and software procedures used to operate the websites acquire, during their normal operation, some personal data, the transmission of which is implicit in the use of internet communication protocols. This information is not collected to be associated with identified subjects, but which, by their very nature, could allow identification of the interested party. This category of information includes geolocation data, IP addresses, browser type, operating system, domain name and website addresses from which access or exit was made, information on the pages visited by users within of the site, access time, stay on the single page, internal route analysis and other parameters relating to the operating system and the user's IT environment. Therefore, it is information that, by its very nature, allows users to be identified, through processing and association even with data held by third parties.
On the Website, cookies may be used, both session (which are not stored on the computer of the person concerned and disappear when the browser is closed) and persistent cookies, for the transmission of personal information, or in any case of systems for the tracking of the interested parties.

6. Source of personal data
The personal data that the data controller processes is collected directly by the data controller at the Customer / interested party at the time of, and during, navigation of this on the Site (or using other social applications or web of the data controller), or , also through its own sales representatives, at the time of, or following, the signing of the Contract, during the execution of the same, or from public sources.
As stated above, the data controller, as data controller in charge of processing, in order to perform the obligations deriving from the Contract, can store and / or process data, particularly navigation, potentially sensitive, genetic and biometric or judicial, of third parties, of which the Client / interested party arranges as the data controller, acquired, with the prior consent of said third parties, at the time of, and during, navigation of the same third parties on the Site (or using other social or web applications referable to the owner of the treatment).

7. Legitimate interests
The legitimate interests of the data controller or third parties may constitute a valid legal basis for processing, provided that the interests or the fundamental rights and freedoms of the data subject do not prevail. In general, such legitimate interests can exist when a relevant and appropriate relationship exists between the data controller and the data subject, for example when the data subject is a customer of the data controller. In particular, it is in the legitimate interest of the data controller to process personal data of the Customer / interested party: for fraud prevention purposes, for direct marketing purposes, to ensure the free circulation of the same data within the business group to which the owner of the processing possibly belongs, or related to traffic, in order to guarantee network and information security, ie the ability of a network or system to withstand unforeseen events or unlawful acts that may compromise availability, authenticity, integrity and confidentiality of data.

8. Circulation of personal data

(8a) Communication of personal data - categories of recipients
In addition to employees and contractors in various capacities of the data controller (who are authorized by the data controller to process data according to adequate written operating instructions, in order to guarantee the confidentiality and security of data), some processing operations they can also be carried out by third parties, to whom the data controller entrusts certain activities, or part of them, functional to the purposes referred to in point (4a), thus both in the execution of contractual and legal obligations, among which mention should be made, to title, however, inevitably, not exhaustive: commercial and / or technical partners; companies that provide banking and financial services; companies that perform document archiving services; debt collection company; accounting and auditing company; rating company; subjects who carry out, in favor of the data controller, professional assistance and consultancy activities; companies that carry out customer care activities; factoring company, credit securitization or other assignee of receivables; Group companies to which the data controller may belong; subjects who provide commercial information; IT services company. The subjects belonging to the aforementioned categories treat the same personal data as independent data controllers, or as data controllers, with reference to specific processing operations that fall within the contractual services that the subjects perform in favor / in the interest of the data controller; Data controllers are given adequate written operating instructions by the data controller, with particular reference to the adoption of minimum security measures, in order to guarantee the confidentiality and security of data.
Some processing operations may be carried out by third parties, to whom the data controller entrusts certain activities, or part of them, even functionally to the purposes referred to in point (4b), among which mention must, in any case, inevitably, not exhaustive: commercial and / or technical partners; companies providing institutional marketing services; advertising agencies; subjects who provide assistance and consultancy with reference to competitions and prize operations. The subjects belonging to the aforementioned categories treat the personal data as autonomous data controllers, or as controllers, with reference to specific processing operations that fall within the contractual services that the subjects perform in favor of / in the interest of the data controller; Data controllers are given adequate written operating instructions by the data controller, with particular reference to the adoption of minimum security measures, in order to guarantee the confidentiality and security of data.
The list, subject to periodic updating, of the data controllers with whom the data controller himself has relations is available, upon written request to be sent to the data controller's offices.
Personal data may also be communicated, in the event of a request, to the competent authorities, in fulfillment of obligations deriving from mandatory laws.

 

(8b) Transfer of personal data to third countries
The personal data of the Customer / interested party may also be transferred abroad, both in European Union countries and in countries outside the European Union and, in the latter case, or on the basis of an adequacy decision, or in the context and with the adequate guarantees provided for by the GDPR (therefore, in particular, in the presence of contractual clauses for the protection of data approved by the European Commission), or, outside the hypotheses mentioned above, by resorting to one or more of the exceptions provided for by the GDPR (in particular, by virtue of the explicit consent of the Client / interested party, or for the execution of the Contract concluded by the Customer / interested party, or for the execution of a contract stipulated between the data controller and another natural person or legal in favor of the Customer / interested party, in particular for the execution of activities assigned to it by the data controller for the execution of the Contract concluded with the Customer / interested party). For the hypothesis of data transfers to countries outside the European Union, the Customer / interested party is allowed, upon written request to be sent to the office of the data controller, to know the appropriate guarantees, or the exceptions, which legitimize cross-border treatment. It is understood, in the event of transfer of data to countries outside the European Union, that for every request concerning the data, also for the exercise of the rights recognized by the GDPR to the Customer / interested party, this can always validly apply to the owner of the treatment.


9. Criteria for determining the retention period of personal data
For the purposes referred to in point (4a) above, the period of retention of personal data issued by the Customer / interested party, and the consequent potential treatment thereof, coincides with the period of prescription of rights / duties (legal, fiscal, etc. ) descendants of the Contract: tendentially 10 years, therefore, except for the occurrence of interruptive events of the prescription which could prolong, in fact, said period.
For the purposes referred to in point (4b) above, the period of retention of data released by the Client / interested party, and the consequent potential treatment thereof, ends with the revocation of the consent previously released by the Customer / interested party or, in the absence of this, however, one year after the termination of any relationship between the data controller and the Customer / interested party.

10. Rights of the Customer / interested party
The data controller recognizes - and facilitates the exercise, by the Customer / interested party, of - all the rights provided by the GDPR, in particular the right to request access to their personal data and to extract a copy (art. 15 GDPR ), to the rectification (art. 16 GDPR) and to the cancellation of the same (art. 17 GDPR), to the limitation of the processing that concerns it (art. 18 GDPR), to the portability of data (art. 20 GDPR, where the assumptions) and to oppose the processing that concerns him (articles 21 and 22 GDPR, for the hypotheses mentioned therein and, in particular, to the processing for marketing purposes or that results in an automated decision-making process, including profiling, which produces legal effects concerning him, if the conditions exist).
The data controller also acknowledges, to the Customer / interested party, if the processing is based on consent, the right to revoke said consent at any time, without affecting the lawfulness of the processing based on the consent given before the revocation. To do this, the Customer / interested party can unsubscribe at any time on the Site (or on other social applications or the data controller's website) or by using the appropriate link at the bottom of every commercial communication received, or by contacting the data controller at contact details above.
The data controller also informs the Customer / interested party of the right to lodge a complaint with the Italian Data Protection Authority, as the supervisory authority operating in Italy, and to appeal to the courts, as much against a decision of the Guarantor Authority , as for the data controller and / or a data controller.

11. Security of systems and personal data
Taking into account the state of the art and the implementation costs, as well as the nature, object, context and purpose of the processing, as well as the risk, in terms of probability and seriousness, for the rights and freedoms of individuals , the data controller adopts technical and organizational measures deemed appropriate to guarantee an adequate level of security to the risk, in particular ensuring, on a permanent basis, the confidentiality, integrity, availability and resilience of the processing systems and services ( also through the encryption of personal data, where necessary) and the ability to promptly restore the availability of data in the event of a physical or technical accident, and by adopting internal procedures aimed at regularly testing, verifying and assessing the effectiveness of the technical and organizational measures employed .
In assessing the adequate level of security, the risks presented by the treatment are taken into account, deriving, in particular, from destruction, loss, modification, unauthorized disclosure or accidental or illegal access to personal data transmitted, stored or otherwise processed.
The data controller shall do his best to ensure that anyone acting under his authority and having access to personal data does not process such data unless he is instructed to do so by the data controller.
Having said this, the Customer / interested party acknowledges and accepts that no security system guarantees absolute protection in terms of certainty; therefore, the data controller does not respond for acts or acts of third parties who illegally, despite the appropriate precautions taken, should access the systems without the necessary authorizations.

12. Automated decision-making processes, including profiling
The data controller can perform automated treatments, including profiling, in relation to the purposes referred to in point (4b) above, to optimize the navigability of the Site (or the usability of other social applications or web of the data controller) and for improve the shopping experience, except as specified above with regard to the rights of opposition and withdrawal of consent from the Customer / interested party.
Profiling means any form of automated processing of personal data aimed at assessing certain aspects relating to a natural person, in particular to analyze or foresee aspects concerning, for example, personal preferences, interests or location of said person, also in order to create profiles, or homogeneous groups of subjects by characteristics, interests or behavior.
The data controller does not carry out any automated processing that produces legal effects that concern the Customer / interested party or that significantly affect his person, unless this is necessary for the conclusion or execution of the Contract, is authorized by law or is based on the explicit consent of the Client / interested party, in any case always acknowledging the right to obtain human intervention, to express his / her opinion and to challenge the decision.