Privacy Policy

Privacy Policy

Data Controller

Alla Vetreria Perletti Sagl
Via Navett 6
6503 Bellinzona
Ticino – Switzerland

Email address of the Data Controller: info@vetreriaperletti.ch


Types of Data Collected

Among the Personal Data collected by this Application, either independently or through third parties, are: usage data; tracking tools; responses to questions; clicks; keypress events; motion sensor events; mouse movements; scroll position; touch events; first name; last name; phone number; email; username; data provided while using the service; physical address.

Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information notices displayed prior to data collection.

Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application.
Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to provide it, the Application may be unable to provide its services. In cases where this Application specifically states that certain Data is optional, Users are free to withhold such Data without consequences on the availability or functionality of the Service.

Users unsure about which Data is mandatory are encouraged to contact the Data Controller.

The possible use of Cookies—or other tracking tools—by this Application or by the owners of third-party services used by this Application serves, unless otherwise specified, the purpose of providing the Service requested by the User, as well as any additional purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for third-party Personal Data obtained, published, or shared through this Application and confirms they have the right to communicate or share it, freeing the Data Controller from any liability toward third parties.


Methods and Place of Data Processing

Methods of Processing
The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of the Personal Data.

Data processing is carried out using IT and/or telematic tools, following organizational procedures and logic strictly related to the stated purposes. In addition to the Data Controller, in some cases, the Data may be accessible to other individuals involved in the operation of this Application (administrative, sales, marketing, legal staff, system administrators) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communication agencies) appointed, if necessary, as Data Processors by the Data Controller. An up-to-date list of these parties may be requested from the Data Controller at any time.

Place
The Data is processed at the Data Controller’s operating offices and at any other location where the parties involved in the processing are located. For more information, please contact the Data Controller.

The User’s Personal Data may be transferred to a country other than the one where the User is located. To obtain further information regarding the place of processing, the User may refer to the relevant section of this document concerning the details on the processing of Personal Data.

The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization governed by international public law or formed by two or more countries, such as the United Nations, as well as regarding the security measures adopted by the Data Controller to safeguard the Data.

The User can check whether one of the aforementioned transfers is taking place by reviewing the section of this document relating to details on the processing of Personal Data or by requesting information from the Data Controller using the contact details provided above.


Retention Period

The Data is processed and stored for as long as required for the purposes for which it was collected.

Therefore:

  • Personal Data collected for purposes related to the execution of a contract between the Data Controller and the User will be retained until the execution of that contract is completed.

  • Personal Data collected for purposes related to the legitimate interests of the Data Controller will be retained as long as needed to fulfill those interests. Users may find more information about the legitimate interests pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.

When processing is based on the User’s consent, the Data Controller may retain the Personal Data for a longer period until such consent is revoked. Additionally, the Data Controller may be obliged to retain the Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

Once the retention period expires, the Personal Data will be deleted. Therefore, the right to access, erase, rectify, and the right to data portability can no longer be exercised after the expiration of this period.

Purpose of Data Processing

User Data is collected to allow the Data Controller to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect its own rights and interests (or those of Users or third parties), detect any malicious or fraudulent activity, and for the following purposes: Displaying content from external platforms, SPAM protection, Contacting the User, Registration and authentication provided directly by this Application, Collection of privacy preferences, Creation and management of this Application, and Analytics.

For detailed information on the purposes of processing and the Personal Data used for each purpose, Users may refer to the section “Details on the Processing of Personal Data.”


Details on the Processing of Personal Data

Personal Data is collected for the following purposes using the following services:


Contacting the User

Phone contact (this Application)
Users who provide their phone number may be contacted for commercial or promotional purposes related to this Application, as well as to fulfill support requests.
Personal Data processed: phone number.


Analytics

The services in this section enable the Data Controller to monitor and analyze web traffic and track User behavior.

Google Analytics (Google Ireland Limited)
Google Analytics is a web analysis service provided by Google Ireland Limited (“Google”). Google uses the Personal Data collected to track and examine the use of this Application, to prepare reports, and to share them with other Google services.
Google may use Personal Data to contextualize and personalize the ads of its advertising network.
Personal Data processed: Cookies; Usage Data.
Place of processing: Ireland – Privacy PolicyOpt Out. Participant in the Privacy Shield.


SPAM Protection

This type of service analyzes the traffic of this Application, potentially containing Users’ Personal Data, with the purpose of filtering it from parts of traffic, messages, and content recognized as SPAM.

Google reCAPTCHA (Google Ireland Limited)
Google reCAPTCHA is a SPAM protection service provided by Google Ireland Limited.
The use of reCAPTCHA is subject to Google’s privacy policy and terms of use.
Personal Data processed: clicks; Usage Data; keypress events; motion sensor events; touch events; mouse movements; scroll position; answers to questions; Tracking Tools.
Place of processing: Ireland – Privacy Policy.


Creation and Management of this Application

The core components of this Application are developed and managed directly by the Data Controller using the software listed below.

WordPress (self-hosted) (this Application)
This Application is developed and managed by the Controller using a CMS (Content Management System) called WordPress.
Personal Data processed: last name; email; physical address; first name; phone number.


Displaying Content from External Platforms

This type of service allows viewing content hosted on external platforms directly from the pages of this Application and to interact with them.
These services might still collect web traffic data for the pages where the service is installed, even when Users do not use it.

Google Fonts (Google Ireland Limited)
Google Fonts is a font display service provided by Google Ireland Limited that allows this Application to incorporate content of this kind on its pages.
Personal Data processed: Usage Data; Tracking Tools.
Place of processing: Ireland – Privacy Policy.

Google Maps Widget (Google Ireland Limited)
Google Maps is a map visualization service provided by Google Ireland Limited that allows this Application to display maps directly on its pages.
Personal Data processed: Tracking Tools.
Place of processing: Ireland – Privacy Policy.

YouTube Video Widget (Google Ireland Limited)
YouTube is a video content visualization service provided by Google Ireland Limited that allows this Application to incorporate video content on its pages.
Personal Data processed: Usage Data; Tracking Tools.
Place of processing: Ireland – Privacy Policy.


Collection of Privacy Preferences

This type of service allows this Application to collect and save Users’ preferences related to the collection, use, and processing of their personal information, as required by applicable privacy legislation.

CookieYes Consent (CookieYes Limited)
CookieYes Consent enables the Data Controller to store users’ cookie consent preferences and ensure they are respected during future visits to this website. It does not collect or store any personal information from visitors.
Personal Data processed: Tracking Tools.
Place of processing: United Kingdom – Privacy Policy.

Cookie Policy

This Application uses Tracking Tools. To learn more, Users may refer to the Cookie Policy.


Additional Information for Users
Legal Basis of Processing

The Data Controller may process Personal Data relating to the User if one of the following conditions applies:

  • The User has given consent for one or more specific purposes. Note: In some jurisdictions, the Controller may be allowed to process Personal Data without the User’s consent or any other legal basis specified below, as long as the User does not object (“opt-out”) to such processing. This, however, does not apply if the processing of Personal Data is subject to European data protection law.

  • The processing is necessary for the performance of a contract with the User and/or for any pre-contractual obligations.

  • The processing is necessary for compliance with a legal obligation to which the Controller is subject.

  • The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.

  • The processing is necessary for the legitimate interests pursued by the Controller or by a third party.

In any case, the Controller will gladly help to clarify the specific legal basis that applies to the processing, and whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.


Further Information on Storage Period

Unless otherwise stated in this document, Personal Data is processed and stored for as long as required for the purpose it was collected for and may be retained for a longer period due to legal obligations or based on User consent.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Controller and the User shall be retained until such contract has been fully performed.

  • Personal Data collected for the purposes of the Controller’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Controller in the relevant sections of this document or by contacting the Controller.

Where processing is based on User consent, the Controller may retain the Personal Data for a longer period until such consent is withdrawn. Additionally, the Controller may be obliged to retain the Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

Once the retention period expires, the Personal Data will be deleted. Therefore, the rights of access, erasure, rectification, and data portability cannot be enforced after that period.


User Rights

Users may exercise certain rights regarding their Data processed by the Data Controller.

In particular, to the extent permitted by law, Users have the right to:

  • Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.

  • Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent.

  • Access their Data. Users have the right to learn if Data is being processed by the Controller, obtain disclosure regarding certain aspects of the processing, and obtain a copy of the Data undergoing processing.

  • Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.

  • Restrict the processing of their Data. Users have the right, under certain circumstances, to restrict the processing of their Data. In this case, the Controller will not process the Data for any purpose other than storing it.

  • Have their Personal Data deleted or otherwise removed. Users have the right, under certain circumstances, to obtain the erasure of their Data from the Controller.

  • Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used, and machine-readable format and, if technically feasible, to have it transmitted to another controller without any hindrance.

  • Lodge a complaint. Users have the right to bring a claim before their competent data protection authority or take legal action.

Users also have the right to obtain information about the legal basis for Data transfers to countries outside the European Union or to any international organization governed by public international law or set up by two or more countries—such as the UN—and about the security measures taken by the Controller to safeguard their Data.


Details About the Right to Object

Where Personal Data is processed for a public interest, in the exercise of an official authority vested in the Controller, or for the purposes of the legitimate interests pursued by the Controller, Users may object to such processing by providing a ground related to their particular situation.

Users are informed that they may object to the processing of their Data for direct marketing purposes at any time, without providing any justification. If the User objects to processing for direct marketing purposes, the Personal Data will no longer be processed for such purposes. To find out whether the Controller is processing Data for direct marketing purposes, Users may refer to the relevant sections of this document.


How to Exercise These Rights

Any requests to exercise User rights can be directed to the Controller through the contact details provided in this document. These requests can be exercised free of charge and will be addressed by the Controller as early as possible and always within one month. Any rectification, erasure, or restriction of processing will be communicated by the Controller to each recipient, if any, to whom the Personal Data has been disclosed unless this proves impossible or involves disproportionate effort. At the User’s request, the Controller will inform the User about those recipients.

 

Additional Information for Users in Switzerland

This section applies to Users in Switzerland and, for such Users, replaces any other potentially divergent or conflicting information contained in the privacy policy.

Further details regarding the categories of Data processed, the purposes of the processing, the categories of personal data recipients (if any), the retention period, and other information about Personal Data can be found in the section titled “Detailed Information on the Processing of Personal Data” within this document.

User Rights Under the Swiss Federal Act on Data Protection

Users may exercise certain rights concerning their data within the limits of the law, including the following:

  • The right to access Personal Data;

  • The right to object to the processing of their Personal Data (which also allows Users to request the restriction of the processing, the deletion or destruction of Personal Data, and the prohibition of disclosure of Personal Data to third parties);

  • The right to receive their Personal Data and to transfer it to another controller (data portability);

  • The right to request the rectification of inaccurate Personal Data.

How to Exercise These Rights

Any requests to exercise the User’s rights may be addressed to the Controller using the contact details provided in this document. Such requests are free of charge, and the Controller will respond as soon as possible, providing the information required by law.


Additional Information About Processing
Legal Defense

The User’s Personal Data may be used by the Controller in legal proceedings or in the preparatory stages leading to possible legal action arising from improper use of this Application or the related Services by the User.
The User declares to be aware that the Controller may be required to reveal the Data at the request of public authorities.

Specific Information

Upon the User’s request, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data.

System Logs and Maintenance

For operation and maintenance purposes, this Application and any third-party services it uses may collect system logs, i.e., files that record interactions and may also contain Personal Data, such as the User’s IP address.

Information Not Contained in This Policy

More details concerning the processing of Personal Data may be requested from the Controller at any time using the contact information provided.

Changes to This Privacy Policy

The Controller reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and, where possible, on this Application and/or—where technically and legally feasible—sending a notice to Users via any contact information available to the Controller. Please consult this page frequently, referring to the date of the last modification listed below.

If the changes affect processing activities based on the User’s consent, the Controller will collect new consent from the User, where required.


Definitions and Legal References
Personal Data (or Data)

Any information that directly, indirectly, or in connection with other information—including a personal identification number—allows for the identification or identifiability of a natural person.

Usage Data

Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers used by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s response (successful, error, etc.), the country of origin, the features of the browser and the operating system used by the User, the various time details per visit (e.g., the time spent on each page), and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.

User

The individual using this Application who, unless otherwise specified, coincides with the Data Subject.

Data Subject

The natural person to whom the Personal Data refers.

Data Processor (or Processor)

The natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.

Data Controller (or Controller)

The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Application. Unless otherwise specified, the Data Controller is the owner of this Application.

This Application

The means by which the Personal Data of the User is collected and processed.

Service

The service provided by this Application as described in the relative terms (if available) and on this site/application.

European Union (or EU)

Unless otherwise specified, all references made within this document to the European Union include all current member states of the European Union and the European Economic Area.

Cookie

Cookies are Tracking Tools consisting of small sets of data stored in the User’s browser.

Tracking Tool

Tracking Tool means any technology—e.g., Cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting—that enables the tracking of Users, for example by accessing or storing information on the User’s device.

Legal References

This privacy statement is prepared based on multiple pieces of legislation.

Unless otherwise specified, this privacy policy relates exclusively to this Application.

Last modification: August 28, 2023