Privacy and Cookie Policy

Privacy and Cookie Policy

To comply with the obligations imposed by the applicable regulation (EU Regulation on Personal Data Protection No. 679/2016, GDPR) and subsequent amendments, this website respects and protects the privacy of its visitors and users, taking all possible reasonable measures to ensure that the rights of the users are not violated.

This privacy policy exclusively applies to online activities on this site and applies to visitors/users of the site. It does not apply to information gathered through other channels on this website. The objective of the privacy policy is to provide maximum transparency with regard to the information that the website collects and uses.

Legal Basis of Processing

This website processes data based on consent. By using and consulting this website, visitors and users explicitly consent to this Privacy Policy and the processing of their personal data in relation to the methods and purposes described hereinafter, including the possible diffusion to third parties, if necessary to provide the service.

The provision of data and the Consent to collect and process data is optional. Users can refuse to provide consent and can revoke consent provided previously at any time (via the link Contacts in the page footer). However, refusing consent may make it impossible to provide certain services and affect the browsing experience on the website.

Data Collected and Purposes

Like all websites, this website saves information collected automatically during users’ visits in log files. The information collected may include the following:

  • Internet Protocol (IP) address;

  • Type of browser and parameters of the device used to connect to the website;

  • Name of the internet service provider (ISP);

  • Date and time of the visit;

  • Entry (referral) and exit web page;

  • The number of clicks performed on the website.

The information above is processed in an automated manner and collected in an aggregate format to verify that the website works as expected, as well as for security purposes.

For security purposes (anti-spam filters, firewall, virus detection), the data automatically registered can also include personal data such as the IP address, which can be used, in compliance with legislation in force on the matter, for the purpose of blocking attempts to damage said site or cause damage to other users, or however harmful or illegal activities. These data are never used to identify or profile the user, but only for the purposes of the site and its users.

Where the website allows users to post comments or offers services requested specifically by users, the website automatically collects and saves some of the users’ identification data, including their email addresses. This data is deemed voluntarily submitted by users at the time the service is provided. By inserting a comment or other information, the user expressly accepts the privacy information and, in particular gives consent for the contents entered to be freely diffused, including to third parties.

The data received will exclusively be used to supply the service requested and for the sole time necessary for service supply.

The information that users make public via the services and tools available to them on the website are provided by users consciously and voluntarily. This website shall not be liable for any breaches or violations in connection with such information. Users are responsible for making sure they have the authorisation to publish personal data belonging to third parties or content protected by national and international laws.

The data gathered from the site while in use are used exclusively for the purposes indicated and kept for the strict time necessary to perform the stated activities. In any case, the data detected by the site will never be supplied to third parties, for any reason, unless following a legitimate request by the judicial authorities and only for cases outlined by law.
Data used for security purposes (to block attempts to cause damage to the website) are saved for only seven days.

Place of Processing

Data collected by the website are processed on the premises of the Data Controller:

CONFALONIERI MATITE Srl
Single-member Company
Via Castelfidardo, 11 – 20121 MILAN
comatite@confaloniericosmetica.com

Cookies

Like all websites, this website uses cookies, small text file that allow to save information about visitors’ preferences, to improve the functionality of the website and make browsing easier by automating procedures (e.g. login, language of the website) and to analyse how the website is used.

Session cookies are essential to recognise logged-in users and are useful to avoid providing the requested functionality to the wrong user, as well as for security reasons, to prevent cyberattacks on the website. Session cookies do not contain personal data and are saved for the duration of the session, i. e. until the browser is closed. No consent is required for their use.

Functionality cookies are strictly necessary to use the website and are connected to expressed requests for functionalities made by the user (such as logging in), for which no consent is required.

By using the website, users expressly consent to the use of cookies.

Disabling Cookies

Cookies are connected to the browser used and CAN BE DISABLED DIRECTLY FROM THE BROWSER, i.e. refusing or revoking consent to the use of cookies. Users should note that disabling cookies may prevent some of the features of the website from working properly.
The instructions on how to disable cookies can be found on the following web pages:

Mozilla FirefoxMicrosoft Internet ExplorerMicrosoft EdgeGoogle ChromeOperaApple Safari

Third-party Cookies

This website is also an intermediary for third-party cookies used to provide additional services and features to visitors and to improve the use of the site, such as social media buttons, or videos. This website has no control on third-party cookies, which are entirely managed by third parties. As a consequence, information on the use and purposes of third-party cookies and on how to disable them are provided directly by the relevant third parties on the pages indicated below.

In particular, this website uses cookies from the following third parties:

Social Network Plugins
This website also implements social network plug-ins and/or buttons, to allow users to share content on their preferred social media. These plug-ins are programmed in order not to store any cookies and protect users’ privacy. If required by the social network settings, cookies are stored only when the user voluntarily and effectively uses the plug-ins. If the user browses while logged into the social network, then they will have already accepted the use of cookies used by this site at the time they registered on the social network.
The collection and use of any information obtained through the plug-ins is regulated by the privacy policy of each social network, to which the user should refer.

Transfer of Data to Non-EU Countries

This website may share some of the data collected with service providers based outside the European Union. In particular, with Google, Facebook and Microsoft (LinkedIn), through social media plug-ins and the Google Analytics service. Transfers are authorised based on specific decisions from the European Union and the Data Protection Authority, in particular decision 1250/2016 (Privacy ShieldItalian Data Protection Authority page), for which no consent is required. The above-mentioned companies all adhere to the Privacy Shield.

Security Measures

This website processes users’ data lawfully and fairly, adopting the necessary security measures aimed at preventing unauthorised access, diffusion, change or destruction of data. Data processing is carried out using electronic and/or telematic tools, with organisational and logical arrangement strictly correlated to the above indicated purposes. Other than the owner, in some cases, the data may be accessed by categories of workers involved in site organisation (administrative, sales, marketing and legal staff, system administrators) or external subjects (such as suppliers of third-party technical services, couriers, hosting providers, IT companies and communication agencies).

Data Subject Rights

Pursuant to Regulation EU 679/2016 (GDPR) and national regulations, the User can exercise the following rights according to the methods and within the limits set by the applicable regulations:

  • request confirmation of the existence of personal data pertaining to them (right to access);

  • be informed on the origin of the data;

  • receive the data in intelligible form;

  • be informed on the logic, methods and purposes of processing;

  • request the update, rectification, integration, erasure, and transformation into anonymous form, block any unlawful processing, including data no longer necessary for the purposes for which they were collected.

  • in the case of data processing based on consent, receive, at no other cost than a fee for the support service, their data provided to the Data Controller in a structured and commonly used format readable by automated devices;

  • right to lodge complaints to the Supervisory Authority (Data Protection Authority – link to the Data Protection Authority);

  • more in general, exercise all the rights recognised by the applicable laws and regulations.

Requests must be submitted to the Data Controller.

In the case of data processing based on legitimate interests the rights of the data subjects are guaranteed (except for the portability right, which is not regulated), in particular the right to object to data processing, which can be exercised by sending a request to the Data Controller.

Updates

This Privacy Policy was updated on 30 June 2021