DESTINATIONS
INSIGHTS

Privacy Policy

 

This Privacy Policy is made pursuant to Art. 13 of the European Regulation No. 679/2016 and applies exclusively to all Data collected through the Website www.epicitaly.cc This Privacy Policy is subject to updates that will be published on the Website punctually. This Privacy Policy and the Cookie Policy, set out the basis on which the Personal Data of the Data Subject will be processed.

This document contains a section dedicated to Users in Switzerland and their privacy rights.

Data Controller

The Data Controller of the Data collected from this Website is VAT 000000000, email: info@epicitaly.cc.

Platform

The Website is built on a WordPress platform which is intended to host and operate key components of the Website. These platforms can provide analytical tools, user registration management, comment and database management, e-commerce, payment processing, etc. The use of these tools involves the collection and processing of Personal Data. Some of these services operate through servers located geographically in different places, making it difficult to determine the exact location where Personal Data is stored.

Personal Data

Personal Data means any information concerning an identified or identifiable natural person (Data Subject). An identifiable natural person is any natural person who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier, one or more characteristic elements of his or her physical identity.

Category of Personal Data processed

The Personal Data processed by this Website, either autonomously or through third parties, include Common Data such as: Cookies, Usage Data, Contact Data including name, e-mail, telephone number, billing address; Personal Data including CF and billing data; marketing preferences and cookies.

Methods of Personal Data Processing

The Personal Data provided or acquired will be processed in accordance with the principles of correctness, lawfulness, transparency and protection of confidentiality in accordance with current legislation. The Data Controller processes the Users’ Personal Data by adopting appropriate security measures aimed at preventing unauthorised access, disclosure, modification or destruction of Personal Data. The Processing is carried out by means of computer and/or telematic tools, with organisational methods and logics strictly related to the purposes indicated.

Purpose of the Processing of Personal Data and Legal Basis

Personal Data may be collected autonomously by the Controller or through third parties. In this case, the computer systems and software procedures in charge of the functioning of this Website acquire certain Personal Data of the Users, of a technical-informatics nature (e.g. IP address, type of browser used, operating system, domain name and addresses of websites from which access or exit was made, etc.), the transmission of which is inherent to the normal functioning of the Internet. Such Data may be processed for the sole purpose of obtaining anonymous statistical information on the use of the site and/or to check its correct functioning and will be deleted immediately after processing.

The Data that the Data Subject chooses to voluntarily provide will be processed in compliance with the conditions of lawfulness pursuant to art. 6 GDPR and will be processed to allow the Website to provide its services, as well as for the Purposes indicated below and will be kept for the time necessary to fulfil the aforesaid Purposes.

1) Responding to requests and providing Information

The Data shall be processed in order to be contacted or to follow up on specific requests made to the Controller by the Data Subject for communications of a nature relating to the Services and/or Contents of the same Controller, by e-mail or other communication tools such as telephone or instant messaging WhatsApp Business or through Active Campaign.

Legal basis: this processing is optional and based on the consent of the Data Subject, however, the provision of the Data is necessary for the pursuit of the indicated purpose.

Period of data retention: until consent is revoked by the Data Subject.

2) Information and pre-contractual fulfilments

The Data shall be processed in order to be contacted or to follow up on specific requests made to the Data Controller by the Data Subject for communications of an informative nature and/or for information regarding the purchase of the Data Controller’s Services, by means of e-mail messages or by filling in the Contact Form and other communication tools such as telephone or WhatsApp Business instant messaging or through Active Campaign.

Legal basis: this processing is optional and based on the consent of the Data Subject, however, the provision of the Data is necessary for the pursuit of the indicated purpose.

Period of data retention: until revocation of consent by the Data Subject.

3) Processing necessary within the framework of a contract

The Data shall be processed in order to fulfil the obligations deriving from the contract entered into between the Data Subject and the Controller for the sale of the Services on the Website, to contact the Data Subject in relation to the Contract and for the management of the same, for the management of requests for legal guarantees, assistance, requests for withdrawal, management and termination of the Contract

Legal basis: this processing is necessary for the performance of the Contract to which the Data Subject is party, for the execution of pre-contractual measures or to comply with a legal obligation to which the Data Controller is subject.

Data retention period: 10 (ten) years or other legal obligation.

4) Fulfilment of any legal obligations

The Data shall be processed in order to fulfil any type of obligation contemplated and provided for by current laws, regulations, related rules, business practices and tax/fiscal matters, including also for the purposes provided for by the anti-money laundering legislation Legislative Decree no. 231/2007 and subsequent amendments.

Legal basis: this processing is necessary to fulfil a legal obligation to which the Data Controller is subject.

Period of data retention: 10 (ten) years or other legal obligation.

5) Soft spam

The Data shall be processed to allow the Data Controller to send by e-mail to the Data Subject commercial and promotional communications having as their object Services similar to the Services being sold without the need for the express and prior consent of the Data Subject, as provided for in Article 130, paragraph 4, Privacy Code as amended by Legislative Decree no. 101 of 2018, and provided that the Data Subject does not exercise the right to object.

Legal basis: this processing is based on the legitimate interest of the Data Controller pursuant to Article 6(F) and Recital No. 47 of the GDPR.

Period of data retention: until the Data Subject objects.

6) Newsletter

The Data shall be processed for sending communications and promotional, commercial and advertising material or relating to initiatives and events of the Data Controller, through newsletters.

Legal basis: this processing is based on the consent freely expressed by the Data Subject pursuant to Article 6(1)(A) of the GDPR.

Period of data retention: until consent is revoked by the Data Subject by means of the specific tool at the foot of the newsletter or by request to the Data Controller.

7) Direct marketing

The Data shall be processed for direct sales of Products/Services, market research, sending of communications and promotional, commercial and advertising material or concerning initiatives and events, by e-mail and Whatsapp Business.

Legal basis: this processing is based on the consent freely expressed by the Data Subject pursuant to Article 6(1)(A) of the GDPR.

Data retention period: until the consent is revoked by the Data Subject.

8) Statistics

The Data shall be processed to perform statistical analysis on aggregate and anonymous data to analyse the behaviour of the Data Subject in order to improve the products and services provided by the Controller as well as to meet the Data Subject’s expectations.

Legal basis: this processing is based on the consent freely given by the Data Subject.

Period of data retention: until the consent is revoked by the Data Subject.

9) Profiling

Data will be processed for the analysis and evaluation of interests, habits, consumption choices, including the creation of profiles in order to be able to send personalised information and promotional material on the Services/Products offered by the Data Controller.

Legal basis: this processing is based on the consent freely expressed by the Data Subject pursuant to Article 6(1)(A) of the GDPR.

Period of data retention: until the consent is revoked by the Data Subject.

Communication of Data

In addition to the Data Controller, in some cases, the following may have access to the Data

a) categories of specially trained Data Processors involved in the organisation of the Website (administrative, sales, marketing, legal, system administrators);

b) external parties (such as third party technical service providers, hosting providers, IT companies, communication agencies) also appointed as Data Processors by the Data Controller pursuant to Art. 28 GDPR. The updated list of Data Processors, if appointed, can always be requested from the Data Controller;

c) public or private entities that can access the Data in compliance with legal obligations;

d) subjects that perform accessory and instrumental tasks with respect to the Controller’s activity;

Processing times

As expressly provided for by Art. 5, co. 1, letter e) of the GDPR, the Data are kept for the time necessary for the Processing of the same in relation to the performance of the service requested by the Data Subject, or required by the Purposes described above in this document. At the end of the retention period, the Personal Data will be deleted and therefore, the rights of access, deletion, rectification and portability of the Data can no longer be exercised.

Cookies

This Website uses cookies. Cookies are small text files that can be used by websites to make the experience more efficient for you and to personalise content and ads, provide social networking features and traffic analysis. Cookie Policy

Place of Processing and transfer of Data abroad

The Data are processed at the operational headquarters of the Data Controller. For further information, please contact the Data Controller. The Data may be processed by natural persons and/or legal entities operating on behalf of the Controller and under specific contractual obligations and based in EU or non-EU countries. In the event that the Data is transferred outside the EEA, the Data Controller will take all appropriate contractual measures to ensure adequate protection of the Data.

Exercise of the data subject’s rights

The Data Subject has the right to exercise the faculties provided for in Articles 7, 15-22 of European Regulation 679/2016. In particular, he/she has the right to revoke his/her consent at any time and, upon simple request to the Data Controller, he/she may request access to his/her Personal Data, receive the Personal Data provided to the Data Controller and, where possible, transmit it to another Data Controller without hindrance (so-called portability), obtain the updating, limitation of the processing, rectification of the Data and the deletion of the Data processed in breach of the applicable legislation. He/she has the right, for legitimate reasons, to object to the Processing of Personal Data concerning him/her and to the Processing for the purpose of sending advertising material, direct sales and for carrying out market research. He/she also has the right to lodge a complaint with the Garante della Privacy as supervisory authority for the protection of personal data or to take legal action. The data subject may exercise his/her rights by contacting the Data Controller by e-mail at: info@epicitaly.cc

 

Tools used for the Processing of Personal Data

CONTACT FORM

The Data Subject, by filling in the Contact Form with his/her Data, consents to the use of such Data to respond to requests for information, or any other purpose indicated by the header of the form. Personal Data collected through the Contact Form: Email, First Name and Last Name, Telephone

 

This website uses:

WhatsApp Business

WhatsApp Business is an instant messaging service provided by WhatsApp Ireland Limited. Please also refer to the WhatsApp Business Terms of Use which can be found at the following link: Click here

Your data will be transmitted to WhatsApp Business services under the terms that WhatsApp outlines in the ‘WhatsApp Business Terms of Service’ document at the following link: Click here

Personal Data collected: phone number, email, Usage Data, Cookie. Place of Processing: Ireland- Privacy Policy

ActiveCampaign (Active Campaign LLC)

ActiveCampaign, LLC (’ ActiveCampaign “) provides a newsletter platform that enables Data Controllers to reach out to their customers, understand how they interact with such communications and other content, and tailor marketing to their customers” interests. The Data Subject may choose at any time to unsubscribe from the newsletter by clicking on a specific unsubscribe button that he or she will find within the emails. After clicking on the unsubscribe button his Data will be deleted immediately from the software. Personal Data collected: Email and Name. Place of Processing: USA – Privacy Policy

EMAIL ADDRESS MANAGEMENT

These services allow the management of a database of email contacts, telephone contacts or contacts of any other kind used to communicate with the Data Subject. These services may also allow the collection of data relating to the date and time of viewing of messages by the Interested Party, as well as the interaction of the Interested Party with them, such as information on clicks on links inserted in messages.

Newsletter

By registering for the newsletter, the email address of the Data Subject is automatically included in a list of contacts to whom email messages containing information, including of a commercial and promotional nature, relating to this Website may be sent. The Data Subject’s email address may also be added to this list as a result of registering with this Site or after making a purchase. The Interested Party may choose at any time to unsubscribe from the newsletter by clicking on a specific button that he/she will find within the emails. After clicking on the unsubscribe button the Data Subject’s Data will be immediately deleted from the ‘email marketing’ software. Personal Data collected: email and Name. This Website uses the newsletter service provided by:

ActiveCampaign (Active Campaign LLC)

ActiveCampaign, LLC (’ ActiveCampaign “) provides a newsletter platform that enables Data Controllers to reach their customers, understand how they interact with such communications and other content, and tailor marketing to their customers” interests. The Data Subject may choose at any time to unsubscribe from the newsletter by clicking on a specific unsubscribe button that he or she will find within the emails. After clicking on the unsubscribe button his Data will be deleted immediately from the software. Personal Data collected: Email and Name. Place of Processing: USA – Privacy Policy

INTERACTION WITH SOCIAL NETWORKS

These services allow interactions with social networks directly from the pages of this Website. The interactions and information acquired by this Website are, in any case, subject to the privacy settings of the Data Subject for each social network. If a social network interaction service is installed, it is possible that the service collects traffic data relating to the pages where it is installed, even when Users do not use the service.

Facebook (Meta Platforms, Inc.)

The Facebook buttons are interaction services with the Facebook social network, provided by Meta Platforms, Inc. Personal Data collected: Cookies and Usage Data. Data processing location: Ireland – Privacy Policy

Instagram (Meta Platforms, Inc.)

The Instagram buttons are interaction services with the Instagram social network, provided by Meta Platforms, Inc. Personal Data collected: Cookies and Usage Data. Data processing location: Ireland – Privacy Policy

LinkedIn (LinkedIn Ireland Unlimited Company)

The LinkedIn buttons are interaction services with the LinkedIn social network, provided by LinkedIn Corporation. Personal Data collected: Cookies and Usage Data. Data processing location: Ireland – Privacy Policy

TikTok (TikTok Technology Limited)

The TikTok buttons are interaction services with the TikTok social network provided by TikTok Technology Limited. Personal Data collected: Cookies and Usage Data. Data processing location: Ireland – Privacy Policy

REMARKETING AND RETARGETING

These services allow this Website to communicate, optimise, and serve advertisements based on the past use of this Website by the Data Subject. This activity is carried out through the tracking of Usage Data and the use of Cookies. This Website uses the following services:

Facebook Remarketing (Meta Platforms, Inc.)

Facebook Remarketing is a remarketing and behavioural targeting service provided by Facebook, which connects the activity of this Website with Facebook’s advertising network. This Website uses the Facebook Pixel tool to measure conversions. Through the Facebook Pixel, it is possible to understand the actions people take on the Website. The data collected can be used to:

– Ensure ads are shown to the right people;

– Create audiences for ad targeting;

– Leverage other advertising tools offered by the platform.

The information collected is anonymous to the operators of this Website and cannot be used to identify an individual Data Subject. However, the information is saved and analysed by Facebook, which may link it to a specific profile and use it for its own advertising purposes, as outlined in Facebook’s privacy policy. This allows Facebook to display ads both on Facebook and on third-party sites. The Owner of this Website has no control over how this data is used. For more information on how users can protect their privacy, please refer to Facebook’s Privacy Policy.

CONTENT ON EXTERNAL PLATFORMS

These services allow the display of content hosted on external platforms directly from the pages of this Website and the interaction with them. If a service of this type is installed, it is possible that, even if Users do not use the service, it collects traffic data related to the pages where it is installed.

This Website uses:

YouTube (Google Ireland Limited)

YouTube is a video content display service managed by Google that allows this Website to integrate such content into its own pages. Personal Data collected: Cookies and Usage Data. Data processing location: Ireland – Privacy Policy

Changes to this Privacy Policy

The Data Controller reserves the right to make changes to this Privacy Policy at any time by giving notice to Users on this page. Therefore, it is recommended to check this page frequently, referring to the date of the last modification indicated at the bottom. In the event that the changes are not accepted, the Data Subject is required to stop using this Website and may request the Data Controller to remove their Personal Data. Unless otherwise specified, the previous Privacy Policy will continue to apply to Personal Data collected up to that point. The Data Controller is not responsible for updating all the links displayed in this Privacy Policy, so whenever a link is not functioning and/or updated, Users acknowledge and agree that they must always refer to the document and/or section of the websites referred to by such link.

Privacy Policy updated as of October 2024.