Your privacy is extremely important to us, please read carefully this document which informs you in a complete and transparent way about the processing that the legal entity specified in the section ‘Data Controller and Data Processor’ will perform on the Personal Data you provide and/or the Data collected as part of the contacts you may have by visiting this Website/Application or interacting with our social network profiles (e.g. Facebook, Instagram, TikTok, LinkedIn etc.).

User
The individual using this Application who, unless otherwise specified, coincides with the Data Subject.

Data subject
The natural person to whom the Personal Data refers.

Personal data (or data)
Any information that, directly, indirectly or in connection with other information, including a personal identification number, allows for the identification or identification of a natural person.

Usage Data
Information collected automatically through this Application (or third-party services used in this Application), which may include: IP addresses or domain names of the computers used by Users who use this Application, URI (Uniform Resource Identifier) addresses, time of the request, the method used to send the request to the server, the size of the file received in response, the numeric code that indicates the status of the server response (success, error, etc.), the country of origin, the characteristics of the browser and operating system used by the user, the various time details per visit (for example, the time spent on each page within the application) and the details on the path followed within the application with particular reference to the sequence of pages visited and other parameters relating to the operating system of the device and / or the user’s IT environment.

Data Controller (or Data Controller)
The natural or legal person, public authority, agency or other body which, alone or in collaboration with others, determines the purposes and means of the processing of Personal Data, including the security measures relating to the use and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.

Data Processor (or Data Processor)
The natural or legal person, public authority, agency or other body that processes Personal Data on behalf of the Data Controller, as described in this privacy statement.

This Website / Application
The ways in which the User’s Personal Data are collected and processed.

Service
The service provided by this Website / Application as described in the relevant terms (if available) and on this Website / Application.

European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.

Cookies
Small text files that can be used by websites to make the user experience more efficient.

Legal information
This privacy statement has been developed on the basis of provisions of several legislations, including art. 13/14 of regulation (EU) 2016/679 (general regulation on data protection). This privacy statement refers exclusively to this Website / Application, unless otherwise specified in this document.

Encanto srl

Via Filippo Turati, 5/b
41030 San Prospero s / S (Modena) Italy
VAT number: IT02793310364
Contact of the Data Controller
Contact of the Data Processor

The categories of Personal Data that this Application collects, independently or through third parties, are specified below:

Biographical data
Name, middle name, surname, date of birth, gender, identity document (in case of applications for open positions or spontaneous applications).

Contact details
Residential address (street, city, province, state, post code), domicile, email address, telephone number, mobile number.

Sales data
Shipping and billing address, delivery and payment methods, name of the credit card holder and card expiry date, information requested by Customer Service, VAT number and / or Tax Code, identity document number (where required by a law and within the limits of that law).

Tracking Newsletters and related User Actions / Behaviors
Information relating to the opening of newsletters or links.

Purchase data
Details of the products purchased (e.g. item, price, discount, variant, calculated spending level, abandoned cart, etc.).

Navigation data
Data relating to the browsing behavior and / or use of the Website / Application of the Owner through, for example, cookies or information relating to the pages visited or searched or relating to the wishlist collected during navigation or purchases in the online store.

Full details on each type of Personal Data collected are provided in the dedicated sections of this Privacy Policy or by specific explanatory texts displayed prior to the Data Collection.
Personal Data may be freely provided by the User or, in case of Usage Data, collected automatically when using this Application.
Unless otherwise indicated, all the Data requested by this Application are mandatory and failure to provide the Data could make it impossible for this Application to provide its services. In cases where this Application explicitly specifies that some Data are not mandatory, Users are free not to communicate these Data without consequences for the availability or operation of the Service.
Users who are not sure which personal data are mandatory are invited to contact the Data Controller.
Any use of cookies – or other tracking tools – by this Website / Application or by the owners of third party services used by this Website / Application has the purpose of providing the Service requested by the User, in addition to any other purpose described in this document and in what concerns the Cookie management .
Users are responsible for the Personal Data of third parties obtained, published or shared through this Application and confirm that they have the consent of the third party to provide the Data to the Data Controller.

Processing methods
The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification or unauthorized destruction of the Data.
Data processing takes place via computer and / or enabled IT tools, following organizational procedures and methods strictly related to the purposes indicated. In addition to the Data Controller, in some cases, the Data may be accessible to certain types of persons in charge, involved in the operation of this Website / Application (administration, sales, marketing, legal, system administration) or external parties (such as service providers third party technicians, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller. The updated list of these subjects may be requested at any time from the Data Controller.

Legal basis for processing
The Data Controller may process Personal Data relating to Users if one of the following conditions occurs:

  • Users have given their consent for one or more specific purposes. Note: in some legislations the Data Controller may be authorized to process Personal Data until the User objects to such processing (“opt-out”), without having to rely on consent or any other of the following legal bases. This, however, does not apply when the processing of Personal Data is subject to European data protection legislation;
  • The provision of Data is necessary for the execution of an agreement with the User and / or for any pre-contractual obligations of the same;
  • The processing is necessary to fulfill a legal obligation to which the Data Controller is subject;
  • Processing is related to a task that is carried out in the public interest or in the exercise of the official authority conferred on the Data Controller;
  • the processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.

In any case, the Data Controller offers the utmost willingness to clarify the specific legal basis applicable to the processing and in particular if the provision of Personal Data is a legal or contractual requirement or a requirement necessary to enter into a contract.

Place
The data is processed at the owner’s operational offices and in any other places where the parties involved in the processing are located.
Depending on the User’s location, it may be necessary to transfer the data collected to a country other than their own. For further information on the place of processing of such transferred data, users can consult the section containing the details on the processing of Personal Data. In case of transfer outside the EEA (European Economic Area), this will always take place in compliance with the rights and guarantees provided by the Privacy Law (GDPR).
Users also have the right to know the legal basis of data transfers to a country outside the European Union or to any international organization governed by international public law or established by two or more countries, such as the United Nations, and on security measures adopted by the Data Controller to safeguard their data.
Users can find further information by checking the relevant sections of this document or inquire by contacting the Data Controller using the information provided in the ‘Data Controller and Data Processor’ section.

Retention time of the collected data
Personal Data must be processed and stored for the time necessary for that for which they were collected. Therefore:
Personal Data collected for purposes related to the execution of a contract between the Owner and the User must be kept until the contract has been fully executed.
The Personal Data collected for the purposes of the Data Controller’s legitimate interests must be kept for the time necessary to fulfill these purposes. Users can find specific information relating to the legitimate interests pursued by the Data Controller within the relevant sections of this document or by contacting the Data Controller.
The Data Controller may be authorized to keep Personal Data for a longer period each time the User has given consent to such processing, provided that such consent is not withdrawn. Furthermore, the Data Controller may be obliged to keep Personal Data for a longer period when required for the execution of a legal obligation or on the order of an authority.
Once the retention period has expired, the Personal Data will be deleted. Therefore, the right of access, the right to erasure, the right of rectification and the right to data portability cannot be enforced after the retention period has expired.

The Data relating to the User is collected to allow the Owner to provide its Services, as well as for the following purposes:

  • Traffic optimization and distribution;
  • Hosting and back-end infrastructure;
  • Registration and authentication;
  • User purchase order management;
  • User order shipping management;
  • Managing contacts and sending messages;
  • Contact with the user, assistance management and contact requests;
  • Displaying content from external platforms;
  • Content comments;
  • Analyses;
  • Remarketing and Behavioral Targeting;
  • Spam protection.

Users can find further detailed information on these processing purposes and on the specific Personal Data used for each purpose in the respective sections of this document.

Personal Data is collected for the following purposes and using the following services:

Analyses

The services contained in this section allow the Owner to monitor and analyze web traffic and can be used to keep track of user behavior.

Google Analytics (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google uses the data collected to track and examine the use of this application, to prepare reports on its activities and share them with other Google services.
Google may use the data collected to contextualize and personalize the advertisements of its own advertising network.
Personal data collected: cookies and usage data.
Place of processing: EU / US – Privacy PolicyOpt Out .

Facebook Ads Conversion Tracking (Meta Platforms Ireland Limited)
Facebook Ads Conversion Tracking is an analytics service provided by Meta Platforms Ireland Limited that links data from the Facebook advertising network with actions performed on this Application.
Personal data collected: cookies and usage data.
Place of processing: EU / US – Privacy Policy .

Contact the user

Mailing list or Newsletter (this Application)
By filling out the contact form with their Data, the User authorizes this Application to use these details to respond to requests for information, quotes or any other type of request, as indicated by the form header.
Personal data collected: email address, name and surname, company.

Comments on content

Content commenting services allow users to make and publish their comments on the contents of this Application.
Depending on the settings chosen by the Owner, users can also leave anonymous comments. If an email address exists in the Personal Data provided by the user, it can be used to send notifications of comments on the same content. Users are responsible for the content of their comments.
If a content commenting service provided by third parties is installed, it can still collect web traffic data for the pages where the commenting service is installed, even when users do not use the content commenting service.

Comment system managed directly (this Application)
This app has its own internal content commenting system.
Personal data collected: email address, username and website.

Viewing content from external platforms

This type of service allows you to view content hosted on external platforms directly from the pages of this Application and interact with them.
This type of service may still collect data on web traffic for the pages in which the service is installed, even when Users do not use it.

Google Fonts (Google Inc.)
Google Fonts is a typeface display service provided by Google Inc. which allows this Application to incorporate content of this type on its pages.
Personal data collected: Usage data and various types of data as specified in the privacy policy of the service.
Place of processing: EU / US – Privacy Policy .

Google Maps widget (Google Inc.)
Google Maps is a map viewing service provided by Google Inc. which allows this Application to incorporate content of this type on its pages.
Personal data collected: cookies and usage data.
Place of processing: EU / US – Privacy Policy .

Gravatar (Automattic Inc.)
Gravatar is an image viewing service provided by Automattic Inc. which allows this Application to incorporate content of this type on its pages.
Note that if Gravatar images are used for comment forms, the commenter’s email address or parts of it may be sent to Gravatar – even if the commenter has not registered for that service.
Personal data collected: email address and usage data.
Place of processing: EU / US – Privacy Policy .

Instagram widget (Instagram, Inc.)
Instagram is an image viewing service provided by Instagram, Inc. which allows this Application to incorporate content of this type on its pages.
Personal data collected: cookies and usage data.
Place of processing: EU / US – Privacy Policy .

SoundCloud Widget (SoundCloud Limited)
Soundcloud is an audio content delivery service provided by SoundCloud Limited which allows this Application to embed such content on its pages.
Personal data collected: Usage data.
Place of processing: DE – Privacy Policy .

Spotify Widget (Spotify AB)
Spotify is an audio content delivery service provided by Spotify AB which allows this Application to embed content of this type on its pages.
Personal data collected: cookies and usage data.
Place of processing: EU / US – Privacy Policy .

Typekit (Adobe Systems Incorporated)
Typekit is a font display service provided by Adobe Systems Incorporated that allows this Application to embed content of this type on its pages.
Personal data collected: Usage data and various types of data as specified in the privacy policy of the service.
Place of processing: EU / US – Privacy Policy .

Vimeo video (Vimeo, LLC)>
Vimeo is a video content viewing service provided by Vimeo, LLC that allows this Application to embed content of this type on its pages.
Personal data collected: cookies and usage data.
Place of processing: EU / US – Privacy Policy .

YouTube video widget (Google Inc.)
YouTube is a video content viewing service provided by Google Inc. which allows this Application to incorporate content of this type on its pages.
Personal data collected: cookies and usage data.
Place of processing: EU / US – Privacy Policy .

Back-end hosting and infrastructure

This type of service is intended to host data and files that allow this Application to be distributed, as well as to provide a ready-to-use infrastructure for the execution of specific functions or parts of this Application. Some of these services work through geographically distributed servers, making it difficult to determine the actual location in which Personal Data is stored.

Register.it (Register SpA)
Register.it is a hosting service provided by Register SpA
Personal data collected: various types of data as specified in the privacy policy of the service.
Place of processing: EU – Privacy Policy .

Managing contacts and sending messages

This type of service allows you to manage a database of e-mail contacts, telephone contacts or any other contact information to communicate with the user.
These services may also collect data relating to the date and time when the message was viewed by the User, as well as when the User interacted with it, for example by clicking on the links included in the message.

MailChimp (The Rocket Science Group, LLC.)
MailChimp is an email management and sending service provided by The Rocket Science Group, LLC.
Personal data collected: email address.
Place of processing: EU / US – Privacy Policy .

Management of assistance and contact requests

This type of service allows this Application to manage the support and contact requests received by e-mail or by other means, such as the contact form.
The personal data processed depend on the information provided by the user in the messages and on the means used for communication (e.g. email address).

WhatsApp (WhatsApp Ireland Limited)
WhatsApp (WhatsApp Messenger and WhatsApp Business) is an instant messaging application and platform, since February 19, 2014 it is part of the Meta Inc. group. The main office for the EU is in Dublin, Ireland, under the name of WhatsApp Ireland Limited.
Personal data collected: mobile phone number and to use the functions of optional services, additional information is collected.
Place of processing: EU – Privacy Policy .

Facebook Messenger (Meta Platforms Ireland Limited)
Facebook Custom Audience is a remarketing and behavioral targeting service provided by Meta Platforms Ireland Limited that connects the activity of this Application to the Facebook advertising network.
Personal data collected: cookies, email address and to take advantage of the optional services functions, additional information is collected.
Place of processing: EU – Privacy PolicyOpt Out .

Registration and authentication

By registering or authenticating, users allow this Application to identify them and provide them with access to dedicated services.
Depending on what is described below, third parties may provide registration and authentication services. In this case, this Application will be able to access some Data, stored by these third-party services, for registration or identification purposes.

Direct registration (this Application)
The User registers by filling out the registration form and providing Personal Data directly to this Application.
Personal data collected: email address, username and various types of data.

Management of purchases, payments and shipments

This type of service allows this Application to manage the order, payment and shipment of users’ purchase orders for goods and / or services.
The Personal Data collected by this Application, independently or through third parties, are described below.

WooCommerce (Automattic Inc.)
WooCommerce is an e-commerce solution provided by Automattic Inc., it works in this Application to offer the user online shopping experiences for goods or services.
The user who registers and / or authenticates on this Application can proceed with the execution of a purchase order.
Personal data collected: name, billing address, shipping address, email address and other data (some optional) to execute the order placed by the user.
Place of processing: EU / US – Privacy Policy .

Nexi XPay (Nexi Payments SpA)
XPay is a payment gateway provided by Nexi that allows you to accept online payments through all channels and in all modes: e-commerce, mobile transactions, recurring payments, one-click payments.
Personal data collected: depending on the Services that the user chooses, personal data and / or data to make purchases from merchants, to process payments, including information on any financing instruments.
Place of processing: EU – Privacy Policy .

PayPal (PayPal Inc.)
PayPal offers digital payment and money transfer services provided by PayPal Inc. The user can securely log into his PayPal account from this Application and proceed with the payment for the purchase of products or services. The login credentials to the PayPal account, the credit card number and the security code of the user are never stored in this Application.
Personal data collected: depending on the Services that the user chooses, personal data and / or data to make purchases from merchants, to process payments, including information on any financing instruments.
Place of processing: EU / US – Privacy Policy .

Apple Pay (Apple Inc.)
Apple Pay is a non-instant mobile payment tool provided by Apple Inc. which allows you to make contactless payments, using mobile devices in physical stores and online payments on supported websites and apps, including via fixed devices.
Personal data collected: depending on the Services that the user chooses, personal data and / or data to make purchases from merchants, to process payments, including information on any financing instruments.
Place of processing: EU / US – Privacy Policy .

Google Pay (Google Inc.)
Google Pay is a non-instant mobile payment tool provided by Google Inc. which allows you to make contactless payments, using mobile devices in physical stores and online payments on supported websites and apps, including via fixed devices.
Personal data collected: depending on the Services that the user chooses, personal data and / or data to make purchases from merchants, to process payments, including information on any financing instruments.
Place of processing: EU / US – Privacy Policy .

Remarketing and behavioral targeting

This type of service allows this Application and its partners to inform, optimize and serve advertising based on the past use of this Application by the User.
This activity is performed by monitoring the Usage Data and using cookies, the information that is transferred to the partners who manage the remarketing and behavioral targeting activity.
In addition to any opt-out offered by one of the services listed below, the User can disable the use of cookies by a third-party service by visiting the Network Advertising Initiative opt-out page .

Facebook Custom Audience (Meta Platforms Ireland Limited)
Facebook Custom Audience is a remarketing and behavioral targeting service provided by Meta Platforms Ireland Limited that connects the activity of this Application to the Facebook advertising network.
Personal data collected: cookies and email address.
Place of processing: EU / US – Privacy PolicyOpt Out .

Facebook Remarketing (Meta Platforms Ireland Limited)
Facebook remarketing is a remarketing and behavioral targeting service provided by Meta Platforms Ireland Limited that connects the activity of this Application to the Facebook advertising network.
Personal data collected: cookies and usage data.
Place of processing: EU / US – Privacy PolicyOpt Out .

Spam protection

This type of service analyzes the traffic of this Application, potentially containing users’ Personal Data, in order to filter it from parts of traffic, messages and content that are recognized as SPAM.

Akismet (Automattic Inc.)
Akismet is a SPAM protection service provided by Automattic Inc.
Personal data collected: various types of data as specified in the privacy policy of the service.
Place of processing: EU / US – Privacy Policy .

Users can exercise certain rights relating to their data processed by the Data Controller.

Right to access
Right to know what data is processed by the Data Controller, to obtain information on certain aspects of the processing and to obtain a copy of the data being processed.

Right to portability
Receive a copy of the Personal Data that you have provided to the Data Controller and the right to have them transmitted to another Data Controller, if technically possible.

Right to rectification
Right to obtain from the Data Controller the correction of inaccurate Personal Data concerning him without undue delay.

Right to erasure
Cancellation of any Personal Data in relation to which the Data Controller no longer has any legal basis for the processing.

Right to limitation of processing
Limitation of the way the Data Controller processes your Personal Data, to the extent required by applicable data protection law.

Right of opposition
In addition to the rights listed above, you have the right to object at any time to the processing of your Personal Data by the Data Controller in pursuit of its legitimate interest. You have the right to object to direct marketing, which includes profiling. If you prefer that your Personal Data be processed exclusively through traditional contact methods, you can object to the processing of your Personal Data carried out through automated contact methods.

Right of Revocation
The User has the right to withdraw, in whole or in part, the consent to the processing of their Personal Data concerning the purpose of sending advertisements or direct sales or carrying out market research or commercial communication with automated methods. contact (e-mail, other remote communication systems via communication networks such as, for example: SMS, MMS, messaging platforms, etc.) and traditional contact methods (mail).

Details on the right to object to the processing
Where Personal Data are processed for a public interest, in the exercise of an official authority conferred on the Data Controller or for the purposes of the legitimate interests pursued by the Data Controller, Users may object to such processing by providing a reason related to their particular situation to justify the objection.

Any requests to exercise user rights can be addressed to the Data Controller through the contact details provided in this document, in the ‘Data Controller and Data Processor’ section. These requests can be exercised free of charge. Subject to verification of legitimacy in the exercise of the User’s right, the Data Controller will provide an answer as soon as possible and usually within one month.

This Website / Application uses cookies. To learn more and for detailed information on cookies, the User can consult our information on Cookie Management .

The user’s personal data may be used for legal purposes by the owner in court or in the stages that lead to possible legal actions deriving from the improper use of this application or related services. The User declares to be aware that the Data Controller may be required to disclose personal data at the request of the public authorities.

In addition to the information contained in this privacy statement, this Application may provide the User with additional and contextual information on particular Services or the collection and processing of Personal Data upon request.

System logs and maintenance
For operational and maintenance purposes, this Application and all third-party services may collect files that record the interaction with this Application (system logs) and use other Personal Data (such as the IP address) for this purpose.

Information not contained in this policy
More details regarding the collection or processing of personal data can be requested from the Data Controller at any time. Please see the contact information at the beginning of this document.

How Do Not Track Requests Are Handled
This app supports “Do Not Track” requests.
To determine if any of the third party services using the Application comply with “Do Not Track” requests, please read their specific privacy policies.

The Owner reserves the right to make changes to this Privacy Policy at any time by notifying Users on this page and possibly within this Website / Application and / or – as far as technically and legally feasible – by sending a notice to Users through any contact information available to the Owner. It is highly recommended that you check this page often, referring to the date of the last modification listed below. If a User objects to any of the changes to the policy, the User must cease using this application and may request that the Owner remove their Personal Data. Unless otherwise indicated, the Privacy Policy in force at the time applies to all Personal Data of the Owner relating to Users.

Last updated: May 30, 2022