Privacy Policy

Privacy Policy

Data Controller

SIRTEC S.r.l. , with registered office at via Gino Bozzini 5C – 37135 Verona VAT number 03786030233

Data Controller’s email address: info@sirtecgroup.it

Types of Data Collected

Among the Personal Data collected by this Application, either independently or through third parties, are: email address, Cookies, Usage Data, password, first name, last name and email address.

Full details on each type of Personal Data collected are provided in the dedicated sections of this Privacy Policy or through specific information notices displayed before the Data are collected.

Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Application.

Unless otherwise specified, all Data requested by this Application are mandatory. If the User refuses to provide them, it may be impossible for this Application to provide the Service. Where this Application indicates that certain Data are optional, Users are free not to provide such Data without this affecting the availability or operation of the Service.

Users who are uncertain about which Data are mandatory are encouraged to contact the Data Controller.

Any use of Cookies, or other tracking tools, by this Application or by the owners of third-party services used by this Application, unless otherwise specified, is intended to provide the Service requested by the User, in addition to any other purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for any Personal Data relating to third parties obtained, published or shared through this Application and confirms that they have the right to communicate or disclose such Data, releasing the Data Controller from any liability towards third parties.

Methods and Place of Processing the Collected Data

Methods of Processing

The Data Controller adopts appropriate security measures to prevent unauthorised access, disclosure, alteration or destruction of Personal Data.

Data processing is carried out using IT and/or telematic tools, following organisational procedures and methods strictly related to the purposes indicated. In addition to the Data Controller, in certain cases, the Data may be accessible to persons involved in the organisation of this Application, such as administrative, sales, marketing and legal personnel and system administrators, or to external parties such as third-party technical service providers, postal couriers, hosting providers, IT companies and communication agencies. Such parties may also be appointed, where necessary, as Data Processors by the Data Controller.

An up-to-date list of Data Processors may be requested from the Data Controller at any time.

Legal Basis of Processing

The Data Controller processes Personal Data relating to the User where one of the following conditions applies:

The User has given consent for one or more specific purposes. Note: under certain legal systems, the Data Controller may be permitted to process Personal Data without the User’s consent or another of the legal bases specified below until the User objects to such processing by opting out. However, this does not apply where the processing of Personal Data is governed by European data protection legislation.

Processing is necessary for the performance of a contract with the User and/or for the implementation of pre-contractual measures.

Processing is necessary to comply with a legal obligation to which the Data Controller is subject.

Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller.

Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.

The User may always request that the Data Controller clarify the specific legal basis applicable to each processing activity and, in particular, whether the processing is based on legislation, required under a contract or necessary to enter into a contract.

Place

The Data are processed at the Data Controller’s operating offices and at any other location where the parties involved in the processing are located. For further information, contact the Data Controller.

The User’s Personal Data may be transferred to a country other than the country in which the User is located. To obtain further information regarding the place of processing, the User may refer to the section containing details on the processing of Personal Data.

The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organisation governed by public international law or established by two or more countries, such as the United Nations, as well as information regarding the security measures adopted by the Data Controller to protect the Data.

Where any of the transfers described above take place, the User may refer to the relevant sections of this document or request information from the Data Controller using the contact details provided at the beginning of this document.

Retention Period

The Data are processed and stored for as long as required for the purposes for which they were collected.

Therefore:

Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until that contract has been fully performed.

Personal Data collected for purposes related to the legitimate interests of the Data Controller will be retained until such interests have been fulfilled. The User may obtain further information regarding the legitimate interests pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.

Where processing is based on the User’s consent, the Data Controller may retain Personal Data for a longer period until such consent is withdrawn. Furthermore, the Data Controller may be required to retain Personal Data for a longer period in order to comply with a legal obligation or an order issued by an authority.

At the end of the retention period, the Personal Data will be deleted. Therefore, once this period has expired, the rights of access, erasure, rectification and data portability may no longer be exercised.

Purposes of Processing the Collected Data

The User’s Data are collected to allow the Data Controller to provide its Services, as well as for the following purposes: contacting the User, interaction with social networks and external platforms, registration and authentication, access to accounts on third-party services, payment management, infrastructure monitoring, interaction with live chat platforms, remarketing and behavioural targeting, contact management and sending email messages, analytics, displaying content from external platforms, commercial affiliation, interaction with support and feedback platforms, user database management, management of support and contact requests, and hosting and backend infrastructure.

To obtain more detailed information about the purposes of processing and the Personal Data specifically relevant to each purpose, the User may refer to the relevant sections of this document.

Facebook Permissions Requested by this Application

This Application may request certain Facebook permissions that allow it to perform actions through the User’s Facebook account and collect information from it, including Personal Data. This service allows this Application to connect with the User’s account on the Facebook social network, provided by Facebook Inc.

For further information regarding the following permissions, please refer to the Facebook permissions documentation and Facebook’s Privacy Policy.

The permissions requested are as follows:

Basic Information

The basic information of the User registered on Facebook, which normally includes the following Data: ID, name, profile image, gender and location language and, in certain cases, the User’s Facebook Friends. Where the User has made additional Data publicly available, such Data will also be accessible.

Email

Provides access to the User’s primary email address.

Page Management

Allows the Application to retrieve access tokens for the Pages and Applications administered by the User.

Insights

Provides access to Insights Data relating to pages, applications and domains owned by the User.

User Rights

Users may exercise certain rights regarding the Data processed by the Data Controller.

In particular, the User has the right to:

Withdraw Consent at Any Time

The User may withdraw any consent previously given for the processing of their Personal Data.

Object to the Processing of Their Data

The User may object to the processing of their Data where the processing is carried out on a legal basis other than consent. Further details regarding the right to object are provided in the section below.

Access Their Data

The User has the right to obtain information regarding the Data processed by the Data Controller, certain aspects of the processing and a copy of the Data being processed.

Verify and Request Rectification

The User may verify the accuracy of their Data and request that they be updated or corrected.

Obtain Restriction of Processing

Where certain conditions apply, the User may request the restriction of the processing of their Data. In such cases, the Data Controller will not process the Data for any purpose other than their storage.

Obtain the Erasure or Removal of Personal Data

Where certain conditions apply, the User may request that the Data Controller erase their Data.

Receive Their Data or Have Them Transferred to Another Data Controller

The User has the right to receive their Data in a structured, commonly used and machine-readable format and, where technically feasible, to have those Data transferred to another Data Controller without hindrance.

This provision applies where the Data are processed by automated means and the processing is based on the User’s consent, on a contract to which the User is a party or on contractual measures connected with it.

Lodge a Complaint

The User may lodge a complaint with the competent personal data protection supervisory authority or bring legal proceedings.

Details Regarding the Right to Object

Where Personal Data are processed in the public interest, in the exercise of official authority vested in the Data Controller or for the purposes of the legitimate interests pursued by the Data Controller, Users have the right to object to such processing on grounds relating to their particular situation.

Users are informed that, where their Data are processed for direct marketing purposes, they may object to the processing without providing any reason.

To determine whether the Data Controller processes Data for direct marketing purposes, Users may refer to the relevant sections of this document.

How to Exercise These Rights

To exercise their rights, Users may send a request using the Data Controller’s contact details provided in this document.

Requests are submitted free of charge and will be handled by the Data Controller as soon as possible and, in any event, within one month.

Further Information Regarding Processing

Legal Defence

The User’s Personal Data may be used by the Data Controller in legal proceedings or during the preparatory stages leading to possible legal action, in order to defend against misuse of this Application or the related Services by the User.

The User declares that they are aware that the Data Controller may be required to disclose the Data upon request by public authorities.

Specific Information Notices

At the User’s request, in addition to the information contained in this Privacy Policy, this Application may provide the User with additional and contextual information notices regarding specific Services or the collection and processing of Personal Data.

System Logs and Maintenance

For purposes related to operation and maintenance, this Application and any third-party services used by it may collect system logs, namely files that record interactions and may also contain Personal Data, such as the User’s IP address.

Information Not Contained in this Policy

Further information regarding the processing of Personal Data may be requested from the Data Controller at any time using the contact details provided.

Response to “Do Not Track” Requests

This Application does not support “Do Not Track” requests.

To determine whether any third-party services used by this Application support such requests, the User is encouraged to consult their respective Privacy Policies.

Changes to this Privacy Policy

The Data Controller reserves the right to make changes to this Privacy Policy at any time by informing Users through this page.

Users are therefore encouraged to consult this page regularly, referring to the date of the latest update indicated at the bottom.

Where the User does not accept the changes made to this Privacy Policy, the User must stop using this Application and may request that the Data Controller remove their Personal Data.

Unless otherwise specified, the previous Privacy Policy will continue to apply to the Personal Data collected up to that time.