Extended Privacy Policy of www.coffeel.it

GDPR General Data Protection Regulation UE 2016/679

INFORMATION ON THE PROCESSING OF PERSONAL DATA
of users who consult the website for the protection of personal data pursuant to articles 13 and 14 of Regulation (EU) 2016/679

PRIVACY POLICY

Per CoffeelOROMO TRIBÙ S.A.S.” with exclusive reference to the website www.coffeel.it (hereinafter “Site”), the privacy of its users is of primary importance.

This Privacy Policy defines what data is collected and how it is used, disclosed, transferred, and/or stored by the Site. This site collects some personal data from its users. Users may be subject to different levels of protection. Some Users therefore enjoy higher protection. Further information on protection criteria can be found in the applicability section.


Data Controller

If you have any questions regarding this privacy policy, you can contact us using the information below:

  • OROMO TRIBÙ S.A.S.
  • Registered office:
    VIA XXV APRILE 4, 18039 VENTIMIGLIA (IMPERIA) ITALY
  • Tel. (+39) 0184.841522
  • Email: info@coffeel.it

Our users can send requests regarding the protection of personal data, privacy, and security to info@coffeel.it.


Types of Data Collected

It is possible to visit our site anonymously.

Among the personal data collected by www.coffeel.it, independently or through third parties, there are: Cookies, Usage Data, Email, Name, and various types of Data.

Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed before the data is collected.

Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of the site.

In cases where the site indicates some Data as optional, Users are free to refrain from communicating such Data, without this having any consequences on the availability of the Service or its operation.

Users who have doubts about which Data is mandatory are encouraged to contact the Controller.

The use of Cookies – or other tracking tools – by the site or by the third-party service providers used by the site, unless otherwise specified, is aimed at providing the Service requested by the User, in addition to any other purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through the site and guarantees that they have the right to communicate or disclose them, releasing the Controller from any liability towards third parties.


Methods and Place of Processing of the Collected Data

Processing Methods

The Data Controller processes the Personal Data of Users by adopting appropriate security measures to prevent unauthorized access, disclosure, alteration, or destruction of Personal Data.

Processing is carried out using computers and/or IT-enabled tools, organizational methods, and with procedures strictly related to the purposes indicated.

In addition to the Controller, in some cases, the Data may be accessible to certain types of persons involved in the operation of the site (administration, sales, marketing, legal, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Controller. The updated list of Data Processors can always be requested from the Data Controller.


Legal Basis of Processing

The Data Controller processes Personal Data relating to the User if one of the following conditions exists:

  1. The User has given consent for one or more specific purposes; Note: in some jurisdictions, the Data Controller may be authorized to process Personal Data without the User’s consent or another legal basis specified below, until the User objects (“opt-out”) to such processing. This is not, however, applicable if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
  2. Processing is necessary for the performance of a contract with the User and/or for pre-contractual measures;
  3. Processing is necessary to comply with a legal obligation to which the Data Controller is subject;
  4. Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
  5. Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.

It is always possible to ask the Data Controller to clarify the concrete legal basis of each processing and, in particular, to specify whether the processing is based on the law, provided for by a contract, or necessary to conclude a contract.


Location

  • Data is processed at the operational offices of the Data Controller and in any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.
  • The Personal Data of the User may be transferred to a country other than that in which the User is located. To obtain further information on the place of processing, the User can refer to the section concerning the details of the processing of Personal Data.
  • The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization of public international law or consisting of two or more countries, such as the UN, as well as regarding the security measures taken by the Data Controller to protect the Data.
  • If one of the transfers described above takes place, the User can refer to the respective sections of this document or request information from the Data Controller by contacting them at the opening address.

Retention Period

The Data is processed and stored for the time required by the purposes for which it was collected.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until such contract is fully performed.
  • Personal Data collected for purposes related to the legitimate interests of the Data Controller will be retained until such interests are satisfied. The User can obtain further information about the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.

When the processing is based on the User’s consent, the Data Controller may retain the Personal Data longer until such consent is revoked. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or an order from an authority.

At the end of the retention period, the Personal Data will be deleted. Therefore, at the end of this term, the right of access, deletion, rectification, and the right to data portability cannot be exercised.


Purposes of Processing of the Collected Data

User Data is collected to allow the Data Controller to provide its Services, as well as for the following purposes: Statistics, Management of email addresses and sending of email messages, Payment management, Interaction with social networks and external platforms, Contacting the User, Spam protection, Affiliate marketing, Management of landing pages and invitation pages, Performance testing of content and features (A/B testing), Management of User databases, Heat mapping and session recording, Interaction with online survey platforms, and Interaction with live chat platforms.

For further detailed information on the purposes of processing and on the Personal Data relevant to each purpose, the User can refer to the respective sections of this document.


Details on the Processing of Personal Data

Personal Data is collected for the following purposes and using the following services:

Facebook Permissions requested by this Site

This Site may request certain Facebook permissions that allow it to perform actions with the User’s Facebook account and to collect information, including Personal Data, from it.

For more information on the following permissions, please refer to the Facebook permissions documentation and the Facebook privacy policy.

The requested permissions are as follows:

Basic information

Basic information about the User registered on Facebook, which normally includes the following Data: id, name, picture, gender, and language localization, and in some cases, the “Friends” of Facebook. If the User has made additional data publicly available, it will be available as well.

Sharing

Sharing on behalf of the User.

Insights

Provides access to Insight data for pages, applications, and domains owned by the User.

Like

Provides access to the list of all pages that the User has liked.

Friends ‘About me’

Provides access to the ‘About me’ section of the friends’ profile.

Access to private data

Allows access to the User’s and friends’ private data.

Access to activities

Provides access to the list of User activities.

Access to friends lists

Provides access to the lists of friends that the User has created.

Access to requests

Provides read access to the User’s friend requests.

Access to News Feed

Provides access to News Feed posts and allows the application to search on it.

Status update

Updates the User’s status.


Implementation for Contacting the User and being contacted by the User.

Mailing List or Newsletter (This Site)

By registering for the mailing list or newsletter, the User’s email address is automatically added to a list of contacts to which email messages containing information, also of a commercial and promotional nature, related to this Site may be transmitted. The User’s email address may also be added to this list as a result of registering on this Site or after making a purchase.

Personal data collected: Email and Name.

Contact Form (This Site)

By filling in the contact form with their Data, the User consents to their use to respond to requests for information, quotes, or any other kind of request as indicated by the form’s header.

Personal data collected: Email and Name.

Whatsapp WEB (Facebook Inc.)

The “Contact us with Whatsapp” button and associated widgets are a messaging service for interaction via the “Whatsapp” web application.

Location of processing: USA

  1. Update of the Terms of service and the Privacy policy for users in the European Union
  2. Whatsapp Privacy Policy

Facebook Messenger (Facebook Inc.)

The “Contact us with Facebook Messenger” button and associated widgets are a messaging service for interaction via the “Facebook Messenger” web application.

Location of processing: USA

Policy on data collected by Facebook (This policy describes the information we process to support Facebook, Instagram, Messenger, and other products and functions offered by Facebook Inc.)


Management of Email Addresses and Mail Sending

  • These services allow the management of a database of email contacts, phone contacts, or contacts of any other type, used to communicate with the User.
  • These services may also allow the collection of data concerning the date and time of display of messages by the User, as well as the User’s interaction with them, such as information on clicks on links inserted in messages.

MailChimp (The Rocket Science Group, LLC.)

MailChimp is an email address management and message sending service provided by The Rocket Science Group, LLC.

Personal Data collected: email.

Location of processing: USA – Privacy Policy.

Contact Form 7

Contact Form 7 is a form creation and management service that allows this site to integrate such content within its pages provided by TypeForm S.L.

Personal data collected: Email and Name. Various types of Data as specified by the privacy policy of the service.

Location of processing: Japan – Privacy Policy


SPAM Protection

These services analyze the traffic on this Site, potentially containing Personal Data of Users, in order to filter it from parts of traffic, messages, and content recognized as SPAM.

Google reCAPTCHA (Google Inc.)

Google reCAPTCHA is a SPAM protection service provided by Google Inc.
The use of the reCAPTCHA system is subject to the privacy policy and terms of use of Google.

Personal Data collected: Cookie and Usage Data.

Location of processing: United States – Privacy Policy. Subject to the Privacy Shield.

Akismet (Automattic Inc.)

Akismet is a SPAM protection service provided by Automattic Inc.

Personal Data collected: Various types of Data as specified by the privacy policy of the service.

Location of processing: United States – Privacy Policy.


Access to Third-Party Services

These services allow this Site to retrieve data from your accounts on third-party services and perform actions with them.
These services are not activated automatically but require the express authorization of the User.

Twitter Account Access (Twitter, Inc.)

This service allows this Site to connect with the User’s account on the Twitter social network, provided by Twitter, Inc.
Personal data collected: Various types of data as specified by the privacy policy of the service.

Location of processing: USA – Privacy Policy

Facebook Account Access (This Site)

This service allows this Site to connect with the User’s account on the Facebook social network, provided by Facebook, Inc.
Permissions required: Share, Insights, and Likes.

Location of processing: USA – Privacy Policy


Statistical Analysis

The services in this section allow the Data Controller to monitor and analyze traffic data and are used to track User behavior.

Google Analytics (Google Inc.)

Google Analytics is a web analytics service provided by Google Inc. (“Google”). Google uses personal data collected for the purpose of tracking and examining the use of this Site, compiling reports, and sharing them with other Google services.
Google may use personal data to contextualize and personalize the ads of its advertising network.

The following link https://tools.google.com/dlpage/gaoptout?hl=it also provides the Google Analytics browser add-on for opt-out.

Personal data collected: Cookies and Usage Data.

Location of processing: USA – Privacy PolicyOpt Out

Facebook Ads Conversion Tracking (Facebook, Inc.)

Facebook Ads Conversion Tracking is a statistics service provided by Facebook, Inc. that connects data from the Facebook ad network with actions performed within this site.
Personal data collected: Cookies and Usage Data.

Location of processing: USA – Privacy Policy


Content Commenting

Commenting services allow Users to make and publish their comments on the content of this Site.
Users, depending on the settings chosen by the Data Controller, can leave comments anonymously. If the User’s email is among the Personal Data released by the User, it may be used to send notifications of comments regarding the same content. Users are responsible for the content of their comments.

In the case that a commenting service provided by third parties is installed, it is possible that, even if Users do not use the commenting service, it may collect traffic data related to the pages where the commenting service is installed.

Indirectly Managed Comment System (Disqus)

This site has an indirectly managed content commenting system.

DISQUS (DISQUS)

Disqus is a content commenting service provided by Big Heads Labs Inc.
Personal data collected: Cookies, Usage Data, and various types of data as specified by the privacy policy of the service.

Location of processing: USA – Privacy PolicyOpt Out

Info: https://help.disqus.com/customer/portal/articles/466235-use-of-cookies

FACEBOOK COMMENTS (FACEBOOK, INC.)

Facebook Comments is a service managed by Facebook, Inc. that allows the User to leave their comments and share them within the Facebook platform.
Personal data collected: Cookies and Usage Data.

Location of processing: USA – Privacy Policy


Interaction with Social Networks

These services allow interactions with social networks or other external platforms directly from the pages of this Site.
Interactions and information obtained by this Site are always subject to the User’s privacy settings for each social network.

In the case that a service of interaction with social networks is installed, it is possible that, even if Users do not use the service, it may collect traffic data related to the pages where it is installed.

LinkedIn Social Button and Widgets (LinkedIn Corporation)

The LinkedIn social button and widgets are services for interacting with the LinkedIn social network, provided by LinkedIn Corporation.
Personal data collected: Cookies and Usage Data.

Location of processing: USA – Privacy Policy

Facebook Like Button and Social Widgets (Facebook, Inc.)

The “Like” button and social widgets for Facebook are services for interacting with the Facebook social network, provided by Facebook, Inc.
Personal data collected: Cookies and Usage Data.

Location of processing: USA – Privacy Policy

Twitter Tweet Button and Social Widgets (Twitter, Inc.)

The Tweet button and social widgets for Twitter are services for interacting with the Twitter social network, provided by Twitter, Inc.
Personal data collected: Cookies and Usage Data.

Location of processing: USA – Privacy Policy

Pinterest Button (Pinterest, Inc.)

The Pinterest button is a service for interacting with the Pinterest social network, provided by Pinterest, Inc.
Personal data collected: Cookies and Usage Data.

Location of processing: USA – Privacy Policy


Content on External Platforms

These services allow you to view content hosted on external platforms directly from the pages of this Site and interact with them.
In the case that a service of this kind is installed, it is possible that, even if Users do not use the service, it may collect traffic data related to the pages where it is installed.

Video Vimeo (Vimeo, LLC)

Vimeo is a video content viewing service operated by Vimeo, LLC, which allows this Application to integrate such content into its pages.
Personal data collected: Cookies and Usage Data.

Location of processing: USA – Privacy Policy

YouTube Video Widget (Google Inc.)

YouTube is a video content viewing service operated by Google Inc., which allows this Site to integrate such content into its pages.
Personal data collected: Cookies and Usage Data.

Location of processing: USA – Privacy Policy

Google Font (Google Inc.)

Google Fonts is a font style display service operated by Google Inc., which allows this Site to integrate such content into its pages.
Personal data collected: Cookies and usage data.

Location of processing: USA – Privacy Policy

Google Maps (Google Inc.)

Google Maps is a map display service operated by Google Inc., which allows this Site to integrate such content into its pages.
Personal data collected: Cookies and usage data.

Location of processing: USA – Privacy Policy

Google Translator (Google Inc.)

Google Translate provides automatic translation of the Site into various languages, which the user can choose from the widget at the top of each page of the site.
Personal data collected: Cookies and usage data.

Location of processing: USA – Privacy Policy

Instagram Widget (Instagram, Inc.)

Instagram is an image display service provided by Instagram, Inc., which allows this website to embed content of this type on its pages.
Personal data collected: Cookies and Usage Data.

Location of processing: United States – Privacy Policy.

Leadin Widget (HubSpot Inc.)

Leadin is an email address management and user behavior tracking service on the site for statistical purposes provided by HubSpot, Inc.
Leadin is used to collect user personal data. Once registered, the service collects data on user behavior on the site, such as pages visited and viewing time.

Personal data collected: Cookies, Usage Data, Name, Surname, Email Address.

Location of processing: USA – Privacy Policy

TAWK.TO Chat

Tawk.to is a live chat with visitor data recording.
Personal data collected: Cookies and usage data.

Location of processing: Latvia – Privacy Policy.

Data Protection Disclaimer (https://www.tawk.to/data-protection/) :

  1. GDPR Compliance Disclaimer
  2. SUB Processor List
  3. DPA | Data Processing Addendum

Remarketing and Behavioral Targeting

This type of service allows the company and its partners to communicate, optimize, and serve advertising based on the User’s past use of the company.
This activity is carried out by tracking Usage Data and using Cookies, information that is transferred to the partners to whom the remarketing and behavioral targeting activity is linked.

In addition to the opt-out options offered by the services listed below, the User can opt-out of receiving cookies related to a third-party service by visiting the Network Advertising Initiative opt-out page.

Facebook Remarketing (Facebook, Inc.)

Facebook Remarketing is a remarketing and behavioral targeting service provided by Facebook, Inc. that connects the company’s activity with the Facebook advertising network.
Personal data collected: Cookies and Usage Data.

Location of processing: USA – Privacy PolicyOpt Out.

AdWords Remarketing (Google Inc.)

AdWords Remarketing is a remarketing and behavioral targeting service provided by Google Inc. that connects the company’s activity with the Adwords advertising network and the Doubleclick Cookie.
Personal data collected: Cookies and Usage Data.

Location of processing: USA – Privacy PolicyOpt Out.

Remarketing with Google Analytics for display advertising (Google Inc.)

Google Analytics for display advertising is a remarketing and behavioral targeting service provided by Google Inc. that connects the tracking activity carried out by Google Analytics and its Cookies with the Adwords advertising network and the Doubleclick Cookie.
Personal data collected: Cookies and Usage Data.

Location of processing: USA – Privacy PolicyOpt Out.


Tag Management

This type of service helps the Owner manage the tags or scripts needed on this Application centrally.
This results in user data flowing through these services, potentially resulting in the retention of this data.

Google Tag Manager (Google LLC)

Google Tag Manager is a tag management service provided by Google LLC.
Personal data collected: cookies and usage data.

Location of processing: United States – Privacy Policy. Participant in Privacy Shield.


DNS Services

CloudFlare is a traffic optimization and distribution service provided by CloudFlare Inc.
The integration methods of CloudFlare involve filtering all traffic on this Site, i.e., communications between this Site and the User’s browser, also allowing the collection of statistical data on it.

Personal data collected: Various types of data as specified in the privacy policy of the service.

Location of processing: USA – Privacy Policy


Further information on Personal Data

Server: Siteground

This site is hosted on servers provided by the hosting provider SITEGROUND Spain S.L. is a company registered and existing under the laws of the Kingdom of Spain (registration number CIF: B87194171), with registered address: Calle de Prim 19, 28004 Madrid, Spain, and is responsible for the processing of personal data that we collect.

Privacy policy of SITEGROUND : https://it.siteground.com/privacy?scid=3&lang=it_IT

User Rights

Users can exercise certain rights with reference to the Data processed by the Owner.
In particular, the User has the right to:

  • revoke consent at any time. The User can revoke the consent to the processing of their Personal Data previously expressed.
  • object to the processing of their Data. The User may object to the processing of their Data when it occurs on a legal basis other than consent. Further details on the right of opposition are set out in the section below.
  • access their Data. The User has the right to obtain information on the Data processed by the Owner, on certain aspects of the processing, and to receive a copy of the Data processed.
  • verify and request rectification. The User can verify the correctness of their Data and request its update or correction.
  • obtain the limitation of the processing. When certain conditions are met, the User may request the limitation of the processing of their Data. In this case, the Owner will not process the Data for any other purpose than their retention.
  • obtain the cancellation or removal of their Personal Data. When certain conditions are met, the User may request the cancellation of their Data by the Owner.
  • receive their Data or have it transferred to another data controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to obtain its transfer without hindrance to another controller. This provision is applicable when the Data is processed with automated tools and the processing is based on the User’s consent, on a contract of which the User is a party, or on contractual measures connected to it.
  • file a complaint. The User can file a complaint with the competent data protection supervisory authority or take legal action.

Details on the right of opposition

When Personal Data is processed in the public interest, in the exercise of public powers vested in the Owner or for the pursuit of a legitimate interest of the Owner, Users have the right to object to the processing for reasons related to their particular situation.
Users are reminded that if their Data is processed for direct marketing purposes, they can object to the processing without providing any reason. To find out if the Owner processes data for direct marketing purposes, Users can refer to the respective sections of this document.

How to exercise rights

To exercise User rights, Users can send a request to the contact details of the Owner indicated in this document. Requests are filed free of charge and processed by the Owner as soon as possible, in any case within one month.

Applicability of the higher level of protection

While most of the provisions of this document apply to all Users, some are expressly subject to the application of a higher level of protection to the processing of Personal Data.
This higher level of protection is always guaranteed when the processing:

  • is carried out by a Holder based in the EU;
  • concerns Personal Data of Users who are in the EU;
  • involves the processing of Personal Data collected in the EU.

Further information on processing

Defense in court

The User’s Personal Data may be used by the Owner in court or in the preparatory stages of legal action arising from improper use of this Application or related services by the User.
The User declares to be aware that the Owner may be required to disclose the Data upon request of public authorities.

Specific information

Upon User request, in addition to the information contained in this privacy policy, this Site may provide the User with additional and contextual information regarding specific services, or the collection and processing of Personal Data.

System logs and maintenance

For operation and maintenance purposes, this Site and any third-party services used by it may collect system logs, i.e., files that record interactions and that may also contain Personal Data, such as the User IP address.

Information not contained in this policy

More information in relation to the processing of Personal Data may be requested at any time from the Owner using the contact details.

Response to “Do Not Track” requests

This Site does not support “Do Not Track” requests.
To determine whether any of the third-party services it uses honor the “Do Not Track” requests, please read their privacy policies.

Changes to this privacy policy

The Owner reserves the right to make changes to this privacy policy at any time by giving notice to its Users on this page and possibly within this Site and/or – as far as technically and legally feasible – sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
If a User objects to any of the changes to the Policy, the User must cease using this Site and can request that the Owner removes their Personal Data. Unless stated otherwise, the then-current privacy policy applies to all Personal Data the Owner has about Users.

Information about this privacy policy

The Data Controller is responsible for this privacy policy.

Definitions and legal references

Personal Data (or Data)

Any information that directly or indirectly, also in connection with any other information, including a personal identification number, makes the natural person identified or identifiable.

Usage Data

Information collected automatically from this Site (or third-party services employed in this Site), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Site, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.

User

The individual using this Site, which must coincide with or be authorized by the Data Subject, to whom the Personal Data refers.

Data Subject

The legal or natural person to whom the Personal Data refers.

Data Processor (or Data Supervisor)

The natural person, legal person, public administration or any other body, association or organization authorized by the Data Controller to process the Personal Data in compliance with this privacy policy.

Data Controller (or Owner)

The natural person, legal person, public administration or any other body, association or organization with the right, also jointly with another Data Controller, to make decisions regarding the purposes, and the methods of processing of Personal Data and the means used, including the security measures concerning the operation and use of this Site. The Data Controller, unless otherwise specified, is the Owner of this Site.

This Site (or this Application)

The hardware or software tool by which the Personal Data of the User is collected.

Cookie

Small piece of data stored in the User’s device.

Legal information

Notice to European Users: this privacy statement has been prepared in fulfillment of the obligations under Art. 10 of EC Directive n. 95/46/EC, and under the provisions of Directive 2002/58/EC, as revised by Directive 2009/136/EC, on the subject of Cookies.

This privacy policy relates solely to this Site.

Menu