The purpose of this document is to inform the natural person (hereinafter “Data Subject”) regarding the processing of their personal data (hereinafter “Personal Data”) collected by the data controller, Larin srl, with registered office at via della Rivetta 32B, 32100 Belluno, Italy, tax code/VAT number 01144900253, VAT number IT 01144900253, e-mail address assistenza@larin.it, (hereinafter the “Controller”), through and AmuseApp (hereinafter the “Application”).
Changes and updates will be binding as soon as they are published on the Application. In the event of non-acceptance of the changes made to the Privacy Policy, the Data Subject must cease using this Application and may request that the Controller delete their Personal Data.
- Categories of Personal Data processed The Controller processes the following types of Personal Data voluntarily provided by the Data Subject: The Controller processes the following types of Personal Data collected automatically: Failure by the Data Subject to provide Personal Data for which there is a legal or contractual obligation, or which constitutes a necessary requirement for the conclusion of the contract with the Controller, will make it impossible for the Controller to establish or continue the relationship with the Data Subject. A Data Subject who provides the Controller with Personal Data of third parties is directly and solely responsible for their origin, collection, processing, communication, or disclosure.
- Contact data: first name, last name, address, e-mail, phone number, images, authentication credentials, any further information sent by the Data Subject, etc.
- Tax and payment data: tax code, VAT number, credit card details, bank account details, etc.
- Data relating to the employment relationship: data entered in the curriculum vitae, data relating to spouse or children, social security data, etc.
- Technical data: Personal Data produced by the devices, applications, tools, and protocols used, such as, for example, information about the device used, IP addresses, browser type, Internet Service Provider (ISP) type. Such Personal Data may leave traces that, particularly when combined with unique identifiers and other information received from servers, may be used to create profiles of natural persons
- Browsing and Application usage data: such as, for example, pages visited, number of clicks, actions taken, session duration, etc.
- Cookies and similar technologies The Application uses cookies, web beacons, unique identifiers, and other similar technologies to collect the Data Subject's Personal Data regarding pages, links visited, and other actions carried out when the Data Subject uses the Application. These are stored so that they can be transmitted upon the Data Subject's next visit. The full Cookie Policy can be viewed at the following address: ____________________
- Legal basis and purposes of processing The processing of Personal Data is necessary: On the basis of the Controller's legitimate interest, the Application allows interactions with external platforms or social networks whose processing of Personal Data is governed by their respective privacy policies, to which reference should be made. The interactions and information acquired through this Application are in any case subject to the privacy settings that the Data Subject has chosen on such platforms or social networks. This information – in the absence of specific consent to processing for further purposes – is used solely to enable use of the Application and to provide the information and services requested. The Data Subject's Personal Data may also be used by the Controller to defend itself in legal proceedings before the competent courts.
- for the performance of the contract with the Data Subject, and specifically:
- fulfillment of any obligation arising from the pre-contractual or contractual relationship with the Data Subject
- registration and authentication of the Data Subject: to allow the Data Subject to register on the Application, log in, and be identified, including via external platforms
- support and contact with the Data Subject: to respond to the Data Subject's requests
- payment management: to manage payments by credit card, bank transfer, or other means
- for compliance with a legal obligation, and specifically:
- fulfillment of any obligation set out in current regulations, laws, and regulations, in particular regarding tax matters
- on the basis of the Controller's legitimate interest, for:
- email marketing purposes for the Controller's products and/or services to directly sell the Controller's products or services using the e-mail address provided by the Data Subject in the context of the sale of a product or service similar to the one that was the subject of the sale
- management, optimization, and monitoring of the technical infrastructure: to identify and resolve any technical issues, to improve the Application's performance, to manage and organize information within an IT system (e.g., servers, databases, etc.)
- security and fraud prevention: to ensure the security of the Controller's assets, infrastructure, and networks
- statistics using anonymous data: to carry out statistical analyses on aggregated and anonymous data in order to analyze the Data Subject's behavior, to improve the products and/or services provided by the Controller, and to better meet the Data Subject's expectations
- on the basis of the Data Subject's consent, for:
- profiling of the Data Subject for marketing purposes: to provide the Data Subject with information about the Controller's products and/or services through automated processing aimed at collecting personal information for the purpose of predicting or evaluating their preferences or behavior
- retargeting and remarketing: to reach, with a personalized advertisement, the Data Subject who has already visited or has shown interest in the products and/or services offered by the Application, using their Personal Data. The Data Subject may opt out by visiting the page of the Network Advertising Initiative
- marketing purposes for the Controller's products and/or services: to send commercial and/or promotional information or materials, to carry out direct sales activities for the Controller's products and/or services, or to conduct market research using automated and traditional means
- marketing purposes for third-party products and/or services: to send third parties' commercial and/or promotional information or materials, to carry out direct sales activities, or to conduct market research on their products and/or services using automated and traditional means
- disclosure of Personal Data for third-party marketing purposes: to disclose Personal Data to third parties operating in the marketing and advertising sector so that they may use it to send commercial and/or promotional information or materials, to carry out direct sales activities for their products and/or services, or to conduct market research using automated and traditional means
- detection of the Data Subject's exact location: to detect the Data Subject's presence, to monitor access, times, and presence of the Data Subject at a given location, etc.
- for the performance of the contract with the Data Subject, and specifically:
- Methods of processing and recipients of Personal Data The processing of Personal Data is carried out using paper-based and IT tools, with organizational procedures and logic strictly related to the purposes indicated, and through the adoption of appropriate security measures. Personal Data are processed exclusively by: The parties listed above are required to use appropriate safeguards to protect the Personal Data and may access only the data necessary to carry out the tasks assigned to them. Personal Data will not be disseminated indiscriminately in any way.
- persons authorized by the Controller to process Personal Data who have committed to confidentiality or are subject to an appropriate legal obligation of confidentiality;
- parties who act autonomously as separate data controllers, or parties appointed as data processors by the Controller in order to carry out all the processing activities necessary to pursue the purposes set out in this notice (for example, business partners, consultants, IT companies, service providers, hosting providers);
- parties or entities to which Personal Data must be disclosed by legal obligation or by order of the authorities.
- Location If necessary, Personal Data may be transferred to parties located outside the territory of the European Economic Area (EEA). Whenever Personal Data is transferred outside the EEA, the Controller will adopt every contractual measure suitable and necessary to ensure an adequate level of protection of Personal Data, including – among others – agreements based on the standard contractual clauses for the transfer of data outside the EEA, approved by the European Commission. To request information on the specific safeguards adopted, the Data Subject may contact the Controller at the following e-mail address: assistenza@larin.it.
- Retention period of Personal Data Personal Data will be retained for the period of time necessary to fulfill the purposes for which it was collected, in particular: At the end of the retention period, all Personal Data will be deleted or retained in a form that does not allow identification of the Data Subject.
- for purposes relating to the performance of the contract between the Controller and the Data Subject, it will be retained for the entire duration of the contractual relationship and, after termination, for the ordinary limitation period of 10 years. In the event of legal proceedings, for their entire duration, until the deadlines for bringing appeals have expired
- for purposes relating to the Controller's legitimate interest, it will be retained until that interest has been fulfilled
- for the fulfillment of a legal obligation, by order of an authority, and for defense in legal proceedings, it will be retained in accordance with the timeframes set out by such obligations and regulations, and in any case until the expiry of the limitation period provided for by applicable law
- for purposes based on the Data Subject's consent, it will be retained until consent is withdrawn. For marketing purposes, for a period not exceeding 24 months.
- Rights of the Data Subject Data Subjects may exercise certain rights with regard to the Personal Data processed by the Controller. In particular, the Data Subject has the right to: To exercise their rights, Data Subjects may send a request to the following e-mail address: assistenza@larin.it. Requests will be taken in charge by the Controller immediately and handled as quickly as possible, and in any case within 30 days.
- be informed about the processing of their Personal Data
- withdraw consent at any time
- restrict the processing of their Personal Data
- object to the processing of their Personal Data
- access their Personal Data
- verify and request rectification of their Personal Data
- obtain the restriction of processing of their Personal Data
- obtain the erasure of their Personal Data
- transfer their Personal Data to another controller
- lodge a complaint with the supervisory authority for the protection of their Personal Data and/or take legal action.