For cookie information and to manage your preferences, please see the Cookie Policy.
Data Controller
The Base srl, with registered office at Viale del Poggio Fiorito, 27, 00144 Roma RM, as Data Controller, informs you pursuant to Article 13 of Legislative Decree No. 196 of 30 June 2003 (the “Privacy Code”) and Article 13 of EU Regulation 2016/679 (the “GDPR”) that your data will be processed in the manner and for the purposes set out below.
Types of Data collected
The Personal Data collected by rockinroma.com, either independently or through third parties, include first name, surname, gender, date of birth and email address. Full details of each type of data collected are provided in the relevant sections of this privacy policy or in specific notices displayed before the data are collected.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Application. Unless otherwise specified, all Data requested by this Application are mandatory. If the User refuses to provide them, the Application may be unable to provide the Service. Where this Application indicates that certain Data are optional, Users may choose not to provide them without any effect on the availability or operation of the Service.
Users who are unsure which Data are mandatory are encouraged to contact the Data Controller.
Unless otherwise stated, the use of Cookies or other tracking tools by this Application or by the providers of third-party services used by this Application serves to provide the Service requested by the User, as well as the other purposes described in this document and in the Cookie Policy, where available. The User assumes responsibility for third-party Personal Data obtained, published or shared through this Application and guarantees that they have the right to disclose or disseminate them, releasing the Data Controller from any liability towards third parties.
Methods and place of processing the collected Data
Methods of processing
The Data Controller adopts appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of Personal Data. Processing is carried out using computers and/or IT tools, following organisational procedures and methods strictly related to the stated purposes.
In addition to the Data Controller, in some cases the Data may be accessible to other parties involved in the operation of this Application (administrative, sales, marketing, legal and system administration personnel) or to external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies and communications agencies), appointed, where necessary, as Data Processors by the Data Controller. An updated list of Data Processors may be requested from the Data Controller at any time.
Legal basis of processing
The Data Controller processes Personal Data relating to the User where one of the following conditions applies:
the User has given consent for one or more specific purposes. Note: under some jurisdictions, the Data Controller may be permitted to process Personal Data without the User’s consent or another of the legal bases specified below until the User objects (“opts out”). This does not apply, however, where the processing of Personal Data is governed by European data protection law;
- processing is necessary for the performance of a contract with the User and/or for taking pre-contractual steps;
- processing is necessary to comply with a legal obligation to which the Data Controller is subject;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
- processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or a third party.
- The User may always ask the Data Controller to clarify the specific legal basis of each processing activity, particularly whether processing is based on law, required by a contract or necessary to enter into a contract.
Place
Data are processed at the Data Controller’s operating offices and at any other locations where the parties involved in processing are based. For further information, please contact the Data Controller. The User’s Personal Data may be transferred to a country other than the one in which the User is located. Further information on the place of processing can be found in the section detailing the processing of Personal Data.
The User has the right to obtain information about the legal basis for transferring Data outside the European Union or to an international organisation governed by public international law or established by two or more countries, such as the United Nations, and about the security measures adopted by the Data Controller to safeguard the Data. If any such transfer takes place, the User may refer to the relevant sections of this document or contact the Data Controller using the details provided at the beginning.
Retention period
Data are processed and stored for as long as required by the purposes for which they were collected.
Therefore:
- Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until that contract has been fully performed.
- Personal Data collected for the purposes of the Data Controller’s legitimate interests will be retained for as long as needed to fulfil those interests. The User may obtain further information about the legitimate interests pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
Where processing is based on consent, the Data Controller may retain Personal Data for longer until that consent is withdrawn. The Data Controller may also be required to retain Personal Data for a longer period to comply with a legal obligation or an order from an authority.
Personal Data will be deleted at the end of the retention period.
Consequently, the rights of access, erasure, rectification and data portability cannot be exercised after the retention period has expired.
Purposes of processing the collected Data
The User’s Data are collected to enable the Data Controller to provide its Services, as well as for the following purposes: registration and authentication, and contacting the User. For more detailed information about the purposes of processing and the Personal Data used for each purpose, the User may refer to the relevant sections of this document.
Details of the processing of Personal Data
Personal Data are collected for the following purposes and using the following services:
- Contacting the User
Contact form (this Application)
By completing the contact form with their Data, the User consents to their use to respond to requests for information, quotations or any other request indicated by the form’s heading.
Personal Data collected: surname, email address and first name. - Registration and authentication
By registering or authenticating, the User allows the Application to identify them and give them access to dedicated services. Depending on the arrangements described below, registration and authentication services may be provided with the assistance of third parties. Where this occurs, this Application may access certain Data stored by the third-party service used for registration or identification.
Personal Data collected: surname, date of birth, email address, first name and gender.
User rights
Users may exercise certain rights regarding the Data processed by the Data Controller. In particular, the User has the right to: - withdraw consent at any time. The User may withdraw consent previously given to the processing of their Personal Data.
- object to the processing of their Data. The User may object to processing based on a legal basis other than consent. Further details about the right to object are provided below.
- access their Data. The User has the right to obtain information about the Data processed by the Data Controller and certain aspects of processing, and to receive a copy of the Data processed.
- verify and request rectification. The User may verify the accuracy of their Data and request that they be updated or corrected.
- restrict the processing of their Data. Under certain circumstances, the User may request restriction of processing. In this case, the Data Controller will not process the Data for any purpose other than storage.
- have their Personal Data deleted or otherwise removed. Under certain circumstances, the User may request that the Data Controller erase their Data.
- receive their Data or have them transferred to another controller. The User has the right to receive their Data in a structured, commonly used, machine-readable format and, where technically feasible, to have them transferred to another controller without hindrance. This applies where Data are processed by automated means and processing is based on the User’s consent, on a contract to which the User is a party or on pre-contractual measures related to that contract.
- lodge a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.
Details of the right to object
Where Personal Data are processed in the public interest, in the exercise of official authority vested in the Data Controller or for the purposes of the Data Controller’s legitimate interests, Users may object to processing on grounds relating to their particular situation.
Where Personal Data are processed for direct marketing purposes, Users may object without providing any justification. To find out whether the Data Controller processes Data for direct marketing purposes, Users may refer to the relevant sections of this document.
How to exercise your rights
To exercise their rights, Users may contact the Data Controller by sending:
– a registered letter with acknowledgement of receipt to The Base srl, with registered office at Viale del Poggio Fiorito, 27, 00144 Roma RM;
– an email to [email protected]
Further information about processing
Legal proceedings
The User’s Personal Data may be used by the Data Controller in legal proceedings, or in preparation for possible legal action, to protect against misuse of this Application or related Services by the User. The User acknowledges that the Data Controller may be required to disclose Data at the request of public authorities.
Specific notices
At the User’s request, in addition to the information contained in this privacy policy, this Application may provide further contextual information concerning specific Services or the collection and processing of Personal Data.
System logs and maintenance
For operational and maintenance purposes, this Application and any third-party services it uses may collect system logs: files recording interactions that may also contain Personal Data, such as the User’s IP address.
Information not contained in this policy
Further information about the processing of Personal Data may be requested from the Data Controller at any time using the contact details provided.
Responses to Do Not Track requests
This Application does not support “Do Not Track” requests. To find out whether any third-party services used support them, Users should consult the respective privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to amend this privacy policy at any time by notifying Users on this page and, where possible, within this Application and/or, where technically and legally feasible, by sending a notice using any contact details available to the Data Controller. Users are therefore asked to check this page regularly, referring to the date of the latest update indicated at the bottom.
Where changes affect processing based on consent, the Data Controller will obtain fresh consent from the User where necessary.
Definitions and legal references
Personal Data (or Data)
Any information that directly or indirectly, including in combination with other information such as a personal identification number, identifies or makes it possible to identify a natural person.
Usage Data
Information collected automatically through this Application or third-party applications integrated into it, including the IP addresses or domain names of the computers used by Users connecting to this Application, URI (Uniform Resource Identifier) addresses, the time of a request, the method used to submit it to the server, the size of the response file, the numerical code indicating the status of the server’s response (successful, error, etc.), the country of origin, the characteristics of the User’s browser and operating system, details of the time spent on each visit (such as time spent on individual pages), and details of the path followed within the Application, particularly the sequence of pages visited, together with parameters relating to the User’s operating system and IT environment.
User
The individual using this Application who, unless otherwise specified, is the Data Subject.
Data Subject
The natural person to whom the Personal Data relate.
Data Processor (or Processor)
The natural or legal person, public authority, agency or other body that processes Personal Data on behalf of the Data Controller, as described in this privacy policy.
Data Controller (or Controller)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing Personal Data, including the security measures relating to the operation and use of this Application. Unless otherwise specified, the Data Controller is the owner of this Application.
This Application
The hardware or software tool through which Users’ Personal Data are collected and processed.
Service
The service provided by this Application as described in the relevant terms, where applicable, on this website/application.
European Union (or EU)
Unless otherwise specified, references to the European Union in this document include all current Member States of the European Union and the European Economic Area.
Legal references
This privacy policy is based on several legal provisions, including Articles 13 and 14 of Regulation (EU) 2016/679. Unless otherwise specified, this privacy policy relates solely to this Application.
Cookie Policy
1. What cookies are
A cookie is a short piece of text sent to your browser by a website you visit. It allows the website to remember information about your visit, such as your preferred language and other settings. This can make subsequent visits easier and make the site more useful.
Cookies are used for various purposes, such as remembering your preferences, counting visitors and managing registration and authentication.
Session cookies are essential to ensure the website functions correctly. They do not contain personal data and last only for the current session, until the browser is closed. They do not require consent.
The functionality cookies used by the site are strictly necessary for its use and do not require consent.
2. Third-party cookies
This site also acts as an intermediary for third-party cookies used to provide certain features to visitors and improve the use of the site. This site has no control over these cookies, which are managed entirely by the relevant third parties. Information about their use and purposes, and how to disable them, is therefore provided directly by those third parties.
This site uses the following third-party services:
– Google Analytics, which uses performance cookies to collect anonymous browsing data (with IP addresses truncated at the last octet), exclusively in aggregate form, to examine how users use the site. Further information about Google Analytics cookies is available on the Google Analytics Cookie Usage on Websites page. Users may selectively disable the collection of data by Google Analytics by installing Google’s browser add-on (https://tools.google.com/dlpage/gaoptout).
Privacy and cookie information
For further information about Google’s use and processing of data, please consult its dedicated privacy page (https://policies.google.com/privacy?hl=en) and the page explaining how Google uses data when you use its partners’ sites or apps (https://policies.google.com/technologies/partnersites?hl=en).
3. Types of cookies used
This site uses only:
– session cookies to ensure correct operation in terms of navigation and the active language;
– functionality cookies to manage the display of the cookie notice.
By using the site, visitors expressly consent to the use of the cookies described in this notice.
4. Disabling cookies
Cookies are associated with the browser and can be disabled directly in the browser, thereby refusing or withdrawing consent to their use. Please note that disabling cookies may prevent certain features of the site from working correctly.