Data Controller

Azienda Agricola Fattoria Le Pupille – Piagge Del Maiano 92 A, 58100 Grosseto GR, Italy VAT No. 01101240537 in the person of its legal representative

Data Controller contact email: info@fattorialepupille.it

Types of Data collected

Among the Personal Information collected by this Website, independently or through third parties, there are: Cookies and Usage Data.

Full details of each Data type collected are given in the relevant sections of this privacy policy or in specific information displayed before the Data is collected.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Website.
Unless otherwise specified, all Data requested by this Website is mandatory. If the User refuses to communicate this Data, it may be impossible for this Website to provide the Service. Where the Website indicates that certain Data is optional, Users may refrain from providing the Data and there will be no consequences regarding the availability or functionality of the Service.
Users in doubt as to what Data is mandatory are encouraged to contact the Data Controller.
Any use of Cookies – or other tracking tools – by this Website or by third-party service providers used by this Website, unless otherwise specified, is intended to provide the Service requested by the User, in addition to the additional purposes described in this document and in the Cookie Policy, if available.

The User assumes the responsibility for the Personal Data of third parties obtained, published or shared through this Website and warrants that they have the right to disclose or disseminate such Data, freeing the Data Controller from any liability to third parties.

Method and place of processing the Data collected

Data processing methods

The Data Controller shall take appropriate security measures to prevent the unauthorised access, disclosure, modification or destruction of Personal Data.
Processing is carried out with the aid of computerised and/or electronic transmission tools, using organisational procedures and logic strictly for the aforementioned purposes. In addition to the Data Controller, other parties involved in the organisation of this Website (administrative, commercial, marketing, legal, system administrator personnel) might also have access to the Data or external parties that have been appointed (such as third-party technical service providers, couriers, hosting providers, IT companies, communication agencies), and, if necessary, as Process Managers by the Data Controller. An updated list of Data Managers is always available on request from the Data Controller.

Legal basis for data processing

The Data Controller shall process the User’s Personal Data in the event that one of the following conditions is met:

  • the User has given consent for one or more specific purposes. NB: in some judicial systems the Data Controller may be authorised to process Personal Data without the User’s consent or on any other of the legal bases specified below unless the User objects to such processing (opts out). However, this does not apply if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
  • processing is necessary for the execution of a contract with the User and/or for the execution of pre-contractual measures;
  • processing is necessary to fulfil a legal obligation to which the Data Controller is subject;
  • processing is necessary for the performance of a task carried out in the public interest or for the exercise of official authority vested in the Data Controller;
  • processing is necessary to pursue the legitimate interest of the Data Controller or a third party.

However, it is always possible to ask the Data Controller to clarify the specific legal basis of all processing and, in particular, to specify whether the processing is based on the law, provided for by a contract or necessary for the conclusion of a contract.

Place

The Personal Data and all the information on this Website are located in ITALY at the SERVICE PROVIDER:

The Data is processed at the Data Controller’s operational headquarters and in any other place where the parties involved in the processing are located. For further information, contact the Data Controller.
Personal data may be transferred to a country other than that in which Users are located. More information on the place of processing of the User’s Data is available in the section on details of Personal Data processing.

The User has the right to obtain information on the legal basis for the transfer of Data outside the European Union or to an international organisation governed by public international law or consisting of two or more countries, such as the UN, and on the security measures taken by the Data Controller to protect the Data.

If one of the transfers described above takes place, the User may refer to the respective sections of this document or request information from the Data Controller by contacting them using the contact details given at the start.

Retention period

Data is processed and stored for the time required for the purposes for which it was collected.

Therefore:

  • Personal Data collected for purposes related to the execution of a contract between the Data Controller and a User will be retained until the execution of the contract is complete.
  • The Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained until such time as such interest is satisfied. Further information regarding the legitimate interest pursued by the Data Controller can be obtained from the relevant sections of this document or by contacting the Data Controller.

Where the processing of Personal Data is based on the User’s consent, the Data Controller may retain the Data for longer, until said consent is revoked. Furthermore, the Data Controller may be obliged to keep the Personal Data for a longer period in accordance with a legal obligation or by order of an authority.

Personal Data will be deleted at the end of the retention period. The right to access, annul and rectify Personal Data and the right to Data portability, therefore, can no longer be exercised after this period has ended.

Purposes for Processing the Personal Data collected

The Data concerning the User is collected to allow the Data Controller to provide its Services, as well as for the following purposes: Interaction with external social networks and platforms, and Statistics.

For more detailed information on the purposes of processing and on the specific Personal Data related to each purpose, the User can refer to the relevant sections of this document.

Rights of the User

Users may exercise certain rights with regard to the Data processed by the Data Controller.

In particular, the User has the right to:

  • withdraw their consent at any time; Users may revoke their consent to the processing of their Personal Data as described above.
  • object to the processing of their Data. Users may object to the processing of their Data when it is done so on legal grounds other than consent. Further details on the right of objection are shown in the section below.
  • access their Data. Users have the right to obtain information on the Data processed by the Data Controller and on particular aspects of the processing, and to obtain a copy of any Data processed.
  • check and ask for the Data to be corrected; Users may check that their Data is correct and ask for it to be updated or corrected.
  • have the processing restricted. When certain conditions are met, Users may ask for the processing of their Data to be restricted. In this eventuality, the Data Controller may not process the Data for any purpose other than for its retention.
  • have their Personal Data removed or deleted. When certain conditions are met, the User may request the cancellation of their Data by the Data Controller.
  • have their Data sent to themselves or transferred to another Controller. Users have the right to receive their Data in a structured format that is commonly used and that can be read by automatic devices and, where technically feasible, to have it transferred without hindrance to another Controller. This instruction is applicable where the Data is processed by automated means, and the processing is based on the User’s consent, in respect of a contract to which the User is a party or contractual measures connected to this.
  • submit a complaint. Users may submit a complaint with the competent supervisory authority for Personal Data protection or take legal action.

DETAILS ON THE RIGHT OF OBJECTION

When the Personal Data is processed in the public interest, in the exercise of public powers vested in the Data Controller, or to pursue a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.

Users are reminded that where their Data is processed for direct marketing purposes, they may object to the processing without giving any reason. To find out whether the Data Controller is processing for direct marketing purposes, Users should refer to the relevant sections of this document.

HOW TO EXERCISE USER RIGHTS

In order to exercise their rights, Users may address a request to the Data Controller at the contact details indicated in this document. Requests are filed free of charge and processed by the Data Controller as soon as possible and in any event within one month.

FURTHER INFORMATION ABOUT THE PROCESSING

LEGAL DEFENCE

The Personal Data of the User may be used by the Data Controller in legal proceedings or in the preparatory stages for a possible defence against abuses of this Website or related Services by the User.
The User declares that they are aware that the Data Controller may be obliged to disclose the Data by order of public authorities.

SPECIFIC INFORMATION

Upon the User’s request, in addition to the information contained in this privacy policy, this Website may provide the User with the additional and contextual information regarding specific Services or the collection and processing of Personal Data.

MAINTENANCE AND SYSTEM LOGS

Out of necessity related to its operation and maintenance, this Website and any third-party services used by it may collect system logs, which are files that record the interactions and may also contain Personal Data, such as the IP address of the User.

INFORMATION NOT CONTAINED IN THIS POLICY

Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the aforementioned contact details.

RESPONSE TO “DO NOT TRACK” REQUESTS

This Website supports “Do Not Track” requests through cookie settings.
To find out whether any third-party support services have been used, Users are invited to consult the respective privacy policies.

CHANGES TO THIS PRIVACY POLICY

The Data Controller reserves the right to make modifications to this privacy policy at any time by informing Users on this page and, if possible, on this Website as well as, where technically and legally feasible, by sending a notification to Users through one of the contact details held by the Data Controller. Please consult this page regularly and check the date of the latest change, which is indicated at the bottom of the page.

Where changes involve processing on the legal grounds of consent, the Data Controller will seek to obtain the User’s consent again, if necessary.

LEGAL DEFINITIONS

PERSONAL DATA (OR DATA)

Personal Data consists of any information that, directly or indirectly, also in connection with any other information, including a personal identification number, can identify a physical person or make it possible to identify them.

USAGE DATA

This is information collected automatically through this Website (or by third-party applications integrated into this Website), including: IP addresses or domain names of the computers used by the Users to connect to the Website, Uniform Resource Identifiers (URIs), the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal aspects of the visit (for example, the time spent on each page) and the details of the path followed within the Website, with particular reference to the sequence of pages visited, to the parameters related to the User’s operating system and to the User’s IT environment.

USER

The individual who uses this Website that, unless otherwise specified, coincides with the Data Subject.

THE DATA SUBJECT

The physical person to whom the Personal Data refers.

PROCESSING MANAGER (OR MANAGER)

The physical person, legal entity, public administration and any other entity that processes Personal Data on behalf of the Data Controller, as set forth in this privacy policy.

DATA CONTROLLER (OR CONTROLLER)

The physical or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data and the instruments to be used, including any security measures relating to the operation and use of this Website. Unless otherwise specified, the Data Controller is the owner of this Website.

THIS WEBSITE

The hardware or software tool through which the Personal Data of the Users is collected and processed.

SERVICE

The Service provided by this Website as defined in the relevant terms (if any) on this site/application.

EUROPEAN UNION (OR EU)

Unless otherwise stated, any reference in this document to the European Union shall be deemed to extend to all current Member States of the European Union and the European Economic Area.

COOKIES

A small packet of data stored on the User’s device.

EUROPEAN UNION (OR EU)

This privacy policy is drawn up based on multiple legislative systems, including articles 13 and 14 of EU Regulation 2016/679.
Unless otherwise specified, this privacy policy only concerns this Website.