www.simonabonacci.com

This Application collects some Personal Data from its Users.


Users may be subject to different levels of protection. Some Users therefore enjoy greater protection. Further information regarding the protection criteria can be found in the applicability section.

This document can be printed using the print command in the settings of any browser.

Policy Summary

Personal Data processed for the following purposes and using the following services:

    • Access to accounts on third-party services

      • Facebook account access

        Permissions: Access to activities; Access to friends lists; City; Events; Groups; Gender

    • Contact the User

      • Contact form

        Personal Data: ZIP code; city; Tax ID; last name; date of birth; email address; physical address; country; name; VAT number; profession; gender

    • Payment Management

      • PayPal

        Personal Data: billing address; device information; email address; last name; payment information; phone number; Usage Data

      • Google Pay

        Personal Data: surname

    • Tag Management

      • Google Tag Manager

        Personal Data: Usage Data

    • Interaction with social networks and external platforms

      • Facebook Like button and social widgets

        Personal Data: Usage Data; Tracking Tool

    • Registration and authentication

      • Instagram Authentication

        Personal Data: various types of Data as specified in the privacy policy of the service

    • Platform and hosting services

      • Shopify

        Personal Data: billing address; shipping address; email address; first name; last name; Usage Data; payment information; phone number

    • Statistics

      • Google Analytics, Google Analytics with anonymized IP and Google Ads conversion tracking

        Personal Data: Usage Data; Tracking Tool

    • Viewing content from external platforms

      • Instagram widget and Google Fonts

        Personal Data: Usage Data; Tracking Tool

Contact information

    • Data Controller

      SB Industries srls

      Owner's email address: info@simonabonacci.com

Full policy

Data Controller

SB Industries srls

Owner's email address: info@simonabonacci.com

Types of Data collected

Among the types of Personal Data collected by this Application, either independently or through third parties, there are: Tracker; Usage Data; first name; last name; gender; date of birth; VAT number; profession; physical address; country; email address; ZIP/Postal code; city; Tax ID; billing address; shipping address; phone number; payment information; device information.

Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed before the data is collected.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Application.
Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to provide such Data, it may be impossible for this Application to provide the Service. In cases where this Application indicates some Data as optional, Users are free to refrain from providing such Data, without this having any consequence on the availability or operation of the Service.
Users who have doubts about which data are mandatory are encouraged to contact the Owner.
Any use of Cookies - or other tracking tools - by this Application or by the owners of third-party services used by this Application, unless otherwise specified, is intended to provide the Service requested by the User, in addition to any other purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Application and guarantees that he or she has the right to communicate or disseminate them, freeing the Data Controller from any liability towards third parties.

Method and place of processing of the collected data

Treatment methods

The Data Controller takes appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.
Processing is carried out using computer and/or electronic means, following organizational methods and procedures strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the operation of this Application (administrative, sales, marketing, legal, and system administrators) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, and communications agencies) may have access to the Data, also appointed, if necessary, as Data Processors by the Data Controller. The updated list of Data Processors may be requested from the Data Controller at any time.

Legal basis for processing

The Data Controller processes Personal Data relating to the User if one of the following conditions applies:

  • the User has given consent for one or more specific purposes; Note: Under some jurisdictions, the Data Controller may be authorized to process Personal Data without the User's consent or any other of the legal bases specified below, until the User objects to such processing ("opt-out"). However, this does not apply if the processing of Personal Data is regulated by European data protection legislation;
  • processing is necessary for the performance of a contract with the User and/or for the implementation of pre-contractual measures;
  • processing is necessary for compliance with a legal obligation to which the Data Controller is subject;
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
  • processing is necessary for the pursuit of the legitimate interest of the Data Controller or third parties.

However, it is always possible to ask the Data Controller to clarify the specific legal basis for each processing operation and, in particular, to specify whether the processing is based on the law, provided for by a contract, or necessary to conclude a contract.

Place

The Data is processed at the Data Controller's operating offices and in any other locations where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User's Personal Data may be transferred to a country other than their own. For further information on the place of processing, the User can refer to the section containing details on the processing of Personal Data.

In case of higher protection, the User has the right to obtain information regarding the legal basis of the transfer of Data outside the European Union or to an international organization governed by public international law or consisting of two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect the Data.

If one of the transfers described above takes place, the User can refer to the respective sections of this document or request information from the Data Controller by contacting him at the contact details provided at the beginning.

Retention period

The Data is processed and stored for the time required by the purposes for which it was collected.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Owner and the User will be retained until such contract has been fully performed.
  • Personal Data collected for purposes related to the Data Controller's legitimate interest will be retained until such interest is fulfilled. Users may obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.

When processing is based on the User's consent, the Data Controller may retain the Personal Data for a longer period until such consent is revoked. Furthermore, the Data Controller may be required to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period, the Personal Data will be deleted. Therefore, upon expiration of this period, the right to access, erasure, rectification, and the right to data portability can no longer be exercised.

Purpose of the Processing of Collected Data

The User's Data is collected to allow the Owner to provide its Service, comply with legal obligations, respond to requests or enforcement actions, protect its rights and interests (or those of Users or third parties), identify any malicious or fraudulent activity, as well as the following: Access to third-party accounts, Statistics, Registration and authentication, Displaying content from external platforms, Interaction with external social networks and platforms, Contacting the User, Platform and hosting services, Payment management, and Tag Management.

To obtain detailed information on the purposes of the processing and on the Personal Data processed for each purpose, the User may refer to the section "Details on the Processing of Personal Data".

Facebook permissions required by this Application

This Application may request certain Facebook permissions that allow it to perform actions with the User's Facebook account and collect information, including Personal Data, from it. This service allows this Application to connect with the User's account on the Facebook social network, provided by Facebook Inc.

For more information on the following permissions, please refer to Facebook permission documentation and to the Facebook privacy policy .

The required permissions are as follows:

Basic information

The basic information of a registered Facebook user, which typically includes the following data: ID, name, image, gender, and localization language, and, in some cases, Facebook "Friends." If the user has made additional data publicly available, this data will be available.

Access to activities

Provides access to the User's activity list.

Access to friends lists

Provides access to the friend lists the User has created.

City

Provides access to the city indicated in the User's profile.

Events

Provides access to the list of events the User is attending.

Groups

Provides access to the list of groups the User is a member of.

Sex

Provides access to the User's gender.

Details on the processing of personal data

Personal Data is collected for the following purposes and using the following services:

  • Access to accounts on third-party services

    This type of service allows this Application to collect data from your accounts on third-party services and perform actions with them.
    These services are not activated automatically, but require the express authorization of the User.

    Facebook Account Access (Facebook, Inc.)

    This service allows this Application to connect with the User's account on the Facebook social network, provided by Facebook, Inc.

    Permissions requested: Access to activities; Access to friends lists; City; Events; Groups; Gender.

    Place of processing: United States – Privacy Policy .

  • Contact the User

    Contact form (this Application)

    By filling out the contact form with their Data, the User consents to their use to respond to requests for information, quotes, or any other kind indicated by the form header.

    Personal Data processed: ZIP code; city; Tax ID; last name; date of birth; email address; physical address; country; name; VAT number; profession; gender.

  • Payment Management

    Unless otherwise specified, this Application processes all payments by credit card, bank transfer, or other means through external payment service providers. In general, and unless otherwise specified, Users are requested to provide their payment details and personal information directly to these payment service providers.
    This Application is not involved in the collection and processing of such information: instead, it will only receive a notification from the payment service provider in question that the payment has been completed.

    PayPal (Paypal)

    PayPal is a payment service provided by PayPal Inc., which allows the User to make online payments.

    Personal Data processed: billing address; device information; email address; first name; last name; payment information; phone number; Usage Data.

    Place of processing: See PayPal's privacy policy – Privacy Policy .

    Google Pay (Google LLC)

    Google Pay is a payment service provided by Google LLC, which allows the User to make online payments using their Google credentials.

    Personal Data processed: surname.

    Place of processing: United States – Privacy Policy .

  • Tag Management

    This type of service is functional to the centralized management of the tags or scripts used on this Application.
    The use of these services involves the flow of User Data through them and, if applicable, their retention.

    Google Tag Manager (Google LLC)

    Google Tag Manager is a tag management service provided by Google LLC.

    Personal Data processed: Usage Data.

    Place of processing: United States – Privacy Policy .

  • Interaction with social networks and external platforms

    This type of service allows you to interact with social networks, or other external platforms, directly from the pages of this Application.
    The interactions and information acquired by this Application are in any case subject to the User's privacy settings relating to each social network.
    This type of service may still collect traffic data for the pages where the service is installed, even when Users do not use it.
    It is recommended to log out of the respective services to ensure that the data processed on this Application are not linked to the User's profile.

    Facebook Like button and social widgets (Facebook, Inc.)

    The “Like” button and Facebook social widgets are services for interacting with the Facebook social network, provided by Facebook, Inc.

    Personal Data processed: Usage Data; Tracking Tool.

    Place of processing: United States – Privacy Policy .

  • Registration and authentication

    By registering or authenticating, the User allows this Application to identify him or her and give him or her access to dedicated services.
    Depending on what is described below, registration and authentication services may be provided with the help of third parties. If this occurs, this Application will be able to access some Data stored by the third-party service used for registration or identification.
    Some of the services listed below may also collect Personal Data for targeting and profiling purposes; for more information, please refer to the description of each service.

    Instagram Authentication (Facebook, Inc.)

    Instagram Authentication is a registration and authentication service provided by Facebook, Inc. and connected to the Instagram social network.

    Personal Data processed: various types of Data as specified in the privacy policy of the service.

    Place of processing: United States – Privacy Policy .

  • Platform and hosting services

    These services are intended to host and operate key components of this Application, enabling the provision of this Application from a single platform. These platforms provide the Owner with a wide range of tools, such as analytics, user registration management, comment and database management, e-commerce, payment processing, etc. The use of these tools involves the collection and processing of Personal Data.
    Some of these services operate through servers geographically distributed in different locations, making it difficult to determine the exact location where the Personal Data is stored.

    Shopify (Shopify Inc.)

    Shopify is a platform provided by Shopify Inc. that allows the Owner to develop, operate, and host a website dedicated to e-commerce.

    Personal Data processed: billing address; email address; first name; last name; payment information; phone number; Usage Data.

    Place of processing: Canada – Privacy Policy .

  • Statistics

    The services contained in this section allow the Data Controller to monitor and analyze traffic data and are used to track User behavior.

    Google Analytics (Google LLC)

    Google Analytics is a web analytics service provided by Google LLC (“Google”). Google uses the Personal Data collected to track and examine the use of this Application, compile reports, and share them with other Google services.
    Google may use Personal Data to contextualize and personalize the ads of its own advertising network.

    Personal Data processed: Usage Data; Tracking Tool.

    Place of processing: United States – Privacy Policy  Opt Out .

    Google Analytics with anonymized IP (Google LLC)

    Google Analytics is a web analytics service provided by Google LLC (“Google”). Google uses the Personal Data collected to track and examine the use of this Application, compile reports, and share them with other Google services.
    Google may use Personal Data to contextualize and personalize the ads of its own advertising network.
    This Google Analytics integration anonymizes your IP address. This anonymization works by shortening Users' IP addresses within European Union member states or other signatory states to the Agreement on the European Economic Area. Only in exceptional cases will the IP address be sent to Google's servers and shortened within the United States.

    Personal Data processed: Usage Data; Tracking Tool.

    Place of processing: United States – Privacy Policy  Opt Out .

    Google Ads Conversion Tracking (Google LLC)

    Google Ads conversion tracking is a statistics service provided by Google LLC that connects data from the Google Ads advertising network with actions performed within this Application.

    Personal Data processed: Usage Data; Tracking Tool.

    Place of processing: United States – Privacy Policy .

  • Viewing content from external platforms

    This type of service allows you to view content hosted on external platforms directly from the pages of this Application and interact with them.
    This type of service may still collect web traffic data relating to the pages where the service is installed, even when users do not use it.

    Instagram Widget (Facebook, Inc.)

    Instagram is an image viewing service managed by Facebook, Inc. that allows this Application to integrate such content within its pages.

    Personal Data processed: Usage Data; Tracking Tool.

    Place of processing: United States – Privacy Policy .

    Google Fonts (Google LLC)

    Google Fonts is a font display service managed by Google LLC that allows this Application to integrate such content within its pages.

    Personal Data processed: Usage Data; Tracking Tool.

    Place of processing: United States – Privacy Policy .

User Rights

Users may exercise certain rights with reference to the Data processed by the Data Controller.

If you have greater protection, you may exercise all the rights listed below. Otherwise, you may contact the data controller to find out which rights apply to you and how to exercise them.

In particular, the User has the right to:

  • withdraw consent at any time. The User may revoke the consent to the processing of his/her Personal Data previously expressed.
  • object to the processing of your data. Users may object to the processing of their data when it occurs on a legal basis other than consent. Further details on the right to object are provided in the section below.
  • access your data. The User has the right to obtain information on the Data processed by the Owner, on certain aspects of the processing and to receive a copy of the processed Data.
  • verify and request rectification. The User can verify the accuracy of his/her Data and request its updating or correction.
  • obtain restriction of processing. When certain conditions apply, the User may request that the processing of their Data be limited. In this case, the Data Controller will not process the Data for any purpose other than its storage.
  • obtain the deletion or removal of your Personal Data. When certain conditions apply, the User may request that the Data Controller delete their Data.
  • receive your Data or have it transferred to another owner. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transmitted to another controller without hindrance. This provision applies when the Data is processed by automated means and the processing is based on the User's consent, on a contract to which the User is a party, or on contractual obligations related to it.
  • lodge a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.

Details on the right to object

When Personal Data is processed in the public interest, in the exercise of official authority vested in the Data Controller, or to pursue a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.

Users are informed that, if their data is processed for direct marketing purposes, they can object to the processing without providing any justification. To find out whether the Data Controller processes data for direct marketing purposes, Users can refer to the relevant sections of this document.

How to exercise your rights

To exercise User rights, Users may direct a request to the Data Controller's contact details provided in this document. Requests are submitted free of charge and will be processed by the Data Controller as quickly as possible, in any case within one month.

Applicability of the higher level of protection

While most of the provisions of this document apply to all Users, some are expressly subject to the applicability of a higher level of protection to the processing of Personal Data.

This higher level of protection is always guaranteed when the processing:

  • is performed by a Data Controller based in the EU; or
  • concerns Personal Data of Users located in the EU and is functional to the offer of goods or services for a fee or free of charge to such Users; or
  • It concerns Personal Data of Users located in the EU and allows the Data Controller to monitor the behavior of such Users to the extent that such behavior takes place within the Union.

This Application uses Tracking Tools. To learn more, the User can consult the Cookie Policy .

Further information on treatment

Defense in court

The User's Personal Data may be used by the Data Controller in court or in the preparatory stages leading to possible legal action for the defense against abuse in the use of this Application or related Services by the User.
The User declares to be aware that the Data Controller may be required to disclose the Data by order of public authorities.

Specific information

Upon the User's request, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

System logs and maintenance

For operational and maintenance purposes, this Application and any third-party services it uses may collect system logs, which are files that record interactions and may also contain Personal Data, such as the User's IP address.

Information not contained in this policy

Further information regarding the processing of Personal Data may be requested from the Data Controller at any time using the contact details.

Response to “Do Not Track” requests

This Application does not support “Do Not Track” requests.
To find out whether any third-party services used support them, the User is invited to consult their respective privacy policies.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Application and, where technically and legally feasible, by sending a notification to Users via one of the contact details available to the Data Controller. Therefore, please check this page frequently, referring to the date of the last modification indicated at the bottom.

If the changes affect processing whose legal basis is consent, the Data Controller will collect the User's consent again, if necessary.

Personal Data (or Data)

Personal data is any information that, directly or indirectly, even in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.

Usage Data

This information is collected automatically through this Application (including third-party applications integrated into this Application), including: the IP addresses or domain names of the computers used by the User who connects to this Application, the URI (Uniform Resource Identifier) ​​addresses, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (for example, the time spent on each page) and the details relating to the path followed within the Application, with particular reference to the sequence of pages visited, the parameters relating to the operating system and the IT environment of the User.

User

The individual using this Application who, unless otherwise specified, coincides with the Data Subject.

Interested

The natural person to whom the Personal Data refers.

Data Controller (or Controller)

The natural person, legal person, public administration or any other entity that processes personal data on behalf of the Data Controller, as set out in this privacy policy.

Data Controller (or Owner)

The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data and the tools used, including the security measures relating to the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.

This Application

The hardware or software tool by which the Personal Data of Users is collected and processed.

Service

The Service provided by this Application as defined in the relevant terms (if any) on this site/application.

European Union (or EU)

Unless otherwise specified, any reference to the European Union contained in this document shall be deemed to extend to all current member states of the European Union and the European Economic Area.

Cookie

Cookies are Tracking Tools that consist of small portions of data stored within the User's browser.

Tracking Tool

By Tracking Tool we mean any technology—e.g., cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting—that allows Users to be tracked, for example by collecting or storing information on the User's device.


Legal references

This privacy policy is drafted on the basis of multiple legislative provisions, including Articles 13 and 14 of Regulation (EU) 2016/679.

Unless otherwise specified, this privacy policy applies exclusively to this Application.