Privacy Policy
Types of Data Collected
Among the Personal Data collected by company, either independently or through third parties, are: Cookies, Usage Data, email, and various types of Data.
Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific informational texts displayed prior to the collection of the data.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of company.
Unless specified otherwise, all Data requested by company is mandatory. If the User refuses to provide it, it may be impossible for company to provide the Service. In cases where company indicates certain Data as optional, Users are free to refrain from providing such Data without any consequences for the availability or functionality of the Service.
Users who have doubts about which Data is mandatory are encouraged to contact the Data Controller.
The use of Cookies or other tracking tools by company or by third-party service providers used by company, unless otherwise specified, is intended to provide the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through company and guarantees that they have the right to communicate or disseminate it, releasing the Data Controller from any liability to third parties.
Methods and Place of Processing the Collected Data
Processing Methods
The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.
The processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the organization of company (administrative, commercial, marketing, legal, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) may have access to the Data, appointed, if necessary, as Data Processors by the Data Controller. The updated list of Data Processors can always be requested from the Data Controller.
Legal Basis of Processing
The Data Controller processes Personal Data relating to the User if one of the following conditions exists:
It is always possible to request the Data Controller to clarify the specific legal basis of each processing and, in particular, to specify whether the processing is based on law, required by a contract, or necessary to conclude a contract.
Place
The Data is processed at the Data Controller’s operating offices and in any other place where the parties involved in the processing are located. For further information, contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one where the User is located. To obtain further information on the place of processing, the User can refer to the section detailing the processing of Personal Data.
The User has the right to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organization governed by public international law or established by two or more countries, such as the UN, as well as about the security measures taken by the Data Controller to protect the Data.
The User can verify whether one of the transfers described above takes place by examining the section of this document relating to the details on the processing of Personal Data or request information from the Data Controller by contacting them at the details provided at the beginning.
Retention Period
Data is processed and stored for the time required by the purposes for which it was collected.
Therefore:
When processing is based on the User’s consent, the Data Controller may retain the Personal Data for longer until such consent is revoked. Additionally, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, the Personal Data will be deleted. Therefore, the rights of access, deletion, rectification, and data portability cannot be exercised after the expiration of this period.
Purposes of Processing the Collected Data
The User’s Data is collected to allow the Data Controller to provide its Services, as well as for the following purposes: Statistics, Advertising, Contacting the User, Interaction with external social networks and platforms, Managing contacts and sending messages, Remarketing and behavioral targeting, Heat mapping and session recording, Hosting and backend infrastructure, Content and functionality performance testing (A/B testing), Data transfer outside the EU, and Displaying content from external platforms.
For further detailed information on the purposes of processing and the Personal Data relevant to each purpose, the User can refer to the relevant sections of this document.
Details on the Processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
Contacting the User
Mailing List or Newsletter (company)
By registering for the mailing list or newsletter, the User’s email address is automatically added to a list of contacts to which email messages containing information, including commercial and promotional content, related to company may be sent. The User’s email address may also be added to this list as a result of registering on company or after making a purchase.
Personal Data collected: email.
Managing Contacts and Sending Messages
This type of service allows the management of a database of email contacts, phone contacts, or any other type of contact used to communicate with the User.
These services may also collect data related to the date and time the messages are viewed by the User, as well as the User’s interaction with them, such as information on clicks on links inserted in the messages.
Heat Mapping and Session Recording
Heat mapping services are used to identify which areas of a page are subject to cursor movement or mouse clicks to detect which areas attract the most interest. These services allow monitoring and analyzing traffic data and are used to track User behavior.
Some of these services may record sessions and make them available for later viewing.
Hotjar Heat Maps & Recordings (Hotjar Ltd.)
Hotjar is a heat mapping and session recording service provided by Hotjar Ltd.
Hotjar respects generic “Do Not Track” headers. This means the browser can instruct the script not to collect any User data. This is a setting available in all major browsers. Further information on opting out of Hotjar is available here.
Personal Data collected: Cookies, Usage Data, and various types of Data as specified in the service’s privacy policy.
Place of processing: Malta – Privacy Policy – Opt Out.
Hosting and Backend Infrastructure
This type of service has the function of hosting Data and files that allow company to function, enable its distribution, and provide a ready-to-use infrastructure to deliver specific functionalities of company.
Some of these services operate through servers geographically located in different places, making it difficult to determine the exact location where Personal Data is stored.
DigitalOcean
DigitalOcean is a hosting and backend service provided by DigitalOcean LLC.
Personal Data collected: various types of Data as specified in the service’s privacy policy.
Place of processing: USA – Privacy Policy. Subject to the Privacy Shield.
Interaction with External Social Networks and Platforms
This type of service allows interaction with social networks or other external platforms directly from the pages of company.
The interactions and information acquired by company are always subject to the User’s privacy settings for each social network.
If a social network interaction service is installed, it may collect traffic data related to the pages where it is installed, even if Users do not use the service.
Facebook Like Button and Social Widgets (Facebook, Inc.)
The Facebook “Like” button and social widgets are services for interaction with the Facebook social network, provided by Facebook, Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy.
Twitter Tweet Button and Social Widgets (Twitter, Inc.)
The Twitter Tweet button and social widgets are services for interaction with the Twitter social network, provided by Twitter Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy.
Google+ +1 Button and Social Widgets (Google Inc.)
The Google+ +1 button and social widgets are services for interaction with the Google+ social network, provided by Google Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy.
LinkedIn Button and Social Widgets (LinkedIn Corporation)
The LinkedIn button and social widgets are services for interaction with the LinkedIn social network, provided by LinkedIn Corporation.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy.
Advertising
This type of service allows the use of User Data for commercial communication purposes in various advertising forms, such as banners, also in relation to the User’s interests.
This does not mean that all Personal Data is used for this purpose. Data and conditions of use are indicated below.
Some of the services listed below may use Cookies to identify the User or use behavioral retargeting techniques, i.e., displaying personalized ads based on the User’s interests and behavior, detected even outside company. For more information, we suggest checking the privacy policies of the respective services.
Google AdSense (Google Inc.)
Google AdSense is an advertising service provided by Google Inc. This service uses the “DoubleClick” Cookie, which tracks the use of company and the User’s behavior in relation to advertisements, products, and services offered.
The User can decide at any time not to use the DoubleClick Cookie by deactivating it: google.com/settings/ads/onweb/optout.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy – Opt Out.
Direct Email Marketing (DEM) (company)
company uses User Data to send commercial proposals related to services and products provided by third parties or unrelated to the product or service provided by company.
Personal Data collected: email.
Remarketing and Behavioral Targeting
This type of service allows company and its partners to communicate, optimize, and serve ads based on the User’s past use of company.
This activity is carried out by tracking Usage Data and using Cookies, information that is transferred to the partners to which the remarketing and behavioral targeting activity is linked.
In addition to the opt-out options offered by the services listed below, the User can opt out of receiving cookies related to a third-party service by visiting the Network Advertising Initiative opt-out page.
AdWords Remarketing (Google Inc.)
AdWords Remarketing is a remarketing and behavioral targeting service provided by Google Inc. that connects the activity of company with the Adwords advertising network and the DoubleClick Cookie.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy – Opt Out.
Facebook Remarketing (Facebook, Inc.)
Facebook Remarketing is a remarketing and behavioral targeting service provided by Facebook, Inc. that connects the activity of company with the Facebook advertising network.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy – Opt Out.
Facebook Custom Audience (Facebook, Inc.)
Facebook Custom Audience is a remarketing and behavioral targeting service provided by Facebook, Inc. that connects the activity of company with the Facebook advertising network.
Personal Data collected: Cookies and email.
Place of processing: USA – Privacy Policy – Opt Out.
Google Ad Manager Audience Extension (Google Inc.)
Google Ad Manager Audience Extension is a remarketing and behavioral targeting service provided by Google LLC that tracks visitors to company and allows selected advertising partners to display personalized ads to them on the web.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy – Opt Out. Subject to the Privacy Shield.
Twitter Remarketing (Twitter, Inc.)
Twitter Remarketing is a remarketing and behavioral targeting service provided by Twitter, Inc. that connects the activity of company with the Twitter advertising network.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy – Opt Out. Subject to the Privacy Shield.
LinkedIn Website Retargeting (LinkedIn Corporation)
LinkedIn Website Retargeting is a remarketing and behavioral targeting service provided by LinkedIn Corporation that connects the activity of company with the LinkedIn advertising network.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy – Opt Out.
Statistics
The services contained in this section allow the Data Controller to monitor and analyze traffic data and are used to track User behavior.
Google Analytics (Google Inc.)
Google Analytics is a web analytics service provided by Google Inc. (“Google”). Google uses the Personal Data collected to track and examine the use of company, compile reports, and share them with other Google services.
Google may use the Personal Data to contextualize and personalize ads in its advertising network.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy – Opt Out.
Facebook Ads Conversion Tracking (Facebook, Inc.)
Facebook Ads conversion tracking is a statistics service provided by Facebook, Inc. that connects data from the Facebook advertising network with actions performed on company.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy.
Google Ads Conversion Tracking (Google Inc.)
Google Ads conversion tracking is a statistics service provided by Google Inc. that connects data from the Google Ads advertising network with actions performed on company.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy. Subject to the Privacy Shield.
Twitter Ads Conversion Tracking (Twitter, Inc.)
Twitter Ads conversion tracking is a statistics service provided by Twitter, Inc. that connects data from the Twitter advertising network with actions performed on company.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy. Subject to the Privacy Shield.
LinkedIn Conversion Tracking (LinkedIn Corporation)
LinkedIn conversion tracking is a statistics service provided by LinkedIn Corporation that connects data from the LinkedIn advertising network with actions performed on company.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy.
Content and Functionality Performance Testing (A/B Testing)
The services contained in this section allow the Data Controller to track and analyze the User’s response, in terms of traffic or behavior, in relation to changes in the structure, text, or any other component of company.
Google Website Optimizer (Google Inc.)
Google Website Optimizer is an A/B testing service provided by Google Inc. (“Google”).
Google may use the Personal Data to contextualize and personalize ads in its advertising network.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy. Subject to the Privacy Shield.
Data Transfer Outside the EU
The Data Controller may transfer Personal Data collected within the EU to third countries (i.e., all countries outside the EU) only in compliance with a specific legal basis. Therefore, such Data transfers are carried out according to one of the legal bases described below.
The User can request information from the Data Controller regarding the specific legal basis applicable to each individual service.
Transfer to Third Countries Based on Consent (company)
When this is the legal basis, the transfer of Personal Data from the EU to third countries occurs only when the User has expressly consented to such transfer after being informed of the risks due to the absence of an adequacy decision and the adequate safeguards adopted.
In such cases, the Data Controller informs the Users and collects their consent through company.
Personal Data collected: various types of Data.
Displaying Content from External Platforms
This type of service allows the display of content hosted on external platforms directly from the pages of company and to interact with them.
If such a service is installed, it may collect traffic data related to the pages where it is installed, even if Users do not use the service.
Google Fonts (Google Inc.)
Google Fonts is a font style display service managed by Google Inc. that allows company to integrate such content within its pages.
Personal Data collected: Usage Data and various types of Data as specified in the service’s privacy policy.
Place of processing: USA – Privacy Policy. Subject to the Privacy Shield.
YouTube Video Widget (Google Inc.)
YouTube is a video content display service managed by Google Inc. that allows company to integrate such content within its pages.
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy. Subject to the Privacy Shield.
Further Information on Personal Data
User Data Analysis and Predictions (“Profiling”)
The Data Controller may process Usage Data collected through company to create or update User profiles. This type of processing allows the Data Controller to evaluate choices, preferences, and User behavior for the purposes specified in the respective sections of this document.
User profiles may also be created using automated tools, such as algorithms, which may also be offered by third parties. For further information on profiling activities, the User can refer to the respective sections of this document.
The User has the right to object to such profiling activities at any time. To learn more about the User’s rights and how to exercise them, the User can refer to the section of this document relating to User rights.
Automated Decision-Making Processes
When a decision that may produce legal effects for the User or similarly significantly affect them is made solely through technological means without human intervention, an automated decision-making process occurs.
Within the purposes described in this document, company may use the User’s Personal Data to make decisions based entirely or partially on automated processes. company resorts to automated decision-making processes to the extent necessary to conclude or execute a contract between the User and the Data Controller or, if required by law, with the User’s prior consent.
Automated decisions depend on technological tools provided by the Data Controller or third parties and are generally based on algorithms that respond to predefined criteria. The logic behind automated decision-making processes aims to:
For further information on purposes, any third-party services, and the specific logic of automated decision-making processes adopted by company, the User can refer to the respective sections of this document.
Effects of Automated Decision-Making Processes and User Rights
Users subject to this type of processing may exercise specific rights aimed at preventing or limiting the potential effects of automated decision-making processes. In particular, Users have the right to:
User Rights
Users may exercise certain rights regarding their Data processed by the Data Controller.
In particular, the User has the right to:
Details on the Right to Object
When Personal Data is processed in the public interest, in the exercise of official authority vested in the Data Controller, or to pursue a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.
Users are reminded that, if their Data is processed for direct marketing purposes, they can object to the processing without providing any justification. To find out whether the Data Controller processes Data for direct marketing purposes, Users can refer to the respective sections of this document.
How to Exercise Rights
To exercise their rights, Users can send a request to the contact details of the Data Controller provided in this document. Requests are filed free of charge and processed by the Data Controller as soon as possible, in any case within one month.
Cookie Policy
company uses Cookies. To learn more and view the detailed information, the User can consult the Cookie Policy.
Further Information on Processing
Legal Defense
The User’s Personal Data may be used by the Data Controller in legal proceedings or in the preparatory stages of such proceedings to defend against misuse of company or related Services by the User.
The User declares that they are aware that the Data Controller may be required to disclose Data by public authorities.
Specific Information
Upon the User’s request, in addition to the information contained in this privacy policy, company may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.
System Logs and Maintenance
For operational and maintenance purposes, company and any third-party services used by it may collect system logs, i.e., files that record interactions and may contain Personal Data, such as the User’s IP address.
Information Not Contained in This Policy
Further information regarding the processing of Personal Data may be requested at any time from the Data Controller using the contact details provided.
Response to “Do Not Track” Requests
company does not support “Do Not Track” requests.
To find out whether any third-party services used support them, the User is invited to consult their respective privacy policies.
Changes to This Privacy Policy
The Data Controller reserves the right to make changes to this privacy policy at any time by informing Users on this page and, if possible, on company, as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details held by the Data Controller. Therefore, please consult this page regularly, referring to the date of the last modification indicated at the bottom.
If the changes affect processing whose legal basis is consent, the Data Controller will collect the User’s consent again, if necessary.
Definitions and Legal References
Personal Data (or Data)
Any information that, directly or indirectly, even in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.
Usage Data
Information collected automatically through company (including by third-party applications integrated into company), including: IP addresses or domain names of the computers used by the User connecting to company, URI (Uniform Resource Identifier) addresses, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server’s response (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various time details of the visit (e.g., the time spent on each page), and details about the path followed within the Application, with particular reference to the sequence of pages visited, parameters related to the operating system and the User’s IT environment.
User
The individual using company, who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural or legal person, public authority, agency, or other body that processes Personal Data on behalf of the Data Controller, as described in this privacy policy.
Data Controller (or Controller)
The natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of company. The Data Controller, unless otherwise specified, is the owner of company.
company (or this Application)
The hardware or software tool through which the Personal Data of Users is collected and processed.
Service
The service provided by company as defined in the relevant terms (if any) on this website/application.
European Union (or EU)
Unless otherwise specified, all references to the European Union in this document include all current member states of the European Union and the European Economic Area.
Cookie
A small piece of data stored within the User’s device.
Legal References
This privacy policy is drafted based on multiple legislative systems, including Articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy policy applies exclusively to company.
Last Updated: October 2024
Data Controller
EcoPivoDuo Ltd
VAT: GB123456789
10 Maple Grove, London, SE10 8XL, United Kingdom
Email Address of the Data Controller: [email protected]