Privacy Policy

INFORMATION ON DATA PROCESSING (Regulation 679/2016 – GDPR)

The following document illustrates how our company obtains and uses the data concerning its customers, suppliers, and in general, all the persons with whom it has contact during its commercial activity, and indicates the subjects with whom it shares them.

 

INDEX

  1. Data Controller and Processor
  2. Gathered Data
  3. Cookies Policy
  4. The Purposes of Processing
  5. Legal Basis for the Processing of Personal Data
  6. Who Can Receive the Personal Data of the Person Concerned (Beneficiaries)
  7. The Storage Period
  8. Access, Modification or Removal of Personal Data (Rights of the Person Concerned)
  9. Right to Object to Data Processing
  10. Data Storage and Security
  11. International Transfers
  12. Questions

 

  1. Data Controller and Processor

Any data we receive or gather will be handled by:

Ella srl with registered headquarters in Curno (BG) Via Repubblica 1/C Taxpayers code and VAT number 02943980165 in its capacity as personal data controller. To contact with the data processor, Mario Carsana, send an e-mail to ella@ellasrl.it.

  1. Gathered Data

In order to perform our business activities and to prepare the tax documents necessary for purchase-sale operations, our company needs to process some data (listed below).

As soon as a client makes a purchase order – be it in paper form, by phone or online on the website www.ellasrl.it –, his/her personal data are registered in a database. The same happens to our company, when we place an order for merchandise or services. All documents concerning commercial operations with third parties are therefore created using personal data saved in a purpose-designed software programme.

The company gathers and/or receives the following data concerning clients/suppliers and all physical persons:

  • Identifying data (name and surname, company name etc.…)
  • Place of residence or stay
  • Fixed and mobile phone numbers
  • E-mail address
  • Taxpayer code and VAT number
  • IBAN and other bank data

We specify that we do not gather personal data such as genetic, biometric and health-related data.

 

Data Collection Methods

On-line orders: to finalize an order on the website www.ellasrl.it, during the purchase, the user will be asked to insert his/her personal and payment data.

Printed or phone orders: whenever an order to purchase our products is placed, we will ask the necessary personal data to invoice, and contact information such as address, e-mail address and phone number.

The User Data are gathered to allow the Data Controller to provide his services as well as for the following purposes: Contacting the User, Interaction with external social networks and platforms, Statistics, Displaying content from external platforms. Users can find further detailed information about such purposes of processing and about the specific Personal Data used for each purpose in the respective sections of this document.

By joining our mailing list or newsletter, the User’s email address will be automatically added to the contact list of those who may receive emails with news and promotions concerning our company, Ella srl. The User’s email address might also be added to this list as a result of signing up to this Website or after making a purchase.

STATISTICS

The services contained in this section enable the Data Controller to monitor and analyze web traffic and can be used to keep track of User behavior.

INTERACTIONS WITH SOCIAL NETWORKS AND EXTERNAL PLATFORMS

This type of service allows interaction with social networks or other external platforms directly from the pages of www.ellasrl.it.

The interactions and the acquired information are always subject to the User’s privacy settings for each social network.

When an interaction service with other social networks is installed, this may still gather traffic data for the pages where it is installed, even if the Users do not use it.

AddThis (Addthis Inc.)

AddThis is a service that displays a widget that allows interaction with external social networks and platforms as well as sharing the contents of this website. Depending on the configuration, this service can display widgets belonging to third parties such as the managers of social networks where interactions are shared. In this case, also third parties that provide the widget will be informed of interactions and Usage Data on the pages where this service is installed.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy.

Google Analytics (Google Inc.)

Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google utilizes the Data gathered to track and examine data use, prepare reports and share them with other Google services.

Google may use the Data collected to contextualize and personalize the ads of its own

advertising network.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy – Opt Out

DISPLAYING CONTENT FROM EXTERNAL PLATFORMS

This kind of service allows you to visualize content hosted on external platforms directly from the Ella srl website pages and to interact with them.

When a service of this kind is installed, it may still collect traffic data for the pages where it is installed, even if the Users do not use it.

Google Fonts (Google Inc.)

Google Fonts is a typeface visualization service provided by Google Inc. that allows Ella srl to incorporate content of this kind on its pages.

Personal Data Collected: Usage Data and different kinds of Data according to what has been specified in the privacy policy of the service.

Place of processing: USA – Privacy Policy.

Google Maps Widget (Google Inc.)

Google Maps is a map visualization service provided by Google Inc. that allows Ella srl to incorporate content of this kind on its pages.

Personal Data Collected: Cookie and Usage Data.

Processing Site: USA – Privacy Policy.

User Rights

Users may exercise certain rights regarding their Data processed by the Data Controller. In particular, Users have the right to:

  • Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
  • Object to the processing of his/her own data. The User can object to the processing of his/her own data when it occurs on a different juridical base than the one agreed on. Further details on the right to object are listed in the section below.
  • Access their Data. Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
  • Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
  • Restrict the processing of their Data. Users have the right, under certain circumstances, to restrict the processing of their Data. In this case, the Data Controller will not process their Data for any purpose other than storing it.
  • Have their Personal Data deleted or otherwise removed. Users have the right, under certain circumstances, to have their Data deleted by the Data Controller.
  • Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine-readable format and, if technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable provided that the Data is processed by automated means and that the processing is based on the User’s consent, on a contract which the User is part of or on pre-contractual obligations thereof.
  • Lodge a complaint. Users have the right to bring a claim before their competent data protection authority or to take legal action.

Details about the right to object to processing

Where Personal Data is processed for a public interest, in the exercise of an official authority vested in the Owner or for the purposes of the legitimate interests pursued by the Data Controller, Users may object to such processing by providing a ground related to their particular situation to justify the objection.

Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time without providing any justification. To learn whether the Data Controller is processing Personal Data for direct marketing purposes, Users may refer to the relevant sections of this document.

  1. Cookies Policy

To learn about the cookies that we use on our website pages, the User may consult our cookies policy directly on our website www.ellasrl.it.

  1. The Purposes of Processing

Personal data will be used to correctly provide the service required. Below, here is a list of how we may use Personal Data:

  1. Personal Data will be used to prepare all the relevant documents for business and tax purposes, such as orders, invoices, contracts, merchandise, shipment and invoice payments.
  2. The contact information will be used to send administrative information and commercial offers concerning our products and possible customized proposals.
  3. Legal Basis for the Processing of Personal Data

The Data Controller may process Personal Data relating to Users if one of the following applies:

  • A purchase-sale agreement needs to be performed according to the purpose specified in paragraph a) of article 4;
  • The person concerned has given his/her consent for the purpose specified in paragraph b) of article 4 mentioned above.
  1. Who Can Receive the Personal Data of the Person Concerned (Beneficiaries)

Below is a description of when and how the Personal Data may be shared with third parties:

  • With our suppliers, subcontractors and business partners (“Services Suppliers”) which process information in order to supply a service for our company or on behalf of it. Together with our Service Suppliers, we sign agreements that forbid them from divulging and sharing the data they gather and receive from the person concerned with anyone else, and to use the data for different purposes other than the fulfillment of their assignments.
  • To prevent fraud when we believe it is necessary to divulge information to investigate, prevent or respond to possible improper business practices and to safeguard our and third parties’ rights and property.
  • To comply with the law when it is asked or imposed by law courts or government, law enforcement and regulatory authorities. We might also communicate the Data of the interested person to exercise or protect our legal rights, or to defend ourselves in the event of legal action.
  1. The Storage Period

Personal Data will be retained until the end of our contractual and business relationship, i.e. for the time needed to fulfill the legal obligations for the purpose specified in article 4, paragraph a). As concerns paragraph b) of the same article, data may be stored for maximum of ten years – unless a prior removal request is made.

  1. Access, Modification or Removal of Personal Data (Rights of the Person Concerned)

The person concerned can:

  • Ask, at any time, for confirmation that his/her Personal Data is being processed and, in this case, ask to access it.
  • Check, correct, update, limit, abolish or delete (Right to be forgotten) the Personal Data s/he previously gave us.
  • Exercise the right to data portability as well as to withdraw, at any time, any expressed consent given without there being any invalidation of the legitimacy of the processing based on the prior express consent.

Should the person concerned wish to exercise any of his/her rights, s/he can turn to our company and to Date Controller using the addresses indicated in this document.

For any complaint regarding the processing of his/her Personal Data, the person concerned can turn to the Guarantor for protection of their personal data and to other competent public authorities.

Should the person concerned wish to stop receiving marketing e-mails form www.ellasrl.it, s/he can send an e-mail in which they withdraw any consent previously expressed.

It is worth noting that, if the person concerned chooses not to receive marketing e-mails from our company, we still have the authority to send him/her important administrative, accounting, legal messages.

We must underline, too, that we could be forced to save some information because of some compulsory filing procedures and/or to complete the transactions that the person concerned started before filing this request.

  1. Right to Object to Data Processing

Even when the personal data are processed in a legitimate way in order to perform a task in the public interest or in the exercise of public powers, i.e. for the legitimate interests of our company, the person concerned still has the right to object to the processing of data concerning his/her particular situation. Even when the personal data are processed for direct marketing purposes, the person concerned has the right to object to their data being processing – and to the possible profiling related to it. In this case, after the object of the person concerned, his/her data will not be processed anymore.

  1. Data Storage and Security

We adopt numerous measures to protect the personal information of the person concerned.

We try to take any reasonable organizational, technical and administrational measures to protect the information of the person concerned and to prevent any loss, improper use and unauthorized access as well as any disclosure, modification and/or destruction thereof. We adopt reasonable measures to ensure that the processed data respects the predicted use thereof, and accurate, exhaustive and up-to-date for the purposes we use them for. Unfortunately, no data transmission or data memory system can guarantee absolute security. If Users have any reason to think that their interaction with us is no longer safe, they should immediately notify us of the problem getting in touch with our Data Processor through the contact details provided in this document.

  1. International Transfers

Ella srl is a company operating under Italian law with no foreign headquarters, so for the moment, it does not need to transfer users’ data abroad.

  1. Questions

For further information about the personal data processing or the User rights, please contact the Data Processor using the addresses listed above.

Please sign to of acknowledge and authorize to the processing of personal data and send us a copy via e-mail to ella@ellasrl.it.