Privacy Policy of ALMA NATA S.R.L.
1) Why are you receiving this communication
ALMA NATA S.R.L., registered office: Via Andrea Previtali 24, 24122, Bergamo (BG), as Data Controller, wishes to inform you about which data it collects and how, in order to guarantee respect for your fundamental rights and freedoms, with particular reference to the confidentiality and security with which the data is processed.
2) Object of the processing
The data processed by a refers to:
– Data collected automatically. Information on the use of the site.
Your use of our sites involves the processing of data on the browser and device you are using and your IP address (this is the number that identifies a specific device on the internet and is necessary for your device to communicate with the sites). We will be able to analyze which site you came from, what you have done and what you have not done on our site. The computer systems and applications dedicated to the operation of this website collect, during their normal operation, some data (the transmission of which is implicit in the use of Internet communication protocols) potentially associated with identifiable users. The data collected includes the IP addresses and domain names of the computers used by users who connect to the site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters regarding the operating system, browser and IT environment used by the user. These data are processed, for the time strictly necessary, for the sole purpose of obtaining statistical information on the use of the site and to check its regular operation. The provision of such data is mandatory as it is directly linked to the web browsing experience.
While Users are browsing, the following information may be collected and stored in the log files of the server (hosting) of the site:
– internet protocol (IP) address;
– browser type;
– parameters of the device used to connect to the site;
– name of the internet service provider (ISP);
– date and time of visit;
– web page of origin of the visitor (referral) and exit;
– possibly the number of clicks.
– Data provided voluntarily by the user.
Your contact and account data. We will store the contact information you provide us (for example, name, surname, address, telephone number, e-mail, country of residence) when you create an account on the site, purchase a product and/or participate in our competitions or promotions and/or by calling for assistance.
Your billing data. We will store the billing data you provide us only for the purposes of managing your purchase orders and shipping the products.
Other data. Additional data may also be collected that you voluntarily provide through the email address published on the site info@alma-nata.it
– Cookies. The site does not use/uses first-party/third-party technical/profiling cookies which may collect user navigation data, the provision of which is mandatory for technical cookies to allow navigation while it is optional and occurs through the expression of a free and informed consent for profiling and third-party cookies. Cookies operate in order to analyze the effectiveness of the site and make it easier and more intuitive over time. For more information, a specific cookie policy is available on this site in the dedicated section.
3) Legal basis of the processing
The legal basis of such processing is found in your express and unequivocal consent in the legitimate interest of the owner, in the fulfillment of legal and/or contractual obligations. (ex art. 6 GDPR).
4) For what purposes do we use your personal data
Without the necessary consent:
The collection and processing of personal data will be carried out
– for purposes strictly connected and instrumental to the fulfillment of the obligations inherent to the relationships with our company (to: process and manage your orders, ship the products you purchased, provide you with the necessary after-sales assistance, manage the return procedure for the products purchased) and/or to process requests promoted by email, as well as, possibly for fulfillments and obligations provided for by laws, regulations and community regulations or by provisions issued by authorities legitimated to do so by law and by supervisory and control bodies and for anonymous and aggregate statistical purposes;
– for statistical purposes exclusively in anonymous and aggregate form;
– to protect the security of the site and users, to unmask and prevent fraud and/or abuse to the detriment of the website;
– for the legitimate interest of the Data Controller;
– for the fulfillment of legal obligations, secondary and/or community legislation.
With explicit consent:
– Send you newsletters and/or communications via email relating to initiatives, events or promotions that may interest you;
– analyze your data on the use, preference and consumption of our products to improve our approach to you and our customers in general, through automated processing that includes profiling. We do this so that we can make better decisions in relation to services, advertising, products and content that are based on greater awareness of how our customers use our services and to guarantee you a more personalized experience. For this purpose, we may also collect your mobile device’s advertising identifier (IDFA – Identifier for Advertising – for iOS devices and AAID – Google Advertising ID – for Android devices) to allow us to always provide you with targeted and relevant ads based on your preferences and interests.
5) How long do we retain your personal data
Personal Data collected for purposes related to the execution of a contract between the Data Controller and the Customer, as well as to process the requests promoted, will be retained until the execution of such contract is completed, in any case no longer than 10 years.
Data collected for promotional and direct marketing purposes will be retained until the consent is revoked and, in any case, for a period not exceeding 2 years.
Data collected for direct profiling purposes will be retained until the consent is revoked and, in any case, for a period not exceeding 12 months.
The Data Controller may be required to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority, or for its own legitimate interest in order to protect its own right, including in court.
At the end of the retention period, the Personal Data will be deleted. Therefore, upon expiration of such period, the right of access, cancellation, rectification and the right to data portability can no longer be exercised.
6) The security of your personal data
The processing of your data will be carried out using tools that guarantee their confidentiality, integrity and availability. The processing is carried out on paper and through information and/or automated systems and will include all the operations or set of operations provided for in art. 4 of the GDPR and necessary for the processing in question, including communication to the persons in charge of the processing itself. The data in question will not be disclosed; instead, they will or may be communicated to public or private entities that operate within the scope of the purposes described above.
7) Who can access your personal data
Only authorized persons may access your data in the context of the tasks assigned by the Data Controller.
For the purposes indicated, the data – or some of them – may also be accessible or may be communicated to persons whose right to access your personal data is recognized by provisions of law or secondary or community legislation.
8) Where your personal data resides
The management and storage of your personal data will take place on paper for the time necessary to process the order, duly stored in special archives to which access by unauthorized persons is prohibited and/or on servers owned by the owner located at the headquarters, as well as on servers located within the European Union, owned by third-party companies, appointed and duly appointed as Data Processors. The data will not be transferred outside the European Union.
9) Is it mandatory to consent to the provision of your data?
The transmission of your browsing data is mandatory to continue browsing this site.
The provision of your data required for the conclusion of the sales contract and/or to process the requests promoted by you, is necessary for the purpose.
The provision of data for direct marketing and/or profiling purposes is optional.
The Data Controller does not request other data, however some of your personal and/or identification data may be provided by you incidentally on the occasion of a request sent by email to info@alma-nata.it
10) What are your rights in relation to the GDPR?
According to the provisions of the GDPR, ALMA NATA S.R.L. guarantees the following rights:
– obtain confirmation as to whether or not personal data concerning you is being processed and, where that is the case, obtain access to the personal data (Right of access, art. 15);
– obtain the rectification of inaccurate personal data concerning you without undue delay (Right to Rectification, art. 16);
– obtain the erasure of personal data concerning you without undue delay, the Data Controller has the obligation to erase your personal data without undue delay, if certain conditions exist (Right to be forgotten, art. 17);
– obtain the restriction of processing in certain cases (Right to restriction of processing, art. 18);
– receive the personal data you have provided to us in a structured, commonly used and machine-readable format and possibly transmit them to another Data Controller (Right to data portability, art. 20);
– object at any time, for reasons related to your particular situation, to the processing of personal data concerning you (Right to object, art. 21);
– receive without undue delay communication of the personal data breach suffered by the Data Controller and/or the Processors if said breach represents a threat to the rights and freedoms of the interested party (Art. 34);
– withdraw the consent expressed at any time (Conditions for consent art. 7).
11) For any request you can contact the contacts provided by the Data Controller.
If you believe that we have not respected your rights regarding the protection of personal data, you can contact the Authority for the protection of personal data. Alternatively, if you reside in another country, you can contact the local Authority for the protection of personal data.
12) Minors
Our e-commerce is not intended for minors under 16 years of age, but is intended for an adult audience. If you are a parent or guardian and you think that your child has transmitted data to us, you can contact us.
13) Data Controller
The Data Controller is ALMA NATA S.R.L., registered office: Via Andrea Previtali 24, 24122, Bergamo (BG)
Mail: info@alma-nata.it
The list of data controllers and data processors can be consulted at the owner’s office.
12) Updating this information
This information may be subject to changes. Any substantial changes will be communicated to you by email or through our website.
You can change your preferences regarding the sending of emails for marketing purposes and processing through profiling using the privacy settings of your account or by writing to the email address indicated above.