This information is in compliance with the provisions of EU Regulation 679/2016 (hereinafter, "Regulation") and any specific local rules applicable to the protection of personal data processed in the manner indicated below.
DATA CONTROLLER AND DATA PROTECTION
The Owner of the Personal Data collected concerning the User and the Company VST srl based in Fabriano (AN) 60044, Via Martiri delle Foibe Istriane n. 7/L, VAT IT02597550421, (hereinafter, "Acupuncture”).
ACUPUNCTURE has a data protection officer and a "Privacy" unit that can be contacted by e-mail at the dedicated firstname.lastname@example.org..
Should, concerning specific data processing purposes, Acupucture. be joint controller with third parties, or third parties are controller for to the processing of your personal data, you will be provided with all the necessary information prior to you providing us your personal information.
TYPE OF DATA COLLECTED
The personal data processed are collected as provided directly by the interested party or collected automatically.
The data provided directly by the interested party are all personal data that are provided to the Data Controller in any way, directly by the interested party.
The data collected automatically are navigation data. Such data, although not collected in order to be associated with the user's identity, could indirectly, through processing and association with data collected by the Data Controller, allow its identification.
Among the Personal Data collected by this Application, independently or through third parties, there are: first name, surname, password, email, telephone number, billing address, shipping address, house number, city, province, ZIP code, Usage Data, Cookies, Tax Code.
PURPOSE AND LEGAL BASIS OF PROCESSING
The personal Data collected will be acquired and processed always in compliance with the principles of lawfulness established by the law to enable us to:
- guarantee the smooth navigation of the Site, which necessitates processing to navigate the Site and fulfil legal obligations;
- process your request to purchase products from the Acupuncture or to use the services offered by the Site, which necessitates processing to execute on contractual and/or pre-contractual measures taken upon your request;
- reply to your contact requests, which necessitates processing to execute on contractual and/or pre-contractual measures taken upon your request;
- Performing marketing activities both via automatic means (text messages, MMSs, messaging platforms, e-mails, push notifications) and not automatic means (mail, phone with operator), if you provide your explicit consent.
- Marketing activities can be done by sending newsletters, or through promotions, discounts, incentives, commercial information and other related means, by mail, phone call, direct sales, email, automatic voice calls, messaging platforms, text messages and/or MMSs.
- conduct customer profiling activities, if you provide your explicit consen
- Customer profiling can be conducted by analysing the Customer interests and preferences regarding Owner products and services, as well as your shopping habits.
Finally, the Owner may also process your personal data to comply with any legal obligations that it may have and to pursue his legitimate interests or that of third parties, in compliance with the conditions and limits set by the current legislation.
The Data are processed and stored for the time required by the purposes for which they were collected.
- Personal Data collected for purposes related to the execution of a contract between the Owner and the User will be retained until the execution of this contract is completed.
- The Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained until this interest is satisfied. The User can obtain further information regarding the legitimate interest pursued by the Owner in the relevant sections of this document or by contacting the Owner.
When the processing is based on the User's consent, the Data Controller can keep the Personal Data longer until such consent is revoked. Furthermore, the Data Controller may be obliged to keep Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, the Personal Data will be deleted. Therefore, at the end of this term the right of access, cancellation, rectification and the right to data portability can no longer be exercised.
The personal data will process by means of telematic, paper and computer tools, and such processing will be based on the principles of fairness, lawfulness, and transparency to protect your rights and privacy. In particular, the processing of your data, also for purposes of customer profiling, may be automated, for example through a comparative analysis of your purchases (types, quantities, frequency, timing etc.), and through the analysis of the type and number of your requests for product information within a given timeframe.
The data will be process in a manner that will minimize the risk of destruction, loss, and unauthorized access to your data or any unauthorized or non-compliant processing.
DETAILS ON THE PROCESSING OF PERSONAL DATA
Personal Data is collected for the following purposes and using the following services:
Contact Form (SERVICE) (This Application)
By filling in the contact form with User Data, he consents to their use to respond to requests for information, quotes, or any other nature indicated by the form header.
Personal data collected: email, name and phone number.
- Mailing list or newsletter (This Application)
By registering for the mailing list or newsletter, the User's email address is automatically entered in a list of contacts to which email messages containing information, including commercial and promotional information, relating to this Application may be transmitted. Your email address may also be added to this list as a result of registering for this Application or after making a purchase.
Personal data collected: email and name.
- Payment management
Payment management services allow this Application to process payments by PayPal or credit card. The data used for the payment are acquired directly by the requested payment service manager without being in any way processed by this Application.
Some of these services may also allow the scheduled sending of messages to the User, such as emails containing invoices or notifications regarding payment.
PayPal is a payment service provided by PayPal Inc., which allows the User to make payments online.
- Shopify Payments
Shopify Paymentsis a payment service provided by Shopify International Limited, which allows the User to make payments online.
- Registration and authentication
By User registration or authentication, the User allow the Application to identify him and give him access to dedicated services. Depending on the following, registration and authentication services may be provided with the help of third parties. If this happens, this application may access some Data stored by the third-party service used for registration or identification.
- Direct Recording (This Application)
The User registers by filling out the registration form and providing his Personal Data directly to this Application.
Personal Data collected: name, surname, User ID, password, email, telephone number, billing address, shipping address, house number, city, province, postcode, usage data, cookies, tax code.
The services contained in this section allow the Data Controller to monitor and analyze traffic data and serve to track the User's behavior.
- Statistics collected directly (This Application)
This Application uses an internal statistics system, which does not involve third parties.
Personal data collected: Cookies and Usage Data.
- Tag management
This type of service is functional to the centralized management of the tags or scripts used on this Application.
The use of these services involves the flow of User Data through them and, if necessary, their retention.
- Google Tag Manager (Google Inc.)
Google Tag Manager is a tag management service provided by Google LLC.
Personal data collected: Cookies and Usage Data.
MORE INFORMATION ABOUT PERSONAL DATA
- Selling goods and services online
The Personal Data collected is used for the provision of services to you or for the sale of products, including payment and possible delivery. The Personal Data collected to refine the payment may be those relating to the credit card, used for the payment instruments provided. The payment data collected by this Application depends on the payment system used.
Users may exercise certain rights with reference to the Data processed by the Data Controller.
In particular, he has the right to:
- withdraw consent at all times. The User may withdraw him consent to the processing of your personal data previously expressed.
- to oppose the processing of its Data. The user can oppose the processing of their data when it occurs on a legal basis other than consent. Further details on the right to object are indicated in the section below.
- access their Data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing and to receive a copy of the Data processed.
- check and ask for rectification. The User can verify the correctness of his Data and request its updating or correction.
- to obtain the treatment limitation. When certain conditions are met, the User may request the limitation of the processing of their Data. In this case, the Data Controller will not process the Data for any other purpose other than their conservation.
- obtain the cancellation or removal of his Personal Data. When certain conditions are met, the User may request the cancellation of his Data by the Owner.
- receive their Data or have them transferred to another data controller. The User has the right to receive his / her Data in a structured format, commonly used and readable by an automatic device and, where technically feasible, to obtain its unhindered transfer to another owner. This provision is applicable when the Data is processed with automated tools and the processing is based on the User's consent, on a contract to which the User is a party or on contractual measures connected to it.
- propose a complaint. The User can lodge a complaint with the competent personal data protection supervisory authority or act in court.
DETAILS OF THE RIGHT OF OPPOSITION
When Personal Data are processed in the public interest, in the exercise of public authority vested in the Owner or to pursue a legitimate interest of the Owner, Users have the right to object to the processing for reasons related to their particular situation.
Users are reminded that, if their data are processed for direct marketing purposes, they can oppose the processing without providing any reasons. To find out if the Data Controller processes data for direct marketing purposes, Users can refer to the respective sections of this document.
HOW TO EXERCISE RIGHTS
To exercise the rights of the User, Users can direct a request to the contact Owner in e-mail address email@example.com. Requests are filed free of charge and processed by the Data Controller as soon as possible, in any case within one month.
LEARN MORE ABOUT TREATMENT
DEFENCE IN COURT
The User's Personal Data may be used by the Owner in court or in the preparatory stages for its eventual establishment for the defense against abuse in the use of this Application or related Services by the User.
The User declares to be aware that the Owner may be obliged to disclose the Data by order of the public authorities.
SYSTEM LOGS AND MAINTENANCE
For needs related to operation and maintenance, this Application and any third parts services used by it may collect system logs, which are files that record the interactions and which may also contain Personal Data, such as the User IP address.
INFORMATION NOT CONTAINED IN THIS POLICY
Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using contact details.
If the changes affect treatments whose legal basis is consent, the Data Controller will collect the User's consent again, if necessary.
PERSONAL DATA (OR DATA)
Any information that, directly or indirectly, also in connection with any other information, including a personal identification number, makes a natural person identified or identifiable constitutes personal data.
This is the information collected automatically through this Application (including from third-party applications integrated into this Application), including: IP addresses or domain names of the computers used by the User connecting with this Application, addresses in URI notation ( Uniform Resource Identifier), the time of the request, the method used in forwarding the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.) country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (for example the time spent on each page) and the details of the itinerary followed within the Application, with particular reference the sequence of pages consulted, the parameters relating to the operating system and the IT environment of the User.
The person who uses this application who, unless otherwise specified, coincides with the interested party.
The natural person to whom personal data relates.
DATA CONTROLLER (OR OWNER)
DATA CONTROLLER (OR PROPRIETOR)
The natural or legal person, the public authority, the service or other body which, individually or together with others, determines the purposes and means of processing personal data and the tools adopted, including security measures relating to the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.
The hardware or software tool through which the User Personal Data are collected and processed.
The Service provided by this Application as defined in its terms (if any) on this site/application.
EUROPEAN UNION (OR EU)
Unless otherwise specified, any reference to the European Union contained in this document is intended to be extended to all current Member States of the European Union and the European Economic Area.
Cookies are small text strings that the visited website sends to User's device.