Information concerning the handling of personal data Pursuant to and for the purposes of Regulation EU 2016/679 or GDPR

 

PURPOSE OF THIS DOCUMENT

This policy provides information on how any personal data collected from users browsing the Site www.oliotoscanoigp.it may be processed.

The policy is provided in accordance with art.13 of Regulation EU 2016/679 and the applicable Italian laws on the protection of the personal data of anyone interacting with the online services offered by: www.oliotoscanoigp.it.

The provisions below also take into account Directive 2002/58/EC and the provisions of the Data Protection Authority on the use of cookies.

It is specified that the consent mechanisms will be evident, brief and easily understandable; if the original conditions for which consent was requested were to be changed, for example if the purpose of data processing changed further consent will be required pursuant to European Regulation no. 679/2016. According to the rules of the Regulations, the treatments carried out by the Consortium for the protection of Toscano PGI Extra Virgin Olive Oil will be based on the principles of lawfulness, correctness, transparency, purpose limitation and conservation, data minimization, accuracy, integrity and confidentiality.

Quite apart from what specified for navigation data, the User is free to provide personal data. It will not be possible to access the site in case of failure to provide personal data.


DATA CONTROLLER

The data controller is the Consortium for the Protection of Toscano PGI Extra Virgin Olive Oil, with registered office in Florence, Viale F.lli Rosselli, 20 to which it can address itself to assert its rights.

The contact details of the Data Controller are listed below:


SCOPE

This policy applies only to the Site and is not applicable to third-party websites that may be accessible via links that connect the Site to other websites, for which the Data Controller is not responsible.


DATA PROCESSING LOCATION

Data in connection with the services offered on the Site (physically located on the server connected to the internet) are processed on the Data Controller’s premises by employees, collaborators or specifically appointed data processors, or by individuals tasked with occasional maintenance operations.


CATEGORIES OF DATA PROCESSED BROWSING DATA

The information technology systems and software procedures used by the Site during the course of its normal operation acquire some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified users but due to its nature, when elaborated and combined with data held by third parties, it may lead to their identification. This category of data includes, for example, IP addresses or the domain names of the computers used by users to connect to the Site; the addresses in URI (Uniform Resource Identifier) format of the resources requested, the time when the request is made, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server (successful, error, etc.) and other parameters concerning the user’s operating system and computer environment. This data is used solely to obtain anonymous statistical information on how the Site is used and to make sure it is working properly. The Data Controller may provide personal data to ascertain liability in the event of hypothetical cybercrimes or to comply with requests authorised by judicial authorities.


DATA PROVIDED VOLUNTARILY BY WEBSITE USERS

By optionally, voluntarily and explicitly sending emails to the addresses published on the Site, or by filling in the request forms or following other procedures available on the Site, the receiver automatically acquires users’ email addresses, required to reply to their requests, and any other personal details included in the emails.

Users are free to provide personal data indicated in specific request forms or in contacts to request the forwarding of informative material or other correspondence. Users who do not provide their data may not be able to receive what they requested.

Information summaries will be provided or displayed on the relevant pages of the Site for specific services on demand.


USERNAME AND PASSWORD

Where access to specific areas of the Site requires the creation of a username and/or a password, Users will be responsible for keeping their access details confidential and inform the Data Controller immediately in the event of their unauthorised use.


COOKIES

Cookies are small text files stored on Users’ devices when they visit a website; they allow the Site to recognise Users’ devices. Cookies have different purposes, for example, they allow users to browse through website pages, remember preferences and, in general, provide a better browsing experience.

Depending on their functions and purposes, cookies can be categorised as technical cookies, profiling cookies and third-party cookies.

For additional information on the cookies used by the Site, please see the relevant section.


PROCESSING METHODS

Personal data are processed, in compliance with the principles of confidentiality, correctness, lawfulness and transparency, with and without electronic or automated, computerized or telematic instruments with logics strictly related to the purposes themselves also through the use of fax, telephone, cell phone, e-mail or other remote communication techniques. To provide a complete service this Site may contain links to other websites that the user can independently decide to consult. All these links are not managed by this Data Controller which, as a consequence, cannot be held responsible for errors, contents, cookies, publications of illegal moral content, advertising banners or files that do not comply with current regulations and compliance with Privacy laws by the above-mentioned sites.


PURPOSE OF THE TREATMENT

The treatment we intend to carry out, with specific consent where necessary, has the following purposes:

a. allow browsing and consultation of the Consortium site for the protection of the Tuscan PGI extra virgin olive oil ;

b. respond to requests for assistance or information, which we will receive via e-mail, telephone or chat through the online application , or through the appropriate form;

c. possibly to elaborate studies, research, market statistics, send informative material ,commercial information , improve the service (“customer satisfaction”) by e-mail or text message, and / or through the use of the telephone with operator and / or through the official pages of the Consortium for the protection of the Toscano PGI Extra Virgin Olive Oil on social networks;

d. marketing and / or promotion purposes, commercial initiatives, advertising purposes, to inform about events and promotions concerning the olive sector, all by e-mail, App, Social, regular mail, newsletter, sending commercial communications and advertising on events offered and organized by the Controller;

e. for exclusive purposes of security and prevention of fraudulent conduct, the Controller establishes an automatic control system that involves the detection and analysis of user behavior on the site associated with the processing of Personal Data including the IP address.


LEGAL BASIS AND MANDATORY OR OPTIONAL NATURE OF DATA PROCESSING

The legal basis of the processing of Personal Data for the purposes referred to in the previous section is art. 6 (1) (b) of the Regulation as the data processing is necessary for the provision of the contracted services. The provision of Personal Data for these purposes is optional but failure to provide it would make it impossible to access to the website.


DATA RECIPIENTS OR CATEGORIES OF RECIPIENTS

For the above-mentioned purposes, personal data may be communicated to the following categories of recipients who will process them in their capacity as Data Processors and/or as natural persons acting under the authority of the Data Controller and Data Processor:

  • subjects who provide website management services for the Site, the IT systems and the communication networks;
  • firms of professionals or companies that provide assistance and advice to the Data Controller.

In any case, data may be transmitted to subjects authorised to access them by national or EU laws or regulations (e.g. public safety authorities, judicial authorities and police).

The complete list of the persons in charge of the processing is available by sending a written request to the Consortium for the protection of Toscano PGI extra virgin olive oil at the address Viale F.lli Rosselli, 20 – 50123 Firenze.


TRANSFERS OF DATA TO THIRD COUNTRIES AND SAFEGUARDS

For the above-mentioned purposes, personal data may be transferred to electronic systems located in EU.


DATA RETENTION

Data will be retained in a format that will consent the identification of the data subjects for the time strictly necessary to achieve the purposes for which they were collected and other authorised and connected purposes in compliance with the applicable legislation. Once the above mentioned storage terms have expired, the data will be destroyed or made anonymous, compatibly with the technical procedures of deletion and backup.


RIGHTS OF THE INTERESTED PARTY

Pursuant to articles 15, 16, 17, 18, 20, 21 and 22 of EU Regulation no. 2016/679, the interested party has the right to obtain confirmation that data concerning him is being processed and, in this case, to obtain access to the data and the following information.

The interested party has the right to obtain the indication:

a. of the purposes of the processing;

b. the categories of personal data in question;

c. the recipients or the categories of recipients to whom the personal data have been or will be communicated, in particular for recipients of third countries or international organizations;

d. whenever possible, the period of storage of personal data provided or, if it is not possible, the criteria used to determine this period;

e. all available information on the origin of the data if it is not collected by the data subject;

f. the existence of an automated decision-making process, including profiling.

The interested party also has:

a. the right to obtain from the data controller the correction of inaccurate personal data concerning him without undue delay;

b. the right to obtain from the data controller the cancellation (“right to be forgotten”) of personal data concerning him without undue delay;

c. the right to obtain treatment limitation from the data controller;

d. the right to object at any time, for reasons connected with his particular situation, to the processing of personal data;

e. the right to receive personal data concerning him in a structured, commonly used and automatically readable form;

f. the right to withdraw consent at any time;

g. the right to lodge a complaint with a supervisory authority;

h. the right to be informed of the existence of adequate safeguards, if personal data are transferred to a third country or to an international organization;

i. the right to obtain a copy of the data being processed.

To exercise these rights, you can contact the Data Controller at the contact points indicated in paragraph 1- Data Controller, by submitting a specific request by registered letter, fax and / or e-mail.


RIGHT TO COMPLAIN

Data subjects who believe that the processing of their personal data conducted through this site violates the GDPR and national legislation provisions have the right to submit a complaint to the Data Protection Authority, or seek a judicial remedy.


AMENDMENTS TO THIS PRIVACY POLICY

The Data Controller reserves the right to update this Privacy Policy at any time to comply with legislation changes and to improve it, taking into account suggestions put forward by customers, collaborators and users.