PRIVACY POLICY
Pursuant to Articles 13 and 14 of EU Regulation No. 2016/679 (hereinafter, "GDPR")
This Privacy Policy aims to describe the management of personal data collected by I. STAGNITTA CAFFÈ di Marilù Stagnitta & C. S.N.C. ("Company") through this website, in compliance with the applicable regulation. You can print or save this document using the functionality of your internet browser (=browser: usually "file" > "save as").
Collection of Personal Data
The personal data that may be collected are the following:
-
Personal data for registering on the site to open a customer account
-
Data on the customer account page related to the completion of orders and the purchasing methods chosen by the user
-
Email address for receiving newsletters
-
Personal data provided to receive specific assistance
-
Browsing data
-
Cookies, for details, refer to the Cookie Policy on the website
-
Statistical data, not attributable to the person, related to site views
-
Pseudonymized profiling data associated with personalized advertising for the user
Voluntariness of Providing Data
Except for what is specified for browsing data, the user is free to provide the personal data necessary for I. STAGNITTA CAFFÈ di Marilù Stagnitta & C. S.N.C. to use the e-commerce services offered by the Company, subject to consent to this policy. Failure to provide these data may result in the inability to obtain the requested services. Regarding cookies, for which details are given in the cookie policy, the user has the option to block them at any time.
For completeness, it should be noted that in some cases (not part of the regular management of this site), the Authority may request information and details for the purposes of monitoring personal data processing. In such cases, the response is mandatory under penalty of administrative sanction.
Purposes and Methods of Processing
The collected personal data ("Data") may be processed for the following purposes:
-
With the consent of the data subject, to fulfill a specific user request ("E-commerce Service");
-
With the consent of the data subject, to send newsletters with commercial and/or promotional information about the Company's products and services ("Marketing");
-
With the consent of the data subject, to allow the Company to carry out pseudonymized user profiling to improve the shopping experience, making it personalized.
The data may be processed through paper and/or electronic and automated methods, in particular, via regular mail or email, telephone (e.g., automated calls, SMS, MMS), fax, and any other electronic channel (e.g., websites, mobile apps).
Other Parties Who May Process Data
The data may be processed by parties operating on behalf of the Company and based on specific contractual obligations. The data may also be shared with third parties to fulfill legal obligations, comply with orders from public authorities, or for prior consent or to exercise the Company's rights in judicial proceedings.
Transfer of Data Outside the European Economic Area (EEA)
The Company currently does not transfer data outside the European Economic Area and does not provide them to international organizations.
Our company is hosted on the Wix.com platform. Wix.com provides us with the online platform that allows us to sell our products and services. Your data may be stored through Wix.com’s data storage, databases, and general applications. Your data is stored on secure servers, protected by firewalls.
All direct payment gateways offered by Wix.com and used by our company adhere to the PCI-DSS standards as managed by the PCI Security Standards Council, which is a joint commitment from brands like Visa, MasterCard, American Express, and Discover. PCI-DSS requirements help ensure secure management of credit card information by our store and its suppliers.
Links to Third-Party Websites
Third-party websites accessible from this site are under the responsibility of the respective third parties. The Company disclaims all responsibility for any requests and/or provision of personal data to third-party websites.
Data Controller
The data controller is I. STAGNITTA CAFFÈ di Marilù Stagnitta & C. S.N.C., located in Palermo, via A. Crescenzio 5/15, Registry of Enterprises of the Palermo Chamber of Commerce, Tax Code and VAT Number 05227850822. All updated references of the Company are listed at the bottom of each page on the Company’s website.
Data Retention
Our company is hosted on the Wix.com platform. Wix.com provides us with the online platform that enables us to sell our products and services. Your data may be stored through Wix.com’s data storage, databases, and general applications. Your data is stored on secure servers, protected by firewalls.
All direct payment gateways offered by Wix.com and used by our company adhere to PCI-DSS standards as managed by the PCI Security Standards Council, which is a joint commitment from brands like Visa, MasterCard, American Express, and Discover. PCI-DSS requirements help ensure the secure management of credit card information by our store and its suppliers.
-
Data processed to provide the Service will be stored by the Company for the period deemed strictly necessary to achieve such purposes, unless the Company needs to handle any disputes related to the provision of the Service, in which case, the data will be stored until the completion of such procedures.
-
Data related to the customer account are retained for ten years from the last use of the service by the user.
-
Data processed for Marketing purposes will be retained by the Company from the moment the data subject provides consent until such consent is revoked. If consent is revoked, such data may be retained for a longer period, as in the previous case, to handle potential disputes and/or litigation.
Rights of the Data Subject
The data subject is entitled to the following rights:
-
Right of access, i.e., the right to obtain confirmation from the Company whether or not personal data is being processed and, if so, access to the data;
-
Right to rectification and erasure, i.e., the right to obtain the correction of inaccurate data and/or the completion of incomplete data or the erasure of data for legitimate reasons;
-
Right to restriction of processing, i.e., the right to request the suspension of processing if legitimate reasons exist;
-
Right to data portability, i.e., the right to receive the data in a structured, commonly used, and readable format, as well as the right to transmit the data to another data controller, if applicable;
-
Right to object, i.e., the right to object to the processing of data if legitimate reasons exist, including processing of data for marketing and profiling purposes, if applicable;
-
Right to receive information regarding any data breaches affecting the individual.
Modifications
This Privacy Policy was last updated on 30/07/2020. The Company reserves the right to modify all or part of this Privacy Policy or simply update its content (for example, following changes to applicable law), after which it will publish any updates on this website.