Pursuant to articles 13 and 14 of EU Regulation 2016/679
Last update date: 24/02/2022
With this document, Cancellato S.r.l., Benefit & Innovative StartUp Company , with registered office in Milan, via Premuda n. 46, C.F. and VAT number 11746840963, in the person of the legal representative pro tempore , owner of the website www.cancellatouniform.com (hereinafter, "Site") , informs the interested party (User) that his personal data, relating to navigation within the Site itself, with direct access from the homepage or through sub-pages, as well as relating to the use of the services, goods or products offered, will be treated with the utmost care and with tools designed to ensure suitable safety. It is specified that this information - compliant with the provisions of articles 13 and 14 of EU Regulation 2016/679 on the protection of personal data (also "General Data Protection Regulation" - GDPR) and Legislative Decree 196/2003 ( "Code regarding the protection of personal data") - is not to be considered valid for other and external websites that may be consulted through the links present therein.
- DATA CONTROLLER.
The data controller is Cancellato S.r.l., Benefit & Innovative StartUp Company , with registered office in Milan, via Premuda n. 46, C.F. and VAT number 11746840963 . The owner can also be contacted at the e-mail address firstname.lastname@example.org .
- PURPOSE OF DATA PROCESSING.
The processing of User data is aimed at:
- to allow correct navigation on this Site;
- conclude and execute the purchase and sale of goods offered on the Site;
- to allow registration on the Site and the use of services reserved for registered users;
- perform aggregate and anonymous statistical analysis of navigation and users;
- receive, manage and respond to requests made by e-mail or telephone;
- to allow subscription to the newsletter for sending commercial and promotional information on the products of Cancellato S.r.l., Innovative Benefit & StartUp Company;
- comply with all the obligations incumbent on the data controller provided for by current legislation;
- defend a right in court or before judicial authorities exercising judicial functions.
- LEGAL BASIS FOR DATA PROCESSING.
The processing of the User's personal data is lawful, as:
- necessary for the execution of the contract of which you are a party, or for the execution of pre-contractual measures taken at your request, to: allow correct navigation on the Site; conclude and execute the purchase and sale of goods offered on the Site; allow registration on the Site and use of the services reserved for registered users; check requests made by e-mail or telephone;
- based on express consent, for subscribing to the newsletter;
- necessary to fulfill a legal obligation to which the data controller is subject;
- necessary for the pursuit of the legitimate interest of the data controller, for carrying out aggregate and anonymous statistical analyzes of navigation and users, aimed at a possible improvement of the Site and understanding how the data controller is sought on the Internet , and for the defense of one's own right in court or before judicial authorities.
- TYPE AND SOURCES OF DATA PROCESSED.
Cancellato S.r.l., Innovative Benefit & StartUp Company does not process personal data relating to minors who have not yet turned 18. By accessing the Site, the possible registration of a user account, the use of the services offered or the purchase of goods, the User expressly declares that he is 18 years old.
- Data deriving from the User's navigation.
These data, through the normal functioning of the Site, are acquired and transmitted implicitly in the use of Internet communication protocols. This is information that is not collected to be associated with identified data subjects, but, by its very nature, through processing with data held by third parties, it could allow Users to be identified.
This category of data includes the IP addresses or domain names of the computers used by the Users who connect to the Site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used when submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server and other parameters relating to the operating system and the IT environment of the User.
These data are used for the sole purpose of obtaining anonymous and aggregated statistical information on the use of the Site and to check its correct functioning, and reside permanently on servers of third parties (hosting providers). The data could also be used to ascertain responsibility in the event of any harmful illegal actions carried out on or through the Site.
These data processing and association activities are, however, never carried out by the data controller, they are used for the sole purpose of checking correct functioning and are automatically deleted after processing.
- 3. Data provided voluntarily by the User.
These data are provided by the User, during the voluntary interaction with the Site, in order to use the services offered on the Site, purchase the products sold on the Site , request information, receive assistance or to any personal purpose.
In particular, it is:
- personal data required to register the User account: name and surname, date of birth, e-mail address; optional personal data: sex;
- personal data necessary to conclude and execute the purchase and sale of goods on the Site: shipping and billing address, telephone, payment data, in addition to the data necessary to register the User account in advance;
- personal data of third parties, if provided voluntarily by the User who decides, for example, to purchase a good to be delivered to a friend, or to make a gift; in such cases, Cancellato S.r.l., Innovative Benefit & StartUp Company will deliver the privacy information to this third party at the time of the first communication;
- personal data provided voluntarily in case of contact by e-mail or telephone to request information, receive assistance or for any personal purpose;
- personal data required to subscribe to the newsletter: e-mail.
- DATA PROCESSING METHOD.
The processing of your personal data is carried out in a manner strictly necessary to meet the aforementioned purposes, by means of some or of the series of operations indicated in art. 4, no. 2) of EU Regulation 2016/679: collection, registration, organization, structuring, storage, consultation, processing, adaptation, modification, selection, extraction, comparison, use, interconnection, blocking, communication, cancellation and destruction of data. The operations can be carried out with or without the aid of electronic, telematic or automated tools, in any case in compliance with the provisions of art. 32 of EU Regulation 2016/679.
- CONFERRING DATA.
The provision of personal data by the User, while not a legal obligation, is a necessary requirement for:
- correct navigation on this Site;
- to purchase goods offered on the Site;
- register on the Site and use the services reserved for registered users;
- receive, manage and respond to requests made by e-mail or telephone;
- subscribe to the newsletter;
therefore, failure to provide it will make it impossible to fulfill the aforementioned purposes.
In any case, by giving the data controller, or its authorized persons, personal data for any of the purposes listed above, the data controller may process them to fulfill legal obligations and pursue their legitimate interests in carrying out analyzes aggregate and anonymous statistics of navigation and users and protection of one's own right in court or before judicial authorities.
- DATA STORAGE.
The User's personal data will be processed and stored for the entire period necessary for the fulfillment of the aforementioned purposes and, in particular:
- the data collected to conclude and execute contracts for the purchase of goods on the Site are kept until the conclusion of the contract and the administrative-accounting formalities, while the billing data are kept for ten years from the invoice date;
- the data relating to the payment of commercial transactions relating to the purchase of goods on the Site are kept until the certification of the payment and the conclusion of the related administrative-accounting formalities resulting from the expiry of the right of withdrawal and the terms applied for the contestation of the payment;
- the data collected for user account registration are kept until the account is deleted;
- the data collected for the use of any services offered on the Site are kept until the termination or conclusion of the use of the service;
- the data collected to receive, manage and find requests made by e-mail or telephone are kept until the request is exhausted;
- the data collected for subscription to the newsletter are kept as long as the User remains subscribed to the newsletter and / or objects to such processing;
- the data collected for the fulfillment of legal obligations are kept for the time required by law or regulation;
- the data collected for the defense of rights in court are kept until the limitation period of the right to be asserted or, if a legal proceeding has been initiated, until the final conclusion of the same.
- DATA COMMUNICATION.
The User's personal data may be disclosed to, or become aware of, for the purposes listed above and to provide, improve, protect and promote our services:
- subjects authorized to process, i.e. collaborators and / or employees of the data controller;
- data processors and related additional managers and authorized subjects, such as, by way of example but not limited to: accountants, consultants, service providers, IT service providers or assistance to the same, and related technical staff in charge, any collaborators, in charge of occasional maintenance operations, all adequately trained in the protection of confidentiality;
- banking institutions and online payment infrastructures;
- couriers, carriers and freight forwarders;
- judicial or administrative authorities, for the fulfillment of legal obligations;
- subjects who process data in execution of specific legal obligations.
The User's personal data are not subject to any fully automated decision-making process, including profiling.
- 10. DATA TRANSFER TO THIRD COUNTRIES.
Personal data are transferred to third countries with respect to the European Union and the European Economic Area, as they are stored and stored on Shopify's servers located in Canada and the United States. In any case, Shopify offers guarantees regarding the collection, use and storage of personal data of data subjects residing in the European Economic Area, as stated on https://it.shopify.com/legal/privacy
- RIGHTS OF THE INTERESTED PARTY.
Pursuant to articles15-18 and 20-21 of EU Regulation 2016/679, the User has the right to obtain:
- confirmation of the existence or not of personal data concerning you, even if not yet registered, and their communication in an intelligible form;
- the indication:
- of the origin of personal data;
- of the purposes and methods of the processing;
- of the logic applied in case of processing carried out with the aid of electronic tools;
- of the identification details of the owner and of any managers;
- of the subjects or categories of subjects to whom the personal data may be communicated or who can learn about them as managers or agents;
- updating, rectification or, when interested, integration of data;
- the cancellation, transformation into anonymous form or blocking of data processed in violation of the law, including those that do not need to be kept for the purposes for which the data were collected or subsequently processed;
- the attestation that the operations referred to in letters c) and d) have been brought to the attention, also as regards their content, of those to whom the data have been communicated or disseminated, except in the case in which this fulfillment proves impossible or involves a manifestly disproportionate use of means with respect to the protected right.
The User has the right to object, in whole or in part:
- for legitimate reasons, to the processing of personal data concerning him, even if pertinent to the purpose of the collection;
- to the processing of personal data concerning him for the purpose of sending advertising or direct sales material or for carrying out market research or commercial communication.
The User has the right to revoke, at any time, the consent provided, in relation to the processing activities of which it represents the legal basis, without prejudice to the lawfulness of the processing based on the consent given before the revocation.
The User has the right to data portability, i.e. to receive personal data concerning him in a structured format, commonly used and readable by an automatic device, and has the right to transmit such data to another data controller without hindrance. You also have the right to propose the right to complain to a supervisory authority (in Italy, the Guarantor for the Protection of Personal Data: www.garanteprivacy.it ).
The User can exercise his rights with a written request sent to the data controller, at the addresses indicated above.
The User concerned is required to periodically check any changes published on the Site..