Privacy policy
Circular letter on personal data processing performed by the website: fabma.it,in compliance with art. 13 of the European General Data Protection Regulation (GDPR – 2016/679)
Fabma S.N.C. di Luca e Matteo Mantegazza & C., as data controller, notify to data subjects the following information on data processing.
This circular letter is referred to and is valid only for this website (fabma.it) and not for other external websites surfed by the user through links available in fabma.it. The data controller isn’t responsible of processing performed by third part websites. Please take a look to data processing policy when you visit a third part website.
DATA CONTROLLER
The data controller is Fabma S.N.C. di Luca e Matteo Mantegazza & C., VAT number: IT00666060355 and established in Via Umbria 17, 42124 Reggio Emilia (RE) – Italy. You can contact the data controller by the following mail address: info@fabma.it
PURPOSES OF PROCESSING, LEGAL BASIS AND RETENTION TIME
We process personal data only with a proper legal basis established by law. In the following list you can found all the information concerning the purposes of processing, the types of personal data processed, the legal basis and the data retention time.
Purposes of processing | Categories of personal data | Legal Basis | Data retention time |
To browse on the website and guarantee the proper functionality and cyber security to the website itself and other users. | Browsing data | Legitimate interest pursued by the controller to promote his own business through his website, to maintain it online, reachable and to defend itself and the other visitors against possible cyber attacks | Data controller will keep the browsing data for the time strictly necessary to reach processing purposes. For what concern cookies retention time more information are available consulting the website’s Cookie Policy. |
To manage the communication through social networks | Identification data Data related to the data subject profile Data shared by the data subject within the interaction with the data controller | To manage pre-contractual requests submitted by data subjects Legitimate interest of Data Controller concerning the management of communications with data subjects to satisfy specific submitted requests | This data will be processed for the time strictly necessary to manage your request. After this process, data submitted to fulfill your enquiry will be deleted or further processed for other purpose, if a commercial agreement took place (ex. to manage the service provision) |
TYPES OF PERSONAL DATA PROCESSED
Surfing data – Systems and software procedures responsible for the functioning of this website acquire, during their normal operation, several personal data which transmission is implicit in the use of Internet communication protocols.
Those information is not collected to be associated with the purpose to identify data subjects, but them might allow users to be identified through further processing and association with other data held by data controller or third parties.
This category of data includes:
- IP addresses or domain names of computers utilized by users connecting to the site;
- the URI (Uniform Resource Identifier) addresses of the requested resources;
- the time of request;
- the method used in submitting the request to the server;
- the size of file obtained in response;
- the numeric code indicating the status of response given by the server (good result, error, etc.),
- other parameters relating to the operating system and the user’s IT environment.
This data are processed only to obtain anonymous statistical information on the use of the site and to check its proper functioning, and are deleted immediately after processing. The data could be used to ascertain responsibility in case of hypothetical cybercrimes that might damage the website or other users during the browsing session.
The website could also automatically process data through setting cookies in user’s browser. Cookies are small strings of text set during the browsing in the website and, according to their purposes and the values set up, they allow the site and/or third parties to collect information related to the user, usually anonymously. The use of this electronic tool is analytically described through the Cookie Policy of the website.
Personal data sent by the user: Into this website isn’t available any form or other tools throght which users can communicate personal data (identification data, data concerning contact details and postal address, etc.). Any request should be submitted and managed using the contacts of data controller available on the website.
The owner manages part of his online communication through public profiles on social networks.
Comments left below posts/shared content and any other interaction will follow the rules and policies of the social platform (the latter could be configured as an autonomous Data Controller of these treatments, therefore please refer to the privacy policies of the individual social networks).
Private correspondence with data subjects (through the messaging/chat tools provided by the social network itself) will be processed in compliance with the rules of the social platform with the purpose of managing communication and providing answers to the requests of the data subject.
The data may also be processed outside the social network in a pre-contractual and, subsequently, contractual context in case of establishment of a relationship with the data subject.
The owner mainly uses the following social networks: Instagram
Trasmission of PERSONAL TO THIRD PARTIES
Your personal data may be transmitted only to the following third parts:
· Companies which provide IT systems and website management and development services (as e-commerce and secure payment infrastructure, web development consultants, etc.); |
· Companies and professional offices which provide business assistance and consultancy (IT technologies, accounting, etc.); |
· Public institutions, for the fulfillment of legal obligations related to commercial relationship, to investigate on crime or cyber-attacks delivered or suspected to our systems or to other visitors, or to manage disputes. |
Further information related to the third parties who may process your personal data are available by submitting a specific request to the data controller.
PROVISION OF DATA AND CONSEQUENCES OF REFUSAL TO REPLY
The communication of your personal data is mandatory when the process is necessary to browse in the website, to carry out commercial and information requests received through contact forms or personal area, to provide the services and to perform a contract with customers. the denial to submit those data will affect our capability to carry out your requests.
In the other cases, such as for marketing purposes, the transmission of data it’s optional and when necessary dependent to your explicit consent.
RIGHTS OF DATA SUBJECTS
We inform you about the existence of your rights to access to your personal data, to rectify and/or cancel the same, restrict the process performed on your data, object to processing activities and to request data portability (Articles 15 to 22 of the EU Regulations 2016/679 GDPR).
If the data processing has his foundation on your explicit consent (art. 6, § 1, lect. a), you have the right to revoke this consent whenever you want, without to prejudice the lawfulness of previous processing activities.
You can reach the Data controller to ask for more information about data processing o to fill a complaint by contacting the e-mail address:
info@fabma.it
In order to facilitate the detection of your requests about your rights, we suggest to specify in the e-mail subject the following statement: “Request to exercise a data subject right”.
Within the communication it’s important to clarify your identity, the type of your relationship with the Data Controller, the right you’re asking to exercise and all the further information useful to identify the data or the processing involved in your requests. You can also use the form provided by the Italian Supervisory Authority available at the following link: https://www.garanteprivacy.it/home/modulistica-e-servizi-online
You are entitled to file your complaints with the Italian control authority at the Supervisory Authority address for the protection of personal data, by sending a certified e-mail to the address protocollo@pec.gpdp.it or a registered letter addressed to: Piazza Venezia 11, 00187 Roma (Italy), or with the control authority of another EU member country.
This circular letter was updated on 30/04/2024