ex-or.ae Privacy Policy

This Website gathers Personal Data from its Users.

Data Controller

Paolo Balossi

EXOR HOLDING SA
Piazza Dante Alighieri 8 – CH6900 Lugano – Ti – Switzerland
Data Controller’s email address: p.balossi@ex-or.ae

Gathered Data Category

This Website gathers personal data – such as email; first name; last name; cookies; usage data – independently or via third parties.

For further details on each category of gathered data, see the relevant sections in this Privacy Policy, or the specific informative texts displayed before data collection.
Personal Data may be spontaneously provided by you, or, in case of usage data, automatically gathered while using this Website.
Unless otherwise specified, all Data requested by this Website are mandatory. If you refuse to provide them, it may be impossible for this Website to supply the relevant services. If some of the Data is marked as optional on this Website, you are free to abstain from providing such data, without any consequence on the service’s availability or operation.
Should you have any doubts on what Data is mandatory, please contact the Data Controller.
Cookies – or other tracking tools – are used by this Website or by the providers of third-party services used by this Website, unless otherwise specified, to provide the Service requested by you, and for any additional purpose described in this document and in the Cookie Policy, if applicable.

You shall be liable for any third-party Personal Data obtained, published or shared via this Website, and warrant that you have the right to reveal or disclose them, holding the Controller harmless against any liability toward third parties.

Data processing methods and place

Processing methods

The Controller shall adopt suitable security measures to prevent any unauthorized access, disclosure, modification and distribution of Personal Data.
Processing is carried out with IT and/or telematic tools, and with organizational methods and logics closely related to the purposes stated herein. Apart from the Controller, in certain cases, the Data may be accessible to other persons involved in the Website organization (administrative, commercial, marketing and legal staff and system administrators), or external parties (such as providers of third-party technical services, couriers, hosting providers, IT enterprises, communication agencies), including those appointed as Data Supervisor by the Controller, if applicable. You can request the updated list of Data Supervisor to the Data Controller at any time.

Legal basis of the processing

The Controller shall process your Personal Data if at least one of the following conditions is met:

  • You have consented to one or more specific purposes; Note: in some jurisdictions, the Controller may be authorized to process Personal Data without the User’s consent, or with another legal basis specified below, unless the User opts out from such processing. However, this does not apply if Personal Data processing is governed by the European regulation on Personal Data Protection;
  • Processing is required to perform a contract stipulated with you and/or execute certain pre-contractual measures;
  • Processing is required to fulfil a legal obligation the Controller is subjected to;
  • Processing is required to perform a task of public interest or to exercise the Controller’s public authority;
  • Processing is required to pursue the Controller or third-party’s legal interests.

In any case, you may always ask the Controller to clarify the actual legal basis for processing, and, in particular, to specify whether the processing is based on the Law, included in a contract or required to stipulate a contract.

Place

Your Data shall be processed at the Controller’s operating headquarters and in any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.
Your Personal Data may be transferred to another country. For further information on the processing place, you can refer to the section on Personal Data Processing.

You have the right to obtain information on the legal basis for Data transfer outside of the European Union or to an international public law organization or comprising two or more Countries – such as the UN – and on the security measures adopted by the Controller to protect your Data.

Furthermore, you may ascertain if one of the transfers described above has occurred, by referring to the section on Personal Data Processing herein, or by asking the Data Controller at the contract details listed above

Retention Period

Your Data shall be processed and stored for the period required by the purposes for which they were gathered in the first place.

Therefore:

  • I Personal Data collected for purposes related to the performance of a contract between you and the Data Controller shall be retained until the performance of such contract is fully completed.
  • Personal Data collected for purposes related to the Data Controller’s legal interest shall be retained until such interest is fulfilled. For further information on the Controller’s legal interest, see the relevant sections of this document or contact the Controller.

If processing is based on your consent, the Controller may retain your Personal Data as long as such consent is not revoked. Furthermore, the Data Controller may be required to retain your Personal Data longer, to comply with a legal obligation or by government order.

At the end of the retention period, your Personal Data shall be deleted. Therefore, at the end of such term, you may no longer exercise the right to access, cancel, modify and transfer your Data.

Purposes of Data Processing

Your Data are collected to allow the Data Controller to provide its Services, and for the following purposes: Contacting the user; Managing tags; Traffic optimization and distribution; Protection against SPAM; Registration and authentication; Platform and hosting services; Statistics; Content viewing from external platforms; Interaction with social media and external platforms; Content feedback; Contact info management and sending messages; User database management.

For detailed information on the purposes of Data processing and on the Personal Data concretely relevant for each purpose, see the related sections in this document.

Details on Personal Data Processing

Personal Data are gathered for the following purposes, and using the following services:

  • Content Feedback

    Feedback services allow users to formulate and post their feedback on the contents on this Website.
    Based on the Data Controller’s settings, users may also leave anonymous feedback. If the email is included in the Personal Data provided by you, it may be used to send notifications on feedback made on the same content. Users are responsible for the content of their feedback.
    If a third-party feedback service is installed, it might gather traffic data on the pages where the feedback service is present, even if you don’t use it.

    Feedback system operated directly (this Website)

    This Website has its own content feedback system.
    Personal Data gathered: last name; email; first name; website.

  • Contattare l’Utente

    Mailing list o newsletter (questo Sito Web)

    By subscribing to our mailing list or newsletter, your email address will be automatically included in a list of contacts, and you may receive emails containing information – including marketing and promotional material – related to this Website. Your email address may also be included in this list after registering to our Website or after making a purchase.

    Personal Data gathered: last name; email; first name; message.

    Contact form (this Website)

    By filling out the contact form with your Data, you consent to their use to reply to information or quote requests, or any other request indicated in the form heading.

    Personal Data gathered: last name; email; first name; various types of Data.

  • Contact info management and sending messages

    This type of services is used to manage an email, telephone or other contact info database, used to communicate with you.
    Furthermore, these services may also gather data on the message display date and time, on your interactions with them, and on the message links clicked on.

    Mailchimp (The Rocket Science Group, LLC.)

    Mailchimp is an address management and email sending services provided by The Rocket Science Group, LLC.

    Personal Data gathered: last name; email; first name.

    Place of processing: United States – Privacy Policy. . Participating in the Privacy Shield.

  • User database management

    This type of service allows the Data Controller to create user profiles starting from the email address, name or any other data supplied by you to this Website, as well as tracking your activities via statistics tools. These Personal Data may also be crossed with publicly-available user information (such as social media profiles) and used to build private profiles that the Controller may view and use to improve this Website.
    In addition, some of these service may allow scheduled sending of messages to users, such as emails based on specific actions performed on this Website.

    Personal Data Management

    You can access your Personal Data gathered by this Website, by sending an email to p.balossi@ex-or.ae or using this form Personal Data Management

  • Tag Management

    This type of services is essential for the central management of tags and scripts used in this Website.
    Using these services entails a Personal Data flow through them, and their retention, if applicable.

    Google Tag Manager (Google LLC)

    Google Tag Manager is a tag management service provided by Google LLC.

    Personal Data gathered: Cookies; Usage data.

    Place of processing: United States –Privacy Policy.. Participating in the Privacy Shield.

  • Interaction with social media and external platforms

    This type of services is used to interact with social media or other external platforms directly from the pages of this Website.
    Nevertheless, any interaction and information acquired by this Website is subjected to your Privacy settings in each social media platform.
    If a third-party social media interaction service is installed, it might gather traffic data on the pages where the service is present, even if you don’t use it.

  • Traffic optimization and distribution

    This type of services allows the Website to distribute their content via servers located across the nation and optimize its performance.
    Personal Data processed depend on the characteristics and methods of implementation of these services, which, due to their nature, filter any communication between this Website and your browser.
    Given the scattered nature of this system, actually determining where contents that may contain your Personal Data are transferred is very difficult.

    Cloudflare (Cloudflare Inc.)

    Cloudflare is a traffic optimization and distribution service provided by Cloudflare Inc.
    Cloudflare’s integration methods require it to filter the entire Website traffic, i.e. any communication between this Website and your browser, whilst gathering statistical data on it.

    Personal Data gathered: Cookies; various types of data, as specified in the service’s Privacy Policy.

    Place of processing: United States – Privacy Policy.

  • Protection against SPAM

    This type of services analyses the traffic on this Website – which might include your Personal Data – in order to protect it against traffic portions, messages and contents recognized as SPAM.

    Google reCAPTCHA (Google LLC)

    Google reCAPTCHA is a SPAM protection service provided by Google LLC.
    Use of the reCAPTCHA system is subject to Google’s Privacy Policy andTerms of Use. di Google.

    Personal Data gathered: Cookies; Usage data.
    Place of processing: United States – Privacy Policy. Participating in the Privacy Shield.

  • Registration and authentication

    When you register or login to the Website, the Application will identify you and grant you access to targeted services.
    Depending on the specifications set out below, registration and authentication services may be supplied with third-party services. In this case, the Application may have access to some of the Data retained by the third-party service used for registering or log in.

    WordPress.com Single Sign On (Automattic Inc.)

    WordPress.com Single Sign On is a registration and authentication service provided by Automattic Inc. and connected to WordPress.com network.

    Personal Data gathered: various types of data, as specified in the service’s Privacy Policy.

    Place of processing: United States – Privacy Policy.

  • Platform and hosting services

    The purpose of these services is hosting some key components of this Website and making them functional, thus allowing this Website to be hosted on a single platform. These platform provide a wide range of tools to the Data Controller, such as, for instance, analytical tools, user registration management tools, feedback and database management tools, e-commerce tools, payment processing tools, etc. Use of these tools entails Personal Data gathering and processing. Some of these services work via servers that are located in different places, making it hard to actually determine where your Personal Data are stored.

    WordPress.com (Automattic Inc.)

    WordPress.com is a platform provided by Automattic Inc. and allowing the Data Controller to develop, operate and host this Website.

    Personal Data gathered: various types of data, as specified in the service’s Privacy Policy.
    Place of processing: United States – Privacy Policy.

      SiteGround Spain S.L.

    For further information, refer to Privacy Policy di SiteGround

  • Statistics

    The services contained in this section allow the Data Controller to monitor and analyse traffic data and track user behaviour.

    WordPress Stat (Automattic Inc.)

    WordPress Stats è un servizio di statistica fornito da Automattic Inc.

    WordPress Stats is a statistics service provided by Automattic Inc.
    Personal Data gathered: Cookies; Usage data.
    Place of processing: United States –Privacy Policy.

    Google Analytics con IP anonimizzato (Google LLC)

    Google Analytics is a web analysis service provided by Google LLC (“Google”). Google uses Personal Data gathered to track and analyse the use of this Website, create reports and share them with other services developed by Google.
    Google may use your Personal Data to contextualize and customize the ads of its advertisement network.
    This Google Analytics integration makes your IP address anonymous. Anonymisation works by shortening users’ IP addresses within the borders of European Member States or in other Countries participating in the European Economic Area agreement. Only in exceptional cases, the IP address will be forwarded to Google’s servers and shortened in the United States.

    Personal Data gathered: Cookies; Usage data.
    Place of processing: United States –Privacy Policy – Opt Out. Participating in the Privacy Shield.

    Google Analytics (Google LLC)

    Google Analytics is a web analysis service provided by Google LLC (“Google”). Google uses Personal Data gathered to track and analyse the use of this Website, create reports and share them with other services developed by Google.
    Google may use your Personal Data to contextualize and customize the ads of its advertisement network.
    Personal Data gathered: Cookies; Usage data.
    Place of processing: United States – Privacy Policy – Opt Out. articipating in the Privacy Shield.

  • Content viewing from external platforms

    This type of services is used to view contents hosted on external platforms directly from the pages of this Website and interact with them.
    If this kind of service is installed, it might gather traffic data on the pages where the service is present, even if you don’t use it.

    Widget Video YouTube (Google LLC)

    YouTube is a video content viewing service managed by Google LLC and allowing this Website to integrate these contents in its pages.
    Personal Data gathered: Cookies; Usage data.
    Place of processing: United States –Privacy Policy. Participating in the Privacy Shield.

    Google Maps Widget (Google LLC)(Google LLC)

    Google Maps is a map viewing service managed by Google LLC and allowing this Website to integrate these contents in its pages.

    Personal Data gathered: Cookies; Usage data.
    Place of processing: United States –Privacy Policy. Participating in the Privacy Shield.

User rights

You can exercise the following rights on the Data processed by the Data Controller.

In particular, you have the right to:

  • revoke your consent at any time. You can revoke your consent to Personal Data processing previously expressed.
  • object to Personal Data processing.  You can object to Personal Data processing if carried out on a different legal basis than the one you consented to. For further details on the right to object, see the following section.
  • access your Data. You have the right to obtain information on the Data processed by the Data Controller and on certain processing aspect, and receive a copy of the Data processed.
  • check your Data and ask to modify them. You can check if your Data are correct and ask for their update or correction.
  • obtain processing limitations. Under certain conditions, you can request processing limitations for your Personal Data. In this case, the Data Controller shall not process your Data for any purpose other than retention.
  • obtain the cancellation or removal of your Personal Data. Under certain conditions, you can request the Data Controller to cancel your Data.
  • receive your Data or transfer them to another Data Controller You have the right to receive your Data in a structured, commonly-used format readable from an automatic device, and, if technically feasible, obtaining their unhindered transfer to another Data Controller. This provision applies when Data is treated with automated tools and processing is consent-based, on a contract stipulated with you or on relevant contractual measures.
  • lodge a complaint. You can lodge a complaint with the Data Protection supervisory authority or engage in legal proceedings.
Details on the right to object

If Personal Data are processed in the public interest, to exercise the Data Controller’s public authority, or to pursue the Controller’s legal interest, the Users have the right to object to processing for reasons related to their peculiar situation.
It should be noted that, if your Personal Data are processed for direct marketing purposes, you may object to their processing without stating any reason. To find out if the Data Controller is processing your Data for direct marketing purposes, refer to the relevant sections in this document.

How to exercise your rights

In order to exercise your rights, you can make a request by contacting the Data Controller at the contact details indicated herein. Requests are submitted for free and processed by the Data Controller in the shortest time possible, no later than one month.

This Website utilizes Cookies. For more information and to see the detailed document, refer to the Cookie Policy.

Further processing information

Legal defence

Your Personal Data may be used by the Data Controller for legal defence or in the preparatory stages of any proceedings against misuse of this Website or the related Services filed by users.
You declare to be aware that the Data Controller may be compelled to disclose your Data on the orders of the Public Authorities.

Specific policies

Upon your request, in addition to the information contained in this Privacy Policy, this Website may provide additional and context-related info related to specific Services or to Personal Data gathering and processing.

System log and maintenance

For operating and maintenance purposes, this Website, and any third party services employed by the same, may collect system logs – files recording user interactions – which may also include Personal Data, such as the User IP address.

Information not included in this Policy

You can request further information on Personal data processing to the Data Controller at any time, using the relevant contact details.

Reply to “Do Not Track” requests

This Website does not support “Do Not Track” requests.
To find out if any third-party services support them, you can consult the relevant Privacy Policies.

Modifications to this Privacy Policy

The Data Controller reserves the right to make any changes to this Privacy Policy at any time, by informing Users on this page, on this Website (if applicable), and, if legally feasible, by notifying them via the contact details in his possession. Please consult this page regularly, referring to the last review date indicated at the bottom of the Privacy Policy.
If the changes affect any consent-based processing, the Data Controller shall ask for your consent again, if required.

Legal definitions and references

Personal Data (or Data)

Personal Data means any information that can make a natural person directly or indirectly identified or identifiable, also in connection with any other information, including a personal identification number.

Usage Data

Information automatically gathered by this Website (and by third-party applications integrated in this Website), such as: IP addresses or domain names of computers used by users who connect to the site, URI addresses (Uniform Resource Identifier) of requested resources, the time of the request, the method utilized to submit the request to the server, the size of the file obtained in reply, the numerical code indicating the status of the response from the server (successful, error, etc.), the country of origin, the visitor’s browser and operating system characteristics, the various time details per visit (e.g. time spent on each page) and the details on the path followed inside the Application, with particular reference to the sequence of pages visited, and other parameters about the operating system and the user’s IT environment.

User

The natural person using this Website who, unless otherwise specified, coincides with the Data Subject.

Data Subject

The natural person the Personal Data refer to.

Data Supervisor (or Supervisor)

The natural or legal person, public administration and any other entity processing personal data on behalf of the Data Controller, according to the provisions set forth in this Privacy Policy.

Data Controller (or Controller)

The natural or legal person, public authority, service or other body which, individually or collectively, determines the purposes and methods for personal data processing and the tools adopted, including the safety measures related to this Website operation and use. The Data Controller, unless otherwise specified, is the owner of this Website.

This Website (or Application)

The hardware or software tool through which Personal Data are gathered and processed.

Service

The Service provided by this Website, as defined in the related terms (if applicable) on this website/application.

European Union (or EU)

Unless otherwise specified, any reference to the European Union in this document is extended to all current Community and European Economic Area Members.

Cookies

Small portion of data retained in the user’s device.


Legal references

This Privacy Policy has been drafted based on multiple legislative frameworks, including articles 13 and 14 of (EU) Regulation 2016/679.
Unless otherwise specified, this Privacy Policy applies solely to this Website.

Last modified: 11 September 2019