This page describes the methods and logic behind the processing of personal data of users (hereinafter, also referred to as the users) who visit the site: www.mangiamoitaliano.eu (hereinafter, also referred to as the Site).
This information is provided pursuant to Art. 13 of EU Regulation 2016/679, the "General Data Protection Regulation" (hereinafter GDPR) and the applicable Italian data protection legislation, Legislative Decree 196/2003 and subsequent amendments, particularly those introduced by Legislative Decree no. 101/2018, to those who interact with the site from the above address and not for other external and possibly linked websites.
Processing of personal data means any operation or set of operations performed with or without the aid of automated processes and applied to personal data or sets of personal data, even if not recorded in a database, such as collection, recording, organization, structuring, storage, processing, selection, blocking, adaptation or modification, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, comparison or interconnection, restriction, erasure or destruction.
1. Data controller
The data controller is BEFORE SB SRL with registered office in Terranova Sappo Minulio in via Vaccari 5 (RC) 89010 – VAT number 03255140802.
Data processing related to information/booking/purchase request forms takes place at our company headquarters and is handled, using electronic tools and after adopting appropriate security measures, by personnel working at the office responsible for processing.
2. Data Protection Officer
The Data Protection Officer (DPO) is a role provided for by Article 37 of the GDPR. Our company, being relatively small, is not required to have a DPO.
The contact details of our Data Protection Office are provided below, for the deletion of data from our archives and for any other need:
3. Legal basis of the processing
The personal data indicated on this page are processed in the performance of tasks carried out in the public interest or in any case connected to the exercise of public authority.
Following consultation of this site, data relating to identified or identifiable individuals may be processed. The data provided freely and voluntarily by users is acquired and processed in compliance with the rules established by the GDPR and used exclusively for institutional purposes.
The staff in charge of our offices undertakes to respect and protect your privacy by treating the personal data you provide in compliance with the legal provisions aimed at guaranteeing the security, accuracy, updating and relevance of the data with respect to the declared purposes.
The personal data provided by users who submit requests is used solely for the purpose of fulfilling the request submitted and is disclosed to third parties only when strictly necessary and functional to that purpose, in compliance with European and national regulations. The data is processed by personnel specifically authorized to process data only when processing is necessary to perform their assigned duties.
4. Method of treatment
Personal data are processed electronically for the time strictly necessary to achieve the purposes for which they were collected.
Specific security measures are observed to prevent data loss, illicit or incorrect use, and unauthorized access. The data will obviously be printed and transmitted as requested (if shipping documents are required or if transmission is required by law).
The Data Controller will process the personal data for the time necessary to fulfill the aforementioned purposes and in any case for no more than 10 years from the termination of the Service Terms and for no more than 2 years from the collection of data for the Marketing Purposes.
In the case of data present in NEWSLIST, the permanence in the latter will be considered valid permanently unless a cancellation request is requested (information provided at the bottom of all mailing list emails; unsubscribing from the newsletter is an automated procedure and does not require the intervention of the Data Controller).
Personal data submitted via the Website is stored on servers located within the European Union. Communications stored in Google services (Google Forms, Google Mail, and other proprietary tools of the same platform) are replicated on Google-owned servers. Communications stored in Facebook, Instagram, and WhatsApp services are replicated on Facebook-owned servers.
Communications stored in Microsoft services (Office 365 forms, Outlook, and other proprietary tools on the same platform) are managed in replication on Microsoft-owned servers. The data in the PHPLIST mailing lists owned by the Data Controller are stored in Italy. The data in the sendinblue.com mailing lists are stored on their secure servers. The data in the mailchimp.com mailing lists are stored on their secure servers.
5. Type of data and purpose of processing
All personal data provided through the Site will be processed lawfully and fairly in order to provide the requested services and to respond to user communications and questions, always in pursuit of the institutional purposes of the Presidency of the Council of Ministers as required by law.
Data provided voluntarily
Through the Site, you can send requests and communications using the contact addresses listed on the site. Providing this data is mandatory and necessary to respond to requests and to contact the sender for clarifications regarding the information provided. Data sent via completed forms is handled by a third party (Katia Cortelli's technical partner ABC OnLine) who ensures proper transmission using encrypted connections.
The Data Controller may retain data submitted by visitors for the sole purpose of providing the service requested by the visitor; such data will not be used for commercial, marketing, or profiling purposes by the Data Controller. The data will be stored on cloud platforms such as: WordPress servers on the Automattic platform, Aruba Cloud, Amazon AWS Cloud, Google Cloud, Microsoft Office 365, Google Suite, Zoho Docs & Mail, and external storage systems. These systems are ALWAYS PROTECTED by the security procedures required by the aforementioned regulation to ensure compliance with GDPR directives.
However, the Data Controller cannot guarantee the correct use of data by third parties sent to provide a service to the visitor. Visitors wishing to use one of the services listed above will be informed of additional methods and purposes of data processing by a third party shortly before sending the data. These methods will be defined by the Partners during the service creation phase, using the tools provided by the platform. Visitors using these services are aware that their data will be sent to third parties.
In the absence of procedures for the use of data by third parties to provide the service, the visitor has the right to ask the Data Controller for the destination and method of sending the data. The Data Controller is exempt from any liability regarding the improper use of data by third parties.
Navigation data
This category of data includes the IP addresses or domain names of computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (successful, error, etc.), and other parameters relating to the user's operating system and IT environment. Browsing data is not collected for the purpose of identifying users, but for the sole purpose of anonymously collecting statistical information on the use of the site and its services.
Marketing purposes
Only with your specific and separate consent (Article 7 of the GDPR) will the data be used for the following marketing purposes: sending news and offers via email, post, and/or text message, as well as telephone contact, or communications relating to the services offered by the Data Controller and measuring satisfaction with the quality of the services;
Your data will be added to newsletter systems only with your consent during the registration process on the site. The Data Controller uses services provided by Mailchimp and Sendinblue.
6. Cookies
Cookies are small text files that visited sites send to the user's terminal, where they are stored before being retransmitted to the same sites on the next visit.
The Site uses:
Session cookies whose use is not instrumental to the collection of personal data identifying the user, being limited to the sole transmission of session identification data in the form of numbers automatically generated by the server.
Session cookies are not stored permanently on the user's device and are automatically deleted when the browser is closed.
Third-party cookies for viewing videos on YouTube.
Our company and the personnel responsible for managing information do not have access to the data collected and processed independently by third parties. For more information on the logic and methods of data processing collected by social networks, users are invited to read the privacy policies provided by the providers of these services: YouTube https://www.google.it/intl/it/policies/privacy/
Analytics cookies used to collect information, in aggregate form, on the number of users and how they visit the Site.
The site uses Google Analytics, whose cookie policy can be viewed at https://support.google.com/analytics/answer/6004245. To respect the privacy of our users, the service is used in "anonymizeip" mode, which masks the IP addresses of users browsing the website (more information on this feature).
The data is collected for the sole purpose of compiling anonymous statistical information on the use of the Site and verifying its proper functioning. Browsing data may be used to identify the user only if necessary to detect computer crimes.
Technical cookies are not used for User profiling activities.
Users can choose to enable or disable cookies by changing their browser settings according to the instructions provided by the relevant providers at the links below. Chrome, Firefox, Safari, Internet Explorer, Opera
7. Rights of the interested parties
Data subjects (natural persons to whom the data refers), pursuant to Article 15 et seq. of the GDPR, may exercise their rights at any time, specifically the right to access their personal data, request its rectification or restriction, update it if incomplete or incorrect, and delete it if collected unlawfully, as well as to object to its processing, unless the Data Controller has legitimate grounds for doing so.
To this end, you can contact the Data Controllers by sending a request via certified email to the certified email address (PEC) or by using the specific form available on the website. The form can be downloaded directly from the Italian Data Protection Authority at: www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/1089924.
You also have the option to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), following the procedures and instructions published on the Authority's official website at www.garanteprivacy.it.
The exercise of rights is not subject to any form constraint and is free of charge.
8. Changes to this policy
This Policy is subject to updates in compliance with legislative or regulatory provisions.
legal information
The texts, information, and other data published on this site, as well as links to other satellite sites on the web, are for informational purposes only and do not have any official character. Mangiamo Italiano assumes no responsibility for any errors or omissions of any kind and for any type of direct, indirect or accidental damage resulting from reading or using the information published, or any form of content present on the site or from accessing or using the material contained on other sites.