Privacy Policy

PRIVACY POLICY OF GIUFRA S.R.L. OWNER OF THE TRADEMARK "ASTRA MAKE-UP"

About Giufra

The website of Giufra S.r.l., as well as the e-commerce portal integrated therein (hereinafter collectively, "Website") are operated by Giufra S.r.l., with registered office in Via Veneto 152 - 06059, Zona Industriale Ponte Rio (PG), Italy, +39 075 898 76 91, E-mail: marketing@astramakeup.com, C.F. and P.I. no. IT 01837230547 (hereinafter, "Giufra" or "we").

Giufra is the exclusive owner of the Astra Make-Up trademark and all "ASTRA" products contained on the Web Site.

Giufra s.r.l. collects some Personal Data of its Users.

 

Data Controller

Giufra S.R.L - via Veneto 152 - 06059, Ponte Rio Industrial Zone (PG), Italy

 P.iva: 01837230547

Controller’s email address: marketing@astramakeup.com

 

Types of Data Collected

Among the Personal Data collected by Giufra, either independently or through third parties, are: First name; last name; date of birth; phone number; address; city; email; Cookies; Usage Data; geographic location; unique device identifiers for advertising (Google Advertiser ID or IDFA identifier, for example); in-app purchases; username; country; Data disclosed while using the service; various types of Data; launches; number of sessions; session duration; page scroll interactions; mouse movements; relative position to scroll; keypress events; clicks; session statistics; pageviews; interaction events; page events; IP address; device information; app information; device logs; operating systems; browser information; language; house number; address; geographic region; approximate location; location information; ZIP code; state; province; latitude (of city); longitude (of city); metropolitan area; billing address; shipping address; payment information; point-of-sale data; billing data; product interaction; purchase history; order ID; User ID; ID; Tax ID; password.

Full details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or through specific informational texts displayed prior to the collection of such Data. Personal Data may be freely provided by the User or, in the case of Usage Data, automatically collected during the use of Giufra.

Unless otherwise specified, all Data requested by Giufra is mandatory. If the User refuses to provide them, it may be impossible for Giufra to provide the Service. In cases where Giufra indicates certain Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or its operation.

Users in doubt as to which Data are mandatory are encouraged to contact the Data Controller. Any use of Cookies - or other tracking tools - by Giufra or the owners of third party services used by Giufra is for the purpose of providing the Service requested by the User, in addition to the additional purposes described in this document and in the Cookie Policy.

 

The User assumes responsibility for the Personal Data of third parties obtained, published or shared through Giufra.

Method and place of processing of collected Data Mode of treatment

The Data Controller takes appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data.

The processing is carried out by means of computer and/or telematic tools, with organizational methods and logics strictly related to the indicated purposes. In

addition to the Data Controller, in some cases, other parties involved in the Giufra organization (administrative, sales, marketing, legal, system administrators) or external parties

(such as third party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, Data Processors by the Data Controller may have access to

the Data. The updated list of Data Processors can always be requested from the Data Controller.

Location

The Data are processed at the Holder's operational offices and at any other location where the parties involved in the processing are located. For more information, please contact the Data Controller.

The User's Personal Data may be transferred to a country other than the country in which the User is located. To obtain more information about the location of the processing, the User may refer to the section on Personal Data processing details.

Retention period

Unless otherwise stated in this document, Personal Data is processed and kept for the time required by the purpose for which it was collected and may be kept for a longer period due to any legal obligations or based on Users' consent. The maximum retention time, if Personal Data is not used, is 24 months.

Purposes of the Processing of Collected Data

User Data is collected to enable the Data Controller to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect its rights and interests (or those of Users or third parties), detect any malicious or fraudulent activities, as well as for the following purposes: Contacting the User, Contact management and message sending, Payment management, Tag management, Hosting and backend infrastructure, Location-based interactions, Registration and authentication, Remarketing and behavioral targeting, Advertising, Displaying content from external platforms, Statistics, Infrastructure monitoring, Social features, Support request and contact management, Interaction with support and feedback platforms, Interaction with live chat platforms, Access to accounts on third-party services, Management of data collection and online surveys, Traffic optimization and distribution, Commercial affiliation, and Interaction with data collection platforms and other third parties.

To obtain detailed information on the purposes of processing and the Personal Data processed for each purpose, the User may refer to the section "Personal Data Processing Details."

Facebook permissions requested by Giufra

Giufra may require certain Facebook permissions that allow it to perform actions with the User's Facebook account and collect information, including Personal Data, from it. This service allows Giufra to connect with the User's account on the social network Facebook, provided by Facebook Inc.

For more information on the following permissions, refer to the Facebook permissions documentation and Facebook's privacy policy.

The required permits are as follows:

Background information

The basic information of the User registered on Facebook which normally includes the following Data: id, name, image, gender and language of location and, in some cases Facebook "Friends". If the User has made additional Data publicly available, the same will be available.

'About Me' by friends

Provides access to the 'About Me' section of friends' profiles.

Access to private data

Allows access to User's and friends' private data.

Access to activities

Provides access to the User's activity list.

E-mail

Provides access to the User's primary e-mail address.

Details of the processing of Personal Data

Personal Data are collected for the following purposes and using the following services:

Access to accounts on third-party services

These types of services allow Giufra to take Data from your accounts on third-party services and perform actions with them.

These services are not activated automatically, but require your express permission.

Facebook Account Login (Meta Platforms Ireland Limited)

This service allows Giufra to connect with the User's account on the social network Facebook, provided by Meta Platforms Ireland Limited.

Required permissions: 'About Me' of friends; Access to private data; Access to activities; Email. Place of processing: Ireland - Privacy Policy.

Access to the X account (X Corp.).

This service allows Giufra to connect with the User's account on the social network X, provided by X Corp.

Personal Data Processed: last name; Data disclosed while using the service; Usage Data; email; device information; name; password; Tracking Tools; username.

Place of processing: United States - Privacy Policy.

Commercial affiliation

This type of service allows Giufra to display ads for products or services offered by third parties. The ads can be displayed either in the form of advertising links or as banners in various graphic forms.

Clicks on the icon or banner posted on Giufra are tracked by the third-party services listed below and are shared with Giufra.

To find out what data is collected please refer to the privacy policies of each service.

Awin (AWIN AG)

Awin is a commercial affiliate service provided by AWIN AG. Personal Data Processed: Usage Data; Tracking Tools.

Place of processing: Germany - Privacy Policy.

Contact User

If you have any questions or complaints about Giufra's processing of your personal data, please contact the Data Protection Officer at marketing@astramakeup.com. Users also have the right to file complaints about Giufra's processing of their personal data with the appropriate authorities. We encourage, however, users to give Giufra the opportunity to address any concerns by contacting it before contacting the relevant authorities.

Full contact details:

Data Protection Officer: Giufra S.r.l. via Veneto 152 - 06059, Zona Industriale Ponte Rio (PG), Italy,

Tel: +39 075 898 76 91,

E-mail: marketing@astramakeup.com

Mailing list or newsletter (Giufra)

By registering for the mailing list or newsletter, the User's email address is automatically added to a list of contacts to whom email messages containing information, including information of a commercial and promotional nature, about Giufra may be sent. The User's email address may also be added to this list as a result of registering with Giufra or after making a purchase.

Personal Data Processed: email.

Social features

Firebase Dynamic Links (Google Ireland Limited)

Firebase Dynamic Links is a social feature provided by Google Ireland Limited. Dynamic Links are tracked using Firebase or Google Analytics for Firebase and provide the Owner with details about the User's navigation path to and within Giufra.

Personal Data processed: various types of Data as specified by the privacy policy of the service.

Place of processing: Ireland - Privacy Policy.

Managing contacts and sending messages

These types of services enable the management of a database of email contacts, telephone contacts, or contacts of any other type used to communicate with the User.

These services may also allow for the collection of data related to the date and time of the User's viewing of messages, as well as the User's interaction with them, such as information about clicks on links embedded in messages.

Mailchimp (The Rocket Science Group, LLC.)

Mailchimp is an address management and email messaging service provided by Intuit Inc. Personal Data Processed: email.

Place of processing: USA - Privacy Policy.

Firebase Cloud Messaging (Google Ireland Limited)

Firebase Cloud Messaging is a messaging service provided by Google Ireland Limited. Firebase Cloud Messaging allows the Owner to send messages and notifications to Users on platforms such as Android, iOS, and on the web. Messages can be sent to individual devices, groups of devices, or based on topics or specific segments of Users.

Personal Data processed: various types of Data as specified by the privacy policy of the service. Place of processing: Ireland - Privacy Policy.

Sendgrid (Sendgrid)

Sendgrid is an address management and email messaging service provided by Sendgrid Inc. Personal Data Processed: last name; Usage Data; email; address; first name.

Place of processing: United States - Privacy Policy.

Leanplum

Leanplum is an omnichannel customer engagement and loyalty platform that helps create personalized experiences, promote user engagement through smart marketing strategies basted on metrics.

Personal Data Collected: various types of Data as specified by the privacy policy of the service. Place of Processing: Privacy Policy: https://www.leanplum.com/privacy/

Payment management

Payment processing services allow Giufra to process payments by credit card, bank transfer or other means. The data used for payment is acquired directly from the operator of the requested payment service without being processed in any way by Giufra.

Some of these services may also allow the scheduled sending of messages to the User, such as emails containing invoices or notifications regarding payment.

PayPal (Paypal)

PayPal is a payment service provided by PayPal Inc. that enables the User to make online payments. Personal Data processed: various types of Data as specified by the privacy policy of the service.

Satispay

Satispay is a mobile payment platform. Due to its mode of operation, which is completely independent of credit or debit cards, Satispay enables users to make online payments. Giufra does not collect any unencrypted information from users who use Satispay to pay all transmitted info is tokenized. Giufra does not provide Satispay with any data about the acquiring customer. For more information on Satispay's Privacy Policy go to this link: https://www.satispay.com/it-it/privacy/

Scalapay (Scalapay S.r.l.)

Scalapay is a payment service provided by Scalapay Ltd. that allows customers to pay in installments.

Personal Data Processed: in-app purchases; address; metropolitan area; zip code; city; click; Social Security Number; last name; purchase history; date of birth; billing information; usage data; point of sale data; ID; session duration; email; interaction events; page events; keypress events; order ID; User ID; billing address; shipping address; physical address; payment information; location information; browser information; device information; app information; product interaction; page scroll interactions; IP address; launches; latitude (of city); language; device log; longitude (of city); mouse movements; country; name; house number; number of sessions; phone number; pageview; approximate location; geographic location; location relative to scroll; province; geographic region; operating systems; session statistics; status.

Place of processing: Italy - Privacy Policy.

Tag management

This type of services is functional for the centralized management of tags or scripts used on Giufra. The use of such services implies the flow of User Data through them and, where appropriate, their retention.

Google Tag Manager (Google LLC)

Google Tag Manager is a tag management service provided by Google LLC. Personal Data Processed: Cookies; Usage Data.

Place of processing: USA - Privacy Policy.

Management of data collection and online surveys

This type of service allows Giufra to manage the creation, implementation, administration, distribution and analysis of online forms and surveys in order to collect, save and reuse Data from responding Users.

The Personal Data collected depends on the information requested and provided by Users in the corresponding online form.

These services may be integrated with a wide range of third-party services to enable the Data Controller to perform subsequent actions with the processed Data - for example, contact management, messaging, statistics, advertising, and payment processing.

For the purposes described above, we may collect data such as your age, gender, approximate geographic location, information about your use of our service, and preferences about third-party services and products. This data is processed in a way that does not directly identify any individual, but to obtain useful information on a collective basis.

 

Aggregate data, which do not allow for personal identification of users, may be shared with reliable and selected partners. This sharing is intended to improve the products and services offered, as well as to support data-driven marketing initiatives. Specifically, data may be shared with:

  • Market analysis partners that help us understand industry
  • Research organizations that conduct studies on the use of digital
  • Advertising partners for the development of targeted campaigns, but without sharing information that personally identifies you.

 

The processing of your data for these purposes is based on our legitimate interest in improving our services and offerings and contributing to market research, always respecting your privacy.

Support request management and contact

This type of services allows Giufra to manage support and contact requests received by email or through other tools, such as the contact form.

The Personal Data processed depends on the information provided by the User within the messages and the tool used for communication (e.g. email address).

Hosting and backend infrastructure

These types of services have the function of hosting Data and files that allow Giufra to function, enable its distribution, and provide a ready-to-use infrastructure to deliver specific Giufra functionality.

Some of these services operate through servers located geographically in different locations, making it difficult to determine the exact location where Personal Data is stored.

Short ( formerly Sendinblue)

Personal data collected by Brevo regarding the identity and contact information of its Users are stored for a maximum period of two years after the termination of the contractual relationship for User clients, or after their collection by the data controller or since the last contact of the User prospect for data related to the latter.

Shopify

Because we need your data to provide Shopify services to you, we generally retain your personal data for as long as you use Shopify products or services. If you close shopify, stop paying subscription fees, or suffer account deactivation, we retain shopify data for two years before we begin the process of deleting or anonymizing your personal data.

Interaction with data collection platforms and other third parties

These types of services allow Users to interact with data collection platforms or other services directly from Giufra's pages for the purpose of saving and reusing data.

In case one of these services is installed, it is possible that, even if Users do not use the service, it will collect Usage Data related to the pages where it is installed.

Aggregated data, which do not allow personal identification of users, may be shared with reliable and selected partners. This sharing is intended to improve the products and services offered, as well as to support data-driven marketing initiatives. Specifically, data may be shared with:

  • Market analysis partners that help us understand industry
  • Research organizations that conduct studies on the use of digital
  • Advertising partners for the development of targeted campaigns, but without sharing information that personally identifies you.

 

The processing of your data for these purposes is based on our legitimate interest in improving our services and offerings and contributing to market research, always respecting your privacy.

Infrastructure monitoring

This type of services allows Giufra to monitor the use and behavior of components of it, to enable the improvement of performance and functionality, maintenance or troubleshooting.

The Personal Data processed depend on the characteristics and mode of implementation of these services, which by their nature filter the activity of Giufra.

Firebase Performance Monitoring (Google Ireland Limited)

Firebase Performance Monitoring is a monitoring service provided by Google Ireland Limited. Personal Data processed: various types of Data as specified by the privacy policy of the service. Place of processing: Ireland - Privacy Policy.

Traffic optimization and distribution

This type of services allows Giufra to distribute its content through servers located in the territory and to optimize its performance.

The Personal Data processed depends on the characteristics and mode of implementation of these services, which by their nature filter communications between Giufra and the User's browser.

Given the distributed nature of this system, it is difficult to determine the places to which content is transferred, which may contain Personal Data of the User.

Advertisement

Some of the services below may use Tracking Tools to identify the User, or use the technique of behavioral retargeting, i.e. displaying advertisements tailored to the User's interests and behavior, or measuring the performance of ads. For more information on this, we suggest you check the privacy policies of the respective services. Generally, such services provide the ability to disable such tracking. In addition to any opt-out feature provided by any of the services listed in this document, the User can read more about how to turn off interest-based advertisements in the appropriate section "How to turn off interest-based advertising" in this document.

Meta ads conversion tracking (Meta pixel) (Facebook, Inc.).

Meta ads conversion tracking (Meta pixel) is a statistics service provided by Meta Platforms, Inc. or Meta Platforms Ireland Limited, depending on how the Data Controller manages the processing of the Data, that links data from the Meta ad network with actions taken within Giufra. The Meta pixel monitors conversions that can be attributed to Facebook, Instagram, and Audience Network ads.

Personal Data Processed: Usage Data; Tracking Tools.

Place of processing: USA - Privacy Policy.

Google Ads (Google Inc.) conversion tracking.

Google Ads conversion tracking is a statistics service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links data from the Google Ads ad network with actions taken within Giufra.

Personal Data Processed: Usage Data; Tracking Tools. Place of processing: USA - Privacy Policy.

Facebook Audience Network (Facebook, Inc.)

Facebook Audience Network is an advertising service provided by Facebook, Inc. For an understanding of Facebook's use of data, please see Facebook's data policy.

To enable the operation of Facebook Audience Network, Giufra may use certain mobile device identifiers (including Android Advertising ID or Advertising Identifier for OS) or cookie-like technologies. Among the ways in which Audience Network delivers advertising messages to the User is by using the User's advertising preferences. The User can control the sharing of his or her advertising preferences within Facebook's Ad settings.

You may opt-out of certain Audience Network targeting features through your device settings. For example, you may change the settings on advertising available for mobile devices, or follow the instructions applicable to Audience Network that may be found within this privacy policy.

Personal Data Processed: Cookies; Usage Data; unique device identifiers for advertising (Google Advertiser ID or IDFA identifier, for example).

Place of processing: United States - Privacy Policy - Opt Out.

Facebook's Similar Audience (Facebook, Inc.)

Facebook's Similar Audience is an advertising and behavioral targeting service provided by Facebook, Inc. that uses Data collected through Facebook's Personalized Audience service in order to show advertisements to Users with similar behaviors to Users who are already on a Personalized Audience list based on their previous use of Giufra or their interaction with relevant content through Facebook applications and services.

Based on this Data, personalized ads will be shown to Users suggested by Facebook's Similar Audiences.

Users can opt-out of Facebook's cookies for ad personalization by visiting this opt-out page . Personal Data Processed: Cookies; Usage Data.

Place of processing: United States - Privacy Policy - Opt Out.

Google Ad Manager (Google Ireland Limited)

Google Ad Manager is an advertising service provided by Google Ireland Limited with which the Owner may conduct advertising campaigns jointly with external advertising networks with which the Owner, unless otherwise specified herein, has no direct relationship. Users who do not wish to be tracked by the different advertising networks may use Youronlinechoices. For an understanding of Google's use of data, please see Google's Partner Policy. This service uses the Cookie "DoubleClick", which tracks the use of Giufra and the behavior of the User in relation to advertisements, products and services offered.

The User can decide at any time to disable all DoubleClick cookies by going to: Ads Settings. Personal Data Processed: Cookies; Usage Data.

Place of processing: Ireland - Privacy Policy.

Microsoft Advertising (Microsoft Corporation)

Microsoft Advertising is an advertising service provided by Microsoft Corporation. Personal Data Processed: Usage Data; Tracking Tool.

Place of processing: United States - Privacy Policy - Opt Out.

Registration and authentication

By registration or authentication, the User allows the Application to identify him/her and give him/her access to dedicated services.

Depending on what is indicated below, registration and authentication services may be provided with the help of third parties. If this occurs, this Application may access some Data stored by the third-party service used for registration or identification.

Facebook Authentication (Facebook, Inc.)

Facebook Authentication is a registration and authentication service provided by Facebook, Inc. and linked to the social network Facebook.

Personal Data processed: various types of Data as specified by the privacy policy of the service. Place of processing: USA - Privacy Policy.

Facebook Oauth (Meta Platforms Ireland Limited)

Facebook Oauth is a registration and authentication service provided by Meta Platforms Ireland Limited and linked to the Facebook network.

Personal Data Processed: Tracking Tools; various types of Data. Place of processing: Ireland - Privacy Policy.

Sign in with Apple (Apple Inc.)

Sign in with Apple is a registration and authentication service provided by Apple Inc. In instances where the User is asked to provide his or her email address, Sign In with Apple may generate a private referral address on the User's behalf that automatically forwards messages to his or her personal verified email address - thereby hiding his or her email address from the Owner.

Personal Data Processed: last name; date of birth; email; first name; phone number. Place of processing: United States - Privacy Policy.

Remarketing and behavioral targeting

This type of service allows Giufra and its partners to communicate, optimize and serve advertisements based on the User's past use of Giufra.

This activity is facilitated by tracking Usage Data and using Tracking Tools to collect information that is then transferred to partners that handle remarketing and behavioral targeting

activities.

Some services offer an email list-based remarketing option.

In addition to the opt-out

features offered by the services below, the User can opt-out by visiting the Network Advertising Initiative opt-out page.

Users can also opt out of certain advertising features through corresponding device configuration options, such as mobile device advertising configuration options or generic advertising configuration.

Remarketing Google Ads (Google Inc.).

Remarketing Google Ads is a remarketing and behavioral targeting service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links Giufra's activity with the Google Ads advertising network and the DoubleClick Cookie.

Users can opt out of Google's cookies for ad personalization by visiting Google's Ads Settings. Personal Data Processed: Cookies; Usage Data.

Place of Processing: USA - Privacy Policy - Opt Out.

Facebook Custom Audience (Facebook, Inc.)

Facebook Custom Audience is a remarketing and behavioral targeting service provided by Facebook, Inc. that connects Giufra's activity with the Facebook advertising network.

Personal Data Processed: Cookies; email.

Place of Processing: USA - Privacy Policy - Opt Out.

Facebook Remarketing (Facebook, Inc.)

Facebook Remarketing is a remarketing and behavioral targeting service provided by Facebook, Inc. that links Giufra's activity with the Facebook advertising network.

Personal Data Processed: Cookies; Usage Data. Place of Processing: USA - Privacy Policy - Opt Out. Remarketing with Google Analytics (Google Inc.).

Remarketing with Google Analytics is a remarketing and behavioral targeting service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links the tracking activity performed by Google Analytics and its Cookies with the Google Ads advertising network and the Doubleclick Cookie. Personal Data Processed: Cookies; Usage Data. Place of Processing: USA - Privacy Policy - Opt Out.

Statistics

The services contained in this section allow the Data Controller to monitor and analyze traffic data and serve to track User behavior.

Google Analytics for Firebase (Google Ireland Limited)

Google Analytics for Firebase, or Firebase Analytics, is an analytics service provided by Google Ireland Limited.

For an understanding of Google's use of data, please see Google's Partner Policy.

Firebase Analytics may share Data with other services provided by Firebase including, for example, Crash Reporting, Authentication, Remote Config or Notifications. Users may consult this privacy policy for a detailed description of the other tools used by the Owner.

To enable Firebase Analytics to work, Giufra uses some mobile device identifiers i.e. cookie-like technologies.

The User may opt-out of certain Firebase features through the settings on their mobile device. For example, he or she may change the settings on advertising available on his or her mobile device, or follow the instructions applicable to Firebase that may be found within this privacy policy.

Personal data processed: in-app purchases. Place of processing: Ireland - Privacy Policy.

Google Analytics (Universal Analytics) with anonymized IP

Google Analytics (Universal Analytics) is a web analytics service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, ("Google"). Google uses the Personal Data collected for the purpose of tracking and examining the use of Giufra, compiling reports and sharing them with other services developed by Google.

Google may use Personal Data to contextualize and personalize ads in its ad network.

This Google Analytics integration anonymizes your IP address. Anonymization works by abbreviating within the borders of the member states of the European Union or other countries that are party to the Agreement on the European Economic Area the IP address of Users. Only in exceptional cases will the IP address be sent to Google's servers and abbreviated within the United States.

For an understanding of Google's use of data, please see Google's Partner Policy. Personal Data Processed: Usage Data; Tracking Tool.

Place of processing: United States - Privacy Policy - Opt Out; Ireland - Privacy Policy - Opt Out.

Meta Events Manager (Meta Platforms Ireland Limited)

Meta Events Manager is a statistics service provided by Meta Platforms Ireland Limited. By integrating the Meta pixel, Meta Events Manager can give the Owner information about traffic and interactions on Giufra.

Personal Data Processed: Usage Data; Tracking Tools. Place of processing: Ireland - Privacy Policy.

Google Analytics 4 (Google Ireland Limited)

Google Analytics is a statistics service provided by Google Ireland Limited ("Google"). Google uses the Personal Data collected for the purpose of tracking and examining the use of Giufra, compiling reports and sharing them with other services developed by Google.

Google may use Personal Data to contextualize and personalize ads in its ad network.

In Google Analytics 4, IP addresses are used at the time of collection and then deleted before the data is recorded in any data center or server. To learn more, you can consult Google's official documentation.

For an understanding of Google's use of data, please see Google's Partner Policy. Personal Data Processed: Tracking Tools.

Place of processing: Ireland - Privacy Policy - Opt Out.

Appsflyer (AppsFlyer Ltd)

Appsflyer is a statistics service provided by AppsFlyer Ltd. Personal Data Processed: Usage Data; Tracking Tools.

Place of processing: Israel - Privacy Policy - Opt Out.

Viewing content from external platforms

This type of service allows to display content hosted on external platforms directly from the pages of Giufra and interact with them.

In the event that such a service is installed, it is possible that, even if Users do not use the service, it will collect traffic data related to the pages where it is installed.

Google Fonts (Google Inc.)

Google Fonts is a font style display service operated by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which allows Giufra to integrate such content within its pages.

Personal Data Processed: Usage Data; various types of Data as specified by the service's privacy policy.

Place of processing: USA - Privacy Policy.

Information on how to turn off interest-based advertisements

In addition to any opt-out features provided by any of the services listed in this document, Users can read more about how to turn off interest-based advertisements in the appropriate section of the Cookie Policy.

Further information on the processing of Personal Data Push notifications

Giufra can send push notifications to the User.

Online sale of goods and services

The Personal Data collected is used to provide services to the User or to sell products, including payment and possible delivery. The Personal Data collected to finalize payment may be that of the credit card, bank account used for the transfer, or other payment instruments provided. The Payment Data collected by Giufra depends on the payment system used.

Cookie Policy

Giufra makes use of Tracking Tools. To learn more, Users can consult the Cookie Policy.

More information for users Legal basis for processing

The Owner processes Personal Data related to the User if one of the following conditions exists:

  • The User has given consent for one or more specific
  • processing is necessary for the performance of a contract with the User and/or the execution of pre-contractual measures;
  • processing is necessary to fulfill a legal obligation to which the Controller is subject;
  • the processing is necessary for the performance of a task of public interest or the exercise of public authority vested in the Controller;
  • processing is necessary for the pursuit of the legitimate interest of the Controller or third

However, it is always possible to ask the Data Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on law, required by a contract or necessary to conclude a contract.

Additional information on shelf life

Unless otherwise stated in this document, Personal Data is processed and kept for the time required by the purpose for which it was collected and may be kept for a longer period due to any legal obligations or based on Users' consent. The period does not exceed 24 months in case of non-use

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the performance of that contract is
  • Personal Data collected for purposes attributable to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the

When processing is based on the User's consent, the Controller may retain Personal Data longer until that consent is revoked. In addition, the Controller may be required to retain Personal Data for a longer period to fulfill a legal obligation or by order of an authority.

 

At the end of the retention period, the Personal Data will be deleted. Therefore, at the expiration of this period the right of access, deletion, rectification and the right to Data portability can no longer be exercised.

Rights of the User based on the General Data Protection Regulation (GDPR)

Users may exercise certain rights with respect to the Data processed by the Data Controller. In particular, to the extent provided by law, the User has the right to:

  • Revoke consent at any time. The User may revoke the previously expressed consent to the processing of his/her Personal Data.
  • Object to the processing of their You may object to the processing of your Data when it is done pursuant to a legal basis other than consent.
  • Access to your You have the right to obtain information about the Data processed by the Data Controller, certain aspects of the processing and to receive a copy of the Data processed.
  • verify and request Users may verify the accuracy of their Data and request that it be updated or corrected.
  • obtain restriction of The User may request the restriction of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its preservation.
  • Obtain the deletion or removal of their Personal The User may request the deletion of their Data from the Data Controller.
  • Receive their Data or have their Data transferred to another You have the right to receive your Data in a structured, commonly used, machine-readable format and, where technically feasible, to have it transferred unimpeded to another data controller.
  • propose The User may bring a complaint to the relevant data protection supervisory authority or take legal action.

Users have the right to obtain information regarding the legal basis for the transfer of Data abroad including to any international organization governed by international law or formed by two or more countries, such as the UN, as well as regarding the security measures taken by the Data Controller to protect their Data.

Details of the right to object

When Personal Data are processed in the public interest, in the exercise of public powers vested in the Data Controller or in pursuit of a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.

Users are reminded that, should their Data be processed for direct marketing purposes, they may object to the processing at any time, free of charge and without providing any reasons. If Users object to processing for direct marketing purposes, the Personal Data are no longer processed for such purposes. To find out whether the Data Controller processes Data for direct marketing purposes, Users may refer to the respective sections of this document.

How to exercise rights

In order to exercise their rights, Users may address a request to the contact details of the Controller indicated in this document. The request is free of charge and the Controller will respond as soon as possible, in any case within one month, providing the User with all the information required by law. Any rectification, deletion or restriction of processing will be communicated by the Controller to each of the recipients, if any, to whom the Personal Data has been transmitted, unless this proves impossible or involves a disproportionate effort. The Data Controller shall notify the User of such recipients if the User so requests.

More information about the treatment Litigation defense

The User's Personal Data may be used by the Owner in legal proceedings or in the preparatory stages to its possible establishment for the defense against abuse in the use of Giufra or related Services by the User.

The User declares that he/she is aware that the Data Controller may be obliged to disclose the Data by order of public authorities.

Specific disclosures

Upon the User's request, in addition to the information contained in this privacy policy, Giufra may provide the User with additional and contextual disclosures regarding specific Services, or the collection and processing of Personal Data.

System logs and maintenance

For operation and maintenance purposes, Giufra and any third-party services it uses may collect system logs, which are files that record interactions and may also contain Personal Data, such as the User IP address.

Information not contained in this policy

Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on Giufra as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details it has. Therefore, please consult this page frequently, referring to the date of last modification indicated at the bottom.

 

If the changes affect processing whose legal basis is consent, the Controller will collect the User's consent again, if necessary.

Definitions and legal references Personal Data (or Data)

Personal data is any information that, directly or indirectly, including in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.

Usage Data

This is the information collected automatically through Giufra (including by third party applications integrated into Giufra), including: the IP addresses or domain names of the computers used by the User who connects with Giufra, the addresses in URI (Uniform Resource Identifier) notation, the time of the request, the method used in forwarding the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc..) the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (e.g. the length of time spent on each page) and the details of the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the User's operating system and computer environment.

User

The individual using Giufra which, except where otherwise specified, coincides with the Data Subject.

Interested

The natural person to whom the Personal Data refers.

Data Processor (or Manager)

The natural person, legal entity, public administration and any other entity that processes personal data on behalf of the Controller, as set forth in this privacy policy.

Data Controller (or Owner)

The natural or legal person, public authority, service or other body which, individually or jointly with others, determines the purposes and means of the processing of personal data and the instruments adopted, including the security measures relating to the operation and use of Giufra. The Data Controller, unless otherwise specified, is the owner of Giufra.

Giufra (or this Application)

The hardware or software tool by which Users' Personal Data are collected and processed.

Service

The Service provided by Giufra as defined in the relevant terms (if any) on this site/application.

European Union (or EU)

Unless otherwise specified, any reference to the European Union in this document is understood to extend to all current member states of the European Union and the European Economic Area.

Cookie

Cookies are Tracking Tools that consist of small portions of data stored within the User's browser.

Tracking Tool

Tracking Tool means any technology - e.g., cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting - that allows tracking Users, for example, by collecting or storing information on the User's device.

Legal references

Unless otherwise specified, this privacy policy covers Giufra only.

Last modified: June 26, 2024