Pursuant to EU Regulation 2016/679 (GDPR) and Legislative Decree. 196/03 (and subsequent amendments)
Information Version: 5.0 dated 07/07/2020
This Notice describes the types of data that we can collect and process through the use of the ALGHO platform produced and managed by Quest-it, describing its collection, use, maintenance, protection and disclosure practices.
Quest-it srl, with registered office in – Via Leonida Cialfi, 23, 53100 Siena (SI) – ITALY, firstname.lastname@example.org, VAT code IT 01214250522 – (hereinafter also referred to as, “Quest-it”, or the “Owner”), which operates in the production, maintenance and distribution directly or through software and related services partners. In the person of its legal representative, Quest-it guarantees compliance with the regulations on the protection of personal data by providing the following information about the processing of data communicated or otherwise collected during the use of the ALGHO platform (the “platform” or “ALGHO”) . QUEST-IT has appointed Findata Srl, with registered office in Viale Margherite n.41 Pollena T. (NA), as Data Protection Officer, in the person of Dr. Cino Wang Platania who can be contacted via email DPO@thedigitalbox.com.
Data Controller: the natural person, the legal person, the public administration and any other body, association or organization which is responsible, even jointly with another owner, for decisions regarding the purposes, methods of processing personal data and the tools used, including the information security profile.
Data Protection Officer: the person, company, body, association or body to which the owner entrusts, also externally, for the particular experience or for the capabilities, tasks of management and control of data processing.
End-User or Data Subject: these terms refer to anyone (a customer or a potential one)who browses through one of the web pages managed by QUEST-IT, uses an APP managed by QUEST-IT, who is contacted or enters data through one of the digital marketing platforms used by QUEST-IT or directly within one of the QUEST-IT offices. In the case of minors, the provisions indicated in Art. 2-quinquies of the Legislative Decree 196/03 (with the changes made by Legislative Decree 101/18) are adopted.
ALGHO: it is the platform you are using at the moment. It is a Chat bot, chatbot or chatterbot, a software designed to simulate a conversation with a human being. The main purpose of these software is to simulate human behavior and these are used for various purposes such as online help, to answer the FAQs of users who access a site etc; the Owner could offer within its web spaces the possibility, for end-users and customers, to interact with a chatbot to offer the services requested by the end-user, improve the user experience with the disclosure of information (description of services, products, promotions, etc.) and to acquire contact information.
Websites: The web pages managed by the Data Controller such as www.bluespirit.com.
Personal Data: We consider as personal any information that is voluntarily submitted and that personally identifies someone, including contact information (e.g. your name, email address, company name, address, telephone number) and other information about you or your business. Personal Information may also include information about any transaction, whether free or paid, information that is available on the Internet, such as from Facebook, LinkedIn, Twitter and Google, or publicly available information.
Particular Data: Also known as “sensitive” data, we consider as particular data the racial or ethnic origin, religious and philosophical beliefs, political opinions, trade union membership, information relating to health, orientation and sexual life as well as biometric and genetic data.
Browsing information: They refer to the information on your computer and visits to this website (and to other web pages managed by QUEST-IT) such as the IP address, geographic location, browser type, reference source, the duration of the visit and the pages viewed.
Consent: This refers to the free expression of the will of the interested party with which he expressly accepts a certain processing of his personal/sensitive data, of which he has been previously informed by the Data Controller.
Data processed, purposes and legal bases of the processing
Data generated by accessing the site
The computer systems and software procedures, used to make ALGHO work, acquire some personal data during their normal operation, whose transmission is implicit in the use of Internet communication protocols.
These data (such as domain names, IP addresses, operating system used, type of browser device used for connection) are not accompanied by any additional personal information and are used for:
I) obtain anonymous statistical information on the use of the platform;
II) manage the control needs of the methods of use of the platform;
III) ascertain responsibility in the event of hypothetical computer crimes.
The legal basis that legitimizes the processing of such data is the need to make Algho’s functions usable following user access.
Data provided voluntarily by the user
Personal information, which includes the name, surname, email address and information indicated in conversations with the system or any other identifier to contact the data subject (online or offline) or any other information that can be attributed directly or indirectly to the data subject and which will provided by the interested party himself through the ALGHO platform will be necessary:
for the execution of the contract or pre-contractual measures adopted at the request of the same. This includes the management of responses to interested parties regarding navigation assistance, administrative purposes, the management of payments and for the fulfillment of legal obligations such as those of an accounting, tax nature, or to process requests from the ‘judicial authority;
in the presence of specific consent, for marketing activities such as the periodic sending, by e-mail, of newsletters and advertising material and to receive updates on our activities, promotional communications and invitations to events, training courses, webinars, special promotions, participate in market analysis and research or commercial communication with automated contact methods, or through remote communications (eg via mobile and fixed networks, with sms, MMS etc.) and traditional (paper mail);
in the presence of specific consent, the data will be processed for profiling purposes, in particular for the creation of a commercial profile and / or for the analysis of preferences, habits or consumption choices, also by crossing such personal data with other information collected through any accepted profiling cookies. The processing of your personal data for profiling purposes will take place with tools and methods, better provided for in the following paragraph 5 (Processing methods).
3.1 The technologies that QUEST-IT and third parties providing content and applications may use for this automatic data collection include:
COOKIES. A cookie is a small file placed on your computer’s hard drive. You can refuse to accept cookies by appropriately configuring your browser. However, if you select this setting you may not be able to access some of the services of the ALGHO platform or the websites managed by QUEST-IT. Unless you have adjusted your browser settings to reject cookies, our system may issue cookies when using the ALGHO platform or the websites managed by QUEST-IT. In the browser, it is possible to disable the storage of cookies or remove the registered cookies, but this could lead to a reduction in functionality, a slowdown or the inability to use some parts of the ALGHO platform or the pages managed by QUEST-IT. For more information on cookies and how to delete them based on the type of browser used, refer to: www.allaboutcookies.org.
To know the cookies used by ALGHO, please refer to the specific information.
Nature of the provision
Apart from that specified for navigation data and for data collected through the ALGHO Platform, the provision of data:
with respect to the purposes referred to in point 3a) it is mandatory and any refusal will make it impossible for QUEST-IT to implement the contractual commitments undertaken.
with respect to the purposes referred to in point 3b) and 3c), membership is optional and the use of data for these purposes is strictly subject to the release of an explicit consent by the customer. Any refusal to process, of all or part of the same, will make it impossible for QUEST-IT to carry out the treatments for the purposes described.
Methods of processing and data retention time
The data collected will be processed using electronic or in any case automated, IT and telematic tools, or through manual processing with logic strictly related to the purposes for which the personal data were collected and, in any case, in order to guarantee the security of the same in any case. . The data is kept for the time strictly necessary to manage the purposes for which the data are collected in compliance with current regulations and legal obligations. If not necessary for the aforementioned purposes, the data will be kept for no more than 6 months.
In any case, QUEST-IT and the respective data processors appointed by you, apply rules that prevent the retention of data indefinitely and therefore limits the retention time in compliance with the principle of minimization of data processing by carrying out a periodic check on a regular basis. annually on the data processed and on the possibility of being able to cancel them if no longer necessary for the intended purposes.
The processing of personal data for profiling purposes will take place, in the event of consent, with data processing tools which, following cross-referencing, will create a commercial and behavioral profile on the web. This data processing tool also relates the data collected while browsing the web pages through the use of first-party profiling cookies accepted with the data collected using the methods previously specified.
Subjects authorized to process, responsible subjects and data communication
The processing of the collected data is carried out by personnel appointed by QUEST-IT for this purpose, identified and authorized for processing according to specific instructions given in compliance with current legislation.
The data collected, if necessary or instrumental for the execution of the aforementioned purposes, may be processed by third parties appointed as external data processors (whose updated list can be requested via email by writing to email@example.com) and, depending on the case, communicated to them as autonomous owners, and more precisely:
– Companies of The Digital Box group of which Quest-it is part for the purposes referred to in point 3a) and 3b);
– Persons, companies, associations or professional firms that provide assistance and advice to our Company, for the purposes referred to in point 3a);
– Third parties providing content and value-added services requested by the end-user;
– Companies, organizations, associations that perform services connected and instrumental to the execution of the aforementioned purposes (market analysis and research service, management of payments by credit card, maintenance of IT systems).
– Public authorities, when the conditions are met.
The data processors appointed by QUEST-IT will process the data only as indicated by QUEST-IT itself and are authorized to process them for different purposes for the purposes for which they were collected. All data will be used exclusively and limited to the purposes determined following the signed contracts.
Furthermore, the personal data collected and processed will never be disclosed.
Transfer of personal data outside the EU
Your data may also be processed by IT service providers, in their capacity as Data Processors. If they operate outside the European Union, QUEST-IT, in compliance with the legislation on the transfer of data to a non-European country, undertakes to stipulate, if necessary, agreements that guarantee an adequate level of protection and / or to sign the necessary contractual clauses.
Rights of the Data Subject
At any time it is possible to access the data, have confirmation of its existence, know its origin, oppose the processing or request the cancellation, modification or updating of all personal information collected by QUEST-IT, exercising the right to limitation of the treatment and the right to data portability, by sending an e-mail to the address firstname.lastname@example.org.
It is also possible to lodge a complaint with an Italian supervisory authority, the Personal Data Protection Authority (link: https://tinyurl.com/y53c4ye2).
Data security details
Personal data are protected by technical, IT, organizational, logistical and procedural security measures, against the risk of destruction or loss, even accidental, and of unauthorized access or unauthorized processing. These measures are periodically updated on the basis of technical progress, the nature of the data and the specific characteristics of the processing and are constantly monitored and verified over time. These security measures correspond to the requirements that the Data Controller and the managers appointed by him have identified as adequate. Periodic “Risk Analysis” activities are conducted to verify adherence to the security protocols adopted and new security measures are introduced or updated, if necessary, following organizational changes and technological innovations or changes in the type of data collected. The security measures are constantly monitored and periodically checked.