Privacy Policy
Personal Information and Types of Data collected
The information I collect
To complete your order, you must provide me with some information (Etsy has provided you with your permission), such as your name, e-mail address, postal address, payment details and product details you have ordered. You may decide to provide me with additional personal information (such as size / measurements, physical details, etc. to order a personalized product), if you contact me directly via Etsy's Convo. The data collected through Etsy, are usage data, email, name, surname, username, image, date of birth and registration date to Etsy. Data communicated during use of the service, geographical location, country, province, postcode, city and shipping address.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the purchase and confirmation of an order.
If the user refuses to communicate them, it may be impossible for me to manage the order and provide the Service according to the Etsy regulations.
Mode and place of processing of collected data
Because I need your information and how I use it
The Controller takes appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data.
Processing is carried out using IT and / or telematic tools, with organizational methods and with logic strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the organization may have access to Data (administrative, commercial, marketing, legal, system administrators, financial consultants) or external subjects (as suppliers of third party technical services, postal couriers, hosting providers, IT companies, communication agencies)
I rely on a number of legal bases to collect, use and share your information, including:
• are necessary to provide my services, such as when I use your information to complete your order, resolve disputes or provide customer support;
• when you have provided your affirmative consent, which you can revoke at any time, for example by registering to my mailing list;
• if necessary to comply with legal obligations or a court order or in connection with a legal action, such as storing information about your purchase if required by tax law; is
• if necessary for my legitimate interest, provided that your rights or interests do not prevail, such as 1) provide and improve my services. I use your information to provide the services you have requested and in my legitimate interest to improve my services; and 2) Compliance with the Seller's Rules and the Etsy Terms of Use. I use your information as needed to comply with my obligations, pursuant to the Seller's Settlement and Etsy Terms of Use.
3. Sharing and dissemination of information
Information about my customers is important to my business. I will share your personal information only for limited reasons and circumstances, as follows:
• Etsy. I share the information with Etsy as necessary to provide you with my services and for compliance with my obligations under the Etsy Sales Rules and Conditions of Use.
• Service providers. I use trusted third parties to perform certain functions and to provide services to my store, such as delivery companies. I will share your personal information with these third parties, but only to the extent necessary to perform these services. Example I provide the postal service of Italian Post Office or various express couriers, for logistics services, shipping and delivery of both national and international orders. (UPS, SDA, TNT)
• Business transfers. Should I proceed with the sale or merger of my business, I may disclose your information in connection with this transaction, but only to the extent permitted by law.
• Compliance with the law. I may collect, use, store and share your information if, in good faith, I deem it reasonably necessary to: (a) respond to legal proceedings or government requests; (b) apply contracts, conditions and regulations; (c) avoiding, investigating and combating fraud, and other problems related to illegal, security or technical activities; or (d) protect the rights, property and safety of my customers, or others.
4. How long will you retain your personal information
Data retention
The Data are processed and stored for the time required by the purposes for which they were collected.
Therefore:
• Personal Data collected for purposes related to the execution of a service / order
• Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained until such interest is met. The User can obtain further information regarding the legitimate interest pursued by the Owner in the relevant sections of this document or by contacting the Data Controller.
When the processing is based on the consent of the User, the Data Controller may retain the Personal Data for a longer period until such consent is revoked. Furthermore, the Data Controller may be obliged to keep Personal Data for a longer period in compliance with a legal obligation or an order of an authority.
At the end of the retention period the Personal Data will be deleted. Therefore, at the end of this term the right of access, cancellation, rectification and the right to data portability can no longer be exercised.
Generally, I keep your data for the following period of time: 5 years.
Legal basis of the processing
The Holder processes Personal Data relating to the User in the event one of the following conditions exists:
• the User has given consent for one or more specific purposes; Note: in some jurisdictions the Data Controller may be authorized to process Personal Data without the User's consent or another of the legal bases specified below, as long as the User does not object to such processing. However, this is not applicable if the processing of Personal Data is regulated by European legislation regarding the protection of Personal Data;
• the processing is necessary for the execution of a contract with the User and / or the execution of pre-contractual measures;
• the processing is necessary to fulfill a legal obligation to which the Data Controller is subject;
• processing is necessary for the performance of a task carried out in the public interest or for the exercise of public authority vested in the Holder;
• processing is necessary for the pursuit of the legitimate interest of the owner or third parties.
In any case, it is always possible to ask the Owner to clarify the concrete legal basis of each treatment and in particular to specify whether the treatment is based on the law, provided for by a contract or necessary to conclude a contract.
5. In case of transfer of personal information outside of Europe, how will the transfer be managed
Transfers of personal information outside the EU
I may store and process your information via third-party hosting services in the United States and other jurisdictions. As a result, I may transfer your personal information to a jurisdiction with data protection and governmental surveillance laws other than those in force in your jurisdiction.
6. The rights of buyers regarding the use of their personal information and contact details
Your rights
If you live in certain territories, including the EU, you have different rights related to your personal information. While some of these rights are generally applicable, others apply only in some specific cases. I describe these rights below:
• Access. You have the right to access and receive a copy of your personal information in my possession by contacting me using the following contact details.
• Modification, limitation, cancellation. In addition, you have the right to modify your personal information, to limit the use of your personal information or to delete your personal information. Except for exceptional circumstances (such as when I am required to retain data for legal purposes), I generally delete personal information on request.
• Opposition. You may object to the processing by me of some of your information based on my legitimate interest and receipt of marketing messages from me after giving your explicit consent to receive them. In such cases, I will delete your personal information, except in cases where there are compelling and legitimate reasons for me to continue using such information or
• where it is necessary for legal reasons.
• Complaint. If you live in the EU and wish to express a concern regarding the use of your information (and without prejudice to any rights you may have), you have the right to do so with your local data protection authority.
In particular, the User has the right to:
• withdraw consent at any time. The User can withdraw consent to the processing of their Personal Data previously expressed.
• oppose the processing of your data. You may object to the processing of your data when it occurs on a legal basis other than consent. Further details on the right of opposition are indicated in the section below.
• access your data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing and to receive a copy of the Data processed.
• verify and request correction. The User can verify the correctness of his Data and request its updating or correction.
• obtain treatment limitation. When certain conditions are met, the User may request the limitation of the processing of their Data. In this case, the Data Controller will not process the Data for any other purpose other than their conservation.
• obtain the cancellation or removal of their Personal Data. When certain conditions are met, the User can request the cancellation of their Data by the Owner.
• receive your data or have it transferred to another holder. You have the right to receive your data in a structured format, commonly used and readable by automatic device and, where technically feasible, to obtain the transfer without hindrance to another holder. This provision is applicable when the Data are processed with automated tools and the processing is based on the User's consent, on a contract of which the User is a party or on contractual measures connected to it.
• propose a complaint. The User can lodge a complaint with the competent personal data protection authority or act in court.
Data Controller
Katia Zilio via Sabotino 7 60022 Castelfidardo AN Italy
Email address of the Owner: katia.zil@libero.it