The Data Controller is CASA EDITRICE TABACCO s.r.l., with registered office in Tavagnacco (UD), via E. Fermi n. 78 (email: info@tabaccoeditrice.com - PEC: amministrazione@pec.tabaccoeditrice.com - phone: +39 0432 573822).
PRIVACY POLICY - PERSONAL DATA PROCESSING
DATA CONTROLLER
DATA CATEGORIES, PURPOSES AND LEGAL BASIS OF PROCESSING
The Controller processes your personal data for the following purposes:
A) REGISTRATION AND PARTICIPATION IN THE PLATFORM/COMMUNITY
Data processed: mandatory personal data (name and surname, addresses, nationality); mandatory contact data (email address); optional personalization data (date of birth, favorite sports, interests, personal website and other similar information that the User may choose to provide to personalize their Profile); system data (IP address, date and time of access, browser type and operating system used, device name and other technical information automatically collected during navigation and access to Services); activity logs (recording of operations performed by the User while using the Platform/Community).
Purpose: to allow registration and access to the Platform/Community, creation of a Profile/Account and participation in the Community life.
Legal basis: performance of a contract to which the data subject is party (art. 6, par. 1, lett. b, GDPR).
Retention period: for the entire duration of Community registration and for a subsequent period of 24 months from Account deactivation or until deletion request by the data subject.
Nature of provision: mandatory; failure to provide data will result in the inability to register to the Community and use related Services.
B) CONTENT SHARING
Data processed: photos, videos, GPX tracks, routes, geolocation data, reports, comments and other personal data possibly entered by the User in their Profile or in uploaded content.
Purpose: to share content with other Community Users and publish excursions, events, comments, reports, etc.
Legal basis: performance of a contract to which the data subject is party (art. 6, par. 1, lett. b, GDPR).
Retention period: personal data referable to the User will be retained for the entire duration of Community registration and for a subsequent period of 24 months from Account deactivation or until deletion request by the data subject. The Controller, by virtue of the license granted under art. 9.2 of the General Terms and Conditions, may anonymize content and retain it without time limits for the purposes provided in the contract.
Nature of provision: optional; failure to provide data does not affect Community registration but limits the ability to share content.
Processing of geolocation data: geographic position data is processed exclusively on the User's device to allow position display on maps and route recording. Such data is transmitted to the Controller and shared with other Users only if the User voluntarily decides to upload and share a route on the Community.
Dissemination: published content will be visible to other Community Users and may be indexed by search engines. As provided in the General Terms of Use (art. 9.2), the User grants Tabacco, free of charge, a non-exclusive, irrevocable, worldwide, perpetual, unlimited, assignable and sub-licensable right to use content published on the Platform.
C) SUBSCRIPTION SERVICES
Data processed: personal data (name and surname), contact data (email address), country of residence, data related to the chosen Subscription plan and payment data (managed directly by the banking institution).
Purpose: management of Subscriptions for access to Services offered through the "TABACCOMAPP" Application, including use of Tabacco cartography and Community access.
Legal basis: performance of a contract to which the data subject is party (art. 6, par. 1, lett. b, GDPR); compliance with legal obligations (art. 6, par. 1, lett. c, GDPR), arising from tax regulations (issuing and retention of electronic invoices, VAT declaration), civil law (retention of accounting records pursuant to arts. 2214 ff. c.c.) and further legal provisions applicable to contractual management and electronic payment processing.
Retention period: data will be retained for the entire duration of the Subscription and, subsequently, for a period of 10 (ten) years, in compliance with provisions regarding retention of accounting records (art. 2220 c.c.), tax obligations related to electronic invoices and VAT declarations (art. 433 c.p.p.), and to ensure enforceability of rights arising from the contractual relationship.
Nature of provision: mandatory; failure to provide data will result in the inability to activate Subscription Services.
D) AUTHENTICATION CREDENTIALS MANAGEMENT
Data processed: email address and Password.
Purpose: to allow access to the Platform/Community and prevent unauthorized access.
Legal basis: performance of a contract to which the data subject is party (art. 6, par. 1, lett. b, GDPR).
Retention period: until Account deletion.
Nature of provision: mandatory.
E) COMMERCIAL AND PROMOTIONAL COMMUNICATIONS FROM THE CONTROLLER
Data processed: personal data (name and surname) and contact data (email address).
Purpose: sending promotional and commercial communications related to the Controller's activities.
Legal basis: consent of the data subject (art. 6, par. 1, lett. a, GDPR).
Retention period: until consent withdrawal by the data subject.
Nature of provision: optional; failure to provide consent does not affect Community registration or use of Subscription Services.
F) COMMERCIAL OFFERS TO SUBSCRIBERS AND FORMER SUBSCRIBERS
Data processed: personal data (name and surname) and contact data (email address) of Users who have purchased a Subscription.
Purpose: sending commercial offers regarding products or services similar to those covered by the already purchased Subscription.
Legal basis: legitimate interest of the Controller (art. 6, par. 1, lett. f, GDPR) pursuant to art. 130, paragraph 4, Legislative Decree 196/2003, for Users who have completed at least one payment for Subscription Services.
Retention period: until the data subject exercises the right to object.
Nature of provision: automatic for subscribed Users; the data subject has the right to object free of charge and easily to sending such communications through opt-out functionality present in each communication or by contacting the Controller.
Opposition methods: each commercial communication sent will contain, in compliance with regulatory provisions, clear and simple methods to freely object to subsequent sending of commercial communications.
G) WEBSITE BROWSING AND APPLICATION USE
Data processed: IP addresses or domain names of computers used, source and exit web page, URI/URL addresses of requested resources, date and time of visit, information about the user's operating system and browser, as well as further technical data related to navigation.
Purpose: to ensure proper use of the Website and Application, process anonymous statistics on service use, monitor correct functioning of offered Services, as well as to ascertain liability in case of computer crimes against the Website, Application or Users.
Legal basis: legitimate interest of the Controller (art. 6, par. 1, lett. f, GDPR) in the proper management and technical administration of the Website and Application.
Retention period: not exceeding 90 days, except in cases where they must be retained to ascertain liability in case of computer crimes against the Website, Application or Users.
Nature of provision: automatic during navigation.
RECIPIENTS OF PERSONAL DATA
Your personal data may be communicated, based on needs, to the following categories of recipients:
- Subjects acting as persons authorized to process under the direct authority of the Controller;
- Subjects acting as data processors pursuant to art. 28 GDPR (IT service providers, companies providing hosting services, Website and Application management and maintenance), including, without limitation, InfoFactory s.r.l. and DataMind s.r.l.;
- Banking institutions and companies managing payments for Subscription management (including Banca Sella);
- Judicial or administrative authorities, for compliance with legal obligations;
- Other Community Users, limited to content published by the data subject.
Personal data will not be transferred to third countries or international organizations.
AUTOMATED DECISION-MAKING PROCESSES
The Controller does not carry out processing involving automated decision-making processes, including profiling.
DATA SUBJECT RIGHTS
As a data subject, you have the right to:
- Access personal data and obtain confirmation of the existence or not of personal data concerning you (art. 15 GDPR);
- Rectify inaccurate or incomplete personal data (art. 16 GDPR);
- Erase personal data in the cases provided (art. 17 GDPR);
- Restrict processing in the cases provided (art. 18 GDPR);
- Receive data in a structured, commonly used and machine-readable format (art. 20 GDPR - data portability);
- Object to the processing of personal data when based on the legitimate interest of the Controller (art. 21 GDPR);
- Withdraw consent at any time, without affecting the lawfulness of processing based on consent given before withdrawal;
- Lodge a complaint with the Data Protection Authority (www.garanteprivacy.it).
The above rights may be exercised by contacting the Controller at the contacts indicated in this privacy policy.
DATA SECURITY
In accordance with art. 32 GDPR, the Controller has implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in compliance with personal data protection regulations. Processing takes place through the use of procedures and tools, including IT systems, suitable to guarantee the confidentiality, integrity and availability of data.
CHANGES TO THE PRIVACY POLICY
This privacy policy may be subject to changes. Any variation will be communicated to the data subject through publication on the Website or Application and through other available communication channels. The Controller reserves the right to unilaterally modify, in whole or in part, this privacy policy, notifying the User, as provided by art. 17.3 of the General Terms of Use.
COOKIE INFORMATION
For detailed information on the use of cookies through this Website and Application, please consult the Cookie Policy available on the website www.tabaccomapp-community.it.
Last update date: April 07, 2025