225 lines
20 KiB
PHP
225 lines
20 KiB
PHP
<!DOCTYPE html>
|
||
<html lang="en">
|
||
|
||
<head>
|
||
<meta charset="utf-8" />
|
||
<title>CIMAC Cookie Policy</title>
|
||
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
|
||
<meta content="Cookie Policy for PPeasy Platform" name="description" />
|
||
<meta content="Paola Crespi" name="author" />
|
||
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
|
||
|
||
<!-- App favicon -->
|
||
<link rel="shortcut icon" href="../assets/images/favicon.ico">
|
||
|
||
<!-- App css -->
|
||
<link href="assets/css/bootstrap.min.css" rel="stylesheet" type="text/css" />
|
||
<link href="assets/css/jquery-ui.min.css" rel="stylesheet">
|
||
<link href="assets/css/icons.min.css" rel="stylesheet" type="text/css" />
|
||
<link href="assets/css/metisMenu.min.css" rel="stylesheet" type="text/css" />
|
||
<link href="assets/css/app.min.css" rel="stylesheet" type="text/css" />
|
||
|
||
<style type="text/css">
|
||
.auth-logo-text {
|
||
text-align: left;
|
||
}
|
||
|
||
.auth-logo-text p,
|
||
.auth-logo-text strong,
|
||
.auth-logo-text span,
|
||
.auth-logo-text a {
|
||
text-align: left;
|
||
margin-bottom: 10px;
|
||
line-height: 1.5;
|
||
font-size: 10pt;
|
||
font-family: Calibri, sans-serif;
|
||
color: black;
|
||
}
|
||
|
||
.auth-logo-text p:first-child strong {
|
||
font-size: 14pt;
|
||
}
|
||
|
||
.auth-logo-text strong {
|
||
font-weight: bold;
|
||
}
|
||
|
||
.auth-logo-text a {
|
||
color: #00F;
|
||
text-decoration: underline;
|
||
}
|
||
|
||
.auth-logo-text p+p,
|
||
.auth-logo-text p+strong,
|
||
.auth-logo-text strong+p,
|
||
.auth-logo-text strong+strong {
|
||
margin-top: 20px;
|
||
}
|
||
|
||
.privacy-title {
|
||
font-size: 18pt !important;
|
||
font-weight: bold;
|
||
margin-bottom: 20px;
|
||
}
|
||
|
||
.cookie-table {
|
||
width: 100%;
|
||
border-collapse: collapse;
|
||
margin: 20px 0;
|
||
}
|
||
|
||
.cookie-table th,
|
||
.cookie-table td {
|
||
border: 1px solid #ddd;
|
||
padding: 8px;
|
||
text-align: left;
|
||
font-family: Calibri, sans-serif;
|
||
font-size: 10pt;
|
||
}
|
||
|
||
.cookie-table th {
|
||
background-color: #f2f2f2;
|
||
font-weight: bold;
|
||
}
|
||
|
||
.indented {
|
||
margin-left: 20px;
|
||
}
|
||
</style>
|
||
</head>
|
||
|
||
<body class="account-body accountbg">
|
||
|
||
<!-- Cookie Policy page -->
|
||
<div class="container">
|
||
<div class="row vh-100">
|
||
<div class="col-12 align-self-center">
|
||
<div>
|
||
<div class="card auth-card shadow-lg">
|
||
<div class="card-body">
|
||
<div class="px-5">
|
||
<div>
|
||
<a href="https://www.cimac.it/modulo_certificazione/public/login" class="logo logo-admin"><img src="assets/img/cimac-logo.png" height="55" alt="logo" class="auth-logo"></a>
|
||
</div><!--end auth-logo-box-->
|
||
|
||
<div class="text-center auth-logo-text">
|
||
<br>
|
||
<p class="privacy-title">Cookie Policy</p>
|
||
|
||
<p><strong>Introduction</strong></p>
|
||
<p>Dear User,<br>
|
||
Anci Servizi s.r.l. with sole shareholder, B.U. Cimac (hereinafter referred to as the “Controller” pursuant to Article 26 of European Regulation 2016/679), following the new Guidelines on cookies and other tracking tools issued by the Supervisory Authority on June 10, 2021—which can be consulted at the following address: <a href="https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9677876">Linee guida cookie e altri strumenti di tracciamento - 10 giugno 2021</a>—and in accordance with the provisions of European Regulation 2016/679 (hereinafter also “GDPR”), hereby informs users of the website, in general terms, as follows and, in detail, through the table provided in the subsequent point 4, regarding the cookies and other tracking systems and technical identifiers specifically used on the website you are browsing.</p>
|
||
|
||
<p><strong>1. Cookies</strong></p>
|
||
<p>A cookie is a small text file placed by a website on the user's hard drive. Specifically, these are strings of text that websites (so-called publishers or “first parties”) visited by the user, or different websites or web servers (so-called “third parties”), place and store—directly in the case of publishers and indirectly through them in the case of third parties—on a terminal device available to the user. Cookies uniquely identify the browser or allow access to information on the user's terminal.<br>
|
||
As noted by the Supervisory Authority in its June 2021 decision, “... Terminals refer to, for example, a computer, tablet, smartphone, or any other device capable of storing information ... including IoT (Internet of Things) devices ...”. Cookies do not damage the computer and do not contain viruses. They streamline web traffic analysis or indicate when a specific site is visited, allowing web applications to send information to individual users.</p>
|
||
<p><strong>Why are cookies used?</strong></p>
|
||
<p>Cookies are necessary for the operation of the website (technical cookies) to optimize performance and provide better browsing experiences (so-called navigation cookies). They offer users a smooth and simplified browsing experience, avoiding the need to re-enter the same information on each visit. Cookies perform various functions, including session monitoring, storing configuration information for users accessing the server, and facilitating online content usage (e.g., tracking items in an online shopping cart or form data).<br>
|
||
The Supervisory Authority notes that similar results can be achieved using other tools such as “tracking tools” and “passive identifiers,” which involve merely observing the user and allow similar processing to cookies. Passive tools include, for example, fingerprinting.<br>
|
||
Information encoded in cookies may include personal data (e.g., username, unique identifier, email address, IP address) or non-personal data (e.g., language settings, device type used for browsing).<br>
|
||
Only the cookies listed in the table in point 4 are used on this website.</p>
|
||
|
||
<p><strong>2. Types of Cookies and Classification Methods</strong></p>
|
||
<p>Cookies can be classified by lifecycle:<br>
|
||
<span class="indented"><strong>Session Cookies:</strong> Placed during a website visit and removed when the user leaves the site and closes the browser. Stored in temporary memory, they allow a website to track a user across pages. Websites use cookies (see <a href="https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9677876">Linee guida cookie e altri strumenti di tracciamento - 10 giugno 2021</a>) because they lack their own memory. These cookies act like keys—if your computer has the key, the site grants access without treating you as a new visitor. These cookies are not stored persistently and are deleted when the browser is closed.</span><br>
|
||
<span class="indented"><strong>Persistent Cookies:</strong> Stored on the computer for a longer period and removed only after expiration or manual deletion. During their lifespan, information is transmitted to the server each time the user visits the site or views a resource from the site (e.g., an ad). They store login details and remember preferences or settings. Mostly used to monitor user behavior and improve user experience.</span>
|
||
</p>
|
||
<p>Cookies can also be classified by origin:<br>
|
||
<span class="indented"><strong>First-party Cookies:</strong> Sent directly by the site being visited and managed by the site owner.</span><br>
|
||
<span class="indented"><strong>Third-party Cookies:</strong> Sent by domains different from the one in the address bar, often appearing when pages include external content (e.g., ads). These cookies may track browsing history and are used by advertisers to serve personalized ads.</span>
|
||
</p>
|
||
<p>Cookies can be classified by purpose:<br>
|
||
<span class="indented"><strong>Technical Cookies:</strong> Necessary for navigation and service delivery.</span><br>
|
||
<span class="indented"><strong>Statistical Cookies:</strong> Used by the site owner to optimize the site by collecting aggregated user data.</span><br>
|
||
<span class="indented"><strong>Preference Cookies (Functional Cookies):</strong> Enhance site usability and personalize browsing experience.</span><br>
|
||
<span class="indented"><strong>Marketing and Profiling Cookies:</strong> Used to build a user profile and deliver targeted ads.</span><br>
|
||
<span class="indented"><strong>Social Network Cookies:</strong> Allow social networks (e.g., Facebook) to identify users and collect data while browsing other sites.</span>
|
||
</p>
|
||
|
||
<p><strong>3. Other Tracking Tools and Technical Identifiers</strong></p>
|
||
<p>The Data Protection Authority, on this web page <a href="https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9677876">Linee guida cookie e altri strumenti di tracciamento - 10 giugno 2021</a>, explores the subject in greater depth through a summary sheet of its guidelines on cookies and other tracking tools.<br>
|
||
In this context, the Data Controller wishes to remind users that tracking tools may have different characteristics in terms of duration and, therefore, may be considered based on their lifespan (session or persistent), or from a subjective perspective (depending on whether the publisher acts independently or on behalf of a “third party”).<br>
|
||
Identifiers may be categorized according to various criteria, the main one being the purpose for which they are used: either “technical” or “non-technical” in nature, with the latter category to be interpreted broadly, since the current legal framework—aimed at protecting the confidentiality of electronic communications as well as personal information—is structured as a general prohibition on the processing of data subjects’ information, except for exceptions that are strictly and narrowly codified and not subject to analogical extension.<br>
|
||
In the following point 4, the Data Controller, in compliance with the aforementioned provision, highlights—by means of a table—the tracking systems and technical identifiers present, where applicable, on the website you are browsing.</p>
|
||
|
||
<p><strong>4. Technical Cookies Used</strong></p>
|
||
<p>The Data Controller, through the service provided by C.E. Soft s.r.l., uses only technical cookies necessary for the proper functioning of the web application. These cookies do not require user consent, as they are solely used to ensure essential functionality and secure browsing, without profiling or tracking purposes.<br>
|
||
Following the most important information about active cookies:</p>
|
||
<table class="cookie-table">
|
||
<tr>
|
||
<th>Cookie</th>
|
||
<th>Purposes</th>
|
||
<th>Category</th>
|
||
<th>Duration</th>
|
||
<th>Notes</th>
|
||
</tr>
|
||
<tr>
|
||
<td>laravel_session</td>
|
||
<td>Maintains authenticated user session</td>
|
||
<td>Technical</td>
|
||
<td>Session (browser closure)</td>
|
||
<td>Securely stored, linked to server-side data</td>
|
||
</tr>
|
||
<tr>
|
||
<td>XSRF-TOKEN</td>
|
||
<td>Protects against CSRF attacks</td>
|
||
<td>Technical</td>
|
||
<td>Session</td>
|
||
<td>Secure token, no sensitive data, read by JavaScript</td>
|
||
</tr>
|
||
</table>
|
||
<p>As these cookies are strictly necessary, they cannot be disabled via the application, as their removal would compromise the web application's functionality.</p>
|
||
|
||
<p><strong>5. Your Rights and How to Exercise Them</strong></p>
|
||
<p>I diritti riconosciuti agli interessati dal GDPR sono:<br>
|
||
<span class="indented">art. 15 – Right of access: the data subject/user has the right to obtain information about which of their personal data is being processed by the Controller, the purposes pursued, the duration for which such data will be retained, and the methods with which said data is processed.</span><br>
|
||
<span class="indented">art. 16 – Right to rectification: the data subject/user has the right to verify the accuracy of their data and to request any modifications or additions.</span><br>
|
||
<span class="indented">art. 17 – Right to erasure: the data subject/user may request the erasure of their data under certain conditions, such as, for example, when the personal data is no longer necessary for the purpose for which it was collected.</span><br>
|
||
<span class="indented">We reserve the right to decline your request for erasure (pursuant to art. 17 GDPR) for any of the following reasons:</span><br>
|
||
<span class="indented"> - to exercise the right to freedom of expression and information;</span><br>
|
||
<span class="indented"> - to comply with legal obligations or carry out a task in the public interest or exercise official authority;</span><br>
|
||
<span class="indented"> - for reasons of public health in the public interest;</span><br>
|
||
<span class="indented"> - for archiving, research, or statistical purposes;</span><br>
|
||
<span class="indented"> - to establish, exercise, or defend a legal claim.</span><br>
|
||
<span class="indented">art. 18 – Right to restriction of processing: the data subject/user may request a restriction on processing activities concerning their data under certain conditions, such as, for example, if the data was acquired for a specific purpose unlawfully.</span><br>
|
||
<span class="indented">art. 20 – Right to data portability: the user/data subject has the right to receive their data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another controller when the data is processed by automated means and the processing is based on the User’s consent, on a contract to which the User is party, or on related contractual measures.</span><br>
|
||
<span class="indented">art. 21 – Right to object: the user/data subject has the right to object to the processing of their data when such processing is based on legal grounds other than consent, for reasons related to their particular situation; when, on the other hand, the legal basis is consent, the data subject/user may object at any time, but the processing carried out up to that point remains lawful.</span><br>
|
||
<span class="indented">art. 22 – Automated decision-making regarding individuals, including profiling: except for specific exemptions expressly provided for by law, the data subject/user has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them.</span>
|
||
</p>
|
||
<p>To exercise the rights listed above or for further information, simply send an e-mail to the following address: <a href="mailto:privacy@assocalzaturifici.it">privacy@assocalzaturifici.it</a>, indicating in the subject “cookies policy: exercise of rights under GDPR” and specifying in the body of the e-mail the right you wish to exercise and, if applicable, the e-mail address at which you wish to receive a response.<br>
|
||
The Data Controller will respond to the exercise of rights within the timeframes specified in art. 12, paragraph 3, GDPR. Please remember that you have the right to lodge a complaint with a supervisory authority (Data Protection Authority: <a href="https://www.garanteprivacy.it">www.garanteprivacy.it</a>).</p>
|
||
|
||
<p><strong>6. Data Breach</strong></p>
|
||
<p>If the Data Controller suffers a data breach as defined in Article 34, posing a risk to individuals’ rights and freedoms, it will—if necessary—notify the Supervisory Authority and inform affected individuals.</p>
|
||
|
||
<p><strong>7. Different Purposes</strong></p>
|
||
<p>If the Data Controller intends to process personal data for purposes other than those for which it was collected, it will first provide the data subject with information about the new purpose and obtain specific consent if required.</p>
|
||
|
||
</div><!--end auth-logo-text-->
|
||
|
||
<h4 class="mt-0 mb-3 mt-5"></h4>
|
||
<br><br><br><br><br><br><br><br><br><br><br><br><br>
|
||
|
||
</div><!--end card-body-->
|
||
</div><!--end card-->
|
||
</div><!--end auth-card-->
|
||
</div><!--end col-->
|
||
</div><!--end row-->
|
||
</div><!--end container-->
|
||
<!-- End Cookie Policy page -->
|
||
|
||
<!-- jQuery -->
|
||
<script src="assets/js/jquery.min.js"></script>
|
||
<script src="assets/js/jquery-ui.min.js"></script>
|
||
<script src="assets/js/bootstrap.bundle.min.js"></script>
|
||
<script src="assets/js/metismenu.min.js"></script>
|
||
<script src="assets/js/waves.js"></script>
|
||
<script src="assets/js/feather.min.js"></script>
|
||
<script src="assets/js/jquery.slimscroll.min.js"></script>
|
||
|
||
<!-- App js -->
|
||
<script src="../assets/js/app.js"></script>
|
||
|
||
</body>
|
||
|
||
</html> |