- This section contains information on how to manage COVIDiary19 with reference to the processing of COVIDiary19 users’ data.
- This information is also valid for the purposes of art. 13 of Legislative Decree no. 196/2003, Code regarding the protection of personal data, and for the purposes of Article 13 of EU Regulation no. 2016/679, concerning the protection of natural persons with regard to the processing of personal data and the free circulation of such data, for subjects who interact with COVIDiary19 and can be reached at the address corresponding to the initial page:
- The information is provided only for COVIDiary19 and not for other websites that may be consulted by the user through links contained therein.
- The purpose of this document is to provide information on the methods, timing and nature of the information that the data controllers must provide to users when connecting to the COVIDiary19 web pages, regardless of the purposes of the connection, according to Italian legislation and European.
- The information may undergo changes due to the introduction of new rules in this regard, therefore the user is invited to check this page periodically.
- If the user is under the age of 16, pursuant to article 8, c.1 EU regulation 2016/679, he / she must legitimize his / her consent through the authorization of his / her parents or guardians.
II – DATA PROCESSING
1 – Data Holder
1. The data controller is the natural or legal person, public authority, service or other body that, individually or together with others, determines the purposes and means of processing personal data. He also deals with safety profiles.
2. With regard to this website, the data controller is: Luigi Paiano, and for any clarification or exercise of the user’s rights he may contact him at the following e-mail address: email@example.com
2 – Responsible for data processing
1. The controller is the natural or legal person, public authority, service or other body that processes personal data on behalf of the controller.
2. Pursuant to Article 28 of EU Regulation no. 2016/679, upon the appointment of the owner of the data, the person in charge of data processing of the COVIDiary19 site is: Luigi Paiano.
III – COOKIES
1 – Type of Cookies
2. A cookie consists of a reduced set of data transferred to the user’s browser from a web server and can only be read by the server that made the transfer. This is not executable code and does not transmit viruses.
3. Cookies do not record any personal information and any identifiable information will not be stored. If you want, you can prevent the saving of some or all cookies. However, in this case the use of the site and the services offered could be compromised. To proceed without changing the options related to cookies, simply continue browsing.
Below are the types of cookies that the site uses:
2 – Technical cookies
1. There are many technologies used to store information on the user’s computer, which are then collected by the sites. Among these the best known and used is that of HTML cookies. They are used for navigation and to facilitate access and use of the site by the user. They are necessary for the transmission of communications on the electronic network or the supplier to provide the service requested by the customer.
2. The settings to manage or deactivate cookies may vary depending on the internet browser used. In any case, the user can manage or request the general deactivation or cancellation of cookies, modifying the settings of his internet browser. This deactivation can slow down or prevent access to some parts of the site.
3. The use of technical cookies allows the safe and efficient use of the site.
4. Cookies that are inserted in the browser and retransmitted by Google Analytics or the statistics service of bloggers or similar are technical only if used for the purpose of optimizing the site directly from the owner of the site, which can collect information in aggregate form on the number users and how they visit the site. Under these conditions, for analytics cookies the same rules apply, in terms of information and consent, provided for technical cookies.
5. From the point of view of duration we can distinguish temporary session cookies that are deleted automatically at the end of the browsing session and are used to identify the user and thus avoid logging in to each page visited and the permanent ones that remain active in the PC up upon expiry or cancellation by the user.
6. Session cookies may be installed in order to allow access to and access to the reserved area of the portal as an authenticated user.
7. They are not stored permanently but only for the duration of the navigation until the browser is closed and disappear when the browser is closed. Their use is strictly limited to the transmission of session identifiers consisting of random numbers generated by the server necessary to allow the safe and efficient exploration of the site.
3 – Third-party cookies
1. In relation to the provenance we distinguish the cookies sent to the browser directly from the site you are visiting and those of third parties sent to the computer from other sites and not from the one you are visiting.
2. Permanent cookies are often third-party cookies.
3. The majority of third-party cookies consists of tracking cookies used to identify online behavior, understand the interests and then customize the advertising proposals for users.
4. Third-party analytical cookies may be installed. They are sent from the domains of the aforementioned third parties external to the site.
5. Third-party analytical cookies are used to detect information on user behavior on COVIDiary19 . The survey takes place anonymously, in order to monitor the performance and improve the usability of the site. The third-party profiling cookies are used to create profiles relating to users, in order to propose advertising messages in line with the choices expressed by the users themselves.
6. The use of these cookies is governed by the rules set by the third parties themselves, therefore, users are invited to read the privacy policies and indications to manage or disable the cookies published on the related web pages.
4 – Profiling cookies
1. Profiling cookies are those that create profiles related to the user and are used in order to send advertising messages in line with the preferences expressed by the same in the context of surfing the net.
2. When these types of cookies are used, the user must give explicit consent.
3. Article 22 of EU Regulation 2016/679 and Article 122 of the Code on data protection will apply.
IV – DATA PROCESSED
1 – Data processing mode
1. Like all websites, this site also makes use of log files in which information collected in an automated manner is stored during user visits. The information collected could be the following:
– internet protocol (IP) address;
– type of browser and device parameters used to connect to the site;
– name of the Internet service provider (ISP);
– date and time of visit;
– web page of origin of the visitor (referral) and exit;
– possibly the number of clicks.
2. The aforementioned information is processed in an automated form and collected in an exclusively aggregated form in order to verify the correct functioning of the site, and for security reasons. This information will be processed according to the legitimate interests of the holder.
3. For security purposes (spam filters, firewalls, virus detection), the automatically recorded data may possibly also include personal data such as IP address, which could be used, in accordance with applicable laws, in order to block attempts atdamage to the site itself or to damage other users, or in any case harmful activities or constituting a crime. Such data are never used for the identification or profiling of the user, but only for the protection of the site and its users, such information will be treated according to the legitimate interests of the owner.
5. The information that users of the site believe to make public through the services and tools made available to them, are provided by the user knowingly and voluntarily, exempting this site from any liability regarding any violation of laws. It is up to the user to verify that they have permission to enter personal data of third parties or contents protected by national and international standards.
2 – Purposes of data processing
1. The data collected by the site during its operation are used for the purposes indicated above and for the following purposes:
sending newsletters with commercial information and updates on projects of COVIDiary19
2. Data retention will be carried out for the period strictly necessary to achieve the aforementioned purpose and in any case not exceeding one year.
3. The data used for security purposes (block attempts to damage the site) are kept for the time strictly necessary to achieve the previously indicated end.
3 – Data provided by the user
1. As indicated above, the optional, explicit and voluntary sending of e-mails to the addresses indicated on this website entails the subsequent acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data included in the message.
2. Specific summary information will be progressively reported or displayed on the pages of the site prepared for particular services on request.
4 – Support in configuring your browser
1. The user can manage cookies also through the settings of his browser. However, deleting cookies from your browser may remove the preferences you have set for the site.
2. For further information and support, you can also visit the specific help page of the web browser you are using:
– Internet Explorer: http://windows.microsoft.com/en-us/windows-vista/block-or-allow-cookies
– Firefox: https://support.mozilla.org/en-us/kb/enable-and-disable-cookies-website-preferences
– Safari: http://www.apple.com/legal/privacy/it/
– Chrome: https://support.google.com/accounts/answer/61416?hl=en
– Opera: http://www.opera.com/help/tutorials/security/cookies/
5 – Social Network Plugin
2. The collection and use of information obtained by means of the plugin are governed by the respective privacy policies of the social networks, to which reference is made:
Google+: http: //www.google.com/policies/technologies/cookies
V. USER RIGHTS
- The art. 13, c. 2 of EU Regulation 2016/679 lists the user’s rights.
- The COVIDiary19 website therefore intends to inform the user of the existence:
– the right of the interested party to ask the holder for access to personal data (Article 15 of the EU Regulation), their updating (Article 7, paragraph 3, letter a) of the Legislative Decree 196/2003), the rectification (Article 16 of the EU Regulation), integration (Article 7, paragraph 3, letter a) of the Legislative Decree 196/2003) or the limitation of processing that concerns it (Article 18 of the EU Regulation) or to oppose, for legitimate reasons, to their treatment (Article 21 EU Regulation), in addition to the right to data portability (Article 20 EU Regulation);
– the right to request cancellation (Article 17 of the EU Regulation), the transformation into anonymous form or blocking of data processed in violation of the law, including those whose retention is unnecessary for the purposes for which the data are been collected or subsequently processed (Article 7, paragraph 3, letter b) of Legislative Decree 196/2003);
– the right to obtain the attestation that the operations of updating, rectification, integration of data, cancellation, blocking of data, transformation have been brought to the attention, also as regards their content, of those to whom the data have been communicated or disseminated, except in the case where such fulfillment proves impossible or involves a use of means manifestly disproportionate to the protected right (Article 7, paragraph 3, letter c) of Legislative Decree no. 196/2003);
3. The requests may be addressed to the data controller, without formalities or, alternatively, using the model provided by the Guarantor for the Protection of Personal Data, or by sending an email to: firstname.lastname@example.org
4. If the treatment is based on art. 6, paragraph 1, lett. a) – express consent to use – or on art. 9, paragraph 2, lett. a) – express consent to the use of genetic, biometric, health-related data revealing religious beliefs, philosophical or union membership, revealing racial or ethnic origin, political opinions – the user has the right to revoke the consent at any time without prejudice to the lawfulness of the treatment based on the consent given prior to the revocation.
5. Likewise, in the event of violation of the law, the user has the right to lodge a complaint with the Guarantor for the Protection of Personal Data, as the authority responsible for monitoring the processing in the Italian State.
6. For a more in-depth examination of the rights that compete with it, see articles 15 and ss. of the 2016/67 EU Regulation and the art. 7 of Legislative Decree no. 196/2003.
VI – DATA TRANSFER TO EXTRA UE COUNTRIES
- This site may share some of the data collected with services located outside the European Union. In particular with Google, Facebook and Microsoft (LinkedIn) through social plugins and the Google Analytics service. The transfer is authorized and strictly regulated by Article 45, paragraph 1 of EU Regulation 2016/679, for which no further consent is required. The companies mentioned above guarantee their adherence to the Privacy Shield.
- Data will never be transferred to third countries that do not comply with the conditions set out in Article 45 and following of the EU Regulation.
VII. SECURITY DATA PROVIDED
- This site processes the data of users in a lawful and correct manner, adopting appropriate security measures to prevent unauthorized access, disclosure, modification or unauthorized destruction of data. Processing is carried out using IT and / or telematic tools, with organizational methods and with logic strictly related to the purposes indicated.
- In addition to the owner, in some cases, may have access to the data categories of employees involved in the organization of the site (administrative, commercial, marketing, legal, system administrators) or external subjects (as suppliers of third party technical services, couriers postal services, hosting providers, IT companies, communication agencies).
VIII. CHANGES TO THIS DOCUMENT
- This document, published at the address:
- It may be subject to changes or updates. In the case of significant changes and updates, these will be reported with appropriate notifications to users.
- Previous versions of the document will still be available on this page.
- The document was updated on 25/05/2018 to comply with the relevant regulations, and in particular in compliance with EU Regulation 2016/679