INFORMATION ON THE PROCESSING OF PERSONAL DATA
OZ S.p.A., with registered office in Via Bastion n.49/4 36061, Bassano del Grappa (VI), P.I. 00262760242 (hereinafter “OZ”), owns the site www.ozracing-ebike.com (“Site”), which offers its users (“Users”) the possibility to purchase some products online (hereinafter “Services”).
Pursuant to Art. 13 of EU Regulation 2016/679 (“Regulation”) and applicable privacy legislation OZ, as data controller (“Data Controller”), informs you that any personal data you may provide through the Site will be processed in compliance with the aforementioned legislation and according to the criteria indicated below.
- DATA CONTROLLER
The data controller is OZ, in the person of the legal representative pro tempore, with registered office in via Bastion n.49/4 36061, Bassano del Grappa (VI), P.I. 00262760242, Italy.
- TYPES OF PROCESSED DATA
– Navigation data: the computer systems and software procedures used to operate this Site acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of the computers used by users who connect to the Site, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and computer environment of the User. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the Site and to check its correct functioning and is deleted immediately after processing. The data could be used to ascertain responsibility in the event of hypothetical computer crimes to the detriment of the Site: apart from this possibility, at present the data on web contacts do not persist for more than seven days.
– Personal and contact data, provided voluntarily by the User for the creation of a Profile: the creation of a personal profile within the Site involves the processing of the User’s personal data requested in the relevant section of the Site, with the aim of creating a profile. The data subject of the processing are: name, surname, e-mail. The creation of the profile may also take place through the use of social networks. In this case, this may entail the possibility that OZ may have access to some additional personal data with respect to those requested during registration on the Site, based on the authorizations you have given to the social network itself and to which reference is made for privacy management policies.
– Personal and contact data, provided voluntarily by the User in order to purchase one or more products: the finalization of the purchase process of one or more products on the Site involves the processing of the User’s personal data requested in the relevant section of the Site. The data subject to processing are: name, surname, e-mail, address and telephone number.
– Personal and contact data, provided voluntarily by the User for the sending of promotional communications relating to the Services: if the User subscribes to the newsletter service or gives his/her consent for the receipt of commercial communications by the owner, the data will be processed for the sending of such communications by e-mail or ordinary mail or by SMS, to the addresses provided by the User. The data subject of the processing are: name, surname, e-mail, mobile phone number and domicile.
– Cookies: for the processing of data through cookies, please read the relevant policy
– In addition to the aforementioned categories of Personal Data, further data directly provided by the user and shared on the social pages owned by OZ (Facebook, Instagram, etc.) may be processed, for the management of which reference should be made to the third parties that provide these services. Among the data collected through the Social pages there are, for example, likes, comments, images and in general any content and information published by the Users in this context.
– OZ does not request and does not process particular data (e.g. data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data) – aimed at uniquely identifying a natural person, data relating to a person’s health or sexual life or sexual orientation.
3. PURPOSE AND LEGAL BASIS OF THE PROCESSING
The Users’ data collected are processed by the Owner for the following purposes.
– FUNCTIONING OF THE SITE: to guarantee the functioning and security of the Site and the information exchanged on it, i.e. the ability of this Site to resist, at a given level of security, unforeseen events or unlawful or malicious acts that compromise the availability, authenticity, integrity and confidentiality of personal data stored or transmitted and the security of the related services offered or made accessible. The legal basis for the processing is art. 6, par. 1 letter f) of the Regulation.
– CREATION OF A PERSONAL PROFILE ON THE SITE: to create a personal profile of the User through the Site or through the use of an existing social network account, to allow the creation of a custom profile of the User. The legal basis for the processing is art. 6, par. 1, letter b) of the Regulation, execution of pre-contractual measures to which the person concerned is a party.
– FINALIZATION OF A PURCHASE THROUGH THE SITE: for the finalization of one or more purchases through the Site. The legal basis for the processing is art. 6, par. 1, letter b) of the Regulation being the processing necessary for the execution of pre-contractual measures to which the person concerned is a party and/or the contract to which the interested party is a party.
– SENDING COMMERCIAL/PROMOTIONAL COMMUNICATIONS, INVITATIONS TO THE HOLDER’S EVENTS/WORKSHOP: if the user has given his/her explicit consent, to send invitations to events organized by the holder or to send promotional communications about the holder’s activity, as well as market research/statistical surveys. The legal basis for the processing is art. 6, letter A) of the Regulations, i.e. the consent of the interested party.
4. NATURE OF THE PROVISIONS OF DATA
The provision of your Personal Data is optional.
The provision of the data referred to in point 3 (creation of a personal profile, finalization of a purchase) is optional. However, failure to provide the data may prejudice the possibility of using certain Services, including the creation of the profile, finalization of the purchase procedure, etc..
The provision of the data referred to in point 3 (sending commercial/promotional communications relating to the holder’s Services) is optional. The user may revoke his/her consent at any time and without giving reasons. The easiest way to do so is to click on the “Unsubscribe” link, which can be found in every newsletter or communication received. The user may alternatively send a communication to the owner at firstname.lastname@example.org.
We would also like to remind you that on the basis of the regulations in force, the Company may use the e-mail details provided by you when purchasing a product to offer you products similar to those purchased by you. However, if you do not wish to receive such communications, you may give notice at any time, either by using the link on the email communications you have received or by sending an email to the owner at email@example.com. OZ, in this case, will interrupt the aforesaid activity without delay.
5. TREATMENT MODALITIES
The processing shall be carried out both on paper and by telematic means, with the aid of modern computer systems and with manual means, only by persons expressly appointed for this purpose. The processing will be carried out with logic and through forms of organization of data strictly related to the obligations, tasks or purposes mentioned above. The Data Controller uses technical and organizational measures to protect the data in its possession from manipulation, loss, destruction and against access by unauthorized persons. Security measures are constantly improved according to technological development.
6. SCOPE OF COMMUNICATION AND DISSEMINATION
The User’s personal data will be processed by persons authorized to carry out these tasks, duly appointed as data processors or persons in charge of processing, equipped with security measures to ensure the confidentiality of the data subjects to whom the data refer and to prevent undue access to third parties or unauthorized personnel. Should it be necessary, the data collected may be communicated, within the limits strictly pertinent to the obligations, tasks or purposes specified above, to public or private entities (insurers, auditing and certification companies, logistics and transport companies, IT service companies, etc.) or to the competent authorities for the purposes of preventing, detecting or prosecuting crimes, in compliance with the rules governing the matter. No data shall be disseminated.
The updated list of all Data Processors is available at OZ’s headquarters and may be requested at the following e-mail address: firstname.lastname@example.org. This list may be subsequently supplemented and/or updated as necessary.
7. PROCESSING DURATION AND DATA RETENTION PERIOD
– OZ undertakes to cancel from its systems the personal data provided for registration on the Site and use of the relative services, including purchases made through the Site, after 10 years from the date of cancellation of the relative registration on the Site or after 10 years from the date of purchase of the product;
– OZ has decided to provide for the cancellation of the personal data processed in order to send information of a commercial and marketing nature in relation to the activity, events, as well as for participation in satisfaction surveys and market research, after 2 years from the collection of personal data, or until your possible opposition.
In any case, OZ undertakes to inspire the processing of data to the principles of adequacy and minimization, annually verifying the need to keep the data for a period of time no longer than is necessary to achieve the purposes for which the data was collected and processed.
The Data Controller may store personal data in order to comply with regulatory obligations, or to ascertain, exercise or defend a right in court.
Once the purposes for which the personal data have been collected and processed have been achieved, the owner will take the appropriate measures to make them anonymous, so as to prevent identification, without prejudice to the possibility of continuing to use the personal data in anonymous form.
8. DATA OF MINORS
The Site and the Services are not aimed at minors and OZ does not therefore intend to collect personal data from minors.
9.TRANSFER OF PERSONAL DATA TO THIRD COUNTRIES
The entire Data processing is carried out in Italy and in the countries of the European Union.
Should there be a need to transfer the Data to Third Party Countries, the Data Controller undertakes to:
– Ensure that the country to which the Data will be sent guarantees an adequate level of protection, as provided for in article 45 of the Regulation; or
– Verify and carry out the transfer only in the event that the data controller or data processor provides adequate guarantees providing for enforceable rights and effective remedies for the data subjects (pursuant to Article 46 of the Regulation).
10. RIGHTS OF THE USER
Each data subject is guaranteed the following rights pursuant to Articles 15 et seq. of the Regulation:
– Right to information;
– Right of access of the data subject;
– Right of rectification;
– Right to cancellation (right to oblivion);
– Right to limitation of processing,
– Right to data portability;
– Right to object.
If you believe that the processing of your personal data has been carried out unlawfully, you may lodge a complaint to one of the supervisory authorities responsible for compliance with the rules on the protection of personal data. In Italy, the complaint may be submitted to the Personal Data Protection Guarantor (http://www.garanteprivacy.it/).
11. EXERCIZE OF RIGHTS
In order to exercise these rights, users may send a communication to the e-mail address email@example.com, indicating in the subject “Privacy – exercise of rights”.
*** *** ***