Accesso al pannello di amministrazione dell'eshop >> (Questo messaggio lo vedi solo tu!)

- PRIVACY POLICY ENG


Privacy Policy of shop.libriproibiti.com (English)

This Website collects certain Personal Data from its Users.

This document can be printed using the print command available in the settings of any browser.

Data Controller

Massimo Girometta
Via Carcassola, 22 – 20056 Trezzo sull’Adda (MI), Italy
Email: libriproibiti.shop@gmail.com

Types of Data Collected

Among the Personal Data collected by this Website, either independently or through third parties, are: Usage Data; Tracking Tools; first name; last name; email address; responses to questions; clicks; keypress events; motion sensor events; mouse movements; scroll position; touch events; Data communicated while using the service.

Full details regarding each type of Personal Data collected are provided in the dedicated sections of this privacy policy or through specific information notices displayed prior to the collection of the Data.

Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Website.

Unless otherwise specified, all Data requested by this Website is mandatory. If the User refuses to provide such Data, it may be impossible for this Website to provide the Service. In cases where this Website specifically states that certain Data is optional, Users are free not to provide such Data without any consequence on the availability or operation of the Service.

Users who are uncertain about which Data is mandatory are encouraged to contact the Data Controller.

Any use of Cookies — or other tracking tools — by this Website or by the owners of third-party services used by this Website is intended to provide the Service requested by the User, in addition to the other purposes described in this document and in the Cookie Policy.

The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Website.

Methods and Place of Processing of Collected Data

Methods of Processing

The Data Controller adopts appropriate security measures aimed at preventing unauthorized access, disclosure, modification, or destruction of Personal Data.

Processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the organization of this Website (administrative, commercial, marketing, legal personnel, system administrators) may have access to the Data, as well as external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies), who may also be appointed, if necessary, as Data Processors by the Data Controller. An updated list of Data Processors may always be requested from the Data Controller.

Place

The Data is processed at the Data Controller’s operating offices and in any other location where the parties involved in the processing are located. For further information, please contact the Data Controller.

The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information about the place of processing, the User may refer to the section concerning details on the processing of Personal Data.

Data Retention Period

Unless otherwise specified in this document, Personal Data shall be processed and retained for as long as required by the purpose for which it was collected and may be retained for a longer period due to legal obligations or based on the Users’ consent.

Purposes of Processing of Collected Data

User Data is collected to enable the Data Controller to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect its own rights and interests (or those of Users or third parties), detect any malicious or fraudulent activity, as well as for the following purposes: Displaying content from external platforms, Contacting the User, Hosting and backend infrastructure, SPAM protection, and Collection of privacy preferences.

For detailed information about the purposes of processing and the Personal Data processed for each purpose, the User may refer to the section “Details on the processing of Personal Data”.

Details on the Processing of Personal Data

Personal Data is collected for the following purposes and using the following services:

Contacting the User

Contact form and email management (this Website)
By filling in the contact form with their Data, the User consents to its use for responding to requests for information, quotations, or any other inquiries as indicated in the header of the form.

Personal Data processed: last name; email address; first name.

SPAM Protection

This type of service analyzes the traffic of this Website, which may potentially contain Users’ Personal Data, in order to filter it from traffic, messages, and content recognized as SPAM.

Displaying Content from External Platforms

This type of service allows content hosted on external platforms to be displayed directly from the pages of this Website and to interact with them.

Such services may still collect web traffic data related to the pages where the service is installed, even when Users do not use it.

Google Ireland Limited – Google Fonts

Google Fonts is a font style visualization service provided by Google Ireland Limited that allows this Website to integrate such content within its pages.

Personal Data processed: Usage Data; Tracking Tools.
Place of processing: Ireland – Privacy Policy..

Google Ireland Limited – YouTube Video Widget

YouTube is a video content visualization service provided by Google Ireland Limited that allows this Website to integrate such content within its pages.

Personal Data processed: Usage Data; Tracking Tools.
Place of processing: Ireland – Privacy Policy.

Meta Platforms Ireland Limited – Instagram Widget

Instagram is an image visualization service provided by Meta Platforms Ireland Limited that allows this Website to integrate such content within its pages.

Personal Data processed: Usage Data; Tracking Tools.
Place of processing: Ireland – Privacy Policy.

Meta Platforms Ireland Limited – Facebook Like Button and Social Widgets

The “Like” button and Facebook social widgets are interaction services with the Facebook social network provided by Meta Platforms Ireland Limited.

Personal Data processed: Usage Data; Tracking Tools.
Place of processing: Ireland – Privacy Policy.

iubenda srl – Privacy Controls and Cookie Solution

Privacy Controls and Cookie Solution by iubenda allows the Data Controller to collect and store Users’ preferences regarding the processing of Personal Data and specifically regarding the use of Cookies and other Tracking Tools on this Application.

Personal Data processed:
• IP address
• Tracking Tools

Service provided by:
• iubenda srl (Italy) – Privacy Policy

Hosting and Backend Infrastructure

This type of service has the function of hosting Data and files that enable this Website to operate, allow its distribution, and provide a ready-to-use infrastructure to deliver specific features of this Website.

Some of the services listed below, if present, may operate on geographically distributed servers, making it difficult to determine the actual location where Personal Data is stored.

Netsons s.r.l.

A Hosting Service of the Netsons.com Network.

Personal Data processed: various types of Data as specified in the service’s privacy policy.
Place of processing: Italy – Privacy Policy.

Vitamino Srl

E-commerce management platform (Website Building) – scontrino.com

Personal Data processed: various types of Data as specified in the service’s privacy policy.
Place of processing: Italy – Privacy Policy.

Analytics

The services contained in this section enable the Data Controller to monitor and analyze traffic data and are used to track User behavior.

Google LLC – Google Analytics 4

Google Analytics is an analytics service provided by Google LLC (“Google”). Google uses the Personal Data collected to track and examine the use of this Application, compile reports, and share them with other services developed by Google. Google may use Personal Data to contextualize and personalize ads within its advertising network.

In Google Analytics 4, IP addresses are used at the time of collection and then deleted before the data is stored in any data center or server. For more information, Users may consult Google’s official documentation.

To learn more about how Google uses Data, please refer to Google’s partner policy and Business Data page.

Personal Data processed:

  • Usage Data
  • number of Users
  • session statistics
  • Tracking Tools

Service provided by:

Payment Methods and Data Processing

For the management of payments related to the services/products offered, the Data Controller provides Users with different payment methods, including:

  • payment via the PayPal platform;
  • payment by bank transfer.

PayPal – Payment via PayPal

If the User chooses to make payment through PayPal, the data strictly necessary to manage the transaction (such as first name, last name, email address, amount, and order details) may be communicated to PayPal, which will act as an independent Data Controller with regard to the data processed for the execution of the payment.

The processing of data by PayPal will take place in accordance with its own privacy policy, available on the official website of the service provider.

Please note that the Data Controller does not access the User’s payment instrument data (e.g., credit card number or bank details associated with the PayPal account), which are handled directly by the provider through secure systems and encryption protocols in compliance with industry standards.

The communication of data to PayPal is necessary for the performance of the contract and for the proper management of the payment.

Payment by Bank Transfer

In the case of payment by bank transfer, the Data Controller may process the data contained in the payment instruction (such as the payer’s first and last name, IBAN, originating bank, amount, and payment reference), exclusively for administrative, accounting, and tax purposes related to the execution of the contract.

Such data is processed in compliance with the principles of lawfulness, fairness, transparency, and data minimization provided for by Regulation (EU) 2016/679 and retained for the time necessary to fulfill contractual and legal obligations.

Traffic Optimization and Distribution

This type of service allows this Application to distribute its content through servers located in different territories and to optimize its performance.

The Personal Data processed depends on the characteristics and implementation methods of these services, which by their nature filter communications between this Application and the User’s browser.

Due to the distributed nature of this system, it is difficult to determine the locations where content, potentially containing the User’s Personal Data, is transferred.

BunnyWay d.o.o. – Bunny CDN

Bunny CDN is a traffic optimization and distribution service provided by BunnyWay d.o.o.

Personal Data processed: Usage Data.
Place of processing: Slovenia – Privacy Policy.

Cookie Policy

This Website uses Tracking Tools. For more information, Users may consult the Cookie Policy.

Additional Information for Users

Legal Basis for Processing

The Data Controller processes Personal Data relating to the User where one of the following conditions applies:

  • the User has given consent for one or more specific purposes;
    Note: in some jurisdictions, the Data Controller may be authorized to process Personal Data without the User’s consent or another of the legal bases specified below until the User objects (“opt-out”) to such processing. However, this does not apply where the processing of Personal Data is subject to European data protection legislation;
  • processing is necessary for the performance of a contract with the User and/or for the implementation of pre-contractual measures;
  • processing is necessary to comply with a legal obligation to which the Data Controller is subject;
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
  • processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.

In any case, it is always possible to request that the Data Controller clarify the specific legal basis of each processing activity and in particular to specify whether the processing is based on law, required by a contract, or necessary to enter into a contract.

Further Information on Data Retention

Unless otherwise specified in this document, Personal Data shall be processed and retained for as long as required by the purpose for which it was collected and may be retained for a longer period due to legal obligations or based on the User’s consent.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User shall be retained until such contract has been fully performed.
  • Personal Data collected for purposes related to the legitimate interest of the Data Controller shall be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.

When processing is based on the User’s consent, the Data Controller may retain Personal Data for a longer period until such consent is withdrawn. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or upon order of an authority.

At the end of the retention period, Personal Data shall be deleted. Therefore, once this period has expired, the rights of access, erasure, rectification, and data portability can no longer be exercised.

User Rights

Users may exercise certain rights regarding the Data processed by the Data Controller.

In particular, within the limits provided by law, the User has the right to:

  • withdraw consent at any time. The User may withdraw previously given consent to the processing of their Personal Data;
  • object to the processing of their Data. The User may object to the processing of their Data when it is carried out on a legal basis other than consent;
  • access their Data. The User has the right to obtain information regarding the Data processed by the Data Controller, certain aspects of the processing, and to receive a copy of the processed Data;
  • verify and request rectification. The User may verify the accuracy of their Data and request that it be updated or corrected;
  • obtain restriction of processing. The User may request that the processing of their Data be restricted. In such a case, the Data Controller will not process the Data for any purpose other than storage;
  • obtain erasure or removal of their Personal Data. The User may request the deletion of their Data by the Data Controller;
  • receive their Data and have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transmitted to another controller without hindrance;
  • lodge a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.

Users are also entitled to obtain information regarding the legal basis for Data transfers abroad, including to any international organization governed by international law or established by two or more countries (such as the United Nations), as well as regarding the security measures adopted by the Data Controller to safeguard their Data.

Details on the Right to Object

Where Personal Data is processed in the public interest, in the exercise of official authority vested in the Data Controller, or for the purposes of the legitimate interests pursued by the Data Controller, Users have the right to object to such processing on grounds relating to their particular situation.

Users are informed that, where their Data is processed for direct marketing purposes, they may object to such processing at any time, free of charge and without providing any justification. If Users object to processing for direct marketing purposes, the Personal Data will no longer be processed for such purposes. To determine whether the Data Controller processes Data for direct marketing purposes, Users may refer to the relevant sections of this document.

How to Exercise Rights

To exercise their rights, Users may submit a request to the contact details of the Data Controller provided in this document. Requests may be made free of charge and will be handled by the Data Controller as soon as possible and, in any event, within one month, providing Users with all information required by law.

Any rectification, erasure, or restriction of processing shall be communicated by the Data Controller to each recipient, if any, to whom the Personal Data has been disclosed, unless this proves impossible or involves disproportionate effort. The Data Controller shall inform the User about those recipients if requested.

Further Information on Processing

Legal Defense

The User’s Personal Data may be used by the Data Controller in legal proceedings or in the preparatory stages of possible legal action for the defense against abuses in the use of this Website or related Services by the User.

The User declares to be aware that the Data Controller may be required to disclose Data by order of public authorities.

Specific Information Notices

Upon request, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information notices regarding specific Services or the collection and processing of Personal Data.

System Logs and Maintenance

For operational and maintenance purposes, this Website and any third-party services used by it may collect system logs, i.e., files that record interactions and may also contain Personal Data, such as the User’s IP address.

Information Not Contained in This Policy

Further information regarding the processing of Personal Data may be requested at any time from the Data Controller using the contact details provided.

Changes to This Privacy Policy

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Website, as well as, where technically and legally feasible, by sending a notification to Users through any contact details available.

Users are therefore encouraged to review this page frequently, referring to the date of the latest modification indicated at the bottom.

If the changes affect processing activities whose legal basis is consent, the Data Controller will collect the User’s consent again, where required.

DEFINITIONS AND LEGAL REFERENCES

Personal Data (or Data)

Personal Data means any information that, directly or indirectly, including in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.

Usage Data

Information collected automatically through this Website (including from third-party applications integrated into this Website), including: IP addresses or domain names of the computers used by the User connecting to this Website, URI (Uniform Resource Identifier) addresses, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s response (successful outcome, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various time details of the visit (for example, the time spent on each page), and details relating to the path followed within the Application, with particular reference to the sequence of pages visited and parameters relating to the User’s operating system and IT environment.

User

The individual using this Website who, unless otherwise specified, coincides with the Data Subject.

Data Subject

The natural person to whom the Personal Data refers.

Data Processor (or Processor)

The natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Data Controller, as described in this privacy policy.

Data Controller (or Controller)

The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data and the tools adopted, including security measures concerning the operation and use of this Website. Unless otherwise specified, the Data Controller is the owner of this Website.

This Website (or this Application)

The hardware or software tool by which Users’ Personal Data is collected and processed.

Service

The Service provided by this Website as described in the relevant terms (if available) on this site/application.

European Union (or EU)

Unless otherwise specified, any reference to the European Union contained in this document shall be deemed to include all current Member States of the European Union and the European Economic Area.


Cookie

Cookies are Tracking Tools consisting of small portions of data stored within the User’s browser.

Tracking Tool

Tracking Tool means any technology — such as Cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting — that enables the tracking of Users, for example by collecting or storing information on the User’s device.

Legal References

Unless otherwise specified, this privacy policy exclusively concerns this Website.

Last updated: 25/02/2026