Privacy Policy of Fresia SPA
This Website collects some Personal Data from its Users.
Data Controller
Fresia SPA – Via Trento e Trieste 30, 17017 Millesimo (SV)
Data Controller’s email address: fresia@fresia.it
Types of Data collected
Among the Personal Data collected by this Website, either independently or through third parties, are: email, first name, last name, phone number, address, province, postal code, city, Cookies, Usage Data, geographic location, username, and street number.
Full details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed prior to the data collection itself.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Website.
Unless otherwise specified, all Data requested by this Website is mandatory. If the User refuses to provide it, it may be impossible for this Website to provide the Service. In cases where this Website indicates some Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or its operation.
Users who have doubts about which Data is mandatory are encouraged to contact the Data Controller.
Any use of Cookies – or other tracking tools – by this Website or by the owners of third-party services used by this Website, unless otherwise stated, serves the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Website and guarantees that they have the right to communicate or disseminate them, releasing the Data Controller from any liability towards third parties.
Method and place of processing of the collected Data
Processing methods
The Data Controller adopts appropriate security measures aimed at preventing unauthorized access, disclosure, modification, or destruction of Personal Data.
Processing is carried out using IT and/or telematic tools, with organizational methods and with logics strictly related to the indicated purposes. In addition to the Data Controller, in some cases, other subjects involved in the organization of this Website (administrative, commercial, marketing, legal personnel, system administrators) or external subjects (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communication agencies) may have access to the Data, also appointed, if necessary, as Data Processors by the Data Controller. The updated list of Data Processors can always be requested from the Data Controller.
Legal basis of processing
The Data Controller processes Personal Data relating to the User if one of the following conditions exists:
• the User has given consent for one or more specific purposes; Note: In some jurisdictions, the Data Controller may be authorized to process Personal Data without the User’s consent or another of the legal bases specified below, until the User objects (“opt-out”) to such processing. However, this is not applicable if the processing of Personal Data is regulated by European legislation on the protection of Personal Data;
• processing is necessary for the performance of a contract with the User and/or for the execution of pre-contractual measures;
• processing is necessary to fulfill a legal obligation to which the Data Controller is subject;
• processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
• processing is necessary for the pursuit of the legitimate interest of the Data Controller or third parties.
In any case, it is always possible to ask the Data Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on law, provided for by a contract, or necessary to conclude a contract.
Place
The Data is processed at the operational headquarters of the Data Controller and in any other place where the parties involved in the processing are located. For further information, contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the place of processing, the User can refer to the section concerning the details on the processing of Personal Data.
The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization governed by public international law or set up by two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect the Data.
If one of the transfers just described takes place, the User can refer to the respective sections of this document or request information from the Data Controller by contacting them at the details provided at the beginning.
Retention period
Data is processed and stored for the time required by the purposes for which it was collected.
Therefore:
• Personal Data collected for purposes related to the execution of a contract between the Data Controller and the User will be retained until the execution of such contract is completed.
• Personal Data collected for purposes attributable to the legitimate interest of the Data Controller will be retained until the satisfaction of such interest. The User can obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
When processing is based on the User’s consent, the Data Controller may retain Personal Data longer until such consent is revoked. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, the Personal Data will be deleted. Therefore, upon expiry of this term, the right of access, deletion, rectification, and the right to data portability can no longer be exercised.
Purposes of the Processing of collected Data
The User’s Data is collected to allow the Data Controller to provide its Services, as well as for the following purposes: Contacting the User, Tag Management, Hosting and backend infrastructure, Interaction with social networks and external platforms, Location-based interactions, SPAM protection, Registration and authentication, Statistics, and Displaying content from external platforms.
To obtain further detailed information on the purposes of the processing and on the Personal Data concretely relevant for each purpose, the User can refer to the relevant sections of this document.
Details on the processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
• Contacting the User
Mailing list or newsletter (this Website)
By registering for the mailing list or newsletter, the User’s email address is automatically added to a contact list to which email messages containing information, including of a commercial and promotional nature, relating to this Website may be transmitted. The User’s email address may also be added to this list as a result of registering on this Website or after making a purchase.
Personal Data collected: last name, email, and first name.
Contact form (this Website)
The User, by filling in the contact form with their Data, consents to their use to respond to requests for information, quotes, or any other nature indicated in the header of the form.
Personal Data collected: postal code, city, last name, email, address, first name, phone number, and province.
• Tag Management
This type of service is functional for the centralized management of tags or scripts used on this Website.
The use of such services involves the flow of User Data through them and, where appropriate, their retention.
Google Tag Manager (Google LLC)
Google Tag Manager is a tag management service provided by Google LLC.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy. Subject adhering to the Privacy Shield.
Segment (Segment.io Inc.)
Segment is a tag management service provided by Segment.io, Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy.
• Hosting and backend infrastructure
This type of service has the function of hosting Data and files that allow this Website to function, enable its distribution, and provide a ready-to-use infrastructure to deliver specific functionalities of this Website.
Some of these services operate through servers located geographically in different places, making it difficult to determine the exact location where Personal Data is stored.
ArubaCloud (Aruba S.p.A.)
ArubaCloud is a hosting service provided by Aruba S.p.A.
Personal Data collected: various types of Data as specified in the privacy policy of the service.
Place of processing: Italy – Privacy Policy.
• Interaction with social networks and external platforms
This type of service allows interaction with social networks, or other external platforms, directly from the pages of this Website.
The interactions and information acquired by this Website are in any case subject to the User’s privacy settings relating to each social network.
In the event that an interaction service with social networks is installed, it is possible that, even if Users do not use the service, it may collect traffic data relating to the pages on which it is installed.
Facebook Like button and social widgets (Facebook, Inc.)
The “Like” button and Facebook social widgets are interaction services with the Facebook social network, provided by Facebook, Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy. Subject adhering to the Privacy Shield.
YouTube button and social widgets (Google Inc.)
The YouTube button and social widgets are interaction services with the YouTube social network, provided by Google Inc.
Personal Data collected: Usage Data.
Place of processing: United States – Privacy Policy. Subject adhering to the Privacy Shield.
Tweet button and Twitter social widgets (Twitter, Inc.)
The Tweet button and Twitter social widgets are interaction services with the Twitter social network, provided by Twitter, Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy. Subject adhering to the Privacy Shield.
• Location-based interactions
This Website may collect, use, and share Data relating to the User’s geographic location, in order to provide services based on the location itself.
Most browsers and devices provide default tools to deny geographic tracking. If the User has expressly authorized this possibility, this Website may receive information on their actual geographic location.
The User’s geographic localization occurs non-continuously, upon specific request of the User or when the User does not indicate their location in the specific field and allows the application to automatically detect the position.
Personal Data collected: geographic location.
• SPAM protection
This type of service analyzes the traffic of this Website, potentially containing Users’ Personal Data, in order to filter it from parts of traffic, messages, and content recognized as SPAM.
Google reCAPTCHA (Google Inc.)
Google reCAPTCHA is a SPAM protection service provided by Google Inc.
The use of the reCAPTCHA system is subject to Google’s privacy policy and terms of use.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy. Subject adhering to the Privacy Shield.
• Registration and authentication
By registering or authenticating, the User allows the Application to identify them and give them access to dedicated services.
Depending on what is indicated below, registration and authentication services may be provided with the help of third parties. If this occurs, this application may access some Data stored by the third-party service used for registration or identification.
Direct registration (this Website)
The User registers by filling out the registration form and providing their Personal Data directly to this Website.
Personal Data collected: postal code, city, last name, email, address, first name, street number, phone number, province, and username.
• Statistics
The services contained in this section allow the Data Controller to monitor and analyze traffic data and serve to track User behavior.
Google Analytics (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google uses the Personal Data collected for the purpose of tracking and examining the use of this Website, compiling reports, and sharing them with other services developed by Google.
Google may use the Personal Data to contextualize and personalize the ads of its advertising network.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy – Opt Out. Subject adhering to the Privacy Shield.
Google Analytics with anonymized IP (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google uses the Personal Data collected for the purpose of tracking and examining the use of this Website, compiling reports, and sharing them with other services developed by Google.
Google may use the Personal Data to contextualize and personalize the ads of its advertising network.
This Google Analytics integration anonymizes your IP address. The anonymization works by shortening the IP address of Users within the borders of the member states of the European Union or in other countries adhering to the agreement on the European Economic Area. Only in exceptional cases will the IP address be sent to Google’s servers and shortened within the United States.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy – Opt Out. Subject adhering to the Privacy Shield.
User ID extension for Google Analytics (Google Inc.)
Google Analytics on this Website uses a function called User ID. This allows for more accurate tracking of Users by assigning each one a unique ID for various sessions and devices, but in a way that does not allow Google to personally identify an individual or permanently identify a specific device.
The User ID extension also allows connecting Data from Google Analytics with other User-related data collected by this Website.
The Opt Out link provided below allows you to disable tracking for the device you are using, but does not exclude further tracking activities carried out by the Data Controller. To disable the latter as well, contact the Data Controller via the contact email address.
Personal Data collected: Cookies.
Place of processing: United States – Privacy Policy – Opt Out. Subject adhering to the Privacy Shield.
• Displaying content from external platforms
This type of service allows you to view content hosted on external platforms directly from the pages of this Website and interact with them.
In the event that a service of this type is installed, it is possible that, even if Users do not use the service, it may collect traffic data relating to the pages on which it is installed.
Google Fonts (Google Inc.)
Google Fonts is a font style visualization service managed by Google Inc. that allows this Website to integrate such content within its pages.
Personal Data collected: Usage Data and various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy. Subject adhering to the Privacy Shield.
User Rights
Users can exercise certain rights with reference to the Data processed by the Data Controller.
In particular, the User has the right to:
withdraw consent at any time. The User can withdraw consent to the processing of their Personal Data previously expressed.
object to the processing of their Data. The User can object to the processing of their Data when it occurs on a legal basis other than consent. Further details on the right to object are indicated in the section below.
access their Data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing, and to receive a copy of the processed Data.
verify and request rectification. The User can verify the correctness of their Data and request its updating or correction.
obtain the restriction of processing. When certain conditions are met, the User can request the restriction of the processing of their Data. In this case, the Data Controller will not process the Data for any other purpose than their storage.
obtain the erasure or removal of their Personal Data. When certain conditions are met, the User can request the deletion of their Data by the Data Controller.
receive their Data or have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to obtain its transfer without hindrance to another controller. This provision is applicable when the Data is processed by automated means and the processing is based on the User’s consent, on a contract to which the User is a party, or on contractual measures connected to it.
lodge a complaint. The User can lodge a complaint with the competent personal data protection supervisory authority or take legal action.
Details on the right to object
When Personal Data is processed in the public interest, in the exercise of official authority vested in the Data Controller, or to pursue a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons connected to their particular situation.
Users are reminded that, if their Data is processed for direct marketing purposes, they can object to the processing without providing any reason. To find out whether the Data Controller processes data for direct marketing purposes, Users can refer to the respective sections of this document.
How to exercise rights
To exercise the User’s rights, Users can direct a request to the contact details of the Data Controller indicated in this document. Requests are filed free of charge and processed by the Data Controller as quickly as possible, in any case within one month.
Cookie Policy
This Website uses Cookies. To learn more and to view the detailed information, the User can consult the Cookie Policy.
Further information on processing
Defense in court
The User’s Personal Data may be used by the Data Controller in court or in the preparatory stages leading to its possible establishment for the defense against abuses in the use of this Website or related Services by the User.
The User declares to be aware that the Data Controller may be obliged to disclose the Data by order of public authorities.
Specific information
Upon the User’s request, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.
System logs and maintenance
For needs related to operation and maintenance, this Website and any third-party services used by it may collect system logs, i.e., files that record interactions and may also contain Personal Data, such as the User’s IP address.
Information not contained in this policy
Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.
Response to “Do Not Track” requests
This Website does not support “Do Not Track” requests.
To find out if any third-party services used support them, the User is invited to consult the respective privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Website as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details held by the Data Controller. Please therefore consult this page regularly, referring to the date of last modification indicated at the bottom.
If the changes affect processing whose legal basis is consent, the Data Controller will collect the User’s consent again, if necessary.
Definitions and legal references
Personal Data (or Data)
Personal data is any information that, directly or indirectly, also in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.
Usage Data
This is the information collected automatically through this Website (also from third-party applications integrated into this Website), including: the IP addresses or domain names of the computers used by the User who connects with this Website, the addresses in URI (Uniform Resource Identifier) notation, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (success, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (e.g., the time spent on each page) and the details relating to the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the operating system and the User’s IT environment.
User
The individual who uses this Website who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural or legal person, public administration, and any other entity that processes personal data on behalf of the Data Controller, as set out in this privacy policy.
Data Controller (or Controller)
The natural or legal person, public authority, service, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data and the tools adopted, including the security measures relating to the operation and use of this Website. The Data Controller, unless otherwise specified, is the owner of this Website.
This Website (or this Application)
The hardware or software tool by which the Personal Data of Users is collected and processed.
Service
The Service provided by this Website as defined in the relevant terms (if any) on this site/application.
European Union (or EU)
Unless otherwise specified, any reference to the European Union contained in this document is intended to be extended to all current member states of the European Union and the European Economic Area.
Cookie
Small portion of data stored within the User’s device.
Legal references
This privacy policy is drafted based on multiple legislative systems, including Articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy policy exclusively concerns this Website.
