Website Privacy Policy
1. General information
a) Introduction
Thank you for your
interest in our website. Protecting customers/visitors/users data and using it
only in the way our customers/visitors/users expect from us is our top priority.
Therefore, the following policy is designed to inform you about the processing
of your personal data and your rights regarding this processing in accordance
with the General Data Protection Regulation ("GDPR") and other data
protection laws pursuant to art. 13 of EU Regulation No. 2016/679 (GDPR), to all
those who interact with the web services provided by the Professional
Practice of Dr. Chimico Steardo Antonio, accessible electronically
at: www.analisidottsteardo.it corresponding to the official home page of the Site.
The information may
be subject to changes due to the introduction of new rules in this regard. We
therefore invite you to periodically check this page.
You must be over 16
years of age to register on this site and to allow us to collect and store your
personal data. If you are under the age of 16, we have the right to block
and/or delete your account or user profile. Parents or guardians of the minor
can in any case contact us to block the account or profile of the minor for
which they are responsible, through the means available in the section relating
to the rights of the user.
b) Data
Controller
Dr. Steardo
Antonio represents the data controller according to
the GDPR and he is therefore responsible for the processing of the data
illustrated below.
The Professional
Studio of Dr. Chimico Steardo Antonio (from here on also "Professional
Studio"), Via San Giacomo, 32 - 80133 Naples (NA), Tel.: 081/0063603 - e-mail:
info@analisidottsteardo.it.
2. Processing of Personal Data when
using our website
Among the Personal Data collected by this Website,
independently or through third parties, there are: email; first name; last name; telephone
number; city; Cookies;
data Usage; unique
identifiers of advertising devices (Google Advertiser ID or IDFA identifier,
for example). Full details of each type of data
collected are provided in the dedicated sections of this privacy policy or
through specific information texts displayed before the collection of the data. This data is collected for the purpose of optimizing and improving
our website as well as our online services.
Personal Data may be freely provided by the User or, in the
case of Data Usage, collected automatically during the use of this Website.
Unless otherwise specified, all Data requested by this Website are mandatory.
If the User refuses to communicate them, it may be impossible for this Website
to provide the Service. In cases where this Website indicates some Data as
optional, Users are free to refrain from communicating such Data, without this
having any consequence on the availability of the Service or on its operation.
Your personal data is only stored if you provide it to your account, e.g. as
part of a registration in the "Work with us" area or by filling in
the fields in the "Contacts" section. Users who have doubts about
which Data is mandatory are encouraged to contact the Data Protection Officer.
Any use of Cookies - or other tracking tools - by this Website or by the owners
of third-party services used by this Website, unless otherwise specified, has
the purpose of providing the Service requested by the User, in addition to the
other purposes described in this document and in the Cookie Policy, if
available. The User assumes responsibility for the Personal Data of third
parties obtained, published or shared through this Website and guarantees to
have the right to communicate or disseminate them, freeing the Owner from any
liability to third parties.
3. Methods and place of processing
the collected Data
Mode
The Data Controller
shall take appropriate security measures to prevent unauthorized access,
disclosure, modification or destruction of Personal Data.
The processing is
carried out using computer and/or telematic tools, with organizational methods
and logic strictly related to the purposes indicated. In addition to the
Owner, in some cases, other parties involved in the organization of this
Application (administrative, commercial, marketing, legal, system
administrators) or external parties may have access to the Data (as third-party
technical service providers, postal couriers, hosting providers, IT companies,
communication agencies) also appointed, if necessary, Data Processors by the
Data Controller. The updated list of Data Processors may
always be requested from the Data Controller.
Legal basis of the Processing
The Data Controller processes Personal Data relating to
the User if one of the following conditions is met:
·
the User has given consent for one or more specific
purposes;
Note: in some jurisdictions the Owner
may be authorized to process Personal Data without the consent of the User or
another of the legal bases specified below, until the User opposes
("opt-out") to such processing. However, this is not applicable
if the processing of Personal Data is regulated by European legislation on the
protection of Personal Data;
·
the processing is necessary for the execution of a
contract with the User and/or for the execution of pre-contractual measures;
·
processing is necessary to fulfil a legal obligation
to which the Data Controller is subject;
·
processing is necessary for the performance of a
task in the public interest or for the exercise of official authority vested in
the Data Controller;
·
processing is necessary for the pursuit of the legitimate
interest of the Owner or third parties.
However, it is always
possible to ask the Data Controller to clarify the concrete legal basis of each
processing and in particular to specify whether the processing is based on the
law, required by a contract or necessary to conclude a contract.
Place
The Data are processed at
the operational headquarters of the Data Controller and in any other place
where the parties involved in the processing are located. For more information, contact the owner.
The User’s Personal Data may
be transferred to a country other than the one in which the User is
located. To obtain further information on the place of processing, the
User can refer to the section relating to the details of the processing of
Personal Data.
The User has the right to obtain
information about the legal basis of the transfer of Data outside the European
Union or to an international organization of public international law or
consisting of two or more countries, such as the UN, as well as regarding the
security measures taken by the Data Controller to protect the Data.
The User can check whether one of the
transfers described above takes place by examining the section of this document
relating to the details of the processing of Personal Data or ask for
information from the Data Controller by contacting him at the opening details.
Storage Time
The Data are processed and stored for the
time required by the purposes for which they were collected. Therefore:
·
The Personal Data
collected for purposes related to the execution of a contract between the Owner
and the User will be retained until the execution of this contract is
completed.
·
The Personal Data
collected for purposes attributable to the legitimate interest of the Data
Controller will be retained until such interest is satisfied. The User may
obtain further information about the legitimate interest pursued by the Data
Controller in the relevant sections of this document or by contacting the Data
Controller.
When processing is based on the User’s
consent, the Data Controller may retain the Personal Data for longer until such
consent is revoked. In addition, the Data Controller may be obliged to
retain Personal Data for a longer period in compliance with a legal obligation
or by order of an authority.
At the end of the storage period, the
Personal Data will be deleted. Therefore, upon expiry of this period, the right
of access, cancellation, rectification and the right to data portability can no
longer be exercised.
4. Purposes of Data Processing
The User’s Data is collected to allow the
Owner to provide the Service, comply with legal obligations, respond to
requests or executive actions, protect their rights and interests (or those of
Users or third parties), identify any malicious or fraudulent activities, as
well as for the following purposes:
Contacting the User, Statistics,
Advertising, Displaying content from external platforms, Tag management,
Managing contacts and sending messages. The data will also be used for
interaction with social networks and external platforms. To obtain
detailed information on the purposes of the processing and on the Personal Data
processed for each purpose, the User can refer to the section "Details on
the processing of Personal Data".
Details on the processing of Personal Data
Personal Data is collected for the
following purposes and using the following services:
• Contact the User
Contact form (this Website) By filling in
the contact form with their Data, the User consents to their use to respond to
requests for information, quotes, or any other nature indicated by the form
header. Personal Data processed: surname; email; first
name; telephone number (optional).
The personal data that you have filled in
the contact form will be processed only to respond to your request. Filling in
and sending the contact form is an affirmative action by which you give us
consent to the processing of data.
• Managing contacts and sending messages
This type of service allows you to manage
a database of email contacts, telephone contacts or contacts of any other type,
used to communicate with the User. These services may also allow the
collection of data relating to the date and time of the display of messages by
the User, as well as the User’s interaction with them, such as information on
clicks on links inserted in messages.
·
reCaptcha
In order to protect the data, you enter
via the forms of this site, we use the reCAPTCHA service of Google Inc.
(Google). This service verifies that you are a person to prevent some of
the website functions from being (ab)used by spam robots (especially in the
comments section). Using this feature implies that your IP address and other
data are requested by Google for the Google reCAPTCHA service. In any
case, within the member states of the European Union and the European Economic
Area, the IP address is truncated and anonymized before transmission by
Google. Only in exceptional cases is the full IP address sent to one of
Google’s servers in the US and truncated once received. Google then uses
this information to verify on our behalf how you are using our site. The
IP address provided by reCAPTCHA will not be aggregated with any other data
held by Google.
The collection of this data is subject to
the data protection rules of Google (Google Inc.). For more information on
Google’s privacy policy, please visit: https://www.google.com/intl/it/policies/privacy/
By using the reCAPTCHA service, you
authorize Google to process your data for the purpose and in the manner
described above.
• Management of tags
This type of service is functional to the
centralized management of the tags or scripts used on this Website. The
use of these services involves the flow of User Data through them and, where
applicable, their retention.
Google Tag Manager (Google Ireland Limited) Google Tag Manager is a tag
management service provided by Google Ireland Limited. Personal Data
processed: Cookies; Usage data. Place of processing: Ireland -
Privacy Policy. Subject adhering to the Privacy Shield.
• Interaction with data collection platforms
and other third parties
This type of service allows Users to
interact with data collection platforms or other services directly from the
pages of this Website in order to save and reuse data. In the event that
one of these services is installed, it is possible that, even if the Users do
not use the service, it collects Usage Data relating to the pages in which it
is installed.
• Interaction with social networks and
external platforms
This type of service allows you to
interact with social networks, or with other external platforms, directly from
the pages of this Website. The interactions and information acquired by this
Website are in any case subject to the User’s privacy settings related to each
social network. This type of service may still collect traffic data for pages
where the service is installed, even when Users do not use it. We recommend
that you log out of the respective services to ensure that the data processed
on this Website is not linked to your profile.
Facebook Like button and social widgets
(Facebook, Inc.)
The "Like" button and Facebook
social widgets are services of interaction with the Facebook social network,
provided by Facebook, Inc. Personal Data processed: Cookies; Usage
data. Place of processing: United States - Privacy Policy. Privacy
Shield Party.
Google Maps widget (Google Ireland
Limited)
Google Maps is a map visualization service
provided by Google Ireland Limited that allows this Application to integrate
such content within its pages.
Personal Data processed: Data Usage; Tracking
Tool.
Place of treatment: Ireland – Privacy Policy.
• Management of Payments
Unless otherwise specified, this
Application processes all payments by credit card, bank transfer or other means
through external payment service providers. In general, and unless
otherwise specified, Users are requested to provide payment details and
personal information directly to such payment service providers.
This Application is not involved in the
collection and processing of such information: instead, it will receive only a
notification from the payment service provider in question about the payment.
Paypal (Paypal)
Paypal is a payment service provided by
Paypal Inc., which allows the User to make online payments.
Personal Data processed: various types of Data as specified in the privacy
policy of the service.
Place of treatment: Consult the Paypal privacy policy – Privacy
Policy.
• Platform and hosting services
These services are intended to host and
operate key components of this Application, making it possible to deliver this
Application from a single platform. These platforms provide the Owner with
a wide range of tools such as, for example, analytical tools, for the
management of user registration, for the management of comments and the
database, for electronic commerce, for processing payments etc. The use of
such tools involves the collection and processing of Personal Data.
Some of these services operate through
servers located geographically in different places, making it difficult to
determine the exact place where Personal Data is stored.
Prestashop (Prestashop S.A.)
Prestashop is a platform provided by
Prestashop S.A. that allows the Owner to develop, operate and host a website
dedicated to e-commerce. Personal Data processed: various types of Data as
specified in the privacy policy of the service. Place of processing: France - Privacy
Policy.
• Online sales of goods and services
The Personal Data collected are used for
the provision of services to the User or for the sale of products, including
payment and possible delivery. The Personal Data collected to complete the
payment may be those relating to the credit card, the current account used for
the bank transfer or other payment instruments provided. The Payment Data
collected by this Application depends on the payment system used.
• The statistics
The services contained in this section
allow the Data Controller to monitor and analyze traffic data and are used to
keep track of the User’s behavior.
Google Analytics with anonymized IP
(Google Ireland Limited)
Google Analytics is a web analytics
service provided by Google Ireland Limited ("Google"). Google
uses the Personal Data collected for the purpose of tracking and examining the
use of this Application, compiling reports and sharing them with other services
developed by Google.
Google may use the Personal Data to
contextualize and personalize the ads of its advertising network.
This Google Analytics integration
anonymizes your IP address. Anonymization works by shortening the IP address of
the Users within the borders of the member states of the European Union or in
other countries party to the Agreement on the European Economic Area. Only in
exceptional cases will the IP address be sent to Google’s servers and shortened
within the United States.
Personal Data processed: Usage Data;
Tracking Tool.
Place of treatment: Ireland– Privacy Policy – Opt Out.
5. Rights of the User
Users may exercise certain rights with
reference to the Data processed by the Data Controller. In particular, the
User has the right to:
•
revoke consent at
any time. The User
may revoke consent to the processing of their previously expressed Personal
Data.
•
object to the
processing of their Data. The
User may object to the processing of their Data when it takes place on a legal
basis other than consent. Further details on the right to object are given
in the section below.
•
access their Data. The User has the right to obtain
information on the Data processed by the Data Controller, on certain aspects of
the processing and to receive a copy of the Data processed.
•
verify and request
rectification. The
User can verify the correctness of their Data and request its update or
correction.
•
obtain the
limitation of treatment. When
certain conditions are met, the User may request the restriction of the
processing of their Data. In this case, the Data Controller will not
process the Data for any other purpose than their storage.
•
obtain the deletion
or removal of their Personal Data. When certain conditions are met, the User may request
the deletion of their Data by the Owner.
•
receive your Data
or have it transferred to another data controller. The User has the right to receive
their Data in a structured, commonly used and machine-readable format and,
where technically feasible, to obtain its transfer without hindrance to another
holder. This provision is applicable when the Data are processed with
automated tools and the processing is based on the User’s consent, on a
contract to which the User is a party or on contractual measures related to it.
•
lodge a complaint. The User may lodge a complaint with
the competent Personal Data Protection Supervisory Authority "Authority
for the Protection of Personal Data to e-mail garante@gpdp.it“
act in court.
Details on the right of objection
When the Personal Data are processed in the public interest,
in the exercise of public authority vested in the Data Controller or to pursue
a legitimate interest of the Data Controller, Users have the right to object to
the processing for reasons related to their particular situation. Users
are reminded that, if their Data are processed for direct marketing purposes,
they can object to the processing without providing any reason. To find
out whether the Data Controller processes data for direct marketing purposes,
Users can refer to the respective sections of this document.
6. Cookie
Policy
To make your visit to our site more
enjoyable and to enable the use of certain functions, we may use
"cookies" on various pages. Cookies are small text files that
are stored on the terminal device. Some of the cookies we use are deleted
after the end of the browser session. Other cookies remain on your device
and allow us or our partner companies to recognize your browser on your next
visit. You can set your browser to be informed about the setting of cookies
separately and individually decide on their acceptance or exclude the
acceptance of cookies in certain cases or in general. For more
information, see the help function of your Internet browser. If cookies
are not accepted, the functionality of our website may be limited.
To learn more about how we use cookies,
you can access our "Cookie Policy” https://www.analisidottsteardo.it/
Further information on the treatment
Defence in court - The User’s Personal Data may be used by
the Owner in court or in the stages preparatory to its possible establishment
for the defense against abuse in the use of this Website or related Services by
the User. The User declares to be aware that the Data Controller may be
obliged to disclose the Data by order of public authorities.
Specific information - At the request of the User, in addition
to the information contained in this privacy policy, this Website may provide
the User with additional and contextual information regarding specific Services,
or the collection and processing of Personal Data.
System logs and maintenance - For needs related to operation and
maintenance, this Website and any third-party services used by it may collect
system logs, e.g. files that record interactions and may also contain Personal
Data, such as the User IP address.
Response to "Do Not Track"
requests - This Website
does not support "Do Not Track" requests. To find out if any
third-party services used support them, the User is invited to consult their
respective privacy policies.
Changes to this privacy policy - The Data Controller reserves the right
to make changes to this privacy policy at any time by notifying Users on this
page and, if possible, on this Website as well, if technically and legally
feasible, by sending a notification to the Users through one of the contact
details of which it is in possession. Please, consult therefore, this page
frequently, referring to the date of the last modification indicated at the bottom.