
PRIVACY POLICY
Personal data processed for the following purposes and using the following services:
Access to accounts on third-party services
Access to Facebook account
Permissions: Checkin; Contact email
Access to Twitter account
Personal Data: various types of Data as specified by the privacy policy of the service
Contacting the User
Contact by phone
Personal Data: phone number
Mailing list or newsletter
Personal Data: Cookie; email; name
Interaction with social networks and external platforms
Linkedin social button and widgets
Personal Data: Cookie; Usage Data
SPAM protection
Google reCAPTCHA
Personal Data: Cookie; Usage Data
Registration and authentication
Facebook Authentication, Instagram Authentication and Google OAuth
Personal Data: various types of Data as specified by the service's privacy policy
Direct Registration
Personal Data: Postcode; city; surname; email; User ID; language; country; VAT number; password; province; company name; workplace; username; various types of Data
Statistics
Google Analytics
Personal Data: Cookies; Usage Data
Transfer of Data outside the EU
Other legal basis for the transfer of Data to third countries, Transfer of Data from the EU and/or Switzerland to the US based on the Privacy Shield, Transfer of Data to countries that guarantee European standards, Transfer to third countries based on consent and Transfer to third countries based on standard contractual clauses
Personal Data: various types of Data
Display of content from external platforms
Google's programmable search engine
Personal Data: Cookies; Usage Data
Further information on the processing of Personal Data
Personal Data collected through sources other than the User
The Owner of www.draion.it may have legitimately collected Personal Data relating to the User without the User's involvement, drawing on sources provided by third parties, in accordance with the legal bases described in the section on the legal bases for processing.
If the Controller has collected Personal Data in such a way, the User can find specific information about the sources in the respective sections of this document or by contacting the Controller.
Identification of the User by means of a Universal Unique Identifier (UUID)
Www.draion.co.uk can track Users by saving a so-called ‘universal unique identifier’ (UUID) for statistical analysis purposes or to store User preferences. This identifier is generated with the installation of this Application, is not deleted when the Application is closed or updated, but is only permanently removed if the User decides to uninstall the Application from his/her device. If the Application is reinstalled, a new UUID is generated.
Contact Information
Data Controller
Studio Draion Professional Association
Piazza Toniolo, 5i - 56125 Pisa (IT)
Owner's email address: tecnico@draion.it
Full policy
Data Controller
Studio Draion Professional Association
Piazza Toniolo, 5i - 56125 Pisa (IT)
Owner's email address: tecnico@draion.it
Types of Data collected
Among the Personal Data collected by www.draion.it, either independently or through third parties, are: surname; username; email; password; company name; VAT number; country; province; postcode; city; place of work; various types of Data; User ID; language; telephone number; name; Cookie; Usage Data.
Full details on each type of Data collected are provided in the relevant sections of this privacy policy or by means of specific information texts displayed prior to the collection of such Data.
Personal Data may be freely provided by the User or, in the case of User Data, automatically collected during the use of www.draion.it.
Unless otherwise specified, all Data requested by www.draion.it are mandatory. If the User refuses to provide them, it may be impossible for www.draion.it to provide the Service. In cases where www.draion.it indicates certain Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or its operation.
Users in doubt as to which Data are mandatory are encouraged to contact the Data Controller.
The possible use of Cookies - or of other tracking tools - by www.draion.it or by the owners of third party services used by www.draion.it, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published or shared through www.draion.it and warrants that he/she has the right to communicate or disseminate it, releasing the Owner from any liability towards third parties.
Method and place of processing of collected Data
Processing methods
The Data Controller adopts appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of Personal Data.
The processing is carried out using computer and/or telematic instruments, with organisational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other subjects involved in the organisation of www.draion.it (administrative, sales, marketing, legal, system administrators) or external subjects (such as third party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, Data Processors by the Data Controller, may have access to the Data. The updated list of Data Processors can always be requested from the Data Controller.
Legal basis of the processing
The Data Controller processes Personal Data relating to the User where one of the following conditions exists
the User has given consent for one or more specific purposes; Note: in some jurisdictions, the Controller may be authorised to process Personal Data without the User's consent or another of the legal bases specified below, until the User objects (‘opts-out’) to such processing. However, this does not apply if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
processing is necessary for the performance of a contract with the User and/or the performance of pre-contractual measures;
processing is necessary for the performance of a legal obligation to which the Controller is subject;
processing is necessary for the performance of a task carried out in the public interest or in the exercise of public authority vested in the Controller;
processing is necessary for the pursuit of the legitimate interest of the Controller or of third parties.
However, it is always possible to request the Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on law, required by a contract or necessary to conclude a contract.
Place
The Data are processed at the Data Controller's operational headquarters and in any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User's Personal Data may be transferred to a country other than the country in which the User is located. To obtain further information on the location of the processing, the User may refer to the section on Personal Data processing details.
The User has the right to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organisation under public international law or consisting of two or more countries, such as the UN, as well as about the security measures taken by the Controller to protect the Data.
The User can verify whether one of the transfers just described takes place by examining the section of this document relating to details on the processing of Personal Data or request information from the Controller by contacting him at the contact details given at the beginning.
Retention period
Data are processed and stored for the time required by the purposes for which they were collected.
Therefore:
Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the performance of such contract is completed.
Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.
When the processing is based on the User's consent, the Data Controller may keep the Personal Data longer until such consent is revoked. Moreover, the Controller may be obliged to keep the Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period the Personal Data will be deleted. Therefore, at the end of this period, the right of access, cancellation, rectification and the right to Data portability can no longer be exercised.
Purposes of the Data collected
The User's Data are collected to enable the Data Controller to provide the Service, to comply with legal obligations, to respond to requests or enforcement actions, to protect its rights and interests (or those of Users or third parties), to identify possible fraudulent or malicious activities, as well as for the following purposes: Access to accounts on third party services, Registration and authentication, Contacting the User, Interaction with social networks and external platforms, Protection against SPAM, Statistics, Data transfer outside the EU and Display of content from external platforms.
To obtain detailed information on the purposes of the processing and the Personal Data processed for each purpose, the User may refer to the section ‘Personal Data Processing Details’.
Facebook permissions required by www.draion.it
Www.draion.com may require certain Facebook permissions that allow it to perform actions with the User's Facebook account and collect information, including Personal Data, from it. This service allows www.draion.it to connect with the User's account on the social network Facebook, provided by Facebook Inc.
For more information on the following permissions, please refer to the Facebook permissions documentation and Facebook's privacy policy.
The required permissions are as follows:
Basic information
The basic information of the User registered on Facebook which normally includes the following Data: id, name, picture, gender and language location and in some cases Facebook ‘Friends’. If the User has made further Data publicly available, this will be available.
Checkin
Provides read access to the user's authorised checkins or those of a friend that the user can view.
Contact Email
Provides access to the User's contact email address.
Details of Personal Data processing
Personal Data is collected for the following purposes and using the following services:
Access to accounts on third-party services
These types of services allow www.draion.it to take Data from your accounts on third party services and perform actions with them.
These services are not activated automatically, but require the express permission of the User.
Facebook account access (www.draion.it)
This service allows www.draion.it to connect with the User's account on the social network Facebook, provided by Facebook, Inc.
Required permissions: Checkin; Contact Email.
Place of processing: United States - Privacy Policy.
Twitter account access (Twitter, Inc.)
This service allows www.draion.it to connect with the User's account on the social network Twitter, provided by Twitter, Inc.
Personal Data processed: various types of Data as specified by the privacy policy of the service.
Place of processing: United States - Privacy Policy.
Contacting the User
Contact by phone (www.draion.it)
Users who have provided their telephone number may be contacted for commercial or promotional purposes related to www.draion.it, as well as to fulfill support requests.
Personal data processed: telephone number.
Mailing list or newsletter (www.draion.it)
By registering to the mailing list or newsletter, the User's email address is automatically added to a list of contacts to whom email messages may be sent containing information, including commercial and promotional information, related to www.draion.it. The User's email address may also be added to this list as a result of registering with www.draion.it or after making a purchase.
Personal Data Processed: Cookie; email; name.
Interaction with social networks and external platforms
This type of service allows interactions with social networks, or other external platforms, directly from the pages of www.draion.it.
The interactions and information acquired by www.draion.it are in each case subject to the User's privacy settings relating to each social network.
This type of service may still collect traffic data for the pages where the service is installed, even when Users do not use it.
It is recommended to disconnect from the respective services to ensure that the data processed on www.draion.it is not linked back to the User's profile.
Linkedin social button and widgets (LinkedIn Corporation)
LinkedIn's social button and widgets are services for interaction with the Linkedin social network, provided by LinkedIn Corporation.
Personal Data Processed: Cookies; Usage Data.
Place of processing: United States - Privacy Policy.
Protection against SPAM
This type of service analyses the traffic of www.draion.it, potentially containing Users' Personal Data, in order to filter it from parts of traffic, messages and content recognised as SPAM.
Google reCAPTCHA (Google Ireland Limited)
Google reCAPTCHA is a SPAM protection service provided by Google Ireland Limited.
Use of reCAPTCHA is subject to Google's privacy policy and terms of use.
Personal data processed: Cookies; Usage Data.
Place of processing: Ireland - Privacy Policy.
Registration and Authentication
By registering or authenticating, the User allows the Application to identify him/her and give him/her access to dedicated services.
Depending on what is indicated below, registration and authentication services may be provided with the help of third parties. If this happens, this Application may access some Data stored by the third-party service used for registration or identification.
Facebook Authentication (Facebook, Inc.)
Facebook Authentication is a registration and authentication service provided by Facebook, Inc. and connected to the social network Facebook.
Personal Data processed: various types of Data as specified by the privacy policy of the service.
Place of processing: United States - Privacy Policy.
Instagram Authentication (Instagram, Inc.)
Instagram Authentication is a registration and authentication service provided by Instagram, Inc. and connected to the social network Instagram.
Personal Data processed: various types of Data as specified by the privacy policy of the service.
Place of processing: United States - Privacy Policy.
Google OAuth (Google Ireland Limited)
Google OAuth is a registration and authentication service provided by Google Ireland Limited and connected to the Google network.
Personal Data processed: various types of Data as specified by the privacy policy of the service.
Place of processing: Ireland - Privacy Policy.
Direct registration (www.draion.it)
The User registers by filling in the registration form and providing his/her Personal Data directly to www.draion.it.
Personal Data processed: Postcode; city; surname; email; User ID; language; country; VAT number; password; province; company name; place of work; username; various types of Data.
Statistics
The services contained in this section allow the Data Controller to monitor and analyse traffic data and serve to keep track of the User's behaviour.
Google Analytics (Google Ireland Limited)
Google Analytics is a web analysis service provided by Google Ireland Limited (‘Google’). Google uses the Personal Data collected in order to track and examine the use of www.draion.it, compile reports and share them with other services developed by Google.
Google may use Personal Data to contextualise and personalise ads in its advertising network.
Personal Data processed: Cookies; Usage Data.
Place of processing: Ireland - Privacy Policy.
Transfer of Data outside the EU
The Controller may transfer Personal Data collected within the EU to third countries (i.e., all non-EU countries) only in accordance with a specific legal basis. Therefore, such Data transfers are performed in accordance with one of the legal bases described below.
The User may request information from the Controller regarding the applicable legal basis concretely applicable to each individual service.
Other legal basis for the transfer of Data to third countries (www.draion.it)
When no other legal basis is applicable, Personal Data may be transferred from the EU to third countries only under one of the following conditions
the transfer is necessary to perform a contract concluded between the User and the Controller or pre-contractual measures taken at the request of the User;
the transfer is necessary to conclude or perform a contract concluded in the interest of the User by the Controller and another natural or legal person
the transfer is necessary for reasons of public interest; * the transfer is necessary to establish, exercise or defend a legal claim;
the transfer is necessary to protect the vital interests of the Data Subject or of other persons, when the Data Subject is physically or legally incapable of giving consent. In such cases, the Controller will inform the User of the legal basis applicable to the actual transfer via www.draion.it.
Personal Data processed: various types of Data.
Transfer of Data from the EU and/or Switzerland to the United States on the basis of the Privacy Shield (www.draion.it)
Where this is the legal basis, the transfer of Personal Data from the EU or Switzerland to the United States takes place on the basis of the EU-US or Switzerland-US Privacy Shield agreement.
In particular, Personal Data is transferred to entities that have self-certified under the Privacy Shield and therefore guarantee an adequate level of protection for the transferred Data. The services affected by the transfer of Data are listed in the respective sections of this document. Among them, those adhering to the Privacy Shield can be identified by consulting the relevant privacy policy or by checking the status of their registration on the official Privacy Shield list.
Your rights under the Privacy Shield are described in continually updated form on the U.S. Department of Commerce website. The transfer of Personal Data from the EU or Switzerland to the United States to entities that are not (or no longer) Privacy Shield members is only permissible under another valid legal basis. Users may request information from the Controller about such legal bases.
Personal Data processed: various types of Data.
Transfer of Data to countries that guarantee European standards (www.draion.it)
When this is the legal basis, the transfer of Personal Data from the EU to third countries takes place on the basis of an adequacy decision adopted by the European Commission. The European Commission adopts adequacy decisions with respect to individual third countries that it deems to ensure a level of protection of Personal Data comparable to that provided by European legislation on the protection of Personal Data. The User can view the updated list of adequacy decisions on the European Commission's website.
Personal Data processed: various types of Data.
Transfer to third countries based on consent (www.draion.it)
When this is the legal basis, the transfer of Personal Data from the EU to third countries takes place only when the User has expressly consented to such transfer after having been informed of the risks due to the absence of an adequacy decision and of the adequate safeguards adopted.
In such cases, the Controller informs Users and collects their consent through www.draion.it.
Personal Data processed: various types of Data.
Transfer to third countries on the basis of standard contractual clauses (www.draion.it)
When this is the legal basis, the transfer of Personal Data from the EU to third countries takes place on the basis of standard Personal Data protection clauses adopted by the European Commission.
In such cases the recipients of the Data have agreed to treat the Personal Data in accordance with the levels of protection provided by the legislation. Users may request further information by contacting the Controller at the contact details indicated in this document.
Personal Data processed: various types of Data.
Displaying content from external platforms
This type of service allows content hosted on external platforms to be viewed directly from the pages of www.draion.it and to interact with them.
If a service of this type is installed, it is possible that, even if Users do not use the service, it may collect traffic data relating to the pages where it is installed.
Google's programmable search engine (Google Ireland Limited)
Google's programmable search engine is a search engine embedding service operated by Google Ireland Limited that allows www.draion.it to embed such content within its pages.
Personal data processed: Cookies; Usage Data.
Place of processing: Ireland - Privacy Policy.
Further information on the processing of Personal Data
Personal Data collected through sources other than the User
The Data Controller of www.draion.it may have lawfully collected Personal Data about You without Your involvement from sources provided by third parties in accordance with the legal bases described in the section on the legal bases for processing.
If the Controller has collected Personal Data in such a way, the User can find specific information about the sources in the respective sections of this document or by contacting the Controller.
User identification by means of a Universal Unique Identifier (UUID)
Www.draion.co.uk can track Users by saving a so-called ‘universal unique identifier’ (UUID) for statistical analysis purposes or to store Users' preferences. This identifier is generated with the installation of this Application, is not deleted when the Application is closed or updated, but is only permanently removed if the User decides to uninstall the Application from his/her device. If the Application is reinstalled, a new UUID is generated.
User Rights
Users may exercise certain rights with respect to the Data processed by the Data Controller.
In particular, the User has the right to:
revoke consent at any time. The User may revoke the consent to the processing of its Personal Data previously expressed.
object to the processing of their Data. The User may object to the processing of its Data when it is done on a legal basis other than consent. Further details on the right to object are set out in the section below.
access to their Data. The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing and to receive a copy of the Data processed.
verify and request rectification. The User may verify the correctness of its Data and request that it be updated or corrected.
obtain the restriction of the processing. When certain conditions are met, the User may request the restriction of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its preservation.
obtain the deletion or removal of their Personal Data. When certain conditions are met, the User may request the deletion of its Data by the Data Controller.
receive their Data or have them transferred to another Data Controller. The User has the right to receive its Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another data controller. This provision is applicable when the Data are processed by automated means and the processing is based on the User's consent, on a contract to which the User is party or on contractual measures related thereto.
Proposing a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.
Details of the right to object
When Personal Data are processed in the public interest, in the exercise of public authority vested in the Controller or in pursuit of a legitimate interest of the Controller, Users have the right to object to the processing for reasons related to their particular situation.
Users are reminded that if their Data are processed for direct marketing purposes, they may object to the processing without giving any reason. To find out whether the Controller processes Data for direct marketing purposes, Users may refer to the respective sections of this document.
How to exercise rights
To exercise their rights, Users may address a request to the contact details of the Controller indicated in this document. Requests are filed free of charge and processed by the Controller as soon as possible, in any case within one month.
Cookie Policy
Www.draion.co.uk makes use of Tracking Tools. To find out more, the User can consult the Cookie Policy.
Further information on processing
Legal defence
The User's Personal Data may be used by the Data Controller in legal proceedings or in the preparatory phases of such proceedings in order to defend against abuses in the use of www.draion.it or related Services by the User.
The User declares that he/she is aware that the Data Controller may be obliged to disclose the Data by order of public authorities.
Specific disclosures
Upon the User's request, in addition to the information contained in this privacy policy, www.draion.it may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.
System logs and maintenance
For operation and maintenance purposes, www.draion.it and any third-party services used by it may collect system logs, i.e. files that record interactions and which may also contain Personal Data, such as the User's IP address.
Information not contained in this policy
Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.
Response to ‘Do Not Track’ requests
Www.draion.com does not support ‘Do Not Track’ requests.
To find out whether any third-party services used support them, the User is invited to consult their respective privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on www.draion.it as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details it has. Therefore, please consult this page frequently, referring to the date of last modification indicated at the bottom.
If the changes affect processing whose legal basis is consent, the Controller will collect the User's consent again, if necessary.
Definitions and legal references
Personal data (or Data)
Personal data is any information that, directly or indirectly, even in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.
Usage Data
This is information collected automatically through www.draion.it (including by third-party applications integrated into www.draion.it), including: IP addresses or domain names of computers used by the User who connects with www.draion.it, addresses in URI (Uniform Resource Identifier) notation, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.. ) the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (e.g. the length of time spent on each page) and the details of the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the operating system and the User's IT environment.
User
The individual who uses www.draion.it which, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refer.
Data Controller (or Processor)
The natural person, legal entity, public administration and any other entity that processes Personal Data on behalf of the Controller, as set out in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public authority, service or other body which, individually or jointly with others, determines the purposes and means of the processing of personal data and the instruments adopted, including the security measures relating to the operation and use of www.draion.it. The Data Controller, unless otherwise specified, is the owner of www.draion.it.
www.draion.it (or this Application)
The hardware or software tool through which Users' Personal Data are collected and processed.
Service
The Service provided by www.draion.it as defined in the relevant terms (if any) on this website/application.
European Union (or EU)
Unless otherwise specified, any reference in this document to the European Union shall be deemed to include all current member states of the European Union and the European Economic Area.
Cookies
Cookies are tracking tools that consist of small pieces of data stored within the User's browser.
Tracking Tool
A Tracking Tool is any technology - e.g. cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting - that allows Users to be tracked, for example by collecting or storing information on the User's device.
Legal references
This Privacy Policy is drafted on the basis of multiple legislative orders, including Articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy policy relates exclusively to www.draion.it.