Privacy Policy

PRIVACY NOTICE
Link to the General Data Protection Regulation No. 2016/679 (GDPR)

Fitness Investment SRL has always paid close attention to the protection of personal data and to respecting the principles of confidentiality and human dignity.

Pursuant to the new EU Regulation 679/2016 and in accordance with the accountability principle, any processing of personal data must be lawful and fair. For all natural persons, the methods used to collect data, its storage and the type of use must be transparent, including how personal data is accessed and processed.

The transparency principle requires that information and communications relating to the processing of such data be easily accessible and understandable and use clear, plain language.

With this in mind, please read the following notice.

Fitness Investment SRL, as Data Controller pursuant to and for the purposes of EU Regulation 2016/679, hereby informs the data subject that personal data concerning them, acquired by the Controller or requested subsequently and/or communicated by third parties, is necessary and will be used for the purposes set out below.

In compliance with Articles 13 (data collected from the data subject) and 14 (data not collected from the data subject) of EU Regulation 2016/679 (GDPR), the following information is provided to users of www.fitactive.it and the operational link https://www.fitactive.it. It applies exclusively to processing carried out through this Website and not to other websites that may be visited through links from it; users are advised to read the privacy notices provided by the respective controllers of those websites.

The purpose of this privacy notice is to provide maximum transparency regarding the information collected by the website, the purposes for which it is collected and how it is used.

Data Controller

Fitness Investiment Srl, licensee of the “FitActive” trademark, Tax Code 10046400965, VAT No. 10046400965, certified email: privacy.fitactive@pec.it, email: privacy@fitactive.it and Privacy telephone number: +39 3665242024, with its operational privacy address at Via Giuseppe di Vittorio no. 4, 20813 Bovisio Masciago (MB), Italy, where the acting physical person responsible for GDPR protection can be identified (the “Company”, “www.fitactive.it Data Controller”), as controller of the personal data of users of www.fitactive.it, guarantees compliance with personal-data protection legislation and provides the following information regarding data communicated or otherwise collected while browsing this website, pursuant to Article 13 of Legislative Decree 196/2003 and Articles 13 and 14 of EU Regulation 2016/679 of 27 April 2016.
Please note that the data subject has the right to access their personal data at any time by submitting a request to our designated data-processing contact using the contact details provided below:

Data Controller – Fitness Investiment Srl, licensee of the “FitActive” trademark, Tax Code 10046400965, VAT No. 10046400965, certified email: privacy.fitactive@pec.it, email: privacy@fitactive.it and Privacy telephone number: +39 3665242024, with its operational privacy address at Via Giuseppe di Vittorio no. 4, 20813 Bovisio Masciago (MB), Italy, where the acting physical person responsible for GDPR protection can be identified.

Likewise, with regard to the processing in question, you may exercise the following rights: information, access to data, rectification, erasure, restriction of processing, data portability, lodging a complaint with a supervisory authority and withdrawal of consent.

The website is hosted on the Windows hosting platform of Aruba S.p.A.

To ensure the highest level of personal-data security in compliance with the GDPR, Aruba S.p.A.'s Windows hosting service provides the following services:

  • SSL certificate designed to prevent unauthorized disclosure of or access to transmitted personal data (GDPR – Article 32(2));
  • daily and weekly backups against the risk of accidental loss of personal data (GDPR – Article 5(1)(f));
  • continuous monitoring of website vulnerabilities and their prompt resolution (GDPR – Article 32(1)(d)).

The website is divided into a public area and a private area. The private area is intended exclusively for the franchise network to distribute materials to all locations. It is protected by a username and password together with preventive IP blocking, so that credentials can be used only from the location to which they are assigned. Each location may request authorization for two additional IP addresses, for example to allow managers to access the area from home.

The personal data collected on the website is listed in full on the dedicated Privacy Policy page at: https://www.fitactive.it/privacy-cookies-policy.php.

CONTACTS

To exercise the rights described above or for any other request, you may write to the Data Controller: Fitness Investiment Srl, licensee of the “FitActive” trademark, Tax Code 10046400965, VAT No. 10046400965, certified email: privacy.fitactive@pec.it, email: privacy@fitactive.it and Privacy telephone number: +39 3665242024, with its operational privacy address at Via Giuseppe di Vittorio no. 4, 20813 Bovisio Masciago (MB), Italy, where the acting physical person responsible for GDPR protection can be identified.

In addition, the Privacy Officer is available for any information concerning FitActive's processing of personal data at the following address: privacy.fitacyive@pec.it. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. Consent regarding processing is expressed as indicated below:

with regard to use of the contact details provided for commercial or promotional communications by the Controller; communication to third parties of contact details provided for commercial communications; use of personal data for profiling purposes; geolocation as specified in the information provided; and use of sensitive data as specified in the information provided:

By signing this Registration Form, I ACCEPT the General Terms and Conditions shown on the reverse and undertake to comply with the “Internal Regulations”, of which I have been fully informed.

Legal basis for processing

The processing of personal data is based on the right to information, the performance of contractual obligations or social-contact obligations, or, where necessary, on consent given through the free and informed completion of the relevant information fields in the dedicated forms.

Providing data, and therefore consenting to its collection and processing, is optional. The User may refuse consent and may withdraw consent already given at any time (by clicking the Cookie Policy link at the bottom of the page or through browser settings with regard to cookies). Refusing consent may, however, make it impossible to provide certain services and may reduce the website browsing experience.

The Controller processes Personal Data relating to the User where one of the following conditions applies:

  • the User has given consent for one or more specific purposes;
  • processing is necessary for the performance of a contract with the User and/or in order to take steps at the User's request prior to entering into a contract;
  • processing is necessary for compliance with a legal obligation to which the Controller is subject;
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
  • processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party.

It is always possible to ask the Controller to clarify the specific legal basis for each processing activity and, in particular, to specify whether processing is based on law, required by a contract or necessary in order to enter into a contract.

Purposes and methods of processing

Processing of personal data means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means.

The personal data of users of the website www.fitactive.it and the operational link https://www.fitactive.it will be processed in the ways and forms prescribed by the GDPR in order to provide the Website's functions, with particular but not exclusive reference to the data-collection procedures described therein, contact forms, any registration/access process for restricted areas, newsletter subscriptions and similar activities.

In addition to purposes connected, instrumental and necessary to providing the service, processing of data collected by the website is carried out for the following purposes:

  • to respond to specific requests made by the User to the Controller through the Website and its communication tools (contact forms, product and service information request forms and similar tools);
  • possible subscription to the newsletter (where provided) and subsequent sending of commercial and informational communications relating to the sector in which the Controller operates, subject to the User's specific consent;
  • informational communications relating to the Controller's services following a request for information by email, completion of the contact form or use of other communication tools;
  • other ancillary purposes or purposes connected with those listed above and in any event falling within the scope of the Website's activities, including geolocation on the map;
  • processing the email address provided by the data subject in connection with the sale of a product or service, including for sending, without further consent, communications concerning the subsequent direct sale of products or services similar to those already purchased;
  • collecting data and information exclusively in aggregated and anonymous form in order to verify the correct operation of the website, improve the online store (where applicable) and platform, and improve performance and features. None of this information is linked to the natural person using the website and it cannot in any way identify them.

The collected data will be processed using electronic or otherwise automated, IT and telematic tools, or by manual processing according to logic strictly related to the purposes for which the personal data was collected and in any event in a manner that guarantees its security. Data is retained only for the time strictly necessary to manage the purposes for which it was collected, in compliance with applicable rules and legal obligations. Personal-data processing is carried out by Fitness Investiment Srl, licensee of the “FitActive” trademark, Tax Code 10046400965, VAT No. 10046400965, certified email: privacy.fitactive@pec.it, email: privacy@fitactive.it, Privacy telephone number: +39 3665242024, with operational privacy address at Via Giuseppe di Vittorio no. 4, 20813 Bovisio Masciago (MB), Italy, where the acting physical person responsible for GDPR protection can be identified. Processing will be carried out exclusively by our authorized data-processing personnel and data will be supplied to third-party companies only where specifically requested and necessary.

The newsletter containing promotional content (where available) is provided directly by the Data Controller using MailUp, which processes data on the Controller's behalf as a processor. MailUp uses web beacons to detect whether a message is opened, clicks on hyperlinks contained in emails, the IP address or type of browser used to open an email and similar information. Users can easily object to further newsletter mailings by clicking the consent-withdrawal link included in every newsletter email. After consent is withdrawn, the Controller will send the User a message confirming the withdrawal.

The Controller adopts appropriate security measures to prevent unauthorized access to, disclosure, alteration or destruction of Personal Data. Processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the stated purposes. In addition to the Controller, Data may in some cases be accessible to persons involved in the organization of this Website (administrative, sales, marketing and legal staff, system administrators) or external parties (such as third-party technical-service providers, postal couriers, hosting providers, IT companies and communication agencies), who may be appointed as Processors where necessary. The updated list of Processors may always be requested from the Data Controller by contacting Fitness Investiment Srl, licensee of the “FitActive” trademark, Tax Code 10046400965, VAT No. 10046400965, certified email: privacy.fitactive@pec.it, email: privacy@fitactive.it, Privacy telephone number: +39 3665242024, with operational privacy address at Via Giuseppe di Vittorio no. 4, 20813 Bovisio Masciago (MB), Italy, where the acting physical person responsible for GDPR protection can be identified.

Purposes and lawfulness of processing

Pursuant to EU Regulation 679/2016, personal data:

  • is processed lawfully, fairly and transparently in relation to the data subject (Article 5);
  • is collected for specified, explicit and legitimate purposes and subsequently processed in a manner that is compatible with those purposes (Article 5).

The User's Data is collected to allow the Controller to provide its services, as well as for the following purposes: analytics, contacting the User, interaction with social networks and external platforms, displaying content from external platforms and interaction with social networks and external platforms.

The purposes for which your data is collected are compliance with legal obligations and obligations arising from the contract entered into with our Company.

For these purposes, providing the data is mandatory and consent does not need to be requested or obtained because the purposes for which the data is processed are lawful.

By accepting this privacy notice, periodic newsletters and emails concerning promotions or initiatives of our Company will be sent.

Data collected

This website collects user data in two ways.

Data collected automatically

While browsing the website, a number of items of information relating to the IT systems used by the User are normally acquired. These include, for example:

  • Internet Protocol (IP) address;
  • browser type;
  • name of the Internet Service Provider (ISP);
  • date and time of visit;
  • referring and exit web pages;
  • where applicable, the number of clicks and page(s) visited;
  • device data.

This data is used for statistical and analytical purposes exclusively in aggregated form. None of this information is linked to the natural-person User of the website and it cannot in any way identify them. The IP address is used exclusively for security purposes and is not cross-referenced with any other data.

Data provided voluntarily

The website may collect other data where Users voluntarily use services such as comments, communications (chat, contact forms, newsletter subscription) or purchasing services (shopping cart). These include, for example:

  • first and last name;
  • username;
  • email address;
  • residential address;
  • shipping address (where required for shipping purposes);
  • social-media profiles;
  • geographical location

This data is provided voluntarily by the User when requesting the service and will be used exclusively to provide the requested service.

Users hold this website harmless from any liability concerning possible violations of law. It is the User's responsibility to ensure that they have permission to enter third-party personal data or content protected by national and international rules.

Types of data collected

Personal Data collected by this Website, either independently or through third parties, includes: cookies, usage data, email, data communicated while using the service, first name, last name, date of birth, telephone number, address, country, province and unique device identifiers for advertising purposes (for example Google Advertiser ID or IDFA).

Full details of each type of Data collected are provided in the dedicated sections of this privacy policy or through specific notices displayed before the Data is collected.

Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Website.

Unless otherwise specified, all Data requested by this Website is mandatory.

If the User refuses to provide it, this Website may be unable to provide the Service.

Where this Website indicates certain Data as optional, Users are free not to provide such Data without any consequence for the availability or operation of the Service.

Users who are uncertain about which Data is mandatory are encouraged to contact Fitness Investiment Srl, licensee of the “FitActive” trademark, Tax Code 10046400965, VAT No. 10046400965, certified email: privacy.fitactive@pec.it, email: privacy@fitactive.it, Privacy telephone number: +39 3665242024, with operational privacy address at Via Giuseppe di Vittorio no. 4, 20813 Bovisio Masciago (MB), Italy, where the acting physical person responsible for GDPR protection can be identified.

Any use of Cookies—or other tracking tools—by this Website or by the owners of third-party services used by this Website, unless otherwise stated, is intended to provide the Service requested by the User in addition to the further purposes described in this document and in the Cookie Policy.

The User is responsible for third-party Personal Data obtained, published or shared through this Website and guarantees that they have the right to communicate or distribute it, releasing the Controller from any liability toward third parties.

Contacting the User

Contact form

By completing the contact form with their Data, the User consents to its use to respond to requests for information, quotations or any other request indicated by the form heading.

Personal Data collected: postal code, last name, email, address, country, first name, telephone number, VAT number, province, company name, state and various types of Data as specified in the service's privacy policy.


Mailing List or Newsletter

By registering for the mailing list or newsletter, the User's email address is automatically added to a contact list to which email messages containing information, including commercial and promotional information relating to this Website, may be sent. The User's email address may also be added to this list as a result of registration with this Application or after making a purchase.


MailUp

MailUp S.p.A. is a technology company that has developed a digital cloud-computing platform offering businesses functions and tools for creating, sending, marketing-automation and tracking of newsletters, emails and SMS messages. The platform can be integrated via API with e-commerce, CMS and CRM systems and provides an SMTP server for sending transactional emails from other systems.


Customer Service

FitActive customer-service staff act as the link between the Company and customers seeking assistance. They provide the first point of contact with the company and are responsible for helping customers, answering questions and providing appropriate guidance. By its nature and duties, this service necessarily involves access to personal data; making a call or contact is considered acceptance of the GDPR processing methods described in this policy.

Personal Data collected: city, last name, cookies, email, country, first name, telephone number, province and state.

Transfer of collected data to third parties

Data collected by the website is not provided to third parties unless requested lawfully by a judicial authority and only in the cases provided by law. Data may nevertheless be provided to third parties where necessary to provide a specific service or to carry out website security or optimization checks.

The User expressly consents to the transfer of Data in the cases indicated below.

Third-party service providers

This Website may provide certain personal data to consultants, web agencies and software houses for website security or optimization checks; to judicial authorities following a specific request; to third-party companies acting on behalf of the Controller (for example for shipping samples or products); or to the MailUp platform for sending newsletters. In the case of e-commerce, this Website shares your personal data with the shipping company responsible for delivering the ordered goods.

To complete payment, we provide the necessary payment data to the financial institution or payment provider selected to handle the payment procedure, or to the payment-service provider selected during the purchasing process. These providers have access only to the personal data necessary to perform their tasks. They may not use such data for other purposes and are also required to process personal data in accordance with this Privacy Notice, the Controller's instructions and applicable personal-data protection legislation. Examples of payment platforms include PayPal, Tinaba, Postepay, Skrill, online bank transfer and postal payment slips.

Business transfers

If ownership of the website or all of its assets is transferred to third parties, or in the event of a merger, joint venture or reorganization, customers' personal data will naturally be among the transferred assets.

Disclosure to third parties

Your personal data may be disclosed to third parties known to us solely and exclusively for the purposes stated above and, in particular, to the following categories of recipients:

  • External companies that provide services on our behalf;
  • Bodies and Public Administrations for compliance with legal obligations;
  • Professionals who may assist with compliance with legal obligations.
  • Subsidiaries or affiliated companies, or companies with which a Franchising, trademark use or trademark licensing agreement is in place.

These parties will process personal data as external Data Processors.

Protection of the company and other parties

We disclose account data and other personal data only when expressly required by law; to enforce or apply our General Terms and Conditions of Use and Sale and other agreements; or to protect our property or rights, as well as the safety of the company, our users or other parties. This includes exchanging information with other companies and organizations for fraud prevention or credit-risk reduction. Obviously, this does not include selling, sharing or otherwise disclosing personal data received from customers for commercial purposes in breach of the commitments made in this Privacy Policy. Your data will never be transferred to third parties for marketing purposes. Your data will not be transferred to non-EU third countries or international organizations, nor will it be stored on servers located in a third country.

Confidentiality obligation

Data processing is carried out using electronic tools and/or paper media by persons bound by confidentiality, according to methods related to the stated purposes and, in any event, in a manner designed to ensure the security and confidentiality of the data. The data collected will not be disclosed or disseminated to third parties except as provided by law.

Place of processing

Data collected through the website is processed at the premises of the Data Controller and at the Web Hosting data center. The web hosting provider is located in the European Economic Area and operates in accordance with European regulations. Data is processed at the Controller's operating offices and in any other place where the parties involved in the processing are located. For further information, contact the Controller. The User's Personal Data may be transferred to a country other than the one in which the User is located. For further information on the place of processing, the User may refer to the section containing details on the processing of Personal Data. The User has the right to obtain information on the legal basis for transfers of Data outside the European Union or to an international organization governed by public international law or established by two or more countries, such as the UN, as well as on the security measures adopted by the Controller to protect the Data. If any of the transfers described above takes place, the User may refer to the relevant sections of this document or request information from the Controller using the contact details provided at the beginning.

Data retention period

Data provided by the Data Subject will be retained until expressly withdrawn by the Data Subject, including through actions in their browser, deletion of cookies, an express request by email or telephone to the Controller (see the relevant section), or by any other means. Browsing data will be retained for the technical time required to perform the functions for which it was collected.

Retention period

Data is processed and stored for the time required for the purposes for which it was collected, up to 5 years.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Controller and the User will be retained until that contract has been fully performed.
  • Personal Data collected for purposes related to the Controller's legitimate interest will be retained until that interest has been satisfied. The User may obtain further information about the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.

Where processing is based on the User's consent, the Controller may retain Personal Data for longer, until that consent is withdrawn. The Controller may also be required to retain Personal Data for a longer period in order to comply with a legal obligation or an order from an authority. At the end of the retention period, Personal Data will be deleted. Therefore, once that period has expired, the rights of access, erasure, rectification and data portability can no longer be exercised.

Our website uses cookies and similar technologies to ensure proper operation and improve the browsing experience. This document provides information on the use of cookies and similar technologies, how they are used by our website and how to manage them.


Definitions

Cookies are small text files (letters and/or numbers) that allow the web server to store information on the client (the browser) for reuse during the same visit to the website (session cookies) or later, even after several days (persistent cookies). Cookies are stored, according to the User's preferences, by the individual browser on the specific device being used (computer, tablet, smartphone).

Similar technologies, such as web beacons, transparent GIFs and all forms of local storage introduced with HTML5, may be used to collect information about User behavior and use of the services.

Throughout the remainder of this document, we will refer to cookies and all similar technologies simply as “cookies”.

Based on their characteristics and use, cookies can be divided into different categories:

  • Strictly necessary cookies.These cookies are essential for the website to function correctly. Their duration is strictly limited to the working session (they are deleted when the browser is closed).
  • Analytics and performance cookies.These cookies are used to collect and analyze website traffic and usage anonymously. Although they do not identify the User, they can, for example, determine whether the same User returns at different times. They also make it possible to monitor the system and improve its performance and usability. These cookies can be disabled without any loss of functionality.
  • Profiling cookies.These are persistent cookies used to identify User preferences (anonymously or otherwise) and improve the browsing experience.

Third-party cookies

When visiting a website, cookies may be received both from the website visited (“first-party”) and from websites managed by other organizations (“third parties”). A notable example is the presence of “social plugins” for Facebook, Twitter, Google+ and LinkedIn. These are parts of the page generated directly by those websites and integrated into the page of the host website. The most common use of socialpluginsis to enable content sharing on social networks.

The presence of these pluginsinvolves the transmission of cookies to and from all websites managed by third parties. The management of information collected by “third parties” is governed by their respective notices, which you should consult. For greater transparency and convenience, the web addresses of the various notices and cookie-management methods are listed below.

Facebook: cookie policy - privacy settings

Twitter: cookie policy - privacy settings

Google+: cookie policy - privacy settings

LinkedIn: cookie policy - privacy settings

Pinterest: cookie policy - privacy settings

Google Analytics

Our website also includes certain components transmitted by Google Analytics, a web traffic analysis service provided by Google, Inc. (“Google”). These are third-party cookies collected and managed anonymously to monitor and improve the performance of the host website (performance cookies).

Google Analytics uses “cookies” to collect and analyze information anonymously about how our website is used (including the User's IP address). This information is collected by Google Analytics, which processes it in order to prepare reports on website activity. This website does not use (and does not allow third parties to use) Google's analytics tool to monitor or collect personally identifiable information. Google does not associate the IP address with any other data held by Google, nor does it attempt to link an IP address with a User's identity. Google may also disclose this information to third parties where required by law or where those third parties process the information on Google's behalf.

For further information, please refer to the following link:https://www.google.it/policies/privacy/partners/

The User may selectively disable Google Analytics by installing the opt-out component provided by Google in their browser. To disable Google Analytics, please refer to the following link:https://tools.google.com/dlpage/gaoptout

Cookie management

The User may decide whether to accept cookies by using their browser settings.

Warning:Disabling technical cookies in whole or in part may compromise the use of website features. Public content, however, remains accessible even if cookies are completely disabled.

Disabling “third-party” cookies does not affect browsing in any way.

Settings may be configured specifically for different websites and web applications. In addition, leading browsers allow different settings to be defined for “first-party” and “third-party” cookies.

For example, in Firefox, through the Tools->Options-> Privacy menu, you can access a control panel where you can choose whether to accept the different types of cookies and remove them.

Chrome: https://support.google.com/chrome/answer/95647?hl=it

Firefox: https://support.mozilla.org/it/kb/Gestione%20dei%20cookie

Edge: https://privacy.microsoft.com/it-it/windows-10-microsoft-edge-and-privacy

Internet Explorer: http://windows.microsoft.com/it-it/windows7/how-to-manage-cookies-in-internet-explorer-9

Opera: http://help.opera.com/Windows/10.00/it/cookies.html

Safari: http://support.apple.com/kb/HT1677?viewlocale=it_IT

PLEASE NOTE AND REMEMBER

  1. The website https://www.fitactive.it/ uses Cookies to make the User's browsing experience easier and more intuitive. Cookies are small text strings used to store certain information that may concern the User, their preferences or the device used to access the internet (computer, tablet or mobile phone). They are mainly used to adapt the website's operation to the User's expectations, provide a more personalized browsing experience and remember choices made previously (please note that the website will automatically ask for authorization to use cookies).
  2. A cookie consists of a small set of data transferred to the User's Browser by a web server and can only be read by the server that made the transfer. It is not executable code and does not transmit viruses.
  3. Cookies do not record any personal information and any identifying data will not be stored. If you wish, you can prevent some or all cookies from being saved. However, in this case, use of the website and the services offered may be impaired. To continue without changing cookie options, simply continue browsing and accept their use as described above. Please remember that cookies can also be deleted by clearing browsing history, etc.

The types of cookies used by the website are listed below:

  1. There are many technologies used to store information on a User's computer, which is then collected by websites. The best known and most widely used are HTTP cookies. They are used for browsing and to facilitate User access to and use of the website. They are necessary for transmitting communications over an electronic network or for the provider to supply the service requested by the customer.
  2. The settings used to manage or disable cookies may vary depending on the Browser used. As already noted, you are given the option to manage them, but disabling cookies may slow down or prevent access to certain parts of the website.
  3. Technical cookies enable the website to operate safely and efficiently.
  4. The duration of storage distinguishes temporary cookies, which are automatically deleted, from persistent cookies, which remain active until they expire or are deleted by the User, while session cookies enable operation within the reserved area and remain until the browser is closed.
  5. Any third-party cookies are sent directly by the browser from the website being visited to third-party websites. They are generally used to understand Users' online behavior. Their use is governed by the rules of the relevant third parties, which are responsible for privacy protection.
  6. Profiling cookies are governed by Article 22 of EU Regulation 2016/679 and Article 122 of the Italian Personal Data Protection Code.
  7. The User may decide whether to accept cookies by using their browser settings.

Disabling technical cookies in whole or in part may compromise use of the website's features. Public content, however, remains accessible even if cookies are completely disabled.

Disabling “third-party” cookies does not affect browsing in any way.

Settings may be configured specifically for different websites and web applications. In addition, leading browsers allow different settings to be defined for “first-party” and “third-party” cookies.

For example, in Firefox, through the Tools -> Options -> Privacy menu, you can access a control panel where you can decide whether to accept the different types of cookies and remove them.

Chrome: https://support.google.com/chrome/answer/95647?hl=it

Firefox: https://support.mozilla.org/it/kb/Gestione%20dei%20cookie

Edge: https://privacy.microsoft.com/it-it/windows-10-microsoft-edge-and-privacy

Internet Explorer: http://windows.microsoft.com/it-it/windows7/how-to-manage-cookies-in-internet-explorer-9

Opera: http://help.opera.com/Windows/10.00/it/cookies.html

Safari: http://support.apple.com/kb/HT1677?viewlocale=it_IT

Our website uses cookies and similar technologies to ensure proper operation and improve the browsing experience. This document provides information on the use of cookies and similar technologies, how they are used by our website and how to manage them. Cookies are small text files (letters and/or numbers) that allow the web server to store information on the client (the browser) for reuse during the same visit to the website (session cookies) or later, even after several days (persistent cookies). Cookies are stored, according to the User's preferences, by the individual browser on the specific device used (computer, tablet, smartphone). Similar technologies, such as web beacons, transparent GIFs and all forms of local storage introduced with HTML5, may be used to collect information about User behavior and use of the services. Throughout the remainder of this document, we will refer to cookies and all similar technologies simply as “cookies”.

Based on their characteristics and use, cookies can be divided into different categories:

  • Strictly necessary cookies.These cookies are essential for the website to function correctly. Their duration is strictly limited to the working session (they are deleted when the browser is closed).
  • Analytics and performance cookies.These cookies are used to collect and analyze website traffic and usage anonymously. Although they do not identify the User, they can, for example, determine whether the same User returns at different times. They also make it possible to monitor the system and improve its performance and usability. These cookies can be disabled without any loss of functionality.
  • Profiling cookies.These are persistent cookies used to identify User preferences (anonymously or otherwise) and improve the browsing experience.

When visiting a website, cookies may be received both from the website visited (“first-party”) and from websites managed by other organizations (“third parties”). A notable example is the presence of “social plugins” for Facebook, Twitter, Google+ and LinkedIn. These are parts of the page generated directly by those websites and integrated into the page of the host website. Social plugins are most commonly used to share content on social networks. The presence of these plugins entails the transmission of cookies to and from all websites managed by third parties. The management of information collected by “third parties” is governed by their respective notices, which you should consult. For greater transparency and convenience, the web addresses of the various notices and cookie-management methods are listed below.

Facebook: cookie policy - privacy settings

Twitter: cookie policy - privacy settings

Google+: cookie policy - privacy settings

LinkedIn: cookie policy - privacy settings

Pinterest: cookie policy - privacy settings

Interaction with social networks and external platforms

These types of services allow interaction with social networks or other external platforms directly from the pages of this Website.

Interactions and information obtained through this Website are in all cases subject to the User's privacy settings for each social network.

If a social-network interaction service is installed, it may collect traffic data relating to the pages on which it is installed even when Users do not use the service.


1. Facebook Like button and social widgets(Facebook Inc.)

The Facebook Like button and social widgets are services for interacting with the Facebook social network, provided by Facebook, Inc.

Personal Data collected:Cookies and Usage Data.
Place of processing:USA - Privacy Policy


2. Google+ +1 button and social widgets(Google Inc.)

The Google+ +1 button and social widgets are services for interacting with the Google+ social network, provided by Google Inc.

Personal Data collected:Cookies and Usage Data.
Place of processing:USA - Privacy Policy


3. Twitter Tweet button and social widgets(Twitter Inc.)

The Twitter Tweet button and social widgets are services for interacting with the Twitter social network, provided by Twitter, Inc.

Personal Data collected:Cookies and Usage Data.
Place of processing:USA - Privacy Policy


4. Pinterest Pin It button and social widgets(Pinterest, Inc.)

The Pinterest Pin It button and social widgets are services for interacting with the Pinterest social network, provided by Pinterest, Inc.

Personal Data collected:Cookies and Usage Data.
Place of processing:USA - Privacy Policy

Analytics

The services contained in this section allow the Data Controller to monitor and analyze traffic data and are used to track User behavior.


Google Analytics(Google Inc.)

Google Analytics is a web analytics service provided by Google Inc. (“Google”). Google uses the Personal Data collected to track and examine use of this Website, prepare reports and share them with other services developed by Google.

Google may use the Personal Data to contextualize and personalize advertisements in its advertising network.

Personal Data collected:Cookies and Usage Data.
Place of processing:USA - Privacy Policy


Facebook Analytics(Facebook Inc.)

Facebook Analytics is a web analytics service provided by Facebook Inc. (“Facebook”). Facebook uses the Personal Data collected to track and examine use of this Website, prepare reports and share them with other services developed by Facebook.

Facebook may use the Personal Data to contextualize and personalize advertisements in its advertising network.

Personal Data collected:Cookies and Usage Data.
Place of processing:USA - Privacy Policy

Displaying content from external platforms

This type of service allows content hosted on external platforms to be displayed directly from the pages of this Website and allows interaction with that content.

If a service of this type is installed, it may collect traffic data relating to the pages on which it is installed even when Users do not use the service.


Google Fonts(Google Inc.)

Google Fonts is a font style display service managed by Google Inc. that allows this Website to integrate such content into its pages.

Personal Data collected:Cookies and Usage Data.
Place of processing:USA - Privacy Policy


Google Maps widget(Google Inc.)

Google Maps is a map display service managed by Google Inc. that allows this Website to integrate such content into its pages.

Personal Data collected:Cookies and Usage Data.
Place of processing:USA - Privacy Policy


Google Maps widget(Google Inc.)

YouTube is a video content display service managed by Google Inc. that allows this Application to integrate such content into its pages.

Personal Data collected:Cookies and Usage Data.
Place of processing:USA - Privacy Policy

Address management and email messaging

These services make it possible to manage a database of email contacts, telephone contacts or contacts of any other kind used to communicate with the User.

These services may also make it possible to collect data relating to the date and time messages are viewed by the User, as well as the User's interaction with them, such as information on clicks on links included in the messages.


MailUp(MailUp S.p.A.)

MailUp is an address management and email messaging service provided by Mailchimp Inc.

Personal Data collected:Cookies and Usage Data.
Place of processing:USA - Privacy Policy

Security measures

The Data Controller processes visitor/User data lawfully and fairly, adopting appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of data. Processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the stated purposes. We are committed to protecting the security of your personal data during transmission by using Secure Sockets Layer (SSL) software, which encrypts the information you enter. It is important that you adopt suitable safeguards against unauthorized use of your website access credentials.

Rights of the User/Data Subject

Pursuant to European Regulation No. 679/2016 (GDPR) and Article 7 of Italian Legislative Decree No. 196 of 30 June 2003, the User may, in accordance with the procedures and within the limits laid down by applicable law, exercise the following rights:

  • object, in whole or in part and on legitimate grounds, to the processing of personal data concerning them for the purpose of sending advertising or direct sales material, conducting market research or carrying out commercial communications;
  • request confirmation as to whether personal data concerning them exists (right of access);
  • know its origin;
  • receive it in an intelligible form;
  • obtain information about the logic, methods and purposes of the processing;
  • request its updating, rectification, integration, erasure, transformation into anonymous form or blocking of data processed unlawfully, including data whose retention is no longer necessary for the purposes for which it was collected;
  • where processing is based on consent, receive, at no cost other than any cost of the medium used, the data they provided to the Controller in a structured, machine-readable form and in a format commonly used by electronic devices;
  • the right to lodge a complaint with the Supervisory Authority (Italian Data Protection Authority);http://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/4535524;
  • and, more generally, exercise all rights granted to them under applicable law.

These rights may be exercised in the forms and within the time limits set out in Article 12 of the GDPR by written communication sent to the Controller, Fitness Investiment Srl, licensee of the “FitActive” trademark, Tax Code 10046400965, VAT No. 10046400965, certified email (PEC): privacy.fitactive@pec.it, email: privacy@fitactive.it, and Privacy telephone number: +39 3665242024, whose operational address for privacy matters is Via Giuseppe di Vittorio No. 4, 20813 Bovisio Masciago (MB), Italy, where the acting individual Privacy Officer responsible for GDPR protection may be contacted.

Requests must be addressed to the Data Controller or the Data Processor.

Please note that, pursuant to applicable law, the Data Subject may exercise the rights granted against the Data Controller under EU Regulation 679/2016, namely:

Right of access (Art. 15)

The Data Subject has the right to obtain from the Controller confirmation as to whether or not personal data concerning them is being processed and, where that is the case, access to the personal data and the following information:

  1. the purposes of the processing;
  2. the categories of personal data concerned;
  3. the recipients or categories of recipient to whom the personal data has been or will be disclosed, in particular recipients in third countries or international organizations;
  4. where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  5. the existence of the right to request from the Controller rectification or erasure of personal data or restriction of processing of personal data concerning the Data Subject, or to object to such processing;
  6. the right to lodge a complaint with a supervisory authority;
  7. where the personal data is not collected from the Data Subject, any available information as to its source;
  8. the existence of automated decision-making, including profiling referred to in Article 22(1) and (4), and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the Data Subject.

Where personal data is transferred to a third country or to an international organization, the Data Subject has the right to be informed of the appropriate safeguards pursuant to Article 46 relating to the transfer.
The Controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the Data Subject, the Controller may charge a reasonable fee based on administrative costs. Where the Data Subject makes the request by electronic means, and unless otherwise requested by the Data Subject, the information shall be provided in a commonly used electronic form.
The right to obtain a copy shall not adversely affect the rights and freedoms of others.

Right to rectification (Art. 16)

The Data Subject has the right to obtain from the Controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the Data Subject has the right to have incomplete personal data completed, including by providing a supplementary statement.

Right to erasure (Art. 17)

The Data Subject has the right to obtain from the Controller the erasure of personal data concerning them without undue delay, and the Controller has the obligation to erase personal data without undue delay where one of the following grounds applies:

  1. the personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed;
  2. the Data Subject withdraws consent on which the processing is based according to Article 6(1)(a), or Article 9(2)(a), and where there is no other legal ground for the processing;
  3. the Data Subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the Data Subject objects to the processing pursuant to Article 21(2);
  4. the personal data has been unlawfully processed;
  5. the personal data must be erased for compliance with a legal obligation under Union or Member State law to which the Controller is subject;
  6. the personal data has been collected in relation to the offer of information society services referred to in Article 8(1).

Where the Controller has made personal data public and is obliged pursuant to paragraph 1 to erase it, the Controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers processing the personal data that the Data Subject has requested the erasure of any links to, or copies or replications of, that personal data.

Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:

  1. for exercising the right of freedom of expression and information;
  2. for compliance with a legal obligation which requires processing under Union or Member State law to which the Controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
  3. for reasons of public interest in the area of public health in accordance with Article 9(2)(h) and (i) and Article 9(3);
  4. for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), insofar as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing;
  5. for the establishment, exercise or defense of legal claims.

Right to restriction of processing (Art. 18)

The Data Subject has the right to obtain from the Controller restriction of processing where one of the following applies:

  1. the accuracy of the personal data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the personal data;
  2. the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of its use instead;
  3. the Controller no longer needs the personal data for the purposes of the processing, but it is required by the Data Subject for the establishment, exercise or defense of legal claims;
  4. the Data Subject has objected to processing pursuant to Article 21(1), pending verification whether the legitimate grounds of the Controller override those of the Data Subject.

Where processing has been restricted under paragraph 1, such personal data shall, with the exception of storage, only be processed with the Data Subject's consent or for the establishment, exercise or defense of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.

A Data Subject who has obtained restriction of processing pursuant to paragraph 1 shall be informed by the Controller before the restriction of processing is lifted.

Right to data portability (Art. 20)

The Data Subject has the right to receive the personal data concerning them, which they have provided to a Controller, in a structured, commonly used and machine-readable format and has the right to transmit that data to another Controller without hindrance from the Controller to which the personal data was provided, where:

  1. the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a), or on a contract pursuant to Article 6(1)(b);
  2. the processing is carried out by automated means.

In exercising their right to data portability pursuant to paragraph 1, the Data Subject has the right to have the personal data transmitted directly from one Controller to another, where technically feasible.

The exercise of the right referred to in paragraph 1 of this Article shall be without prejudice to Article 17. That right shall not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.

The right referred to in paragraph 1 shall not adversely affect the rights and freedoms of others.

The Data Subject has the right to object, on grounds relating to their particular situation, at any time to processing of personal data concerning them which is based on Article 6(1)(e) or (f), including profiling based on those provisions. The Controller shall no longer process the personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.

  • Where personal data is processed for direct marketing purposes, the Data Subject has the right to object at any time to processing of personal data concerning them for such marketing, including profiling to the extent that it is related to such direct marketing.
  • Where the Data Subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
  • The right referred to in paragraphs 1 and 2 shall be explicitly brought to the attention of the Data Subject and shall be presented clearly and separately from any other information at the latest at the time of the first communication with the Data Subject.
  • In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, the Data Subject may exercise their right to object by automated means using technical specifications.
  • Where personal data is processed for scientific or historical research purposes or statistical purposes pursuant to Article 89(1), the Data Subject, on grounds relating to their particular situation, has the right to object to processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

In addition to the rights set out above, the Data Subject has the right to lodge a complaint with the Supervisory Authority where provided by law. The Data Controller reserves the right to make changes to this Privacy Policy at any time by informing Users on this page and, where possible, on this Website, as well as, where technically and legally feasible, by sending a notice to Users through one of the contact details held by the Controller. Users are therefore invited to consult this page regularly. Where changes concern processing whose legal basis is consent, the Controller will obtain the User's consent again where necessary.

Minors

European rules effective from 25 May 2018
The new European Regulation (GDPR), through Article 8, introduced specific rules which do not, however, affect a minor's legal capacity to act, which remains governed by national civil law.
The provision does not generally apply to all processing of minors' data; for it to apply, two requirements must be met:

  • there must be a direct offer of information society services to persons under 16 years of age;
  • the processing of minors' data must be based on consent.

If processing instead has another legal basis, such as compliance with a legal obligation, legitimate interests, etc., the provision does not apply. Where both requirements are met, Article 8 prohibits the direct offer of digital services (including registration with social networks and messaging services) to persons under 16 unless parental consent is obtained (and it must be verified that consent is given by the person exercising parental responsibility) or consent is given by another lawful representative. In essence, the GDPR introduces an exception for the specific cases described above to the general rule established by national law, lowering the age threshold from 18 years (in Italy) and thereby creating a form of digital age of consent at which consent to the processing of personal data, including profiling, is permitted. Member States may lower this threshold further, but not below 13 years. In this context, the Italian legislature set the applicable age in Italy at 14 through the decree adapting the Italian Privacy Code. The rule concerns only the lawfulness of consent to personal-data processing and does not affect the validity of the underlying contract, which remains governed by national law or the law of the forum competent to decide any disputes concerning the service. Recital 38 also states that “the consent of the holder of parental responsibility should not be necessary in the context of preventive or counselling services offered directly to a child.” This refers to services protecting minors, such as those concerning cyberbullying or child support more generally. Indeed, the relevant rules recognize that a minor over 14 may exercise rights intended to protect them against cyberbullying. Italian law also allows a minor who has reached the age of 14 to consent to adoption, which could appear inconsistent with an inability to register on a social network. Social networks generally provide a dedicated form (such as Facebook's) for reporting profiles/accounts belonging to persons below the permitted age, in which case the account is removed.

Online services

At present, the rules of the various online services provide for the following age limits:

Facebook: children under 13 may not register; persons under 16 may register only with parental consent. WhatsApp: children under 13 may not register; persons under 16 require parental consent. Twitter: persons under 16 may not use Periscope.

Privacy Code and legitimate interests

The decree adapting the Italian Privacy Code to the GDPR provides that, where minors' data is processed on the basis of legitimate interests, notification of the processing to the national Data Protection Authority is required only for processing of personal data necessary to authorize a change to a minor's first name or surname.

Publication of photographs online

Publishing a photograph online falls within the processing of personal and sensitive data and constitutes interference with a minor's private life. Particular care must therefore be taken when publishing images of minors, even where they are one's own children. The rule provides that publication of children's photographs requires the consent of both parents. Without the agreement of both parents, the photograph may not be published. In addition, Article 13 of Presidential Decree No. 448 of 22 September 1988 (Code of Juvenile Criminal Procedure) prohibits “the publication and dissemination, by any means, of news or images capable of identifying a minor who is involved in proceedings in any capacity. 2. Paragraph 1 shall not apply after the beginning of the trial if the court proceeds in public session.” The prohibition must also be observed where a minor is involved in any capacity in judicial proceedings concerning matters other than criminal law. Consent by minors is valid from the age of 16. Before the age of 16, consent must be obtained from parents or lawful representatives.

Minors

The Controller does not intentionally collect personal information relating to minors. If information about minors is inadvertently recorded, the Controller will delete it promptly at the Users' request.

Complaints

Each Data Subject has the right, pursuant to Articles 77 et seq. of the GDPR, to lodge a complaint with a supervisory authority, which for Italy is the Garante per la protezione dei dati personali (Italian Data Protection Authority). The forms, methods and time limits for lodging complaints are established and governed by applicable national law. A complaint is without prejudice to administrative and judicial remedies, which in Italy may alternatively be brought before the same Authority or the competent Court.

Profiling

Personal data provided through the forms is NOT subject to profiling.
Profiling allows the Controller to evaluate certain personal aspects of the Data Subject, particularly their preferences, interests and tastes in relation to the products sold and the activities carried out by the Controller, so that the Controller may offer the Data Subject a sales service that is more specific and targeted to their needs.

Validity

This Privacy Policy applies to all current and future fitness centers and related activities operating under the FitActive il Fitness per Tutti brand.

Updates

This Privacy Notice was last updated on 25 May 2018