Privacy Policy

Privacy Policy

This Application collects some Personal Data of its Users.

Data Holder

PRISM Impresa Sociale s.r.l.
Via Falautano (Palazzo Grimaldi)
94100 – Enna
Italy

Holder’s email address: info@prismonline.eu

Types of Data Collected

Among the Personal Data collected by this Application, either independently or through third parties, are: Cookie, Usage Data, email, first and last name.

Full details on each type of data collected are provided in the dedicated sections of this privacy policy or by means of specific information texts displayed before data collection.
 Personal Data may be freely provided by the User or, in the case of User Data, automatically collected during the use of this Application.
 Unless otherwise specified, all Data requested by this Application are mandatory. If the User refuses to provide them, it may be impossible for this Application to provide the Service. In cases where this Application indicates certain Data as optional, User is free to refrain from communicating such Data, without any consequences on the availability of the Service or its operation.
 User who have any doubts regarding which Data are mandatory are encouraged to contact the Data Controller.

 Any use of Cookies or other tracking tools by this Website or by the owners of third-party services used by this Website, unless otherwise specified, is intended to provide the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Website and guarantees that they have the right to communicate or distribute them, releasing the Data Controller from any liability towards third parties

Method and location of data processing

Processing methods

The Data Controller uses appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of Personal Data.

The processing is carried out using computerised and/or electronic tools, with organisational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other subjects involved in the organisation of this Website (personnel in administration, sales, marketing, legal, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) may have access to the Data, they are also appointed, if necessary, as Data Processors by the Data Controller. The updated list of Data Processors can always be requested from the Data Controller.

Legal basis for processing

The Data Controller processes Personal Data relating to the User if one of the following conditions is met:

  • the User has given consent for one or more specific purposes (Art. 6(1)(a) GDPR). Note: in some jurisdictions the Data Controller may be authorised to process Personal Data without the User’s consent or another of the legal reasons specified below, until the User objects (opts out) to such processing. However, this does not apply if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
  • processing is necessary for the performance of a contract to which the User is party or in order to take steps prior to entering into a contract (Art.6(1)(b) GDPR);
  • processing is necessary for compliance with a legal requirement to which the Controller is subject (Art. 6(1)(c) GDPR);
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller (Art. 6(1)(e) GDPR);
  • the processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party (Art. 6(1)(f) GDPR).

However, it is always possible to ask the Data Controller to clarify the actual legal basis of each processing and in particular to specify whether there is a legal basis for the processing, provided for in a contract or necessary to conclude a contract.

Place

The Data are processed at the headquarters of the Data Controller and in any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.

Your Personal Data may be transferred to a country other than the country in which you are located. To obtain further information on the processing location, the User may refer to the section on details of the processing of Personal Data.

The User has the right to obtain information on the legal basis for the transfer of Data outside the European Union or to an international organisation under public international law or constituted by two or more countries, such as the UN, and on the security measures taken by the Data Controller to protect the Data.

The User may check whether one of the transfers described above takes place by examining the section of this document relating to the details of the processing of Personal Data or request information from the Data Controller by contacting them at the details given at the beginning.

Storage period

Data are processed and stored for the time required by the purposes for which they were collected.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Controller and the User will be retained until the performance of that contract is completed.
  • Personal Data collected for purposes related to the legitimate interest of the Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.

When processing is based on the User’s consent, the Controller may keep the Personal Data for a longer period until such consent is revoked. In addition, the Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period, the Personal Data will be deleted. Therefore, at the expiry of this period, the right of access, cancellation, rectification and the right to Data portability can no longer be exercised.

Purposes of Data Processing

The User Data are collected to enable the Controller to provide its Services, as well as for the following purposes: Statistics and Contacting the User.

To obtain further detailed information on the purposes of the processing and the Personal Data concretely relevant for each purpose, the User may refer to the relevant sections of this document.

Details of Personal Data Processing

Personal Data are collected for the following purposes and using the following services:

– Registration and authentication

By registering or authenticating the User allows the Application to identify him/her and give him/her access to dedicated services.
 Depending on what is indicated below, the registration and authentication services may be provided with the help of third parties. If this occurs, this Application may access certain Data stored by the third-party service used for registration or identification.

Direct Registration (this Application)

The User registers by filling in the registration form and providing his or her Personal Data directly to this Application.

Personal Data collected: Social Security Number, surname, date of birth, email, User ID, profile picture, address, country, name, phone number, password, profession, gender, website and various types of Data.

– Contacting the User

Mailing list or newsletter (this Application)

By registering for the mailing list or newsletter, the User’s email address is automatically added to a list of contacts to whom email messages containing information, including of a commercial and promotional nature, relating to this Application may be sent. The User’s email address may also be added to this list as a result of registering with this Application or after making a purchase.

Personal data collected: surname, email and first name.

Contact form (this Application)

The User, by filling in the contact form with his/her Data, consents to the use of such Data to respond to requests for information, quotations, or any other nature indicated in the header of the form.

Personal data collected: surname, email and first name.

– Statistics

The services contained in this section allow the Data Controller to monitor and analyse traffic data and serve to keep track of the User’s behaviour.

Google Analytics (Google Inc.)

Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google uses the Personal Data collected in order to track and examine the use of this Application, compile reports and share them with other services developed by Google.
 Google may use the Personal Data to contextualise and personalise the advertisements of its advertising network.

Personal data collected: Cookies and Usage Data.

Place of processing: United States – Privacy PolicyOpt Out. Privacy Shield Adherent.

Google Analytics with anonymised IP (Google Inc.)

Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google uses the Personal Data collected in order to track and examine the use of this Application, compile reports and share them with other services developed by Google.
 Google may use the Personal Data to contextualise and personalise the advertisements of its advertising network.
 This Google Analytics integration anonymises your IP address. The anonymisation works by shortening the IP address of Users within the borders of the member states of the European Union or in other countries which are party to the Agreement on the European Economic Area. Only in exceptional cases will the IP address be sent to Google’s servers and abbreviated within the USA.

Personal data collected: Cookies and Usage Data.

Place of processing: United States – Privacy PolicyOpt Out. Privacy Shield Adherent.

– Interaction with social networks and external platforms

This type of service allows interactions with social networks, or other external platforms, directly from the pages of this Application.
 The interactions and information acquired by this Application are in any case subject to the User’s privacy settings relating to each social network.
 If a social network interaction service is installed, it is possible that, even if Users do not use the service, it may collect traffic data relating to the pages where it is installed.

+1 button and social widgets of Google+ (Google Inc.)

The +1 button and Google+ social widgets are services for interaction with the Google+ social network, provided by Google Inc.

Personal data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Privacy Shield Adherent.

Linkedin social button and widgets (LinkedIn Corporation)

The LinkedIn social button and widgets are services for interaction with the Linkedin social network, provided by LinkedIn Corporation.

Personal data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Privacy Shield Adherent.

Facebook Like button and social widgets (Facebook, Inc.)

The Facebook ‘Like’ button and social widgets are interaction services with the social network Facebook, provided by Facebook, Inc.

Personal data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Privacy Shield Adherent.

Twitter Tweet button and social widgets (Twitter, Inc.)

The Tweet button and Twitter social widgets are services for interacting with the social network Twitter, provided by Twitter, Inc.

Personal data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Privacy Shield Adherent.

Pinterest ‘Pin it’ button and social widgets (Pinterest)

The Pinterest ‘Pin it’ button and social widgets are services for interacting with the Pinterest platform, provided by Pinterest Inc.

Personal data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy.

– Content commentary

The comment services allow Users to formulate and make public their own comments regarding the content of this Application.
 Depending on the settings decided by the Owner, Users may also leave their comments anonymously. If the Personal Data provided by the User includes email, this may be used to send notifications of comments regarding the same content. Users are responsible for the content of their comments. In the event that
a comment service provided by third parties is installed, it is possible that, even if Users do not use the comment service, it may collect traffic data relating to the pages where the comment service is installed.

Directly managed commenting system (this Application)

This application has its own content commenting system.

Personal data collected: surname, email and first name.

– Managing contacts and sending messages

This type of service allows the management of a database of email contacts, telephone contacts or contacts of any other type used to communicate with the User.
 These services may also collect data on the date and time the User views the messages, as well as the User’s interaction with them, such as information on clicks on links in the messages.

MailChimp (The Rocket Science Group, LLC.)

MailChimp is an address management and email messaging service provided by The Rocket Science Group, LLC.

Personal data collected: surname, email and first name.

Place of processing: United States – Privacy Policy. Privacy Shield Adherent.

– Interaction with data collection platforms and other third parties

This type of service allows Users to interact with data collection platforms or other services directly from the pages of this Application in order to save and reuse data.
 If one of these services is installed, it is possible that, even if Users do not use the service, it will collect Usage Data relating to the pages where it is installed.

MailChimp widget (The Rocket Science Group, LLC.)

The MailChimp widget allows you to interact with the MailChimp email address management and messaging service provided by The Rocket Science Group LLC.

Personal data collected: surname, email and first name.

Place of processing: United States – Privacy Policy. Privacy Shield adherent.

– RSS Feed Management

This type of service enables the management of RSS feeds and the distribution of their content. Depending on the characteristics of the service used, these services may also be used to place advertisements within the content and to collect statistical data on it.

FeedPress (Beta Et Compagnie Sarl)

FeedPress is an RSS feed management service provided by Beta Et Compagnie Sarl that enables statistical data to be collected on the consultation of content.

Personal data collected: Usage data.

Place of processing: France – Privacy Policy.

– Tag Management

This type of service is functional for the centralised management of the tags or scripts used on this Application.
 The use of these services involves the flow of the User’s Data through them and, where applicable, their retention.

Google Tag Manager (Google LLC)

Google Tag Manager is a tag management service provided by Google LLC.

Personal data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Privacy Shield Adherent.

– SPAM protection

This type of services analyses the traffic of this Application, potentially containing Users’ Personal Data, in order to filter it from traffic, messages and contents recognised as SPAM.

Akismet (Automattic Inc.)

Akismet is a SPAM protection service provided by Automattic Inc.

Personal Data collected: various types of Data as specified by the privacy policy of the service.

Place of processing: United States – Privacy Policy.

Google reCAPTCHA (Google Inc.)

Google reCAPTCHA is a SPAM protection service provided by Google Inc.
Use of the reCAPTCHA
system is subject to Google’s privacy policy and terms of use.

Personal data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Privacy Shield adherent.

– Displaying content from external platforms

This type of service makes it possible to display content hosted on external platforms directly from the pages of this Application and to interact with them.
If a service of this type is installed, it is possible that, even if Users do not use the service, it may collect traffic data relating to the pages where it is installed.

Google AdSense (Google Inc.)

Google AdSense is a service for displaying advertising banners provided by Google Inc.
which allows this Application to integrate such content into its pages.

Personal data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Privacy Shield adherent.

Google Fonts (Google Inc.)

Google Fonts is a font display service operated by Google Inc. that allows this Application to integrate such content into its pages.

Personal Data collected: Usage Data and various types of Data as specified by the privacy policy of the service.

Place of processing: United States – Privacy Policy. Privacy Shield Adherent.

Gravatar (Automattic Inc.)

Gravatar is an image display service operated by Automattic Inc. that allows this Application to integrate such content within its pages.
Please note that if Gravatar
images are used for commenting systems, the commenter’s email address (or parts thereof) may be sent to Gravatar, even if he or she is not subscribed to this service.

Personal data collected: Usage data and email.

Place of processing: United States – Privacy Policy.

Google Maps widget (Google Inc.)

Google Maps is a map display service operated by Google Inc. which allows this Application to integrate such content into its pages.

Personal data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Privacy Shield Adherent.

SoundCloud Widget (SoundCloud Limited)

Soundcloud is an audio content delivery service operated by SoundCloud Limited which allows this Application to integrate such content within its pages.

Personal data collected: Usage data.

Place of processing: Germany – Privacy Policy.

YouTube Video Widget (Google Inc.)

YouTube is a video content display service operated by Google Inc. which allows this Application to integrate such content into its pages.

Personal data collected: Cookies and Usage Data.

Place of processing: United States – Privacy Policy. Privacy Shield Adherent.

– Analysis of User Data and forecasts (‘profiling’)

The Owner may process the usage data collected through this Application to create or update user profiles. This type of processing allows the Owner to assess the User’s choices, preferences and behaviour for the purposes specified in the respective sections of this document.
 User profiles may also be created using automated tools, such as algorithms, which may also be offered by third parties. For further information on profiling activities, the User may refer to the respective sections of this document.
 The User has the right to object to such profiling activity at any time. To find out more about the User’s rights and how to exercise them, the User may refer to the section of this document on Users’ rights.

– Personal data collected through sources other than the User

The Owner of this Application may have legitimately collected Personal Data relating to the User without the User’s involvement, drawing on sources provided by third parties, in accordance with the legal bases described in the section on the legal bases for processing.
 If the Controller has collected Personal Data in such a way, the User can find specific information regarding the sources in the respective sections of this document or by contacting the Controller.

– Platform and hosting services

These services are intended to host and operate key components of this Application, making it possible to deliver this Application from a single platform. These platforms provide the Owner with a wide range of tools such as, for example, analytical tools, user registration management, comment and database management, e-commerce, payment processing etc. The use of these tools involves the collection and processing of Personal Data. Some of these services operate through servers located geographically in different places, making it difficult to determine the exact location where Personal Data is stored.

tophost.co.uk

tophost.co.uk is an accredited hosting provider and registrar. Which enables the Owner to develop, operate and host this Application.

Personal Data collected: various types of Data as specified by the privacy policy of the service.

Place of processing: Italy – Privacy Policy.

User Rights

Users may exercise certain rights with regard to the Data processed by the Data Controller.

In particular, the User has the right to:

  • withdraw consent at any time. The User may revoke his or her previously expressed consent to the processing of his or her Personal Data.
  • oppose the processing of their Data. You may object to the processing of your Data when it is done on a legal basis other than consent. Further details on the right to object can be found in the section below.
  • access to their Data. The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing and to receive a copy of the Data processed.
  • verify and request rectification. The User may verify the correctness of his/her Data and request that it be updated or corrected.
  • obtain restriction of processing. When certain conditions are met, the User may request the restriction of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its storage.
  • obtain the deletion or removal of their Personal Data. When certain conditions are met, the User may request the deletion of their Data by the Data Controller.
  • receive their Data or have them transferred to another data controller. The User has the right to receive his or her Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another controller. This provision is applicable when the Data are processed by automated means and the processing is based on the User’s consent, on a contract to which the User is a party or on contractual measures related thereto.
  • Propose a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.

Details on the right to object

Where Personal Data are processed in the public interest, in the exercise of public authority vested in the Controller or in pursuit of a legitimate interest of the Controller, Users have the right to object to the processing on grounds relating to their particular situation.

Users are informed that, should their Data be processed for direct marketing purposes, they may object to the processing without giving any reason. To find out whether the Controller processes Data for direct marketing purposes, Users may refer to the respective sections of this document.

How to exercise rights

In order to exercise their rights, Users may address a request to the Controller’s contact details indicated in this document. Requests are filed free of charge and processed by the Controller as quickly as possible, in any case within one month.

Further information on treatment

Defence in court

The User’s Personal Data may be used by the Data Controller in legal proceedings or in the preparatory stages to its possible establishment for the defence against abuses in the use of this Application or related Services by the User.
 The User declares that he/she is aware that the Data Controller may be obliged to disclose the Data by order of public authorities.

Specific information

Upon the User’s request, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

System logs and maintenance

For operation and maintenance purposes, this Application and any third-party services used by it may collect system logs, i.e. files that record interactions and which may also contain Personal Data, such as the User’s IP address.

Information not contained in this policy

Further information in connection with the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

Responding to ‘Do Not Track’ requests

This Application does not support “Do Not Track” requests.
 To find out whether any third-party services used support them, the User is invited to consult their respective privacy policies.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by informing Users on this page and, if possible, on this Application as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details held by the Data Controller . Please therefore consult this page regularly, referring to the date of last modification indicated at the bottom.

If the changes affect processing whose legal basis is consent, the Controller will collect the User’s consent again, if necessary.

Definitions and legal references

Personal Data (or Data)

Personal data is any information that, directly or indirectly, even in conjunction with any other information, including a personal identification number, makes a natural person identified or identifiable.

Usage Data

This is the information collected automatically through this Application (including by third party applications integrated in this Application), including: IP addresses or domain names of the computers used by the User who connects with this Application, URI (Uniform Resource Identifier) notation addresses, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various time connotations of the visit (e.g. the time spent on each page) and details of the itinerary followed by the User.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (e.g. the length of time spent on each page) and the details of the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the operating system and the User’s IT environment.

User

The individual using this Application who, unless otherwise specified, is the Data Subject.

Interested

The natural person to whom the Personal Data refer.

Processor (or Manager)

The natural person, legal entity, public administration and any other entity that processes personal data on behalf of the Controller, as set out in this privacy policy.

Data Controller (or Owner)

The natural or legal person, public authority, service or other body that, individually or jointly with others, determines the purposes and means of the processing of personal data and the instruments adopted, including the security measures relating to the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.

This Application

The hardware or software tool by which Users’ Personal Data are collected and processed.

Service

The Service provided by this Application as defined in the relevant terms (if any) on this site/application.

European Union (or EU)

Unless otherwise specified, any reference to the European Union in this document shall be deemed to extend to all current member states of the European Union and the European Economic Area.

Legal references

This privacy policy is drawn up on the basis of multiple legal regulations, including Articles 13 and 14 of Regulation (EU) 2016/679.

Unless otherwise specified, this privacy policy relates exclusively to this Application.

Contact information

Data Controller

PRISM Impresa Sociale s.r.l.
Via Falautano (Palazzo Grimaldi)
94100 – Enna
Italy

Controller’s email address: info@prismonline.eu

Cookie Policy

USE OF COOKIES ON THIS SITE

This website uses cookies to improve the use of the site and provide services and functionality to its users.

It is possible to restrict or disable the use of cookies via your web browser; however, without cookies some or all of the site’s functionality may be unusable.

Cookies are small text fragments stored on your browser by the website you visit. Websites use cookies to store information about your browsing behaviour, your preferences or to manage access to restricted areas. The operators of the websites and those who install them through the websites can only access the cookies they have stored on your browser.

Cookies differ in the following types:

TECHNICAL COOKIES

These cookies are essential to complete tasks requested by the user. For example, to store information provided by the user while browsing the site or to manage the ‘login’ status during the visit.

PROFILING COOKIES

These cookies store information related to the use of the site to provide personalised information for promotional purposes.

THIRD-PARTY COOKIES

Third-party cookies are those cookies sent to your computer from sites other than the one you are browsing. Third-party cookies result from the use of content displayed on the site you are visiting but originating from external servers. For example, third-party cookies may be sent when you view content on the site such as YouTube videos, Facebook or Twitter boxes, Google Maps or similar. These cookies may be used by third parties to record the use of the website for marketing purposes.