Information on website users personal data processing according to EU Regulations (UE) 2016/679.
This informative document, released in compliance with that which is provided in art.13 of EU Regulations 2017/679 (GDPR) and Legislative Decree n.196/2003 as amended by the Legislative Decree n. 101/2018, contains the description of the operations carried out on the personal data of the Users collected during the access, navigation and use of this Internet site (https://www.24bottles.com/, below called the Website) as well as during the consultation of other web sites using links found on the same Site.
1. The data controller
2. Data processing location
3. Types of processed data
5. Cookies used by the website
6. Processed information and personal data
7. Management of the information requests – contact us
8. Management of the information requests – corporate gifts
9. Reception of open and/or spontaneous candidatures for working positions
10. Becoming a 24Bottles retailer – sponsorship 11. Subscribing to the 24bottles newsletter
12. Registration, access and management of the personal area – my account
13. E-commerce service management
14. Social plug-in
15. Processing modes
16. Categories of subjects to whom data can be communicated (receivers)
17. Data subject rights
1. The data controller
Design24 Società Benefit S.r.l. (Limited Liability Company), with headquarters in via Arturo Toscanini, 9, 40055 Villanova di Castenaso (BO), is the Data Controller of the personal data of the Users collected during the use of this website’s services. Design24 Società Benefit S.r.l. will deal the personal data of whom it will enter into contact according to principles of lawfulness, correctness and transparency, as well as the lawful and regulatory provisions for the following purposes:
– Access to the website and navigation;
– Management of the requests for information – Contact Us
– Management of the requests for information – Corporate Gifts;
– Registration to the 24Bottles newsletter; – Registration, access and management of the restricted areas;
– Management of the eCommerce service;
2. Data processing location
The data processing connected to the web services of this internet site is carried out in the above-mentioned legal headquarters of the Data Controller and in the hosting Company who supplies the service with server located in the EU.
3. Types of processed data
The IT systems and the software procedures needed to operate this web site acquire certain personal data, as part of their standard functions, whose transmission is implicit in the use of Internet communication protocols. This information hasn’t been collected to be associated to identified interests, but due to their nature, they could permit the identification of the User, through elaborations and associations with data held by third parties. The data that is part of this category are IP addresses or dominion names of computers used by the User who is connected to the website, the URI addresses URI (Uniform Resource Identifier) of the requested resources, the time of the request, the method used when making the request to the server, the dimension of the file obtained as an answer, the numerical code identifying the status of the server’s answer (successful, error, etc.) and other parameters related to the operating system and to the User’s IT environment. This data is only used to obtain anonymous statistical information on the use of the website and in order to control correct operations and is cancelled immediately following elaboration. The data could be used for the assessment of responsibility in case of IT crimes damaging the website or the Data Controller: except for this possibility, the data on the web contacts is not stored beyond the legal terms.
Data supplied voluntarily by the User
The optional, specific and voluntary sending of emails to the addresses indicated in this website involves the subsequent acquisition of the address of the sender by Design24 Società Benefit S.r.l., as it is needed to answer requests, as well as any eventual other personal data inserted in the communication. Specific informative data will be brought back or visualized in the pages of the website provided for specific services.
What is a cookie?
Cookies are short rows of text that are unloaded and inserted in the User’s device when he visits a website. At every subsequent visit, the cookies are sent back to the website where they came from (first party cookie) or to another website that recognises them (third party cookie). Cookies are useful because they allow the website to recognize the User’s device. They have various purposes such as, for example, allowing the User to navigate efficiently through the web pages, to remember his favourite websites and, in general terms, to improve the navigation experience. They also contribute to guaranteeing that online publicity is targeted towards the personal requirements of the User and his interests.
Types of cookies
Cookies can be first or third party. “First party” cookies refer to the host website domain, while “third party” cookies refer to external domains. Third party cookies are necessarily installed by an external subject, always defined as third party, and not managed by the website.
Nature of the cookies
These cookies are used to accomplish the navigation or to supply a service requested by the User. They are not used for any other purpose and are usually installed directly by the website of Data Controller. They can be divided in:
– Navigation or session cookies, that guarantee normal navigation and use of the website (allowing the User to be recognised to access restricted areas, for example); they are in fact necessary for the correct operation of the website; – Cookie analytics of third parties, assimilated to technical cookies when used directly by the website Data Controller to collect information, in anonymous and aggregated form, on the number of Users and how they visit the website, to improve the performance of the website;
– Functionality cookies, that allow the User to navigate according to a series of selected criteria (for example, the language, the products selected for purchase) to improve the service rendered to the User. Previous User consent is not requested for the installation of these cookies The above cookies can be:
– Temporary, when they are automatically cancelled at the end of the connection of the User; – Permanent, when they remain in the memory of the User’s device, unless the User deletes them voluntarily.
We inform the User that it is possible to manage and deactivate the cookies directly from the browser settings:
o MS Internet Explorer (https://support.microsoft.com/it-it/help/17442/windows-internet-explorer-delete-manage-cookies)
MS Edge: (https://privacy.microsoft.com/it-it/windows-10-microsoft-edge-and-privacy)
This website occasionally uses these cookies, which allow you to aggregate behavioral navigation data in order to optimize web pages. These data are purchases in anonymous form. For more information on HotJar’s policies, visit the link:
|Tredoom||1. By preferences (type language settings)|
2. Statistical data on site visits (n. Views)
3. Cookies for targeted advertising
|Stripe||1. To use own services (authentication, fraud prevention, site functions)|
2. Analysis and improvement of services
3. Targeted advertising
|Paypal||1. Functioning services|
2. Performance evaluation (to improve the payment flow)
3. Saving user identification and / or preferences
4. Targeted advertising
Links verified and active on 10.06.2019.
5. Cookies used by the website
Technical navigation cookies or session cookies strictly necessary for the functioning of the website or to enable the user to exploit the requested content and services:
|JSESSIONEID||Maintains the user settings during navigation||session|
|CONSENT||Stores the user’s preferences and information every time he or she visits web pages containing Google services||20 years|
|NID||Stores the user’s preferences and information every time he or she visits web pages containing Google services||2 month|
|1P_JAR||Stores the user’s preferences and information every time he or she visits web pages containing Google services||1 month|
|PHPSESSID||Maintains the user settings during navigation||Session|
|wordpress_test_cookie||A WordPress test cookie that checks whether the browser is enabled to save cookies.||Session|
|cbwpt_cookie_consent||Blocks cookies generated by third party services beforehand, so there is no need to block and unblock each individual code manually after the visitor has given consent. The procedure is automated.||12 months|
|woocommerce_cart_hash||Helps WooCommerce to determine when the shopping cart contents and/or data change.||Session|
|woocommerce_items_in_cart||Helps WooCommerce to determine when the shopping cart contents and/or data change.||Session|
|wp_woocommerce_session_||Contains a unique code for every customer so that it knows where to find shopping cart data in the database for each customer.||2 days|
|woocommerce_recently_viewed||Brings up the recently viewed products widget.||Session|
|store_notice[notice id]||Enables customers to ignore the store notice.||Session|
Functionality cookies, which enable users to navigate on the basis of a series of selected criteria in order to improve the service provided to them.
|wordpress_test_cookie||This is a WordPress test cookie that checks whether the browser is enabled to save cookies or not.||session|
|woocommerce_recently_viewed||Feed the Recent Displayed Products widget.||session|
Analytics third-party cookies (anonymized): “analytics cookies” where used directly by the website operator to collect information, in aggregated form, on the number of users and how they visit the website, navigation or session cookies.
|_utma||Distinguishes visitors and their respective sessions.||2 years|
|__utmc||User leaving rate (approximate value) – necessary for the Google Analytics third party service.||Until the end of navigation|
|_utmv||Used to store visitor-level custom variable data. This cookie is created when a developer uses the _setCustomVar method with a visitor level custom variable. The cookie is updated every time data is sent to Google Analytics.||2 years from set|
|_ga||generation of statistics on use of the website||2 years|
|_gid||Used to distinguish users||1 day|
|_gat||Used to throttle the request rate.||1 minute|
|_fbp||Used by Facebook to deliver a series of advertisement products such as real-time bidding from third party advertisers.||3 months|
|_fbp||Used by Facebook to provide a series of advertising products as offers in real time by third party advertisers.||3 months|
|CONSENT||Memorize your preferences and information every time you visit web pages containing Google services||20 years|
|NID||Memorize your preferences and information every time you visit web pages containing Google services||6 months|
|1P_JAR||Memorize your preferences and information every time you visit web pages containing Google services||1months|
6. Principles that can be applied to data processing by Design24 Società Benefit S.r.l..
7. Processed information and personal data
By means of the functions found in the website of Design24 Società Benefit S.r.l., the User can grant his own personal information and thus become identifiable and so it can be processed in order to manage the Users’ requests. Among the information that can be requested, including but not limited to, there is personal data such as: – Name and Last name – Home address for shipment and invoicing of the orders carried out by the User – Details on the orders, such as the history of the shipped orders – Telephone Number – E-mail address – The type of Browser and IP address of the device used – The pages visited by the User – The time and date in which the User visited the website
8. Management of the information requests – contact us
Design24 Società Benefit S.r.l. will process the personal data of the Users who fill in the online form to ask for information on the services and products offered, the state of the orders, and all other User requests to manage, to find and to reply to all User requests. The data will be recorded, kept and used exclusively to manage and to reply to the requests and for the time needed to fulfil the above-mentioned purposes. The legal base of this processing is the consent given by the User. The granting of these data for these processing purposes is optional. However, the lack, partial or inexact granting of these data could make it impossible for Design24 Società Benefit S.r.l. to manage and to answer the Users’ requests.
9. Management of the information requests – corporate gifts
Design24 Società Benefit S.r.l. will process the personal data of the Users who fill in the online form to ask for information on the Corporate services and products offered by the Data Controller, in order to manage, to find and to reply to all User requests. The User can also grant additional information (such as Company logo, personalised description, Country). This additional data will be processed by Data Controller in compliance with existing legislation. The data will be recorded, kept and used exclusively to manage and to reply to the requests and for the time needed to fulfil the above-mentioned purposes. The legal basis of this processing is the implementation of pre-contractual measures and/or the implementation of a contract of which the User is a party. The granting of these data for these processing purposes is optional. However, the lack, partial or inexact granting of these data could make it impossible for Design24 Società Benefit S.r.l. to manage and to answer the Users’ requests.
10. Reception of open and/or spontaneous candidatures for working positions
The Data Controller will manage the Users’ personal data contained in the C.V. spontaneously sent by the User or following a recruiting campaign, promoted by the Data Controller, to manage the selection of new staff and for the assessment of the candidate. Data will be retained for the period that is strictly necessary to the fulfilment of the purpose and conserved for a period of 2 years from the moment of reception of the CV. The legal basis that legitimates this processing is the implementation of pre-contractual measures, according to art. 111-bis of Legislative Decree n. 196/2003, as amended by Legislative Decree n. 101/2018, and in art. 6 letter b) of EU Regulations 2016/679, where the Data Subject’s consent is not mandatory. The granting of this data for this processing purpose is optional. However, the lack, partial or inexact granting of personal data could involve the impossibility for the Data Controller to receive the candidature and to assess the compliance with the desired working profile.
11. Becoming a 24Bottles retailer – sponsorship
The Data Controller will use the personal data and information requested during the compilation of the online form to organise, manage and assess possible Distributors of 24Bottles products worldwide. This data and information will be used by Design24 Società Benefit S.r.l. to manage pre-contractual negotiations with the potential Retailer and for the time necessary for the achievement of this purpose. The legal basis which legitimates the treatment of collected data is the implementation of pre-contractual measures in order to take steps at the request of the data subject prior to entering into a contract. The granting of this data is optional. However, the lack, partial or inexact granting of data could involve the impossibility for Design24 Società Benefit S.r.l. to manage and reply to potential Retailers requests.
12. Subscribing to the 24bottles newsletter
Design24 Società Benefit S.r.l. will process personal data (email address) of the Users who insert their email address in the specific form for the registration to the 24Bottles newsletter that contains informative and promotional content. These data will be registered, retained and used exclusively for the registration of the Data Subject to the Data Controller newsletter. The legal basis of this treatment is the consent of the data subject released by ticking the checkbox at the bottom of the contact form. Data will be processed until the withdrawal of the consent and/or the exercise of the right of opposition by the Data Subject (unsubscribe / opt-out).
13. Registration, access and management of the personal area – my account
Design24 Società Benefit S.r.l. will process Users’ personal data in order to allow the use of services reserved for the registered Users. The legal basis for this treatment is the implementation of the contract or, depending on the cases, the implementation of pre-contractual measures adopted upon the data subject request. For these purposes personal data will be processed for the time necessary for the development of single processing activities. Design24 Società Benefit S.r.l. can however conserve personal data for the purposes and for the maximum periods of conservation indicated in this informative document or in the cases established by the Regulations and/or the law. Design24 Società Benefit S.r.l. will process Users’ personal data in order to: – Allow the User to access the Website and navigate in it; – To allow the User to access the Website and to navigate as a logged User, recognising the User independently from the device used; – Maintain and manage the User’s account; – Memorise data and User information in the account (biographical data, order history, eventual returns, delivery addresses, payment forms). The granting of data for these purposes is optional and does not involve the impossibility for the User to proceed with online purchases. However, since the treatment is necessary in order to allow access to the Website and/or navigation as a logged User and/or the performance of management services and account maintenance, the lack of communication of this data will involve the impossibility for the customer to register, access the personal area of the Website and use the services reserved to registered Users.
14. E-commerce service management
Design24 Società Benefit S.r.l. will process Users personal data to allow them to purchase 24Bottles products online through the Website, in order to allow the conclusion of the purchasing contract and for the correct accomplishment of the obligations rising from this contract and, lastly, to reply to the eventual requests sent by the User during the purchasing procedure. Design24 Società Benefit S.r.l. will also process User data in order to fulfil the consequent legal obligations and administration-accounting procedures. It is possible to use different forms of payment to purchase 24Bottles products (credit cards or PayPal). Within the purchasing procedure the User must supply his financial information in order to complete the purchase and/or to request the emission of an invoice (VAT id, fiscal code, etc.) In order to proceed to the shipping of the product purchased online, the User shall also supply the requested information relating to his address (name, surname, shipping address, telephone number and email address). The legal basis for the aforesaid processing is the performance of a contract from Design24 Società Benefit S.r.l.. For these purposes the data will be processed for the time necessary for the development of single processing activities and not beyond 10 years from the time of purchase. If requested by specific regulations, the time of conservation of the data could be longer. The granting of data for this purpose is optional. However, the lack, partial or inexact granting of data will involve the impossibility for the Data Controller to carry out the online purchasing contract, and for the User to obtain the requested product(s).
15. Social plug-in
16. Processing modes
Personal data is and will be used with automatic tools for the time necessary to achieve the purposes for which it has been collected. Data is used by Authorised technical staff for the processing, duly instructed by Design24 Società Benefit S.r.l.. Specific emergency measures are observed in order to prevent personal data breach that means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
17. Categories of subjects to whom data can be communicated (receivers)
The Receivers to whom Design24 Società Benefit S.r.l. communicates personal data act as Data Processors, designated by the Data Controller older through specific contract, or as Authorised persons for the processing of personal data under the direct authority of the Data Controller. Processed data collected will not be diffused and/or transmitted in Countries outside the European Economic Area.
18. Data subject rights
The Data Subject Users of the Website have the right to:
• Obtain the access to personal data: the user has the right to obtain, from the Data Controller of the treatment, the confirmation that a treatment of personal data concerning the User is or not occurring and, in this case, access to the data. The access can concern the following information: o Processing purposes; o The categories of concerned personal data; o The receivers or the categories of receivers to which data has been or will be communicated, in particular if destined to third party countries or international organizations; o The period of conservation of personal data, or the criteria used in order to determine this period; o The existence of the right to request the correction or the erasure of data to the Data Controller, or the limitation of the treatment or the opposition to it; o The existence of an automated decisional process. • Rectification personal data: the Data Subject has the right to obtain the correction of inexact personal data, and to obtain the integration of incomplete personal data.
• Request to erasure personal data: for the reasons indicated in art. 17 GDPR, the Data Subject has the right to request the erasure of data without any unjustified delay to the treatment Data Controller and the Data Controller has the obligation to delete the Data Subject’s personal data.
• Right to restriction of processing: in the event in which one of the hypotheses of art. 18 GDPR occurs, the Data Subject has the right to request the limitation of his own data processing. • Data portability: the Data Subject has the right to receive his personal data supplied to a Data Controller, in a structured format, of common and readable use, and has the right to transmit this data to another Data Controller in case the processing was based upon consent and/or contract and is carried out by automatic means. • Request of opposition to the processing: the Data Subject has the right to oppose the processing of his personal data anytime, for reasons related to his own particular situation.
• Withdrawal of consent: the Data Subject has the right to withdraw his consent at any time. The Data Subject also has the right to lodge a complaint to the Italian Authority for the protection of personal data, firstname.lastname@example.org. The requests for the exercise of Data Subject rights can be addressed to email@example.com