Privacy Policy
Data Controller
Azienda Agricola Colle San Massimo,
Via Colle San Massimo 15,
64021 Case di Trento (TE)
VAT No. 06933180967
Data Controller’s email address: collesanmassimo@gmail.com
Types of Data collected
Among the Personal Data collected by this Application, either independently or through third parties, there are: Cookies; Usage Data; first name; last name; email; various types of Data; Data communicated during the use of the service.
Complete details on each type of Data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed before the Data collection itself.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application.
Unless otherwise specified, all Data requested by this Application are mandatory. If the User refuses to provide them, it may be impossible for this Application to provide the Service. In cases where this Application indicates certain Data as optional, Users are free to refrain from communicating such Data without affecting the availability or operation of the Service.
Users who are uncertain about which Data are mandatory are encouraged to contact the Data Controller.
The possible use of Cookies – or other tracking tools – by this Application or by third-party service providers used by this Application, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to the other purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Application and guarantees that they have the right to communicate or disseminate them, releasing the Data Controller from any liability toward third parties.
Methods and place of processing the collected Data
Methods of processing
The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.
Processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other subjects involved in the organization of this Application (administrative, commercial, marketing, legal staff, system administrators) or external subjects (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) may have access to the Data. These subjects may also be appointed, if necessary, as Data Processors by the Data Controller. The updated list of Data Processors can always be requested from the Data Controller.
Legal basis of processing
The Data Controller processes Personal Data relating to the User if one of the following conditions applies:
- the User has given consent for one or more specific purposes; Note: in some jurisdictions, the Data Controller may be allowed to process Personal Data without the User’s consent or another legal basis specified below, until the User objects (“opt-out”) to such processing. This does not apply when the processing of Personal Data is regulated by European data protection legislation;
- processing is necessary for the performance of a contract with the User and/or for pre-contractual measures;
- processing is necessary to comply with a legal obligation to which the Data Controller is subject;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
- processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by third parties.
It is always possible to request clarification from the Data Controller regarding the specific legal basis of each processing activity and, in particular, to specify whether the processing is based on law, provided for by a contract, or necessary to conclude a contract.
Place
The Data is processed at the operational offices of the Data Controller and in any other place where the parties involved in the processing are located. For further information, contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information about the place of processing, the User may refer to the section relating to details on the processing of Personal Data.
The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization governed by public international law or formed by two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect the Data.
The User may verify whether one of the transfers described above takes place by examining the relevant section of this document concerning the processing of Personal Data or by requesting information from the Data Controller using the contact details provided above.
Retention period
The Data is processed and stored for the time required for the purposes for which it was collected.
Pertanto:
- Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until such contract has been fully executed.
- Personal Data collected for purposes connected to the legitimate interest of the Data Controller will be retained until such interest has been satisfied. The User may obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
When processing is based on the User’s consent, the Data Controller may retain Personal Data for a longer period until such consent is withdrawn. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, Personal Data will be deleted. Therefore, once this period has expired, the rights of access, deletion, rectification, and data portability can no longer be exercised.
Purposes of the Data collected
The User’s Data is collected to allow the Data Controller to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect its own rights and interests (or those of Users or third parties), detect any malicious or fraudulent activity, as well as for the following purposes: Advertising, Statistics, Contacting the User, Interaction with social networks and external platforms, Displaying content from external platforms, and Hosting and backend infrastructure.
For detailed information on the purposes of processing and on the Personal Data processed for each purpose, the User may refer to the section “Details on the processing of Personal Data”.
Details on the processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
Contact form
By filling in the contact form with their Data, the User consents to its use for responding to requests for information, quotes, or any other nature indicated in the form’s header.
Personal Data processed: last name; email; first name; various types of Data.
Interaction with social networks and external platforms
This type of service allows interactions with social networks or other external platforms directly from the pages of this Application.
The interactions and information acquired by this Application are in any case subject to the User’s privacy settings for each social network.
This type of service may still collect traffic data for the pages where it is installed, even when Users do not use it.
Users are advised to log out of their respective services to ensure that the data processed on this Application is not linked to their profile.
Facebook Like button and social widgets (Facebook, Inc.)
The “Like” button and Facebook social widgets are services for interacting with the Facebook social network, provided by Facebook, Inc.
Personal Data processed: Cookies; Usage Data.
Place of processing: United States – Privacy Policy.
User Rights
Users may exercise certain rights regarding the Data processed by the Data Controller.
In particular, the User has the right to:
- withdraw consent at any time. The User may withdraw consent to the processing of their Personal Data previously given.
- object to the processing of their Data. The User may object to the processing of their Data when it is carried out on a legal basis other than consent. Further details on the right to object are provided in the section below.
- access their Data. The User has the right to obtain information regarding the Data processed by the Data Controller, on certain aspects of the processing, and to receive a copy of the Data processed.
- verify and request rectification. The User may verify the accuracy of their Data and request that it be updated or corrected.
- obtain restriction of processing. When certain conditions apply, the User may request the restriction of the processing of their Data. In this case, the Data Controller will not process the Data for any purpose other than their storage.
- obtain the erasure or removal of their Personal Data. When certain conditions apply, the User may request the deletion of their Data by the Data Controller.
- receive their Data or have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to obtain the transfer of such Data to another controller without hindrance. This provision applies when the Data is processed by automated means and the processing is based on the User’s consent, on a contract to which the User is a party, or on contractual measures related thereto.
- lodge a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.
Details on the right to object
When Personal Data is processed in the public interest, in the exercise of official authority vested in the Data Controller, or for the purposes of the legitimate interests pursued by the Data Controller, Users have the right to object to such processing on grounds related to their particular situation.
Users are reminded that, where their Data is processed for direct marketing purposes, they may object to such processing at any time without providing any justification. To find out whether the Data Controller processes Data for direct marketing purposes, Users may refer to the relevant sections of this document.
How to exercise these rights
To exercise their rights, Users may send a request to the contact details of the Data Controller indicated in this document. Requests are made free of charge and will be processed by the Data Controller as soon as possible, and in any case within one month.
Additional information about Data processing
Legal defense
The User’s Personal Data may be used by the Data Controller in legal proceedings or in the preparatory stages leading to possible legal action for the defense against misuse of this Application or related Services by the User.
The User declares to be aware that the Data Controller may be required to disclose the Data by order of public authorities.
Specific information
Upon request of the User, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific Services or the collection and processing of Personal Data.
System logs and maintenance
For operation and maintenance purposes, this Application and any third-party services it uses may collect system logs, i.e., files that record interactions and may also contain Personal Data, such as the User’s IP address.
Information not contained in this policy
Further information regarding the processing of Personal Data may be requested at any time from the Data Controller using the contact details provided.
Response to “Do Not Track” requests
This Application does not support “Do Not Track” requests.
To determine whether any third-party services used support them, the User is invited to consult their respective privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, within this Application, as well as—where technically and legally feasible—by sending a notification to Users via one of the contact details held by the Data Controller. Users are therefore encouraged to check this page frequently, referring to the date of the last modification indicated at the bottom.
Should the changes affect processing activities whose legal basis is consent, the Data Controller will collect the User’s consent again, if necessary.
Definitions and legal references
Personal Data (or Data)
Personal Data constitutes any information that, directly or indirectly, even in connection with any other information — including a personal identification number — makes a natural person identified or identifiable.
Usage Data
This is information collected automatically through this Application (or through third‑party applications integrated into this Application), including: the IP addresses or domain names of the computers used by the User who connects to this Application, the URI (Uniform Resource Identifier) addresses, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server’s response (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various time details of the visit (e.g., time spent on each page), and details about the path followed within the Application, with particular reference to the sequence of pages visited, as well as parameters relating to the User’s operating system and IT environment.
User
The individual using this Application who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural or legal person, public authority, agency, or other body that processes Personal Data on behalf of the Data Controller, as described in this privacy policy.
Data Controller (or Controller)
The natural or legal person, public authority, service, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, as well as the tools adopted, including the security measures concerning the operation and use of this Application. Unless otherwise specified, the Data Controller is the owner of this Application.
This Application
The hardware or software tool through which the Users’ Personal Data is collected and processed.
Service
The Service provided by this Application as defined in the relevant terms (if available) on this website/application.
European Union (or EU)
Unless otherwise specified, any reference to the European Union in this document is intended to include all current member states of the European Union and the European Economic Area.
Cookie
Cookies are Tracking Tools consisting of small pieces of data stored within the User’s browser.
Tracking Tool
Tracking Tool refers to any technology — e.g., Cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting — that enables the tracking of Users, for example by collecting or storing information on the User’s device.
Legal references
This privacy notice is drafted on the basis of multiple legislative frameworks, including Articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy notice applies exclusively to this Application.