Privacy Policy of Flexpack
This Application collects certain Personal Data from its Users.
This document can be printed using the print command found in the settings of any browser.
FLEX-PACK SRL
SL: Piazza Vittorio Emanuele II 36, Orzinuovi (BS)
SO: Via Milano 27, 26029 Soncino (CR)
Via Milano 40, 26029 Soncino (CR)
P.IVA (VAT ID) 03654060981
N. REA 552189
Cap. Soc. (Share Capital) € 10,000.00
Data Controller’s email address: info@flex-pack.it
Types of Data Collected
Among the Personal Data collected by this Application, either independently or through third parties, there are: Tracking Tools; Usage Data; name; surname; phone number; VAT ID; company name; physical address; country; email; city; Tax Code; sector of activity.
Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or by means of specific informative texts displayed before the data collection.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application.
Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to communicate it, it may be impossible for this Application to provide the Service. In cases where this Application indicates certain Data as optional, Users are free not to communicate such Data, without this having any consequence on the availability or operation of the Service.
Users who have doubts about which Data is mandatory are encouraged to contact the Data Controller.
Any use of Cookies – or other tracking tools – by this Application or by the owners of third-party services used by this Application, unless otherwise specified, serves the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Application and guarantees to have the right to communicate or disseminate them, releasing the Data Controller from any liability towards third parties.
Mode and Location of Processing the Collected Data
Mode of Processing
The Data Controller adopts appropriate security measures aimed at preventing unauthorized access, disclosure, modification, or destruction of Personal Data.
The processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the organization of this Application (administrative, commercial, marketing, legal, system administrators personnel) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller, may have access to the Data. The updated list of Data Processors can always be requested from the Data Controller.
Legal Basis of Processing
The Data Controller processes Personal Data relating to the User if one of the following conditions exists:
- the User has given consent for one or more specific purposes; Note: in some jurisdictions, the Data Controller may be authorized to process Personal Data without the User’s consent or another of the legal bases specified below having to exist, until the User objects (“opt-out”) to such processing. However, this is not applicable if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
- processing is necessary for the execution of a contract with the User and/or for the execution of pre-contractual measures;
- processing is necessary to fulfil a legal obligation to which the Data Controller is subject;
- processing is necessary for the performance of a task carried out in the public interest or for the exercise of official authority vested in the Data Controller;
- processing is necessary for the pursuit of the legitimate interest of the Data Controller or third parties.
It is, however, always possible to ask the Data Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on law, provided for by a contract, or necessary to conclude a contract.
Location
The Data is processed at the Data Controller’s operating offices and in any other place where the parties involved in the processing are located. For more information, contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the place of processing, the User can refer to the section relating to the details on the processing of Personal Data.
The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization under public international law or constituted by two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect the Data.
The User can verify whether one of the transfers described above takes place by examining the section of this document relating to the details on the processing of Personal Data or by asking the Data Controller for information by contacting them at the details provided at the opening.
Retention Period
The Data is processed and stored for the time required by the purposes for which it was collected.
Therefore:
- Personal Data collected for purposes related to the execution of a contract between the Data Controller and the User will be retained until the execution of said contract is completed.
- Personal Data collected for purposes attributable to the legitimate interest of the Data Controller will be retained until the satisfaction of such interest. The User can obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
When the processing is based on the User’s consent, the Data Controller may keep the Personal Data longer until such consent is revoked. Furthermore, the Data Controller may be obliged to keep the Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, the Personal Data will be deleted. Therefore, upon expiry of this term, the right of access, erasure, rectification and the right to Data portability can no longer be exercised.
Purposes of Processing the Collected Data
The User’s Data is collected to allow the Data Controller to provide the Service, fulfil legal obligations, respond to requests or executive actions, protect their rights and interests (or those of Users or third parties), identify any malicious or fraudulent activity, as well as for the following purposes: **Statistics**, **Displaying content from external platforms**, and **Contacting the User**.
To obtain detailed information on the purposes of the processing and the Personal Data processed for each purpose, the User can refer to the section “Details on the processing of Personal Data”.
Details on the Processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
Information on the use of Artificial Intelligence systems
AI
Some content on the Site, including but not limited to text, images, videos, and graphic elements, may have been generated, processed, or modified using Artificial Intelligence (“AI”) tools. The use of such technologies is solely intended for the creation, processing, and optimization of content for product communication and presentation. Where AI-generated or modified content is used for product representation, the essential characteristics, appearance, and identifying elements of the products are reproduced accurately and truthfully to the real items, notwithstanding that any settings, backgrounds, or accessory elements may be digitally processed or artificially generated.
User Rights
Users can exercise certain rights with reference to the Data processed by the Data Controller.
In particular, the User has the right to:
- withdraw consent at any time. The User can withdraw the consent to the processing of their Personal Data previously expressed.
- object to the processing of their Data. The User can object to the processing of their Data when it occurs on a legal basis other than consent. Further details on the right to object are indicated in the section below.
- access their Data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing and to receive a copy of the Data processed.
- verify and request rectification. The User can verify the correctness of their Data and request its updating or correction.
- obtain the restriction of processing. When certain conditions apply, the User can request the restriction of the processing of their Data. In this case, the Data Controller will not process the Data for any purpose other than their storage.
- obtain the erasure or removal of their Personal Data. When certain conditions apply, the User can request the erasure of their Data by the Data Controller.
- receive their Data or have them transferred to another controller. The User has the right to receive their Data in a structured, commonly used and machine-readable format and, where technically feasible, to obtain their transfer without hindrance to another controller. This provision is applicable when the Data is processed by automated means and the processing is based on the User’s consent, on a contract of which the User is a party or on contractual measures connected to it.
- lodge a complaint. The User can lodge a complaint with the competent personal data protection supervisory authority or act in court.
Details on the right to object
When Personal Data is processed in the public interest, in the exercise of official authority vested in the Data Controller, or to pursue a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.
Users are advised that, if their Data were processed for direct marketing purposes, they can object to the processing without providing any reason. To find out whether the Data Controller processes data for direct marketing purposes, Users can refer to the respective sections of this document.
How to exercise the rights
To exercise the User’s rights, Users can address a request to the contact details of the Data Controller indicated in this document. Requests are filed free of charge and processed by the Data Controller as quickly as possible, in any case within one month.
Further information on the processing
Legal defense
The User’s Personal Data may be used by the Data Controller in court or in the preparatory stages for its possible establishment for the defense against abuses in the use of this Application or the connected Services by the User.
The User declares to be aware that the Data Controller may be obliged to disclose the Data by order of the public authorities.
Specific information
Upon the User’s request, in addition to the information contained in this privacy policy, this Application could provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.
System logs and maintenance
For needs related to operation and maintenance, this Application and any third-party services used by it may collect system logs, i.e., files that record interactions and which may also contain Personal Data, such as the User IP address.
Information not contained in this policy
Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.
Response to “Do Not Track” requests
This Application does not support “Do Not Track” requests.
To find out if any third-party services used support them, the User is invited to consult their respective privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Application, as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details they hold. Please therefore consult this page frequently, referring to the date of last modification indicated at the bottom.
If the changes involve processing whose legal basis is consent, the Data Controller will collect the User’s consent again, if necessary.