Privacy Policy

Privacy Policy

PROCEDURE ON THE PRIVACY POLICY OF THE COMPANY WEBSITE AND POLICY ON COOKIES

1.RISKS
The lack of privacy policy pursuant to Articles 13-14 of the EU Privacy Regulation 679/2016 (GDPR) for subjects who navigate any website of our Company interacting with the services provided therein exposes our Company to the potential risk of penalties and/or lawsuits filed by data subjects due to violation of the rights to which they are entitled.

2. PURPOSE
This document illustrates the general policy of our Company as operator of the website with regard to the processing of personal data carried out on or through the website and in particular with regard to the privacy policy.

3. SCOPE
This procedure applies to all those who are engaged in the creation, development and/or maintenance of any Company website, as well as to those who must ensure compliance with privacy of the website. This includes, for example, authorized marketing personnel, internal IT managers, and external webmasters.

4. REGULATION OF ACTIVITIES
The following text should be added to the company website:

PRIVACY POLICY AND POLICY ON COOKIES

1. Purposes and principles of data processing In compliance with the legal obligations on the subject, on this page WILIER TRIESTINA S.P.A. (hereinafter “WILIER”) describes how it manages the website with reference to the processing of personal data of users who browse and interact with web services accessible electronically from the address www.wilier.com and with the electronic pages of the website.

Consultation of the website may involve the processing of data relating to identified or identifiable natural persons. These data can be divided into three general categories: i) browsing data, ii) data provided voluntarily by the user, iii) data relating to the password for access to the B2B section of the website.

Index of the topics (you can browse them by placing the mouse on the list and clicking on the text) 

- Data types
- Purposes of processing
- Logics and forms of organisation of processing.
- Mandatory or optional nature of giving personal data and consequences of failure to provide data
- Are there cases of simplified consent or exemptions from the consent requirement for direct marketing purposes?
- Does the data subject's consent to processing for profiling and direct marketing purposes also apply to the communication of data to third parties?
- Withdrawal of consent
- Communication of data to third parties
- Duration of processing
- Legal basis for processing
- Cookie policy
- Data controller 
- Rights of the data subject
- Changing the policy

 

Data types
The data we process can be of three general types: navigation data, data actively provided by the data subject and data collected from third parties.

i) Browsing data
The IT systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the Internet communication protocols.  
This information is not collected to be associated with identified data subjects, but by their very nature could, through processing and association with data held by third parties, allow users to be identified. This data category includes IP addresses or domain names of computers used by users who connect to the website, URI (Uniform Resource Identifier) of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical code indicating the status of the response from the server (successful, error, etc.), the country of origin, and other parameters regarding the operating system and computer environment of the user (e.g., the characteristics of the browser and operating system used by the visitor, the type of device used to access the Internet, the various temporal details of the visit (e.g. the time spent on each page, and details of the itinerary followed within the pages of the Site, with particular reference to the sequence of consulted pages. This category also includes the so-called system logs, i.e., files that record the interactions between the user and the website. 
This is information that is not collected to be directly associated with identified data subjects, but that by their very nature could, in theory, through processing and association with data held by third parties (in particular, third-party providers of Internet connectivity services), allow users to be identified.
However, this data is used by us only to obtain statistical information in aggregate and anonymous form on the use of the website, to better understand the user's browsing behaviour in order to provide the user with a better browsing experience, to allow the technical functions of the website, to control and optimise its operation, to improve the quality of services offered by the website and ensure the maintenance of its database and supporting IT infrastructure. 
These browsing will be deleted anonymously after the above processing within 12 months from the date of collection.
The browsing data can also be used to ascertain responsibility in the event of crimes against the website or carried out through the website (malware attacks, spamming, unauthorized access to computer systems, etc.) and in this case retention continues for as long as necessary to protect the rights of WILIER and/or third parties.

ii) Data actively provided by users
These are:
- the information sent by users voluntarily and optionally to the addresses indicated on the website by filling in online registration and/or data collection forms or on company blogs (e.g., name or company name, WILIER and surname, e-mail address, address of the registered office, residence or domicile (postal code, city, province), landline or mobile telephone number, country, language of contact, etc.);
- personal data provided by users to use services accessible on the website or to participate in initiatives promoted through the website (e.g., data relating to purchases made by the data subject, such as type of product, date and price of purchase, product model and serial number, retailer from which the purchase was made);
- personal data provided by users who request clarifications, sending news, information or newsletter;
- in the sole case relating to the B2B support service provided by WILIER to resellers/distributors, the personal data referring to the reseller/distributor (WILIER, email, date of purchase by the end customer, name of the local agent, name of the reseller where the product was purchased if different from the reseller/distributor requesting B2B support, etc.), as well as ii) the name of the end customer of the reseller/distributor (associated with our B2B support ticket, in order to be able to associate him/her with any separate complaint received by the same end customer through separate communication channels (such as, in particular, the "contact us" form or info@wilier.it or by telephone received by the customer care service).

Through the web forms available on the websites we never ask you for "particular" personal data (i.e., personal data revealing racial or ethnic origin, religious, philosophical or other beliefs, political opinions, membership of parties, trade unions, associations or organisations of a religious, philosophical, political or trade union nature, as well as personal data disclosing health and sexual orientation) or "judicial" information (data concerning criminal records, or concerning the status of defendant or suspect, etc.). 

When you use certain services on the website, we may process Personal Data of third parties that you send our Company. With respect to these cases, you are the independent data controller, assuming all the obligations and responsibilities under law. In this regard, you grant on this point the broadest indemnity with respect to any dispute, claim, request for compensation for damage caused by processing, etc. that may be received by our Company from third parties whose Personal Data have been processed through its use of the functions of the website in violation of the applicable regulations on Personal Data protection.
In any case, if you provide or otherwise process Personal Data of third parties in the use of the website, you warrant as of now - assuming all related liability - that this particular case of processing is based on a proper legal basis pursuant to article 6 of the Regulation that legitimises the processing of the data.

iii) Data relating to the password for access to the B2B section of the website.
WILIER creates and sends a first password for access to the reserved area of this website, dedicated to the reseller/distributor, via email to the B2B customer. The password must be changed by the B2B customer at the first login. B2B customers must keep their passwords confidential and can ask WILIER to reset them at any time.  

Specific further purposes relating to individual processing can be identified in detail, through additional information, within the various services included in the portal.

iv) Data collected from third parties
Our Company does not collect personal data of the data subject from third parties.
 

Purposes of processing. 
The processing of personal data is aimed at:
a) processing the requests of users for support and contact, e.g., sending informative material or clarifications (bulletins, newsletters, answers to questions, notices, specifications, price lists, other documentation, etc.), 
b) allowing users to register on the website and access services and/or purchase products/services, 
c) performing the service or providing the product requested by the user and organising all management and production activities instrumental to the above supply (including relations with suppliers, and management of payments by credit card, bank transfer or other means) 
d) complying with the obligations provided for by law, regulations and/or EU legislation; and/or
e) carrying out all legal obligations connected with or deriving from the contractual relationship, including if terminated with the data subject and/or the organisation to which he/she belongs (collectively, the "primary objectives").

 

Only with the prior specific consent of the user (obtained through special online and/or paper forms) will the data collected also be used for direct marketing activities (market surveys, sending of commercial and promotional communications, newsletters, through any automated means of communication, email, telephone with operator, text message, chat messages, social networks, etc., or non-automated means, e.g., ordinary mail) and profiling (so-called "secondary purposes"). Such consent is always optional (see below). 

The logic and forms of organisation of processing will be closely related to the individual purposes respectively indicated above. Processing will take place by electronic, telematic and/or paper media. During processing data are subject to protective measures taken by WILIER in order to protect the data against the risk of unauthorised access or processing, for example, are only accessible by having access to various software applications, by entering mandatory personal passwords, only by personnel authorised by WILIER, who must still comply with givens limits of use.

Subjects that process the data. 
The collected data are processed by WILIER's internal delegates who need to have knowledge of them when carrying out their activities (e.g., sales office, marketing office, administrative office, call centre, technical staff for the maintenance of the company IT system, etc.).
WILIER has also appointed some third parties to whom the Company communicates data as data controllers.

Mandatory or optional nature of giving personal data and consequences of failure to provide data
WILIER has a legitimate interest in the processing for these primary purposes. Therefore, such processing will be possible even without the consent of the data subject. The provision of data to WILIER is mandatory if they are necessary for the fulfilment of legal obligations and failure to provide in this case will make it impossible to enter into the contract with you and/or the organisation to which you belong. In the other cases mentioned above, you are free not to provide us with the data, but in this case this will make it impossible to proceed with pre-contractual relations, with the online registration of the person concerned to the website and/or with the provision of services or with the sale of products for which WILIER requests registration and/or provision of data. 
Non-registered users may browse the website and view only the content and materials available without registration.
In relation to the secondary purposes of processing (direct marketing, profiling, as provided for in point 5 above) as well as for the communication of data by WILIER to third parties for these purposes:
- your consent is always optional (free and deniable); the consent must be given or denied by you, separately for i) the processing carried out solely by WILIER and, respectively, for ii) the communication of data by WILIER to third parties for the same purposes;
- failure to provide or consent to the processing of data in this case will prevent WILIER from processing and/or communicating to third parties the data for these secondary purposes, and will not in any way interfere with the pre-contractual or contractual relationship between WILIER and the person or organization to which it belongs.

Are there cases of simplified consent or exemptions from the consent requirement for direct marketing purposes?
As allowed by current legislation and in order to fulfil the privacy obligations of WILIER in accordance with the principles of simplification (referred to in the General Provision of the Privacy Authority of 15 May 2013 - "Consent to the processing of personal data for purposes of "direct marketing" through traditional and automated contact tools"), the consent requested by WILIER regarding the secondary purposes of profiling and direct marketing is unitary and comprehensive for all possible means used for the processing for marketing purposes (electronic/telematic, paper), as well as for all possible purposes of direct marketing (without, that is, multiplying the wordings of consent for each distinct marketing purpose pursued).

NB: WILIER may process personal data, through the use of telephone calls with an operator and the use of ordinary mail, for the aforesaid secondary purposes, without the prior specific consent of the data subject (in this case, the right of the data subject to object to the processing of the data with simplified methods and also electronically through the registration of the telephone number of which the data subject is the holder and other personal data relating to subscribers in printed and electronic directories available to the public, in the Public Register of Oppositions at http://www.registrodelleopposizioni.it/ provided for by Decree No. 178/2010 of the President of the Italian Republic, shall not be affected).
In the event that WILIER requests - for direct marketing purposes - your telephone number and you have given your optional and specific consent to its use, WILIER may process it even if the user is registered with the Public Register of Opposition: because the number in that case is provided by you and not taken from public directories.

Please also note that the Privacy Code allows for so-called "soft spam".. This means that without having to acquire your express consent, we may use the email address that you provided in a previous purchase, in order to proceed, by sending by email, commercial communications and offers for sale, as long as they relate to prodotti e servizi analoghi a quelli da te già acquistati
Upon receipt of any communication and/or promotional email made by WILIER for the purposes already provided, you are informed of the possibility of opposing at any time to processing, easily and free of charge (notifying your choice of opt-out through our online platform).

Does the data subject's consent to processing fordirect marketing and profiling purposes also apply to the communication of data to third parties?
WILIER communicates some data to other companies belonging to the WILIER Group or to third parties that by contract are delegated by us to process the data (e.g., transmit commercial communications) solely on behalf of WILIER based on the same specific marketing consent including that to communicate to third parties for these purposes.
Only with your further, separate, additional, documented, express optional*, WILIER also communicates or transfers the data to third parties who process them as joint data controllers or independent data controllers (they are usually third partners in the promotion of events), who use them for purposes of direct marketing or profiling).

Withdrawal of consent
Even after you have given your consent to the processing of your data for profiling and direct marketing purposes, as a data subject you may at any time notify WILIER of a different intention by one of the following alternative methods:
- by clicking on the "unsubscribe" button, made available to the user at the bottom of promotional emails sent to the data subject, an email will automatically be sent to WILIER and consequently the name of the data subject registered, in a special blacklist, preventing further future direct marketing actions by WILIER to him/her; 
- by transmitting to WILIER by ordinary mail or e-mail your statement of revocation of consent (which in this case will be manually registered in the Company's CRM). This method of communication is always necessary in the event that the data subject wishes to express a more analytical selective will, either with regard to the use of certain individual means and not others (e.g., only paper, only electronic, refusing means sent by automated systems, etc.) for receipt, subject to consent, of WILIER marketing communications, or with regard to individual marketing purposes among those that are concretely possible (choosing for example to receive only newsletters and not sent to our events);
- sending a clear telephone notice of revocation of consent to WILIER without any formality. Upon receiving this opt-out request, VENETA CUCINE will remove and delete the data from the databases used for processing for direct marketing purposes and, where possible, will inform any third parties to whom the data has been communicated for the same purposes of such erasure. 
The simple receipt of the erasure request will automatically be considered as confirmation of erasure.
- If you wish to revoke your consent to any advertising communications coming from social channels (e.g., Facebook, Twitter, etc.), you need to ust directly communicate revocation to the individual social platform, in the manner made available from time to time by the same and/or by the browser you use (since WILIER is not technically able to influence to this end on third-party social platforms). 
The above opposition will not produce any consequences on the provision of any contract activities in progress.

Communication of data to third parties. 
The collected data are processed by WILIER's internal delegates who need to have knowledge of them when carrying out their activities (e.g., sales office, marketing office, administrative office, technical staff for the maintenance of the company IT system, etc.).

WILIER communicates your personal data to third-party recipients only when this is necessary and functional to achieve the purpose of data processing pursued for the service or product requested by you, and in any case only proceeds with communication after informing you, and where necessary, collecting your consent to do so. Disclosure to third parties will always be limited to the data strictly needed for their respective purposes.
The third-party recipients of the data - hereafter better identified - will process the data, according to the case, a) as “data processors" (i.e., on our behalf and on the basis of our written directives aimed at ensuring respect for privacy during processing and under our supervision), or b) as joint data controllers (i.e., on the basis of a written agreement that regulates their respective activities and responsibilities in relation to personal data), or as autonomous data controllers (in this case they will provide the data subject with all the necessary legal information on their respective processing, unless they are bound by professional confidentiality based on current regulations).

Within the primary purposes and in particular when the data subject enters into a contract with our Company, data may be communicated by WILIER to all subjects whose intervention in processing is useful based on the services requested by the data subject and/or legal obligations or arising from regulations or other EU legislation, by way of example: parent, subsidiary or associated companies of the WILIER Group and/or to third-party partner companies that carry out activities functional or complementary to the supply of products or services requested by the data subject (e.g., management of information requests, quotations, orders, contracts, after-sales services), third parties tasked with the execution of activities connected and/or instrumental to processing (such as sales agents, banks for the management of collections and payments, commercial information companies, credit recovery companies, credit transfer companies, credit insurance companies, electronic payment service providers, couriers, carriers and forwarders, factoring companies, insurance companies, lawyers and law firms, accountants, accounting experts, auditors and auditing firms, members of the supervisory body pursuant to Legislative Decree 231/2001 in relation to compliance programmes aimed at preventing certain categories of offences, auditors, third parties appointed to provide web hosting and/or maintenance services for this website and/or for the IT systems used by it and/or for the electronic archives connected to the website; carriers and forwarding agents responsible for the carriage of goods; public security authorities and computer forensics companies in the case of requests related to criminal and civil investigations and/or suspected crimes or other abuses or offences committed against WILIER and/or third parties. 
In the case of processing for secondary purposes (profiling, direct marketing), pursuant to the General Provision of the Authority of 4 July 2013 containing the "Guidelines against spam" we inform you that we will also communicate the data - prior to your specific consent (see below) - to the following product or economic categories of third party recipients: other subsidiaries of the WILIER Group, advertising agencies, marketing analysis companies, communication and/or public relations companies, companies responsible for the design, printing and maintenance of advertising or promotional publishing materials and/or their on-line management, website production companies, web marketing companies, direct e-mailing service companies (e.g., Mail-up or similar), consultants and/or other entities entrusted by us with activities functional to these purposes; maintenance companies of IT systems on which our databases reside or are processed; providers of electronic communication and ICT services; third-party commercial partners with whom WILIER initiates any co-marketing actions (e.g. influencers, resellers, agents).

The data will not be disseminated. 

 

Data transfer abroad
To allow an on-line payment on the WILIER e-shop site, the Data Controller uses the service provided by third party suppliers:
- PAYPAL S.à.r.l. (France - EU), which provides a service for the management of online payments made by the User (see the Paypal privacy policy at https://www.paypal.com/it/webapps/mpp/ua/privacy-full
- STRIPE, 185 Berry Street, Suite 550, San Francisco, CA 94107 (California - U.S.A.) (see Stripe's privacy policy at https://stripe.com/it/privacy and cookies policy at https://stripe.com/cookies-policy/legal).
In order to complete the purchase, the third-party payment service provider - who will act as autonomous Data Controller - collects directly the requested data (e.g. personal data, contact data, credit card or other payment instrument) from the user and processes it. Such data will be processed by the supplier without ever passing through the server of, or being processed by, WILIER, which will receive only the order code issued and notification of payment (date, time, successful or failed completion of the transaction). Such third party services may also allow the scheduled sending of emails to you, such as emails containing invoices or payment notifications.

 

The data are also transferred by our Company to the following third-party suppliers based outside the EU:

- ZENDESK Inc., with registered office at 1019 Market St., San Francisco, CA 94103 (California - U.S.A.) which manages the service of the same name through which the data controller provides the service of managing requests for technical support to dealers and contact with end consumers received by email or other means such as the contact form or chat from the website. For further information on the ZENDESK service, please refer to the privacy policy published at https://www.zendesk.it/company/customers-partners/privacy-policy/ For information on the ZENDESK cookie policy, see the information at https://www.zendesk.it/company/customers-partners/cookie-policy/
- MAILCHIMP (The Rocket Science Group, LLC., with registered office at The Rocket Science Group, LLC 675 Ponce de Leon Ave NE Suite 5000 Atlanta, GA 30308 (Georgia - U.S.A.) which manages on behalf of the data controller the homonymous service of managing addresses and sending email messages, which uses a database of email contacts, telephone contacts or other contacts for bulk sending of email communications (e.g., newsletters, offers and other commercial communications). This service may also allow you to collect data regarding the date and time when your messages were viewed, as well as your interaction with them, such as information about clicks on links in your messages. You can view the MAILCHIMP privacy policy at the URL www.mailchimp.com/privacy/
- AMAZON WEB SERVICES Inc., with registered office at 1200 12th Avenue South, Suite 1200, Seattle, WA 98144 (Washington - U.S.A.), provides an infrastructure and backend service that hosts data and files that enable this website to function, enable its distribution, and provide a ready-to-use facility to deliver specific functions of this website. WILIER has contractually agreed with AMAZON WEB SERVICES that the servers used by them are kept within the European Union. See Amazon Web Services' privacy policy and the types of data it collects, at the URL address: https://aws.amazon.com/it/privacy/?nc1=f_pr.

Duration of processing
Personal browsing data are processed for the time needed to ensure navigation and technical interaction between the user and the website; this time coincides with the duration of the individual browsing session;
The data provided voluntarily by the user and collected through the website are based on two separate general master records
- “B2B” (regarding resellers, distributors, agents of the Company, as well as individuals who request WILIER to issue an invoice valid for tax purposes for a product purchase); the master record is managed solely by WILIER;
- “B2C” (relating to individuals who are end users of company products and who do not request WILIER to issue an invoice valid for tax purposes for a product purchase); the personal data is managed by WILIER and the company NEXSTEP Sas with its operational headquarters in Cittadella;

In the case of processing for primary purposes, personal data are usually processed for the duration of the pre-contractual and/or contractual relationships established with the data subject, in particular: 
a) in the pre-contractual phase, for the time needed to process the requests of the data subject received by the Company (e.g., opening of a ticket for technical intervention under warranty) and to trace and manage the successful completion of the replies sent by the Company to the data subject; that period shall be limited to 24 months from the date of collection of personal data;
b) in relation to the contract2 years of ordinary warranty under the Consumer Code or, in the event of extension, 5 years of warranty);
c) after the termination of the contractual relationship established with the data subject, personal data will be processed to fulfil all legal obligations related to the termination of the contractual relationship (in particular to prove the fulfilment of fiscal and statutory obligations with supervisory authorities (for 10 years from the termination of the contract). 
Personal data are processed for purposes of IT security (e.g., logs) are kept for the time needed to complete the related security checks and evaluate the results (1 year from the time of collection). 
In case of out-of-court or court litigation with the data subject and/or with third parties, the data will be processed for all the time strictly needed to exercise the full protection of the rights of the Data Controller.

The processing for secondary purposes has the following duration (unless the consent of the data subject is renewed at the end of the same period):
- direct marketing: 5 years from the date of collection. 
- profiling: 2 years from the date of collection.
The duration of storage of data collected through cookies is explained in the "Cookie Policy" section below.

Legal basis for processing.WILIER may lawfully process the data for the following reasons:

In the case of primary purposes, processing is necessary, depending on the case, to implement pre-contractual measures taken at the request of the data subject (e.g., requests for clarifications, sending of information or commercial offers), to execute a contract to which the data subject is party, or to fulfil a legal obligation to which WILIER is subject (e.g. to allow verification of the correct fulfilment of legal and contractual obligations towards the data subject or third parties by the administrative and tax authorities, by the board of statutory auditors or by auditors, etc.) and/or based on legitimate interest;
a) WILIER (prevailing over the interests or rights and fundamental freedoms of the data subject) to process data in order to effectively and efficiently manage the relationship with its users, customers and/or suppliers and to organise the related production, organisational and management processes (including relations with its sub-suppliers and/or parent companies, subsidiaries and affiliates pursuant to article 2359 of the Italian Civil Code or with companies under common control) to enable this goal;
b) of the third parties receiving the data, to receive from the Data Controller and process the personal data i) for purposes of verifying the correct fulfilment of the existing legal and contractual obligations towards the data subject or towards third parties (for example, verification by Public Authorities regarding the fulfilment of fiscal obligations, or by the Board of Statutory Auditors or auditors regarding the fulfilment of legal obligations, etc.) or ii) to be able to manage the activities connected with the Data Controller's request to receive support for managing the activities towards the data subjects

- In the case of secondary purposes (direct marketing, profiling), the processing is based on the legitimate interest of WILIERSOCIETA to promote its products and/or services to customers through offline and online (e.g., sending of so-called soft spam or commercial communications by public telephone numbers), and, alternatively, on your consent to the processing for a given purpose, not subsequently revoked.

 

Cookie Policy. 
With the provision of 8 May 2014, the Privacy Authority implemented, with definitive entry into force in Italy as of 2 June 2015, European Directive 2009/136/EC, which requires web page administrators to publish a policy statement relating to the cookie policy of the website that visitors are browsing.
This Policy may be updated at any time due to changes in current legislation or any changes in the configuration and type of cookies used, therefore we suggest that you periodically review this cookie policy in order to know all subsequent updates thereof.
The website may contain links to other websites that have their own privacy policy that may differ from that adopted by the SEO positioning of the website and that does not therefore cover these websites.

What are cookies and how are they used?
Cookies are short strings of information (text files) regarding the activity of the user on the website, which are stored, during the first navigation on the website, on the device (computer, smartphone or tablet) of the user who navigates the Internet, and then retransmitted to the same websites on any subsequent visit of the same user allowing our website to automatically recognise the user (or other users who use the same device) after the first visit and then improve its user experience.   

Their operation is totally dependent on the navigation browser that the user uses and may or may not be enabled by the user.
In order to always ensure the best possible browsing, our website offers the best performance with enabled cookies. By default almost all web browsers are set to automatically accept cookies.
Cookies can be:
- "first party" when they are managed directly by the person in charge of the website;
- "third party" when cookies are set and managed by people outside the website visited by the user.
Third-party cookies fall under the direct and exclusive responsibility of the same operator, and in relation to their installation the operator of the first-party website assumes the role of technical intermediary.

What cookies do we use and for what purpose?
The Website uses or may use, even in combination, the following categories of cookies:
- Permanent or "persistent” cookies: these cookies remain stored on your device even after you leave the website or otherwise close your browser: in particular, they persist until their expiry date or until they are manually deleted by the user. Persistent cookies fulfil many functions in the interest of surfers (such as password storage), but in some cases they can also be used for promotional purposes.

- Session (or temporary) cookies: They have a limited duration to the visit and are deleted when closing the browser, which terminates the "session" of access to the website. As a rule, they allow users to access personalised services and make full use of the website's functions, avoiding the use of other IT techniques that could compromise the confidentiality of users' browsing

- Technical and functional cookies, for example for the transmission of session identifiers necessary to allow safe and efficient browsing of the website. These cookies avoid the use of other computer techniques that could potentially compromise the confidentiality of users' browsing.

For the use of technical cookies the law requires the mere release of the information statement to the data subject, as is the case with this communication, i.e., even without the creation of specific banners on the website.

For all non-technical cookies, on the other hand, their installation is subject to the prior consent of the user in the simplified forms provided for by the Provision of 8 May 2014 of the Authority, i.e., through the publication of synthetic banners that can be viewed by the user on first "landing" on the website and that allow the user to generate a further action of use of the website (based on the "scroll", or on the continuation of navigation within the same web page) by which a user can implicitly communicate consent, or, alternatively, access analytical cookie information (i.e., this policy) as a part of which s/he may express consent or dissent. This consent or denial thereof may be given by the user not in reference to individual cookies installed but in relation to broader categories of cookies, or to specific manufacturers and/or intermediaries with which the website has established business relationships.

Analytics cookies: such cookies may be both temporary and persistent, and allow the collection and aggregate and/or disaggregated analysis of statistical information on access (e.g., geographical area of origin of the user, means of access used, age, etc.) and in general on the behaviour of users on the website and thus to improve the delivered experience and content.
Such analytical cookies can be likened to technical cookies only if they are created and used directly by the first-party website (without, therefore, the intervention of third parties). For example, the site makes use of log files (i.e., it records the history of operations as they are performed) and log files (which include IP addresses, browser type, operating system used by the user's device, Internet Service Provider - ISP), date, time, page of entry and exit and the number of clicks, as well as the pages visited on the website, the third-party websites from which the user comes). All this is to analyse the trends of user behaviour and manage and optimise the website. The information collected in this way is not of personal value as the data is collected and analysed anonymously.
Nel caso in cui invece i cookies analitici siano realizzati e/o utilizzati da terze parti (diverse cioè dal titolare del sito prima parte), gli stessi non possono essere assimilati ai cookies tecnici ed hanno un diverso trattamento giuridico.

On the other hand, if the analytical cookies are created and/or used by third parties (other than the data subject of the first-party website), they cannot be assimilated to technical cookies and have a different legal processing.

 

“Profiling” (or advertising) cookies (always of a permanent nature). These are used to obtain information, whether aggregate or not, useful to assess the use of the website and the activities carried out by the visitor (choice of display of specific pages, specific products and/or services, etc.), used by the data controller for the formulation of commercial advertising of products and/or services targeted and based on previous activities of the user (instead of generalist offered to all).

Social cookies: these cookies are third-party cookies, i.e., they are provided directly by the domains of the most common social media networks that are linked to the first-party website (e.g., WILIER) through links to official pages, content sharing buttons and links. The use of such buttons and functions implies the exchange of information (e.g., texts, photographs, videos, etc.) with such websites. The interactions and information acquired from this website are in certain cases subject to the user's privacy obligations relating to each individual social network. If a service is installed that interacts with social networks, it is possible that, though users do not use the service, it collects browsing data relating to the pages on which it is installed.

List of cookies actually present on the website  
The above premise is intended for teaching purposes alone and does not automatically imply that this website currently uses all the categories of cookies indicated above. The list of cookies actually used by WILIER is as follows.

Cookie name
Session/persistent
Function (technical, analytical, advertising)
Duration (if permanent and if not first deleted by the user)

Cookie name
Session/persistent
Function (technical, analytical, advertising)
Duration (if permanent and if not first deleted by the user)

Statistical analytical cookies

The Website uses Google Analytics cookies, which is a web analytics service provided by Google Inc. (a US company, third party, with registered office at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), for the purpose of tracking history, visitor counts, and browsing statistics of users of our website. Google Analytics does not collect any strictly personal information, but only in aggregate statistical form, data on the age, gender, and preferences of interest of our users (in order to better evaluate the use of our website and the activities carried out by the visitor and better direct the services provided, based on the behaviour as registered above). 

The "Analytics" function is in fact configured by default, in such a way as to significantly mask final portions of the IP address of the user/visitor, and therefore the data relating to the IP address thus collected and visible to us is already anonymised at the source and therefore the analytical cookie does not allow our Company to trace back even indirectly - in particular, through further processing - the identity of the user/visitor.

These Google cookies are stored on servers located in the United States or other countries. Google reserves the right to transfer the information collected with its cookie to third parties where this is required by law or where the third party processes information on its behalf. 
Google may use your personal information to contextualise and customise the ads in its advertising network.
Google also ensures that it does not associate your IP address with any other data held by Google in order to obtain a more detailed user profile. 
You may also selectively disable Google Analytics by downloading and installing the additional opt-out specifically provided by Google for your browser on your browser at the following link: HYPERLINK "http://tools.google.com/dlpage/gaoptou" http://tools.google.com/dlpage/gaoptout
 
For any further information about Google Analytics, please refer to the Privacy Policy referred to in the following link: https://www.google.com/intl/it_ALL/analytics/learn/privacy.html

This website uses the statistics service Conversion monitoring of Google Adwords, provided by Google Inc., which links the data from the ad network Google AdWords (see below) with the actions carried out within this website. This service uses browsing data and cookies. 

The privacy policy relating to the functioning of and consent to the use of Google cookies is available at the following links: 
- Information and general notes on Google services http://www.google.it/analytics/learn/privacy.html
- Procedure for use of data by Google when using websites or applications of Google partners  http://www.google.it/policies/privacy/partners/ 
- Google Analytics cookie policy https://www.google.it/intl/it/policies/technologies/types/ e https://developers.google.com/analytics/devguides/collection/analyticsjs...

The user may at any time refuse Google Analytics  cookies by downloading and installing the appropriate browser plug-in available at the link https://tools.google.com/dlpage/gaoptout?hl=it

On this website WILIER also uses the statistical service HOTJAR Form Analysis & Conversion Funnel provided by the company Hotjar Ltd, with registered office at Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta. HOTJAR respects the generic "do not track" headers, so you can configure your browser so that no user data is collected. See the Hotjar privacy policy at https://www.hotjar.com/legal/policies/privacy and the Hotjar cookie policy at https://www.hotjar.com/legal/policies/cookie-information.

Remarketing and behavioural targeting
Re-marketing and/or behavioural targeting allow a website and its third-party partners to communicate, optimise and serve online advertisements based on the user's past use of this website. This activity is carried out by tracking browsing data and the use of cookies, information that is transmitted to third-party partners to whom the activity of remarketing and behavioural targeting is linked.
This website does not use personal profiling cookies, i.e., cookies based on personal identification data.
Our website uses: 
remarketing lists on the AdWords search network and ads on the Google Display Network, i.e., online ads based on categories of general interest expressed by categories of users through previous web browsing;

the following advertising features of Google Analytics:
- Remarketing with Google Analytics
- Reports on Google Display Network impressions (if used via AdWords)
- Integration with the DoubleClick for Publishers platform (this is an advertising service provided by Google Inc. with which WILIER may conduct advertising campaigns jointly with external advertising networks with which WILIER, if not otherwise specified in this document, has no direct relationship)
- Google Analytics reports on demographic data and interests
which provide additional functions that are not available via standard implementations of Google Analytics and related cookies to be activated (in particular, in addition to the data already collected as a rule via a standard Google Analytics implementation, the collection of user traffic data via Google advertising cookies and anonymous identifiers).

The website also uses the Facebook Remarketingservice, provided by the company Facebook Inc. with registered office at Menlo Park, CA 94025 (California - U.S.A.), which links the activity of this website with the Facebook advertising network. See Facebook's privacy policy at https://www.facebook.com/privacy/explanation
For more information on online behavioural advertising and suggestions on possible measures, in particular to disable the display of advertisements based on online interests: www.youronlinechoiches.eu/it.

Social cookies: 
Facebook: Facebooksocial plugins are managed by Facebook Inc., 1601 South California Avenue, Palo Alto, CA 94304 (California - USA). Facebook plugins are represented by the Facebook logo or the "Like-Button" ("Like") found on the website pages. See an overview of Facebook plugin at the link: http://developers.facebook.com/docs/plugins/. These plugins are used for content sharing. To use these plugins, Facebook provides a cookie necessary for their operation. When you visit the pages of the website that contain the plugin, it establishes a direct connection between the browser and the Facebook server. Facebook then receives the information that you have visited the website with your IP address. If you click the Facebook "Like" button while logged in to your Facebook account, you can link the content of the pages of the website you visit to your Facebook profile. In this way Facebook can correlate your visit to the website with the user account you are using. If you do not want Facebook to be able to make such a link, you need to log out of your Facebook account before logging in to the website. We are not aware of the content of the data transmitted, nor of the use made of it by Facebook. For more information, see Facebook's privacy policy at http://it-it.facebook.com/policy.php and https://www.facebook.com/help/206635839404055

Google: Google+ social pluginsare managed by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Google plugins are represented by the Google logo that is located on the website pages. When you visit a page of the website that contains a Plugin of this type, your browser connects directly to Google's servers. The content of the plugin is directly transmitted by Google to the browser, which then incorporates it into the website. We therefore have no control over the data that Google collects through the Plugin. If you do not want Google to be able to link your visit to the website pages to your Google account, you must log out of your Google account before accessing the website. The purpose and scope of data collection, the processing and use of data by Google as well as your rights in this regard and the various possible settings for protecting your privacy can be found in Google's data protection guidelines for plug-ins: www.google.com/intl/en/policies/privacy/

Twitter: The Twitter social plugin is managed by Twitter Inc. (795 Folsom St., Suite 600, San Francisco, CA 94107, USA). You can consult an analytical illustration of these plug-ins at the link: https://twitter.com/about/resources/buttons  and the Privacy Policy Twitter at the link: http://twitter.com/privacy.

Pinterest: The plugins of the social network Pinterestare managed by the company Pinterest Inc., 635 High Street, Palo Alto, CA, 94301 (California - USA). The various logos containing the plug-in (e.g., "Pin-it-Button" or the "P″ button) can be viewed at the link: http://business.pinterest.com/pin-it-button/. When you open Internet pages of the website that contain the plug-in, a link is created between your computer and the Pinterest servers and the plug-in is displayed on the Internet page by notifying your browser. To do this, both your IP address and the information relating to the pages of the website you have visited are transmitted to Pinterest's server in the USA. The transmission also takes place for users not registered on Pinterest. If you are also a Pinterest user and are logged on to Pinterest when you use the plugin, the information collected through your visit to the website is linked to your Pinterest account and made known to other users. If you do not want Pinterest to link the information to your Pinterest account data, you need to log out of Pinterest before visiting the website that uses the plugin. See Pinterest's most extensive privacy policy at http://it.about.pinterest.com/privacy/

ShareThis: ShareThis is a service provided by ShareThis Inc., with registered office at 4005 Miranda Avenue, Suite 100, Palo Alto, CA 94304-1227 (California - U.S.A.), that displays a widget that allows interaction with external social networks and platforms and sharing of content on this website. Depending on the set-up, this service may show widgets belonging to third parties, such as social network managers to share their interactions with. In this case, even the third parties that provide the widget will be aware of the interactions and data related to the use of the pages on which this service is installed. See ShareThis Privacy Policy at: https://www.sharethis.com/privacy/
Further information on privacy and the use of social cookies can be found directly on the websites of the respective third-party operators.
Information management and ways to eliminate such social cookies are regulated by social media websites themselves: we invite the user to consult the respective privacy policies of each of them, at the following links:

- You Tube https://www.google.it/intl/it/policies/privacy/, https://www.google.com/policies/technologies/types/
- Facebook policy statement: https://www.facebook.com/about/privacy, https://www.facebook.com/legal/FB_Work_Privacy, https://www.facebook.com/help/cookie/ e https://www.facebook.com/policies/cookies/ 
- Facebook configuration: access your account, privacy section, or follow the various guides on the web, such as https://support.mozilla.org/en-US/kb/disable-third-party-cookie
- Twitter policy statements: https://twitter.com/privacy?lang=it, https://support.twitter.com/articles/20170514
- Twitter setup: https://twitter.com/settings/security, https://support.twitter.com/articles/20170519-uso-dei-cookie-e-dialtre-t..., https://help.twitter.com/it/rules-and-policies/twitter-cookies
- Linkedin policy statement: https://www.linkedin.com/legal/cookie-policy, https://www.linkedin.com/legal/privacy-policy?trk=uno-reg-guest-home-pri...
- Linkedin setup: https://www.linkedin.com/settings/
- Pinterest: https://policy.pinterest.com/it/privacy-policy
- Instagram: https://help.instagram.com/155833707900388, https://help.instagram.com/519522125107875
- Vimeo: https://vimeo.com/privacy
- Google policy on the use of data http://www.google.com/policies/technologies/cookie/, complete policy http://support.google.com/analytics/answer/6004245
- Google Google configuration: guide on the general opt-out for Google services (Maps, YouTube...) http://support.google.com/accounts/answer/61416?hl=it
- Google+ policy: http://www.google.it/intl/it/policies/technologies/cookie/
- Google+ set-up: http://www.google.it/intl/it/policies/technologies/managing/

The use of these cookies is purely anonymous; no personal information is collected unless the user intends to provide it expressly by sending contact forms and/or request information. 

How do cookies work and how do you disable them?
Accepting or rejecting cookies is your right
By default, browsers generally accept the use of cookies both from our website and from third-party websites. In order to allow the website to function correctly, exploit its features and use it in its entirety, we recommend that you accept the use of cookies.

The user is enabled, however, to modify the default configuration at any time. To manage how cookies work, as well as the options to limit or block cookies, it is sufficient for the user to change the settings of his Internet browser through the relevant toolbar. You can choose between unconditional acceptance of all cookies (in particular: browsing in any form on our site after the initial appearance on the screen of the synthetic banner that warns you of the presence of cookies on our website, you implicitly consent to the use of cookies), the indistinct rejection of all cookies permanently, or the display of a pop-up window (Warning) whenever a cookie is proposed, in order to be able to evaluate whether to accept it or not through an express action by the user. 
Here are the links for the configuration of the most popular browsers that describe how to manage cookies:
- Chrome: https://support.google.com/accounts/answer/61416?hl=it
- Firefox: https://support.mozilla.org/it/kb/Gestione%20dei%20cookie
- Internet Explorer: http://windows.microsoft.com/it-it/windows-vista/block-or-allow-cookies
- Opera: http://help.opera.com/Windows/10.00/it/cookies.html
- Safari: https://support.apple.com/it-it/HT201265
 

To change the cookie settings on browsers other than those listed, please refer to the help documentation prepared by the manufacturer of your browser.
Remember that you need to set cookie preferences for each browser and each different device (desktop computer, laptop, tablet, smartphone) used when surfing the Internet (also refer to the user manual of the device).
For more information on cookies and privacy, you can consult the specific document of the Privacy Authority at the following link:
http://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docw...
 

The data controller of the personal data is WILIER TRIESTINA S.p.A., Via Fratel Venzo n. 11, Rossano Veneto (VI) - Italy, in the person of the Managing Director Mr. Andrea Gastaldello, email: privacy@wilier.it.
A complete and updated list of the external managers can be consulted at the Company upon written request of the interested party.

 

 

Rights of the data subject
With regard to the processing of personal data you may exercise the following rights, contacting without any particular formality our company at the above email address:
1) ask our Company to confirm whether or not personal data concerning you are being processed and, if so, to obtain access to the personal data and the following information: 
a) the purposes of processing: 
b) the categories of personal data concerned; 
c) the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular if they are recipients in third countries or international organisations; 
d) where possible, the envisaged period of retention of the personal data or, if that is not possible, the criteria used to determine that period; 
e) the existence of the right of the data subject to ask our company to correct or delete personal data or to limit the processing of personal data concerning him or her or to oppose processing; 
f) the right to lodge a complaint with a supervisory authority; if the data are not collected from the data subject, all available information on their origin; 
g) the existence of an automated decision-making process, including profiling and, at least in such cases, significant information on the used logic, as well as the importance and the expected consequences of such processing for the data subject. 

2) where personal data are transferred to a third country or an international organisation, the data subject will have the right to be informed of the existence of appropriate safeguards relating to the transfer.

3) request, and obtain without undue delay, the rectification of inaccurate data; taking into account the purposes of processing, the integration of incomplete personal data, including by providing a supplementary statement; 

4) request the deletion of the data if: 
a) personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; 
b) the data subject withdraws the consent on which processing is based and there is no other legal basis for processing; 
c) the data subject objects to processing, if there is no overriding legitimate reason for carrying out the processing, or to processing carried out for direct marketing purposes (including profiling for the purpose of such direct marketing); 
d) the personal data have been processed unlawfully; 
e) personal data must be deleted in order to fulfil a legal obligation under EU law or the law of the Member State to which our Company is subject; 
f) personal data have been collected in relation to the provision of information society services from the database of our Company;

5) request the restriction of processing concerning you, when one of the following applies: 
a) the accuracy of the personal data is contested by the data subject; in this case the restriction of processing (i.e., suspension thereof) may take place for the time needed by our Company to verify the accuracy of such personal data; 
b) processing is unlawful (for example because the data subject has not been provided with prior information required by law) and the data subject opposes the erasure of personal data (i.e., prefers them to be kept by us in our paper and/or computer files) and instead requests that their use be restricted as above; 
c) although our Company no longer needs them for the purposes of processing, the personal data are necessary for the data subject to ascertain, exercise or defend a right in court 
d) the data subject has opposed processing carried out for direct marketing purposes, pending verification of the possible prevalence of the legitimate reasons of our Company over those invoked by the data subject; 

6) obtain from our Company, upon request, the communication of third-party recipients to whom the personal data have been transmitted;
7) revoke consent at any time to the processing of personal data if previously communicated for one or more specific purposes, it being understood that this will not affect the lawfulness of processing based on the consent given prior to revocation.
8) receive in a structured, commonly used and readable format by automatic device the personal data concerning the data subject provided by him or her to our Company and, if technically feasible, to transmit such data directly to another Data Controller without hindrance on our part, if the following (cumulative) condition is met: 
a) processing is based on the consent of the data subject for one or more specific purposes, or on a contract to which the data subject is a party and for the performance of which processing is necessary; and e 
b) processing is carried out by automated means (software) (overall right to so-called "portability”); 
the exercise of the so-called right to portability is without prejudice to the right of erasure provided for above;

9) not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or significantly affects him or her in a similar manner. NB: Our Company does not make any automated decisions of the above type.
10) lodge a complaint with the competent supervisory authority on the basis of the GDPR (that of your place of residence or domicile).

 

Changing the policy
This privacy policy as of the date of its publication replaces any previous version. Unless otherwise specified, the previous privacy policy will continue to apply to personal data collected to date. WILIER reserves the right to make changes to this privacy policy at any time by notifying users on this page. Please consult this page frequently, taking as a reference the date of last change indicated at the bottom. In the event of non-acceptance of future changes, the data subject must cease using the website or the features to which the privacy change refers, and in the absence of such non-acceptance the changes will be deemed as accepted (except for those that modify the conditions for obtaining consent, where mandatory, to processing).

 

Rev 1.0 dated 21.07.2018

---

* As clarified in the General Provision of the Privacy Authority of 4 July 2013 containing the "Guidelines against spam":
- the communication or transfer to third parties of personal data for marketing purposes in general cannot be based on the acquisition of a single and general consent by the parties concerned for such purposes;
- it is necessary that the data controller acquires specific consent for the communication (and/or transfer) to third parties of personal data for promotional purposes, and separate from that required by the same data controller to carry out its own promotional activities; if the interested party gives such consent, third parties may carry out promotional activities for him also by the automated means referred to in article 130, paragraphs 1 and 2, of the Privacy Code without having to acquire a new consent for the promotional purpose.
- the data controller who intends to collect the personal data of the interested parties also to communicate them (or transfer them) to third parties for their marketing purposes must first provide them with suitable information policy that also identifies each of the third parties or, alternatively, indicates the categories (economic or product) belonging to them.