Privacy Policy
Information on the processing of personal data pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR). In force since 01/07/2022
This disclosure takes into account the provisions of the GDPR and the Privacy Code (Legislative Decree 30 June 2003 n. 196). The document was also drawn up on the basis of the Guidelines of the Privacy Guarantor (especially the Guidelines for combating spam issued by the Privacy Guarantor on 4 July 2013).
The Data Controller is : H-EN, with registered office in Via Pasubio 11, 31025 Santa Lucia Di Piave (TV) Italy
According to the legislation indicated, the processing of personal data by Hiro srl or the Data Controller will be based on principles of correctness, lawfulness, transparency and protection of the privacy and rights of the interested party.
The treatment will be carried out both with manual and/or IT and telematic tools with organization and processing logics strictly related to the purposes themselves and in any case in order to guarantee the security, integrity and confidentiality of the data in compliance with the organizational, physical and logics envisaged by the provisions in force.
Site to which this privacy policy refers: www.veniceart.net ( Site ).
The Data Controller has not appointed a DPO. Therefore, you can send any request for information directly to the Data Controller.
GENERAL INFORMATIONS
This document describes how the Data Controller processes your personal data provided on the Site.
The main treatments of your personal data are described below. In particular, the legal basis of the processing is explained, whether the provision is mandatory and the consequences of failing to provide personal data. To better describe your rights, if necessary, we have specified if and when a certain processing of personal data is not carried out. On the Site you have the possibility to enter personal data of third parties. In this case, you guarantee that you have obtained the consent of these subjects to enter this personal data. Therefore, you undertake to indemnify and hold the Data Controller harmless from any liability.
Registration on the Site
The information and data requested in the event of registration will be used to allow you both to access the reserved area of the Site and to use the online services offered by the Data Controller to registered users. The legal basis of the processing is the need for the Data Controller to carry out pre-contractual measures adopted at the request of the interested party. The provision of data is optional. However, your refusal to provide data will make it impossible to register on the Site. It is also possible to register on the Site using external services. In this case, your registration data will be shared with the companies of these external services for the sole purpose of allowing registration on the Site. The legal basis of this treatment is the legitimate interest of the Data Controller to allow registration on the Site through external services . The provision of personal data for this purpose is purely optional. However, failure to consent to the processing of data will make it impossible to register through external services.
Purchases on the Site
Your personal data will be processed to allow you to make purchases on the Site. In the case of placing an online purchase order, to allow the conclusion of the purchase contract and the correct execution of the operations connected to the same (and, if necessary according to the sector legislation, to fulfill tax obligations). The legal basis of the processing is the obligation of the Data Controller to execute the contract with the interested party or to fulfill legal obligations. Regardless of the above (and therefore from your consent), the Data Controller may process your data for the purpose of so-called "soft-spam", governed by art. 130 of the Privacy Code. This means that limited to the email you provide in the context of a purchase through the Site, the Data Controller will process the email to allow the direct offer of similar products/services, provided that you do not object to such processing in the procedures set out in this information. The legal basis of the processing is the legitimate interest of the Data Controller to send this type of communication. This legitimate interest can be considered equivalent to the interested party's interest in receiving "soft-spam" communications. The Data Controller may send emails to remind the user to complete a purchase. The legal basis of this treatment is the legitimate interest of the Data Controller to send this type of communication.
Respond to your requests
Your data will be processed to respond to your requests for information. The provision is optional, but your refusal will make it impossible for the Data Controller to answer your questions. The legal basis of the processing is the legitimate interest of the Data Controller to follow up on the user's requests. This legitimate interest is equivalent to the user's interest in receiving a response to communications sent to the Data Controller.
Generic marketing
Subject to your consent, the Data Controller may process the personal data you provide in order to send you advertising material and/or newsletters relating to its own products or those of third parties. The legal basis of this treatment is your consent. The provision of personal data for this purpose is purely optional. Failure to consent to the processing of data for marketing purposes will make it impossible for you to receive advertising material relating to products/services of the Data Controller and/or third parties as well as the impossibility for the Data Controller to carry out market surveys, also aimed at assessing the degree of user satisfaction, as well as to send you newsletters.
Profiling
Subject to your consent, the Data Controller may process your personal data for profiling purposes, i.e. for the analysis of your consumption choices by revealing the type and frequency of purchases you have made, in order to send you advertising material and /o newsletters relating to own or third party products, of specific interest to you. The legal basis of this treatment is your consent. The provision of data for this purpose is purely optional. Failure to consent to the processing of your personal data for profiling purposes will make it impossible for the Data Controller to process your commercial profile, through the detection of your choices and purchasing habits as well as to send you advertising material relating to the Controller's products of the Processing and/or third parties, of your specific interest.
Data transfer
The Data Controller does not transfer your personal data to third parties.
Geolocation
In case of access to the Site, you may receive a notification on your device (fixed and/or mobile) which will give you the possibility to allow or not the identification of the device itself (so-called geo-location). You can freely allow or refuse this setting, without this involving substantial changes to the functionality of the Site. You can change the geolocation settings at any time through the settings of your device. The legal basis of the processing consists in the legitimate interest of the Data Controller to provide services relevant to the user's location. This legitimate interest is equal to the user's interest in receiving services that are as relevant as possible to his location.
Communication of personal data
As part of its ordinary activity, the Data Controller may communicate your personal data to certain categories of subjects. In article 2 You can find the list of subjects to whom the Data Controller communicates your personal data. To facilitate the protection of your rights, article 2 may specify in some cases when your data is not communicated to third parties.
The "communication" of personal data to third parties is different from the "transfer" (regulated in the previous point). In fact, in the communication, the third party to whom the data is transmitted can use it only for the specific purposes described in the relationship with the Data Controller. In the transfer, on the other hand, the third party becomes the independent Data Controller of the personal data. Furthermore, your consent is always required to transfer your personal data to third parties.
Without prejudice to the foregoing, it is understood that the Data Controller may in any case use your personal data to correctly fulfill the obligations established by the laws in force.
SPECIFIC PRIVACY NOTICE
Art. 1 Processing methods
1.1 The processing of your personal data will mainly be carried out with the aid of electronic or automated means, according to the methods and with the tools suitable for guaranteeing their security and confidentiality in compliance with the GDPR. If the automatic chatbot service is operational, your personal data will also be processed to allow the activation of this service, through which the user can contact and be contacted by the Data Controller, subject to consent. The legal basis is the legitimate interest of the Data Controller to respond to user requests through the chatbot service. This legitimate interest can be considered equivalent to the interest of the interested party to use the automatic chatbot service.
1.2 The information acquired and the methods of treatment will be pertinent and not excessive with respect to the type of services rendered. Your data will also be managed and protected in secure IT environments appropriate to the circumstances. On the Site, you will have the option of creating a public profile in which other users will be able to view the material you have published and your personal data (eg: photographs or videos). Therefore, you acknowledge and accept that the Data Controller is not responsible for the use that users may make of this material and of your personal data.
1.3 "Particular data" is not processed through the Site. Particular data are those that can reveal racial and ethnic origin, religious, philosophical or other beliefs, political opinions, membership of parties, trade unions, associations or organizations of a religious, philosophical, political or trade union nature, health and sex life.
1.4 No judicial data is processed through the Site.
Art. 2 Communication of personal data
The Data Controller may communicate your personal data to specific categories of subjects. The subjects to whom the Data Controller reserves the right to communicate your data are indicated below:
The Data Controller may communicate your personal data to all those subjects (including the Public Authorities) who have access to personal data pursuant to regulatory or administrative provisions. Your personal data may also be communicated to all those public subjects and/or or private individuals, natural and/or legal persons (legal, administrative and tax consultancy firms, Judicial Offices, Chambers of Commerce, Chambers and Labor Offices, etc.), if the communication is necessary or functional to the correct fulfillment of the obligations deriving from the law. The Data Controller does not make use of employees and/or collaborators in any capacity. Therefore, your personal data will not be communicated to this category of subjects. The Data Controller does not make use of companies, consultants or professionals in charge of installing, maintaining, updating and, in general, managing the hardware and software of the Data Controller. Therefore, your data will not be communicated to these categories of subjects. To send its communications, the Data Controller makes use of external companies in charge of sending this type of communication (CRM platforms). Your personal data (especially your email) may therefore be communicated to these companies. The Data Controller does not make use of external companies to provide the customer care service.
The Owner reserves the right to modify the above list based on its ordinary operations. Therefore, you are invited to regularly access this information to check to which subjects the Data Controller communicates your personal data.
Art. 3 Retention of personal data
3.1 This article describes how long the Data Controller reserves the right to keep your personal data.
For marketing purposes, personal data will be kept until consent is revoked. For inactive users, personal data will be deleted one year after the sending of the last email viewed.
3.2 Without prejudice to the provisions of article 3.1, the Data Controller may keep your personal data for the time required by specific regulations, as amended from time to time.
Art. 4 Transfer of personal data
4.1 The Data Controller is based within the European Union. Therefore, the processing of your data is safe from a regulatory point of view as governed by the GDPR. If the transfer of your personal data takes place in a non-EU country and for which the European Commission has expressed an opinion of adequacy, the transfer is in any case considered safe from a regulatory point of view. This article 4.1 indicates from time to time the countries to which your personal data may possibly be transferred and where the European Commission has expressed an opinion of adequacy.
To allow the correct functioning of the Site, your personal data may be transferred abroad. This is permitted on the basis of the decision of the European Commission of 20 December 2001 n. 2002/2/EC (published in the Official Journal of the European Communities L 2/13 of 4 January 2002) with which it was found that Canada guarantees an adequate level of protection for personal data transferred from the European Union to recipients subject to the law Canada on the Protection of Personal Information and Electronic Documents ("the Canadian Act") of 13 April 2000.
4.2 Without prejudice to what is indicated in article 4.1, your data may also be transferred to non-EU countries and for which the European Commission has not expressed an opinion of adequacy. You are therefore invited to regularly view this article 4.2 to ascertain which of these countries your data is possibly transferred to. To allow the correct functionality of the Site, your personal data may be transferred to the USA. In these cases, the Data Controller will adopt all suitable contractual measures to guarantee an adequate level of protection of personal data, including, among others, the Standard Contractual Clauses approved by the European Commission on 4 June 2021.
4.3 In this article, the Data Controller indicates the countries where it may specifically direct its business. This circumstance may imply the application of the legislation of the reference country, together with that of the GDPR.
At the request of the user, the Data Controller will apply to the processing of personal data the possibly more favorable regulation envisaged by the user's national legislation.
Art. 5. Rights of the interested party
Pursuant to art. 13 of the Privacy Regulation, the Data Controller informs you that you have the right to:
ask the Data Controller for access to your personal data and the correction or cancellation of the same or the limitation of the treatment that concerns you or to oppose their treatment, in addition to the right to data portability revoke the consent at any time without prejudice to the lawfulness of the treatment based on the consent given before the revocation propose a complaint to a supervisory authority (e.g.: the Guarantor for the protection of personal data).
The above rights may be exercised with an informal request to the contacts indicated in the Introduction.
Art. 6. Modifications and Miscellaneous
The Data Controller reserves the right to make changes to this information at any time, giving appropriate publicity to users of the Site and in any case guaranteeing adequate and similar protection of personal data. In order to view any changes, you are invited to regularly consult this information. In the event of substantial changes to this privacy statement, the Data Controller may also notify them by email.