Privacy Policy
INFORMATION PROVIDED PURSUANT TO REGULATION (EU) 2016/679
Welcome to our website!
PASTA MANCINI is committed to protecting the privacy, security, and integrity of the personal data of all individuals with whom we interact. Please read our Privacy Policy carefully. It applies whenever you access or use our website and its services.
Data Processing
By browsing this website, you may be subject to the processing of personal data. This section outlines how we handle the data collected through pastamancini.com and shop.pastamancini.com, both owned by PASTA MANCINI. This policy is provided in accordance with Regulation (EU) 2016/679 (hereafter referred to as the "GDPR") and applicable Italian national legislation, namely Legislative Decree 196/2003, as amended.
Data Controller
The data controller is AZIENDA AGRICOLA MANCINI SOCIETA’ AGRICOLA S.R.L. with registered office at Via Ernesto Paoletti, 1 – 63815 – Monte San Pietrangeli (FM), Italy. Fiscal Code/VAT Number: 01988090443. Tel: (+39) 0734 969311. Email: info@pastamancini.it. For brevity, the company will be referred to as "PASTA MANCINI", "the Company" or "the Data Controller" in this policy.
Types of data processed
Browsing Data
The software applications used to operate the PASTA MANCINI website acquire certain personal data transmitted through secure protocols. This information is not collected to be associated with identified 1 individuals but may, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses, 2 browser identifiers (user agent), URI (Uniform Resource Identifier) addresses of 3 requested resources, request time, method used to submit the request to the server, the numeric code indicating the status of the server's response (e.g., successful, error), and other parameters related to the user's operating system and 4 computer environment.
Data provided voluntarily by the user
The user is only asked to provide personal data (e.g., name, email, telephone number, etc.) when they wish to contact us or use the services offered on the website. In such cases, the user is provided with appropriate information and, where necessary, is asked to give their consent. The processing of the data provided by the user will be carried out in accordance with the purposes and methods indicated in this privacy policy and in any specific information provided from time to time.
Purposes, legal basis, and data retention period
Contacts and information requests – "Write to us"
Data provided directly by the data subject through the use of the contact channels on the website or by filling out and submitting the contact forms. The explicit and voluntary sending of messages to the contact addresses or the filling out of the forms in the dedicated sections involves the acquisition of the sender's contact data, as well as all personal data included in the communications. This data is processed for the following purposes and in compliance with the relevant legal basis for processing, for a retention period not exceeding that necessary for the purposes for which it was collected and processed.
Types of data processed: name, email, telephone number;
Purpose of processing:
- Management of the user's request;
- Provision of the requested service (e.g., response to the user's request, preparation of quotes, information requests, etc.).
Legal basis: Article 6(1)(b) of the GDPR; The processing is necessary to respond to the user's requests; for the performance of pre-contractual and contractual measures taken at the request of the data subject.
Data retention: User requests and the data contained therein will be kept only for the time necessary to allow the Data Controller to identify the correct closure of the request and in any case for as long as may be necessary to protect the Data Controller's interests from potential liability. At the end of this period, the data that allow the identification, even indirect, of a natural person (such as name, email) will be made anonymous and kept, in the form of aggregated data, for statistical purposes.
Further communications following a purchase of goods or services
Following the purchase of a product, PASTA MANCINI may send the user further information, including commercial communications (soft spam), relating to the same product category as the purchases made (such as price list updates). The legal basis for the aforementioned processing is the legitimate interest of the data controller, pursuant to Article 130 of national law, without prejudice to the user's right to object to the sending of such communications at any time, in the manner indicated below or contained in each communication sent.
Newsletter and direct content
If you provide your specific consent (by subscribing to our newsletter), PASTA MANCINI may send you email information about new products, promotions, and special offers. Subscription to the newsletter is optional, explicit, and voluntary; this activity involves the acquisition of the sender's contact data. The data is processed for the following purpose and in compliance with the relevant legal basis for processing, for a retention period not exceeding that necessary for the purposes for which it was collected and processed.
Types of data processed: name, email.
Purpose of processing: Commercial and marketing activities such as:
- Sending newsletters, commercial information via email, regarding new products, promotions, and special offers.
Legal basis: Article 6(1)(a) of the GDPR; Consent of the data subject – Opt-out: Possibility to revoke your consent at any time in each communication/newsletter or by writing to the Data Controller. Once consent has been revoked, the Data Controller will no longer use personal data for these purposes, but may still retain it, in particular as may be necessary to protect the Data Controller's interests from potential liabilities based on such processing.
MailChimp is used to manage the newsletter. Further information on the type, scope, and purpose of data processing is provided in the provider's privacy policy, which can be consulted at MailChimp policy.
Unsubscribing from the service
The user may disable the service at any time through the appropriate procedure. To stop receiving the newsletter, simply click on the "Unsubscribe" button in each newsletter email or send a communication to the following email address: info@pastamancini.it.
Work with us
Data provided directly by the data subject by sending a communication to the indicated contact address and any CV (Curriculum Vitae).
The explicit and voluntary sending of messages and attachments to the contact address on the website involves the acquisition of the sender's contact data, as well as all personal data included in the attached curriculum.
Types of data processed: The personal data processed includes identification data (name, surname, tax code); contact data (email address, telephone, mobile phone, etc.); educational qualifications, work experience, and any additional data included in the CV, strictly necessary for the activities of searching, recruiting and selecting personnel, exclusively for the purpose of evaluating the profile in relation to the available vacancies from time to time, as well as to allow the achievement of the purposes listed below. The company may process "sensitive personal data", where necessary pursuant to Article 9, paragraph 2, letter b) of the GDPR, such as data suitable to reveal health status (such as, for example, belonging to protected categories), which may be contained in the CV or in any further documentation transmitted to the company. The aforementioned data is collected directly from the data subject and/or from third parties in relation to previous work experience (only with prior consent) and/or from publicly accessible sources such as, for example, the professional profile on professional social networks (within the limits of this privacy policy).
Purpose of processing:
- carrying out the activity of searching for and selecting candidates in relation to all positions managed by the company, the evaluation of the profile, aptitudes and professional skills, aimed at establishing an employment or collaboration relationship with the Data Controller; 2) special categories of data may be processed exclusively to evaluate the candidacy for job positions falling within the scope of targeted placement, in order to fulfill the obligations and exercise the specific rights of the Data Controller or the data subject in matters of labor law and social security and protection. In the absence of such a case, as well as in the absence of the conditions set out in Article 9 of the GDPR, such data will not be taken into consideration and will be immediately deleted; 3) only with prior consent to obtain information relating to professional references from previous employers; 4) the company may also process public information relating to the profile present on professional social networks to verify that the data provided corresponds to what has been declared, limited to the professional information useful for the selection in progress; 5) to ascertain, exercise or defend the rights of the Data Controller in an out-of-court and/or judicial setting.
Legal basis: The legal bases for processing are found in Article 6(1)(a), (b) and (f), and Article 9(2)(b) of the GDPR.
Data retention: The processing will have a duration not exceeding that necessary for the purposes for which the data was collected. After the retention periods have expired, all data will be destroyed or made anonymous, consistent with the technical procedures for deletion and backup; more specifically, the data will be deleted after a maximum of 24 consecutive months have elapsed without any event occurring, such as a modification of the data or the scheduling of an interview, or until any request for deletion.
Customer area (restricted access) - Account and Registration – Shop online portal
The restricted area available on this website is accessible to users who have previously completed the registration process. Through the registration or authentication process, the user authorizes the website application to recognize them and provide them with access to exclusive features, present in the online purchasing portal (E-commerce). The registration and authentication processes can be managed directly or with the support of external entities. In the latter case, the application will be able to access certain data stored by the third-party service used for registration or identification.
Direct registration (this Website): The user registers by filling out the registration form and providing this Website directly with their personal data, such as name, surname, and email address.
Registration carried out through the service of third parties, such as:
- Facebook Authentication is a registration and authentication service provided by Facebook, Inc. and linked to the Facebook social network. Personal Data processed: various types of Data as specified in the service's privacy policy. Place of processing: United States - Privacy Policy.
- Google SignIn is a registration and authentication service provided by Google, linked to access to the Provider's account. Personal Data processed: various types of Data as specified in the service's privacy policy. Place of processing: United States - Privacy Policy.
- Twitter Oxi Social Login is a registration and authentication service provided by X (Twitter) and linked to the same social network. Personal Data processed: various types of Data as specified in the service's privacy policy. Place of processing: United States - Privacy Policy.
- LinkedIn LogIn is a registration and authentication service provided by LinkedIn and linked to the same social network. Personal Data processed: various types of Data as specified in the service's privacy policy. Place of processing: United States - Privacy Policy.
- Amazon SignIn is a registration and authentication service provided by Amazon, linked to access to the Provider's account. Personal Data processed: various types of Data as specified in the service's privacy policy. Place of processing: United States - Privacy Policy.
PASTA MANCINI will process the user's personal data to allow the use of services reserved for registered users. The legal basis for this processing is the performance of the contract or, depending on the case, the execution of pre-contractual measures taken at the request of the data subject. For these purposes, the data will be processed for the time strictly necessary to carry out the individual processing activities. PASTA MANCINI may, however, retain the data for a longer period of time in order to fulfill specific obligations established by Regulations and/or laws in force to which the Data Controller is subject. For this purpose, the Data Controller will process users' personal data for:
- Allowing the user to access the Site and browse it;
- Allowing the user to register on the Site, creating an account, and to use the services reserved for registered users, including the possibility of purchasing through the Site and exercising the right of withdrawal;
- Allowing the user to access the Site and browse as a logged-in user, recognizing the user regardless of the device used;
- Maintaining and managing the user's account;
- Storing in the account data and information of the user (personal data, history of their orders, any returns, delivery addresses, etc.);
- Allowing the user to insert products into the Cart and to conclude the purchase contract through the Site;
- Allowing the user to make online payments for purchases made on the Site;
- Executing the purchase contract;
- Receiving commercial communications in support of the purchase and/or customer satisfaction. The provision of data for the aforementioned purpose is optional and does not prevent the user from making online purchases. However, since the processing is necessary to allow access to the Site and/or browsing as a logged-in user and/or the provision of account management and maintenance services, failure to communicate the data will make it impossible for the user to register, access the restricted area of the Site and use the services reserved for registered users. The email address of the user who has registered an account on the Site will also be processed by PASTA MANCINI for sending the Data Controller's informative and commercial newsletter, concerning the same product category as the purchases made. The legal basis that legitimizes the sending of this newsletter is the legitimate interest of the Data Controller (Article 130, paragraph 4 of Legislative Decree 196/2003 and Recital 47 of the GDPR). The data subject may at any time object to such processing by using the appropriate unsubscribe link, present at the bottom of each promotional communication.
Online Purchasing Portal Management (E-commerce)
Regardless of whether or not the User has logged in, PASTA MANCINI will process the user's personal data to allow them to purchase products online through the Site, to allow the conclusion of the purchase contract and for the correct execution of the obligations arising from such contract, and finally, to follow up on any requests sent by the user. PASTA MANCINI will also process user data to fulfill the consequent legal obligations and administrative and accounting requirements. To purchase products, you can use various payment methods (credit card, Paypal, etc.). During the purchase process, the user must provide some financial information to complete the purchase and/or request the issuance of an invoice (VAT number, tax code, etc.). To proceed with the shipment of the product purchased online, the user must also provide the information required for the shipment of the order to their home (name, surname, shipping address, telephone number and email address). The legal basis for the aforementioned processing is the performance of the contract by PASTA MANCINI.
For these purposes, the data will be processed for the time strictly necessary to carry out the individual processing activities and no longer than 10 years from the date of purchase. If required by specific regulations, the data retention period may be longer. The provision of data for this purpose is optional. However, the failure, partial or inaccurate provision of data may make it impossible for the Data Controller to execute the online purchase contract and for the user to obtain the requested product(s). The service is not intended for minors under the age of 18, as defined by applicable law. PASTA MANCINI does not knowingly collect data, including personal data, on minors or other individuals who are not legally able to use the site and its services. If we become aware that we have collected the personal data of a minor, we will immediately delete it, unless we are legally obliged to retain such data. The user is requested to contact us if they believe that PASTA MANCINI has erroneously or unintentionally collected information about a minor. For further information, please refer to the sales " Terms and Conditions" on the website.
ADDITIONAL PURPOSES
Furthermore, the data may be processed for additional purposes, such as:
- Contractual purposes, related and instrumental to the establishment and management of relations with customers, such as the acquisition of preliminary information for the possible conclusion of a contract; in this case, the data will be kept by the Data Controller for the time strictly necessary for the execution of the requested service and for the correct execution of the contractual relationship with the user. In any case, since such personal data is processed to provide the services and allow the execution of the contractual relationship, the Data Controller may retain it for a longer period, in particular as may be necessary to protect the interests of the Data Controller itself from potential liabilities. At the end of this period, the data will be deleted.
- Fulfilling obligations required by State laws, regulations and Community regulations, or provisions issued by authorities authorized by law and by control bodies (e.g. tax, accounting, administrative, etc.); in this case, the data will be kept by the Data Controller for the period provided for by specific legal obligations or by applicable regulations.
- Exercising the rights of the Data Controller in court and managing any disputes.
- Statistics: Collection of data and information in an exclusively aggregated and anonymous form in order to verify the correct functioning of the site, with a view to continuous improvement. None of this information is related to the physical person-user of the site, and does not in any way allow their identification.
- Security: Collection of data and information in order to protect the security of the site and users (spam filters, firewalls, virus detection) and to prevent or uncover fraud or abuse to the detriment of the website. The data, including the domain names of the computers used by users who connect to the site, the Uniform Resource Identifier (URI) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (success, error, etc.) and other parameters relating to the operating system and the user's computer environment, are automatically recorded and may also include personal data (IP address) that could be used, in accordance with the applicable laws, in order to block attempts to damage the site itself or to harm other users, or in any case harmful or criminal activities. Such data is never used to identify or profile the user and is deleted periodically.
- Cookies: Cookies are small text strings that the websites visited by the user send to their terminal (usually the browser), where they are stored and then retransmitted to the same sites on the subsequent visit by the same user. During navigation on a website, the user may also receive cookies on their terminal that are sent by sites or web servers of different parties (so-called "third parties"), on which some elements may reside (such as, for example, images, maps, sounds, specific links to pages of other domains) present on the site that the user is visiting. Cookies, usually present in large numbers in users' browsers and sometimes even with very long persistence characteristics, are used for different purposes: execution of computer authentications, monitoring of sessions, storage of information on specific configurations concerning users who access the server, etc. For more information, please refer to the site's Cookie policy.
Unless otherwise specified, the processing of personal data will take place for the entire period in which the data subject uses this website and the services provided through it. In case of withdrawal of consent, personal data will be kept by the Data Controller in order to prove the fulfillment of its obligations, until their prescription.
Optional nature of data provision
Apart from what is specified for browsing data, the user is free to decide whether or not to provide their personal data through this website and/or the services connected to it. Failure to provide the data may make it impossible to provide the requested service. The mandatory nature of any information requested is marked with an asterisk (*). Any refusal to communicate to PASTA MANCINI certain data marked as mandatory makes it impossible to pursue the main purpose of the specific collection: such refusal could, for example, make it impossible for PASTA MANCINI to conclude the contract, or to provide the other services available on its websites. The provision to PASTA MANCINI of additional data, other than those marked as essential, is optional and does not entail any consequences with regard to the pursuit of the main purpose of the collection.
Data processing location
The processing related to the web services of PASTA MANCINI and the related acquired data will be processed by the Data Controller in Italy, within the territory of the European Union and the European Economic Area. If, for technical, organizational and/or operational reasons, it is necessary to use subjects located outside the European Economic Area, please be informed that the Data Controller will ensure that the processing of data by these subjects takes place in compliance with applicable law. Therefore, transfers will be carried out through adequate guarantees, such as adequacy decisions, standard contractual clauses approved by the European Commission or other guarantees considered adequate. The data subject may request more information by writing to the references of the Data Controller indicated at the beginning of this information.
Methods and security of processing The processing of personal data takes place through IT tools suitable for guaranteeing the security and confidentiality of the data itself and in any case in compliance with the appropriate security measures as required by art. 32 GDPR, through secure communication protocols with SSL encryption algorithms. Personal data will be processed in accordance with the legislative provisions of the aforementioned legislation and the confidentiality obligations provided therein.
Sharing website content through social networks We are present on social media platforms to communicate with interested parties and to inform them about our activities. The processing of personal data may also take place outside the European Economic Area (EEA). In any case, the General Terms and Conditions (T&C) and Terms of Use, as well as the data protection statements and other provisions of the individual operators of these online platforms, apply. These provisions provide information in particular on the rights of data subjects, including in particular the right of access to information. In fact, through the PASTA MANCINI website it is possible to share content through Social Networks. All "social plug-ins" present on the site are marked with the respective logo owned by the social network platform. The user is free to decide if and what content to share on one or more social networks (Facebook, Linkedin, etc.). In this case, please note that no personal data of the user is acquired by PASTA MANCINI and the user is invited to check the settings of their account on the social network in order to identify any data acquired by external platforms. For information on the purposes, type and methods of collection, processing, use and storage of personal data by the Social Network platform, as well as for the methods through which to exercise your rights, please consult the specific Privacy Policy of the Social Network. Privacy Policy - Facebook. Privacy Policy - Instagram. Privacy Policy - Linkedin
Recipients
Personal data will be processed by personnel in charge of developing and managing the website who are authorized to process it for the purposes indicated above and who have undertaken to maintain confidentiality or have received an adequate legal obligation of confidentiality. Personal data will be processed by subjects appointed as data processors as they process data on behalf of the Data Controller (e.g. subjects with whom it is necessary to interact for the provision of services such as hosting providers, providers of platforms for sending e-mails or, again, any subjects delegated to carry out technical maintenance activities including the maintenance of network equipment and electronic communication networks, subjects that provide the payment technology platform for product orders in the e-payments area, etc.). Personal data may be shared with third parties with whom PASTA MANCINI has ongoing contractual relationships for services functional to the performance of the activity (such as, for example, companies responsible for managing and fulfilling sales orders, carriers for the delivery of products, professionals, companies or professional firms that provide assistance and consultancy services in accounting, administrative, legal, tax, financial and debt recovery matters relating to the provision of services, etc.). The data may be communicated, even without consent, to all inspection bodies responsible for verification and control, such as the Revenue Agency, ministerial bodies and competent authorities, local authorities, tax commissions of any order and degree, at their express request, who will process them as independent data controllers for institutional purposes and/or by virtue of the law during investigations and controls. Personal data is not intended for publication or dissemination. A complete list of appointed data processors is available from the Data Controller.
Rights of the data subjects Articles 15 and following of the GDPR EU 2016/679 confer specific rights to data subjects. In particular, the right to obtain confirmation of the existence or non-existence of personal data, access to personal data and the rectification or erasure of the same or the restriction of processing concerning them or to object to their processing, in addition to the right to data portability, the communication of such data and the purposes on which the processing is based. Furthermore, data subjects have the right to obtain the withdrawal of consent at any time without prejudice to the lawfulness of processing based on consent given before revocation, the transformation into anonymous form or the blocking of data processed in violation of the law, as well as the updating or, if there is an interest in doing so, the integration of the data. Data subjects have the right to object, for legitimate reasons, to the processing itself. The exercise of these rights is not subject to any time limit and can be exercised free of charge by contacting the Data Controller at the addresses indicated at the beginning of this information by ordinary mail and/or e-mail.
Data subjects who believe that the processing of personal data concerning them carried out through this site is in violation of the provisions of the Regulation have the right to lodge a complaint with a supervisory authority (for Italy: Garante per la protezione dei dati personali www.garanteprivacy.it), as provided for by Article 77 of the Regulation itself, or to bring legal action (Article 79 of the Regulation).
Modifications and updates to the policy PASTA MANCINI reserves the right to modify or simply update the content of the site's Policy, in part or in whole, also due to changes in applicable law. Such changes will be binding as soon as they are published on the website. The Data Controller therefore invites the user to visit this section regularly to take note of the most recent and updated version of the Policy in order to always be informed about the personal data collected and the use made of it by the Data Controller.
Last update: 01/10/2024