PRIVACY POLICY

Privacy Policy

Types of Data Collected

Among the Personal Data collected by company, either independently or through third parties, are: Cookies, Usage Data, email, and various types of Data.

Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific informational texts displayed prior to the collection of the data.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of company.
Unless specified otherwise, all Data requested by company is mandatory. If the User refuses to provide it, it may be impossible for company to provide the Service. In cases where company indicates certain Data as optional, Users are free to refrain from providing such Data without any consequences for the availability or functionality of the Service.
Users who have doubts about which Data is mandatory are encouraged to contact the Data Controller.
The use of Cookies or other tracking tools by company or by third-party service providers used by company, unless otherwise specified, is intended to provide the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through company and guarantees that they have the right to communicate or disseminate it, releasing the Data Controller from any liability to third parties.

Methods and Place of Processing the Collected Data

Processing Methods

The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.
The processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the organization of company (administrative, commercial, marketing, legal, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) may have access to the Data, appointed, if necessary, as Data Processors by the Data Controller. The updated list of Data Processors can always be requested from the Data Controller.

Legal Basis of Processing

The Data Controller processes Personal Data relating to the User if one of the following conditions exists:

  • The User has given consent for one or more specific purposes;
  • Processing is necessary for the performance of a contract with the User and/or for the execution of pre-contractual measures;
  • Processing is necessary to comply with a legal obligation to which the Data Controller is subject;
  • Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
  • Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.

It is always possible to request the Data Controller to clarify the specific legal basis of each processing and, in particular, to specify whether the processing is based on law, required by a contract, or necessary to conclude a contract.

Place

The Data is processed at the Data Controller’s operating offices and in any other place where the parties involved in the processing are located. For further information, contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one where the User is located. To obtain further information on the place of processing, the User can refer to the section detailing the processing of Personal Data.

The User has the right to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organization governed by public international law or established by two or more countries, such as the UN, as well as about the security measures taken by the Data Controller to protect the Data.

The User can verify whether one of the transfers described above takes place by examining the section of this document relating to the details on the processing of Personal Data or request information from the Data Controller by contacting them at the details provided at the beginning.

Retention Period

Data is processed and stored for the time required by the purposes for which it was collected.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the contract is fully performed.
  • Personal Data collected for purposes related to the legitimate interests of the Data Controller will be retained until the satisfaction of those interests. The User can obtain further information about the legitimate interests pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.

When processing is based on the User’s consent, the Data Controller may retain the Personal Data for longer until such consent is revoked. Additionally, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period, the Personal Data will be deleted. Therefore, the rights of access, deletion, rectification, and data portability cannot be exercised after the expiration of this period.

Purposes of Processing the Collected Data

The User’s Data is collected to allow the Data Controller to provide its Services, as well as for the following purposes: Statistics, Advertising, Contacting the User, Interaction with external social networks and platforms, Managing contacts and sending messages, Remarketing and behavioral targeting, Heat mapping and session recording, Hosting and backend infrastructure, Content and functionality performance testing (A/B testing), Data transfer outside the EU, and Displaying content from external platforms.

For further detailed information on the purposes of processing and the Personal Data relevant to each purpose, the User can refer to the relevant sections of this document.

Details on the Processing of Personal Data

Personal Data is collected for the following purposes and using the following services:

Contacting the User

Mailing List or Newsletter (company)

By registering for the mailing list or newsletter, the User’s email address is automatically added to a list of contacts to which email messages containing information, including commercial and promotional content, related to company may be sent. The User’s email address may also be added to this list as a result of registering on company or after making a purchase.

Personal Data collected: email.

Managing Contacts and Sending Messages

This type of service allows the management of a database of email contacts, phone contacts, or any other type of contact used to communicate with the User.
These services may also collect data related to the date and time the messages are viewed by the User, as well as the User’s interaction with them, such as information on clicks on links inserted in the messages.

Heat Mapping and Session Recording

Heat mapping services are used to identify which areas of a page are subject to cursor movement or mouse clicks to detect which areas attract the most interest. These services allow monitoring and analyzing traffic data and are used to track User behavior.
Some of these services may record sessions and make them available for later viewing.

Hotjar Heat Maps & Recordings (Hotjar Ltd.)

Hotjar is a heat mapping and session recording service provided by Hotjar Ltd.
Hotjar respects generic “Do Not Track” headers. This means the browser can instruct the script not to collect any User data. This is a setting available in all major browsers. Further information on opting out of Hotjar is available here.

Personal Data collected: Cookies, Usage Data, and various types of Data as specified in the service’s privacy policy.

Place of processing: Malta – Privacy Policy – Opt Out.

Hosting and Backend Infrastructure

This type of service has the function of hosting Data and files that allow company to function, enable its distribution, and provide a ready-to-use infrastructure to deliver specific functionalities of company.
Some of these services operate through servers geographically located in different places, making it difficult to determine the exact location where Personal Data is stored.

DigitalOcean

DigitalOcean is a hosting and backend service provided by DigitalOcean LLC.

Personal Data collected: various types of Data as specified in the service’s privacy policy.

Place of processing: USA – Privacy Policy. Subject to the Privacy Shield.

Interaction with External Social Networks and Platforms

This type of service allows interaction with social networks or other external platforms directly from the pages of company.
The interactions and information acquired by company are always subject to the User’s privacy settings for each social network.
If a social network interaction service is installed, it may collect traffic data related to the pages where it is installed, even if Users do not use the service.

Facebook Like Button and Social Widgets (Facebook, Inc.)

The Facebook “Like” button and social widgets are services for interaction with the Facebook social network, provided by Facebook, Inc.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy.

Twitter Tweet Button and Social Widgets (Twitter, Inc.)

The Twitter Tweet button and social widgets are services for interaction with the Twitter social network, provided by Twitter Inc.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy.

Google+ +1 Button and Social Widgets (Google Inc.)

The Google+ +1 button and social widgets are services for interaction with the Google+ social network, provided by Google Inc.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy.

LinkedIn Button and Social Widgets (LinkedIn Corporation)

The LinkedIn button and social widgets are services for interaction with the LinkedIn social network, provided by LinkedIn Corporation.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy.

Advertising

This type of service allows the use of User Data for commercial communication purposes in various advertising forms, such as banners, also in relation to the User’s interests.
This does not mean that all Personal Data is used for this purpose. Data and conditions of use are indicated below.
Some of the services listed below may use Cookies to identify the User or use behavioral retargeting techniques, i.e., displaying personalized ads based on the User’s interests and behavior, detected even outside company. For more information, we suggest checking the privacy policies of the respective services.

Google AdSense (Google Inc.)

Google AdSense is an advertising service provided by Google Inc. This service uses the “DoubleClick” Cookie, which tracks the use of company and the User’s behavior in relation to advertisements, products, and services offered.
The User can decide at any time not to use the DoubleClick Cookie by deactivating it: google.com/settings/ads/onweb/optout.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy – Opt Out.

Direct Email Marketing (DEM) (company)

company uses User Data to send commercial proposals related to services and products provided by third parties or unrelated to the product or service provided by company.

Personal Data collected: email.

Remarketing and Behavioral Targeting

This type of service allows company and its partners to communicate, optimize, and serve ads based on the User’s past use of company.
This activity is carried out by tracking Usage Data and using Cookies, information that is transferred to the partners to which the remarketing and behavioral targeting activity is linked.
In addition to the opt-out options offered by the services listed below, the User can opt out of receiving cookies related to a third-party service by visiting the Network Advertising Initiative opt-out page.

AdWords Remarketing (Google Inc.)

AdWords Remarketing is a remarketing and behavioral targeting service provided by Google Inc. that connects the activity of company with the Adwords advertising network and the DoubleClick Cookie.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy – Opt Out.

Facebook Remarketing (Facebook, Inc.)

Facebook Remarketing is a remarketing and behavioral targeting service provided by Facebook, Inc. that connects the activity of company with the Facebook advertising network.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy – Opt Out.

Facebook Custom Audience (Facebook, Inc.)

Facebook Custom Audience is a remarketing and behavioral targeting service provided by Facebook, Inc. that connects the activity of company with the Facebook advertising network.

Personal Data collected: Cookies and email.

Place of processing: USA – Privacy Policy – Opt Out.

Google Ad Manager Audience Extension (Google Inc.)

Google Ad Manager Audience Extension is a remarketing and behavioral targeting service provided by Google LLC that tracks visitors to company and allows selected advertising partners to display personalized ads to them on the web.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy – Opt Out. Subject to the Privacy Shield.

Twitter Remarketing (Twitter, Inc.)

Twitter Remarketing is a remarketing and behavioral targeting service provided by Twitter, Inc. that connects the activity of company with the Twitter advertising network.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy – Opt Out. Subject to the Privacy Shield.

LinkedIn Website Retargeting (LinkedIn Corporation)

LinkedIn Website Retargeting is a remarketing and behavioral targeting service provided by LinkedIn Corporation that connects the activity of company with the LinkedIn advertising network.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy – Opt Out.

Statistics

The services contained in this section allow the Data Controller to monitor and analyze traffic data and are used to track User behavior.

Google Analytics (Google Inc.)

Google Analytics is a web analytics service provided by Google Inc. (“Google”). Google uses the Personal Data collected to track and examine the use of company, compile reports, and share them with other Google services.
Google may use the Personal Data to contextualize and personalize ads in its advertising network.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy – Opt Out.

Facebook Ads Conversion Tracking (Facebook, Inc.)

Facebook Ads conversion tracking is a statistics service provided by Facebook, Inc. that connects data from the Facebook advertising network with actions performed on company.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy.

Google Ads Conversion Tracking (Google Inc.)

Google Ads conversion tracking is a statistics service provided by Google Inc. that connects data from the Google Ads advertising network with actions performed on company.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy. Subject to the Privacy Shield.

Twitter Ads Conversion Tracking (Twitter, Inc.)

Twitter Ads conversion tracking is a statistics service provided by Twitter, Inc. that connects data from the Twitter advertising network with actions performed on company.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy. Subject to the Privacy Shield.

LinkedIn Conversion Tracking (LinkedIn Corporation)

LinkedIn conversion tracking is a statistics service provided by LinkedIn Corporation that connects data from the LinkedIn advertising network with actions performed on company.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy.

Content and Functionality Performance Testing (A/B Testing)

The services contained in this section allow the Data Controller to track and analyze the User’s response, in terms of traffic or behavior, in relation to changes in the structure, text, or any other component of company.

Google Website Optimizer (Google Inc.)

Google Website Optimizer is an A/B testing service provided by Google Inc. (“Google”).
Google may use the Personal Data to contextualize and personalize ads in its advertising network.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy. Subject to the Privacy Shield.

Data Transfer Outside the EU

The Data Controller may transfer Personal Data collected within the EU to third countries (i.e., all countries outside the EU) only in compliance with a specific legal basis. Therefore, such Data transfers are carried out according to one of the legal bases described below.

The User can request information from the Data Controller regarding the specific legal basis applicable to each individual service.

Transfer to Third Countries Based on Consent (company)

When this is the legal basis, the transfer of Personal Data from the EU to third countries occurs only when the User has expressly consented to such transfer after being informed of the risks due to the absence of an adequacy decision and the adequate safeguards adopted.
In such cases, the Data Controller informs the Users and collects their consent through company.

Personal Data collected: various types of Data.

Displaying Content from External Platforms

This type of service allows the display of content hosted on external platforms directly from the pages of company and to interact with them.
If such a service is installed, it may collect traffic data related to the pages where it is installed, even if Users do not use the service.

Google Fonts (Google Inc.)

Google Fonts is a font style display service managed by Google Inc. that allows company to integrate such content within its pages.

Personal Data collected: Usage Data and various types of Data as specified in the service’s privacy policy.

Place of processing: USA – Privacy Policy. Subject to the Privacy Shield.

YouTube Video Widget (Google Inc.)

YouTube is a video content display service managed by Google Inc. that allows company to integrate such content within its pages.

Personal Data collected: Cookies and Usage Data.

Place of processing: USA – Privacy Policy. Subject to the Privacy Shield.

Further Information on Personal Data

User Data Analysis and Predictions (“Profiling”)

The Data Controller may process Usage Data collected through company to create or update User profiles. This type of processing allows the Data Controller to evaluate choices, preferences, and User behavior for the purposes specified in the respective sections of this document.
User profiles may also be created using automated tools, such as algorithms, which may also be offered by third parties. For further information on profiling activities, the User can refer to the respective sections of this document.
The User has the right to object to such profiling activities at any time. To learn more about the User’s rights and how to exercise them, the User can refer to the section of this document relating to User rights.

Automated Decision-Making Processes

When a decision that may produce legal effects for the User or similarly significantly affect them is made solely through technological means without human intervention, an automated decision-making process occurs.
Within the purposes described in this document, company may use the User’s Personal Data to make decisions based entirely or partially on automated processes. company resorts to automated decision-making processes to the extent necessary to conclude or execute a contract between the User and the Data Controller or, if required by law, with the User’s prior consent.
Automated decisions depend on technological tools provided by the Data Controller or third parties and are generally based on algorithms that respond to predefined criteria. The logic behind automated decision-making processes aims to:

  • Allow or improve decision-making;
  • Ensure fair and impartial treatment of Users;
  • Reduce potential harm resulting from human error, personal bias, or other similar circumstances that could lead to discrimination or imbalances in the treatment of individuals;
  • Reduce the risk of non-compliance with contractual obligations by the User.

For further information on purposes, any third-party services, and the specific logic of automated decision-making processes adopted by company, the User can refer to the respective sections of this document.

Effects of Automated Decision-Making Processes and User Rights

Users subject to this type of processing may exercise specific rights aimed at preventing or limiting the potential effects of automated decision-making processes. In particular, Users have the right to:

  • Receive an explanation regarding each decision made as a result of an automated decision-making process and express an opinion on it;
  • Contest the decision by asking the Data Controller to reconsider it or make a new decision on different grounds;
  • Request and obtain human intervention in the processing from the Data Controller. For further information on User rights and their exercise, the User can refer to the section of this document relating to User rights.

User Rights

Users may exercise certain rights regarding their Data processed by the Data Controller.

In particular, the User has the right to:

  • Withdraw consent at any time. The User can withdraw consent to the processing of their Personal Data previously given.
  • Object to the processing of their Data. The User can object to the processing of their Data when it is based on a legal basis other than consent. Further details on the right to object are provided in the section below.
  • Access their Data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing, and to receive a copy of the processed Data.
  • Verify and request rectification. The User can verify the accuracy of their Data and request its update or correction.
  • Obtain the restriction of processing. When certain conditions are met, the User can request the restriction of the processing of their Data. In this case, the Data Controller will not process the Data for any other purpose than its storage.
  • Obtain the erasure or removal of their Personal Data. When certain conditions are met, the User can request the erasure of their Data by the Data Controller.
  • Receive their Data or have it transferred to another Data Controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transferred to another Data Controller without hindrance. This provision is applicable when the Data is processed by automated means and the processing is based on the User’s consent, on a contract to which the User is a party, or on contractual measures related to it.
  • Lodge a complaint. The User can lodge a complaint with the competent data protection supervisory authority or take legal action.

Details on the Right to Object

When Personal Data is processed in the public interest, in the exercise of official authority vested in the Data Controller, or to pursue a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.

Users are reminded that, if their Data is processed for direct marketing purposes, they can object to the processing without providing any justification. To find out whether the Data Controller processes Data for direct marketing purposes, Users can refer to the respective sections of this document.

How to Exercise Rights

To exercise their rights, Users can send a request to the contact details of the Data Controller provided in this document. Requests are filed free of charge and processed by the Data Controller as soon as possible, in any case within one month.

Cookie Policy

company uses Cookies. To learn more and view the detailed information, the User can consult the Cookie Policy.

Further Information on Processing

Legal Defense

The User’s Personal Data may be used by the Data Controller in legal proceedings or in the preparatory stages of such proceedings to defend against misuse of company or related Services by the User.
The User declares that they are aware that the Data Controller may be required to disclose Data by public authorities.

Specific Information

Upon the User’s request, in addition to the information contained in this privacy policy, company may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

System Logs and Maintenance

For operational and maintenance purposes, company and any third-party services used by it may collect system logs, i.e., files that record interactions and may contain Personal Data, such as the User’s IP address.

Information Not Contained in This Policy

Further information regarding the processing of Personal Data may be requested at any time from the Data Controller using the contact details provided.

Response to “Do Not Track” Requests

company does not support “Do Not Track” requests.
To find out whether any third-party services used support them, the User is invited to consult their respective privacy policies.

Changes to This Privacy Policy

The Data Controller reserves the right to make changes to this privacy policy at any time by informing Users on this page and, if possible, on company, as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details held by the Data Controller. Therefore, please consult this page regularly, referring to the date of the last modification indicated at the bottom.

If the changes affect processing whose legal basis is consent, the Data Controller will collect the User’s consent again, if necessary.

Definitions and Legal References

Personal Data (or Data)

Any information that, directly or indirectly, even in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.

Usage Data

Information collected automatically through company (including by third-party applications integrated into company), including: IP addresses or domain names of the computers used by the User connecting to company, URI (Uniform Resource Identifier) addresses, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server’s response (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various time details of the visit (e.g., the time spent on each page), and details about the path followed within the Application, with particular reference to the sequence of pages visited, parameters related to the operating system and the User’s IT environment.

User

The individual using company, who, unless otherwise specified, coincides with the Data Subject.

Data Subject

The natural person to whom the Personal Data refers.

Data Processor (or Processor)

The natural or legal person, public authority, agency, or other body that processes Personal Data on behalf of the Data Controller, as described in this privacy policy.

Data Controller (or Controller)

The natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of company. The Data Controller, unless otherwise specified, is the owner of company.

company (or this Application)

The hardware or software tool through which the Personal Data of Users is collected and processed.

Service

The service provided by company as defined in the relevant terms (if any) on this website/application.

European Union (or EU)

Unless otherwise specified, all references to the European Union in this document include all current member states of the European Union and the European Economic Area.

Cookie

A small piece of data stored within the User’s device.

Legal References

This privacy policy is drafted based on multiple legislative systems, including Articles 13 and 14 of Regulation (EU) 2016/679.

Unless otherwise specified, this privacy policy applies exclusively to company.

Last Updated: October 2024

 

Data Controller

EcoPivoDuo Ltd
VAT: GB123456789
10 Maple Grove, London, SE10 8XL, United Kingdom

Email Address of the Data Controller: [email protected]