Privacy and Cookie Policy
In compliance with the obligations arising from the European General Data Protection Regulation No. 679/2016 (GDPR) and subsequent amendments, this website respects and protects the privacy of visitors and users (hereinafter referred to as “data subjects,” as per Art. 4, paragraph 1 of the GDPR), making every reasonable and proportionate effort to safeguard their rights.
The privacy of each visitor to this website is very important to us. For this reason, we have developed a Privacy Policy detailing how we collect, use, disclose, transfer, and store your data.
We invite you to read this document carefully to understand our privacy protection criteria and to contact us with any questions.
Please note that this privacy policy applies exclusively to the online activities of this website and is valid only for data subjects, not for other websites that may be accessed through links. By browsing this site and/or using its services as a data subject, you explicitly approve and consent to the processing of personal data according to the methods and purposes described in this Privacy Policy.
Definitions Used in This Privacy Policy
- Personal Data – Any information relating to an identified or identifiable natural person.
- Processing – Any operation or set of operations performed on personal data or a set of personal data.
- Data Subject – A natural person whose personal data has been processed.
- Children – A natural person under the age of 16.
Principles Regarding the Protection of Your Data
We are committed to following these principles to protect your data:
- We process your personal data only for lawful, fair, and transparent purposes, ensuring that data processing is always based on legitimate grounds.
- We process your data while always keeping your rights in mind and will provide, upon request, all information regarding the processed data.
- Data processing is always limited to the specific purpose requested. Our processing activities always align with the purposes for which the personal data was collected.
- Data processing is performed with only the necessary data. We collect and process only the minimum amount of personal data required for any given purpose.
- Data processing is limited to a specific period. We do not store your personal data longer than necessary.
- We are committed to ensuring the accuracy and security of your data.
- We strive to maintain the integrity and confidentiality of your data.
Data Subject Rights
As a data subject, you have the following rights:
- Right to Information – You have the right to know if your personal data has been processed, what data is collected, how it is used, for what purpose, and by whom.
- Right of Access – You have the right to access your personal data and request a copy of the collected personal data.
- Right to Rectification – You have the right to request the correction or deletion of any personal data that is incorrect or incomplete.
- Right to Erasure (“Right to be Forgotten”) – Under certain circumstances, you can request the deletion of your personal data from our records.
- Right to Restrict Processing – Under certain conditions, you have the right to limit the processing of your personal data.
- Right to Object to Processing – In some cases, you have the right to object to the processing of your personal data, such as in direct marketing cases.
- Right to Object to Automated Processing – You have the right to object to automated processing, including profiling. Additionally, you are not subject to decisions based solely on automated processing that produce legal effects or significantly impact you. This right does not apply when profiling results in legal consequences that affect you.
- Right to Data Portability – You have the right to receive your personal data in a readable format or, if possible, to request a direct transfer from one processor to another.
- Right to Lodge a Complaint – If your access request is denied, you have the right to be informed of the reason for the denial. If you are not satisfied with how your request has been handled, you are encouraged to contact us.
- Right to Seek Supervisory Authority Intervention – You have the right to request intervention from the relevant supervisory authority and/or seek other legal remedies, such as claiming compensation for damages.
- Right to Withdraw Consent – You have the right to withdraw any consent previously given for the processing of your personal data.
Personal Data Collected by This Website
Information Provided Voluntarily
This includes information such as your email address, name, billing address, residential address, and other data necessary to provide you with a product/service or enhance your user experience. The voluntary, explicit, and intentional sending of emails and/or postal mail to the addresses listed on this site results in the acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data included in the message. The user remains solely responsible for the relevance and accuracy of the submitted data.
In the comment forms and/or contact sections of this site, only the data necessary for responding is collected. This information may include, for example, your name and email address. Regarding comments, the user explicitly agrees that the submitted content may be freely viewed by other visitors.
The received data will be used exclusively for providing the requested service and only for the time necessary to fulfill the service. Any information that users choose to make public through the services and tools provided on this site is shared knowingly and voluntarily, releasing this site from any responsibility for potential legal violations. It is the responsibility of data subjects to ensure they have permission to submit third-party personal data or content protected by national and international regulations.
Information Collected Automatically
This refers to data that is automatically stored in server log files. The collected information may include:
- Types and versions of browsers used
- Operating system of the accessing system
- Web page of origin and destination (referral)
- Country of origin
- Date and time of access to the website
- Internet Protocol (IP) address
- Internet Service Provider (ISP) name
- Other similar data and/or information that may be used in case of cyber-attacks
These are anonymous data primarily used to enhance the visitor/user experience and ensure optimal protection of processed personal data. Anonymous server log files are stored separately from any personal data provided by data subjects.
The traffic on this site is monitored by Aruba Web Hosting, which collects users’ IP addresses for a duration of one month.
Publicly Available Information
We may also collect personal data that you have made publicly available.
Location of Data Processing
The data collected by this website is processed at the headquarters of the Data Controller and at the data center of the web hosting provider. The web hosting provider is responsible for processing the data on behalf of the Data Controller, is located within the European Economic Area, and operates in compliance with European regulations.
How We Use Your Personal Data
We use your personal data to:
- Provide you with an appropriate service (such as account registration).
- Provide you with other products and services upon request.
- Send you promotional materials upon request and communicate with you regarding such products and/or services.
- Communicate and interact with you, including notifying you of any service changes.
- Improve your user experience.
- Fulfill legal or contractual obligations.
We will process your personal data for legitimate interests and/or with your consent.
Processing for Contractual Purposes
To fulfill contractual obligations, we process your personal data for the following purposes:
- To identify you.
- To provide you with a service or send/offer a product.
- To communicate information related to sales and invoicing.
Processing for Legitimate Interests
For legitimate interest purposes, we process your personal data for the following reasons:
- To send you personalized offers* (directly from us).
- To manage and analyze our customer database (behavior and purchase history) to improve the quality, variety, and availability of the products/services we offer.
- To conduct surveys on visitor/user satisfaction.
- For security purposes (spam filters, firewalls, virus detection): Automatically recorded data may include personal data such as IP addresses, which may be used in accordance with applicable laws to prevent site damage, harm to other users, or other malicious or criminal activities. These data are never used for user identification or profiling, nor combined with other data or shared with third parties, but are solely used to protect this site and its users.
Unless you communicate otherwise, we may offer you products/services similar or identical to those in your purchase history and browsing behavior, in line with our legitimate interest.
Processing with Your Consent
With your consent, we will process your personal data for the following purposes:
- To send you newsletters and marketing campaign offers (directly from us).
- For any other purposes for which we have requested your consent.
We may also process your personal data to comply with legal obligations and/or use your data in cases provided by law.
We reserve the right to use only anonymized data. We will retain billing data and other relevant information only for the period required by legal obligations.
We may process your personal data for additional purposes not specified in this privacy policy, provided they remain compatible with the original purpose for which the data was collected. This will only occur if:
- The link between the purposes, context, and nature of the personal data is suitable for further processing.
- The additional processing does not harm your interests.
- Adequate safeguards are always in place for data processing.
We will inform you in the event of further data processing or different purposes.
Who else can access your personal data?
We do not share your personal data with third parties. We only share your data with third parties connected to this website. This website has integrated the Google Analytics JS script (with the anonymizer feature). Google Analytics is primarily a web analysis service that collects and analyzes data about visitors’ behavior on this site. From this analysis, information is gathered about the visitor’s origin (the so-called referrer), pages visited, and the frequency and duration of visits, etc. The aim of these analyses is to optimize this site and evaluate the cost-benefit of advertising for this site on the Internet. Google Analytics is a service provided by Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, United States. To perform these analyses, the string of code “_gat._anonymizeIp” is used. Through this code, the IP address of the individual is anonymized by Google. The primary purpose of Google Analytics is to analyze the traffic of this site. However, Google may use the data and information collected, among other things, to evaluate the usage and to provide online reports that represent the activities of this site. Google Analytics places a cookie on the subject’s computer system. With the setting of this cookie, Google is enabled to analyze this site. In every page of this site, where the Google Analytics tracking script is present, the data of the subject will be automatically sent to Google via their browser. Through this technical procedure, Google receives the subject’s IP address and will be able to understand the visitors’ origin and the number of clicks on the site. The cookie is used to store personal information, such as the time of access, the location from which the access was made, and the frequency of visits to this website by the individual. For each visit to this site, this personal data, including the IP address of the Internet access used by the individual, will be transmitted to Google in the United States of America. This personal data is collected by Google through this site and is stored for a period of 26 months. Google may transfer this personal data collected via the aforementioned technical procedure to third parties. The individual can prevent the installation of these cookies at any time by making the appropriate changes to their web browser and permanently rejecting the setting of these cookies. Such a modification to the Internet browser prevents Google Analytics from setting its cookie. Similarly, the individual can delete the cookies already in use by Google Analytics through their browser. The individual also has the option to prevent the collection and subsequent processing of data collected via this site by Google Analytics. To do this, the individual must download and install a browser add-on directly from this link. This add-on instructs Google Analytics not to track visits and/or store the subject’s data. Further information regarding applicable data protection provisions by Google can be found at this link. For more details about Google Analytics, visit this link: https://www.google.com/analytics/.
How we protect your data
We will take every possible effort to keep your personal data secure. We use secure protocols for communication and data transfer (such as HTTPS). We use anonymized data whenever possible. We constantly monitor our systems to prevent possible vulnerabilities and/or cyberattacks. However, data transmission over the internet may, in principle, have security gaps, so absolute protection cannot be guaranteed. In any case, we will notify the relevant authorities of any data breaches in the ways and timeframes provided by current privacy regulations. You will be directly informed in the case of violations concerning your rights or interests. We will do everything reasonably possible to prevent security breaches. If you have registered an account on this site, remember to keep your username and password confidential.
Children
We do not knowingly collect personal information related to children. Our services are not aimed at children.
Cookies and other technologies used
This website uses cookies. We use cookies to personalize content and ads, provide social media features, and analyze our traffic. Cookies are small text files that can be used by websites to make the user experience more efficient. The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies.
We use cookies for the following purposes:
Necessary cookies: These cookies are necessary to use certain important features on our website, such as login. These cookies do not collect any personal information.
Functional cookies: These cookies provide features that make using the service more convenient and enable more personalized functionalities. For example, they may remember your name and email in comment forms so that you don’t have to re-enter this information in subsequent comments.
Analytical cookies: These cookies are used to track the usage and performance of my website and services.
You can remove cookies stored on your computer through your browser settings. Disabling some cookies may prevent certain functions of the website from working properly. Alternatively, you can control some third-party cookies using a privacy enhancement platform such as optout.aboutads.info or youronlinechoices.com/it. For more information about cookies, visit allaboutcookies.org. I use Google Analytics to measure traffic to this site. Google has its own Privacy Policy, which you can review here. To opt out of Google Analytics tracking, visit the Google Analytics opt-out page.
Data Controller and Data Processors
The Data Controller pursuant to the General Data Protection Regulation (GDPR), other applicable data protection laws in the EU member states, and other data protection provisions is SurfChimica Srl, Via Milano 6/6, 20068 Peschiera Borromeo (MI), Tel. +39 2 55308374, Email: contatti@surfchimica.it, Website: www.surfchimica.it.
Data Processors: The Data Processors, in addition to the web hosting service, include all third-party services on this website that, based on a specific contract, process data on behalf of the controller. All third-party services used on this website are located within the European Economic Area and comply with European standards. In particular, the following third-party services are appointed as Data Processors under this privacy policy as they process personal data on this site due to a specific contract:
– Web hosting Aruba
– Google Analytics.
Changes to this Privacy Policy
We reserve the right to make changes to this Privacy Policy. The last modification was made on May 25, 2018.