Privacy Policy
This Website collects some Personal Data from its Users.
Owner and Data Controller
Pursuant to the Personal Data Protection Regulation (EU) 2016/679 (G.D.P.R.)
Edelfeuer srl, Via Noncello 21, 33170 – Pordenone (Italy)
Owner contact email: info@alpenpellet.com
Types of Data collected
Among the types of Personal Data that this Website collects, by itself or through third parties, there are: first name; last name; phone number; company name; physical address; country; county; email address; ZIP/Postal code; city; field of activity; Tracker; Usage Data; Universally unique identifier (UUID); answers to questions; clicks; keypress events; motion sensor events; mouse movements; scroll position; touch events; Videos; Data communicated while using the service; purchase history; billing address; number of Users ; device information; session statistics ; latitude (of city); longitude (of city); browser information.
Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection.
Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Website.
Unless specified otherwise, all Data requested by this Website is mandatory and failure to provide this Data may make it impossible for this Website to provide its services. In cases where this Website specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service.
Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.
Any use of Cookies – or of other tracking tools – by this Website or by the owners of third-party services used by this Website serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy, if available.
Users are responsible for any third-party Personal Data obtained, published or shared through this Website and confirm that they have the third party’s consent to provide the Data to the Owner.
Mode and place of processing the Data
Methods of processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Website (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.
Legal basis of processing
The Owner may process Personal Data relating to Users if one of the following applies:
- Users have given their consent for one or more specific purposes. Note: Under some legislations the Owner may be allowed to process Personal Data until the User objects to such processing (“opt-out”), without having to rely on consent or any other of the following legal bases. This, however, does not apply, whenever the processing of Personal Data is subject to European data protection law;
- provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
- processing is necessary for compliance with a legal obligation to which the Owner is subject;
- processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
- processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.
In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Place
The Data is processed at the Owner’s operating offices and in any other places where the parties involved in the processing are located.
Depending on the User’s location, data transfers may involve transferring the User’s Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Users are also entitled to learn about the legal basis of Data transfers to a country outside the European Union or to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.
If any such transfer takes place, Users can find out more by checking the relevant sections of this document or inquire with the Owner using the information provided in the contact section.
Retention time
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
Therefore:
Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.
The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
The purposes of processing
The User’s Data are collected to enable the Data Controller to provide its Services, as well as for the following purposes: Statistics, Contacting the User, Interaction with social networks and external platforms, Managing contacts and sending messages, Protection from SPAM and Displaying content from external platforms.
To obtain further detailed information on the purposes of the processing and the Personal Data concretely relevant for each purpose, the User may refer to the relevant sections of this document.
Detailed information on the processing of Personal Data
Personal Data are collected for the following purposes and using the following services:
Statistics
The services contained in this section allow the Data Controller to monitor and analyse traffic data and serve to keep track of the User’s behaviour.
Google Analytics 4 (Google Ireland Limited)
Google Analytics is a statistics service provided by Google Ireland Limited (“Google”). Google uses the Personal Data collected in order to track and examine the use of this Website, compile reports and share them with other services developed by Google.
Google may use Personal Data to contextualise and personalise ads in its advertising network.
In Google Analytics 4, IP addresses are used at the time of collection and then deleted before the data is stored in any data centre or server. To find out more, you can consult Google’s official documentation.
Personal data processed: city; browser information; device information; latitude (of city); longitude (of city); number of Users; session statistics.
Place of processing: Ireland – Privacy Policy – Opt Out.
Rights of users
Users may exercise certain rights with regard to the Data processed by the Data Controller.
In particular, the User has the right to:
- withdraw consent at any time. The User may revoke the consent previously given to the processing of his or her Personal Data.
- oppose the processing of their Data. The User may object to the processing of its Data when it is done on a legal basis other than consent. Further details on the right to object are set out in the section below.
- access to their Data. The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing and to receive a copy of the Data processed.
- verify and request rectification. The User may verify the correctness of his/her Data and request that it be updated or corrected.
- obtain the restriction of processing. When certain conditions are met, the User may request the restriction of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its storage.
- obtain the deletion or removal of their Personal Data. When certain conditions are met, the User may request the deletion of their Data by the Data Controller.
- receive their Data or have them transferred to another data controller. The User has the right to receive his or her Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another controller. This provision is applicable when the Data are processed by automated means and the processing is based on the User’s consent, on a contract to which the User is a party or on contractual measures related thereto.
- propose a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.
Details of the right to object
Where Personal Data are processed in the public interest, in the exercise of public authority vested in the Controller or in pursuit of a legitimate interest of the Controller, Users have the right to object to the processing on grounds relating to their particular situation.
Users are reminded that if their Data are processed for direct marketing purposes, they may object to the processing without giving any reason. To find out whether the Controller processes Data for direct marketing purposes, Users may refer to the respective sections of this document.
How to exercise rights
In order to exercise their rights, Users may address a request to the contact details of the Controller indicated in this document. Requests are filed free of charge and processed by the Controller as soon as possible, in any case within one month.
Cookie Policy
This Website makes use of Cookies. To find out more and to view the detailed information, the User can consult the Cookie Policy.
Additional information about Data collection and processing
Legal defence
The User’s Personal Data may be used by the Data Controller in legal proceedings or in the preparatory phases of such proceedings in order to defend against abuses in the use of this Web Site or related Services by the User.
The User declares that he/she is aware that the Data Controller may be obliged to disclose the Data by order of public authorities.
Specific disclosures
At the User’s request, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.
System logs and maintenance
For operation and maintenance purposes, this Website and any third-party services used by it may collect System Logs, i.e. files that record interactions and which may also contain Personal Data, such as the User’s IP address.
Information not contained in this policy
Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.
Responding to “Do Not Track” requests
This Website does not support “Do Not Track” requests.
To find out whether any third party services used support them, the User is invited to consult their respective privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by informing Users on this page and, if possible, on this Web Site as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details held by the Data Controller . Please therefore consult this page regularly, referring to the date of last modification indicated at the bottom.
If the changes affect processing whose legal basis is consent, the Data Controller will collect the User’s consent again, if necessary.
Definitions and legal references
Personal Data (or Data)
Personal Data is any information that, directly or indirectly, even in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.
Usage Data
This is the information collected automatically through this Web Site (including by third party applications integrated into this Web Site), including: the IP addresses or domain names of the computers used by the User who connects with this Website, the addresses in URI (Uniform Resource Identifier) notation, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.) the country of origin the characteristics of the browser and the operating system used by the visitor, the various temporal connotations of the visit (e.g. the length of time spent on each page) and the details of the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the operating system and the User’s IT environment.
User
The individual who uses this Website which, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refer.
Data Controller (or Processor)
The natural person, legal entity, public administration and any other entity that processes Personal Data on behalf of the Controller, as set out in this privacy policy.
Data Controller (or Controller)
The natural or legal person, public authority, service or other body which, individually or jointly with others, determines the purposes and means of the processing of personal data and the instruments adopted, including the security measures relating to the operation and use of this Web Site. The Data Controller, unless otherwise specified, is the owner of this Web Site.
This Web Site (or this Application)
The hardware or software tool through which Users’ Personal Data are collected and processed.
Service
The Service provided by this Website as defined in the relevant terms (if any) on this site/application.
European Union (or EU)
Unless otherwise stated, any reference to the European Union in this document shall be deemed to extend to all current member states of the European Union and the European Economic Area.
Cookie
Small piece of data stored within the User’s device.
Legal references
This Privacy Policy is drafted on the basis of multiple legal regulations, including Articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy policy relates exclusively to this Website.