Biraghiacasa is owned by Biraghi spa, with registered office in Cavallermaggiore, at 1, via Cuneo, entry in the Register of Companies of Cuneo under number 00486510043, share capital of Euro 3,825,000 telephone number 0172.38.01.11, which also owns the domain name.
The products and/or services purchased on the website are offered for sale and sold by Biraghi spa
Therefore, the purchase contract entered into through Biraghiacasa is therefore entered into between the user and Biraghi spa
The user may browse Biraghiacasa as an anonymous user or, after registration, as a registered user of Biraghiacasa.
In light of the above, the data controller hereby provides the user with the following information:
Privacy Notice on Data Processing
We inform you, pursuant to Chapter III of the GDPR (EU Regulation 2016/679 on data protection, hereinafter only referred to as "GDPR"), that the data you provide are processed according to the procedures described below.
This information may be modified at any time, please check – at the bottom of this document – the date of last revision.
Any amendment to this policy shall take effect from its date of publication on the Biraghiacasa website.
1. Type of personal data subject to processing
The following personal data are processed while and due to browsing on the Biraghiacasa website and/or registering on Biraghiacasa and/or making a purchase on Biraghiacasa:
• the email and password with which the user registers on the Biraghiacasa website ("Registration Credentials");
• the personal details (eg name, surname, date of birth, billing address, postal address, tax code) entered by the user in the appropriate sections of the Biraghiacasa website ("Personal Data");
• data relating to purchase orders ("Purchase Data");
• Loyalty Card data, ie the loyalty card which may be associated with the user's account (and notably, the number of the card and the balance of points) ("Associated Loyalty Card Data");
• navigation data (such as cookies), including data provided by the user while using specific functions of the Biraghiacasa website (such as, for example, the creation of shopping lists) ("Navigation Data").
2. Purpose and legal basis of data processing
The data are processed for the following purposes:
a. by Biraghi spa, limited to the Registration Credentials, in order to enable the registration to the Biraghiacasa site and the consequent provision of the services only aimed by Biraghi to registered members of the website;
b. by Biraghi spa, in order to allow their correct execution of the operations related to the online purchase and, therefore, to correctly and timely fulfil all the obligations under the sales contract entered into through the Biraghiacasa website, as well as for the fulfilment of all legal obligations connected to it, including tax and administrative obligations (so-called purpose of fulfilling the purchase contract);
c. by Biraghi spa, in order to allow them to provide the functions of the Biraghiacasa website expressly activated by the user and/or to respond to any requests expressly formulated by them (so-called purposes of response to specific user requests);
d. subject to the prior express consent of the user, by Biraghi spa, for sending informative and promotional communications, including the newsletter, referred to their own products and/or services and/or those of third parties, as well as for carrying out market research, by means of automated systems (eg e-mail, SMS, telephone calls without operator) and traditional systems (eg mail, telephone calls with operator) (so-called marketing/newsletter purposes);
e. subject to the prior express consent of the user provided to Biraghi spa, for profiling purposes, for the analysis and processing by Biraghi of the choices and purchasing habits of the user on the Biraghiacasa through the detection of the type and frequency of purchases made on the Biraghiacasa site (so-called profiling purposes).
• of the processing referred to at point a), c), is the requirement for processing resulting from the execution of a contract to which the data subject is a party or for the execution of pre-contractual measures adopted at the request of the same;
• of the processing referred to at point b) is the requirement for processing resulting from the need to fulfil a legal obligation to which the data controller is subject, as well as for the execution of a contract to which the data subject is a party;
• of the processing referred to at points d), e) is the consent of the data subject.
For the purposes referred to at point (b) of this art. 2, Biraghi spa processes the Personal Data, the Purchase Data, the Data of the Associated Loyalty Card, the Navigation Data (limited to those strictly necessary for the performance and achievement of the purchase procedure), in addition to the user's email address and any other data necessary for the correct fulfilment of the contractual obligations arising for Biraghi from the purchase contract entered into online.
For the purposes referred to at point (c) of this art. 2, Biraghi spa processes the data provided by the user in the context of the use of specific functions of the Biraghiacasa website allowing users to create shopping lists or for the execution of express requests through the website, in addition to that necessary to respond to the request or to allow the user to use the activated function.
For the purposes referred to at point (d) of this art. 2 (so-called marketing/newsletter purposes), Biraghi spa processes the email address provided by the user and the Personal Data, including the telephone number and addresses of the user, if provided.
For the purposes referred to at point (e) of this art. 2 (so-called profiling purposes), Biraghi spa processes the Purchase Data, in addition to those processed for the purposes referred to at point (d) of this art. 2.
3. Additional remarks on data processing
Biraghi spa retains, within the statutory legislation, the log files and IP addresses used when making an online purchase and/or accessing the Biraghiacasa website, with the aim of preventing and ascertaining any fraud.
Unique account deletion
The user's account on the Biraghiacasa website can be deleted using the appropriate function in the "Account Settings" section. The use of the "Delete Account" function involves the cancellation of all the data contained and, as a result, the user is no longer able to log in as a logged in user, unless after registering again.
4. Provision of data and consequences in the event of failure to consent to processing
The provision of data for the purposes referred to at point (a) of art. 2 above is optional. However, since the processing of such data is necessary to allow, respectively, the registration to Biraghiacasa and the provision of the services reserved for members, any refusal to provide consent results in the impossibility for the user to register to Biraghiacasa and therefore, in the impossibility of using the services reserved for members, including the impossibility of making purchases through the Biraghiacasa website.
The provision of data for the purposes referred to at points b) and (c) of art. 2 above is optional. However, since the processing of such data is necessary to allow the conclusion and fulfilment of the purchase contract or, respectively, to meet express requests made on the Biraghiacasa website by the user and/or the activation of specific functions of the Biraghiacasa website, any refusal to provide consent results in the impossibility for the user to enter into purchase contracts through the Biraghiacasa website, to have their requests answered and to use specific functions of the Biraghiacasa website.
With reference to the processing purposes referred to at points (d) (so-called marketing/newsletter purposes) and (e) (so-called profiling purposes) of art. 2 above, consent to the processing of personal data is only optional and may be expressed by selecting a specific box, for each separate purpose, at the bottom of the form for the registration to Biraghiacasa. Failure to consent does not impact in any way the possibility of registering to Biraghiacasa and to make purchases on such website. The only consequences are the following:
• failure to consent to the processing of personal data for the purposes referred to at point (d) of art. 2 above (ie failure to consent to marketing/failure to subscribe to the newsletter) results in the impossibility for the user to receive informative and promotional communications from Biraghi spa, including the newsletter, with reference to its own products and/or services and/or those of third parties, through automated systems (eg e-mail, SMS) and/or traditional (eg mail, telephone), in addition to the impossibility of participating in market research, carried out by Biraghi spa, using the same means;
• failure to consent to the processing of personal data for the purposes referred to at point (e) of art. 2 above (ie failure to consent to profiling) results in the impossibility for Biraghi spa to analyse and process the choices and purchasing habits of the user on the Biraghiacasa website through the detection of the type and frequency of purchases made on Biraghiacasa and, consequently, for the user, in the impossibility of receiving from Biraghi spa, informative and promotional communications (including the newsletter) with reference to their own products and/or services and/or those of third parties which may be of specific interest to the user, by means of automated systems (eg e-mail, SMS) and/or traditional systems (eg mail, telephone).
However, the user may revoke any consent given for the purposes described at points (d) (so-called marketing/newsletter purposes) and (e) (so-called profiling purposes) of art. 2 above, by contacting Biraghi spa at the address indicated in art. 8.2. below, or through the "Privacy settings" section of their Biraghiacasa website account.
Furthermore, limited to the purposes described at point (d) (so-called marketing/newsletter purposes) of art. 2 above, the user may object to the processing of data concerning them for marketing purposes and/or cancel their subscription to the newsletter also using the link at the bottom of the newsletter and/or any email with promotional content sent by Biraghi spa. Any objection expressed according to the procedure indicated above also extends to communications sent by post or SMS or any other form of communication
5. Processing methods
Data processing is mainly carried out by means of electronic or automated tools, such as, and with the means suitable for this purpose, to guarantee the security and confidentiality of the data, in accordance with the provisions of the GDPR. Notably, all technical, IT, organisational, logistical and procedural security measures are adopted, in order to guarantee the minimum level of data protection required by law and to minimise the risks of destruction, loss, unauthorised access or processing which does not comply with the purposes of the collection, access being granted only to the persons in charge of processing by the data controllers or the managers designated by them. Furthermore, data is managed and protected in environments where access is under constant control.
6. Data retention times and location
Personal data are only stored for the period of time strictly necessary to achieve the purposes for which it was collected.
In any case, it is understood that the personal data is stored and processed by Biraghi spa for the purposes referred to at points (d) (so-called marketing/newsletter purposes) and (e) of art. 2 above (so-called profiling purposes), for the period of time allowed by law and by the provisions of the Guarantor for the Protection of Personal Data (24 months).
In the event of cancellation of the user account, the Data is stored, for administrative purposes, for a period not exceeding one quarter, without prejudice to any specific legal obligations on the retention of accounting documentation or for public security purposes.
After the above periods, the data is permanently deleted or transformed into anonymous form, so as not to allow, even indirectly, the possible identification of the user. In these cases, the automatic deletion and/or transformation into anonymous form of the data is also guaranteed by the third parties to whom it has been communicated.
The data is stored on the servers of Aruba, an Italy-registered company with registered office in Ponte San Pietro (BG)
It should be noted that the data remains in Italy and that Aruba guarantees an adequate level of data protection.
7. Scope of data communication (data recipients)
The data, processed for the purposes referred to in art. 2 above, may be communicated to the following subjects:
• employees and/or associates of Biraghi spa who process them (limited to the purposes relating to the tasks entrusted to them) as appointees or data processors, appointed by the data controller;
• companies appointed by Biraghi spa to send commercial communications through automated systems (such as e-mail, SMS,) or traditional systems (such as mail and telephone);
• companies, consultants or professionals who may be in charge of the installation, maintenance, updating and, in general, the management of Biraghi spa's hardware and software, in particular, Aruba spa, as a provider of the hosting service;
• any public and/or private parties, natural and/or legal persons (legal, administrative and tax consultants, judicial offices, chambers of commerce, trade unions, etc.), where the communication is necessary or functional for the correct compliance with the contractual obligations associated with the services provided through the Biraghiacasa website, as well as with legal obligations.
• all parties (including public authorities) who have access to the data under legislative or administrative provisions.
All personal data provided by users during their registration on the Biraghiacasa website and/or navigation and/or purchase through the Biraghiacasa website are not subject to disclosure. The up-to-date list of data processors is available for viewing at the offices of each data controller.
Payment for the Products purchased on the Biraghiacasa website can be made by credit card by selecting the appropriate box during the purchase process. The credit cards accepted for payment include those belonging to the Visa and Mastercard circuits, including virtual cards, Visa Electron, amex and PayPal. All data is transferred in encoded form using a Secure Socket Layer (SSL) certificate, so that it may not be intercepted by external parties. In the same way, in no case does Biraghiacasa manage or/and store any data relating to credit cards because the entry, as well as the management of recurring payments (through the use of tokens) is carried out by Banca Intesa Sanpaolo. In no case does Biraghi spa process the data relating to the credit card used for the payment.
8. Data controller and Data protection officers
The Data Controller is Biraghi spa, 1, Via Cuneo - 12030 Cavallermaggiore (CN), phone 0172/380111 – email firstname.lastname@example.org.
Any request relating to the processing of data may be addressed to the contacts indicated above
9. Your rights
Subject to applicable law, the data subject has the following rights:
• access their personal data and know the origin, purposes and purposes of the processing, the details of the data controller, of the data processor and of the subjects to whom they may be disclosed;
• withdraw their consent at any time, where it constitutes the basis of the processing. In any case, this does not affect the lawfulness of the processing carried out already based on prior consent;
• to update or correct their personal data so that it is always accurate;
• to request the deletion of their personal data from the databases and/or archives of the data controller in the event that they are no longer necessary for the purposes indicated above;
• to limit the processing of their personal data under certain circumstances, such as when their accuracy has been challenged, for the period necessary for the data controller to check it;
• to obtain their personal data in electronic format;
• to object to the processing of their personal data or request to interrupt it for each of the purposes indicated at point 2 above. Following this request, the Data Controller is no longer able to process personal data, unless in the cases provided by the laws and regulations.
The data subject may assert their rights by contacting the Data Controller, in writing, to the email address as indicated in the previous art. 8.
The data subject has the right to lodge a complaint with the supervisory authority responsible for data protection and in particular that of the member state in which they habitually reside or work or in which the alleged breach has occurred.