PRIVACY POLICY
Welcome to the website of ViviCosìGroup!
ViviCosìGroup places the utmost importance on the confidentiality, protection and security of the personal data of the people with whom it comes into contact.
Please read our Privacy Policy carefully, as it applies when you access the website, browse it and use its services.
This document also serves as a privacy notice pursuant to EU Regulation 2016/679 (hereinafter the “Regulation” or “GDPR”) and the applicable national legislation on the processing of personal data, Legislative Decree 196/2003, as subsequently amended, for all those who interact with the web services of ViviCosìGroup.
This privacy notice is provided and is valid for this website and for the websites of ViviCosìGroup relating to services and brands connected to it, such as ViviCosì, Terra e Pane, Terra e Pane shop, InStead of, Mirvana, and does not apply to other websites that the user may access through links available on the websites. ViviCosìGroup non ha alcun controllo su questi siti né sulle procedure da essi applicate per il rispetto della riservatezza dei dati e, pertanto, ViviCosìGroup suggerisce di consultare le norme sulla riservatezza di tutti i soggetti con cui si entra in contatto prima di comunicare informazioni personali.
DATA CONTROLLER.
The Data Controller of the data collected through the websites listed above is INTERNATIONAL FOOD S.R.L. | Sede Legale: Via Pablo Neruda, 91 – 47043 - Gatteo (FC) | Sede Operativa: Via Campagnola, 8 – 47043 - Gatteo (FC), – ITALY | Tel. 0541/627276 | Email office@intfood.it | P.IVA: 04278510401 | Cap.soc. Euro 76.660,22 i.v. | REA FO-433978 |.
(hereinafter also referred to as “ViviCosìGroup”, “Company”, “Data Controller”).
TYPES OF DATA PROCESSED AND PURPOSES OF PROCESSING
Data voluntarily provided by the user
The user is asked to provide personal data (e.g. first name, last name, email address, etc.) only when they wish to contact us or use the services offered on the websites. In such cases, the user is provided with appropriate information and, where necessary, asked to provide consent. Any information that is strictly mandatory is marked with an asterisk (*). The data provided by the user will be processed in accordance with the purposes and methods set out in this privacy notice and in the specific notices provided from time to time.
CONTACTS, INFORMATION REQUESTS
Data provided directly by the data subject by completing and submitting contact/communication forms.
The explicit and voluntary sending of messages to the contact addresses or the completion of the forms in the dedicated section result in the collection of the sender’s contact details, as well as all personal data included in the communications.
These data are processed for the following purposes and on the basis of the relevant legal grounds for processing, and are retained for no longer than necessary for the purposes for which they were collected and processed.
MANDATORY OR OPTIONAL NATURE OF DATA PROVISION
The user is free to decide whether or not to provide their personal data through the website and/or the services connected to it. Failure to provide data, as indicated on a case-by-case basis in the notices provided to the user, may make it impossible to provide the requested service. Any information that is strictly mandatory is marked with an asterisk (*).
Any refusal to provide certain data marked as mandatory makes it impossible to achieve the main purpose of the specific collection: for example, such refusal may make it impossible for the Company to provide responses to the user or other services that may be available on the website. Providing additional data, other than those marked as essential, is optional and has no consequences for achieving the main purpose of the collection.
METHODS OF PROCESSING
Personal data will always be processed in accordance with the principles of fairness, lawfulness, transparency and confidentiality, using technical and organisational security measures to ensure an adequate level of protection. Forms are transmitted using the encrypted SSL/HTTPS protocol. The Data Controller does not carry out automated decision-making processes, including profiling, that produce legal effects or similarly significantly affect the data subject.
RECIPIENTS AND DATA TRANSFERS
Personal data will be processed by internal personnel who are authorised to process it for the purposes indicated above and who have undertaken to maintain confidentiality or are subject to an appropriate legal obligation of confidentiality. Personal data will also be processed by parties appointed as Data Processors pursuant to Art. 28 GDPR, as they process data on behalf of the Data Controller. Personal data may in fact be shared with third parties with whom the Data Controller has contractual relationships concerning services necessary for the performance of its activities (such as companies responsible for developing and managing websites, parties with whom it is necessary to interact to provide services such as hosting providers, consent-management providers, backup hosting providers, customer relationship management suppliers, parties responsible for technical maintenance including maintenance of network equipment and electronic communication networks, companies or professional firms providing employment, administrative, legal, tax, financial and debt-recovery assistance and consultancy in relation to the provision of the Services, etc.). The complete list of appointed external Data Processors is available from the Data Controller.
The data may be disclosed, even without consent, to all inspection bodies responsible for checks and audits, such as the Italian Revenue Agency, ministerial bodies and competent authorities, local authorities and Tax Courts of all levels, upon their express request. These entities will process the data as independent Data Controllers for institutional purposes and/or as required by law during investigations and inspections.
Except as indicated above, personal data are not intended for publication or dissemination.
The data will be processed by the Data Controller in Italy and within the European Union and the European Economic Area. If, for technical, organisational and/or operational reasons, it is necessary to use parties located outside the European Union or the European Economic Area, the Data Controller will ensure that such parties process the data in compliance with applicable legislation. Transfers will be carried out using appropriate safeguards, including: (i) adequacy decisions by the European Commission; (ii) the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023); (iii) Standard Contractual Clauses approved by the European Commission; or (iv) other safeguards deemed adequate pursuant to Arts. 44-49 GDPR. The data subject may request further information by contacting the Data Controller using the details provided at the beginning of this privacy notice.
DATA RETENTION
Personal data processed for contractual purposes, connected with and instrumental to the establishment and management of relationships with customers and/or suppliers, such as obtaining preliminary information for the possible conclusion of a contract, will be retained by the Data Controller for the time strictly necessary to provide the requested service and properly perform the contractual relationship with the user. In any case, since such personal data are processed to provide the Services and enable the performance of the contractual relationship, where necessary to establish, exercise or defend a legal claim, the Data Controller may retain the data for the time strictly necessary for that purpose, within the limitation periods provided by law (ordinarily ten years, or the shorter periods applicable to the specific case). Once those periods have expired, the data will be deleted or anonymised.
The user’s requests, and the data contained therein, will be retained only for the time necessary to enable the Data Controller to verify the proper closure of the request and in any event for as long as necessary to protect the Data Controller’s interests against potential liability. At the end of this period, data that allow a natural person to be identified, even indirectly (such as name and email address), will be anonymised and retained in aggregated form for statistical purposes.
Personal data processed for the purpose of fulfilling legal obligations established by the State, regulations and EU legislation (tax, accounting and administrative), will be retained by the Data Controller for the period required by specific legal obligations or applicable legislation (generally, 10 years for accounting and tax documents).
Unless otherwise specified, personal data will be processed for the entire period during which the data subject uses the Data Controller’s websites and the services provided through them. In the event of withdrawal of consent, the Data Controller will retain the personal data to demonstrate compliance with its obligations until the applicable limitation period has expired.
DATA SUBJECT RIGHTS
Arts. 15 et seq. of the GDPR grant data subjects specific rights.
In particular, the right to obtain confirmation as to whether personal data concerning them are being processed and access to such data (Art. 15), rectification and completion if inaccurate or incomplete (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). The data subject also has the right to object at any time, on grounds relating to their particular situation, to processing based on the legitimate interest of the Data Controller (Art. 21). Where processing is based on consent, the data subject may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3)). The exercise of these rights is not subject to any time limit and may be exercised free of charge by contacting the Data Controller using the details provided at the beginning of this privacy notice by ordinary mail and/or email and/or certified email (PEC).
Data subjects who believe that the processing of their personal data through the Data Controller’s websites violates the GDPR have the right to lodge a complaint with the supervisory authority (for Italy: the Italian Data Protection Authority www.garanteprivacy.it), as provided for by Art. 77 of the Regulation, or to bring appropriate judicial proceedings (Art. 79 of the Regulation).
CHANGES AND UPDATES TO THE PRIVACY POLICY
ViviCosìGroup reserves the right to modify or simply update the content of the website Policy, in whole or in part, including as a result of changes to applicable legislation. Such changes will be binding as soon as they are published on the website. The Data Controller therefore invites users to visit this section regularly to review the most recent and updated version of the Policy, so that they are always informed about the personal data collected and how they are used by the Data Controller.
In the event of any discrepancy between the versions, the Italian version shall prevail.