Pursuant to art. 13 of Regulation (EU) 2016/679 (RGPD or in the English meaning GDPR ( General Data Protection Regulation ) on the protection of personal data and in relation to your personal data their processing by the Data controller will be based on to the principles of correctness, lawfulness and transparency, as well as protection of your privacy and protection of your rights. In relation to this we inform you of the following.
a) Data controller
The Data Controller is OMNIA CONSULT Srl with registered office in Viale Bicchierai, 129
51016 Montecatini Terme (PT) hereinafter the " Data Controller. Your contact details are as follows:
email : email@example.com
b) Purpose and legal basis of the processing
The processing of your personal data, collected at the time of registration on our websites attributable exclusively to the domain tooscans.it (hereinafter the "Site") or at the time of making online purchases on this website, will be made for the purposes
The legal basis
for the processing of personal data relating to each purpose is specified alongside each of them. When consent is indicated as the legal basis for the processing, it is understood that the data will be processed by the Data Controller for these purposes only upon collection of your consent (as "interested party").
The legal basis concerning the execution of the contract
does not require any consent and allows the Data Controller to process the personal data provided based on the contractual obligations assumed (eg
make a service or sell a product).
Finally, as regards the legitimate interests
indicated, they concern the case in which:
a) the interested party has already expressed interest in the commodity sector in question, purchasing certain products or services, and the Data Controller has a specific and justified interest in continuing to send him communications in relation to services or goods similar to those purchased;
b) the owner has an interest in processing the navigation data of the interested party in order to allow him to visit web pages.
Your personal data will be processed for the following purposes
1. management of the procedure for registration on the Site and compilation of data collection forms available on the website to request information, make reports and contact the Data Controller ;( Legal basis of the processing: Execution of the contract
2. allow online purchases, in relation to the specified products and according to the procedures indicated in the contractual sales conditions; ( Legal basis of the processing: Execution of the contract
3. sending for marketing purposes - via e-mail, postal service, social network, sms and specific " apps " - commercial newsletters, offers, promotions, discounts and invitations to events or events (hereinafter the "Promotions") to customers and / or potential customers. ( Legal basis of the processing: Consent of the data subject
4. profiling , through the reading and analysis, through automated decision-making processes, of purchasing behavior, using the data relating to your expenses, in order to improve the commercial offer and carry out specific product promotions and commercial offers on as much as possible suited to your profile and your needs, including through surveys and research market; ( Legal basis of the processing: Consent of the data subject );
5. sending, exclusively to the e-mail address you provided during the purchase of a product or service from the Websites, promotional messages on goods or services similar to those you purchased, unless you object to the processing in the manner described below indicated, according to the provisions of art. 130, paragraph 4, of Legislative Decree. 196/2003 and subsequent ones changes and additions -cd soft spam - ( Legal basis of processing: Legitimate interest of the Data Controller);
6. to allow browsing on the Websites ( Legal basis of processing: legitimate interest
of the Data Controller ).
c) Faculty or obligation to provide data and consequences of failure to provide data
For all purposes, the provision of personal data is not mandatory, however it is necessary to register and make purchases on the Sites. The provision of data in the fields marked with an asterisk is mandatory and their failure to enter does not allow the conclusion of the procedure registration On the other hand, the release of data in the fields not marked with an asterisk, although it may be useful to facilitate relations with us, is optional and failure to do so does not affect the completion of the procedure.
d) Recipients or categories of recipients of personal data
The personal data relating to the processing in question, for the purposes mentioned above, may be communicated:
- to those who, within the Data Controller's organization, need it due to effect of the position held. These individuals are the persons authorized for treatment under the direct authority of the Data Controller pursuant to art. 4 n. 10 of EU Regulation 2016/679 (of followed by "appointees");
- to subjects whose activity is necessary for the execution of the contracts of which you are part or for fulfill specific requests (eg: Transporters, Suppliers of goods and services and Subcontractors both domestic and foreign inside and outside of the European Union, Companies and institutes of the banking sector, credit and insurance companies, factoring companies, financial intermediaries, companies that provide commercial information, mail delivery company);
- to third parties to whom the Data Controller may outsource certain activities and which consequently provide the Data Controller with certain instrumental services, however related to the processing tand to purposes described above, such as administrative, accounting, tax, audit, of information system management, of credit collection, of mass storage, of call center. These third parties carry out processing on behalf of the Data Controller and result authorized to process them as Data Processors in accordance with the provisions by Article 28 of the GDPR. Your personal data referred to above will also be transferred to countries outside the EU against which an adequacy decision has been issued or in any case the transfer is subject to adequate guarantees. In particular, the transfer will be made to the service provider of the website, domiciled in the Republic of S. Marino.
e) Retention period
The Owner will keep the registration data and the accounting data relating to purchases
for 10 years since last use. For marketing
and profiling purposes
, the purchase data from customers and the personal and contact details of customers and potential customers relating to the Promotions will be kept for 24 months and 12 months respectively.
f) Your rights
At any time, in accordance with articles 15 to 22 of EU Regulation no. 2016/679, the right to:
a) request confirmation of the existence or otherwise of personal data;
b) obtain information about the purposes of the processing, the categories of personal data, the recipients or the categories of recipients to whom the personal data have been or will be communicated and the period or conservation criterion;
c) obtain the correction and deletion of data;
d) obtain the processing limitation;
e) obtain data portability, ie receive them from a Data Controller, in a format structured, commonly used and readable by an automatic device, and transmitted to another holder of the processing without hindrance;
f) object to the processing of your personal data at any time (Article 21). In particular, it can object to the processing of your data for the purposes referred to in point " c n.5 " ( so-called soft spam) by accessing to your "Reserved Area" or by selecting the link on each e-mail sent by the Owner.
This will make it impossible for the Data Controller to send you communications in order to promote the direct sale of products or services similar to those you previously purchased (so-called soft
g) oppose an automated decision-making process, including profiling (art.22);
h) withdraw consent at any time without affecting the lawfulness of the processing based on consent given before revocation;
i) to lodge a complaint with the Data Protection Authority (art.77) if it considers that the processing of your data is contrary to the legislation in force.
You can exercise your rights with a written request sent to:
Viale Bicchierai, 129 51016 Montecatini Terme (PT)