AZIENDA AGRICOLA SORLINI CINZIA – for Palazzo Mosela
Privacy Policy pursuant to EU Regulation no. 2016/679 (GDPR). The policy is not to be considered valid for other websites that may be consulted via links present on the websites under the owner's domain, who is in no way responsible for third-party websites. The address of my website is: https://villabenefizio.com/.
Az. Agr. Sorlini Cinzia with registered office in Via San Bartolomeo, 22 – 53045 Montepulciano (SI), Fiscal Code: SRLCNZ51P60B157X and VAT number: 01383500525 (hereinafter, "Data Controller"), as data controller, informs you pursuant to art. 13 of Legislative Decree no. 196 of 30.06.2003, D.lgs 101/2018 (hereinafter, "Privacy Code") and art. 13 of EU Regulation no. 2016/679 (hereinafter, "GDPR") that your data will be processed in the following ways and for the following purposes:
1. Subject of the processing
The Data Controller processes personal, identifying, and non-sensitive data (including, but not limited to, name, surname, company name, address, telephone number, email – hereinafter, "personal data" or "data") that you provide when interacting / filling in data on the Data Controller's website:
• https://palazzomosela.it – palazzomosela.com (hereinafter, "Site") and specifically when filling out contact forms on the Data Controller's website, requesting clarification or support online, and subscribing to newsletters.
2. Purposes of the processing
Your personal data are processed:
1. A) without your express consent (art. 24 lett. a), b), c) Privacy Code and art. 6 lett. b), e) GDPR), for the following Service Purposes:
• manage and maintain the Site or allow you access to dedicated areas;
• allow you to use the Services you may have requested;
• allow you to receive quotes for services you have requested;
• respond to online contact chats;
• process a contact request;
• for general administrative and accounting activities;
• comply with obligations required by law, regulations, community legislation, or an order from an Authority or at the request of the Italian or foreign government or the Italian Chamber of Commerce;
• exercise the Data Controller's rights, such as the right to legal action.
1. B) Only with your specific and distinct consent (artt. 23 and 130 Privacy Code and art. 7 GDPR), for the following Other Purposes:
• send you opinion and satisfaction surveys, newsletters, and/or invitations to events via email, or register you for events in which the Data Controller is involved or organizes.
3. Methods of processing and data retention period
The processing of your personal data is carried out by means of the operations indicated in art. 4 of the Privacy Code and art. 4 n. 2) of the GDPR, namely: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, deletion, and destruction of data. Your personal data are processed both in paper and electronic and/or automated form. The Data Controller will process personal data for the time necessary to fulfill the purposes mentioned above and in any case for no longer than 10 years from the termination of the relationship for Service Purposes and for no longer than 2 years from the collection of data for Other Purposes. In compliance with the provisions of art. 5 paragraph 1 lett. e) of EU Regulation 2016/679, the personal data collected will be stored in a form that allows the identification of the data subjects for a period not exceeding the achievement of the purposes for which the personal data are processed.
4. Security
The Data Controller has adopted a wide variety of security measures to protect your data against the risk of loss, misuse, or alteration. In particular: it has adopted the measures referred to in art. 32-34 of the Privacy Code and art. 32 of the GDPR; it uses data encryption technology where necessary for more secure communications.
Access to data
Your data may be made accessible for the purposes referred to in art. 2.A) and 2.B):
• to employees and collaborators of the Data Controller, in their capacity as data processors and/or internal data controllers and/or system administrators;
• to third-party companies or other subjects (website provider, cloud provider, e-payment service provider, suppliers, hardware and software assistance technicians, forwarders and carriers, credit institutions, professional firms, etc.) who perform outsourced activities on behalf of the Data Controller, in their capacity as data processors (the list of processors is held at the registered office).
6. Communication of data
Without your express consent (ex art. 24 lett. a), b), d) Privacy Code and art. 6 lett. b) and c) GDPR), the Data Controller may communicate your data for the purposes referred to in art. 2.A) to Supervisory Bodies, Judicial Authorities, as well as to all other subjects to whom communication is mandatory by law for the performance of work purposes, such as during the registration of a web domain or the rental of a server on behalf of the client. However, it is ensured that your personal data will never be made public on the data controller's website.
7. Data transfer
The management and storage of personal data will take place in Europe, on servers located in Italy and Europe, owned by the Data Controller and/or by third-party companies, including abroad, appointed and duly designated as data processors for the use of the requested services. The personal data provided may be transferred abroad within or outside the European Union, within the limits and under the conditions referred to in art. 44 et seq. of EU Regulation 2016/679, in order to comply with purposes related to the transfer itself.
8. Nature of data provision and consequences of refusal to respond
The provision of data for the purposes referred to in art. 2.A) is mandatory. In their absence, we cannot guarantee the Services of art. 2.A).
The provision of data for the purposes referred to in art. 2.B) is optional. You can therefore decide not to provide any data or to subsequently deny the possibility of processing data already provided: in this case, you will not receive invitations to events, newsletters, and opinion and satisfaction surveys via email. In any case, you will continue to be entitled to the Services referred to in art. 2.A).
9. Rights of the data subject
As a data subject, you have the rights referred to in art. 7 of the Privacy Code and art. 15 of the GDPR, namely the rights to:
• i. obtain confirmation of the existence or non-existence of personal data concerning you, even if not yet recorded, and their communication in an intelligible form;
• ii. obtain the indication: a) of the origin of the personal data; b) of the purposes and methods of processing; c) of the logic applied in case of processing carried out with the aid of electronic instruments; d) of the identification details of the data controller, the data processors, and the designated representative pursuant to art. 5, paragraph 2 of the Privacy Code and art. 3, paragraph 1, of the GDPR; e) of the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of them as designated representative in the territory of the State, data processors, or agents;
• iii. obtain: a) the updating, rectification, or, when interested, the integration of data; b) the cancellation, anonymization, or blocking of data processed unlawfully, including data whose retention is unnecessary for the purposes for which the data were collected or subsequently processed; c) the certification that the operations referred to in letters a) and b) have been brought to the attention, also as regards their content, of those to whom the data have been communicated or disseminated, except in the case where this fulfillment proves impossible or involves the use of means manifestly disproportionate to the protected right;
• iv. object, in whole or in part: a) for legitimate reasons to the processing of personal data concerning you, even if relevant to the purpose of collection; b) to the processing of personal data concerning you for the purpose of sending advertising material or direct sales or for market research or commercial communication, by using automated call systems without the intervention of an operator by email and/or by traditional marketing methods by telephone and/or postal mail. Please note that the data subject's right to object, set out in the previous point b), for direct marketing purposes by automated methods extends to traditional methods, and that in any case the data subject can exercise the right to object even partially. Therefore, the data subject can choose to receive only communications by traditional methods, or only automated communications, or neither type of communication.
Where applicable, you also have the rights referred to in art. 16-21 of the GDPR (Right of rectification, right to erasure, right to restriction of processing, right to data portability, right to object), as well as the right to lodge a complaint with the Supervisory Authority.
10. How to exercise your rights
You may exercise your rights at any time by sending:
• a registered letter with return receipt to the business address, declared at the beginning;
• an email to the address: CINZIASORLINI@PEC.IT
11. Minors
This Site and the Data Controller's Services are not intended for individuals under 18 years of age, and the Data Controller does not intentionally collect personal information relating to minors. Should information about minors be unintentionally recorded, the Data Controller will promptly delete it upon user request.
12. Data Controller, Processor, and Agents
The Data Controller / Data Processor (pursuant to art. 4, 24, 28 of EU Regulation 2016/679) is San Az. Agr. Sorlini Cinzia with registered office in Via San Bartolomeo, 22 – 53045 Montepulciano (SI), Fiscal Code: SRLCNZ51P60B157X and VAT number: 01383500525 in the name of its legal representative Sorlini Cinzia.
The updated list of data processors and agents is kept at the Data Controller's registered office.
13. Changes to this Policy
This Policy may be subject to changes. We therefore recommend that you regularly check this Policy and refer to the most updated version.
—— FURTHER POLICIES AND AGREEMENTS ——
CONFIDENTIALITY AGREEMENT FOR ALL INFORMATION PROVIDED BY OUR CLIENTS AND WEBSITE USERS
The data controller hereby declares to be aware that as a result of the working relationship with clients and/or free consultation with website users, who contact the data controller via email, chat, or other communication channels, they may become aware of data, information, and news in general, of a confidential nature, and undertakes to maintain the strictest confidentiality regarding what has been received, as well as any other news, confidence, and/or information, in the broadest sense of the term, learned about and/or from the client or website user.
COOKIES POLICY and STATISTICAL DATA
What are cookies
Cookies are small text files that websites visited by users send to their terminals, where they are stored to be retransmitted to the same websites on subsequent visits. Cookies are used for various purposes, have different characteristics, and can be used by both the owner of the website being visited and by third parties. Below you will find all the information on cookies installed through this site, and the necessary instructions on how to manage your preferences regarding them.
