Privacy Policy Midsummer.agency
Who is the Data Controller?
Midsummer Agency S.r.l., with its legal address at Via Messina, 11– 09023 Monastir (CA) (VAT Number: 03733220929) (hereinafter referred to as the “Controller”).
How can you contact us?
You can reach the company at:
Email: hello@midsummer.agency
Pec: midsummer.agency@pec.it
Address: Via Messina, 11– 09023 Monastir (CA)
- Introduction
Under the European General Data Protection Regulation (GDPR), legal entities are not considered data subjects and, as such, the European regulation does not apply to them. However, if personal data concerning an individual is included in the context of corporate data collection, that individual should be considered a data subject under the GDPR, and the relevant regulations apply.
- What data processing activities are conducted through the website? What are the legal bases, purposes, and retention periods?
MARKETING AND PROFILING THROUGH DIGITAL PLATFORMS
PURPOSE
The purpose of data processing is to show marketing content based on your interests, as identified by your interactions on our website or social media. This includes the use of digital platforms’ retargeting tools to deliver targeted advertising messages.
LEGAL BASIS
Consent that can be acquired through Cookies on our Site: Your consent to marketing and profiling cookies is collected through the cookie settings on our site.
Interaction with Social Pages: If you have given consent to the use of profiling cookies on our Site, we may process your contact details and the information communicated during interaction with Social Pages. We use this information, in accordance with your social media privacy settings, to display personalized marketing ads.
RETENTION PERIOD
The data will be stored until the consent is revoked through the cookie settings.
ADDITIONAL INFORMATION
Consent acquired through Cookies on our Site: The User can manage or revoke this consent at any time, as described in our Cookie Policy. We also inform you. that cookies can be both first and third-party and therefore installed, through us, directly by Meta.
In the case of simple User segmentation, your consent is not required.
The user is free to provide the requested data, as there is no legal obligation to provide them. However, if the user chooses not to provide data marked as essential, the Data Controller will not be able to achieve the specified purpose.
CONTACT US
PURPOSE
The purpose of data processing is to enable the submission of information requests.
LEGAL BASIS
Pre-contractual measures carried out at the Data Subject’s request. In case of disputes, data will be processed to act or defend legal claims, corresponding to the legitimate interest of the Data Controller.
RETENTION PERIOD
Data will be retained for 2 years after which they will be deleted.
ADDITIONAL INFORMATION
The user is free to provide the requested data, as there is no legal obligation to provide them. However, if the user chooses not to provide data marked as essential, the Data Controller will not be able to achieve the specified purpose.
REVIEWS
PURPOSE
The purpose is to share your experience and promote the company.
LEGAL BASIS
Legitimate interest of the Owner in importing reviews onto his website. The reviews are freely provided by the interested party without any type of request or solicitation.
RETENTION PERIOD
Reviews will be published on the site until they become outdated and/or until consent is revoked.
ADDITIONAL INFORMATION
The reviews are imported from the platforms on which they are published (Google and Clutch) and paraphrased.
WORK WITH US
PURPOSE
The purpose of data processing is to send spontaneous job applications.
LEGAL BASIS
Execution of pre-contractual measures at the Data Subject’s request.
RETENTION PERIOD
Data will be retained for 2 years after which they will be deleted.
ADDITIONAL INFORMATION
The user is free to provide the requested data, as there is no legal obligation to provide them. However, if the user chooses not to provide data marked as essential, the Data Controller will not be able to achieve the specified purpose.
NAVIGATION DATA
PURPOSE
Site security.
LEGAL BASIS
We will process data based on the company’s legitimate interest in cybersecurity and compliance with legal obligations. The legal basis for processing cookies other than necessary ones is consent.
RETENTION PERIOD
24 months
ADDITIONAL INFORMATION
For cookie regulations, please refer to the separate policy.
- What else should I know?
Data will be processed fairly, transparently, and with the utmost confidentiality, in compliance with appropriate security measures as required by the GDPR and applicable regulations. Processing will be carried out digitally. Data will be publicly disclosed only in the context of reviews and public questions. Additionally, the user will not be subject to automated decision-making processes, including profiling, unless consent is given through the installation of cookies or other tracking tools, subject to the respective policy.
- To whom will my data be communicated?
The Controller may disclose data to entities required by law to fulfill the purposes mandated by law. The Controller also uses certain companies or IT tools that process personal data on behalf of the Controller, such as couriers, all duly appointed as data processors under Article 28 of the GDPR. Data will also be communicated to payment gateways as independent controllers.
The list of data processors is available at the registered office.
In the event of a merger, sale or any other corporate change and/or in the event of the organization of one of these operations, your data may be shared. Furthermore, in the event that the company owned by the Data Controller or part of it is sold to a third party, the latter may continue to use your data, always in the manner provided for in this privacy policy.
- What is the place of data storage and transfer?
The management and storage of personal data will occur on servers located in Italy. However, data may be transferred outside of the European Union for certain activities (newsletter and back in stock). The Data Controller guarantees that transfers outside the EU comply with Articles 44-47 of Chapter V of the GDPR through the use of standard contractual clauses and/or the adequacy decision of July 10, 2023.
- What are my rights, and how can I exercise them?
- a) Data Subject Rights
As a data subject, you have the rights as defined in Article 15 and subsequent articles of the GDPR, including:
- RIGHT OF ACCESS (Article 15 GDPR): The right to obtain confirmation of the existence of personal data concerning you, even if not yet recorded, and their communication in an intelligible form.
- RIGHT TO RECTIFICATION (Article 16 GDPR): The right to obtain the correction of inaccurate personal data concerning you and the completion of incomplete data.
- RIGHT TO ERASURE (Article 17 GDPR): The right to obtain the erasure of personal data in specific cases, such as the withdrawal of consent or the objection to processing.
- RIGHT TO RESTRICT PROCESSING (Article 18 GDPR): The right to obtain the restriction of processing in specific cases, such as when requesting rectification or objection.
- RIGHT TO DATA PORTABILITY (Article 20 GDPR): The right to receive your data in a structured, commonly used, and machine-readable format, or request the transfer of data to another controller.
- RIGHT TO OBJECT (Article 21 GDPR): The right to object to the processing of personal data for specific reasons.
- RIGHT TO LODGE A COMPLAINT: The right to file a complaint with the relevant supervisory authority if you believe that data processing violates current regulations.
- b) How to Exercise these Rights:
You can exercise these rights at any time by contacting the Data Controller at the provided addresses.
Last updated: 23/06/2024
This privacy policy has been drafted by Polimeni.Legal.