Privacy Policy of www.dicastello.it
This Application collects some Personal Data of its Users.
Data Controller
Di Castello s.r.l. – Via Provinciale per Brinzio 4, 21030 Castello Cabiaglio (VA) IT
Email address of the Data Controller: info@dicastello.it
Types of Data Collected
Among the Personal Data collected by this Application, either independently or through third parties, there are: Tracking Tools; usage data; name; email.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application.
Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to provide them, it may be impossible for this Application to provide the Service. In cases where this Application indicates certain Data as optional, Users are free to refrain from providing such Data, without affecting the availability or functionality of the Service.
Users who have doubts about which Data is mandatory are encouraged to contact the Data Controller.
The possible use of Cookies – or other tracking tools – by this Application or by third-party service providers used by this Application aims to provide the Service requested by the User, along with other purposes described in this document and the Cookie Policy.
The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Application.
Methods and Location of Data Processing
Processing Methods
The Data Controller takes appropriate security measures to prevent unauthorized access, disclosure, alteration, or destruction of Personal Data.
Processing is carried out using IT and/or telematic tools, with organizational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the organization of this Application (administrative, commercial, marketing, legal staff, system administrators) or external parties (such as third-party service providers, postal couriers, hosting providers, IT companies, communication agencies) may have access to the Data, appointed, if necessary, as Data Processors by the Data Controller. The updated list of Processors can always be requested from the Data Controller.
Location
The Data is processed at the operational offices of the Data Controller and in any other place where the parties involved in the processing are located. For further information, contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain more information about the location of the processing, the User may refer to the section on details regarding the processing of Personal Data.
Purposes of the Data Processing
The User’s Data is collected to allow the Data Controller to provide the Service, fulfill legal obligations, respond to requests or enforce actions, protect its rights and interests (or those of Users or third parties), detect fraudulent or malicious activities, as well as for the following purposes:
- Statistics
- Display of content from external platforms
- Contact the User
- Interaction with social networks and external platforms
- Hosting and backend infrastructure
For detailed information on the purposes of processing and the Personal Data processed for each purpose, the User can refer to the section “Details on the Processing of Personal Data.”
Details on the Processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
- Contacting the User
- Hosting and backend infrastructure
- Interaction with social networks and external platforms
- Statistics
- Display of content from external platforms
Cookie Policy
This Application uses Tracking Tools. To learn more, Users can refer to the Cookie Policy.
Additional Information for Users in the European Union
This section applies to all users in the European Union, in accordance with the General Data Protection Regulation (GDPR), and, for such Users, replaces any conflicting or divergent information contained in the privacy notice.
Legal Basis for Processing
The Data Controller processes Personal Data relating to the User if one of the following conditions is met:
- The User has consented to one or more specific purposes.
- The processing is necessary for the performance of a contract with the User and/or for the execution of pre-contractual measures.
- The processing is necessary to fulfill a legal obligation to which the Data Controller is subject.
- The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller.
- The processing is necessary for the pursuit of the legitimate interest of the Data Controller or a third party.
It is always possible to request the Data Controller to clarify the actual legal basis of each processing, particularly to specify whether the processing is based on the law, a contract, or necessary to conclude a contract.
Details on Retention Period
Unless otherwise specified in this document, Personal Data is processed and stored for the time necessary to achieve the purpose for which it was collected and may be retained for a longer period due to legal obligations or based on the User’s consent. Therefore:
- Personal Data collected for purposes related to the execution of a contract between the Data Controller and the User will be retained until the completion of that contract.
- Personal Data collected for legitimate interest purposes of the Data Controller will be retained until that interest is fulfilled. The User can obtain more information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
- When processing is based on the User’s consent, the Data Controller may retain Personal Data longer until that consent is revoked. Additionally, the Data Controller may be required to retain Personal Data for a longer period to fulfill a legal obligation or by order of an authority.
At the end of the retention period, the Personal Data will be deleted. Therefore, once this term expires, the rights to access, deletion, rectification, and data portability can no longer be exercised.
User Rights Under the General Data Protection Regulation (GDPR)
Users can exercise certain rights regarding the Data processed by the Data Controller. In particular, within the limits set by the law, the User has the right to:
- Withdraw consent at any time. The User can withdraw their previously given consent to the processing of their Personal Data.
- Object to the processing of their Data. The User can object to the processing of their Data when it occurs on a legal basis other than consent.
- Access their Data. The User has the right to obtain information about the Data processed by the Data Controller, about certain aspects of the processing, and to receive a copy of the processed Data.
- Verify and request correction. The User can verify the correctness of their Data and request its update or correction.
- Obtain the restriction of processing. The User can request the restriction of the processing of their Data. In this case, the Data Controller will not process the Data for any purpose other than its storage.
- Obtain the deletion or removal of their Personal Data. The User can request the deletion of their Data by the Data Controller.
- Receive their Data or have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to transfer it without hindrance to another controller.
- Lodge a complaint. The User can file a complaint with the competent personal data protection authority or take legal action.
Users have the right to obtain information regarding the legal basis for the transfer of Data abroad, including to any international organization governed by international law or constituted by two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect their Data.
Details on the Right to Object
When Personal Data is processed in the public interest, in the exercise of official authority vested in the Data Controller, or for the pursuit of the legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.
Users should be informed that, where their Data is processed for direct marketing purposes, they may object to the processing at any time, free of charge, and without providing any reason. If Users object to the processing for direct marketing purposes, Personal Data will no longer be processed for those purposes.
How to Exercise Rights
Requests to exercise the User’s rights can be addressed to the Data Controller via the contact details provided in this document. The request is free of charge, and the Data Controller will respond as quickly as possible, in any case, within one month, providing the requested information to the User.
Changes to this Privacy Policy
The Data Controller reserves the right to make changes to this Privacy Policy at any time by publishing the updated version on this page. The User is encouraged to consult this page regularly, referring to the last modified date indicated at the bottom. If the changes concern processing based on the User’s consent, the Data Controller will collect the User’s consent again if necessary.
Last modified: March 14, 2025
DEFINITIONS AND LEGAL REFERENCES
Personal Data (or Data)
Personal data refers to any information that, directly or indirectly, including in connection with any other information, such as a personal identification number, identifies or can identify a physical person.
Usage Data
Information collected automatically by this Application (including from third-party applications integrated into this Application), such as: IP addresses or domain names of the computers used by the User connecting to this Application, URI addresses (Uniform Resource Identifier), request times, methods used to send requests to the server, file size obtained in response, numerical code indicating the status of the server’s response (success, error, etc.), the country of origin, browser and operating system features used by the visitor, various time-related aspects of the visit (e.g., time spent on each page), and details about the path followed within the Application, especially the sequence of pages visited, parameters related to the operating system, and the User’s IT environment.
User
The individual using this Application, unless otherwise specified, coincides with the Data Subject.
Data Subject
The physical person to whom the Personal Data relates.
Data Processor (or Processor)
The natural or legal person, public authority, agency, or other body that processes personal data on behalf of the Data Controller, as described in this privacy policy.
Data Controller (or Controller)
The natural or legal person, public authority, service, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data and the tools adopted, including the security measures related to the operation and use of this Application. Unless otherwise specified, the Data Controller is the owner of this Application.
This Application
The hardware or software tool through which the User’s Personal Data is collected and processed.
Service
The service provided by this Application as defined in the relevant terms (if any) on this site/application.
European Union (or EU)
Unless otherwise specified, any reference to the European Union in this document refers to all current member states of the European Union and the European Economic Area.
Cookies
Cookies are Tracking Tools consisting of small portions of data stored inside the User’s browser.
Tracking Tool
A Tracking Tool is any technology (e.g., Cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting) that allows tracking of Users, such as collecting or storing information on the User’s device.
Legal References
Unless otherwise specified, this privacy policy pertains only to this Application.