This website collects certain Personal Data of its Users to improve browsing experience.

CONTROLLER

The Controller is:
PALUMBO & PARTNERS
Registered office: Via Pietro Giannone 9, 20154 Milan – Taxpayer identification and VAT No. 08049330155 – Certified email: studiopalumbo@legalmail.it

TYPES OF DATA COLLECTED

The Personal Data collected by this Application, autonomously or via third parties, includes: Usage Data and Cookies

Full details on each type of data collected are provided in the specific sections of this privacy policy or by means of specific information text displayed before the data are collected.

Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during use of this Application.

Unless otherwise specified, all the Data requested by this Application are compulsory. If the User refuses to communicate such Data, it may not be possible for this Application to provide the Service. Where this Application indicates certain Data as optional, Users are free to refrain from communicating such Data and this will have no effect on the availability of the Service or its operation.

Any Users in doubt as to which Data are compulsory are encouraged to contact the Controller at segreteria@palumboandpartners.it

Any use of Cookies – or other tracking tools – by this Application or by the owners of the third-party services used by this Application, unless specified otherwise, is for the purpose of providing the Service requested by the User, as well as the additional purposes described in this document and in the Cookie Policy.

The User is responsible for the Personal Data of third parties obtained, published or shared through this Application and guarantees that he or she has the right to communicate or disseminate such party Data, releasing the Controller from any liability towards third parties.

HOW AND WHERE THE DATA COLLECTED ARE PROCESSED

HOW THE DATA ARE PROCESSED

The Controller implements appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of the Personal Data.
Processing is carried out by means of computer and/or telematic tools, using organisational methods and logic that are strictly related to the purposes indicated. In some cases, in addition to the Controller, other persons involved in the organisation of this Application (administrative, sales, marketing and/or legal staff and/or system administrators) or external persons (such as providers of third-party technical services, postal couriers, hosting providers, IT companies, communication agencies) also, where necessary, appointed Processors by the Controller, may have access to the Data. The updated list of Processors can always be requested from the Controller.

LEGAL BASIS OF THE PROCESSING

The Controller processes the User’s Personal Data if one of the following conditions is met:

– the User has given consent for one or more specific purposes. Please note that in some jurisdictions the Controller may be authorised to process Personal Data without the User’s consent or without another legal basis specified below, until the User opts out of such processing. However, this does not apply if the processing of Personal Data is governed by European legislation on Personal Data protection

– processing is necessary for the performance of a contract with the User and/or to take steps prior to entering into a contract

– processing is necessary for compliance with a legal obligation to which the Controller is subject

– processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller

– processing is necessary for the purposes of the legitimate interests pursued by the Controller or by third parties.

However, it is always possible to ask the Controller to clarify the legal basis of each processing operation and, in particular, to specify whether the processing is based on law, required by a contract or necessary in order to enter into a contract.

WHERE THE DATA ARE PROCESSED

Data are processed at the Controller’s premises and at any other place where the parties involved in the processing are located. For further information, please contact the Controller.
The User’s Personal Data could be transferred to a country other than the one where the User is located. For further information on where the processing takes place, the User may refer to the section on details on the Personal Data processing.

In the event of greater protection, the User is entitled to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organisation under public international law or consisting of two or more countries, such as the UN, as well as about the security measures undertaken by the Controller to protect the Data.

Should any of the transfers described above take place, the User may refer to the respective sections of this document or request information from the Controller using the contact details given at the beginning of this document.

STORAGE PERIOD

The Data are processed and stored for the time required in relation to the purposes for which they were collected.

Therefore:

– The Personal Data collected for purposes related to the performance of a contract between the Controller and the User will be stored until performance of that contract is completed.

– The Personal Data collected for purposes attributable to the legitimate interest of the Controller will be stored until such interest is satisfied. The User may obtain further information regarding the Controller’s legitimate interest in the relevant sections of this document or by contacting the Controller.

When the processing is based on the User’s consent, the Controller may store the Personal Data longer until such consent is withdrawn. Furthermore, the Controller may be required to store the Personal Data for longer in compliance with a legal obligation or if ordered to do so by an authority.

At the end of the storage period, the Personal Data will be deleted. Therefore, when this period has expired, the right of access, erasure, rectification and the right of Data portability can no longer be exercised.

THE PURPOSES OF THE DATA PROCESSING

The User’s Data are collected to enable the Controller to provide its Services, and for the following purposes: Contacting the User, Statistics, Payment management, Interaction with social networks and external platforms, Registration and authentication, Viewing content from external platforms and Location-based interactions.

For further detailed information on the purposes of the processing and the Personal Data materially relevant for each purposes, the User may refer to the relevant sections of this document.

DETAILS ON PERSONAL DATA PROCESSING

Personal Data are collected for the following purposes and using the following services:
  • • LOCATION-BASED INTERACTIONS

GEOLOCALISATION (THIS APPLICATION)

This Application can collect, use and share Data on the User’s geographical position in order to provide services based on his or her location.
Most browsers and devices provide pre-set tools to refuse geolocation. Only if the User has expressly authorised geolocation can this Application receive information on their actual geographical position.

Personal Data collected: geographical position.

  • STATISTICS

The services contained in this section allow the Controller to monitor and analyse data on traffic and help to track the User’s behaviour.

GOOGLE ANALYTICS WITH ANONYMISED IP (GOOGLE INC.)

Google Analytics is a web analysis service provided by Google Inc. (‘Google’). Google uses the Personal Data collected in order to track and examine use of this Application, compile reports and share them with other services developed by Google.
Google may use Personal Data to contextualise and personalise ads in its advertising network.
This Google Analytics integration renders the User’s IP address anonymous. Anonymisation works by shortening the IP address of Users within the borders of the European Union or in other countries that are party to the agreement on the European Economic Area. Only in exceptional cases is the IP address of Users within the United States sent to the Google servers and shortened.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy – Opt Out

  • VIEWING CONTENT FROM EXTERNAL PLATFORMS

This type of service enables content hosted on external platforms to be viewed directly on the pages of this Application and interaction with them.
If such a service is installed, it is possible that, even if Users do not use the service, it will collect data relating to the pages on which it is installed.

GOOGLE FONTS (GOOGLE INC.)

Google Fonts is a font visualisation service operated by Google Inc. which allows this Application to integrate this content into its own pages.

Personal Data collected: Usage Data and various types of Data as specified by the privacy policy of the service.

Place of processing: USA – Privacy Policy

WIDGET GOOGLE MAPS (GOOGLE INC.)

Google Maps is a map visualisation service operated by Google Inc. which allows this Application to integrate this content into its own pages.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy

RIGHTS OF THE USER

Users may exercise certain rights with regard to the Data processed by the Controller.

In the event of greater protection, the User may exercise all the rights set out below. In any other circumstances, the User may contact the Controller to find out which rights apply in his or her case and how to exercise them.

In particular, the User has the right to:

– withdraw consent at any time. The User can withdraw consent previously expressed for the processing of his or her Personal Data.

– object to the processing of his or her Data. The User may object to the processing of his or her Data when this takes place on a legal basis other than consent. Further details on the right to object are given in the section below.

– access his or her Data. The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing, and to receive a copy of the Data processed.

– check and request rectification. The User may check that his or her Data are correct and request that such Data be updated or rectified.

– obtain restriction of processing. When certain conditions are met, the User may request that the processing of his or her Data be restricted. In this case, the Controller will not process the Data for any purpose other than its storage.

– obtain the erasure or removal of his or her Personal Data. When certain conditions are met, the User may request that his or her Data be erased by the Controller.

– receive his or her Data or have those Data transmitted to another controller. The User has the right to receive his or her Data in a structured, commonly used, machine-readable format and, where technically feasible, to have those Data transmitted without hindrance to another controller. This provision is applicable when the Data are processed by automated means and the processing are based on the User’s consent, on a contract to which the User is party or on contractual measures connected with that contract.

– lodge a complaint. The User can lodge a complaint with the relevant supervisory authority for the protection of personal data or seek judicial remedy.

DETAILS ON THE RIGHT TO OBJECT

When Personal Data are processed in the public interest, in the exercise of official authority vested in the Controller or in pursuit of a legitimate interest of the Controller, Users have the right to object to the processing for reasons relating to their particular situation.

Users are informed that if their Data are processed for direct marketing purposes, they may object to the processing without giving any reason. To find out whether the Controller processes data for marketing purposes, Users may refer to the respective sections of this document.

HOW TO EXERCISE RIGHTS

To exercise their rights, Users may send a request to the Controller using the contact details given in this document. Requests are submitted free of charge and processed by the Controller as quickly as possible, in any case within one month.

APPLICABILITY OF GREATER PROTECTION

While most of the provisions of this document apply to all Users, some are expressly subject to the applicability of a greater level of Personal Data protection.

This greater protection is always guaranteed when the processing:

– is carried out by a Controller with registered office in the EU; or

– concerns the Personal Data of Users who are located in the EU and is functional for the purposes of offering goods or services against payment or free of charge to these Users; or

– concerns the Personal Data of Users who are located in the EU and enables the Controller to monitor the behaviour of these Users to the extent that such behaviour takes place within the EU.

COOKIE POLICY

This Application uses Cookies. For further, more detailed information, please read our

FURTHER INFORMATION ON PROCESSING

LEGAL PROCEEDINGS

The User’s Personal Data may be used by the Controller in legal proceedings, or in the preliminary stages before legal proceedings are brought, to defend against abuses in the use of this Application or of the related Services on the part of the User.
The User states that he or she is aware that the Controller may be obliged to disclose the Data if ordered to do so by the public authorities.

SPECIFIC INFORMATION

When requested by the User, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific Services or on the collection and processing of Personal Data.

SYSTEM LOGS AND MAINTENANCE

For reasons related to functioning and maintenance, this Application and any third-party services used by it may collect System Logs, i.e. files that record interactions and may also contain Personal Data such as the User’s IP address.

INFORMATION NOT CONTAINED IN THIS POLICY

Further information on the processing of Personal Data may be requested from the Controller at any time using the contact details given in this document.

RESPONSES TO ‘DO NOT TRACK’ REQUESTS

This Application does not support ‘Do Not Track’ requests.
To find out whether any third-party services used support such requests, the User may consult their respective privacy policies.

CHANGES TO THIS PRIVACY POLICY

The Controller reserves the right to make changes to this privacy policy at any time, informing Users of these changes on this page and, if possible, on this Application, and – if technically and legally feasible – by sending a notification to Users through one of the contact details held by the Controller. Please return to this page regularly and check the date of last update at the bottom.

If the changes affect processing whose legal basis is consent, then the Controller will collect the User’s consent again, if necessary.

DEFINITIONS AND LEGAL REFERENCES

PERSONAL DATA (OR DATA)

Personal Data is any information relating to an identified or identifiable natural person, including indirectly, by reference to any other information, including a personal identification number.

USAGE DATA

This is information collected automatically by this Application (or by third-party applications that this Application uses), including: IP addresses or dominion names of the computers used by the User who connects to this Application, URI (Uniform Resource Identifier) addresses, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s response (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various timings of the visit (e.g. time spent on each page) and details of the navigation paths followed within the Application, particularly as regards the sequence of pages viewed, the parameters of the User’s operating system and computer environment.

USER

The individual using this Application, who must be the Data Subject (or be authorised by the Data Subject), and whose Personal Data are being processed.

DATA SUBJECT

The natural or legal person to whom the Personal Data refer.

PROCESSOR

The natural or legal person, public administration or any other body, association or organisation entrusted by the Controller to process Personal Data, as set out in this privacy policy.

CONTROLLER

The natural or legal person, public administration and any other body, association or entity that is responsible, including jointly with another controller, for deciding the purposes, methods of processing personal data and the tools used, including the security aspects, in relation to the functioning and use of this Application. The Controller is, unless otherwise specified, the owner of this Application.

THIS APPLICATION

The hardware or software through which Users’ Personal Data are collected.

SERVICE

The Service provided by this Application as defined in the relevant terms and conditions (if any) on this website/application.

EUROPEAN UNION (OR EU)

Unless otherwise specified, any reference to the European Union in this document shall be deemed to extend to all current member states of the European Union and the European Economic Area.

COOKIES

Small pieces of data stored on the User’s device.

LEGAL REFERENCES

This privacy policy has been drawn up based on multiple legal regulations, including Articles 13 and 14 of Regulation (EU) 2016/679.

Unless otherwise specified, this privacy policy concerns only this Application.

LAST UPDATED ON: 19/03/2019

Image