SITE PRIVACY POLICY

This privacy policy, provided pursuant to art. 13 and 14 of European Regulation 679/2016, describes how the website http://www.kocca.it is managed in relation to the processing of personal data that may be acquired in accordance with current legislation.

This privacy policy is provided only for the website http://www.kocca.it and not for third party websites that users may visit by following links on this website.

In any case, http://www.kocca.it undertakes to comply fully with current data protection legislation in all areas under its direct responsibility.

DATA PROCESSING AIMS AND LEGAL BASIS

Any user data collected during navigation of the site are used for purposes connected and/or instrumental to allowing access to the site and all its functions. It is anyway possible to consult the site without providing any personal data, although certain functions may be unavailable and some services may not be provided, as explained and specified, case by case, in this privacy policy.

The site also includes various data collection forms (e.g. for registering new users and/or subscribing to the newsletter service); the data acquired through these forms will always be managed in compliance with current legislation and may be processed:

a. to respond to requests from potential customers for the possible subsequent establishment of a contractual relationship, and/or from customers in relation to purchases and/or products;

b. to allow purchase of the products offered for sale on the site and to carry out activities connected and instrumental to execution of the on-line contract;

c. or order management and processing, to respond to complaints or to provide customer assistance;

d. to carry out administrative-accounting activities deriving from the purchase of products (e.g. sending confirmation of order reception, filing of accounting data relating to the purchase, etc.);

e. to comply with obligations arising from the law or regulations in force;

f. to send advertising and informative material – by post, by email, or by telephone – to provide information on Kocca’s product promotions, and to carry out customer satisfaction surveys.

The provision of personal data of potential customers and existing customers for the purposes described in points a), b), c), d) and e), does not require specific consent as the data provided are needed in order to establish and manage the contract entered into with Kocca Srl and to allow the correct execution of the contractual, accounting and legal obligations arising from the contract. Failure to provide your data will prevent, entirely or partially, correct responses to requests made and/or completion of orders and conclusion of online purchases.

To pursue the promotional and marketing aims as at point f) requires specific consent, which you can provide at the foot of the form. Consent to processing for promotional purposes can be easily revoked by opting out of the receipt of commercial information in accordance with the method shown in the promotional emails sent to your address or by sending your request to the following email address____________ (insert specific email address).

METHODS OF PROCESSING AND RECIPIENTS OF DATA

Processing is carried out by means of IT and/or ICT tools, with organisational methods and logic strictly related to the aims indicated. Kocca Srl works with B2X S.r.l. for management and maintenance of the technological part of the website and for management of the online shop. It follows that the B2X S.r.l. officers responsible for providing the service can collect, use and process the information provided through the website.

Kocca requires its technical services supplier to manage the information in line with Kocca’s company policies and in accordance with regulatory requirements.

The data are processed and stored on the servers of B2X S.r.l. and in the databases of Kocca Srl for the time required by the purposes for which they were collected: in particular, personal data collected for purposes related to the legitimate interest of allowing the website to function will be retained until said interest is fulfilled; for use of such data for contractual purposes, the information will be retained for the entire duration of the contract and for the legally defined period required to manage the accounting and tax obligations arising from the contract.

When processing is based on consent, the Controller can retain personal data until consent is revoked.

The personal data used for the above purposes may be communicated, in writing or by telephone, to the categories and parties indicated below that participate in our business processes in various ways: online payment services, banking, insurance and financial institutions; agents, dealers, distributors and the sales network in general; external consultants, transport, forwarding agents and customs agents; marketing and market research companies, public administrations for the performance of institutional functions, within the limits established by law and regulations.

The scope of possible communication of data will be domestic/European.

The data will not be disseminated beyond the categories and parties indicated above.

DATA CONTROLLER

Following consultation of this site and use of one or more of its services, data relating to identified or identifiable persons may be processed. The data controller is Kocca Srl with registered office in Nola, Interporto di Nola-lotto C/2 n°1/5, Italy.

PLACE OF DATA PROCESSING

The processing operations connected to the web services provided on the website http://www.kocca.it are carried out at the head office of Kocca Srl and also, in relation to website hosting services and the management of the online shop, by B2X S.r.l., which guarantees compliance with statutory legislation in relation to the servers used to provide services to Kocca.

The security measures adopted on the server and on the computer files containing users’ data are suitable to guarantee integrity and availability of the data, and the information stored is protected against the risk of intrusion and unauthorised access.

TYPES OF DATA PROCESSED/SPECIFIC TREATMENTS

Depending on the service supplied, different types of personal data may be processed.

• Navigation data

During normal operation, the computer systems and software procedures used to operate this website acquire various personal data whose transmission is required to navigate websites. This information is not collected to be associated with identified interested parties; however, by its nature it could, through processing and association with data held by third parties, allow users to be identified. Such information includes IP addresses or domain names of the computers of users who connect to the site, the URL addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server and other parameters relating to users’ operating systems and platforms. These data are used for the sole purpose of obtaining anonymous statistical information on use of the site and to monitor its correct operation.

• Data provided voluntarily by the user (communications, comments, newsletters).

The optional, explicit and voluntary sending of data and/or e-mails to the addresses indicated on this site, also by means of contact forms or other technological tools that may be made available, involves the subsequent acquisition of the sender's address, necessary to respond to requests, as well as any other personal data included in the communication sent.

• Cookies

Cookies are small files stored by your browser when you visit a website with a PC, smartphone or tablet. Each cookie contains different data (e.g. the name of the server from which it originated, a numerical identifier, etc.). Cookies may remain on your system for the duration of a session (until the browser is closed) or for longer periods and may contain a unique identifier.

Detailed information on the use of cookies is given in the section entitled "Cookie Policy", which has been prepared by B2X S.r.l. for the website http://www.kocca.it