Privacy Policy
INTRODUCTION
For us at PAL.CO®, we really care about the Privacy of users browsing our e-commerce platform, therefore, we make every effort to ensure their protection.
This privacy policy describes the methods for the processing of your personal data, ensuring you maximum transparency and respect for your rights.
DATA CONTROLLER
The data controller is Palco Srls Unipersonale - with its registered office in Viale Tisia, 112 - 96100 – Siracusa (SR) – e-mail info@palcostudio.it, hereinafter PAL.CO.
Contact details can be found in the 'Contacts’ section of our website.
The services offered by the Data Controller are addressed to people older than 18. If the Data Controller becomes aware of the data processing of children under 18 years of age without valid parental consent or legal guardian, he reserves the right to unilaterally interrupt the use of the service offered, as well as to cancel the acquired data.
LEGAL BASIS
The Users/Data Subjects provide their data VOLUNTARILY and by giving their CONSENT, by filling in the contact or sign up Form, or by joining our Newsletter, or by sending an email to the addresses in the Contacts section.
The Data Controller will use these data for the purpose of following up the obligations arising from the Contract between the parties, that is any communication and contact requests of the User/Data Subject.
PURPOSES
The Data Controller processes and stores the data for the aforementioned purposes, to process your orders and to fulfil the obligations arising from the contract with you, as well as to fulfil the services you required (e.g. replying to contact requests or newsletters).
PAL.CO carries out profiling activities only upon the consent of the User/Data Subject.
In this context, as for the data collected through your browsing device, we ask you to read our Cookie Policy.
CATEGORIES OF RECIPIENTS
Your Personal Data may be communicated to and processed by:
- legal or natural persons acting as external data processors, carrying out outsourced activities, appointed by PAL.CO or by external data processors (including entities entrusted with assistance, communication, marketing, and advertising activities, as well as IT service providers, Website managers, partners, credit institutions, professional firms);
- employees and/or collaborators of the Data Controller (including system administrators) who, acting under the direct authority of the Data Controller, will be authorized to process your Personal Data;
- employees and/or collaborators of the external data processors (including system administrators) who, acting under the direct authority of the external data processors, will be authorized to process your Personal Data.
Your Personal Data will not be communicated to third parties or disseminated, except when communicated by PAL.CO to third parties acting as autonomous owners or consultants in order to protect its rights.
PLACE OF DATA PROCESSING
Your Personal Data is mainly processed at the Data Controller’s premises and at the locations of the data processors. For further information, please contact the Data Controller at the addresses in the section Contacts
You data will be stored at the Servers of Shopify.
TRANSFER OF PERSONAL DATA
Some of your Personal Data may, now or in the future, be shared with Recipients who may be located outside the European Economic Area.
The company ensures that your Personal Data is processed by these Recipients in accordance with the Regulation.
The transfer of data may be based on an adequacy decision or on the Standard Contractual Clauses approved by the European Commission. Some of these processing operations may involve the transfer of the data in question outside the European Economic Area.
The data in such cases are transferred on the basis of articles 46 and 49 of the Regulation.
STORAGE PERIOD
The storage period of the collected data are thus, as per Law, divided:
- for the management and response of client specific requests: maximum 24 months
- for the management and fulfilment of legal obligations: maximum 10 years;
- for the management of complaints and any disputes: for the established prescription period or for the period established by law;
After these periods or when the data has fulfilled the purpose for which it was collected, it is definitively eliminated.
METHOD OF GIVING CONSENT ACTIVE CONSENT.
Our e-commerce platform does not use any automatic or default boxes to obtain your consent on the processing of personal data.
Indeed, as required by EU Regulation, you will be able to express your consent in a clear, determined and conscious way by clicking on the acceptance button, only after you have carefully read the text of the policy.
USE OF PERSONAL DATA
The personal data you provide via our website will be used within the scopes expressed in this privacy policy or on the relevant pages of our e-commerce platform.
We may use your personal data for the following purposes:
- processing your orders;
- fulfilling the obligations arising from the contract with you;
- sending newsletters upon your request and subscription;
- sending e-mails you expressly requested;
- handling your requests and complaints, as well as your actions in relation to our website and service we offer;
- maintaining the security of our website and fraud prevention;
- additional uses permitted by the Applicable Law.
STORAGE OF DATA
Your Personal Data will be processed mainly in an automated form, but also on paper with logics strictly related to the relevant purposes.
The Data Controller has assessed the level of security as adequate taking into account the risks that may arise from loss, destruction, modification, unauthorised disclosure, accidental or unlawful access, abuse or alteration of your Personal Data and adopting security measures appropriate to the risks;
the Data Controller, in general, does not store your Personal Data. However, if this is required to fulfil the purposes for which they were collected, your personal data are stored on servers mainly located in Europe, which are subject to an advanced back-up system.
Notwithstanding the provisions of this section, we will store documents (including electronic documents) containing your personal data:
- if requested by the Italian law;
- if we believe that those documents may be relevant for any legal procedure (ongoing or future);
- if we need to enforce, exercise, or defend our legal rights (including providing information to third parties for the purpose of fraud prevention and credit risk reduction).
- We will adopt a reasonable amount of technical and organizational measures to avoid data loss, improper use or modification of your personal data.
- We will store all the personal data you provide us on our secure servers (firewall and password protected).
- You accept that the data transmission via internet is, by nature, non secure and that we cannot ensure the safety of the data transmitted via internet.
YOUR RIGHTS
As data subject, according to Regulation 678/2016, you have the right to:
- request confirmation of the existence of personal data, including data collected by our e-commerce platform;
- know their origin, the logic and the purposes of their processing;
- obtain updating, correction and integration;
- request cancellation and oblivion, transformation into anonymous form or blocking in case of unlawful processing;
- oppose their processing for legitimate reasons or in the case of use of data for sending advertising material, commercial information, market research, direct sales and interactive commercial communication;
- request the transfer of personal data to third parties, whenever possible and necessary.
You can exercise these rights through direct contact of the Data Controller - by sending a written communication to one of the Contacts in the appropriate section - to whom you may request to proceed to each of the above mentioned charges.
You can ask us to provide you with all your personal data and information in our possession; provision of such information will be subject to the following:
- The provision of appropriate evidence of your identity (a photocopy of the identity document) plus a copy of a utility bill showing your current address;
We may retain the personal data requested by you to the extent permitted by law.
THIRD-PARTY WEBSITES
Our website may include hyperlinks to, and details of, third-party Websites (Google - LinkedIn - Instagram - Facebook).
We have no control over, and are not responsible for, the privacy policies and practices adopted by the above-mentioned third parties.
UPDATING INFORMATION
Please let us know if your personal data in our possession needs to be corrected or updated.
WHO TO CONTACT TO MAKE A COMPLAINT
PAL.CO reminds you that, if you believe that the data processing breaches the provisions of the Regulation, you can submit a complaint to the Authority for the Protection of Personal Data (www.garanteprivacy.it), or to the Authority of the Country of your residence or workplace, or in the place where the alleged breach occurred.
The above is without prejudice to your right to revoke at any time whatsoever consent to data processing you might have granted and to object to our analysis activities.
Moreover, pursuant to Article 21 of the Regulations, you will have the right to object at any time, for reasons relating to your particular situation, to the data processing carried out for the pursuit of the legitimate interest of the Data Controller, pursuant to Article 6, paragraph 1, letter f) of the Regulation.