Introduction
This Policy (together with our Cookie Policy) aims to describe how we process the personal data of users/visitors to this website, accessible at https://www.medinat.it/.
This notice is provided in accordance with current Italian (Legislative Decree 196/2003 and subsequent amendments) and European (European Regulation 2016/679 – GDPR) legislation regarding the protection of personal data.
We recommend that you read this privacy policy carefully before providing any personal data.
Ownership
The data controller is Medinat S.r.l., with registered office in Naples, at Via Francesco Caracciolo, 17, 80122, VAT No. 07275210636, Tax Code 07275210636 (hereinafter referred to simply as the “Owner” or “We”).
Scope of this Policy
This Privacy Policy applies to this website and not to any other websites not owned by Medinat S.r.l. that may be accessed by the user via links (so-called redirects).
What data will we use, for what purposes, and on what legal basis?
We may collect and process the following data:
- Information requests
By completing the contact forms on this site, sending traditional or email messages to the addresses published on the site, or leaving comments or requests via social media pages, the Data Controller collects your personal and contact information (such as your name, surname, email address, and telephone number) and any personal data you may provide in communications. This data is processed solely for the purpose and for the period necessary to respond to your requests. The legal basis for the processing is therefore the performance of a contract or pre-contractual measures [Article 6, paragraph 1, letter b) GDPR].
- Browsing data
The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols.
This category of data includes: IP addresses, browser type, operating system, domain name and website addresses from which access or exit was made, information on the pages visited by users within the site, access time, time spent on each page, internal navigation analysis, and other parameters relating to the user’s operating system and IT environment.
This technical/IT data is collected and used exclusively in an aggregated and non-immediately identifiable manner; it could be used to ascertain liability in the event of hypothetical computer crimes against the site or at the request of public authorities.
- Cookie (referral)
Regarding the installation of cookies by this website, please refer to the Cookie Policy: https://www.medinat.it/cookie-policy/
To whom do we disclose your data?
The personal data collected through this website is accessible to duly authorized and trained individuals acting on behalf of the Data Controller, as persons in charge of managing the requested service.
Furthermore, the User’s personal data may be shared with our service providers instrumental to the services provided by the Data Controller (e.g., shipping companies, website maintenance and technical management companies, email marketing agencies, etc.). These third parties will act as data processors, based on specific agreements entered into pursuant to Article 28 of the GDPR.
A complete list of the parties to whom your data may be disclosed will be made available upon written request to privacy@medinat.it.
How do we process your data?
The processing of your personal data, for each of the above purposes, will take place using automated and/or traditional means and, in any case, in compliance with the principles of lawfulness, necessity, and relevance, adopting appropriate measures to ensure the security, availability, and confidentiality of the data.
Where do we store your data?
The processing related to this site’s web services is stored on servers located within the European Economic Area, specifically at the premises of Aruba S.p.A., located at Via 14, Piazza Giuseppe Garibaldi, CAP 52010 Città Arezzo, which manages the relevant server. Personal data is processed only by technical personnel of that company, specifically appointed for processing, or by persons assigned to occasional maintenance operations.
How long do we keep your data?
Users’ personal data is retained for the time strictly necessary to achieve the aforementioned purposes, in compliance with civil and tax retention obligations and the limits established by law. In any case, after the ten-year limitation period (Article 2946 of the Italian Civil Code; Article 8 of Law No. 212 of July 27, 2000) and the mandatory ten-year retention period for accounting records (Article 2220 of the Italian Civil Code) has expired, and the Data Controller no longer needs to retain the information for potential tax audits, the data will be destroyed, deleted, or transformed into an unintelligible form, unless there are further reasons justifying their retention (e.g., pending legal disputes).
For profiling or marketing purposes to which the data subject has consented by checking the appropriate box in the forms on the site, personal and contact information and details relating to the requested good or service will be retained for a period of 12 months for profiling purposes and 24 months for marketing purposes. After this period, the Data Controller reserves the right to send a reminder to confirm the consent given. In the event of inaction, consent will be automatically deemed extended.
Regarding registration on the site, personal data will be processed until the User deactivates their account.
What rights can you exercise?
As a data subject, pursuant to Articles 15 et seq. of the GDPR, the User may exercise their rights, including the right to access their personal data, the right to request rectification, erasure, or restriction of processing concerning them, or to object to their processing at any time, as well as the right to data portability if the relevant conditions are met.
Furthermore, in the event of the Data Controller’s failure to respond to the aforementioned requests, or incomplete response, the User will have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or to appeal to the competent judicial authority, within the terms and according to the procedures established by EU Regulation 2016/679 (GDPR) and applicable national legislation.
How can you contact the Data Controller to exercise your rights or to withdraw or modify consent given for marketing and profiling purposes?
The User may contact the Data Controller using one of the contact details below:
– Email address: privacy@medinat.it
– Telephone number: +39 081 19560471/2
– Postal address: Via Francesco Caracciolo, 17, 80122, Naples (NA)
How to contact the competent Supervisory Authority to file complaints?
Complaints may be submitted to the competent Supervisory Authorities:
Italian Data Protection Authority
Piazza di Monte Citorio No. 121
00186 Rome
Italy
Fax: (+39) 06.69677.3785
Tel: (+39) 06.696771
Email: garante@gpdp.it
Certified email: protocollo@pec.gpdp.it
How can you be informed of any changes to this Privacy Policy?
The potential entry into force of new industry regulations, as well as the ongoing review and updating of services provided to Users, may require changes to the way we process personal data. Our policy may therefore change over time, and we encourage visitors to periodically review this page. For this purpose, the policy document highlights the date it was last updated.
Last updated: April 19, 2022