Dear Customer,
this information note has been prepared pursuant to Legislative Decree no. 196/2003 and art. 13 of EU Regulation No. 2016/679 (hereinafter: "Regulation") in order to allow you to know our privacy policy, to understand how your personal information is managed when you use our website www.grisocoffee.com (hereinafter: "website") and, where appropriate, to give consent to the informed and aware processing of your personal data. The information and data provided by you or otherwise acquired in the context of the use of the services offered by our website will be processed in compliance with the provisions of the Regulation and will be based on the principles of lawfulness, fairness, transparency, purpose, and storage limitations, data minimization, integrity, and confidentiality.
All the details on the processing of your personal data below.
1. Data Controller and Data Protection Officer
The data controller is C.I.T. Compagnia Italiana Torrefazione "Il Griso" di Balzan Claudia e Biscotti Antonio snc (hereinafter "Il Griso" or "Il Titolare"), with headquarters in via Nicolò Tommaseo nr. 13, 20822 Seveso (MB), c.f. 02944210968.
Data Protection Officer: Mrs. Claudia Balzan.
2. What Data we process and how we collect them
For example, the following data may be processed: name, surname, address, date of birth, fiscal code, e-mail address, and telephone number.
The personal data processed through the website are the following:
a) the personal and contact details provided at the time of registration on the website www.grisocoffee.com and through the compiling of necessary on-line forms for the completion of the sales service;
b) the personal and contact details provided at the time of registration for the newsletter of www.grisocoffee.com;
c) navigation data relating to the use of the services offered through the website collected through cookies in accordance with the cookie policy (full version available at the bottom of this page);
d) the data provided in case of a request for information and assistance;
e) the data provided and collected as a part of promotions and/or competitions;
With regard to the online payment data entered by the Customer, the Data Controller will only process data received from digital payment companies and payment institutions made by credit cards or other digital payment methods which consist exclusively of feedback information related to the outcome of the same payment (successful or rejected). All further information relating to prepaid card or credit card data will be stored by the entities that manage the related service, which are not allowed to use the Personal Data received through the site for other purposes.
The Data Controller does not intend to collect Personal Data of minors nor to deliberately establish any type of contact with them. For this reason, we encourage parents to actively monitor the online activities of their children.
3. Treatment and storage method
The processing will be carried out in automated and/or manual form, in compliance with the provisions of art. 32 of GDPR 2016/679 and Annex B of Legislative Decree no. 196/2003 (art. 33-36 of the T.U.) in the matter of security measures, by specifically appointed people and in compliance with the provisions of art. 29 GDPR 2016/ 679.
The data will be stored for a period not exceeding the administrative purposes for which they were collected and subsequently processed, while they will be stored for profiling and marketing purposes for a period not exceeding 24 months from their registration, without prejudice to their actual transformation into an anonymous form.
You may decide to consent to the processing of your Personal Data for the management and response by the Owner of your requests in relation to products and initiatives organized by "Il Griso". In relation to these purposes, your consent is required at the time of sending the request.
4. Communication and distribution of the data
The collected data will never be distributed and will not be communicated without your explicit consent, except for the necessary communications that may involve the transfer of data to collaborators and/or affiliated companies to “Il Griso” in order to comply with the contracts and the purposes related to them.
The data may be communicated to third parties belonging to the following categories:
a) legal or natural persons acting as external data processors, appointed by the Data Controller (including entrusted people with assistance and/or consultancy activities, communication, website operators, electronic platform operators, partners, professional or freelance firms);
b) employees and/or collaborators of the Data Controller (including system administrators) who, acting under the direct authority of the latter, will be authorized to process the Personal Data.
The subjects belonging to the aforementioned categories perform the function of Data Processor or operate in total autonomy as separate Data Controllers.
The list of any responsible persons is constantly updated and available at the headquarters of the Data Controller.
5. Nature of the provision
The provision of your Personal Data is optional. However, their failed or incorrect communication could affect the possibility of using some services (e.g. the execution of orders and purchases; the sending of newsletters; participation in competitions, promotions, and prize draws).
In case you decide not to give consent to the processing of your Personal Data, it will not be possible for the Data Controller to process your request.
The mandatory or optional nature of the contribution will be indicated from time to time by the use of symbols (e.g. *) placed alongside the information whose provision is mandatory to pursue the respective purpose.
6. Right of access to personal data and other rights
As a data subject, you have the right to:
a) obtain from the Data Controller confirmation of the existence or non-existence of your Personal Data, even if not yet registered, and their communication in an intelligible form as well as access to your Personal Data (by obtaining a copy) and related information (including the purposes of the processing, the categories, and origin of the Personal Data, the categories of recipients to which they have been or may be communicated, the retention period, where possible, the rights exercisable);
b) obtain from the Data Controller the rectification of your Personal Data and the integration of your incomplete Data;
c) obtain from the Data Controller the cancellation of your Personal Data without undue delay, a cancellation that must be considered automatic when the Personal Data will no longer be necessary with respect to the purposes for which they were collected and processed or there is no longer a legal basis for their processing;
d) obtain from the Data Controller the transformation into anonymous form or the blocking of your Personal Data processed in violation of the law, including those whose storage is not necessary, in relation to the purposes for which the Personal Data were collected or subsequently processed;
e) obtain from the Data Controller the limitation of the processing of your Personal Data, among other things, when you contest its accuracy or are opposed to the processing, for the period necessary for the respective verifications;
f) at any time you may withdraw your consent to the processing of your Personal Data for any of the purposes for which it was provided. In this case, the Data Controller refrains from further processing your Personal Data.
You can exercise your rights against the Owner, request information or clarification by writing to the following email address torrefazione.griso@gmail.com or by sending a letter by registered letter a.r. to the address indicated in paragraph "1. Data Controller and Data Protection Officer".
In addition, if you believe that the processing of your Personal Data violates the Privacy Policy, you may lodge a complaint with the Data Protection Authority of the State in which you are resident or in which the alleged breach occurred, or contact the same Authority to request information about the exercise of your rights under the Privacy Policy.
Last updated 05 October 2020.