CONTROLLER
PALUMBO & PARTNERS
Registered office: Via Pietro Giannone 9, 20154 Milan – Taxpayer identification and VAT No. 08049330155 – Certified email: studiopalumbo@legalmail.it
TYPES OF DATA COLLECTED
The Personal Data collected by this Application, autonomously or via third parties, includes: Usage Data and Cookies
Full details on each type of data collected are provided in the specific sections of this privacy policy or by means of specific information text displayed before the data are collected.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during use of this Application.
Unless otherwise specified, all the Data requested by this Application are compulsory. If the User refuses to communicate such Data, it may not be possible for this Application to provide the Service. Where this Application indicates certain Data as optional, Users are free to refrain from communicating such Data and this will have no effect on the availability of the Service or its operation.
Any Users in doubt as to which Data are compulsory are encouraged to contact the Controller at segreteria@palumboandpartners.it
Any use of Cookies – or other tracking tools – by this Application or by the owners of the third-party services used by this Application, unless specified otherwise, is for the purpose of providing the Service requested by the User, as well as the additional purposes described in this document and in the Cookie Policy.
The User is responsible for the Personal Data of third parties obtained, published or shared through this Application and guarantees that he or she has the right to communicate or disseminate such party Data, releasing the Controller from any liability towards third parties.
HOW AND WHERE THE DATA COLLECTED ARE PROCESSED
HOW THE DATA ARE PROCESSED
The Controller implements appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of the Personal Data.
Processing is carried out by means of computer and/or telematic tools, using organisational methods and logic that are strictly related to the purposes indicated. In some cases, in addition to the Controller, other persons involved in the organisation of this Application (administrative, sales, marketing and/or legal staff and/or system administrators) or external persons (such as providers of third-party technical services, postal couriers, hosting providers, IT companies, communication agencies) also, where necessary, appointed Processors by the Controller, may have access to the Data. The updated list of Processors can always be requested from the Controller.
LEGAL BASIS OF THE PROCESSING
The Controller processes the User’s Personal Data if one of the following conditions is met:
– the User has given consent for one or more specific purposes. Please note that in some jurisdictions the Controller may be authorised to process Personal Data without the User’s consent or without another legal basis specified below, until the User opts out of such processing. However, this does not apply if the processing of Personal Data is governed by European legislation on Personal Data protection
– processing is necessary for the performance of a contract with the User and/or to take steps prior to entering into a contract
– processing is necessary for compliance with a legal obligation to which the Controller is subject
– processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller
– processing is necessary for the purposes of the legitimate interests pursued by the Controller or by third parties.
WHERE THE DATA ARE PROCESSED
Data are processed at the Controller’s premises and at any other place where the parties involved in the processing are located. For further information, please contact the Controller.
The User’s Personal Data could be transferred to a country other than the one where the User is located. For further information on where the processing takes place, the User may refer to the section on details on the Personal Data processing.
In the event of greater protection, the User is entitled to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organisation under public international law or consisting of two or more countries, such as the UN, as well as about the security measures undertaken by the Controller to protect the Data.
STORAGE PERIOD
The Data are processed and stored for the time required in relation to the purposes for which they were collected.
Therefore:
– The Personal Data collected for purposes related to the performance of a contract between the Controller and the User will be stored until performance of that contract is completed.
– The Personal Data collected for purposes attributable to the legitimate interest of the Controller will be stored until such interest is satisfied. The User may obtain further information regarding the Controller’s legitimate interest in the relevant sections of this document or by contacting the Controller.
When the processing is based on the User’s consent, the Controller may store the Personal Data longer until such consent is withdrawn. Furthermore, the Controller may be required to store the Personal Data for longer in compliance with a legal obligation or if ordered to do so by an authority.
THE PURPOSES OF THE DATA PROCESSING
The User’s Data are collected to enable the Controller to provide its Services, and for the following purposes: Contacting the User, Statistics, Payment management, Interaction with social networks and external platforms, Registration and authentication, Viewing content from external platforms and Location-based interactions.
For further detailed information on the purposes of the processing and the Personal Data materially relevant for each purposes, the User may refer to the relevant sections of this document.
DETAILS ON PERSONAL DATA PROCESSING
- • LOCATION-BASED INTERACTIONS
GEOLOCALISATION (THIS APPLICATION)
This Application can collect, use and share Data on the User’s geographical position in order to provide services based on his or her location.
Most browsers and devices provide pre-set tools to refuse geolocation. Only if the User has expressly authorised geolocation can this Application receive information on their actual geographical position.
Personal Data collected: geographical position.
- STATISTICS
The services contained in this section allow the Controller to monitor and analyse data on traffic and help to track the User’s behaviour.
GOOGLE ANALYTICS WITH ANONYMISED IP (GOOGLE INC.)
Google Analytics is a web analysis service provided by Google Inc. (‘Google’). Google uses the Personal Data collected in order to track and examine use of this Application, compile reports and share them with other services developed by Google.
Google may use Personal Data to contextualise and personalise ads in its advertising network.
This Google Analytics integration renders the User’s IP address anonymous. Anonymisation works by shortening the IP address of Users within the borders of the European Union or in other countries that are party to the agreement on the European Economic Area. Only in exceptional cases is the IP address of Users within the United States sent to the Google servers and shortened.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy – Opt Out
- VIEWING CONTENT FROM EXTERNAL PLATFORMS
This type of service enables content hosted on external platforms to be viewed directly on the pages of this Application and interaction with them.
If such a service is installed, it is possible that, even if Users do not use the service, it will collect data relating to the pages on which it is installed.
GOOGLE FONTS (GOOGLE INC.)
Google Fonts is a font visualisation service operated by Google Inc. which allows this Application to integrate this content into its own pages.
Personal Data collected: Usage Data and various types of Data as specified by the privacy policy of the service.
Place of processing: USA – Privacy Policy
WIDGET GOOGLE MAPS (GOOGLE INC.)
Google Maps is a map visualisation service operated by Google Inc. which allows this Application to integrate this content into its own pages.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy
RIGHTS OF THE USER
Users may exercise certain rights with regard to the Data processed by the Controller.
In the event of greater protection, the User may exercise all the rights set out below. In any other circumstances, the User may contact the Controller to find out which rights apply in his or her case and how to exercise them.
In particular, the User has the right to:
– withdraw consent at any time. The User can withdraw consent previously expressed for the processing of his or her Personal Data.
– object to the processing of his or her Data. The User may object to the processing of his or her Data when this takes place on a legal basis other than consent. Further details on the right to object are given in the section below.
– access his or her Data. The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing, and to receive a copy of the Data processed.
– check and request rectification. The User may check that his or her Data are correct and request that such Data be updated or rectified.
– obtain restriction of processing. When certain conditions are met, the User may request that the processing of his or her Data be restricted. In this case, the Controller will not process the Data for any purpose other than its storage.
– obtain the erasure or removal of his or her Personal Data. When certain conditions are met, the User may request that his or her Data be erased by the Controller.
– receive his or her Data or have those Data transmitted to another controller. The User has the right to receive his or her Data in a structured, commonly used, machine-readable format and, where technically feasible, to have those Data transmitted without hindrance to another controller. This provision is applicable when the Data are processed by automated means and the processing are based on the User’s consent, on a contract to which the User is party or on contractual measures connected with that contract.
DETAILS ON THE RIGHT TO OBJECT
When Personal Data are processed in the public interest, in the exercise of official authority vested in the Controller or in pursuit of a legitimate interest of the Controller, Users have the right to object to the processing for reasons relating to their particular situation.
HOW TO EXERCISE RIGHTS
APPLICABILITY OF GREATER PROTECTION
While most of the provisions of this document apply to all Users, some are expressly subject to the applicability of a greater level of Personal Data protection.
This greater protection is always guaranteed when the processing:
– is carried out by a Controller with registered office in the EU; or
– concerns the Personal Data of Users who are located in the EU and is functional for the purposes of offering goods or services against payment or free of charge to these Users; or
COOKIE POLICY
FURTHER INFORMATION ON PROCESSING
LEGAL PROCEEDINGS
The User’s Personal Data may be used by the Controller in legal proceedings, or in the preliminary stages before legal proceedings are brought, to defend against abuses in the use of this Application or of the related Services on the part of the User.
The User states that he or she is aware that the Controller may be obliged to disclose the Data if ordered to do so by the public authorities.
SPECIFIC INFORMATION
SYSTEM LOGS AND MAINTENANCE
INFORMATION NOT CONTAINED IN THIS POLICY
RESPONSES TO ‘DO NOT TRACK’ REQUESTS
To find out whether any third-party services used support such requests, the User may consult their respective privacy policies.
CHANGES TO THIS PRIVACY POLICY
The Controller reserves the right to make changes to this privacy policy at any time, informing Users of these changes on this page and, if possible, on this Application, and – if technically and legally feasible – by sending a notification to Users through one of the contact details held by the Controller. Please return to this page regularly and check the date of last update at the bottom.
If the changes affect processing whose legal basis is consent, then the Controller will collect the User’s consent again, if necessary.
DEFINITIONS AND LEGAL REFERENCES
PERSONAL DATA (OR DATA)
Personal Data is any information relating to an identified or identifiable natural person, including indirectly, by reference to any other information, including a personal identification number.
This is information collected automatically by this Application (or by third-party applications that this Application uses), including: IP addresses or dominion names of the computers used by the User who connects to this Application, URI (Uniform Resource Identifier) addresses, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s response (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various timings of the visit (e.g. time spent on each page) and details of the navigation paths followed within the Application, particularly as regards the sequence of pages viewed, the parameters of the User’s operating system and computer environment.
USER
The individual using this Application, who must be the Data Subject (or be authorised by the Data Subject), and whose Personal Data are being processed.
DATA SUBJECT
The natural or legal person to whom the Personal Data refer.
PROCESSOR
The natural or legal person, public administration or any other body, association or organisation entrusted by the Controller to process Personal Data, as set out in this privacy policy.
CONTROLLER
The natural or legal person, public administration and any other body, association or entity that is responsible, including jointly with another controller, for deciding the purposes, methods of processing personal data and the tools used, including the security aspects, in relation to the functioning and use of this Application. The Controller is, unless otherwise specified, the owner of this Application.
THIS APPLICATION
The hardware or software through which Users’ Personal Data are collected.
SERVICE
The Service provided by this Application as defined in the relevant terms and conditions (if any) on this website/application.
EUROPEAN UNION (OR EU)
Unless otherwise specified, any reference to the European Union in this document shall be deemed to extend to all current member states of the European Union and the European Economic Area.
COOKIES
Small pieces of data stored on the User’s device.
LEGAL REFERENCES
This privacy policy has been drawn up based on multiple legal regulations, including Articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy policy concerns only this Application.
LAST UPDATED ON: 19/03/2019