Information pursuant to Articles 13-14 of European Regulation 679/2016 (GDPR)

Pontedilegnotrails di Matteo Aielli protects the confidentiality of your personal data and guarantees its protection and proper processing, in accordance with recent European legislation. Pursuant to Articles 13 and 14 of European Regulation (EU) 2016/679 (hereinafter GDPR) and Legislative Decree 196/03, as amended by Legislative Decree 101/18, we hereby inform you of the following:

1) Data Controller and Data Protection Officer.

The data controller is Pontedilegnotrails di Matteo Aielli, represented by its legal representative pro tempore, with registered office at Via E. Masera, 7, Ponte di Legno 25056, VAT number 03916380987 and Tax Code: LLAMTT78A23F205P.

The data controller can be contacted by email at info@pontedilegnotrails.it.

The data controller has not appointed a Data Protection Officer (DPO).

Data processing, as described below, takes place at Via E. Masera, 7, Ponte di Legno 25056. The data is processed and stored by the data controller within the European Economic Area and will not be transferred outside of it.

2) Type of data and processing.

The data you provide us are common and not special.

This includes your name and surname, date of birth, contact information (landline, mobile phone number, including VoIP, email address, etc.).

You may provide us with the data personally, as the data subject, including via remote tools.

Our website, during its operation, may acquire certain data that is automatically transmitted during navigation, such as IP address, online identifiers, contact time, etc. This information is not processed but will only be used to provide anonymous statistics on the use of the site and to monitor any anomalies, as well as to prevent fraud. For this latter purpose, the data may be used solely for the purposes of communicating with the competent authorities for the purpose of ascertaining liability. Therefore, we inform you that, by its nature, this information could, through association and processing with data held by third parties, allow the user to be identified.

In addition to the above, if you interact with social networks, you may provide your data in the registration window (“Register with…”) of the social network.

Generally speaking, all types of data processing can be identified as those set forth in Article 4, paragraph 1, no. 2 of EU Regulation 679/16 (e.g., collection, recording, organization, storage, etc.). Your data will, however, be processed lawfully, fairly, and transparently. Only the data necessary and essential to achieve the specific purpose will be processed (so-called data minimization and accountability pursuant to Article 5, paragraph 1, letter c of the GDPR), ensuring the accuracy and integrity of the data.

In particular, you acknowledge that your personal data, including sensitive data, may be collected based on information you provide during registration or through communications, including electronic communications, with the data controller.

Persons under the age of 16 may use the services only with the consent of their parents or, in any case, the holder of parental responsibility pursuant to Article 8 of the GDPR.

3) Purpose, legal basis, and methods of data processing.

The processing of your data is primarily aimed at the correct and complete provision of the services you have requested.

Each type of processing is based on a prerequisite or legal basis, pursuant to Art. 6 of the GDPR.

The purposes of the processing are as follows, with the corresponding legal basis in brackets:

a) provision of the requested services, management of purchase orders, supply of products, management of payments, and communications relating to the orders themselves (performance of the contract or pre-contractual measures);
b) fulfillment of tax and accounting obligations, including through third parties and external processors (fulfillment of legal and regulatory obligations);
c) personal communications and internal security (performance of the contract);
d) direct marketing initiatives (so-called soft spam) (Article 130, paragraph 4 of the Privacy Code)
e) commercial communications from other branded companies or third parties operating in the sector; (consent);
f) customer care and customer satisfaction (performance of the contract);

Any additional and future purposes will be subject to an appendix to this policy and any consent required.

Your data will be processed both manually and electronically, only if there is an appropriate legal basis.

Personal data may be processed using both paper and electronic archives (including portable devices), using methods strictly necessary to fulfill the purposes indicated above. The data may be processed using so-called cloud-based IT devices and reside in cloud-based archives.

Providing your data is mandatory as it is necessary to fulfill contractual or legal obligations in relation to the purposes indicated above in letters a), b), c), and f). With regard to letters d) and e), providing your data is optional and may be subject to revocation or objection as described below. The Data Controller informs you that failure to provide or incorrectly provide/update your data may make it impossible to ensure compliance with applicable legislation.

4) Data Sharing.

The data may be processed by our collaborators in customer management, marketing, technical personnel, etc. All such collaborators have received appropriate training and instructions regarding the minimum security measures required to protect your data.

To process your data, the Data Controller may also use third parties such as:

General consultants, accounting and tax advisors, or lawyers, formally delegated or legally authorized, who provide services functional to the purposes indicated above;
Banking and insurance institutions that provide services functional to the purposes indicated above, including companies that handle payment services accepted by our website as independent data controllers;
Parties that process data in compliance with specific legal obligations;
Judicial, police, or administrative authorities, for the fulfillment of legal obligations;
Websites and third-party providers of communications networks and services;
Websites and third-party providers of communications networks and services for the purposes of processing communications sent via email and their content and attachments;

Your data may therefore be disclosed to these entities, who will process it as independent data controllers or processors.

You can verify the compliance of these service providers with applicable legislation on their respective websites, including by requesting the data controller’s contact information using the methods indicated below.

5) Data Retention.

Your personal data, processed for the purposes indicated above, will be retained pursuant to Article 13, paragraph 2, letter a, of the GDPR. The data will be archived for as long as the data controller is subject to retention obligations, for tax purposes, or for other purposes established by law or regulation. In any case, in compliance with the aforementioned provisions, your data will not be retained beyond the period strictly necessary for the purposes described above.

Pending disputes with the data controller, processing will continue until the rights of each party have expired. Regarding marketing purposes, unless the data subject expressly objects to this purpose or withdraws consent, the retention period will be two years.

6) Profiling and Data Dissemination.

Your personal data will not be disseminated or subject to any fully automated decision-making process, including profiling. An exception is made if you connect to the website or social network pages of the Data Controller (Facebook, X, etc.). In this case, your data may be analyzed according to the provisions and purposes indicated by the web service provider or the relevant social network. In this latter case, the hosting service provider or the relevant social network may use cookies. You are therefore advised to review your privacy and security settings on your social profile and disable the use of these tools if you do not wish for such processing. Please note that the Settings option, available on the toolbar of most browsers, includes instructions for preventing the browser from accepting cookies, receiving notifications for each new cookie installed, or disabling unwanted ones. By continuing to use and visit the Data Controller’s website or social network profiles, you automatically consent to the processing of your data and the use of cookies according to your default settings and those indicated by the hosting server or social network used.

7) Data security.

The Data Controller undertakes to protect your data from unauthorized access or other alterations. This involves the use of various security measures (passwords, firewalls, antivirus, backups, etc.) to protect stored data, as well as ongoing reviews of data collection, storage, and processing methods.

In accordance with this policy, the Data Controller will treat all your personal data strictly confidentially, in order to preserve their integrity, confidentiality, and availability (Article 32 of the GDPR) and will take all reasonable steps to ensure the security of your data once it is in the Data Controller’s possession. Likewise, the Data Controller will impose similar measures on third-party providers.

8) Rights of the Data Subject.

The rights granted to you by the GDPR include:

Request access to your personal data and related information; rectification of inaccurate data or completion of incomplete data; The erasure of your personal data (if one of the conditions set out in Article 17, paragraph 1 of the GDPR applies and in compliance with the exceptions set out in paragraph 3 of the same Article); the restriction of the processing of your personal data (if one of the conditions set out in Article 18, paragraph 1 of the GDPR applies);
request and obtain—where the legal basis for processing is a contract or consent, and the processing is carried out by automated means—your personal data in a structured, commonly used, machine-readable format, including for the purpose of communicating such data to another data controller (so-called right to data portability);
object at any time to the processing of your personal data in specific situations that concern you;
Withdraw your consent at any time, limited to cases in which the processing is based on your consent for one or more specific purposes and concerns common personal data (for example, date and place of birth or place of residence), or particular categories of data (for example, data revealing your racial origin, political opinions, religious beliefs, health, or sex life). Processing based on consent and carried out prior to its withdrawal remains lawful;

Lodge a complaint with a supervisory authority (Italian Data Protection Authority – www.garanteprivacy.it).


9) Contact Information

To exercise your rights, you can send an email to the data controller or contact him at: Pontedilegnotrails di Matteo Aielli +39 3382058531 and info@pontedilegnotrails.it.