Privacy policy

PRIVACY POLICY OF THE WEBSITE WWW.PROMIS.CARE

 

promis Srl explains, on this page, how it processes the data of users who visit its website and how the cookies installed by the site itself operate.

This Privacy Policy is provided in compliance with Article 13 of GDPR 2016/679 (General Data Protection Regulation, European regulation on personal data protection), the Privacy Authority Guidelines of June 10, 2021, the EDPB Guidelines 5/2020 related to consent, the CJEU ruling of October 1, 2019 C-673/17, the General Provision of the Privacy Authority regarding cookies of May 8, 2014, no. 229, the “Working Document 02/2013 providing guidance on obtaining consent for cookies,” the WP29 Opinion no. 4/2012 On Cookie Consent Exemption, Directive 2002/58/EC, and Recommendation no. 2/2001 of the Article 29 Working Party.

The following applies only to the site www.promis.care ; the Data Controller is not responsible for the data entered and the cookies installed by other sites that may be accessed through links.

 

Information about the Data Controller

The Data Controller is promis Srl, with registered office at via Negrelli 4, 39100 Bolzano.

To exercise the rights provided by the legislation, it is possible to contact the Data Controller at their office or by writing to support@promis.care .

 

Purpose and legal basis of processing

 

promis Srl processes the data that the user provides through the website for the following purposes:

  1. Fulfillment of obligations provided for by law, by a regulation, or by a community directive

The provision of data for this purpose is mandatory, and the legal basis for processing is the fulfillment of a legal obligation to which the data controller is subject, as established by Article 6(1)(c) of the GDPR. For the processing of personal data for these purposes, the user's consent is not required. The processed data will be retained for the period prescribed by the applicable regulations.

  1. Statistical analysis on aggregated or anonymous data

This processing does not allow the identification of the user, but simply aims to verify the adequacy of the adopted web marketing campaigns and/or the correct functioning of the site, by measuring the traffic of users it generates. The processing of aggregated or anonymous data, which does not allow the identification of the user, does not fall within the scope of personal data protection regulations and therefore no consent is required for their processing.

  1. Request for information, contact, and support

The provision of the requested data is necessary to respond to your request. The legal basis for processing is indicated in Article 6(1)(b) of the GDPR, which is the performance of a contract to which the data subject is a party or the implementation of pre-contractual measures taken at the data subject's request, as well as Article 6(1)(f), which is the pursuit of the legitimate interests of the data controller or third parties. The data processed in relation to your request will be retained by us for one month.

  1. Registration in the reserved area

The provision of the requested data is necessary to allow you access to the reserved area. The legal basis for the processing is indicated by Article 6, paragraph 1, letter b) of the GDPR, and is the execution of a contract to which the data subject is a party or the execution of pre-contractual measures adopted at their request. The data processed and related to your registration will be kept by us until you request deletion and unsubscription.

  1. Application to our facility

The provision of the requested data is necessary to respond to your application or collaboration request at our organization. The legal basis for processing is indicated by Article 6, paragraph 1, letter b) of the GDPR, which is the performance of a contract to which the data subject is a party or the implementation of pre-contractual measures taken at the data subject's request, as well as Article 6, paragraph 1, letter f), which is the pursuit of the legitimate interest of the data controller or third parties. The data processed related to your application will be retained by us for one year.

  1. Sending newsletters

The provision of the requested data to subscribe you to our newsletter and/or to send you communications and promotional material is entirely optional, and the legal basis for this processing is the consent expressed by the data subject for the processing of their personal data. The data processed for promotional and marketing purposes will be retained by us until you withdraw your consent, unless the consent for processing is renewed.

  1. Purchase of products and management of returns and/or complaints

The provision of the requested data is necessary to purchase products on our online shop and to manage all subsequent (and possible) contractual phases. The legal basis for processing is indicated in Article 6, paragraph 1, letter b) of the GDPR, and is the execution of a contract to which the data subject is a party or the execution of pre-contractual measures adopted at their request. The data processed and related to your request will be retained by us for the period required by civil, accounting, and tax regulations, and therefore for 10 years.

  1. Profiling (creation of profiles based on the user's preferences, habits, and consumption choices)

The activity in question can be carried out through the completion of dedicated questionnaires or through the use of online profiling technologies (trackers) or cookies. The provision of data required for profiling activities is optional, and the legal basis for processing is the consent expressed by the data subject for the processing of their personal data. The data processed for profiling purposes will be handled until its revocation and for a maximum of one year, unless the consent to the processing is renewed.

 

Treatment methods, automated decision-making processes, and data retention periods

The processing of Your data is carried out using computerized methods, although potential processing in paper form is not excluded. Automated decision-making processes are not used to process Your personal data. Data collected through cookies will be stored for the period established by each individual cookie. Furthermore, in the case of profiling cookies used by the site, the description of their operation is delegated to the specific section.

 

Data Communication (Recipients)

To ensure the operation of our website and the enjoyment of its content, we may use third-party providers such as IT service providers, hosting companies, and communication companies. Additionally, to guarantee the requested service, for example in the case of purchasing products and similar, we may also use other third-party providers (postal couriers, etc.). The legal basis for the communication is the fulfillment of contractual and regulatory obligations, as well as the execution of pre-contractual measures adopted at your request. It is understood that we will communicate to the Recipients only the data necessary to fulfill the service, preferring data anonymization whenever possible. The data you provide will not be disclosed without your specific and prior consent.

For information regarding the use of third-party cookies, please refer to the specific section located at the end of this document.

 

Transfer of data to third countries or international organizations

Some cookie providers or tools used by our website may transfer personal data to the United States. Since the transfer cannot be carried out under other mechanisms provided by the GDPR, the consent of the data subject is required.

Please note that the United States does not currently provide adequate data privacy protections for European citizens, and local authorities may request access to information without specific safeguards. Users are advised to carefully consider whether they wish to consent to this processing. .

The cookies and providers that may transfer data to the United States are:

  • Google
  • Facebook (Meta)

The website hosting is within the European Union..

 

Rights of the data subject and complaint to the Privacy Authority

You have the right to request access to your data at any time, as well as their modification, integration, or deletion, the limitation or opposition to their processing, where there are legitimate reasons, and the portability of said data to another Data Controller. We will provide you with a written response within 30 days. You may revoke, at any time, the consents given on this site by contacting one of the contacts listed in this Privacy Policy. You may also file a complaint with the national supervisory authority if you believe that your data has been processed unlawfully.

 

 

THE COOKIES OF OUR SITE

Browsing data

This website implicitly collects, using internet communication protocols, during and in the course of its normal operation, some personal data of users who access the site itself, such as the IP address, the domain names of the computers from which the user accesses, the MAC addresses assigned by the manufacturers of network cards, wireless, etc.

These information are not collected to identify users, but they could be through associations and processing, including cross-referencing with third-party data; from these data, statistical information is derived about the use of the site and its operation, as well as additional information in case of liability verification related to cybercrimes.

 

What are cookies?

Cookies are small text strings that websites visited by the user install on their device; these strings are subsequently retransmitted to the site that installed them in case of a subsequent visit by the user. When the user receives, during navigation on the site, cookies sent by different sites or web servers, these are called third-party cookies.

The cookies are installed for various purposes, which may include the ability to perform computer authentications, monitor browsing sessions, and select the language.

 

First-party cookies and third-party cookies

Cookies that are installed directly by promis Srl are called "First-party Cookies", while cookies that are installed and collected by a website other than the one the user is browsing are defined as "Third-party Cookies".

Third-party cookies include social buttons (or social plugins), which allow the site to interact with the most popular social media platforms, such as Facebook, Instagram, LinkedIn, Twitter, etc., as well as Google Analytics cookies, those necessary to implement YouTube iframes, etc. Regarding third-party cookies, it is the responsibility of the third parties to whom the cookie belongs to provide the privacy notices and information about the management of the collected data.

 

 

 

Types of cookies

Technical cookies

They are usually installed directly by the site operator and are cookies that allow communication between the site and the user. They can also be called "navigation" or "session" cookies, or "essential cookies" or "necessary cookies," and are intended to ensure normal navigation and use of the site. andusually last as long as the browsing session on the site.

Since these cookies are necessary for the functioning of the site, their installation on the user's device does not require prior consent.

 

Functional cookies

These cookies allow the user to access advanced features and customizations, as well as to remember the preferences indicated during previous visits, or the changes the user made during previous visits to personalize the site. This category includes, for example, cookies that allow the user to choose the language or save the products selected in the cart.

 

Performance cookies

These cookies are also called "performance cookies" or "analytical cookies" and allow the analysis of how the user uses the site, in order to improve the browsing experience and resolve navigation-related issues. For example, these cookies enable counting visits and traffic sources, or tracking the most viewed pages.

They usually do not allow the identification of the individual user, but contain aggregated and therefore anonymous data. One of the most famous tools for obtaining such statistical reports is Google Analytics, a service provided by Google Inc.

 

Profiling cookies

They are also called "advertising cookies" and are used to track a user's preference and offer them advertising messages based on the preferences gathered.

 

The banner on first access

The provision of the Data Protection Authority dated May 8, 2014, and the Guidelines on the use of cookies and other tracking tools require, in the case of using cookies other than technical cookies, the preparation of a banner at the user's first access to the site (so-called short notice) that essentially indicates the methods of cookie management by the site, refers to the extended privacy policy, and provides for expressing consent to the installation of cookies, including through granular selection of them.

promis Srl has prepared the aforementioned banner. A specific cookie has also been set up to store the user's choice regarding the installation of cookies for 365 days; this means that once the user has given their consent, they will see the banner only once, and if they later wish to change their choices, they can do so via the "Manage my cookies" link.

 

 

Facebook permissions requested by the site and use of Facebook Pixel.

Our site may request to connect with the user's Facebook account to perform certain actions and collect information directly from Facebook.

For more information on how this feature works, please refer tohttps://developers.facebook.com/docs/facebook-login/permissionse ahttps://www.facebook.com/about/privacy/

 

Links to the privacy policies of third parties that install cookies

Facebook:https://www.facebook.com/policies/cookies/