On the 25th of May 2018 the new regulation in the European Union entered into force that is called the General Data Protection Regulation (EU) 2016/679 ("GDPR"). The Regulation provides strict and specific guidelines on how personal data is collected and managed. This also applies to companies and individuals residing outside the European Union but collecting data from EU citizens.
What personal data we collect
When you use our services, you accept that our company collects some of your personal data. We process two types of data, personal data provided by the user for the use of our services and technical data that we automatically collect to improve the service we give you.
Data provided by the user
When you use our site and our services, we may collect the following data about you:
- name and surname;
- mailing address;
- email address;
- IP address;
- telephone number;
- order history and number of transactions;
- history of your visits and your browsing on the Site.
The above data can be collected at different times:
- when you create your account on the Site or log in to your Account;
- when you place your orders;
- while browsing the Site;
- when you contact our customer service.
If you provide personal data of third parties, such as those of your family or friends, you must be sure that these subjects have been adequately informed and have consented to their treatment in the manner described in this statement. We store this data only for the purpose of providing the requested service and we do not disclose this data to third parties.
Data collected automatically
How and why we process your personal data
The processing of personal data is carried out with mainly electronic and telematic methods by Crisma Srl and by other subjects who are properly selected as regards reliability and competence. These subjects carry out instrumental operations to pursue the purposes strictly connected to the use of the Website, its services and to purchase products through the Website.
In general, the data are processed for the provision of the following services available by accessing our site:
- registration on the Site, to use the related services;
- adherence to specific and additional services, such as our newsletter and other similar services that give information about our business, the creation of your Favorites List and the sharing of its contents, the invitation to your friends to join Crisma Srl, to let you know by other users by sending us your photo and your comments;
- product selection, order fulfillment and related activities;
- management of your requests: technical, commercial, on the progress of your orders and requests for information in a broad sense.
In the processing of data that can directly or indirectly identify your person, we try to respect a principle of strict necessity.
For this reason we have configured the Site in such a way that the use of your personal data is reduced to a minimum: therefore, the processing of your data is excluded when the purposes pursued in individual cases can be achieved through the use of anonymous data ( as, for example, in market research aimed at improving services) or through other methods that allow identification of the data subject only in case of need or at the request of the authorities and police forces (such as, for example, for data relating to traffic and your stay on the Website or your IP address).
In some cases, as expressly indicated in the information, your data will be subjected - with your express consent - to processing aimed at creating profiles based on your preferences and your purchases. This is intended to send you information targeted to your needs and interests.
Your data will be disclosed to third parties only with your express consent, except in cases where communication is mandatory by law or is necessary for purposes required by law for the pursuit of which the consent of the interested party is not required; in such cases, the data may be made available to third parties who will treat them independently and only for the aforementioned purposes.
Any processing purpose other than the specific one for which you have provided your personal data will be highlighted in the information note and will be pursued by Crisma Srl only after the acquisition of your express consent (what happens, for example, in customer profiling activities based on purchasing preferences and habits).
There are, however, treatments for which the legislation provides for the exclusion of consent: for example, we inform you that Crisma Srl can process your personal data without obtaining your consent when this is necessary to fulfill a legal obligation or when is necessary to execute the obligations contractually assumed towards you (as in the case in which you have purchased products or have requested to use specific services through our Site).
Finally, we inform you that your personal data will not be transferred abroad to countries, other than those belonging to the European Union, which do not ensure adequate levels of protection for people. If this is necessary to provide the services or to conclude a contract with Crisma Srl for the purchase of products, we assure you that the transfer of your personal data to countries that do not belong to the European Union and that do not ensure an adequate level of protection will be carried out only after conclusion between Crisma Srl and said subjects of specific contracts in accordance with the applicable law and regulations.
It may happen that Crisma Srl finds itself processing personal data of third parties communicated directly by its users to Crisma Srl, for example in the event that the user has purchased a product to be delivered to a friend or when the person who corresponds the price for the purchase of the product is different from the person for whom the product is intended, or even when the user intends to report to a friend a service of www.carellaostuni.com or the offer for sale of a particular product.
We inform you that the consent of these people is not necessary when the data of this subject are communicated to Crisma Srl for the conclusion of the contract, with Crisma Srl, in favor of the third party.
Crisma Srl reserves the right to delete accounts and all related data in the event that illegal contents are found, harmful to the image of Crisma Srl and / or its products or third parties, or in any case offensive content or that promote illegal or defamatory activities , pornographic content, which incites violence, which promotes discrimination related to race, sex, religion and sexual orientation.
Is the providing of data compulsory?
The provision of personal data is mandatory only for the processing necessary for the provision of the services offered (any refusal for the purpose of providing the service makes it impossible to use the service itself). It is instead optional for promotional and profiling purposes and any refusal to give consent does not have negative consequences on the provision of the service offered within the website and related applications.
Who are the subjects of data processing
The data controller is Crisma Srl, Via Cattedrale, 31 - 72017 Ostuni (BR) - VAT number 02164250744.
For any questions or requests regarding your personal data and respect for your privacy, you can write to: firstname.lastname@example.org
The data collected as part of the provision of the service may be communicated to:
- companies that perform functions strictly connected and instrumental to the operation, also technical, of our services, such as suppliers that provide services aimed at reviewing and verifying advertisements, suppliers of direct marketing and customer care services
- administrative and judicial entities and authorities by virtue of legal obligations
Your personal data may be transferred outside the European Union to be processed by some of our service providers. In this case, we make sure that this transfer takes place in compliance with current legislation and that an adequate level of protection of personal data is guaranteed based on an adequacy decision, on standard clauses defined by the European Commission or on Binding Corporate Rules.
In no case do we transfer or sell personal data to third parties.
The owner takes appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of personal data.
The treatment is carried out using IT and / or telematic tools, with organizational methods and with logic strictly related to the purposes indicated. In addition to the owner, in some cases, other subjects may have access to data such as subjects involved in the organization of this application (administrative, commercial, marketing, legal, system administrators) or external subjects (such as suppliers of third party technical services, postal couriers, hosting provider, IT companies, communication agencies) also appointed, if necessary, responsible for the treatment by the owner. The updated list of managers can always be requested from the data controller.
What rights you have on your data
Users can exercise certain rights with reference to the data processed by the owner.
In particular, the user has the right to:
- withdraw consent at any time. The user can withdraw the consent to the processing of their personal data previously expressed.
- object to the processing of your data. The user can object to the processing of their data when it takes place on a legal basis other than consent. Further details on the right to object are indicated in the section below.
- access your data. The user has the right to obtain information on the data processed by the owner, on certain aspects of the treatment and to receive a copy of the data processed.
- check and request the correction. The user can verify the correctness of his data and request its updating or correction.
- obtain the limitation of the treatment. When certain conditions are met, the user can request the limitation of the processing of their data. In this case, the owner will not process the data for any other purpose other than their conservation.
- obtain the cancellation or removal of your personal data. When certain conditions are met, the user can request the cancellation of their data by the owner.
- receive your data or have it transferred to another owner. he user has the right to receive his data in a structured format, commonly used and readable by an automatic device and, where technically feasible, to obtain the transfer without obstacles to another owner. This provision is applicable when the data are processed with automated tools and the treatment is based on the user's consent, on a contract of which the user is a party or on contractual measures connected to it.
- propose a complaint. The user can lodge a complaint with the competent data protection supervisory authority or take legal action.
how long and how we keep your data
The data are processed and stored for the time required by the purposes of the services used and for which they were collected.
- Personal data collected for purposes related to the execution of a contract between the owner and the user will be retained until the execution of this contract is completed.
- Personal data collected for purposes related to the legitimate interest of the owner will be retained until the satisfaction of this interest. The user can obtain further information regarding the legitimate interest pursued by the owner in the relevant sections of this document or by contacting the owner at this email: email@example.com
When the treatment is based on the user's consent, the owner can keep personal data longer until such consent is revoked. Furthermore, the owner may be obliged to keep personal data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, personal data will be deleted. Therefore, at the end of this term, the right of access, cancellation, rectification and the right to data portability can no longer be exercised.
If the changes concern treatments whose legal basis is consent, the owner will collect the user's consent again, if necessary.
What are cookies?
A cookie is a small text file containing a unique identification number that is transferred from the website to your computer's hard drive through an anonymous code that can identify the computer but not the user and passively monitor your activities on the site.
The law states that we can store cookies on your device if they are strictly necessary for the operation of this site and if they do not collect personal data. For all other types of cookies we need your permission.
Our website supports all the latest versions of the main browsers and / or applications. For best results, we recommend downloading the latest version of your browser and / or app. We cannot guarantee the correct functioning of the service and the effectiveness of the indications contained in this information for previous versions of browsers and / or unsupported apps.
Cookies on our site
The main purposes of the cookies installed on our website are:
Techniques: that is, they are used for purposes related to the provision of the service and to allow or improve navigation. These cookies are essential to ensure our website functions properly.
Third parties and profiling:
In addition, specifically designed cookies may be activated to manage connections with the main social networks. They allow the user to interact via social networks (share function Facebook). When a page contains this command, a direct connection is established with the selected social network. The use of the aforementioned technologies is regulated by the privacy policies of these companies.
Cookies can be completely disabled by the browser using the appropriate function provided in most navigation programs.
It is good to know, however, that by deactivating cookies some of the features of our site may not be usable.
Here are the links to the information of the main browsers for more information on disabling cookies: Chrome, Firefox, Internet Explorer.
Other resources external to this site that describe in detail how to delete and disable cookies on the main browsers: how to delete cookies.
Content incorporated by other websites
The articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in exactly the same way that the visitor has visited the other website.
Other useful information for disabling cookies
Th Youronlinechoices and Networkadvertising platforms offer the possibility to refuse or accept the cookies of many digital advertising professionals.
To find out more about targeted advertising you can consult the following pages:
- European Interactive Digital Advertising Alliance (EIDAA)
- Network Advertising Initiative (NAI)
- Interactive Advertising Bureau (IAB)
Last updated: February 20, 2020