Privacy & Cookie Policy

INFORMATION ON THE PROCESSING OF PERSONAL DATA

Pursuant to and for the purposes of Art. 13 of the New European Regulation 2016/679 relating to the protection of natural persons with regard to the processing of personal data (GENERAL DATA PROTECTION REGULATION – GDPR)
As required by the General Data Protection Regulation of the European Union (GDPR 2016/679, Article 13), before proceeding with processing, the interested party (user of the website www.drawingonthefridge.com) is informed that the personal data collected through the site are processed by the Company using IT and/or telematic tools, for the purposes indicated in this statement.

DATA CONTROLLER
To this end, the interested party is provided with the Privacy Policy prepared by SAM GG SRL (hereinafter also "DOF" or "the Company" or "the Data Controller"), creator and promoter of the activities available on the w ww website. drawingonthefridge.com . The Data Controller of personal data is SAM GG SRL, with registered office in Via Don Brusadelli, 41 – 22100 Como, VAT number: 03743480133.

TREATMENT INFORMATION
The personal data being processed are collected directly by SAM GG SRL or by third parties expressly authorized by it, or communicated by the Company to such third parties for the pursuit of the purposes described below.

LEGAL BASIS AND PURPOSE OF THE PROCESSING
The personal data provided by the user when browsing the w ww website. drawingonthefridge.com are processed by the Data Controller in accordance with current regulations regarding the protection of personal data. The legal basis of the processing is identified in the provision of its services by the Company, in the management and facilitation of the website, as well as in the establishment, execution and possible termination of the online sales contract concluded between the parties and in the obligations under the same contract connected and/or directly and/or indirectly deriving from the same.

The processing of personal data by DOF is aimed at pursuing the following purposes:

1 SUBSCRIPTION TO THE DRAWING ON THE FRIDGE.COM NEWSLETTER
In the event that the user decides to subscribe to the "DOF Newsletter", only following a possible and specific consent, the personal data will be processed by the Data Controller for the sending of commercial or promotional communications, related updates, for example, latest trends, new arrivals, exclusive offers, special events and promotions. To unsubscribe from the newsletter, simply click on the appropriate description link at the bottom of the emails received or by writing to the address customerservice@drawingonthefridge.com .

1.2 The provision of personal data and consent to their processing is optional. Failure to provide consent will make it impossible for DOF to allow registration to the "DOF Newsletter", the sending of commercial or promotional communications, updates relating, for example, to the latest trends, new arrivals, exclusive offers , special events and promotions.

1.3 The Data Controller, to compare and possibly improve the results of communications, uses systems for sending newsletters and promotional communications equipped with a reporting mechanism, thanks to which the Data Controller will be able to know, for example: the number of readers, openings and click; the type of device used to read the communication (desktop, mobile); the number of pending users who have not yet confirmed their registration; the number of emails sent by date/hour/minute; the details of emails delivered compared to those sent; the list of those unsubscribed from the newsletter; email openings and clicks on individual links; message display problems; link tracking (i.e. the number of clicks made on the links in the message); click tracking (which links were clicked). All this data is used for the purpose of comparing, and possibly improving, the results of communications.

2 REGISTRATION ON DRAWINGONTHEFRIDGE.COM
In the event that the user decides to register on the website www.drawingonthefridge.com, only following a possible and specific consent, the personal data will be processed by the Data Controller for the purposes of registration on w ww. drawingonthefridge.com . In particular, upon providing your name, surname, e-mail address and setting an access password, these will be processed for the creation of a personal account, to speed up the purchase procedure, to allow the user to view the status of orders and receive updates on purchases made, set and modify your data and any "Preferences" that will improve navigation, and update your account, view the history of returns and requests for exchange of goods, save the items favorites in the Wishlist and to offer the possibility to join at a later time.

2.1 The provision of personal data and consent to their processing is mandatory. Any failure to provide consent will make it impossible for DOF to allow registration on w ww. drawingonthefridge.com , the creation of a personal account, the speeding up of the purchase procedure, viewing the status of orders and receiving updates on purchases made, the possibility for the user to change personal settings and update the account, to view the history of returns and requests for exchange of goods, to save favorite items in the Wishlist.

3 ONLINE SHOPPING ACTIVITIES
The personal data provided will be used for the purposes of establishing, managing, executing and/or concluding the online sales contract. The data provided will be processed by the Data Controller for the purposes of managing the purchase order with reference, by way of example, to payment, shipping, taking charge of any returns, for customer assistance, for the execution of the purposes administrative - accounting related to the management of the order, for the fulfillment of obligations established by current legislation. In case of payment by credit card, the fundamental information for the execution of the transaction (credit card holder, credit/debit card number, expiry date, security code) will be processed by Stripe or, possibly, by companies in charge of anti-fraud control via an encrypted protocol and without third parties being able to have access to it in any way. However, this information will never be viewed or stored by the seller (SAM GG SRL).

3.1 the provision of personal data and consent to their processing is mandatory. Any failure to provide consent will make it impossible for DOF to proceed with the establishment, management, execution and/or conclusion of the online sales contract, therefore making it impossible to carry out, for example, activities related to payment , shipping, taking charge of any returns, customer support activities, carrying out administrative-accounting purposes linked to order management, and fulfilling obligations under current legislation.

4 PROFILING OF THE INDIVIDUAL PERSON
Only following a possible and explicit consent, the personal data provided may be processed by the Data Controller for profiling activities, or analysis of preferences aimed at creating personalized content and offers. The provision of personal data and consent to their processing is optional.

Any failure to provide consent will make it impossible for DOF to carry out profiling activities, or to carry out analysis of preferences aimed at creating personalized content and offers.

DATA PROCESSING AND STORAGE METHODS
The processing of personal data is carried out by the Data Controller in compliance with the provisions of current legislation on Privacy. The Data Controller processes personal data using IT and/or telematic tools and with organizational and logical methods strictly related to the pursuit of the purposes indicated in this information, as well as adopting appropriate security measures in order to prevent access, disclosure, the unauthorized modification or destruction of personal data, their loss and their illicit and incorrect use. However, the Company cannot guarantee its users that the measures adopted for the security of the site and the transmission of data and information on the site are capable of limiting or excluding any risk of unauthorized access or dispersion of data by devices. pertaining to the user. For this reason, users of the site are advised to ensure that their computer is equipped with adequate software to protect network data transmission (for example updated antivirus) and that their Internet Provider has adopted suitable measures for the security of transmission. of data on the network. The Company also undertakes to process the data according to the principles of correctness, lawfulness and transparency, to collect them to the extent necessary and exact for the processing and to allow their use only by personnel for authorized purposes. The management and storage of the personal data acquired will take place in archives or on servers located within the European Union owned by the Data Controller and/or third-party companies appointed as External Data Processors and, in any case, currently located in Italy.

In relation to the different purposes for which they are collected, personal data will be kept for the time strictly necessary to achieve them and, in any case, in compliance with the relevant regulatory provisions in force.

In any case, the Company will take care to avoid the use of the data for an indefinite period by proceeding, on a periodic basis, to appropriately verify the actual continuation of the interest of the subject to whom they refer.

RECIPIENTS AND RESPONSIBLE FOR TREATMENT
The data collected will not be disclosed in any way, but will be processed within the limits and for the purposes described by the Company's employees on the basis of adequate operating instructions (for example, administrative, commercial, marketing, legal personnel, system administrators, etc. .). Some data processing may also be carried out by third parties, appointed as External Data Processors, of whom the Data Controller makes use or could make use as part of the management of the contractual relationship, the provision of the services offered and for the organizational needs of its business. In particular, the data may be communicated to:

  • subjects, public and private, who can access the data pursuant to legal provisions, regulations or community legislation, within the limits established by these rules;
  • subjects who need to access the data for purposes related to the contractual relationship existing between the parties, within the limits strictly necessary for carrying out auxiliary tasks (such as, for example, banks and credit institutions, technical service providers, hosting providers, IT companies , communication agencies, postal couriers and shipping companies);
  • consultants, within the limits necessary to carry out their professional duties.

TRANSFER OF DATA ABROAD
The management and storage of personal data will take place on the servers of the Data Controller and/or third-party companies duly appointed as External Data Processors located within the European Union.

Personal data may be transferred abroad, in compliance with the provisions of current legislation, even to countries not belonging to the European Union. The transfer to non-EU countries, in addition to the cases in which this is guaranteed by the Commission's Adequacy Decisions, is carried out in such a way as to provide appropriate and appropriate guarantees pursuant to the articles. 46 or 47 or 49 of the Regulation.

RIGHTS OF INTERESTED PARTIES
As an interested party, the user may exercise, at any time, the rights provided for in articles 15, 16, 17, 18, 20 and 21 of the GDPR which confer, in particular, the right to:

  • obtain from the Data Controller, pursuant to Article 15, confirmation as to whether or not personal data is being processed and, in this case, obtain access to the data themselves and to information such as: (i) the purposes of the treatment; (ii) the categories of personal data; (iii) the recipients or categories of recipients to whom the personal data have been or will be communicated, in particular if they are recipients located in Third Countries or International Organizations; (iv) when possible, the expected retention period of personal data or, if this is not possible, the criteria used to determine this period;
  • obtain from the Data Controller, pursuant to Article 16, the rectification of inaccurate personal data concerning him without unjustified delay; taking into account the purposes of the processing, the interested party has the right to obtain the integration of incomplete personal data, also by providing a supplementary declaration;
  • obtain from the Data Controller, pursuant to Article 17, the deletion of personal data concerning him without unjustified delay. The Data Controller has the obligation to delete, without unjustified delay, the personal data if one of the reasons indicated in paragraph 1 of Article 17 exists;
  • obtain from the Data Controller, pursuant to Art. 18, the limitation of processing when one of the hypotheses regulated by paragraph 1 of Article 18 occurs;
  • obtain from the Data Controller, pursuant to Article 20, data portability, i.e. receive in a structured format, commonly used and readable by an automatic device, the personal data concerning him/her provided to a Data Controller. The interested party also has the right to transmit such data to another data controller without impediments on the part of the first data controller to whom it was provided, if the conditions indicated in Article 20 paragraph 1 apply. Finally, the interested party has the right to obtain the direct transmission of personal data from one Data Controller to another, if technically feasible;
  • object, in whole or in part, pursuant to Article 21, to the processing of personal data concerning him.

Furthermore, it should be noted that the interested party has the right to withdraw consent at any time without prejudice to the lawfulness of the processing based on the consent given before the revocation, without prejudice to the consequences indicated above regarding a possible refusal to provide such personal data. . The interested party also has the right to lodge a complaint with a Supervisory Authority. In the event of a request for rectification, cancellation or limitation of processing, the Data Controller undertakes to communicate the results of the requests received from the interested party to each of the recipients of his data, unless this proves impossible or involves a disproportionate effort. The Company specifies that the interested party may be asked for a possible contribution if the questions are manifestly unfounded, excessive or repetitive; in this regard, the Data Controller will equip itself with a register to track requests for intervention.

AMENDMENT TO THIS POLICY
The data controller reserves the right to make changes to this Privacy Policy at any time by publicizing them to users on the w ww website. drawingonthefridge.com . Please therefore consult this page often, taking as reference the date of last modification indicated at the end of the document. In case of non-acceptance of the changes made to this Privacy Policy, the interested party may request the Data Controller to delete their personal data. Unless otherwise specified, the previous Privacy Policy will continue to apply to personal data collected up to that point.

Privacy information updated on 03/23/2021

COOKIE POLICY

INFORMATION ON THE PROCESSING AND PROTECTION OF PERSONAL DATA
The following information is intended to provide an overview of the processing of your personal data by the ancote.com website and your rights pursuant to the General Data Protection Regulation (EU) 2016/679 (hereinafter also GDPR ).

DATA CONTROLLER AND DATA PROTECTION OFFICER
The Data Controller of personal data is SAM GG SRL, with registered office in Via Don Brusadelli, 41 – 22100 Como, VAT number: 03743480133.

PURPOSE AND LEGAL BASIS OF THE PROCESSING
The drawingonthefridge.com website processes your personal data for the following purposes:

Necessity to fulfill legal obligations (e.g. obligations established by tax legislation - transport documents, invoicing, etc.). This necessity represents the legal basis that legitimizes the related treatments. The provision of the data necessary for these purposes represents a legal obligation; if the Site does not have the aforementioned personal data, it would be impossible to comply with the provisions of the law.

CATEGORIES OF DATA PROCESSED
The ancote.com website processes personal data collected directly from you, which includes, but is not limited to, personal data (e.g. name, surname, address, date and place of birth, tax code, email address, etc.)

RECIPIENTS OR CATEGORIES OF RECIPIENTS OF PERSONAL DATA
They may become aware of your personal data as The data controllers are the natural and legal persons within the Data Controller's organization, in their capacity as persons authorized to process personal data , in relation to the data necessary to carry out the tasks assigned to them. Furthermore, your data may be processed by those subjects to whom they must be communicated in fulfillment of an obligation established by law, by a regulation or by community legislation.

TREATMENT METHODS
The processing of personal data takes place using manual, IT and telematic tools with logic strictly connected to the purposes themselves and, in any case, in such a way as to guarantee the security and confidentiality of the data themselves.

RIGHTS OF INTERESTED PARTIES
The GDPR gives you specific rights, including that of knowing what personal data is in possession of the ancote.com website and how it is used (Right of access), to obtain its updating, rectification or, if there is interest, integration, as well as cancellation, transformation into anonymous form or limitation of processing.

DATA RETENTION PERIOD AND RIGHT TO CANCELLATION (RIGHT TO BE FORGOTTEN)
The ancote.com website processes and stores your personal data for the entire duration of the relationship with the same, for the execution of the obligations inherent and consequent thereto, for compliance with the applicable legal and regulatory obligations.

Once the aforementioned relationship has ceased, the ancote.com website will process and store your personal data - also for compliance with legal and regulatory obligations, as well as for its own defensive purposes until the expiry of the legally applicable retention period; subsequently the data will be deleted or stored in a form that does not allow your identification (e.g. irreversible anonymisation), unless their further processing is necessary for one or more of the following purposes:

  • resolution of pre-disputes and/or disputes started before the expiry of the retention period;
  • to follow up on investigations/inspections by internal control functions and/or external authorities initiated before the expiry of the retention period;
  • to respond to requests from the Italian public authorities received/notified to the ancote.com website before the retention period expires.

RIGHT TO PORTABILITY
We would like to point out to you that until the expiry of the applicable retention period - you can request to receive or request to transfer your personal data to third parties in a structured, commonly used and readable format for further personal use or to provide them to another data controller (Law to portability). In particular, the data that can be subject to portability are personal data (e.g. name, surname, title, date of birth, sex, place of birth, residence, tax code, etc.).

METHOD OF EXERCISE OF RIGHTS
We inform you that to exercise the above-mentioned rights you can write electronically to privacy@drawingonthefridge.com or for some it is possible to exercise them by accessing the control panel to proceed independently. The exercise of rights is free; The drawingonthefridge.com website has the right to request information necessary for identifying the applicant.

SECURITY OF PERSONAL DATA
Data security is guaranteed in several aspects:

  • Physical access to the servers is not permitted, without prior authorization and only for technical reasons, to IT professionals with proven expertise: e.g. repair of hardware faults
  • IT: double firewall and antivirus.
  • Operating system active only for the necessary components.
  • Double Backup
  • Access to the console is permitted only to a very small group of authorized and specialized users

COMPLAINT OR REPORT TO THE GUARANTOR FOR THE PROTECTION OF PERSONAL DATA
We point out that you have the right to lodge a complaint or make a report to the Guarantor for the Protection of Personal Data or alternatively lodge an appeal with the Judicial Authority. The contacts of Guarantor for the Protection of Personal Data can be consulted on the site web

INFORMATION ON THE USE OF COOKIES
Drawingonthefridge.com uses cookies to guarantee the correct functioning of the procedures and improve the user experience.
This document provides detailed information on the use of cookies by drawingonthefridge.com.

TYPES OF COOKIES

1 Strictly necessary session cookies.
These are essential cookies for the correct functioning of www.drawingonthefridge.com and are used to manage login and access to reserved functions of the site. The duration of cookies is strictly limited to the work session (they are deleted once the browser is closed). Deactivating these cookies completely compromises the use of the site.

2 Technical cookies.
These are essential cookies for the correct functioning of www.ancote.com and aimed at improving usability by the user. The deactivation of these cookies can be done at the risk of compromising the correct functionality of drawingonthefridge.com uses these cookies to: language, sector, price list, country, shipping, cart, recent.
Unlimited duration.

3 Analysis and performance cookies.
They are normally third-party cookies used to collect and analyze traffic and use of the site anonymously. These cookies, without identifying the user, allow us to monitor the system and improve its performance and usability. Deactivating these cookies can be done without any loss of functionality. Unlimited duration. Below are the web addresses of third parties for the management of ANALYTICS cookies: https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage

4 Social cookies.
These are parts of the visited page generated directly by the aforementioned sites and integrated into the page of the host site. The most common use of social plugins is aimed at sharing content on social networks. The presence of these plugins involves the transmission of cookies to and from all sites managed by third parties. The management of information collected by "third parties" is governed by the relevant information to which please refer. Below are the web addresses of the various information and methods for managing cookies.

Facebook information: https://www.facebook.com/help/cookies/
Facebook (configuration): log in to your account. Privacy section.
Google+ information: http://www.google.it/intl/it/policies/technologies/cookies/
Google+ (configuration): http://www.google.it/intl/it/policies/technologies/managing/

COOKIE MANAGEMENT
The user can decide whether or not to accept cookies using their browser settings.
How to disable cookies through your browser
The drawingonthefridge.com website works optimally if cookies are enabled.
You can however decide not to allow cookies to be set on your computer; to do so, access the "Preferences" of your browser. For information on how to change cookie settings, select the browser you are using below: Chrome - Firefox - Internet Explorer - Opera - Safari
Warning: total or partial disabling of technical cookies may compromise the use of the site's features.

Disabling "third party" cookies does not affect navigability in any way.
Profiling cookies. These are permanent cookies used to identify (anonymously) user preferences and improve their browsing experience. Deactivating these cookies can be done without any loss of functionality. Unlimited duration. Since they are third-party cookies, we refer you to the respective information pages:
ADWORDS - https://support.google.com/adwords/answer/2407785?hl=it

-----------------------

This site uses profiling cookies, its own and those of other sites, to send you advertising in line with your preferences. If you want to know more or deny consent to all or some cookies, click here. If you access any element below this banner, you consent to the use of cookies.