This Privacy Policy applies to the website premafanclub.com (hereinafter, the “Website”), and it does not concern other websites that may be consulted by clicking links that redirect to other external websites. In accordance with the European Regulation on Data Protection (Regulation (EU) 2016/679, hereinafter also "GDPR") and the relevant Italian legislation (hereinafter, collectively, the "Applicable Law"), this Privacy Policy is provided to the data subjects interacting with the Website (hereinafter, the “User” or “Users”) while consulting its pages.
With respect to cookies, please refer to the Cookie Policy, which is integral part of this Privacy Policy.
1. Data Controller and contact details
The Data Controller is the Prema Fan Club association, with its registered office in Via Alcide De Gasperi 126, 36040 Grisignano di Zocco (VI), VAT n. IT95155280241, hereinafter also "Data Controller" or only “Controller.”
For any clarification, information, and exercise of the rights listed in this Privacy Policy, contact the Data Controller at the following e-mail contact: help@premafanclub.com.
2. Personal data subject to processing
The personal data processed through the Website are the following:
A. NAVIGATION DATA
The computer systems and software procedures used to operate the website acquire, during their normal operation, some aggregate and not immediately identifiable personal data whose transmission is implicit in the use of Internet communication protocols. These personal data are not collected to be associated with identified data subjects; however, considering their nature, they could enable users to be identified through processing and association with data held by third parties. This category of data includes, for example, IP addresses, domain names of the computers used by users and the addresses in the Uniform Resource Identifier (URI) notation. These technical/computer data are used for the sole purpose of obtaining aggregate or anonymous statistical information on the use of the Website itself, checking the correct functioning of the services offered by the Website and identifying anomalies and/or abuses. This information is deleted immediately after their processing. The data could be used in case of hypothetical computer crimes or at the request of the Public Authority.
B. DATA PROVIDED ON A VOLUNTARY BASIS
By means of the Website, the User may voluntarily provide personal data such as, for example:
- personal data provided by the User (for example e-mail adresse, personal data included in the communication and any annex) through the compiling of the form available on the “Contact Us” section of the Website. The above-mentioned form can be used by Users for any requests for information and/or clarifications.
- personal data provided by the User (for example, name, surname, date of birth, e-mail address and password) in order to create a personal account on the Website, accessible by the User for consultation and/or modification of data and information stored there, saving personal data to speed up the association procedure to the Fan Club.
- further personal data provided by the User during association with the Fan Club and membership fee payment: for information regarding this processing of personal data, please refer to the "Adult members privacy policy" and, if the person concerned is a minor, to the "Minor members privacy policy” .
The Data Controller shall process personal data in compliance with the Applicable Law, assuming that they refer to the same User or to third parties who have expressly authorised the User to provide them or whose personal data that the User was entitled to provide. With respect to these hypothesises, the User undertakes to relieve and indemnify the Data Controller from any objection, claim or request for compensation for damage caused by the processing of personal data that may be received from such third parties.
With reference to the possibility of subscribing to the newsletter via the form at the foot of the Website, the Fan Club acts as data controller on behalf of Prema Racing S.r.l. With reference to this processing of personal data, please refer to the data controller’s privacy policy, Prema Racing S.r.l.
C. COOKIES AND OTHER TRACKING TOOLS
With regard to the types of cookies used by the Website, the User can refer to the Cookie Policy.
3. Purposes and legal basis of the processing
The acquired data will be processed for the following purposes and based on the following legal bases.
PURPOSES LEGAL BASIS
Providing feedbacks to any requests for information/clarification which are sent using the forms available on the Website. The processing is necessary for the performance of a contract to which the User is party and/or in order to take steps at the request of the User prior to entering into a contract [art. 6(1)(b), of the GDPR].
Creating a personal account (to save personal data to speed up the association procedure to the Fan Club). The processing is necessary for the performance of a contract to which the User is party and/or in order to take steps at the request of the User prior to entering into a contract [art. 6(1)(b), of the GDPR].
Complying with legal obligations to which the Data Controller is bound, included responding to any requests to exercise the User’s rights as data subject under current data protection legislation. The compliance with legal obligations to which the Data Controller is bound [Article 6(1)(c) of the GDPR].
Verifying any fraudulent or illegal use of the Website and ensure its security and functionality in the interest of the Users and the Data Controller. The legitimate interest of the Data Controller and the Users themselves to prevent or identify any fraudulent or otherwise illegal use of the Website [art. 6(1)(f) of the GDPR].
Carrying out research/statistical analysis on aggregate or anonymous data, without being able to identify the User, to measure traffic and assess usability and interest of Users with respect to the Website. The legitimate interest of the Controller to verify the usability and appeal of the Website [art. 6(1)(f) of the GDPR].
Ascertaining, exercising, or defending a right in administrative, jurisdictional or extrajudicial proceedings or whenever administrative or jurisdictional authorities exercise their functions. The legitimate interest to ascertain, exercise, or defend a right in administrative, jurisdictional or extrajudicial proceedings or whenever administrative or jurisdictional authorities exercise their functions. [art. 6(1)(f) of the GDPR].
For the information regarding the processing of personal data for the purposes of Fan Club membership and related membership life, please refer to the "Adult members privacy policy" or, if the individual is a minor, to the "Minor members privacy policy”.
4. Nature of personal data provision
Providing data by the User is optional. However, failure to provide this data, in whole or in part, could make impossible to respond to requests for information or clarifications, fufill requests to exercise the User’s rights as data subject or it could make the creation of personal account by the User impossible.
5. Methods of personal data processing
Personal data are processed with manual and/or computer-based instruments, always in ways that ensure security and confidentiality. To this end, the Data Controller has adopted and implements both technical and organisational security measures, which are appropriate to the level of risk related to the carried-out processing of personal data.
In particular, the Website functionality is provided an HTTPS encrypted connection, and personal data are collected, filed, and stored on secure servers protected by firewalls. These servers are physically located within the European Union.
6. Recipients of personal data
The personal data of the User may be shared, for the purposes set out above, with:
• persons authorised by the Data Controller to process personal data pursuant according to and for the purposes of Article 29 of the GDPR and Article 2-quaterdecies of the Privacy Code and who have received specific instructions on how to process the data in accordance with the Applicable Law;
• Prema Racing S.r.l., as the data processor pursuant to and for the purposes of Article 28 of the GDPR in order to give administrative support to the Fan Club on the Website, members, services management and in the management of the events supplied by the Fan Club;
• Prema Racing S.r.l., as data controller, for subscribing to and managing the newsletter organised by Prema Racing S.r.l. itself;
• companies, consultants, or professionals who may be entrusted with the installation, maintenance, updating of the WebSite (for example, web agencies and/or marketing agencies) and, in general, with the management of the hardware and software of the Data Controller, included the hosting provider and cloud computing services providers that act as data processor pursuant to and for the purposes of art. 28 of the GDPR;
• public entities, subjects, or Public Authorities to whom, as independent data controllers, it is mandatory to disclose the personal data of the User according to provisions or orders of the authorities or to prevent and/or detect any fraudulent activity or abuse concerning the use of Website and the services offered by the Data Controller;
• law firms, associated firms, consultants, or professionals (e.g., legal, administrative and/or tax consultancies) who may be appointed to support the Data Controller in order to ensure the correct fulfilment of the legal obligations with which the Data Controller is required to comply and/or in the the ascertainment, exercise, or defence of legal claims in court, or whenever the jurisdictional or administrative authorities exercise their jurisdictional functions.
7. Data transfers to non-EEA countries or international organisations
The Data Controller’s hosting provider’s servers are located within the European Economic Area.
8. Period of retention of personal data
The User's personal data or provided by the User will be kept for a period not exceeding the one necessary for the pursuit of the purposes indicated above and for which they are processed.
In particular, personal data will be kept for the period necessary to provide feedback to any received requests for information and/or clarifications and, in any case, for a period not exceeding three months from the moment the provision of the personal data.
9. Rights of the data subject
The User and/or the third party on whose behalf the User has provided the data, has the right:
• to receive confirmation as to whether or not his/her personal data are being processed and, if so, to obtain access to them and to a range of relevant information, including, by way of example, information concerning : a) the purposes of the processing; b) the categories of personal data that are subject to the processing; c) the entities or categories of entities to whom or which the personal data have been or will be communicated; d) the retention period of the data or, if that is not possible, the criteria used to determine that period; e) the source of the personal data, if not provided by the User;
• to request and to obtain the updating of personal data, the rectification of inaccurate data or the integration of incomplete data when there is an interest;
• to request and obtain the erasure of personal data if: a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; b) the User objects to the processing carried out on the basis of a legitimate interest of the Controller and there is no overriding legitimate reason to continue the processing; c) the personal data have been processed unlawfully; d) the personal data must be erased by the Controller in compliance with a legal obligation;
• to request and obtain the restriction of processing in the event of: (a) contestation of the accuracy of personal data for the time necessary for the Data Controller to carry out the requested verifications; (b) unlawful processing of data by the Data Controller, if the User objects to the erasure of the data and instead requests the restriction of its use; (c) ascertainment, exercise, or defence of a legal claim of the User in court, although the Data Controller no longer needs the data for the purposes of processing; (d) awaiting the outcome of the verification as to whether the Data Controller's legitimate reasons prevail over the legitimate reasons of the data subject;
• in cases where the processing is based on a contract and is carried out by automated means, to request and receive personal data in a structured, commonly used and machine-readable format and to obtain the direct transmission of them by the Controller to another controller, if technically feasible;
• to object, in whole or in part, to the processing of personal data concerning the User, for legitimate reasons related to the User’s particular situation, even if the personal data are relevant to the purpose of collection;
• in cases where the processing is based on consent, to withdraw consent at any given time without prejudice to the lawfulness of processing based on consent before its withdrawal;
• to file a complaint with the supervisory Authority pursuant to Article 77 of the GDPR (and Articles 140-bis et seq. of the Privacy Code), if he/her believes that his/her rights under the Applicable Law have been infringed.
The Data Controller shall inform each recipient to whom the personal data have been transmitted about any rectification, erasure, or restriction of carried out processing, except when this is impossible, or it involves a disproportionate effort.
10. Ways of exercising rights of the data subject
As data subject, the User may exercise the above-mentioned rights at any time contacting the Data Controller at the contact detail listed in paragraph “1. Data Controller and contact details” of this procedure.
To lodge a complaint with the Italian Data Protection Authority, the User may use the forms available on the website of the relative Authority.
11. Updates to the Privacy Policy
This Privacy Policy may be amended, and/or integrated, and/or updated periodically, including as a result of updates to the Applicable Law. In such cases, the Data Controller will inform the User of any amendments, and/or integrations, or updates to this Privacy Policy by publishment on the Website.
Rev. 01 - Last Update: 17/07/2024