1. General Information
1. This policy applies to the website operating at the following URL: borgotancredi.com
2. The website operator and the personal data controller is: Samuele Mazza
3. The operator’s email address is: info@borgotancredi.com
4. The operator is the controller of your personal data with respect to the data you voluntarily provide on the website.
5. The Website uses personal data for the following purposes:
– Presenting offers or information
6. The Website collects information about users and their behavior in the following ways:
– Through data voluntarily entered into forms, which is then entered into the Operator’s systems.
– By storing cookies on end-user devices.
2. Selected Data Protection Methods Used by the Operator
1. The areas where users log in and enter personal data are protected at the transmission layer (SSL certificate). As a result, personal data and login credentials entered on the website are encrypted on the user’s computer and can only be decrypted on the destination server.
2. Personal data stored in the database is encrypted in such a way that only the Operator, who possesses the key, can decrypt it. This ensures that the data remains protected in the event that the database is stolen from the server.
3. User passwords are stored in hashed form. The hashing function is one-way—it cannot be reversed—which is currently the industry standard for storing user passwords.
4. The Operator periodically changes its administrative passwords.
5. To minimize the risk of unauthorized access to data, the Operator uses complex passwords containing uppercase and lowercase letters, numbers, and special characters, with a minimum length of 8 characters.
6. An essential element of data protection is the regular updating of all software used by the Operator to process personal data, which specifically includes regular updates to software components.
7. To protect data, the Operator regularly performs backups.
3. Hosting
1. The website is hosted (technically maintained) on a server operated by aruba.it.
2. To ensure technical reliability, the hosting provider maintains logs at the server level. The following information may be logged:
– resources identified by a URL (addresses of requested resources—pages, files),
– the time the request was received,
– the time the response was sent,
– the client’s hostname—identified via the HTTP protocol,
– information about errors that occurred during HTTP transactions,
– the URL of the page previously visited by the user (referrer link)—if the user accessed the Website via a link,
– information about the user’s browser,
– information about the IP address,
– diagnostic information related to the process of independently ordering services through the order forms on the website,
– information related to the handling of emails sent to the Operator and sent by the Operator.
4. Your Rights and Additional Information About How Your Data Is Used
1. In certain situations, the Controller has the right to transfer your personal data to other recipients if this is necessary to fulfill the contract concluded with you or to comply with the Controller’s legal obligations. This applies to the following groups of recipients:
– a hosting company acting as a processor
– authorized employees and associates who use the data to fulfill the purpose of the website
2. Your personal data processed by the Controller will not be retained longer than is necessary to perform the related activities specified by separate regulations (e.g., accounting requirements). With regard to marketing data, the data will not be processed for longer than 3 years.
3. You have the right to request from the Controller:
– access to your personal data,
– correction of your personal data,
– deletion of your personal data,
– restriction of processing,
– and data portability.