Information provided pursuant to Articles 13 and 14 of the Regulation (EU) 2016/679 (GDPR) – Rev. GDPR 2.0 of 15/10/2018
In compliance with Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), we hereby inform you that Mottolino Spa processes the personal data you provide us voluntarily respecting your rights, freedoms, and dignity, with particular reference to confidentiality and identity. This privacy notice describes how we at Mottolino Spa process the personal data we collect through our Websites and any other site for portable devices, applications, widgets, and any other interactive function for portable devices (hereinafter collectively referred to as our Apps). You can read our privacy notice both during and after registration to our Websites by clicking on “Privacy / Cookie” at the bottom of each page of the site.
This privacy notice does not apply to third-party websites that may be linked to ours, for which we are not responsible in any way. The presence of any link to a different website does not imply our involvement or approval.
I. The source of the personal data we process
The personal data we process are collected directly from the data subject or our Mottolino Spa plants.
II. Data controller
The Data Controller is Mottolino Spa, with headquarters in Via Bondi 473, 23030 Livigno (Sondrio) - [email protected]
III. Data Protection Officer
Our Data Protection Officer is Massimo Castelli – [email protected]
IV. Purpose of processing
In compliance with the regulations in force, the personal data you provide by filling out our forms (personal details, email, phone number, photographs, images, texts, etc.) will be processed for the following purposes:
- adding them to the Mottolino Spa databases [legal grounds for processing: execution of contractual measures];
- meeting your specific requests [legal grounds for processing: our legitimate interest in responding to your requests];
- delivering and managing the Mottolino Key [legal grounds for processing: execution of contractual measures];
- prior your explicit consent, for market research and sending you informative, promotional, and/or advertising material regarding our services through – by way of example – text messages or instant messaging apps (e.g. Skype, WhatsApp, Telegram, Viber, Messenger, Hangouts, Chat, etc.), push notifications, e-mail, newsletters, fax, restricted areas of our website and/or traditional methods (cold calling and snail mail) [legal grounds for processing: your consent. You can withdraw your consent at any time as specified in Section XII Your data access rights];
- we may customise our communications based on your requirements based on the information of your profile and the way you interact with our Website or our commercial communications [legal grounds for processing: your consent. You can withdraw your consent at any time as specified in Section XII Your data access rights];
- sending administrative information, for example information regarding our Websites and changes to our terms and conditions or policies [legal grounds for processing: our legitimate interest in informing you about the changes in our websites];
- purposes that are functional to the comparison and logging of customer-related data through questionnaires to assess the level of satisfaction and improve the service [legal grounds for processing: your consent. You can withdraw your consent at any time as specified in Section XII Your data access rights];
- purposes that are functional to the use of personal data that identify the data subject (company name and logos) to create Mottolino Spa commercial, promotional, and advertising material [legal grounds for processing: your consent. You can withdraw your consent at any time as specified in Section XII Your data access rights];
- IT purposes: to diagnose server problems, manage websites and ensure that they work appropriately [legal grounds for processing: our legitimate interest in managing our IT systems and networks];
- protecting our legitimate interests (to meet legal requirements; respond to public and governmental authorities’ requests, even if not of your country of residence; have our terms and conditions complied with; protect our business; protect our and third-party rights, privacy, security, and property; be able to take all the measures available or limit the damage we may suffer) [legal grounds for processing: compliance with legal obligations and our legitimate interest in protecting Mottolino Spa].
The personal data you provide when you access our website will be used solely for providing the service you request and will not be disclosed to or shared with third parties, unless required by law or strictly necessary for meeting your request prior your written consent.
The optional, explicit, and voluntary sending of emails to the addresses indicated in this website involves the subsequent acquisition of your email address required for replying to the requests, as well as of any other personal information included in the communication.
We process personal data strictly necessary for providing the service you request. We do not process data when these purposes can be achieved through anonymous data or through methods that identify the user only when strictly necessary. When you send us an email to ask for further information, please do not include other names (if not strictly necessary) or special categories of personal data specified in Article 9 of the GDPR. Should you include third-party personal and contact details, you are aware that such an operation involves the processing of personal data other than your own for which you take full responsibility. In such cases, you guarantee that any personal data you indicate in your communication relating to third parties (which will be processed as if that third party has given their consent to processing) have been acquired in compliance with the GDPR. To this regard, you indemnify us against any complaint or claim for compensation for unlawful processing resulting from the acquisition of personal data provided by you in breach of the personal data protection standards.
We do not collect or share personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, neither do we process genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.
V. Who else may receive your personal data
Where necessary, we may share your personal data with the following subjects:
- subjects who are authorised by law, secondary regulations, EU directives, or a collective agreement to access such data;
- entities with whom sharing your personal data is necessary for managing the contractual relationship (consulting firms, offices who prepare payslips, Judicial Offices, Chambers of Commerce, Labour Offices, Public Security, Healthcare, and Police Authorities, Public Administration, Trade Unions, Airports, Travel Agencies, Customs and insurance companies, hotel booking services, IT and multimedia service providers, third-party service providers) with the methods and for the purposes described above. A list of these third parties is available at the Mottolino Spa headquarters;
- Mottolino Spa employees and collaborators within their duties, and/or contractual obligations, including data processors and appointed personnel;
- post offices, forwarders, and couriers for sending documentation and/or material;
- eCTRL Solutions Srl for booking and buying services online;
- Nexi S.p.A. for managing online payments;
- PayPal Europe S.a.r.l. & Cie, S.C.A. for managing online payments;
- Yourbiz Srl for statistics regarding browsing data;
- NBF Soluzioni Informatiche s.r.l. (Shopping Plus platform) for collecting customers’ personal data and data regarding the use of the Mottolino Key loyalty card;
- ContactLab S.p.A. for sending e-mails;
- Computer Halley S.r.l. for browsing statistics regarding the app;
- our third-party service providers for communications support, audits, and consulting services;
- our business partners with whom we may enter into a special relationship for the purposes of commercial communications. As these third parties can use your personal data in compliance with their privacy policies, we recommend you visit their websites for more information about how they process personal data.
We will always ask for your explicit consent should we ever need to share your personal data with third parties not included in this list.
VI. Dissemination of personal data
Personal data will not be disseminated.
VII. What personal data we process
Mottolino Spa processes personal data (personal, fiscal, communication and availability). We may collect and process the following information about you:
- Date of birth
- Telephone number (including landline and mobile phone numbers)
- Email address
- Public social media profiles
- Hobbies and interests
- Consumption habits
- Information about your browser and devices
- Information about the server’s log file
- Information collected through cookies, pixel tags, and other technologies
- Data regarding app use
- Personal data regarding your activity and involvement with our websites (date and time of activities carried out, such as access, registration for a promotion, etc.)
- Personal data regarding your commercial interactions (e.g. whether you open an email or select an offer)
PLEASE DO NOT SEND US ANY SENSITIVE DATA THROUGH OUR WEBSITE OR ANY OTHER MEDIUM.
Sensitive data is personal information revealing:
- Racial or ethnic origin
- Political opinions
- Religion or philosophical beliefs
- Trade union membership
- Health and medical conditions
- Criminal convictions
- Sexual orientation or sex life
We can collect your personal data:
- online, through our websites, for example when you create or use an account connected to our database
- offline, for example when you phone us.
In compliance with the standards in force, the personal data you provide through our websites may be combined with other personal data that you provide (online or offline) or that Mottolino Spa may obtain in other ways (online or offline).
VIII. Data transfer to a third country
The data processed for the above purposes may be transferred to other EU countries.
IX. How long we keep your personal data
Your personal data will be kept accurately and up-to-date. We store your data for the period strictly necessary for the purposes described above and process them for the entire time you are a registered user of our websites. All this without prejudice to storage obligations and applicable limitations. Upon termination, your data will be anonymised or erased where technically possible.
X. Lawfulness, data provision, and consequences of your refusal to provide them
Data provision is a contractual obligation and is indispensable for the purposes indicated in section IV a) b) c) f) i) j). Failure to provide your personal data will make it impossible for us to fulfil the obligations resulting from the contract as well as from legal provisions. In compliance with Article 6 of the GDPR, personal data are processed to fulfil a contract you have entered into, to implement pre-contractual measures taken upon your request, or to fulfil the legal obligations of the data controller.
Providing personal data is optional for the purposes described in section V d) e) g) and h). Failure to provide them will not have any consequences.
Apart from that specified with reference to browsing data and technical cookies, you are always free to provide your personal data or not for the purposes for which you visit our website.
XI. How we process your personal data
Your personal data will be processed in compliance with law and confidentiality obligations using manual methods or electronic tools with a logic strictly related to the purposes above and, in any case, in such a way as to guarantee their security and confidentiality (even in the event of remote communication techniques).
XII. Your data access rights
You have the right to obtain from the data controller access to your personal data (Article 15 of the GDPR), their rectification (Article 16 of the GDPR), their erasure (Article 17 of the GDPR), the restriction to their processing (Article 18 of the GDPR), the notification obligation (Article 19 of the GDPR). You also have the right to data portability (Article 20 of the GDPR) and to object to their processing (Article 21 of the GDPR). You can exercise your rights by contacting the data controller Mottolino S.p.A., Via Bondi, 476 – 23030 Livigno (Sondrio), [email protected].
You also have the right to lodge a complaint with your supervisory authority.
We may use automated individual decision-making processes, including profiling, based on your explicit consent, in compliance with Article 22 of the GDPR.
XIII. Use of our Websites by minors
Our websites are for people aged 14 years and up. The use of this website by people under 16 years of age is subject to their parents’ consent. Please DO NOT PROVIDE any personal data through our websites if you are under 14 years of age. We reserve the right to request the parents’ consent at any time to process personal data of minors. Some websites or apps may have age restrictions based on appropriate content for a certain age or legal requirements. We will duly indicate any age restriction on our website and will ask questions to verify your age before you can proceed.
XIV. Updates to this Privacy Notice
To know when this privacy notice was last amended, check the date and revision number indicated at the top of this notice.
General information about cookies
Cookies are small text files that the websites you visit send to your browser. These text files contain information that will be transmitted to the same websites next time you visit them.
When you browse a website, there can be third-party elements, such as images, maps, sounds, or links to other websites. In such cases, you may receive these third-party cookies.
Cookies are classified based on their duration and the website that installs them.
Below, you can find all the information about the cookies we use and the purposes for which we use them. The aim is to ensure your privacy, make the website easy to use, and optimise its development. Here are the main cookies and the purposes for which they are used.
Technical cookies are used only for transmitting a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service. They are not used for any other purpose, and they are normally installed directly by our website. They can be divided into browser cookies or session cookies and they ensure the correct operation of the website.
Session cookies are temporarily stored on your device when you browse a website for information such as your chosen language or the details to log into the restricted areas. Session cookies are stored for a short time. They are deleted as soon as you close the browser.
Persistent cookies store a text file on your device for a longer period. These cookies have an expiry date. Persistent cookies allow websites to remember your information and settings the next time you visit them, making your browsing experience easier and quicker, as you don’t have to log in again.
These cookies are deleted automatically upon their expiration.
Analytics cookies are used by a website to collect aggregated and anonymous data on the number of users and how they use the website.
Functional cookies allow you to browse a website based on selected criteria (e.g. language, products selected for purchase) to improve the service provided.
Your consent is not required for all technical cookies.
Here is a list of the technical cookies we use on our website:
- Google Analytics (statistics)
- Google Tag Manager (statistics)
- Typekit (font)
- Addthis (social sharing)
- Facebook (widget)
- Tripadvisor (widget)
- Twitter (widget)
- Google Plus (widget)
- Vimeo (widget)
- Hotjar (analysis and feedback plugin - heatmaps)
- Google AdWords (conversion tracking)
- Facebook Pixel (conversion tracking)
- Doubleclic (related to Adwords)
- Technical Analytics cookies (to identify your location and IP)
- Technical cookies (to allow you to view and browse the website)
- YouTube (we use the widget to upload videos)
- Uptime Robot (to verify whether the website is always online and accessible)
- Google Maps Widget (for the map in the Contact page)
- Amazon Web Services (AWS) **Ireland** (daily backup)
- CloudFlare (for CDN and HTTPS)
Profiling cookies create user profiles and send advertisements in line with the preferences shown when browsing the web. Given the invasiveness of these devices in a person’s private life, EU and Italian standards establish that users must be duly informed about their use and give their consent.
This Website does not use profiling cookies.
These cookies are installed by websites other than the one specified in the browser's address bar, or by organizations that do not correspond to the owners of the website.
For example, cookies used to collect information for advertising and content customisation, or statistical purposes can be third-party cookies.
Third-party cookies allow for more accurate statistics about how users explore a website (profiling cookies).
This Website does not use third-party cookies for profiling purposes.
Disabling, enabling, and deleting cookies
You can limit or block cookies at any time by adjusting your browser settings (Internet Explorer, Google Chrome, Mozilla Firefox, Opera, Safari, etc.).
If you prefer not to have cookies installed on your device, you can set your browser to be notified when a cookie is issued. Alternatively, you can set your browser to reject all cookies or just third-party cookies. You can also delete all the cookies already stored on your device. Remember that settings need to be changed separately for each browser and device you use (PC, notebook, smartphone, tablet, etc.).
If you choose not to receive our cookies, we cannot guarantee that our website will work correctly as it otherwise would.
Some functions, for example, may no longer be available. The settings of each browser are changed according to a different procedure. If necessary, you can use the browser’s settings guide.
For detailed information about how to enable, disable, delete, and control cookies, please visit www.aboutcookies.org
2nd rev. October 29th, 2018