Privacy Policy
This notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR) and Article 13 of Legislative Decree no. 196/2003 (Personal Data Protection Code) and relates to all personal data processed according to the methods described below.
Data Controller
The Data Controller of the collected Personal Data is: Apollon Art Studio
Registered office: Via Giuseppe Giusti, 9, 50121 Florence – Tuscany – Italy
Controller’s email address: info@apollonartstudioflorence.com
Types of Data Collected
Full details on each type of data collected are provided in the dedicated sections of this privacy policy. Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using the website. Unless otherwise specified, all requested Data are mandatory. If the User refuses to provide them, it may be impossible to provide the Service. Where certain Data are optional, Users are free not to provide them without affecting the availability or functioning of the Service. Users who are unsure which Data are mandatory are encouraged to contact the Controller. Any use of Cookies or other tracking tools by this website or by third-party service providers, unless otherwise specified, is intended to provide the Service requested by the User. The User assumes responsibility for any third-party Personal Data obtained, published, or shared through the website and guarantees that they have the right to communicate or distribute it, releasing the Controller from any liability toward third parties.
METHODS AND PLACE OF PROCESSING OF COLLECTED DATA
Purpose of Data Processing
User data are collected to allow the Controller to provide its Services, as well as for the following purposes: Statistics, Newsletter, Personalized Advertising, Accounting, Performance testing of content and features, Interaction with social networks and external platforms, Displaying content from external platforms, and interaction with data collection platforms and other third parties. For further detailed information on the purposes of processing and the Personal Data relevant to each purpose, Users may refer to the relevant sections of this document.
Methods of Processing
The Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data. Data processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In addition to the Controller, in some cases, other parties involved in the organization of the website (administrative, commercial, marketing staff, legal advisors, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) may have access to the Data and may be appointed, if necessary, as Data Processors by the Controller. An updated list of Data Processors may always be requested from the Controller.
Legal Basis for Processing
The Controller processes Personal Data relating to the User if one of the following conditions applies:
– the User has given consent for one or more specific purposes;
– processing is necessary for the performance of a contract with the User and/or for pre-contractual measures;
– processing is necessary for compliance with a legal obligation to which the Controller is subject;
– processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
– processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party.
Users may always request clarification from the Controller regarding the specific legal basis of each processing activity.
Place of Processing
Data are processed at the Controller’s operating offices and in any other place where the parties involved in the processing are located. Personal Data may be transferred to a country other than the one in which the User is located. Users may request information regarding the legal basis for data transfers outside the European Union or to international organizations and regarding the security measures adopted by the Controller. If such transfers occur, Users may refer to the relevant sections of this document or contact the Controller.
Retention Period
Data are processed and stored for as long as required by the purposes for which they were collected.
Personal Data collected for contractual purposes will be retained until the contract has been fully performed.
Personal Data collected for legitimate interest purposes will be retained until such interest is satisfied.
When processing is based on consent, Personal Data may be retained until consent is withdrawn. The Controller may also be required to retain Personal Data for a longer period in compliance with legal obligations or by order of an authority. Once the retention period expires, Personal Data will be deleted. After that time, the rights of access, deletion, rectification, and data portability can no longer be exercised.
Details on the Processing of Personal Data
Mailing List or Newsletter
By registering for the mailing list or newsletter, the User’s email address is automatically added to a contact list to which email messages containing information, including commercial and promotional information, may be sent. Personal Data collected: email, first and last name.
Contact Form
By filling out the contact form with their Data, Users consent to their use to respond to requests for information, quotes, or any other type of request indicated in the form header. Personal Data collected: first and last name, email (mandatory), phone number, and other types of Data.
Registration for Access to Reserved Area
By completing the registration form, Users consent to the use of their Data to create a unique account for accessing various website functions (information requests, quotes, or e-commerce). Personal Data collected: first and last name, email (mandatory), phone number, and other types of Data.
Interaction with Social Networks and External Platforms
These services allow interaction with social networks or external platforms directly from the website. Interactions and information acquired are subject to the User’s privacy settings for each social network.
Facebook Social Widgets (Facebook Inc.)
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy.
YouTube Social Widgets (Google Inc.)
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy.
Remarketing and Behavioral Targeting
These services allow advertising based on past use of the website. This activity is performed by tracking Usage Data and using Cookies.
Google Analytics for Display Advertising (Google Inc.)
Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy.
Statistics
Google Analytics (Google Inc.) is a web analysis service provided by Google Inc. Google uses the collected Personal Data to track and examine website usage, compile reports, and share them with other Google services. Personal Data collected: Cookies and Usage Data.
Place of processing: USA – Privacy Policy – Opt Out.
User Rights
Pursuant to Articles 15–21 of Regulation (EU) 2016/679, Users have the following rights:
Right of Access: to obtain confirmation of whether Personal Data concerning them is being processed and access to such Data.
Right to Rectification: to obtain correction of inaccurate Data or completion of incomplete Data.
Right to Erasure: to obtain deletion of Personal Data without undue delay in the cases provided for by law.
Right to Restriction of Processing: in the cases provided by Article 18 GDPR.
Right to Data Portability: to receive Personal Data in a structured, commonly used, and machine-readable format and transmit them to another controller.
Right to Object: to object to the processing of Personal Data pursuant to Article 21 GDPR.
Users also have the right to lodge a complaint with the competent supervisory authority (Data Protection Authority).
Requests must be submitted in writing to the Data Controller. The Controller will respond within the time limits established by applicable law.