Enter your keyword

Privacy Policy

This Privacy Policy is issued pursuant to art. 13 of the European Regulation No. 679/2016 and applies exclusively to all Data collected through the Website www.secret-times.it/en/. This Privacy Policy is subject to updates that will be posted on the Website on a timely basis. This Privacy Policy, together with the Terms and Conditions, any other documents referred to in it and the Cookie Policy, establish the basis on which the Data Subject’s Personal Data will be processed.

The Data Controller of the Data collected from this Website is Secret Times di Stefania Dorta with headquarters in Sassuolo (MO) – 41049 at via Radici in Piani, n. n. 526, P.IVA IT02751910353, email: info@secret-times.it

Personal Data means any information concerning an identified or identifiable individual (Data Subject). An identifiable person is any individual who can be identified, directly or indirectly, with particular reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more characteristic elements of his/her physical identity.

Among the Personal Data processed by this Website, either independently or through third parties, there are Common Data such as Cookie, Usage Data, name, email, Tax Data useful for the purchase and Personal Data useful for the delivery of the purchased Product.

The Personal Data provided or acquired will be subject to processing based on the principles of fairness, lawfulness, transparency and protection of confidentiality in accordance with current regulations. The Data Controller processes Users’ Personal Data by taking appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data. The Processing is carried out by means of computer and/or telematic tools, with organizational methods and logic strictly related to the indicated purposes.

Personal Data may be collected autonomously by the Data Controller or through third parties. In this case, the computer systems and software procedures in charge of the operation of the present Website acquire certain Personal Data of the Users, of a technical-informatics nature (e.g. IP address, type of browser used, operating system, domain name and addresses of websites from which access or exit was made, etc.), the transmission of which is inherent to the normal operation of the Internet. Such Data may be processed for the sole purpose of obtaining anonymous statistical information on the use of the site and/or to check its correct functioning and will be deleted immediately after processing.

The Data that the Data Subject chooses to voluntarily provide will be processed in compliance with the conditions of legality ex art. 6 GDPR and will be processed to allow the Website to provide its services, as well as for the Purposes indicated below and will be kept for the time necessary for the fulfillment of the aforementioned Purposes.

The Purposes of the processing are:

a) Information and pre-contractual fulfillment.

The Data will be processed in order to be contacted or to follow up on specific requests made to the Data Controller by the Data Subject for communications of an informative nature, for interest in purchase with respect to the Products of the same Data Controller and/or for requests for free advice aimed at receiving support in the choice of Product, through e-mail messages or filling out the Contact Form and other communication tools such as telephone or instant messaging WhatsApp Business.

Legal basis: this processing is optional and based on the consent of the Data Subject, however, the provision of Data is necessary for the pursuit of the indicated purpose.

Data Retention Period: 2 years, unless consent is revoked.

b) Processing necessary in the context of a contract.

The Data will be processed in order to fulfill the obligations arising from the contract entered into between the Data Subject and the Data Controller for the sale of the Products on the Website, to contact the Data Subject in relation to the Contract and for the management of the Contract, for the management of requests for legal guarantees, assistance, requests for withdrawal, management and termination of the Contract itself.

Legal basis: This processing is necessary for the performance of the Contract to which the Data Subject is a party, for the execution of pre-contractual measures or to fulfill a legal obligation to which the Data Controller is subject.

Period of data retention: 10 (ten) years or different legal obligation.

c) Fulfillment of any obligations under applicable laws.

The Data will be processed to fulfill any type of obligation contemplated and provided for by current laws, regulations, related rules, business customs and tax/fiscal matters, including also for the purposes provided for by the anti-money laundering legislation Legislative Decree 231/2007 and subsequent amendments.

Legal basis: This processing is necessary to fulfill a legal obligation to which the Data Controller is subject.

Period of data retention: 10 (ten) years or different legal obligation.

d) Softspam

The Data will be processed to allow the Data Controller to send by e-mail to the Data Subject commercial and promotional communications concerning Products and/or Services similar to the Products/Services being sold without the need for explicit and prior consent of the Data Subject, as provided for in Art. 130, paragraph 4, Privacy Code as amended by Legislative Decree no. 101 of 2018, and provided that the Data Subject does not exercise the right to object.

Legal basis: This processing is based on the legitimate interest of the Data Controller in accordance with Art. 6(F) and Recital No. 47 of the GDPR.

Data retention period: until the Data Subject objects.

e) Direct Marketing

The Data will be processed for direct sales of Products/Services, market research, sending of communications and promotional, commercial and advertising material or inherent to initiatives and events, through newsletters, e-mail, SMS, Whatsapp, Chat, Direct Messaging from social media, social networks or through phone calls, paper mail and other informative material.

Legal basis: This processing is based on the consent freely expressed by the Data Subject in accordance with Art. 6(1)(A) of the GDPR

Period of data retention: until the consent is revoked by the Data Subject.

f) Statistics

The Data will be processed to perform statistical analysis on aggregated and anonymous data to analyze the behavior of the Data Subject in order to improve the products and services provided by the Data Controller as well as to meet the Data Subject’s expectations.

Legal basis: This processing is based on the consent freely given by the Data Subject.

Data Retention Period: until the consent is revoked by the Data Subject.

g) Profiling

Data will be processed for the analysis and evaluation of interests, habits, and consumption choices, including the creation of profiles in order to be able to send personalized informative and promotional material about the Services/Products offered by the Data Controller.

Legal basis: This processing is based on the consent freely expressed by the Data Subject in accordance with Art 6(1)(A) of the GDPR.

Period of data retention: until the consent is revoked by the Data Subject.

h) Satisfaction of the Data Subject

The Data will be processed to send Customer Satisfaction surveys in order to improve the range of the Owner’s Products/Services and without marketing purposes.

Legal basis: This processing is based on the legitimate interest of the Data Controller in accordance with Art. 6(F) and Recital No. 47 of the GDPR.

Data retention period: until the Data Subject objects.

i) Waiting List

The Data will be processed to follow up on the specific request made by the Data Subject to the Data Controller to be placed on waiting lists relating to new Products and to receive communications of an informative nature relating to the Product of interest.

Legal basis: This processing is optional and based on the consent of the Data Subject, however, the provision of the Data is necessary for the pursuit of the indicated purpose.

Data Retention Period: until the revocation of consent by the Data Subject.

In addition to the Data Controller, in some cases, the Data may be accessed by:

a) categories of specially trained Data Processors involved in the organization of the Website (administrative, sales, marketing, legal, system administrators);

b) external parties (such as third-party technical service providers, hosting providers, IT companies, and communication agencies) also appointed as Data Processors by the Data Controller ex art. 28 GDPR. The updated list of Data Processors, if appointed, can always be requested from the Data Controller;

c)public or private entities that can access the Data in compliance with legal obligations;

d) subjects that perform accessory and instrumental tasks with respect to the activity of the Data Controller;

As expressly provided by Art. 5, co. 1, letter e) of the GDPR, the Data are kept for the time necessary for the Processing of the same in relation to the performance of the service requested by the Data Subject, or required by the purposes described above in this document.

At the end of the retention period, the Personal Data will be deleted and therefore, the rights of access, deletion, rectification and portability of the Data can no longer be exercised .

This Website uses cookies. Cookies are small text files that can be used by Websites to make the experience more efficient for the Data Subject and personalize content and ads, provide social network features, and analyze traffic. Cookie Policy

The Data is processed at the operational headquarters of the Data Controller. For further information, you may contact the Data Controller. The Data may be processed by individuals and/or legal entities operating on behalf of the Data Controller and under specific contractual obligations and based in EU or non-EU member countries. In the event that data is transferred outside the EEA, the Data Controller will take all appropriate contractual measures to ensure adequate protection of the Data.

The Data Subject has the right to exercise the faculties provided for in Articles 7, 15-22 of European Reg. 679/2016. In particular, he/she has the right to revoke his/her consent at any time and, upon simple request to the Data Controller, he/she may request access to the Personal Data, receive the Personal Data provided to the Data Controller and where possible transmit it to another Data Controller without hindrance (so-called portability), obtain the updating, limitation of the processing, rectification of the Data and the deletion of the Data processed in breach of the regulations in force. He/she has the right, for legitimate reasons, to object to the Processing of Personal Data concerning him/her and to the Processing for purposes of sending advertising material, direct sales and carrying out market research. He/she also has the right to lodge a complaint with the Privacy Guarantor as the supervisory authority for the protection of personal data or to take appropriate legal action. The interested party may exercise his or her rights by contacting the Data Controller by e-mail at: info@secret-times.it

CONTACT FORM

The Data Subject, by filling out the Contact Form with his/her Data, consents to their use to respond to requests for information, or any other purpose indicated by the header of the form. Personal Data collected through Contact Form: Email and Name.

Contact Form 7 (Rock Lobster LLC)

It is a form creation and management service that allows this website to integrate such content within its pages. Personal Data collected: Email and Name. Various types of Data as specified by the Privacy Policy of the service. Place of Processing: Japan– Privacy Policy(link needs to be activated https://contactform7.com/privacy-policy/)

OTHER CONTACT TOOLS

WhatsApp Business

WhatsApp Business is an instant messaging service provided by WhatsApp Ireland Limited. For the purposes of the processing methods, reference is also made to the WhatsApp Business Data Processing Terms which can be found at the following link: https://www.whatsapp.com/legal/business-data-processing-terms/. The Data Subject’s data will transit in WhatsApp Business services according to the terms that WhatsApp reports in the document “WhatsApp Business Terms of Service” at the following link: https://www.whatsapp.com/legal/business-terms/ . Personal Data Collected: phone number, email, Usage Data, Cookie. Place of Processing: Ireland- Privacy Policy (link needs to be activated https://www.whatsapp.com/legal?eea=0#privacy-policy)

EMAIL ADDRESS MANAGEMENT

These services allow you to manage a database of email contacts, telephone contacts, or contacts of any other type used to communicate with the Data Subject. These services may also allow for the collection of data related to the date and time of viewing of messages by the Data Subject, as well as the Data Subject’s interaction with them, such as information about clicks on links included in messages.

Newsletter

By registering for a newsletter, the Data Subject’s email address is automatically added to a list of contacts to whom email messages containing information, including information of a commercial and promotional nature, relating to this Website may be sent. The Data Subject’s email address may also be added to this list as a result of registering with this Website or after making a purchase. The Interested Party may choose at any time to unsubscribe from the newsletter by clicking on a specific button they will find within the emails. After clicking the unsubscribe button the Data Subject’s Data will be deleted immediately from the “email marketing” software. Personal Data collected: email and Name. This Website uses the newsletter service provided by:

MailerLite

MailerLite is a service offered by the UAB MailerLite company that organizes and analyzes newsletter distribution. In case a Data Subject does not want his/her Data to be handled by MailerLite, it will be necessary for him/her to unsubscribe from the newsletter. For this purpose, a link is provided in each newsletter sent. Personal Data collected: email and name. Place of Processing: Lithuania –Privacy Policy (link needs to be activated https://www.mailerlite.com/legal/privacy-policy)

REVIEW OF PRODUCTS SOLD

The Data Subject may provide a review regarding a purchase of a Product made on the Website.

COMMENTS ON CONTENT

Commenting services allow Users to make and publish their own comments regarding the content in the blog section. Users are responsible for the content of their comments. A comment service provided by third parties is not installed.

SPAM PROTECTION

These services analyze traffic on this Website, potentially containing the Personal Data of Users, in order to filter it from parts of traffic, messages and content recognized as SPAM.

WORDFENCE SECURITY (Defiant, Inc)

To prevent cyber-attacks and block suspicious users and IP addresses, this Website uses the Wordfence Security plugin, which installs a technical cookie (wfwaf-authcookie*) that helps determine whether the Data Subject has suspicious characteristics. The Owner does not collect, store or share any personal data via this cookie. The data collected by this plugin is retained for 24 hours.

https://www.wordfence.com/help/general-data-protection-regulation/

https://www.wordfence.com/privacy-policy/

SECURITY MEASURES TAKEN

This Website, to secure the moment when Personal Data is entered, has an SSL certificate and uses the HTTPS protocol. With the use of this protocol, the transactions and data that are transmitted on the Websites take place with maximum security and the content of the communication is not read or manipulated in any way by third parties.

reCAPTCHA

This Website uses reCAPTCHA which is a service subject to the policy on privacy (link needs to be activated https://policies.google.com/privacy?hl=it)

and the terms and conditions (link needs to be activated https://policies.google.com/terms?hl=it)

of Google’s usage policy.

WEBSITE REGISTRATION

With the registration service, the Interested Party allows the Website to identify him/her and give him/her access to dedicated services.

Simple Direct Registration

The Interested Party registers directly on the site by filling in the form and providing his/her Data.

STATISTICS

Statistical services allow the Data Controller exclusively to monitor and analyze traffic data and serve to track the behavior of the Data Subject. This Website uses the following services:

1. Google Analytics (Google Ireland Limited)

Google Analytics is an analytics service provided by Google Ireland Limited. Google uses the Personal Data collected for the purpose of tracking and examining the use of this Website, compiling reports and sharing them with other services developed by Google. Google may use Personal Data to contextualize and personalize ads in its advertising network. Google may also transfer this information to third parties where required to do so by law or where such third parties process this information on Google’s behalf. IP address anonymization is enabled on this site. The IP address transmitted by your browser for purposes related to Google Analytics will not be merged with other data already held by Google.

The following link https://tools.google.com/dlpage/gaoptout?hl=it is made available by Google the browser add-on for deactivating Google Analytics. Personal Data Collected: Cookies and Usage Data. Place of processing: Ireland – Privacy Policy (link needs to be activated https://policies.google.com/privacy?hl=it)

2. Facebook conversion tracking pixel (Meta Platforms, Inc.).

The Facebook conversion tracking (Facebook pixel) is a statistics service provided by Facebook. The Facebook pixel monitors conversions that can be attributed to Facebook ads. Personal data collected: Cookies; Usage data. Place of processing: Ireland- Privacy Policy. (link needs to be activated https://www.facebook.com/about/privacy/)

3. Pinterest conversion tracking pixel (Pinterest Europe Ltd.).

Pinterest’s conversion tracking (Pinterest pixel) is a statistics service that allows the Data Controller to track its customers’ conversions. Personal data collected: Cookies; Usage data. Place of processing: Ireland – Privacy Policy (link needs to be activated https://policy.pinterest.com/it/privacy-policy)

TAG MANAGEMENT

Google Tag manager (Google Ireland Limited)

Google Tag Manager is a service that allows you to manage and monitor all third-party Tags on the Website to get information about the interest shown by Users towards the Website itself and consequently the quality of the content. Personal Data Collected: Cookies and Usage Data. Place of processing: Ireland – Privacy Policy (link needs to be activated https://policies.google.com/privacy)

INTERACTION WITH SOCIAL NETWORKS

These services enable interactions with social networks directly from the pages of this Website. Interactions and information captured by this Website are in each case subject to the Data Subject’s privacy settings related to each social network. In the event that a social network interaction service is installed, it is possible that, even if Users do not use the service, it will collect traffic data related to the pages where it is installed.

1. Facebook (Meta Platforms, Inc.)

Facebook buttons are services for interaction with the social network Facebook, provided by Meta Platforms, Inc. Personal data collected: Cookies and Usage of data. Place of processing: Ireland –Privacy Policy (link needs to be activated https://www.facebook.com/privacy/explanation)

2. Instagram (Meta Platforms, Inc.)

Instagram buttons are services for interaction with the social network Instagram, provided by Meta Platforms, Inc. Personal Data Collected: Cookies and Usage Data. Place of processing: Ireland –Privacy Policy (link needs to be activated https://help.instagram.com/519522125107875)

3. Pinterest (Pinterest Europe Ltd)

Pinterest buttons are interaction services with the social network Pinterest, provided by Pinterest, Inc. Personal Data Collected: Cookies and Usage Data. Place of Processing: Ireland – Privacy Policy (link needs to be activated https://policy.pinterest.com/it/privacy-policy)

4. WhatsApp (WhatsApp Ireland Limited)

WhatsApp buttons are communication interaction services provided by Whatsapp Ireland Limited. Personal Data Collected: Cookies and Usage Data. Place of processing: Ireland- Privacy Policy (link needs to be activated https://www.whatsapp.com/privacy/?lang=it)

5. Youtube (Google Ireland Limited)

Youtube buttons are interaction services with the video content display service operated by Google. Personal Data Collected: Cookies and Usage Data. Place of Processing: Ireland – Privacy Policy (link needs to be activated https://policies.google.com/privacy?hl=it)

REMARKETING AND RETARGETING

These services allow this Website to communicate, optimize, and serve advertisements based on a Data Subject’s past use of this Website. This activity is carried out through tracking of Usage Data and the use of Cookies. This Web Site uses the following services:

1. Facebook Remarketing (Meta Platforms, Inc.)

Facebook Remarketing is a Remarketing and Behavioral Targeting service provided by Facebook, which links this Website’s activity with the Facebook advertising network. This Website makes use of the Facebook Pixel tool in order to measure conversions. Thanks to the Facebook Pixel you can understand the actions that people perform on the Website. The Data that is collected can be used to:

– ensure that advertisements are shown to the right people;

– create audience groups to target ads to;

– take advantage of the additional advertising tools of the platform on which you advertise.

The information collected is anonymous to the operators of this Site and cannot be used to identify an individual Data Subject. However, the information is saved and analyzed by Facebook, which could link the action back to an individual profile and use this information for internal Facebook advertising purposes, as outlined by Facebook’s privacy policy. This will allow Facebook to show advertisements on both Facebook and third-party sites. The Site Owner has no control over how this data is used. For more information on how users can protect their privacy, please refer to Facebook’s Privacy policy. (link needs to be activated https://www.facebook.com/about/privacy/)

2. Google ADS

Google ADS is a service provided by Google Ireland Limited that links this Web Site with Google’s advertising network. This Web Site makes use of the Remarketing functionality of Google Analytics combined with the cross-device adaptability of Google ADS. This functionality makes it possible to connect target groups for promotional campaigns created by the Marketing function of Google Analytics with the adaptability to different Google ADS devices. This makes it possible to show advertisements based on the Respondent’s personal interests, identified through an analysis of the Respondent’s web behavior, whether on a mobile device or other devices. You can permanently disable targeting and remarketing features by disabling the “personalized advertising” feature in your Google account. To do so, simply follow this link: https://www.google.com/settings/ads/onweb/ Personal Data Collected: Cookies and Usage Data. Place of processing: Ireland – Privacy Policy (link needs to be activated https://policies.google.com/privacy?hl=it)

3. Pinterest Ads (Pinterest Europe Ltd.)

Pinterest Ads is a Remarketing and Behavioral Targeting service provided by Pinterest Europe Ltd that links the activity of this Website with the Pinterest advertising network. This Website makes use of the Pixel Tracking tool in order to measure conversions and understand the actions people perform on the Website. For more information on how users can protect their privacy, please refer to Pinterest’s Privacy Policy. (link needs to be activated https://policy.pinterest.com/it/privacy-policy)

CONTENT ON EXTERNAL PLATFORMS

These services allow you to view content hosted on external platforms directly from the pages of this Website and interact with them.
Where such a service is installed, it is possible that, even if Users do not use the service, it may collect Traffic Data related to the pages where it is installed.

This Website uses:

1. Google Maps

Google Maps is a map display service operated by Google that allows this Website to integrate such content within its pages. Personal Data Collected: Cookies and Usage Data. Place of Processing: Ireland – Privacy Policy (link needs to be activated https://policies.google.com/privacy?hl=it)

2. Youtube (Google Ireland Limited)

Youtube is a video content display service operated by Google that enables this Website to integrate such content within its pages. Personal Data collected: Cookies and Usage Data. Place of Processing: Ireland – Privacy Policy (link needs to be activated https://policies.google.com/privacy?hl=it)

3. Calendly (Calendly LCC)

Calendly is an online automated appointment, call and meeting scheduling software operated by Calendly LCC. Personal Data Collected: Cookies and Usage Data. Place of processing: USA – Privacy Policy (link needs to be activated https://calendly.com/pages/privacy)

MANAGING PAYMENTS

Payment processing services enable this Website to process payments by credit card, wire transfer or other means. The Data used for the payment is acquired directly from the operator of the requested payment service without being processed in any way by this Website. Some of these services may also allow the scheduled sending of messages to the Data Subject, such as emails containing invoices or notifications regarding payment. This Website uses the following services:

1. PayPal (Paypal Europe S.à.r.l. et Cie, S.C.A Inc.)

PayPal is a payment service provided by PayPal Europe S.à.r.l. et Cie, S.C.A Inc. that allows the Data Subject to make online payments using their PayPal credentials. Personal Data collected: Cookies and various types of Data as specified by the privacy policy of the service. Place of processing: Luxembourg – Privacy Policy (link needs to be activated https://www.paypal.com/it/webapps/mpp/ua/privacy-full)

2. Sumup (Sumup Limited)

Sumup is a service that enables the Data Subject to make digital payments and transfer money via the Internet. This service is provided by the company Sumup Limited. Personal Data collected: Various types of Data as specified by the privacy policy of the service. Place of processing: Ireland – Privacy Policy (link needs to be activated https://sumup.it/tutela-privacy/?multipr=ossIT)

The Data Controller reserves the right to make changes to this Privacy Policy at any time by giving notice to Users on this page. Therefore, please consult this page often, referring to the date of last modification indicated at the bottom. If you do not accept the changes made to this Privacy Policy, you must discontinue using this Website and may request the Data Controller to remove your Personal Data. Unless otherwise specified, the previous Privacy Policy will continue to apply to the Personal Data collected up to that point. The Data Controller is not responsible for updating all links viewable in this Privacy Policy, so whenever a link is not working and/or updated, Users acknowledge and agree that they should always refer to the document and/or section of the websites referred to by that link.

Privacy Policy updated on May 2022