Privacy Policy
Preamble
PLUSS SRL (hereinafter also “PLUSS” or “the Controller”) is a company that sells graphic products to distributors, entities, professionals and legal entities in general and is responsible for the processing of the personal data of Internet users and, in particular, of those who visit its websites. PLUSS recognizes the importance of safeguarding personal data and respects the rights of individuals. PLUSS is fully aware of the importance of safeguarding privacy and the rights of individuals and, since the Internet is a potentially critical tool for the circulation of your personal data, it has undertaken a serious commitment to comply with rules of conduct which, in line with European Regulation (EU) 679/2016 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, the “GDPR”), ensure safe, controlled, and confidential navigation on the web.
This Privacy Policy may be subject to changes over time, including in relation to legislative and regulatory amendments or integrations on the matter, or as a result of our institutional decisions; therefore, we invite you to periodically consult this section of our website.
This Privacy Policy is to be understood as applicable exclusively to the websites of PLUSS SRL and not to those of other companies, bodies, associations, professionals or any other legal entity or natural person.
Basic principles of PLUSS’ Privacy Policy
1. To carry out processing (any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destructionany operation relating to data, regardless of the means and procedures used, including collection, storage, use, modification, communication, archiving, or destruction of data) personal data (any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural personal information relating to an identified or identifiable individual) exclusively for the purposes and in accordance with the methods illustrated in the information provided to the user each time they access a section of the site where the provision of personal data, directly or indirectly, is required;
2. To use the data voluntarily provided by the user;
3. To use technical cookies to facilitate website navigation and analytical cookies for statistical purposes
4. To transmit the data to third parties (data processors – Art. 4, par. 8, GDPR: “a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller”) solely for purposes instrumental to the specific requests made, and only to parties that have been carefully pre-selected and are contractually bound;
5. To disclose the data to third parties for related activities or whenever required by law, regulation, or EU legislation;
6. To respond to requests for access to, rectification, or erasure of personal data, as well as the exercise of the right to be forgotten, the right to restrict processing, or the right to object to processing. To ensure the exercise of the right to data portability and to inform users of the possibility to lodge a complaint with the supervisory authority;
7. To ensure the proper and lawful processing of your data, safeguarding your privacy, and to implement appropriate security measures to protect the confidentiality, integrity, and availability of such data.
Purposes and means of processing – legal basis – criteria of data collection
Purposes of data processing
All data collection – and subsequent processing – activities are aimed at pursuing PLUSS’ institutional and commercial purposes and, in particular, to:
1. Respond to requests made through contacts established spontaneously by the user, including our social channels or other features made available by the site to establish contacts with PLUSS direct you to our social channels
2. Carry out direct marketing activities related to its products (promotional communications, direct sales offers, surveys and market research, updates on the product catalog, newsletters)
3. Statistical processing on the characteristics of customers and their orders, as well as on registered users or those requesting information. The consequent statistical reports may also be disseminated through PLUSS communication channels, such as its website, during events and conferences, on paper and online illustrative material or digital media, in print (e.g.: newspapers and periodicals) and in the media (e.g.: TV)
4. Exercise, assert or defend in court a right of one’s own or of a third party.
Means of data processing
1. Personal data are processed by the Controller with manual, electronic and telematic means and stored in its filing system. Appropriate security measures are applied to prevent data from loss or alteration – even if accidental – unlawful or improper uses or unauthorised access.
2. All processing will be carried out with criteria which take into account the purposes for which data have been collected and in accordance with the security measures in force, for the purposes explained in information provided pursuant to article 13, GDPR.
3. The contacts referred to in point 2 of the chapter “Purposes of data processing” may be carried out with traditional communication tools (e.g.: direct mail, landline or mobile telephone with operator) or electronic (e.g.: e-mail).
4. The purposes referred to in point 3., “Purposes of data processing” are pursued with electronic processing that separates the information that identifies the data subject from the rest and consists of anonymous reports: the matching with the person to whom the data refer will no longer be reconstructable.
Legal basis of processing
1. For the purpose referred to in point 1. of the “Purposes of data processing”, the legal basis is art. 6, paragraph 1, letter b), GDPR since the processing is aimed at fulfilling pre-contractual or contractual obligations to which the data subject is a party. In this case, to satisfy a request expressly made by the users or of their specific interest
2. For the purposes referred to in point 2. “Purpose of data processing”, the legal basis is the consent of the data subject (Art. 6, para. 1, letter a), GDPR)
3. For the purposes referred to in point 3., “Purposes of data processing”, the legal basis is “legitimate interest” (art. 6, paragraph 1, letter f), GDPR, recital C47, GDPR and Opinion 09 April 2014, no. 6 of the Working Party 29, par. III.3.1.) of PLUSS to analyse the number of people who have an interest in its commercial activity and requests for information on products in order to improve, integrate or modify its product catalogue
4. For the purposes referred to in point 4., “Purposes of data processing”, the legal basis is “legitimate interest” (art. 6, paragraph 1, letter f), GDPR, recital C47, GDPR and Opinion 09 April 2014, no. 6 of the Working Party 29, par. III.3.1.) of PLUSS or a third party to protect their rights.
Criteria used to collect data
Personal data required by PLUSS consist of identification and contact details (name, surname or company name e-mail, phone number). The need to request data as mandatory for participation in individual initiatives or to execute orders or to make requests was considered in compliance with the provisions of art. 25 GDPR (“Data Protection by Design and by Default”), which require the appropriate technical and organisational measures, such as “pseudonymisation” (Art. 4(5) GDPR: “the processing of personal data in such a way that personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is stored separately and subject to technical and organisational measures to ensure that such personal data are not attributed to an identified or identifiable natural person”), aimed at effectively implementing data protection principles, such as minimisation, and integrating the necessary safeguards into the processing in order to meet the requirements of the GDPR and protect the rights of data subjects. In addition, PLUSS has put in place appropriate technical and organisational measures to ensure that only the personal data necessary for the specific purpose of the processing resulting from the initiative or service (e.g. order) to which the data subject has voluntarily subscribed are processed, by default.
Criteria used to determine the period for which data will be stored
Personal data will be kept in our filing systems (art. 4, paragraph 6, GDPR: “any structured set of personal data accessible according to determined criteria, regardless of whether such set is centralized, decentralized or divided in a functional or geographical way”) according to criteria that vary according to the category of the data, the nature of the processing and the purposes of the processing itself.
In principle, the following assessments apply to determine the data storage policy:
1. For the purposes referred to in point 1., “Purposes of data processing”, the data will be stored for the time necessary to fully process the request made by the data subject, including through the chat service, which may continue over time, if the request is not satisfied at the first contact and requires several exchanges of information between the data subject and the Controller or if the data subject intends to ask further questions related to the first request
2. For the purposes referred to in point 2. “Purposes of data processing”, the data are stored in our archives for the period necessary to maintain the relationship established with the person and inform him or her about our commercial activities, allowing PLUSS to continue, legitimately, its marketing and direct sales activities as long as it is considered that the person remains interested in our products and services, especially if registered or a regular customer. As a guideline, the data of these data subjects will be kept for a period of 2 (two) years from the last action taken.
Obviously, this retention period will be interrupted when the person expresses the desire not to receive further information and offers from PLUSS, communicating it in the manner set out in the chapter “Rights of the data subjects with respect to data concerning them”. PLUSS will take appropriate technical and organisational measures to stop contacting the person
3. For the purposes referred to in point 3., “Purposes of data processing”, the personal data stored in our archives for the period necessary for their transformation into anonymous form. After this period, the identification data are no longer identifiable and do not lead back to the person and, therefore, no longer subject to the requirements of the GDPR
4. For the purposes referred to in point 4., “Purposes of data processing”, the data are stored in our archives for the period necessary to carry out the individual phases of any judicial proceedings or disputes that may arise until the conclusion of the same, therefore, within terms consistent with the timing indicated by the competent bodies.
After the periods set out above, the identification data are transformed into anonymous form and used only for statistical reports that do not allow the identity of the person to be traced but which are useful for adapting the services, the product catalogue and the promotional and commercial initiatives of PLUSS. Personal data (personal identification) will therefore be destroyed, unless otherwise ordered by supervisory authorities, law enforcement agencies and the judiciary or to exercise, assert or defend a right of PLUSS or a third party in court.
Where data are processed
Processing carried out for the purposes of the performance of services provided by this website takes place at PLUSS’ headquarter and are performed by the persons authorised to processing. If need be, personal data can be processed by companies which are in charge of the technological management of the website (data processors designated pursuant to art. 28, GDPR), at their offices.
Transfers of personal data to third Countries or international organisations
Processing carried out for the purposes here described takes place at the Controller’s office – and/or at the offices of data processors – and stored in its filing systems. It is understood that, if need be, the Controller will have the right to transfer personal data to third Countries or international organisations. In this case, the Controller assures that the transfer will take place in accordance with provisions laid down in articles 45, 46, 47 and 49, GDPR.
Data Controller
PLUSS SRL – Via D’Ovidio 3, 20131 Milan (MI – Italy) VAT IT02225020185 – e-mail info@pluss.it is the data controller (art. 4, paragraph 7, GDPR: “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data”), pursuant to and for the purposes of the GDPR, since it decides in what way and for what reasons, communicated in the information to be provided to the data subjects, to collect and use the personal data provided by the user, as well as with which tools to process them and which security procedures to activate to guarantee their integrity, confidentiality and availability, subjecting itself to the obligations and responsibilities provided for by art. 24, GDPR.
Data processors, persons authorised to process data and autonomous data controllers
Your personal data may be processed, either manually, electronically or with telematic means, either directly by PLUSS or by third parties who, equipped with experience, technical skills, professionalism and reliability, carry out processing operations on our behalf, in compliance with the security and confidentiality of the information and constantly monitored by us in their work. The data processor is “the natural or legal person, public authority, agency or other body that processes personal data on behalf of the data controller” (art. 4, paragraph 8, GDPR) and is contractually bound by PLUSS, with definition of the limits of operation on the data, the data it can process and the categories of data subjects to which they refer, the nature and purpose of the processing, the limits of data retention, the obligations and rights that PLUSS has towards the data processor, and with the prohibition to use it differently from the task entrusted. It may, if formally authorized, in a general or specific way, by PLUSS, make use of other processors, who are contractually bound by the initial manager appointed directly by PLUSS: violations committed by such other processors fall under the responsibility of the initial manager and not of PLUSS. The complete and updated list of data processors (and, if applicable, of the data processors appointed by the initial data processor, subject to our authorization) can be requested at the address (alternatively, by writing to PLUSS SRL – Via D’Ovidio 3, 20131 Milan (MI – Italy)). The personal data collected will be made available to persons authorized by PLUSS pursuant to art. 29, GDPR who carry out processing activities that are indispensable for the pursuit of the purposes indicated above; the categories of persons authorised to process data are in charge of sales, pre-sales and after-sales commercial activities, administration, management of information services, relations with actual and potential customers, organizers of promotional and advertising campaigns, commercial and institutional activities.
The data may also be processed by control bodies, police forces and the judiciary to assert or defend their rights or a right of a third party in court. These subjects will act as autonomous data controllers and, for anything not reported herein, required to provide their own information on the processing of personal data.
Communication and dissemination of personal data
Users’ data may be communicated to third parties for various purposes. To be precise, the various cases that involve the communication of data to third parties are listed below.
1. The data must be communicated to third parties, independent data controllers, as it is necessary to comply with laws or regulations. Such communication is allowed without the consent of the data subject (art. 6, paragraph 1, letter c), GDPR).
2. Personal data may also be communicated to control bodies, police forces and the judiciary to assert or defend one’s own rights or the rights of a third party in court. Such communication is permitted without the consent of the data subject pursuant to art. 6, paragraph 1, letter f), GDPR, i.e. by virtue of the legitimate interest of the Controller or a third party to safeguard their fundamental rights and freedoms as long as those of the data subject do not prevail.
Social media
The data of users who join the PLUSS social media pages (fans of the page or subscribers to a group of followers of a specific promotional initiative or incentive for the sale of products or novelties in the PLUSS catalog), decide, with this action, to express their intention to follow news, comments, evolutions of PLUSS. These users, following their behavior, can lawfully receive promotional messages concerning the topics for which they have manifestly declared, implicitly by joining the page, to be interested. The sending of promotional communications regarding a specific product or range of products or an institutional or commercial activity in the broadest sense, carried out by PLUSS to which the relevant page refers, must be considered lawfully carried out if, from the context and the mode of operation of the social network, also depending on the information provided spontaneously by the user, it can be inferred that, unequivocally, The user has in some way expressed his or her willingness to receive precisely that type of message, with a behavioral formula that is conclusive of an implicitly declared consent. Therefore, pursuant to the provision of the Authority issuing guidelines on promotional activities and the fight against spam of 04 July 2013, register of measures no. 330, PLUSS may contact the active members of its social pages in order to send messages of an informative and promotional nature on initiatives, services, events and direct sales activities and promotions to develop its commercial activity. When the user leaves the group or stops following the events of PLUSS or exercises the right to object to the processing of data for promotional purposes, then this assumption lapses and, if PLUSS intends to continue to use the data for such promotional and institutional activities, it will request the user’s consent. Conversely, the data of the primary user’s contacts will be used by PLUSS upon request to the individual contact for express consent adequately and previously informed, specific for PLUSS’ promotional messages and issued in free form.
Data subjects’ rights
You can exercise, at any time, by e-mail info@pluss.it (alternatively, by writing to PLUSS SRL – D’Ovidio 3, 20131 Milan (MI – Italy)), the rights pursuant to articles 15-22, GDPR as follows:
Right of access (Article 15, GDPR)
The individual has the right to request whether his or her personal data is being processed and, therefore, has the right to access information concerning him or her and to have information on:
1. purposes of processing (e.g.: sending newsletters);
2. categories of personal data (e.g.: personal data, business activity)
3. recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular if recipients are third countries or international organisations;
4. where possible, the envisaged retention period for personal data or, if this is not possible, the criteria used to determine that period;
5. existence of the right to request the rectification or erasure of personal data or the restriction of the processing of personal data or to object to their processing;
6. the right to lodge a complaint with a supervisory authority;
7. if the data is not collected directly from the individual, all available information on their origin;
8. existence of automated decision-making, including profiling and meaningful information about the logic used, as well as the importance and intended consequences of such processing for the individual (e.g.: if the person has associated a profile of consumption habits by cross-referencing the amount spent with the frequency of spending and the promotional campaign). It should be noted that PLUSS does not perform profiling activities.
Right to rectification (Article 16, GDPR)
The individual has the right to obtain the rectification of inaccurate personal data concerning him or her without undue delay. Taking into account the purposes of the processing, the individual has the right to obtain the completion of incomplete personal data, including by providing a supplementary statement.
Right to erasure (“right to be forgotten”) (Article 17, GDPR)
The individual has the right to obtain the erasure of personal data concerning him/her and Actionaid has the obligation to erase the personal data without undue delay, for one of the following reasons:
1. the personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed;
2. the consent on which the processing is based is revoked and if there is no other legal basis for the processing (e.g.: legitimate interest, regulatory or contractual obligations);
3. you object to the processing for marketing and profiling purposes and there is no overriding legitimate reason for proceeding with the processing;
4. the personal data have been unlawfully processed;
5. your personal data must be erased in order to comply with a legal obligation under Union or Member State law to which you are subject.
Right to restriction of processing (Article 18, GDPR)
You have the right to obtain the restriction of the processing of your personal data where one of the following grounds applies:
1. the individual contests the accuracy of the personal data, for the period necessary to verify the accuracy of such personal data;
2. the processing is unlawful and the person opposes the erasure of the personal data and instead requests that its use be limited (e.g.: does not intend that the processing is carried out for marketing purposes but only for management and administrative purposes);
3. although the data is no longer required for the purposes of processing, the personal data are necessary for the establishment, exercise or defense of legal claims;
4. the person has objected to the processing if the processing is based on their legitimate interests, pending verification of whether their legitimate reasons prevail over those of the controller.
Obligation to notify in the event of rectification or erasure of personal data or restriction of processing (Article 19, GDPR)
The person has the right to request that the rectification or erasure of data or limitation of processing be communicated by PLUSS to other subjects to whom the data may have been communicated. PLUSS may not comply with the request, if the means to be employed are disproportionate to the right to confidentiality invoked by the person.
Right to data portability (Article 20, GDPR)
This right allows the individual to receive in a structured, commonly used and machine-readable format the personal data concerning him or her that has been provided to a person who subjects his or her data to processing and has the right to transmit those data to a subject for the latter’s use without hindrance from the person to whom he or she has provided them. This right can be exercised in the following cases:
1. the processing is based on consent either on a contract or on pre-contractual measures requested by the same person and, at the same time,
2. the processing is carried out by automated means.
The individual has the right to have his or her data transferred directly from one person to another (from the person to whom he or she has provided it to the person to whom he or she wishes it to be transmitted), if technically possible.
Right to object (Article 21, GDPR)
The person has the right to object to the processing of his or her data for the purposes of the legitimate interest of PLUSS or third parties. If personal data are processed for marketing purposes, the individual has the right to object at any time to the processing of personal data concerning him or her for such purposes, including profiling to the extent that it is related to such marketing activity.
Automated decision-making related to natural persons, including profiling (Article 22, GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. In particular, you have the right to object to profiling to which you are subjected through automated processes.
This right cannot be exercised if the decision:
1. it is necessary for the conclusion or performance of a contract;
2. it is authorised by Union or Member State law to which one is subject, which also specifies appropriate measures to protect the rights, freedoms and legitimate interests of the individual;
3. is based on explicit consent.
The person has the right to express his or her opinion and to contest PLUSS’ decision. Anyway, PLUSS does not carry out profiling activities.
Response times
As established by the GDPR, PLUSS will respond to the person within one month of the request, unless complex procedures must be put in place (or the requests are numerous) that do not allow this time to be respected. Full feedback is allowed within three months of the request, but we are obliged to notify you, in any case, within one month of the originally submitted request (Art. 12, paragraph 3, GDPR).
How to lodge a complaint with a supervisory authority
The data subject has the right to lodge a complaint with the supervisory authority (Garante per la Protezione dei Dati Personali – Piazza Venezia 11, 00187 Roma (RM – Italy) – www.garanteprivacy.it, e-mail protocollo@pec.gpdp.it, format https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/4535524&zx=e0yn0riezmmw) to exercise and defend the right of data protection.
What are cookies and how are they used by PLUSS?
Cookies are pieces of information stored on your PC’s hard drive that are sent by your browser to a web server and relate to your use of the network. Consequently, they allow you to know the services, the sites frequented and the options that, while browsing the net, have been manifested.
This information is not, therefore, provided spontaneously and directly, but leaves a trace. The data collected through cookies will be used for technical needs, in order to ensure easier, more immediate and rapid access to the site and its services and easier navigation for the user.
Profiling cookies may also be used, subject to the user’s consent, to create user profiles based on the sections of the site or the actions performed by the user on this site or browsing the web.
The use of so-called session cookies (which are not stored persistently on the user’s computer and are automatically deleted when the browser is closed) is strictly limited to the transmission of session identifiers (consisting of random numbers generated by the server) necessary to allow safe and efficient exploration of the site. The so-called session cookies that are used on this site avoid the use of other computer techniques that are potentially detrimental to the confidentiality of users’ browsing and do not allow the acquisition of personal data identifying the user. In any case, you can configure your browser so that you are notified when you receive a cookie and then decide whether to accept it.
To learn more about how PLUSS uses cookies, click HERE.
Browsing data
The computer systems and software procedures used to operate this site acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified users but which by its very nature could, through processing and association with data held by third parties, allow the identification of the users themselves. This category of data includes the IP addresses or domain names of the computers used by users who connect to the site, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, successful, error or similar) and other parameters relating to the user’s operating system and computer environment. This data is only used to obtain anonymous statistical information on the use of the site and to check its correct functioning and is deleted immediately after processing. The data could be used to ascertain responsibility in the event of hypothetical computer crimes against the site.
The security of your personal data
PLUSS SRL adopts appropriate and preventive security measures to safeguard the confidentiality, integrity, completeness and availability of your personal data. As established by the regulatory provisions governing the security of personal data, technical, logistical and organizational measures are developed that aim to prevent damage, loss, even accidental, alterations, improper and unauthorized use of the data concerning you.
In particular, PLUSS has put in place appropriate technical and organisational measures to ensure a level of security appropriate to the risk that may affect your rights and freedoms, including the confidentiality and confidentiality of individuals. PLUSS adopts security criteria that include, among others:
1. “pseudonymization” (Art. 4(5) GDPR: “the processing of personal data in such a way that personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is stored separately and subject to technical and organizational measures designed to ensure that such personal data are not attributed to an identified or identifiable natural person”) and data encryption
2. systems that permanently safeguard the confidentiality, integrity, availability and resilience of processing systems and services
3. systems to promptly restore the availability and access of personal data in the event of a physical or technical incident
4. procedures for regularly testing, verifying and evaluating the effectiveness of technical and organisational measures in order to ensure the security of processing.
Similar preventive security measures are adopted by third parties (data processors) to whom the Organization has entrusted processing operations of your data on its behalf.
On the other hand, PLUSS is not responsible for untruthful information sent directly by the user (e.g.: correctness of the e-mail address or postal address or other personal data), as well as for information concerning him/her that has been provided by a third party, even fraudulently.