DATA PROTECTION DECLARATION ON THE PROCESSING OF PERSONAL DATA

Information in accordance with Article: 12, 13 and 14 of the Regulation (EU) 2016/679

In accordance with Regulation (EU) 679/2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, this administration, which has always ensured the confidentiality, accuracy, availability and security of personal data, provides the following information:

Purpose of the data processing
The personal data will be collected and processed within the scope of the management activity for the performance of institutional, administrative, and accounting functions or for purposes related to the exercise of rights of clients/suppliers and managers or for non-institutional purposes. The data processing is necessary for the performance of a contract to which the data subject is party or to implement pre-contractual measures taken at the request of the data subject.

Applications:
Your application data can be used within 12 months after receipt of your curriculum vitae for possible contact in this regard. Your applicant data will be deleted after this period unless you have consented to its retention until revoked.

Processing methods
The data will be processed with computer systems and/or in manual form, in any case by means of suitable procedures that guarantee the security and confidentiality and the availability of the same.

The communication of the data
is optional.

The missing communication of data
has the effect of preventing the administration from providing the services requested.

The data can be communicated to
all legal entities (offices, corporations and organs of public administration, companies or institutions), which are obliged to know or may know them in the sense of the regulations. In the case of specific personal data and/or data relating to criminal convictions and offences, communication is made to the legal entities and in the forms specified in the regulation for the processing of sensitive and judicial data (measure of the Data Protection Authority of 30.05.2005).

The data can be
brought to the attention of the controller, the processors, the Data Protection Officer, the personal data processing officers, and the system administrator of this administration.

The data is
distributed exclusively within the framework permitted by the data protection regulations.

Duration of data processing and storage of personal data
The processing operations referred to in the present information will only last for the time strictly necessary to fulfil the obligations imposed on us by national and/or international laws, as well as by the laws of the countries to which the data may be communicated.

Information on the rights of the data subjects
The data subject has the right to obtain confirmation from the controller as to whether personal data relating to him or her are being processed; if this is the case, he or she has the right to be informed of such personal data and to receive the informations specified in Art. 15 GDPR (Right of access by the data subject).
The data subject has the right to request the controller to rectify incorrect personal data concerning him/her and, if necessary, to complete incomplete personal data (Art. 16 GDPR).
The data subject has the right to demand that the controller deletes immediately if one of the reasons listed in Art. 17 GDPR applies (if the data are no longer required for the purposes pursued (right to erasure – right to be forgotten).
The data subject has the right to request the controller to restrict processing if one of the conditions listed in Art. 18 GDPR is met, for example if the data subject has lodged an objection to processing, for the duration of the controller’s examination: Right to restriction of processing.
The data subject has the right to obtain the personal data concerning him/her that he/she has provided to a controller in a structured, common and machine-readable format and the right to transfer such data to another controller without hindrance from the controller to whom the personal data has been provided, under certain circumstances, for example if the processing is based on consent and the processing is carried out throughout automated procedures (right to data portability – Art. 20 GDPR).
The data subject shall have the right to object at any time to the processing of personal data concerning him. The controller will then no longer process the personal data unless he can demonstrate compelling reasons for processing which are worthy of protection and which outweigh the interests, rights and freedoms of the data subject, or unless the processing serves to assert, exercise or defend legal claims (Art. 21 GDPR).
Without prejudice to any other administrative or judicial remedy, every data subject has the right to lodge a complaint with a supervisory authority if the data subject considers that the processing of personal data relating to him or her is in breach of the GDPR (Art. 77 GDPR). The data subject may invoke this right before a supervisory authority in the Member State in which he or she is resident, at his or her place of work or at the place where the alleged infringement is committed. In Italy the competent supervisory authority is: Garante per la protezione dei dati personali

Data controller
Tiefenbrunner Ltd. is a company under Italian law, with legal domicile at Schlossweg 4, Entiklar, I-39040 Kurtatsch an der Weinstraße (BZ), it is responsible for the processing of all personal data that may be collected via this homepage.
Personal data will only be processed in accordance with the present data protection regulations by employees and collaborators of the company who have been expressly appointed as responsible/delegated persons for data processing. The employees have been appropriately trained in this respect and work under the direct supervision and responsibility of the data protection processing owner.

Further privacy information – Website
Tiefenbrunner Ltd. (hereinafter also referred to as the “Company”) has drawn up this data protection declaration in order to inform visitors to this website of the modalities and purposes of data processing. In particular, the visitors or those persons who make use of the web services offered on the website are informed in accordance with Article 13 of Regulation (EU) 679/2016 on the protection of personal data. Your personal data will be processed in accordance with the Legislative Decree no. 196/2003, the Regulation (EU) 2016/679 (General Data Protection Regulation) and the Legislative Decree 101/2018. The present privacy policy refers to the above-mentioned website and does not apply to linked websites and any websites that users may visit.

Your data will be processed in order to provide our services based on your request and to fulfil our pre-contractual and contractual obligations towards you. Your data can be passed on to third parties if required, but only within the scope of our business relationship. Your data will not be transferred to other EU countries. Profiling and automated decisions are not used.

The legislator has enacted a wide range of storage obligations and periods. After these periods have expired, the corresponding data is deleted.
We check links that leave our website editorially very carefully. Nevertheless, we assume no responsibility or liability whatsoever for the content of pages linked to from this website or from any other internet presence.

This Privacy Policy is an integral part of our website and the services we offer. Access to and use of the website implies that this Privacy Policy has been read and understood. If you do not agree with this privacy policy, please do not use our website.
The Company may change or update this Privacy Policy in part or in full. Amendments or updates to the Privacy Policy are available to all users in the Privacy column of the website and are binding from the moment of publication on the website. If the user does not agree with the changes, he/she can interrupt the use of our website. Continued use of our website and of our products and services after the publication of the above-mentioned changes and/or renewals shall be deemed to constitute acceptance of the changes and acknowledgement of the binding nature of the new terms. The website is owned and managed by the Company.

Types of data collectin and processing purpose:
Navigation data
The systems and software processes necessary for the correct operation of the website, in normal use, collect some personal data, the transmission of which is part of the normal use of Internet communication protocols. This is information which, although not collected to identify a data subject, by its very nature allows users to be identified through processing and combination with data transmitted by third parties. This category of data includes IP addresses or domain names, the computers used by users of the website, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to make the request to the server, the size of the file obtained in response, the status of the response given by the server (successful, error, etc.) in numerical code, and other parameters relating to the user’s operating system and computer environment. These data are used for statistical purposes only and are managed anonymously to ensure their correct functioning. The data may also be used to establish responsibility in the event of hypothetical IT law infringements with damage to the site: with the exception of this case, the aforementioned data will not be kept for more than 24 months.

Data provided voluntarily by users/visitors
Data provided
voluntarily and expressly by visitors to the website to the Company for the use of certain services or via e-mail requests may be automatically registered, but the information will be used exclusively for the services mentioned in the information letter. Your data will be used for the purpose of fulfilling your specific requests, contractual obligations, fiscal or accounting obligations, invoicing, debt recovery and for the fulfilment of the obligations required by the laws in force.

Cookies
This website also collects personal data through the use of cookies.
There are three categories of cookies:
# absolutely necessary cookies to ensure basic functions of the website
# functional cookies to ensure the performance of the website
# targeted cookies to improve the user experience

The Internet pages partly use so-called cookies. Cookies do not damage your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, effective and safer. Cookies are small text files that are stored on your computer and saved by your browser.
Most of the cookies we use are so-called “session cookies”. They are automatically deleted at the end of your visit. Other cookies remain stored on your end device until you delete them. These cookies enable us to recognize your browser the next time you visit us.
You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or generally, and activate the automatic deletion of cookies when closing the browser. If you deactivate cookies, the functionality of this website may be limited.
If you do not generally allow us to use cookies, certain features and pages will not function as expected.
With the exception of navigation data, the company only processes data that the user provides voluntarily and explicitly. However, refusal to provide certain information could result in a restriction of the services offered. Once the registration has been made, the personal data will be processed exclusively for the services indicated in the information letter.

Visitors to the website can register for one or more of the following services:
Information about services, requests etc.

  • Registration on the website
  • Purchases of the products offered on the website

Registration
The creation of a customer account is voluntary and is not necessary to use the webshop. The customer account will be deleted after 3 years years since the last login. You have the right to delete the customer account at any time, as provided for in the Regulation (EU) 679/2016, upon request by mail or by post.

Disclosure to third parties
Personal data will not be disclosed under any circumstances, unless required by law or if requested by the judicial authorities or other bodies and institutions. The Company also uses the services of other companies and/or individuals to provide certain services, such as sending e-mails, delivering parcels, making payments. The aforementioned third parties have access only to those personal data that are absolutely necessary for the performance of their own tasks. The Company underlines that the third parties are prohibited from using the personal data for other purposes, as well as the obligation to use
such data in accordance with the Privacy Policy and the applicable legal provisions.
The company does not intentionally collect sensitive or legally relevant personal data via its own website. In accordance with Art.9 of Regulation (EU) 2016/679, special categories of data (“sensitive data”) is personal data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation. According to Art.10 of Regulation (EU) 2016/679, judicially relevant data includes criminal convictions and offences. We recommend that you do not provide such information on our website. Should this be unavoidable (for example, in the case of assignment to protected groups of persons when sending a CV for employment purposes, in response to an offer of employment or when expressing interest in employment in our company), we request that the specific clarification letter be sent by post. In this letter, please give your written consent to the treatment of said personal and sensitive data.

Storage of data
Information and personal data collected through this website, including those voluntarily provided by the visitor in order to obtain the sending of informative material or other communications by writing to the addresses indicated in the “Contacts” section, will be kept only for the time strictly necessary to provide the requested service. Once the service has been provided, all personal data will be deleted in accordance with the Company’s Privacy Policy, unless otherwise requested by the authorities or required by law.

Data security
The Company protects the personal data by means of internationally recognized security standards and procedures that

  • the unauthorised access
  • unauthorised use and distribution
  • unauthorised amendment
  • loss and accidental or unlawful destruction.

 Web analysis with Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider is Google Inc, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Google Analytics uses such target-oriented cookies.
You can find more information on how Google Analytics handles user data in the Google privacy policy: https://support.google.com/analytics/answer/6004245?hl=en
You can prevent the collection of the data generated by the cookie and related to your use of the website to Google, and the processing of this data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de

Google Maps
In our internet presence we use Google Maps to show our location and to provide directions. This is a service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter only “Google”. Through certification in accordance with the EU-US Privacy Shield, Google guarantees that the data protection requirements of the EU are also complied with when processing data in the USA.

If you call up the Google Maps component integrated into our website, Google will store a cookie on your terminal device via your Internet browser. In order to display our location and to create a route description, your user settings and data are processed. We cannot exclude the possibility that Google uses servers in the USA. The legal basis is Art. 6 para. 1 lit. f) GDPR. Our legitimate interest lies in the optimisation of the functionality of our internet presence.

Through the connection to Google established in this way, Google can determine from which website your request has been sent and to which IP address the directions are to be sent. If you do not agree with this processing, you have the possibility to prevent the installation of cookies by the appropriate settings in your internet browser.

In addition, the use of Google Maps and the information obtained via Google Maps is subject to the Google Terms of Use, policies.google.com/terms and the Terms and Conditions for Google Maps.

In addition, Google offers further information at adssettings.google.com/authenticated , policies.google.com/privacy.

Google Fonts
In our internet presence we use Google Fonts to display external fonts. This is a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter only referred to as “Google”.

By being certified according to the EU-US Privacy Shield, Google guarantees that the data protection requirements of the EU are also complied with when processing data in the USA.
To enable the display of certain fonts on our website, a connection to the Google server in the USA is established when our website is called up. The legal basis is Art. 6 para. 1 lit. f) GDPR. Our legitimate interest lies in the optimisation and economic operation of our internet presence.
Through the connection to Google established when you call up our website, Google can determine from which website your enquiry has been sent and to which IP address the representation of the font is to be transmitted.
Google offers further information
under adssettings.google.com/authenticated, policies.google.com/privacy, in particular regarding the possibilities of preventing the use of data.

PayPal
In the webshop you can choose PayPal as payment method, the PayPal privacy policy can be found at: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
The European operating company of PayPal is PayPal (Europe) S.à.r.l. & Cie S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg.

Stripe
In the webshop you can choose Stripe as payment method, the Stripe privacy policy can be found at https://stripe.com/privacy
Stripe is based outside the territory of the European Union in the USA: Stripe, 510 Townsend Street, San Francisco, CA 94103, USA.  Any data transfers outside the EU are subject to the terms of the EU-US Privacy Shield Agreement (https://stripe.com/privacy-shield-policy).

SSL Encryption
This site uses SSL encryption for security reasons and to protect the transmission of confidential content, such as the requests you send to us as site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.
If the SSL encryption is activated, the data that you transmit to us cannot be read by third parties.

Minor visitors
The Company’s website, which is governed by this Privacy Policy, is not intended for the use by minors. We are aware of the need to protect data concerning minors, especially in the online environment. For this reason, we do not collect and store – unless in an involuntary way – any data of minors.

Responsible for the content                                     Head office / address

Tiefenbrunner Ltd.                                                       Tiefenbrunner Ltd. SchlosskellereiTurmhof

Via Castello 4, Niclara

I-39040 Cortaccia sulla Strada del Vino (BZ)

Tel: +39 0471 88 01 22

Fax: +39 0471 88 04 33

E-Mail: info@tiefenbrunner.com