TUMEDEI GENERAL CONDITIONS OF SALES
Tumedei Spa a socio unico (hereinafter, “Controller”), as the data controller, informs you pursuant to Art. 13 of Legislative Decree 30.6.2003 No. 196 (hereinafter, “Privacy Code”) and Art. 13 of EU Regulation No. 2016/679 (hereinafter, “GDPR”) that your data will be processed in the following ways and for the following purposes.
Privacy Policy of www.tumedei.eu
For information regarding your collected personal data, purposes, and entities with whom the data is shared, contact the Controller.
DATA CONTROLLER
Types of Data Collected
The Controller does not provide a list of types of Personal Data collected.
Full details on each type of data collected are provided in the dedicated sections of this privacy policy or by specific information texts displayed before data collection.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application.
Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to provide them, it may be impossible for this Application to provide the Service. In cases where this Application specifically states that some Data is optional, Users are free to refrain from communicating such Data without affecting the availability or functioning of the Service.
Users who have doubts about which Data is mandatory are encouraged to contact the Controller.
The possible use of Cookies – or other tracking tools – by this Application or the owners of third-party services used by this Application, unless otherwise stated, is aimed at providing the Service requested by the User, in addition to other purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Application and guarantees that they have the right to communicate or disclose them, freeing the Controller from any liability towards third parties.
METHODS AND LOCATION OF DATA PROCESSING
Processing Methods
The Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.
Processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In some cases, in addition to the Controller, other parties involved in the organization of this Application (administrative, commercial, marketing, legal staff, system administrators) or external entities (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) appointed, if necessary, as Data Processors by the Controller, may have access to the Data. The updated list of Processors can always be requested from the Data Controller.
Legal Basis for Processing
The Controller processes Personal Data relating to the User if one of the following conditions applies:
-
- The User has given consent for one or more specific purposes;
- Processing is necessary for the execution of a contract with the User and/or for the execution of pre-contractual measures;
- Processing is necessary to comply with a legal obligation to which the Controller is subject;
- Processing is necessary for the performance of a task carried out in the public interest or the exercise of official authority vested in the Controller;
- Processing is necessary for the legitimate interests pursued by the Controller or by third parties.
It is always possible to request the Controller to clarify the concrete legal basis of each processing operation, and in particular to specify whether processing is based on the law, required by a contract, or necessary to conclude a contract.
Location
Data is processed at the operational headquarters of the Controller and at any other place where the parties involved in the processing are located. For further information, contact the Controller.
The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the place of processing, the User may refer to the section containing details on the processing of Personal Data.
The User has the right to obtain information regarding the legal basis for transferring Data outside the European Union or to an international organization governed by public international law or constituted by two or more countries, such as the UN, as well as regarding the security measures adopted by the Controller to protect the Data.
If such a transfer takes place, the User can refer to the respective sections of this document or inquire with the Controller using the contact details provided at the beginning.
Data Retention Period
Data is processed and stored for the time required for the purposes for which it was collected.
Therefore:
- Personal Data collected for purposes related to the execution of a contract between the Controller and the User will be retained until such contract has been fully performed and as required by law.
- Personal Data collected for purposes based on the legitimate interest of the Controller will be retained until such interest is met. The User can obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.
When processing is based on the User’s consent, the Controller may retain Personal Data for a longer period until such consent is revoked. Furthermore, the Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
Once the retention period expires, Personal Data will be deleted. Therefore, after this period, the right of access, deletion, rectification, and data portability can no longer be exercised.
User Rights
Users may exercise certain rights regarding their Data processed by the Controller.
In particular, the User has the right to:
- Withdraw consent at any time. The User can withdraw consent for the processing of their Personal Data previously given.
- Object to the processing of their Data. The User can object to the processing of their Data when it occurs on a legal basis other than consent. Further details on the right to object are provided in the section below.
- Access their Data. The User has the right to obtain information on the Data processed by the Controller, certain aspects of processing, and to receive a copy of the processed Data.
- Verify and request rectification. The User can verify the accuracy of their Data and request its update or correction.
- Obtain restriction of processing. When certain conditions are met, the User may request the restriction of their Data processing. In this case, the Controller will not process the Data for any purpose other than their storage.
- Obtain the deletion or removal of their Personal Data. When certain conditions are met, the User can request the deletion of their Data by the Controller.
- Receive their Data and have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transferred to another controller without hindrance. This provision is applicable when Data is processed by automated means and the processing is based on the User’s consent, on a contract to which the User is a party, or on contractual measures related to it.
- Lodge a complaint. The User can lodge a complaint with the competent data protection authority or take legal action.
Details on the right to object
When Personal Data is processed in the public interest, in the exercise of official authority vested in the Controller, or for the legitimate interests pursued by the Controller, Users have the right to object to processing for reasons related to their particular situation.
Users should be aware that, if their Data is processed for direct marketing purposes, they can object to the processing at any time without providing any justification. To find out whether the Controller processes Data for direct marketing purposes, Users may refer to the relevant sections of this document.
How to exercise rights
To exercise their rights, Users may send a request to the Controller using the contact details provided in this document. Requests are processed free of charge and handled by the Controller as soon as possible, in any case within one month.
ADDITIONAL INFORMATION ON DATA PROCESSING
Legal defense
The User’s Personal Data may be used by the Controller in court or in the preparatory stages of a possible legal action for the defense against abuse in the use of this Application or related Services.
The User declares to be aware that the Controller may be required to disclose Data by order of public authorities.
Specific disclosures
Upon request by the User, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual disclosures regarding specific Services or the collection and processing of Personal Data.
System logs and maintenance
For operational and maintenance purposes, this Application and any third-party services it uses may collect system logs, which are files that record interactions and may also contain Personal Data, such as the User’s IP address.
Information not contained in this policy
More details concerning the processing of Personal Data can be requested at any time from the Controller using the contact information provided.
Response to “Do Not Track” requests
This Application does not support “Do Not Track” requests.
To determine whether any third-party services used support them, the User is encouraged to consult their respective privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by informing Users on this page and, if possible, on this Application, as well as, where technically and legally feasible, by sending a notification to Users via one of the contact details in the Controller’s possession. Please refer to this page regularly, noting the date of the last modification indicated at the bottom.
If the changes affect processing activities based on User consent, the Controller will collect the User’s consent again if necessary.