Information on the Processing of Personal Data of Users of the Website www.magicamor.org
The following information (“the Policy”) is provided pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”) to illustrate the purposes and methods of processing personal data relating to users accessing the website www.magicamor.org (“the Website”), carried out by Magic Amor ETS.
This Policy exclusively concerns the processing of personal data related to users of the Website (“the Data Subjects”) and does not cover the processing of personal data carried out when visiting pages and websites accessible via links on the Website. In addition to this Policy, the Data Controller may provide more specific information regarding certain data processing activities conducted through specific forms on the Website.
Data Controller
The Data Controller for personal data of users accessing the Website is:
Magic Amor ETS
Tax Code: 97286010588
Registered Office: Via Temistocle Calisti, 16, 00166 Rome RM (“the Data Controller”).
Contact Details (“Contacts”):
Phone: +39 351 53.70.727
Email: info@magicamor.org
Types of Data Processed and Purposes of Processing
When users visit the Website, the following data may be processed:
- a) Browsing Data
These are data collected by the Data Controller using software applications necessary to ensure the proper functioning of the Website. These include information such as Internet Protocol (IP) addresses, domain names of computers and devices used by users, browser details, Uniform Resource Identifiers (URIs), and other data that, by providing information about the device and connection used to access the Website, may indirectly identify the Data Subject.
Processing this data is essential to ensure the proper functioning of the Website and is necessary for users to access the services offered. Failure to provide this data prevents navigation of the Website and access to the services offered through it.
The Website’s technical parameters have been configured to minimize the collection and use of users’ identifying data.
- b) Voluntarily Provided Personal Data
This includes data that users provide when filling out forms on the Website, sending emails to the addresses provided, or using the Website’s features.
These data are processed to send communications related to the activities carried out by the Data Controller, limited to the Data Subject’s contact details. Such processing is conducted only with the user’s consent, expressed by entering their email address in the appropriate form. Users can withdraw their consent at any time using the functionality at the bottom of each email received or by contacting the Data Controller via the details provided in this Policy.
- c) Technical and Analytical Data
This includes the IP address and browser specifications collected and communicated to third parties such as Facebook Ireland Ltd., Twitter International Company, and Google Ireland Ltd. to enhance the Data Controller’s visibility and image on social networks.
For this purpose, Facebook Ireland Ltd. acts as a joint data controller, with its registered office at 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Republic of Ireland (EU). Users may contact Facebook directly to exercise their rights regarding these activities.
This processing is carried out in pursuit of the Data Controller’s legitimate interest in promoting its services and image on the aforementioned social networks.
Retention Period of Personal Data
- Data processed under point a) will be retained for the time necessary to allow navigation of the Website and, in any case, no longer than seven days from collection, unless further retention is required for the purposes of investigating crimes or for legal protection.
- Data processed under point b) will be retained only as long as necessary to achieve the purposes for which it was collected. For promotional emails, data will be retained until the user withdraws consent.
Categories of Recipients and Data Transfers to Third Countries
Personal data may be shared with:
- IT service providers for Website management, hosting, and email services;
- Data Controller’s collaborators responsible for managing the Website and responding to requests;
- Public authorities, such as law enforcement or judicial offices, if required by law or a legitimate order.
Personal data will not be transferred to countries outside the European Economic Area (“Third Countries”) or international organizations.
Rights of the Data Subjects
The Data Subject may exercise the rights provided by Articles 15 and following of the GDPR, including:
- Access: Obtain confirmation of the existence of data processing and receive details about it.
- Rectification: Correct or complete inaccurate or incomplete personal data.
- Erasure (Right to be Forgotten): Request the deletion of personal data under specific conditions.
- Restriction: Limit data processing under certain conditions.
- Portability: Receive personal data in a structured, commonly used, and machine-readable format and request its transfer to another controller.
- Objection: Oppose data processing based on legitimate interests, except where the Data Controller demonstrates compelling legitimate grounds.
- Complaint: Lodge a complaint with the supervisory authority (e.g., the Italian Data Protection Authority at Piazza Venezia 11, 00187 Rome, Italy; Email: garante@gpdp.it; PEC: protocollo@pec.gpdp.it).
Requests can be made by contacting the Data Controller using the details provided.