Privacy Policy
This document describes how the personal data of users interacting with the website www.jelu.it is managed and processed. This policy is provided pursuant to Regulation (EU) 2016/679 and other applicable legislation and applies exclusively to data collected through this website.
Article 1 – Data Controller and Legal Basis
Pursuant to Art. 13 of EU Regulation 2016/679, General Data Protection Regulation (hereinafter "GDPR"), you are hereby informed that JELU Consulting, Tax Code 97910400585, VAT No. 14145442003, registered office in Rome, at Viale Romania 32, will process, in its capacity as Data Controller, the personal data of the subjects to whom this Policy is addressed, for the purposes and in the manner set out below.
Article 2 – Purposes of Processing
Data is processed for the purpose of obtaining statistical information on the use of services, ensuring the correct functioning of the services offered and improving the browsing experience, as well as sending communications or responding to those received from the Data Subject through the website.
Article 3 – Data Processing
Such data is collected for the purposes described in Article 2 on the basis of the consent expressed by the user. Processing will be carried out in automated and/or manual form in compliance with the provisions of Article 32 of the GDPR.
In any case, personal data will be processed in accordance with the principles of lawfulness and fairness set out in Article 5 of the GDPR, and always operated in such a way as to ensure the confidentiality and security of the information.
Article 4 – Data Retention Period
The Data Controller reserves the right to retain the collected data for a maximum period of 180 (one hundred and eighty) days, in order to fulfil the purposes indicated in Article 2. After this period, the data will no longer be available.
Article 5 – Categories of Data Processed
The following categories of data will be subject to the processing described herein:
-
Browsing data, meaning the technical information automatically collected during a visit to the website and used for statistical and security purposes;
-
Contact data, namely data sent in an optional, explicit and voluntary manner to the Data Controller. By way of example, electronic communications include messages sent by Data Subjects to pages on the main social media platforms managed by the Data Controller, and the completion and/or submission of any forms present on the website www.jelu.it.
Article 6 – Rights of the Data Subject
The Data Subject has the right:
-
Pursuant to Article 15 of the GDPR, to obtain confirmation from the Data Controller as to whether or not processing of their personal data is taking place. If so, the Data Subject has the right to request specific information such as, by way of example, the purposes of processing, the categories of data processed, third parties to whom such data has been or will be disclosed, and the data retention period;
-
Pursuant to Article 16 of the GDPR, to obtain rectification of inaccurate personal data and completion of incomplete data;
-
Pursuant to Article 17 of the GDPR, to obtain, without undue delay, the erasure of personal data held by the Data Controller, where one of the conditions set out in Article 17 is met — the so-called "right to erasure" (or "right to be forgotten"). This will only be possible in the presence of a specific ground such as, for example, the data being no longer necessary for the purposes for which it was collected, the unlawfulness of the processing, or the need for erasure in order to comply with a legal obligation;
-
Pursuant to Article 18 of the GDPR, to request the restriction of processing in the cases provided for therein, namely: where the accuracy of the data is contested, where processing is unlawful but the Data Subject opposes erasure and requests restriction instead, where the data is needed by the Data Subject for the establishment, exercise or defence of legal claims, or where the Data Subject has objected to processing and a determination on whether the legitimate grounds of the Data Controller override those of the Data Subject is pending;
-
Pursuant to Article 19 of the GDPR, the Data Controller shall communicate to each recipient to whom personal data has been disclosed any rectification, erasure or restriction of processing carried out in accordance with Articles 16, 17(1) and 18, unless this proves impossible or involves disproportionate effort;
-
Pursuant to Article 20 of the GDPR, to receive a copy of the data concerning them, in a structured, commonly used and machine-readable format, as provided for therein;
-
Pursuant to Article 21 of the GDPR, to object at any time to the processing of personal data concerning them;
-
Pursuant to Article 34 of the GDPR, in the event of a personal data breach resulting from theft of archives, cyberattacks, accidental events, etc., which may generate a high risk to the rights and freedoms of the Data Subject, such as the indiscriminate disclosure of data to third parties, the Data Controller shall notify the Data Subject without undue delay, in accordance with the applicable provisions.
Requests from the Data Subject addressed to the Data Controller must be submitted in writing to the email address indicated in Article 8 of this Policy. The Data Controller shall fulfil the Data Subject's requests without delay.
Article 7 – Right to Lodge a Complaint with the Supervisory Authority
The Data Subject has the right, at any time, if they believe that the processing of their personal data by the Data Controller infringes the rights enshrined in the Regulation, to lodge a complaint with the competent supervisory authority, pursuant to Article 77 of the GDPR, namely the Italian Data Protection Authority (Garante per la protezione dei dati personali).
Article 8 – Communications to the Data Controller
For further information or to exercise the rights provided for under this Policy, the Data Controller may be contacted at the email address cda@jelu.it . Requests will be handled free of charge and processed by the Data Controller as soon as possible, and in any event within one month of receipt.
Article 9 – Amendments to the Policy
The Data Controller reserves the right to amend or update, in whole or in part, the content of this Policy, including following changes to applicable legislation at European or national level. In the event of amendments, the Data Subject will be asked to provide updated consent upon their next access.
Article 10 – Definitions and Legal References
In order to ensure a correct and informed understanding of this Privacy Policy, it is considered appropriate to provide the correct interpretation of the terms listed below.
It is further specified that for any definitions not included herein, reference should be made to the relevant legislation, namely the General Data Protection Regulation and Legislative Decrees No. 196 of 30 June 2003 and No. 101 of 10 August 2018.
-
"Personal data", pursuant to Art. 4(1) of the GDPR, means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
-
"Processing", pursuant to Art. 4(2) of the GDPR, means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
-
"Profiling", pursuant to Art. 4(4) of the GDPR, means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's professional performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
-
"Data Controller", pursuant to Art. 4(7) of the GDPR, means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Article 11 – Referral Clause
For matters not expressly addressed in this Policy, reference is made to the provisions of the General Data Protection Regulation, Legislative Decrees No. 196 of 30 June 2003 and No. 101 of 10 August 2018, and other applicable legislation in the field.
Cookie Policy
Article 1 – Purpose
This document aims to provide users of the "Jelu.it" website with a clear and detailed explanation of how cookies work, and to transparently illustrate how they are managed and the purposes for which they are used on the platform.
Article 2 – Definition of Cookies
Cookies are small text strings that websites visited by the user send to the computer and to any device used to access the Internet (such as smartphones and tablets), where they are stored and subsequently retransmitted to the same websites upon the user's next visit.
Cookies may be stored permanently and have a variable duration (so-called "persistent cookies"), or may disappear when the browser is closed or have a limited duration (so-called "session cookies"). Likewise, cookies may be installed by the website being visited (so-called "first-party cookies"), or by other websites (so-called "third-party cookies"), and may be used for various purposes, such as performing authentication, session monitoring and storing information about the activities of users accessing a given website.
Cookies are used for the purpose of:
-
obtaining statistical information on the use of services;
-
ensuring the correct functioning of the services offered and improving the browsing experience;
-
sending communications or responding to communications sent by the Data Subject to the website.
Article 3 – Types of Cookies Used
The cookies used on the "Jelu.it" website can be divided into the following categories:
-
Technical cookies: consent to the processing of this data is necessary to enable navigation within the website. This category includes the IP addresses or domain names of computers and terminals used by users, the URI/URL addresses of the requested resources, the time of the request and other parameters relating to the operating system and IT environment of the Data Subject.
-
Preference/tracking cookies: such data is used to track the Data Subject's browsing activity online and to create profiles of their tastes, habits and choices. Through these cookies, advertising messages consistent with the preferences already expressed by the Data Subject during online browsing may be transmitted to the Data Subject's terminal. Specific consent from the Data Subject will always be required for the processing of such data.
-
Data communicated by the Data Subject: also subject to the processing described herein is the contact data of senders who voluntarily, explicitly and optionally send electronic communications to the Data Controller. By way of example, electronic communications include messages sent by Data Subjects to pages on the main social media platforms managed by the Data Controller, and the completion and/or submission of any forms present on the website www.jelu.it .
Article 4 – Third-Party Cookies
This website uses exclusively third-party cookies from Google Analytics and Wix. With regard to Google Analytics specifically:
-
"_ga" used to distinguish users;
-
"ga<container-id>" used to maintain session state.
With regard to Wix specifically:
-
XSRF-TOKEN: Cookie for fraud detection of calls
-
hs: Security Cookie for Hive (legacy)
-
svSession: Session cookie for identification
-
SSR-caching: Performance cookie for rendering
-
TS\: Cookies for attack detection
-
bSession: Used for system effectiveness measurement
-
fedops.logger.sessionId: Tracking session errors and issues (resilience)
-
_wixAB3|\: Cookie for site experiments
-
server-session-bind: Cookie for API protection
-
client-session-bind: Cookie for API protection
For more information, please consult the regulations and policies of Google Analytics and Wix regarding cookies, available on their respective websites.
Article 5 – Cookie Duration
The Google Analytics cookies referred to in Article 4 have a maximum duration of 2 (two) years and the Wix cookies have a maximum duration of 12 months.
For more information on the duration of the cookies referred to in Article 4, please consult the regulations and policies of Google Analytics and Wix regarding cookies, available on their respective websites.
Article 6 – Obtaining Consent
Upon accessing any page of the website, the Data Subject is shown a banner containing a brief Cookie Policy regarding the Data Controller's cookie management practices and the choices available, with the option to obtain more information by consulting this full Cookie Policy. Before proceeding with browsing, the Data Subject is invited to read this detailed Cookie Policy and is asked to indicate their preferences regarding the installation of optional cookies on their browser, by providing or withholding their consent to their use. To this end, the Data Subject may accept the installation of all cookies by clicking the 'ACCEPT ALL COOKIES' button, or refuse it by clicking the 'REJECT ALL COOKIES' button in the banner. Alternatively, they may select specific types of cookies to install by clicking the "SELECT COOKIES" button. It is noted that the toggle switch for enabling or disabling optional cookies is set by default to "Off".
Article 7 – Cookie Management
The user may decide whether or not to allow the use of cookies through their web browser settings. Most web browsers allow users to: check which cookies are installed on their device and delete them individually, block third-party cookies, block cookies from specific websites, block all cookies and/or delete all cookies when the browser is closed.
To manage cookies, the user may refer to the specific documentation for their browser.
Should the user wish to completely disable the use of cookies, they may find their use of certain website features limited, such as access to restricted areas or the customisation of settings.
In particular, disabling necessary technical cookies may compromise the use of the website and render certain features unavailable or not functioning correctly.
Article 8 – Updates to the Cookie Policy
The Data Controller reserves the right to amend or simply update the content of this Cookie Policy, in whole or in part, including as a result of changes to applicable legislation at European or national level. In the event of amendments, the Data Subject will again be shown the relevant banner for renewed consent, incorporating the changes made.
Article 9 – User Rights
In accordance with the General Data Protection Regulation (GDPR) and other applicable legislation, the user has the right to exercise a series of rights regarding their personal data, including that collected through the use of cookies. These rights include:
-
Right of Access: the user has the right to request confirmation of whether or not personal data concerning them is being processed and, if so, to obtain a copy of such data and detailed information on the methods of processing;
-
Right to Rectification: the user has the right to request the correction of any inaccurate or incomplete personal data collected via cookies;
-
Right to Erasure (Right to be Forgotten): the user may request the erasure of their personal data, including that collected via cookies, in the following cases:
-
When the data is no longer necessary for the purposes for which it was collected;
-
When the user withdraws the consent on which the processing is based;
-
When the user objects to processing and there are no overriding legitimate grounds to continue;
-
When personal data has been processed unlawfully.
4. Right to Restriction of Processing: the user may request a restriction of the processing of their personal data in certain circumstances, for example when they contest the accuracy of the data or object to its processing;
5. Right to Data Portability: where technically feasible, the user has the right to receive the personal data provided in a structured, commonly used and machine-readable format, and to transmit it to another data controller;
6. Right to Object: the user has the right to object at any time to the processing of their personal data, including that collected via cookies, where such processing is based on a legitimate interest of the controller or is aimed at direct marketing;
7. Right to Withdraw Consent: where the processing of personal data is based on the user's consent, the user has the right to withdraw such consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
8. Right to Lodge a Complaint with the Supervisory Authority: should the user believe that the processing of their personal data, including that collected via cookies, violates applicable legislation, they have the right to lodge a complaint with the competent supervisory authority for personal data protection.
Article 10 – Contact Information
Pursuant to Art. 13 of EU Regulation 2016/679 (GDPR), you are hereby informed that JELU Consulting, Tax Code 97910400585, VAT No. 14145442003, registered office in Rome, will process, in its capacity as Data Controller, the personal data of the subjects to whom this Cookie Policy is addressed (hereinafter also referred to as "Data Subjects") for the purposes and in the manner set out below.
Such data is collected for the purposes set out in the Privacy and Cookie Policy, on the basis of the consent expressed by the user through the use of the relevant banner or by continuing to browse the website.
The Data Controller may be contacted at the email address: cda@jelu.it.
