Privacy & Cookie Policy
This Website and all the Apps developed by Sidora, hereinafter referred to as the “Application”, collects Personal Data from its Users.
This document can be printed by running the print command found in the settings of every browser.
The Data Controller
Sidora Srl
Via Giacomo Boni, 15
00162 Roma – Italy
VAT: IT13368101005
Tel. +39 06 87726190
The Data Controller email address: info@sidora.it
Types of Data collected
Among the Personal Data collected by this Application, either autonomously or through third parties, are: name; email address; telephone number; Cookies; usage data.
Full details regarding each type of information gathered are provided in the dedicated sections of this privacy policy or by means of specific informative texts shown before the actual data collection.
The Personal Data can be freely given by the User or, in case of Usage Data, can be automatically collected while using the Application.
If not otherwise specified, each Data required by the Application is mandatory. If the User refuses to share the Data, it might be impossible for the Application to provide the Service. If the Application indicates certain Data as optional, the User is free to refrain from communicating such Data, without it having any consequence on the Service availability and efficiency.
Users who may have doubts regarding which Data is mandatory, can contact the Data Controller.
The potential use of Cookies – or other tracking tools – by this Application or by the owners of third-party services used by this Application, unless otherwise specified, has the purpose to provide the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.
The User takes responsibility over any third-party Personal Data obtained, published or shared through this Application and guarantees to have the right to communicate and share them, releasing the Data Controller from any responsibility towards third parties.
Methods and place of processing collected Data
Methods of Data processing
The Data Controller takes the appropriate security measures intended to prevent the non-authorized access, divulgation, modification or destruction of Personal Data.
The data processing is carried out by computer and/or telematic instruments, through organizational methods and logics closely connected to the stated purposes. In addition to the Data Controller, in certain circumstances, other parties involved in the organization of this Application (like administration, sales, marketing, legal staff and system administrators) or external subjects (like technical service providers, postal couriers, hosting providers, IT companies, advertising agencies) may have access and even be nominated, when necessary, Data Processor from the Data Controller. The updated list of Data Processors can always be requested to the Data Controller.
Legal basis of Data processing
If one of the following conditions exists, the Data Controller is enabled to process Personal Data relating the User:
- The User has given consent to one or more specific purposes; Note: in some jurisdictions the Data Controller may be allowed to process Personal Data without it being necessary to have consent from the User or another of the legal bases specified below, until the User objects (“opts out”) of such processing. However, all this might not be applied if the Personal Data processing is governed by the European legislation in terms of Personal Data protection;
- The processing is necessary to the fulfillment of a contract with the User and/or to the execution of the pre-contractual measures;
- The processing is necessary to satisfy a legal obligation to which the Data Controller is subject;
- The processing is necessary to the execution of a task of public interest or to the exercise of public authority of which the Data Controller is invested;
- The processing is necessary to the pursuit of the legitimate interest for the Data Controller or third parties.
However, it is always possible to ask the Data Controller to clarify the specific legal basis that applies to each processing and in particular to specify whether the processing is based on the law, required by a contract or necessary to seal a contract.
Place of Data Processing
The data are processed at the operational headquarters of the Data Controller and in every other place where the parties involved in the processing might be located. For further information, you may contact the Data Controller.
The Personal Data of the User might be transferred to a country different from where the User is located. In order to get additional information on the place of processing, please refer to the section “Information on Personal Data processing”.
The User is entitled to obtain information on the legal basis of transferring Data outside the European Union or to an international organization under public international law, or formed by two or more countries, such as the UN, as well as on the security measures taken by the Data Controller to protect the Data.
The User can check whether one of the transfers described before takes place by examining the section on this document relating to the details of Personal Data processing or by contacting the Data Controller at the contacts listed at the beginning of this document.
Retention Period
Data are processed and stored for the time required by the purposes for which they were collected.
Therefore:
- Every Personal Data collected for purposes connected to the execution of a contract between the Data Controller and the User, will be retained until the contract is completely fulfilled.
- Every Personal Data collected for purposes connected to the Data Controller legitimate interest, will be retained until such interest is fulfilled. The User may obtain further information regarding the legitimate interest of the Data Controller in the related sections of this document or by contacting the Data Controller.
When the processing is based on the User’s consent, the Data Controller may retain the Personal Data longer, until such consent isn’t revoked. Furthermore, the Data Controller may have the obligation to retain Personal Data longer in compliance with a legal obligation or authority order.
At the end of the retention period, the Personal Data will be deleted. Therefore, when such period expires, the right of access, cancellation, rectification and the right of data portability can no longer be exercised.
Purposes of Processing collected Data
The User’s Data are collected in order to allow the Data Controller to provide the Service, comply with legal obligations, answer to requests or executive actions, safeguard its rights and interests (or those of the Users and third parties), detect any possible malicious or fraudulent activity, as well as for the following purposes: contacting the User, displaying contents from external platforms, and for statistics purposes.
In order to obtain detailed information regarding the purposes of Processing and the Personal Data processed, please refer to the section “Information on Personal Data processing”.
Information on Personal Data processing
Personal Data are collected for the following purposes and by using the following services:
User rights
Users may exercise certain rights in relation to the Data processed by the Data Controller.
In particular, the User has the right to:
- Withdraw consent at any time. The User may revoke the consent to the processing of his or her Personal Data previously given.
- Oppose to the processing of their Data. The User may object to the processing of his or her Data when it is done on a legal basis other than consent. Further details on the right to object are set out in the section below.
- Access their Data. The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing and to receive a copy of the Data processed.
- Verify and request rectification. The User may verify the correctness of his/her Data and request that it be updated and corrected.
- Obtain limitation of processing. When certain conditions are met, the User may request the limitation of its Data processing. In this case, the Data Controller will not process the Data for any purpose other than their storage.
- Obtain the deletion or removal of their Personal Data. When certain conditions are met, the User may request the deletion of their Data by the Data Controller.
- Receive their Data or have them transferred to another owner. The User has the right to receive his or her Data in a structured, commonly used and machine-readable format and, where technically possible, to have it transferred without hindrance to another Controller. This provision is applicable when the Data are processed by automated means and the processing is based on the User’s consent, on a contract to which the User is a party or on contractual measures related thereto.
- Submit a complaint. The User may lodge a complaint to the Data protection competent authorities or take legal action.
Details on the right to object
When Personal Data are processed in the public interest, in the exercise of public powers vested in the Controller or in pursuit of legitimate interest of the Controller, Users have the right to object to the processing on grounds relating to their particular situation.
Users are reminded that if their Data are processed for direct marketing purposes, they may object to the processing without giving any reasons. To find out whether the Controller processes data for direct marketing purposes, Users may refer to the respective sections of this document.
How to exercise your rights
In order to exercise their rights, Users may address a request to the Controller, by using the contact details indicated in this document. Requests are filed free of charge and processed by the Controller as soon as possible, in any event within a month.
Further information on Data processing
Legal defense
The User’s Personal Data may be used by the Data Controller in legal proceedings or in the preparatory stages to their possible establishment, in order to defend against any abuse in the usage of this Application, or related Services, by the User.
The User declares that he/she is aware that the Data Controller may be obliged to disclose the Data by order of public authorities.
Specific Information
By request of the User, in addition to the information contained in this Privacy Policy, this Application may provide the User with additional and contextual information on specific Services or on the collection and processing of Personal Data.
System logs and maintenance
For operational and maintenance purposes, this Application and any third-party services used by it may collect system logs, i.e.: files recording interactions and which may also contain Personal Data, such as the User’s IP address.
Information not contained in this Policy
Further information in relation to the processing of Personal Data may be requested at any time to the Data Controller using the contact details.
Response to “Do Not Track” requests
This Application does not support “Do Not Track” requests.
To find out whether any third-party services used support that kind of requests, the User is invited to consult their respective privacy policies.
Changes to this Privacy Policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Application as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details in its possession. Therefore, please consult this page frequently, referring to the date of last modification indicated at the bottom.
If the changes affect the aspect of consent to processing, the Data Controller will collect the User’s consent again, if necessary.