Privacy Policy

INFORMATION ON THE PROCESSING OF PERSONAL DATA pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR)

 Introduction

 This information is provided for the website “www.laserando.it” (hereinafter also referred to as the “Site”) owned by Varies di Valerio Vetrano, in the person of its legal representative, Mr. Valerio Vetrano, with registered office in Via Cetteo Ciglia n. 20, Pescara (PE) 65128, registered with the Pescara Chamber of Commerce with VAT number 02048810689, (hereinafter also referred to as the “Company”), as Data Controller, pursuant to Article 13 of the “Regulation (EU) 2016/679 of the European Parliament and of the Council”, hereinafter GDPR, which came into force on May 24, 2016 and is applicable from May 25, 2018, and Legislative Decree 101/2018.

Purchases on the Site

Subject to your consent, your personal data will be processed to allow you to make purchases on the Site.

This information is not valid for other websites that may be accessed through our links, for which the Company is in no way responsible.

Soft spamming

The Company may use, for the direct sale of products offered for sale through the Site, the email address you provided in the context of a purchase on the Site, even without your consent, provided that it is a product similar to the one previously sold (so-called soft spamming). You may, however, refuse this processing at any time by communicating your opposition to the Company.

***

In compliance with the GDPR, we hereby inform you that the Company will process your personal, identifying and non-sensitive data (meaning: first name, last name, tax code, VAT number, email, telephone number – hereinafter, “personal data” or “data”) that you have provided, under the following conditions.

 

Art. 1. Purposes and legal basis for processing. Mandatory or optional provision. Consequences of refusing to process.

The processing of personal data (Arts. 6 and 7 GDPR) is aimed at achieving the following purposes:

  1. to enable compliance with obligations deriving from current laws or regulations, in particular, in the administrative, accounting, and public security fields. The legal basis for processing is the Company's need to execute pre-contractual measures adopted at the request of the data subject or to comply with a legal obligation;
  2. in the case of an online purchase order, to allow the conclusion of the purchase contract and the correct execution of the operations related thereto (and, where necessary according to sector legislation, to fulfill tax obligations). The legal basis for processing is the Company's obligation to execute the contract with the data subject or to comply with legal obligations;
  3. limited to the email address you provided in the context of a purchase through the Site, to allow the Company to directly offer similar products (so-called soft spamming), provided that you do not object to such processing in the manner provided in this information notice. The legal basis for processing is the Company's legitimate interest in sending the aforementioned type of communications. This legitimate interest can be considered equivalent to the data subject's interest in receiving "soft-spam" communications;
  4. with your consent, the legal basis for processing is the data subject's consent;
  5. to respond to your requests through the customer care service. Provision is optional, but your refusal will make it impossible for the Company to answer your questions through this service. The legal basis for processing is the Company's legitimate interest in responding to user requests. This legitimate interest is equivalent to the user's interest in receiving a response to communications sent to the Company;
  6. to respond to your requests by email. Provision is optional, but your refusal will make it impossible for the Company to respond to your requests. The legal basis for processing is the Company's legitimate interest in responding to user requests. This legitimate interest is equivalent to the user's interest in receiving a response to communications sent to the Company.

The provision of data for the purposes referred to in point b) is merely optional. However, since this processing is necessary to allow registration on the Site and to make a purchase on the Site, your eventual refusal to provide the data in question will make it impossible to register on the Site and to make such a purchase through the Site.

Notwithstanding the foregoing, it is understood that the Company may in any case use your personal data solely for the purpose of correctly fulfilling the obligations provided for by current laws and the obligations arising from the contractual relationships existing between you and the Company.

Your personal data are processed:

  1. A) without your express consent (Art. 6, letter b), e), GDPR), for the following Service Purposes:

– to process a contract request or a pre-contractual request;

– to execute pre-contractual measures adopted at your request;

– to compile internal statistics;

– to fulfill tax obligations arising from existing relationships;

– to comply with legal obligations, regulations, community legislation, or an order from an Authority;

– to safeguard the vital interests of the data subject or another natural person;

– to perform tasks in the public interest or connected to the exercise of public powers vested in the data controller;

– to prevent or detect fraudulent activities or harmful abuses to the website;

– to pursue a legitimate interest of the Data Controller or third parties, within the limits and conditions referred to in Art. 6, letter f), GDPR;

– to exercise the rights of the Controller (for example, the right of defense in court);

  1. B) Only with your specific and unequivocal consent (Art. 7 GDPR), for the following Marketing Purposes:
  • to send newsletters, commercial communications, and/or advertising material via email about products and/or services, other than those already purchased, offered by the Data Controller (the provision of Data for the purposes just described is optional and the user can decide not to provide any data or revoke the possibility for us to process previously provided data. In this case, you will no longer receive our newsletters, while you will continue to receive our services and retain the right to register on the site).

 

PayPal

On the Site, it is also possible to make purchases through the PayPal payment tool. In this case, you will be directed to a page external to the Site, where you will need to provide the personal data requested by PayPal – which will act as an independent data controller – to complete the purchase process. Personal data will not pass through the Site's server, which will therefore not process such data in any way. The processing of your personal data is necessary to allow the conclusion of the online purchase contract with the Company. Failure to provide this data will therefore prevent you from completing the online purchase process.

 

Special or judicial data

The Company does not process special categories of data or judicial data.

 

Art. 2. Processing Methods

The processing of your personal data will be carried out through collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, deletion and destruction by employees or collaborators of the Company.

The processing of your Data will be based on the principles of fairness, lawfulness and transparency and will be carried out mainly with the aid of electronic or automated means, using appropriate methods and tools, as far as reasonable and in the state of the art, to ensure its security and confidentiality in accordance with the GDPR.

The acquired information and the processing methods will be relevant and not excessive compared to the type of services provided.

Data will also be managed and protected in environments whose access is under constant control and will be protected by authentication systems.

The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of internet communication protocols.

This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified.

This category of data includes IP addresses or domain names of the computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the user's computer environment.

These data are used solely for the purpose of obtaining anonymous statistical information on the use of the site and to check its correct functioning, and are deleted immediately after processing.

The data in question could be used to ascertain responsibility in case of hypothetical computer crimes against our site.

The management and storage of personal data will take place on the Data Controller's servers. Currently, the servers are located in the European Union. Data will not be transferred outside the European Union.

It is understood in any case that, should it become necessary to transfer the location of the servers, in Italy and/or the European Union and/or non-EU countries, such transfer will always take place in compliance with Articles 45 et seq., GDPR. In this case, however, the Data Controller hereby assures that the transfer of data outside the EU will take place in accordance with the applicable legal provisions by stipulating, if necessary, agreements that guarantee an adequate level of protection and/or by adopting the standard contractual clauses provided by the European Commission.

Where the data subject is under 16 years of age, processing is lawful only if and to the extent that such consent is given or authorised by the holder of parental responsibility, whose identification data are acquired.

The optional, explicit and voluntary sending of e-mails to the addresses indicated on this site by its very nature entails the subsequent acquisition of the sender's address, necessary to respond to requests, as well as any other personal data included in the message.

We invite our users, in requests for information or questions, not to send names or other personal data of third parties that are not strictly necessary.

 

Art. 3. Communication and dissemination of data

Personal data processed by the Data Controller will not be disseminated, meaning it will not be disclosed to indeterminate subjects, except in anonymous and aggregated form, for statistical or research purposes.

Your data may be communicated to:

  • all those subjects (including Public Authorities) who have access to personal data by virtue of regulatory or administrative provisions;
  • companies or third parties responsible for printing, enveloping, shipping and/or delivery and/or collection services for products purchased through the Site;
  • post offices, couriers or shipping companies entrusted with the delivery of products purchased through the Site;
  • banks and companies managing national or international payment circuits through which online payments for products purchased through the Site are made;
  • companies, consultants or professionals who may be responsible for the installation, maintenance, updating and, in general, the management of the Company's hardware and software or which the Company uses to provide its services;
  • the company responsible for carrying out customer care activities;
  • all public and/or private entities, individuals and/or legal entities (legal, administrative and tax consulting firms, Judicial Offices, Chambers of Commerce, Labor Chambers and Offices, etc.), if the communication is necessary or functional for the correct fulfillment of obligations arising from law or for the protection of the Company's rights.

It is also specified that the Data Controller may communicate your data, without your express consent (pursuant to Article 6, letters b) and c), GDPR), for the indicated purposes, to supervisory bodies, judicial authorities, and all other subjects to whom communication is mandatory by law for the fulfillment of the aforementioned purposes.

 

Art. 4. Data Controller

The Company, as Data Controller of personal data, can be contacted, through the contact form on the website, at the following addresses:

Varies di Valerio Vetrano Via Cetteo Ciglia n. 20, Pescara (PE) 65128

Telephone: 391-1209389

Email: info@laserando.it

 

Art. 5. Retention of personal data

 User data will be stored only for the time necessary to ensure the correct provision of the services offered and in any case within the terms established by law or by the provisions of the Personal Data Protection Authority; in particular, processing will not exceed a period of 2 (two) years from collection for marketing purposes. After this retention period, the data will be destroyed or anonymized.

To improve the service offered, immediate reporting of malfunctions, abuses or suggestions to the email address: info@laserando.it is appreciated.

 

Art. 6. Data Subject's Rights

Pursuant to Art. 13 of the Privacy Regulation (but also cf. Arts. 12-23 of the GDPR), the Company informs you that you have the right to:

  1. request from the Company access to and confirmation of the existence or not of personal data concerning you, even if not yet recorded, and their communication in an intelligible form;
  2. obtain information on: the origin of personal data; the purposes and methods of processing; the logic applied in case of processing carried out with the aid of electronic instruments; the identification details of the data controller, any data processors and designated representatives; the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of them as representatives, data processors or persons in charge;
  3. obtain the updating, rectification or, when there is interest, the integration of the data;
  4. obtain the erasure of data, transformation into anonymous form or blocking of data processed in violation of the law, including those for which retention is not necessary in relation to the purposes for which the data were collected or subsequently processed;
  5. obtain the restriction of processing of data concerning you or object, in whole or in part, to their processing, in addition to the right to data portability;
  • to obtain confirmation that the operations referred to in numbers 3, 4 and 5 have been brought to the attention, also as regards their content, of those to whom the data have been communicated or disseminated, except in cases where such fulfillment proves impossible or involves a manifestly disproportionate use of means with respect to the protected right;
  • to withdraw consent at any time without affecting the lawfulness of processing based on consent given before withdrawal;
  • to lodge a complaint with a supervisory authority (e.g. the Italian Data Protection Authority).
  • The above rights may be exercised by making a request without formalities to the Company, as data controller, at the contact details indicated above.

     

    Art. 7. Cookie Management

     Cookies are small text files that websites visited by the user send to their terminal (usually the browser), where they are stored and then retransmitted to the same sites at the next visit by the same user.

    Cookies are used to perform computer authentications, session monitoring and storage of specific information concerning users who access the server and are normally present in the browser of each user in a very large number.

    Cookies are distinguished from each other:

    • based on who installs them, depending on whether it is the same operator of the visited site (so-called "first-party cookies") or a different entity (so-called "third-party cookies");
    • based on the purpose of each cookie: some cookies allow for better navigation, memorizing some user choices, for example the language (so-called "technical cookies"), other cookies allow monitoring of user navigation also for the purpose of sending advertising and/or offering services in line with their preferences (so-called "profiling cookies").

    Only profiling cookies require the user's prior consent for their use.

    The Website uses technical cookies as well as third-party profiling cookies.

    The Company is solely responsible for the first-party cookies installed by it on the Website.

    For more information, you can directly consult the "Extended Cookie Policy" page accessible via the appropriate link on the site.

     

    Art. 8. Amendments

    The Company reserves the right to make changes to this policy at any time, by giving appropriate notice to the users of the Website and in any case ensuring adequate and similar protection of personal data. In order to view any changes, you are invited to consult this policy regularly.

     

    Pescara, 06/02/2023