Privacy Policy of www.sacchettovini.it
This Application collects some Personal Data from its Users.
Pursuant to EU Regulation 679/2016, containing provisions for the protection of natural persons with regard to the processing of personal data, Sacchetto S.r.l., owner of the domain name www.sacchettovini.it, email mail_at_sacchettovini.it, with registered office in Via Roma 44 – 35010 Trebaseleghe (PD) hereinafter referred to as the “Owner” in its capacity as Data Controller, is required to provide certain information regarding the use of personal data and cookies.
This privacy policy applies exclusively to the online activities of this site and is valid for visitors/users/buyers of the site, who may hereinafter also be referred to simply as “data subjects.” It does not apply to any information collected through channels other than this website.
The purpose of this privacy policy is to provide maximum transparency regarding the information the site collects and how it uses it.
This document can be printed using the print command in the settings of any browser.
Types of Data Collected
Among the types of Personal Data collected by this Application, either independently or through third parties, there are: Cookies; Usage Data; first name; last name; address; country; email address; ZIP/Postal code; city; unique device identifiers for advertising (for example, Google Advertiser ID or IDFA).
Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed before the data are collected.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Application.
Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to provide this Data, it may be impossible for this Application to provide its Service. In cases where this Application indicates some Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability or operation of the Service.
Users who have doubts about which Data are mandatory are encouraged to contact the Owner.
Any use of Cookies – or other tracking tools – by this Application or by the owners of third-party services used by this Application, unless otherwise specified, is intended to provide the Service requested by the User, in addition to any other purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Application and guarantees that he or she has the right to communicate or disseminate them, freeing the Data Controller from any liability towards third parties.
Methods and place of processing of collected data
Treatment methods
The Data Controller takes appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.
The processing is carried out using computer and/or electronic means, following organizational methods and procedures strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the operation of this Application (administrative, commercial, marketing, legal, and system administrators) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, and communications agencies) may have access to the Data, also appointed, if necessary, as Data Processors by the Data Controller. The updated list of Data Processors may be requested from the Data Controller at any time.
Legal basis for processing
The Data Controller processes Personal Data relating to the User if one of the following conditions applies:
- the User has given consent for one or more specific purposes; Note: Under some jurisdictions, the Data Controller may be authorized to process Personal Data without the User’s consent or any other of the legal bases specified below, until the User objects to such processing (“opt-out”). However, this does not apply if the processing of Personal Data is regulated by European data protection legislation;
- processing is necessary for the performance of a contract with the User and/or for the execution of pre-contractual measures;
- processing is necessary for compliance with a legal obligation to which the Data Controller is subject;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
- processing is necessary for the pursuit of the legitimate interest of the Data Controller or third parties.
- However, it is always possible to ask the Data Controller to clarify the specific legal basis for each processing operation and, in particular, to specify whether the processing is based on the law, provided for by a contract, or necessary to conclude a contract.
Place
The Data is processed at the Data Controller’s operating offices and in any other places where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User’s Personal Data may be transferred to a country other than their own. To obtain further information on the place of processing, the User can refer to the section containing details on the processing of Personal Data.
The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization governed by public international law or consisting of two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect the Data.
The User can verify whether one of the transfers described above is taking place by examining the section of this document relating to the details on the processing of Personal Data or by requesting information from the Data Controller by contacting him/her using the contact details provided at the beginning.
Retention period
The Data is processed and stored for the time required by the purposes for which it was collected.
Therefore:
Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until such contract has been fully performed.
Personal Data collected for purposes related to the Data Controller’s legitimate interest will be retained until such interest has been fulfilled. The User can obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
When processing is based on the User’s consent, the Data Controller may retain Personal Data for a longer period until such consent is revoked. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, the Personal Data will be deleted. Therefore, upon expiration of this period, the right to access, erasure, rectification, and the right to data portability can no longer be exercised.
Purpose of the Processing of Collected Data and Methods of Storage
User Data is collected to allow the Owner to provide its Service, comply with legal obligations, respond to requests or enforcement actions, protect its rights and interests (or those of Users or third parties), identify any malicious or fraudulent activity, as well as for the following purposes: Analytics, Contacting the User, Interaction with external social networks and platforms, SPAM protection, Displaying content from external platforms, Tag Management, Remarketing and behavioral targeting, and Advertising. In particular, the data may be processed for the following purposes:
- in an exclusively aggregated and anonymous form to verify the proper functioning of the site. None of this information is related to the individual User of the site, and does not allow for their identification in any way (as of May 25, 2018, this information will be processed based on the legitimate interests of the Data Controller);
- For security purposes (spam filters, firewalls, virus detection), automatically recorded data may also include personal data such as the IP address, which could be used, in accordance with applicable laws, to block attempts to damage the site itself or other users, or otherwise engage in harmful or criminal activities. This data is never used to identify or profile the user, nor is it cross-referenced with other data, nor is it provided to third parties, but is used only to protect the site and its users (as of May 25, 2018, this information will be processed based on the legitimate interests of the data controller);
- commercial and contractual purposes and the consequent fulfillment of legal and contractual obligations arising from the online purchase of products listed on the site, as well as to effectively manage these commercial relationships. Your personal data will be processed exclusively for the purpose of carrying out all activities related to and instrumental to the proper management and execution of tax and accounting obligations, including the management and execution of any contracts, administration, and payment processing;
- techniques necessary for the survival of the website;
- The Data Controller also uses the User’s data for promotional/advertising purposes, to send information on the items offered on the website sacchettovini.it. The User’s email address will be used exclusively within the limits prescribed by applicable law or, where necessary, after the User has provided specific authorization. The Data Subject, as a User of www.sacchettovini.it, will regularly receive “purchase tips” via email. You may unsubscribe from receiving these promotional messages free of charge by sending a request via email to mail@sacchettovini.it.
The data received will be used exclusively to process the purchase order or for requests made by the User and only for the time necessary to provide the service. However, please note that when the User visits the website www.sacchettovini.it, some data is collected and stored. The domain name or IP address of the accessing computer is temporarily stored for security reasons and deleted after a maximum of 7 (seven) days. Other data, such as the access date, response code, and the amount of data (bytes) transmitted, may also be stored. Data analysis is performed only in a strictly anonymous form (for example: 45% of newsletter readers have read message xy). This process allows the Data Controller to tailor the information contained in the offers to the interests of newsletter subscribers, which is sent in the following manner: the customer will receive the newsletter only if he or she clicks on the link in the information email confirming the activation of the newsletter service.
It is the User’s responsibility to verify that they have permission to enter personal data of third parties or content protected by national and international regulations.
In any case, the data collected by the site during its operation are used exclusively for the purposes indicated above and stored for the time strictly necessary to carry out the specified activities.
In any case, the personal data collected by the site will never be disclosed to third parties, for any reason, unless there is a legitimate request from a judicial authority and only in the cases provided for by law. However, the data may be disclosed to third parties if necessary to provide a specific service requested by the User or to perform security checks or optimize the site.
To obtain detailed information on the purposes of the processing and on the Personal Data processed for each purpose, the User may refer to the section “Details on the Processing of Personal Data”.
Scope of dissemination and categories of subjects
Personal data will be disclosed and processed, in compliance with applicable legislation, by the Data Controller’s personnel, designated as data processors, working in the relevant offices. The personal data collected by the Data Controller may also be disclosed, within the limits strictly relevant to the aforementioned purposes, to the following entities or categories of entities:
- entities to whom communication is required by law, regulation, or national and EU legislation (for example, public administrations and entities whose duties include protection and safety in the workplace) as well as for the performance of contractual or pre-contractual obligations (Credit Institutions, Insurance Companies, and similar entities);
- subjects to whom it is essential to communicate such data for activities strictly related to the existing relationship with the Data Controller, for example consultants, professionals, collaborators or suppliers who collaborate with the organization for aspects related to business management;
- Legal, accounting, and employment consultants, including for the purpose of studying and resolving any legal issues relating to existing contractual positions (for example, lawyers, for the purposes of managing criminal, civil, and administrative litigation; judicial authorities of any order and level, arbitrators; independent professionals, for the purposes of advocacy or consultancy, including those of the opposing party when applicable; insurance companies, in the case of insurance policies that provide for such communications).
Details on the Processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
Contact the User
Contact form (this Application)
By filling out the contact form with their Data, the User consents to their use to respond to requests for information, quotes, or any other kind indicated by the form header.
Personal Data processed: ZIP code; city; last name; email address; address; country; first name.
Mailing list or newsletter (this Website)
By registering for the mailing list or newsletter, the User’s email address is automatically added to a contact list to which email messages containing information, including commercial and promotional information, relating to this Website may be sent. The User’s email address may also be added to this list as a result of registering on this Website or after making a purchase.
Personal Data processed: email address; name.
Managing contacts and sending messages
This type of service allows us to manage a database of email contacts, telephone contacts, or any other type of contact used to communicate with the User.
These services may also collect data relating to the date and time the messages are viewed by the User, as well as the User’s interaction with them, such as information on clicks on links included in messages.
Mailchimp (The Rocket Science Group LLC)
Mailchimp is an email address management and message sending service provided by The Rocket Science Group LLC.
Personal Data processed: email address; name.
Place of processing: United States – Privacy Policy.
Interaction with data collection platforms and other third parties
This type of service allows Users to interact with data collection platforms or other services directly from the pages of this Website for the purpose of saving and reusing data.
If one of these services is installed, it is possible that, even if Users do not use the service, it may collect Usage Data relating to the pages on which it is installed.
Widget Mailchimp (The Rocket Science Group LLC)
The Mailchimp widget allows you to interact with the Mailchimp email address management and message sending service provided by The Rocket Science Group LLC.
Personal Data processed: email address; name.
Place of processing: United States – Privacy Policy.
Registration and authentication
By registering or authenticating, the User allows this Website to identify them and grant them access to dedicated services.
Depending on what is specified below, registration and authentication services may be provided with the help of third parties. If this occurs, this Website will be able to access certain Data stored by the third-party service used for registration or identification.
Some of the services listed below may also collect Personal Data for targeting and profiling purposes; for more information, please refer to the description of each service.
Mailchimp OAuth (The Rocket Science Group LLC)
Mailchimp OAuth is a registration and authentication service provided by The Rocket Science Group LLC and connected to the Mailchimp service.
Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
Tag Management
This type of service is functional to the centralized management of the tags or scripts used on this Application.
The use of these services involves the flow of User Data through them and, if applicable, their retention.
Google Tag Manager (Google Ireland Limited)
Google Tag Manager is a tag management service provided by Google Ireland Limited.
Personal Data processed: Usage Data.
Place of processing: Ireland – Privacy Policy. Privacy Shield participant.
Interaction with social networks and external platforms
This type of service allows interaction with social networks or other external platforms directly from the pages of this Application.
The interactions and information acquired by this Application are in any case subject to the User’s privacy settings for each social network.
This type of service may still collect traffic data for the pages where the service is installed, even when Users do not use it.
It is recommended to log out of the respective services to ensure that the data processed on this Application is not linked to the User’s profile.
Facebook Like button and social widgets (Facebook, Inc.)
The “Like” button and Facebook social widgets are services allowing interaction with the Facebook social network, provided by Facebook, Inc.
Personal Data processed: Cookies; Usage Data.
Place of processing: United States – Privacy Policy. Privacy Shield participant.
SPAM Protection
This type of service analyzes the traffic of this Application, potentially containing Users’ Personal Data, in order to filter it from parts of traffic, messages and contents recognized as SPAM.
Google reCAPTCHA (Google Ireland Limited)
Google reCAPTCHA is a SPAM protection service provided by Google Ireland Limited.
Use of the reCAPTCHA system is subject to Google’s privacy policy and terms of use.
Personal Data processed: Cookies; Usage Data.
Place of processing: Ireland – Privacy Policy. Privacy Shield participant.
Advertising
This type of service allows User Data to be used for commercial communication purposes. These communications are displayed on this Application in the form of banners and other forms of advertising, including those related to the User’s interests.
This does not mean that all Personal Data is used for this purpose. Information and conditions of use are provided below.
Some of the services listed below may use Cookies or other Identifiers to identify the User or use behavioral retargeting, i.e., displaying personalized ads based on the User’s interests and behavior, including those detected outside this Application. For more information, we recommend checking the privacy policies of the respective services.
In addition to the opt-out features offered by the services listed below, the User can opt out by visiting the Network Advertising Initiative opt-out page.
Users may also opt-out of certain advertising features through applicable device settings, such as the device’s mobile advertising settings or general advertising settings.
Facebook Lookalike Audience (Facebook, Inc.)
Facebook Lookalike Audience is an advertising and behavioral targeting service provided by Facebook, Inc. that uses the data collected through Facebook Custom Audience to display ads to users with similar behavior to users who are already in a Custom Audience list based on their previous use of this Application or their interaction with relevant content across Facebook apps and services.
Based on this data, personalized ads will be shown to users suggested by Facebook Lookalike Audience.
Users can opt out of Facebook’s use of cookies for ad personalization by visiting this opt-out page.
Personal Data processed: Cookies; Usage Data.
Place of processing: United States – Privacy Policy – Opt Out. Privacy Shield participant.
Remarketing e behavioral targeting
This type of service allows this Application and its partners to communicate, optimize, and serve advertising based on the User’s past use of this Application.
This activity is facilitated by tracking Usage Data and by using Cookies and other Identifiers to collect information that is then transferred to the partners who manage remarketing and behavioral targeting activities.
Some services offer a remarketing option based on email address lists.
In addition to the opt-out features offered by the services listed below, the User can opt out by visiting the Network Advertising Initiative opt-out page.
Users may also opt-out of certain advertising features through applicable device settings, such as the device’s mobile advertising settings or general advertising settings.
Facebook Custom Audience (Facebook, Inc.)
Facebook Custom Audience is a remarketing and behavioral targeting service provided by Facebook, Inc. that connects the activity of this Application with the Facebook advertising network.
Users can opt out of Facebook’s use of cookies for ad personalization by visiting this opt-out page.
Personal Data processed: Cookies; email address.
Place of processing: United States – Privacy Policy – Opt Out. Privacy Shield participant.
Facebook Remarketing (Facebook, Inc.)
Facebook Remarketing is a remarketing and behavioral targeting service provided by Facebook, Inc. that connects the activity of this Application with the Facebook advertising network.
Personal Data processed: Cookies; Usage Data.
Place of processing: United States – Privacy Policy – Opt Out. Privacy Shield participant.
Remarketing Google Ads (Google Ireland Limited)
Google Ads Remarketing is a remarketing and behavioral targeting service provided by Google Ireland Limited that connects the activity of this Application with the Google Ads advertising network and the DoubleClick Cookie.
Users can opt out of Google’s use of cookies for ad personalization by visiting Google’s Ads Settings.
Personal Data processed: Cookies; Usage Data.
Place of processing: Ireland – Privacy Policy – Opt Out. Privacy Shield participant.
Statistic
The services contained in this section allow the Data Controller to monitor and analyze traffic data and are used to track User behavior.
Google Analytics (Google Ireland Limited)
Google Analytics is a web analytics service provided by Google Ireland Limited (“Google”). Google uses the Personal Data collected to track and examine the use of this Application, compile reports, and share them with other Google services.
Google may use Personal Data to contextualize and personalize ads on its own advertising network.
Personal Data processed: Cookies; Usage Data.
Place of processing: Ireland – Privacy Policy – Opt Out. Privacy Shield participant.
Facebook Analytics for Apps (Facebook, Inc.)
Facebook Analytics for Apps is a statistics service provided by Facebook, Inc.
Personal Data processed: Usage Data; various types of Data as specified in the service’s privacy policy.
Place of processing: United States – Privacy Policy. Privacy Shield participant.
Facebook Ads conversion tracking (Facebook pixel) (Facebook, Inc.)
Facebook Ads conversion tracking (Facebook pixel) is a statistics service provided by Facebook, Inc. that connects data from the Facebook advertising network with actions performed within this Application. The Facebook pixel tracks conversions that can be attributed to Facebook, Instagram, and Audience Network ads.
Personal Data processed: Cookies; Usage Data.
Place of processing: United States – Privacy Policy. Privacy Shield participant.
Google Analytics Demographics and Interest Reporting (Google Ireland Limited)
Google Analytics Demographics and Interests Reporting is an advertising reporting feature that makes demographic and interest data available within Google Analytics for this Application (demographic data means age and gender data).
Users can choose not to use Google cookies by visiting Google’s Ads Settings.
Personal Data processed: Cookies; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example).
Place of processing: Ireland – Privacy Policy – Opt Out. Privacy Shield participant.
Viewing content from external platforms
This type of service allows you to view content hosted on external platforms directly from the pages of this Application and interact with them.
This type of service may still collect web traffic data relating to the pages where the service is installed, even when users do not use it.
Google Fonts (Google Ireland Limited)
Google Fonts is a font display service managed by Google Ireland Limited that allows this Application to integrate such content within its pages.
Personal Data processed: Usage Data; various types of Data as specified in the service’s privacy policy.
Place of processing: Ireland – Privacy Policy. Privacy Shield participant.
Widget Video YouTube (Google Ireland Limited)
YouTube is a video content viewing service managed by Google Ireland Limited that allows this Application to integrate such content within its pages.
Personal Data processed: Cookies; Usage Data.
Place of processing: Ireland – Privacy Policy. Privacy Shield participant.
Widget Google Maps (Google Ireland Limited)
Google Maps is a map viewing service managed by Google Ireland Limited that allows this Application to integrate such content within its pages. Personal Data processed: Cookies; Usage Data.
Place of processing: Ireland – Privacy Policy. Subject adhering to the Privacy Shield.
User Rights
Users may exercise certain rights with reference to the Data processed by the Data Controller.
In particular, the User has the right to:
- withdraw consent at any time. The User may withdraw consent to the processing of their Personal Data previously expressed.
- Object to the processing of your data. Users may object to the processing of their data when it occurs on a legal basis other than consent. Further details on the right to object are provided in the section below.
- Access your Data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing, and to receive a copy of the processed Data.
- Verify and request rectification. The User can verify the accuracy of their Data and request its updating or correction.
- Obtain restriction of processing. When certain conditions apply, the User may request restriction of the processing of their Data. In this case, the Data Controller will not process the Data for any purpose other than its storage.
- obtain the deletion or removal of their Personal Data. Under certain conditions, the User may request that the Data Controller delete their Data.
- Receive your Data or have it transferred to another controller. The User has the right to receive his or her Data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transferred to another controller without hindrance. This provision applies when the Data is processed by automated means and the processing is based on the User’s consent, on a contract to which the User is a party, or on contractual obligations related to it.
- File a complaint. The User may file a complaint with the competent data protection supervisory authority or take legal action.
Details on the right to object
When Personal Data is processed in the public interest, in the exercise of public authority vested in the Data Controller, or to pursue a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.
Users are informed that, if their data is processed for direct marketing purposes, they can object to the processing without providing any justification. To find out whether the Data Controller processes data for direct marketing purposes, Users can refer to the relevant sections of this document.
How to exercise your rights
To exercise User rights, Users may direct a request to the Data Controller’s contact details provided in this document. Requests are submitted free of charge and processed by the Data Controller as quickly as possible, in any case within one month.
Cookie Policy
This Application uses Tracking Tools. To learn more, the User can consult the Cookie Policy.
Further information on treatment
Defense in court
The User’s Personal Data may be used by the Data Controller in court or in the preparatory stages leading to possible legal action for the defense against improper use of this Application or related Services by the User.
The User declares to be aware that the Data Controller may be required to disclose the Data by order of public authorities.
Specific information
Upon the User’s request, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.
System logs and maintenance
For operational and maintenance purposes, this Application and any third-party services it uses may collect system logs, which are files that record interactions and may also contain Personal Data, such as the User’s IP address.
Information not contained in this policy
Further information regarding the processing of Personal Data may be requested from the Data Controller at any time using the contact details.
Response to “Do Not Track” requests
This Application does not support “Do Not Track” requests.
To find out whether any third-party services used support them, the User is invited to consult their respective privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Application and, where technically and legally feasible, by sending a notification to Users via one of the contact details available to the Data Controller. Therefore, please check this page frequently, referring to the date of the last modification indicated at the bottom.
If the changes affect processing whose legal basis is consent, the Data Controller will collect the User’s consent again, if necessary.
Definitions and legal references
Personal Data (or Data)
Personal data is any information that, directly or indirectly, even in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.
Usage Data
This information is collected automatically through this Application (including third-party applications integrated into this Application), including: IP addresses or domain names of the computers used by the User who connects to this Application, URI (Uniform Resource Identifier) addresses, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (for example, the time spent on each page) and the details relating to the path followed within the Application, with particular reference to the sequence of pages visited, the parameters relating to the operating system and the User’s IT environment.
User
The individual who uses this Application who, unless otherwise specified, coincides with the Data Subject.
Interested
The natural person to whom the Personal Data refers.
Data Controller (or Controller)
The natural person, legal person, public administration or any other entity that processes personal data on behalf of the Data Controller, as set out in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data and the tools used, including the security measures relating to the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.
This Application
The hardware or software tool by which the Personal Data of Users is collected and processed.
Service
The Service provided by this Application as defined in the relevant terms (if any) on this site/application.
European Union (or EU)
Unless otherwise specified, any reference to the European Union contained in this document shall be deemed to extend to all current member states of the European Union and the European Economic Area.
Cookie
Small portion of data stored within the User’s device.
Legal references
This privacy policy is drafted on the basis of multiple legislative provisions, including Articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy policy applies exclusively to this Application.
Last modified: 07/12/2020