PRIVACY POLICY

This Privacy Policy is defined on the basis of art. 13 of EU Regulation n. 679/2016 and applies only to all data collected through the https://ferrifirenze.myshopify.com/ website. The Site’s online store is hosted by Shopify Inc, which provides the online e-commerce platform that allows you to sell the Seller’s products. The following is the Privacy Policy and  Cookie Policy  Shopify. This Privacy Policy is subject to updates that will be posted on the website on time. The present Privacy Policy, as well as Terms and Conditions, any other documents referred to therein and the Cookie Policy, establishes the basis on which the user’s personal data will be processed.

Data Controller

The Data Controller of this website is FerriFirenze Srl, Sesto Fiorentino (FI) 50019, via A. Gramsci n. 456, email:  e-commerce@ferrifirenze.it


Methods of personal data processing

The personal data provided or acquired are subjected to a treatment based on principles of correctness, lawfulness, transparency and protection of privacy pursuant to current legislation. The Data Controller processes the user’s personal data adopting appropriate security measures to prevent unauthorized access, disclosure, modification or unauthorized destruction of personal data. Data are processed by means of IT and/or telematics tools, by implementing organizational methods and strategies that are connected to the purposes of the activity.

Purposes for processing the collected data and legal basis

Personal data can be collected autonomously by the Data Controller or by third party. In this case, the computer systems and software used by the website acquire certain user’s personal data, IT related (for example, the IP address, the browser used, the operative system, the domain name and the websites addresses from which you have accessed or exit, etc.), whose transmission is inherent to the correct functioning of Internet. Such data can be processed for the sole purpose of obtaining anonymous statistical information on the use of the website and/or controlling its correct functioning; after their processing, they are immediately erased. The data the user choses to provide spontaneously are collected to allow the website to provide its services and for the following purposes:

a) to fulfill any kind of obligation required by the contract made between the user and the Data Controller for the sale of the Products/Services offered on the website and to provide information required by the user. This processing is mandatory for the execution of the contract to which the User is a party, for the execution of pre-contractual measures or to fulfill a legal obligation to which the Data Controller is subject;

b) for a possible registration procedure aimed at the purchase of the Products/Services and for the purchase procedure needing the insertion of own personal data, tax billing profiles and the like. In that case, data are processed for the execution of the contract, to contact the user in relation to the contract and for its management, the management of statutory warranty claims, assistance, requests for withdrawal, management and termination of the contract. This processing is mandatory for the execution of the contract to which the User is a party;

c) to fulfill any kind of obligation required by current laws, regulations, associated regulations, commercial use and taxation/fiscal subjects. This processing is necessary for compliance with a legal obligation to which the Data Controller is subject;

d) for other additional purposes or related to that indicated above and falling within the sphere of the activities of the website;

e) to act on specific requests made by the user to the Data Controller for informative communications related to the Data Controller’s services by e-mail or filling in contact forms and using other communication tools like phone or instant messaging services like WhatsApp Business, Messenger live etc. This processing is optional, and it is based on the user’s consent, nevertheless, the non-reporting of one or more data will cause the impossibility of responding to the information request and of using the services offered by the Data Controller;

f) for sending information and promotional and commercial offers also through newsletter service, e-mail, mailbox or SMS. This processing is based on the consent freely expressed by the user;

g) for soft spam purposes to allow the Data Controller to send the user via e-mail promotional communication concerning Products and/or Services purchased without the need for the express and prior consent of the user, as required by art. 130, paragraph 4, Code of Privacy, and provided that the user does not exercise the right of opposition. This processing is based on art. 130, paragraph 4 of the Code of Privacy as told by Legislative Decree no.101 of 2018;

h) for carrying out statistical analysis on aggregated and anonymous data to analyse the user’s behaviour, improve the products and services provided by the Data Controller and meet the user’s expectations;

i) for profiling activities for marketing purposes. This processing is based on the consent freely expressed by the user;

 

Category of personal data processed

Among the personal data processed by this website, autonomously or by third party, there are common data like: Cookies, usage data, name, email, phone, countries, cities, tax data useful for purchasing and personal data useful for the delivery of the purchased product. The optional, explicit or voluntary transmission of emails by Contact Form or by the addresses specified on this website entails the successive acquisition of the sender’s address, which is necessary to answer the requests, and of any other personal data included in the email. The user’s consent to the provision of data is necessary to be inserted in the Data Controller’s database and in the interest of the establishment and correct functioning of what offered to users, as well as third party for the fulfilment of the single activity required. Therefore, failure to provide it will hinder the registration in the Data Controller’s database, the refinement of any contract, as well as their execution and that of any other activity. 

Data communication

In some cases, in addition to Data Controller, may have access to data:

a) categories of persons specifically trained involved in the organization of the website (administrative staff, commercial staff, marketing staff, lawyers, system administrators); 

b) external parties (like third party technical service providers, hosting provider, IT companies, communication agencies) also appointed as Data Processors by the Data Controller ex art. 28 GDPR. The updated list of Data Processors, if appointed, can always be requested from the Data Controller; 

c) public or private entities that can access the data in compliance with legal obligations;

d) subjects that perform instrumental tasks with respect to the activity of the Data Controller; 

Processing time

As expressly stipulated by art. 5, co. 1, lett. e) of the GDPR, data are stored for a period of time necessary to provide the service requested by the user, or for the time required for the purposes described in this document, particularly:

- The data collected for contractual obligations will be stored for the time necessary for the accomplishment of the mentioned purposes and in accordance with current legislation;

- The data collected for tax / administrative obligations will be stored for the time necessary for the accomplishment of the mentioned purposes and in accordance with current legislation;

- The data collected for purposes related to the legitimate interest of the Data Controller will be retained until such interest is met; the user can obtain more information regarding the Data Controller’s legitimate interest contacting him/her;

- The data collected based on the user’s consent can be stored until the withdrawal of the consent;

The Data Controller can store the data for a longer time in accordance with a legal obligation or by order of an authority.

At the end of the storing time, personal data will be deleted and consequently access rights, deletion rights, rectification rights and data portability rights can no longer be exercised.

 

Cookies

This website uses Cookies. They are small text files that may be used by websites to make the user’s experience more efficient, to customize contents and advertisements, to provide the functions of the social networks and analyze the traffic. Cookie Policy

 

Place of processing and transfer of data abroad

The data are processed at the Data Controller's operating office. For more information, contact the Data Controller. The data can be processed by natural persons and/or legal entities acting on behalf of the Data Controller, under specific contractual obligations and located in UE or non-UE countries. If the data are transferred outside the EEA, the Data Controller will adopt any contractual measure suitable to ensure an adequate data protection.

 

Tools used for personal data processing  

CONTACT FORM 

The user, filling in the contact Form with his/her data, agrees to their use to answer any request of information or any other purpose indicated by the form header. Personal data collected by the contact Form: email, name and surname.

 

Shopify (Shopify International Ltd)

This site uses the solutions offered by Shopify to create Contact Form. Personal Data collected: Email, Name and Surname. Place of data processing: Ireland - Privacy Policy

 

OTHER CONTACT TOOLS

 

WhatsApp (WhatsApp Ireland Limited)

WhatsApp is an instant messaging service provided by WhatsApp Ireland Limited. Personal data collected: telephone number, email, usage data, Cookies. Place of processing: Ireland - Privacy Policy

 

Snapchat (Snap Group Limited)

Snapchat sms is an instant messaging service provided by Snap Group Limited. Personal Data collected: phone number, mail, usage data, cookies. Place of processing: UK- Privacy Policy

 

EMAIL ADDRESSES MANAGING

These services permit to manage a database of email contacts, telephone contacts or contacts of any other type, used to communicate with the user. Furthermore, these services could permit to collect data related with user’s date and time of viewing of messages, as well as track user's interaction with them, such as information on clicks on the links included in the messages.

 

Newsletter 

By subscribing to the newsletter, the user's email address is automatically added to a list of contacts through Mail munch to which email messages containing information, including commercial and promotional information, relating to this website may be transmitted through other platform Seguno. The user’s email address might also be added to this list as a result of signing up to this website or after making a purchase. The user can choose at any time to unsubscribe from the newsletter by clicking on a specific button he/she will find within the emails. After clicking the button, the user’s data will be immediately deleted by the “email marketing” software. Personal data collected: email and name. This website uses the newsletter service offered by:

 

Mail munch (Six mix LLC)

Mail munch is a suite of services that organizes and analyses the distribution of newsletters. In case a User does not want their Data to be managed by AWeber, it will be necessary to cancel the subscription to the newsletter. For this purpose, a link is provided in each newsletter sent. Personal Data collected: email and name. Place of processing: USA - Privacy Policy

 

Seguno (Seguno Software, Inc.)

Seguno is an email marketing platform created for Shopify. Personal Data collected: email and name. Place of processing USA. Privacy Policy

 

SECURITY MEASURES ADOPTED 

This website has an SSL certificate and uses the HTTPS protocol to secure the moment your personal data is entered. By using this protocol, the transactions and the data transmission to the websites take place with maximum security and the content of the communication is not read or manipulated by third parties anyway.

 

reCAPTCHA

This website uses reCAPTCHA, a service subject to the privacy policy and Google terms and conditions.

 

REGISTRATION ON THE WEBSITE 

With the registration service the user allows the website to identify her/him and give her/him access to the services dedicated. Registration and authentication shall be carried out by

Shopify (Shopify International Ltd.)

This website uses the service offered by Shopify that allows the User to create a private area. Place of Treatment Ireland. For more information on the following permissions, the User can refer to the Privacy Policy

 

STATISTICS 

Statistics services allow the Data Controller only to monitor and analyze the traffic data and keep track of the user’s behaviour. This website uses the following services:

 

  1. Google Analytics (Google Ireland Limited)

Google Analytics is an analysis service offered by Google Ireland Limited. Google uses the collected personal data with the aim of tracking and examining the use of this website, compiling reports and sharing them with other services developed by Google. Google may use the personal data collected to contextualize and personalize notices on its advertising network. Google can also transmit this information to third parties in case there are any legal requirements or in cases where such third parties process the information on Google's behalf. On this website the function of anonymization of the IP address is active. The IP address transmitted by the browser for purposes connected to Google Analytics will not be embedded with other data that Google already possesses.

At the following link https://tools.google.com/dlpage/gaoptout?hl=it Google provides the Google Analytics Opt-Out Browser Add-on to disable tracking by Google Analytics. Personal data collected: Cookies and usage data. Place of processing: Ireland – Privacy Policy

 

Shopify (Shopify International Ltd.)

Conversion monitoring is a statistics service offered by Shopify that allows the Data Controller to monitor conversions of its customers. Personal Data collected: Cookies; Usage data. Place of processing: Ireland - Privacy Policy 

 

INTERACTION WITH SOCIAL NETWORKS 

These services allow to interact with social networks directly from the website pages. The interactions and information acquired by this website are subject to the user’s Privacy Policy of each social network. If a service for interaction with social networks is installed, the site may collect traffic data about the pages, even if users do not use the service.

 

  1. Facebook (Meta Platforms Inc.)

The Facebook buttons are services for interaction with Facebook, offered by Meta Platforms Inc. Personal data collected: Cookies and usage data. Place of processing: Ireland – Privacy Policy 

 

  1. Instagram (Meta Platforms Inc.)

The Facebook buttons are services for interaction with Instagram, offered by Facebook. Personal data collected: Cookies and usage data. Place of processing: Ireland – Privacy Policy

 

  1. Pinterest (Pinterest Europe Ltd)

The Pinterest buttons are services for interaction with Pinterest, offered by Pinterest, Inc. Personal data collected: Cookies and usage data. Place of processing: Ireland - Privacy Policy



  1. Snapchat (Snap Group Limited)

Pinterest buttons are interaction services provided by Snap Inc. Personal Data collected: Cookies and Usage Data. Place of Treatment: UK - Privacy Policy



REMARKETING E RETARGETING 

These services allow this website to communicate, optimize and serve advertising based on the past use of this website by the user. This activity is carried out by tracking of usage data and the use of Cookies. This website uses the following services:

 

  1. Facebook Remarketing (Meta Platforms Inc.)

Facebook Remarketing is a service of Remarketing and Behavioral Targeting offered by Meta Platforms Inc., that links the activity of this website with the Facebook advertising network. This website makes use of Facebook Pixel in order to measure conversions. Thanks to Facebook Pixel we can understand the actions people perform on this website. Data collected can be used for:

- making sure the ads are shown to the right people;

- creating public groups to use advertisements for;

- exploiting the additional advertising tools of the platform on which advertising is made.

Collected information is anonymous to the operators of this website and cannot be used to determine the identity of a single user. However, information is stored and analysed by Facebook, which might relate the action to a single profile and use this information for internal Facebook advertising purposes, as outlined by the Privacy Policy of Facebook. This will allow Facebook to show ads on both Facebook and third-party websites. The website owner does not have any control over the use of these data. For more information on how users can protect their privacy, refer to the Facebook Privacy Policy.

 

  1. Google ADS 

Google ADS is a service provided by Google Ireland Limited that links this website with the Google advertising network. This website makes use of the Remarketing functionalities of Google Analytics combined with the possibility of adaptation to different devices of Google ADS. This functionality allows to link target groups for promotional campaign created by the function Marketing of Google Analytics to the adaptability to different devices of Google ADS. This allows to show advertising based on the personal interests of the use, identified by means of an analysis of the user’s behaviour on the website, either on a mobile device or on other devices. It is possible to disable permanently the targeting and remarketing functions by disabling the function “personalized advertising” on the Google account. For doing this, follow this link: https://www.google.com/settings/ads/onweb/. Personal data collected: Cookies and usage data. Place of processing: Ireland – Privacy Policy 

 

  1. Api Conversions (Meta Platforms, Inc.)

API Conversions is a Facebook Business tool that allows advertisers to share customer actions from their server directly to Facebook. This tool can work in synergy with Facebook Pixels to help advertisers improve the performance, measurement and data collection of their Facebook advertising campaigns.

For more information on how users can protect their privacy, please refer to the Facebook Privacy Policy

 

  1. Instagram Remarketing (Meta Platforms Inc.)

Instagram Remarketing is a service of Remarketing and Behavioral Targeting offered by Meta Platforms Inc., that links the activity of this website with the Instagram advertising network. This website makes use of Pixel in order to measure conversions and understand the actions people perform on this website. Collected information is anonymous to the operators of this website and cannot be used to determine the identity of a single user. However, information is stored and analyzed by Facebook, which might relate the action to a single profile and use this information for internal Facebook advertising purposes, as outlined by the Privacy Policy of Facebook. For more information on how users can protect their privacy, refer to the Instagram Privacy Policy.

 

  1. Pinterest Ads (Pinterest Europe Ltd.)

Pinterest Ads is a Remarketing and Behavioral Targeting service provided by Pinterest Europe Ltd that connects the activity of this Website with the Pinterest advertising network. This Website makes use of the Pixel Tracking tool in order to measure conversions and understand the actions that people perform on the Website. For more information on how users can protect their privacy, please refer to the Pinterest Privacy Policy

 

  1. Snapchat advertising (Snap Group Limited)

Snapchat is a Remarketing and Behavioral Targeting service provided by Snap Inc. that connects the activity of this Website with the advertising network in order to measure conversions and understand the actions that people perform on the Website. For more information on how users can protect their privacy, please refer to the Privacy Policy.

 

PAYMENT MANAGEMENT

Payment processing services allow this website to process payments by credit card, bank transfer or other means. The data used for payment is acquired directly from the manager of the payment service requested without being in any way processed by this website. Some of these services may also allow for the scheduled sending of messages to the user, such as emails containing invoices or notifications regarding payment. This website uses the following services:

 

  1. Apple pay (Apple Inc.)

Apple Pay is a payment service provided by Apple, that allows the user to make online payments on websites and Apps that support it using an IPhone 6 and higher Apple Watch, Mac and iPad Air 2 and higher. Personal data collected: Cookies and different kinds of data as specified in the privacy policy of the service. Place of processing: California, the USA - Privacy Policy

 

  1. Google Pay (Google Ireland Limited)

Google Pay is a payment service provided by Google Ireland Limited, that allows the user to make online payments using her/his own Google account. Personal data collected: Cookies and different kinds of data as specified in the privacy policy of the service. Place of processing: Ireland – Privacy Policy

 

  1. Shop Pay (Shopify International Ltd.)

Shop Pay is an online payment service provided by Shopify International Ltd., that allows the user to register her/his own payment, shipping and invoicing data for fast check-out management on the Shopify platform. Personal data collected: different kinds of data as specified in the privacy policy of the service. Place of processing: Ireland - Privacy Policy

 

Exercise of the rights of the data subject

The data subject may exercise the rights as described in the artt. 7, 15-22 of the EU Regulation 679/2016.  In particular, the right to withdraw his/her consent in any time and, simply asking the Data Controller, he/she may request access to personal data, receive the personal data provided by the Data Controller and, where possible, transmit them to another Data Controller of the processing without impediment (c.d. portability), obtain the update, the limitation of the processing, the rectification of data and the deletion of that processed in contrast with current legislation. The data subject has the right, for legitimate reasons, to oppose the processing of personal data concerning him/her the processing for purposes of sending advertising materials, direct selling and market research. The interested party also has the right to lodge a complaint with the Privacy Authority in its quality of supervisory authority. The data subject may exercise the rights by emailing the owner at:  e-commerce@ferrifirenze.it

 

Changes to this Privacy Policy

The Data Controller reserves the right to make changes to this Privacy Policy at any time by giving notice to users on this page. Therefore, it is recommended to consult this page very often, taking as reference the date of last modification indicated at the bottom. In case of non-acceptance of the changes made to this Privacy Policy, the user is required to cease the use of this website and may request the Data Controller to remove their personal data. Unless otherwise specified, the previous Privacy Policy will continue to apply to personal data up to that date collected moment. The Data Controller is not responsible for the update of the links displayable in this Privacy Policy, therefore, every time a link does not work and/or is not updated, users acknowledge and accept that they must always refer to the document and/or the section of the linked websites.

 

Privacy Policy updated on December 2021

 

Cart

No more products available for purchase

Your Cart is Empty

More » Less «
  • List
  • Map