Cookie Policy
Armal S.p.A. Unipersonale, the Data Controller, informs Users that this website installs technical cookies and, with the User's consent, may install non-technical cookies (e.g., profiling cookies), as detailed below.
You can change your preference at any time using the dedicated icon for consent control (“Your Privacy Choices”) in the lower right corner of the website.
Who we are and what do we do with your personal data?
Armal S.p.A., a company with registered office in Via Fiorentina, 109 - 50052 - Certaldo (Florence, Italy) (hereinafter the “Owner”), acting as Data Controller, takes care of the confidentiality of your personal data/information and ensures that they are protected from any event that may put them at risk of violation.
For this purpose, the Owner implements policies and practices regarding the collection and use of personal data and information, as well as the exercise of the rights granted to Users by the applicable laws. The Owner updates the policies and practices adopted for the protection of personal data each time this is necessary and in the event of regulatory and organizational changes that may affect the processing of Users' personal data.
The Owner has appointed a Data Protection Officer (DPO) that can be contacted for any question about the adopted policies and practices.
You can contact the Data Protection Officer at dpo@armal.biz
How does the Data Controller collect and process your data?
Your personal information will be processed for the following activities:
1. Website browsing
The processing of your personal data/information, such as browsing information like your IP address and the cookies that are saved during your browsing on the website https://www.armal.biz/, are processed by the Data Controller to manage the website and collect information, including in aggregated forms.
Your personal information will not be disclosed or disseminated to undetermined entities.
2. Disclosure to third parties and recipients
Your personal data/information will be prevalently shared with third parties and/or recipients whose activities are necessary for the conduction of the activities related to the aforementioned purposes, as well as to meet regulatory requirements. Any disclosure that does not meet these purposes will require your consent.
In particular, your information will be disclosed to third parties/recipients:
- For the provision of the service (e.g., IT service providers);
- For communications with the financial administration and public supervisory and control bodies, in respect of which the Owner is required to meet specific obligations arising from the specific nature of the activity conducted.
The personal information the Data Controller will process for this purpose are:
- browsing information (IP address).
3. IT security
The Data Controller processes, including through its suppliers (third parties and/or recipients), your personal (e.g., IP address) or traffic data/information collected or obtained, in case of services exposed on the website, to a strictly necessary and proportionate extent to ensure the security and the ability of a network, or servers connected to it, to withstand, at a given level of security, unforeseen events or unlawful or malicious actions affecting the availability, authenticity, integrity and confidentiality of the personal information stored or transmitted.
For these purposes, the Data Controller shall establish procedures for the management of data breaches.
What are cookies and for which purposes are they used?
A “cookie” is a small text file created by certain websites on the user's computer at the time the user accesses a particular site, for the purpose of storing and transporting information. Cookies are sent from a web server (which is the computer on which the visited website is running) to the user's browser (Internet Explorer, Mozilla Firefox, Google Chrome, etc.) and stored on the user's computer; they are then sent back to the website on subsequent visits.
Some operations could not be performed without the use of cookies, which, in some cases, are therefore technically necessary. In other cases, the website uses cookies to facilitate user browsing or to enable users to use the specifically requested services.
Cookies may remain in the system for long periods of time and may also contain a unique identification code. This allows the websites that use them to keep track of the user's browsing within the website itself, for statistical or advertising purposes, to create a personalized profile of the user from the pages the user has visited and to show or send users targeted advertising (“behavioural advertising”).
Which cookies are used and for which primary purposes?
The list below contains the specific categories of cookies used by the Data Controller, with their purposes and the consequence of their de-selection:
| Type of cookie | First-party / third-party | Purpose(s) | Storage time | Consequence if deselected |
|---|---|---|---|---|
| Technical cookies | First-party cookies | Website management. They enable safe and efficient operation and browsing of the website. | Minimum time: end of session, maximum time: 1 year. | These cookies are necessary for the use of the site; blocking them impacts its operation. |
| Third-party cookies | Duration of the session, 30 minutes, 180 days, 1 year or persistent | |||
| Functionality cookies | First-party cookies | They facilitate browsing and the service provided to the user based on a set of criteria selected by the user. | Minimum time: end of session, maximum time: 1 year | It would be impossible to maintain the choices made by users while browsing. |
| Third-party cookies | Minimum time: 30 minutes, 180 days | |||
| Cookie analytics | Third-party cookies | Collect aggregated browsing information from users to optimize the browsing experience and the services. | From 24 hours to 2 years | It would no longer be possible for the Data Controller to collect the aggregated information. |
| Profiling cookies | Third-party cookies | Create user profiles to send advertising messages in line with the preferences expressed by the user during browsing. | Duration of the session, 90 days, 180 days, or persistent | Profiling for the purpose of sending promotional messages would not be possible. |
Third-party cookies
This website also contains third-party cookies, i.e. cookies created by a different website from the one the user is currently visiting.
In particular, users are informed that the website uses the following services that store cookies. The detailed and up-to-date list is shown below and is updated automatically:
Necessary
Google Tag Manager (Google Ireland Limited)
Personal Data processed: Trackers.
Google reCAPTCHA (Google Ireland Limited)
Personal Data processed: answers to questions, clicks, keypress events, motion sensor events, mouse movements, scroll position, touch events, Trackers and Usage Data.
Trackers duration:
- _GRECAPTCHA: duration of the session
- rc::a: indefinite
- rc::b: duration of the session
- rc::c: duration of the session
- rc::f: indefinite
Cloudflare (Cloudflare, Inc.)
Personal Data processed: Trackers and various types of Data as specified in the privacy policy of the service.
Trackers duration:
- _cfuvid: indefinite
- cf_clearance: 30 minutes
Experience
Google Fonts (Google Ireland Limited)
Personal Data processed: Trackers and Usage Data.
Measurement
Google Analytics (Universal Analytics) (Google Ireland Limited)
Personal Data processed: Trackers and Usage Data.
Trackers duration:
- AMP_TOKEN: 1 hour
- _ga: 2 years
- _gac*: 3 months
- _gat: 1 minute
- _gid: 1 day
Meta Events Manager (Meta Platforms Ireland Limited)
Personal Data processed: Trackers and Usage Data.
Trackers duration:
- _fbp: 3 months
- lastExternalReferrer: duration of the session
- lastExternalReferrerTime: duration of the session
Google Analytics 4 (Google Ireland Limited)
Personal Data processed: browser information, device information and Trackers.
Trackers duration:
- _ga: 2 years
- _ga_*: 2 years
Marketing
Meta ads conversion tracking (Meta pixel) (Meta Platforms Ireland Limited)
Personal Data processed: Trackers and Usage Data.
Trackers duration:
- _fbc: 3 months
- _fbp: 3 months
- fr: 3 months
- lastExternalReferrer: duration of the session
- lastExternalReferrerTime: duration of the session
Social buttons
The website https://www.armal.biz/ contains special buttons called social (media) buttons or widgets that depict the icons of social networks (e.g., Facebook, LinkedIn, etc.) and other web services (e.g., YouTube, etc.). They allow users who are browsing the Data Controller's web page to access the relevant social networks with just a click. In this case, the social network and web services collect data relating to the user, while the Data Controller will not share any browsing information or user data collected through its website with social networks and web services accessible through social buttons/widgets. These services create “third-party cookies”. Here are links to the Privacy Policies of the most used social networks and websites to which the buttons refer:
- For Facebook: www.facebook.com/help/cookies
- For LinkedIn: www.linkedin.com/legal/cookie_policy
- For Instagram: privacycenter.instagram.com/policy
- For YouTube: policies.google.com/technologies/cookies
Deselection and activation of “Your Privacy Choices” cookies
Users may, at any time, review, amend or withdraw their choices relating to cookies using the consent control icon displayed in the bottom right corner of the website.
What happens if you do not provide your data?
Please review the consequences of deselecting individual cookies, as outlined in the table above.
How, where and for how long is your data stored?
How do we process your data?
Personal data/information is processed through IT procedures performed by appropriately authorized and trained internal staff, who is authorized to access personal data/information to the extent and within the limits required for the conduction of processing activities concerning users.
The Data Controller will periodically verify the means by which your data are processed and the security measures implemented for said data, which are continuously updated. Also with the help of authorized contractors, the Data Controller will prevent any personal data/information from being collected, processed, archived or stored if it is not necessary, and ensure that the integrity and authenticity of said data/information, as well as their use for actual processing purposes, is protected.
Where are your data processed?
Data/information is mainly stored on servers located within the EU, but can be transferred outside the EU, based on the following guarantees:
- Data privacy framework
- Standard contractual clauses
- Commission adequacy decision
For how long do we process your data?
Cookies: please review the terms of personal data retention, as outlined in the table above.
Website browsing: personal data/information is kept for the time necessary to allow for website browsing and, in any case, for no longer than 12 months, except in cases where events occur that require the intervention of the competent Authorities, also in collaboration with third parties/recipients who take care of the IT security of the Data Controller, to carry out any investigation into the causes that led to the event, as well as to protect the interests of the Data Controller regarding any liability related to the use of the website and the related services.
What are your rights?
In essence, at any time and free of charge, and without any special charges or formalities for your request, you may:
- Obtain confirmation of the processing performed by the Data Controller;
- Access your personal data and be informed about their origin (when data have not been obtained directly by you), the purposes of processing, information regarding the parties to which they are disclosed, the data retention period or the criteria for determining said period;
- Update or correct your personal data, so that it is always exact and accurate;
- Delete your personal data from the databases and/or archives including backup files of the Data Controller in the event, inter alia, that they are no longer necessary for the purposes of the processing or if they are assumed to be unlawful, and provided that the conditions laid down by law are met; and, in any event, whether the processing is not justified by another equally legitimate reason;
- Limit the processing of your personal data to certain circumstances, for example where you have challenged their accuracy, for as long as the Data Controller needs to verify their accuracy. You must also be informed, within a reasonable time, of when the suspension period has ended or the cause of the restriction of processing has ceased to exist, and therefore the restriction itself is lifted;
- Obtain your personal data, if received or processed by the Data Controller with your consent and/or if their processing takes place under an agreement and with automated means, in electronic format, also for the purpose of transmitting them to another Data Controller.
The Data Controller must proceed as required without delay and, in any case, within one month of receiving your request. The time limit may be extended by two months, if necessary, taking into account the complexity and the number of requests received by the Data Controller. In such cases, the Data Controller shall, within one month of receipt of your request, notify you and inform you of the reasons for the extension. To exercise your rights, please contact privacy@armal.biz
How and when can you object to the processing of your personal data?
For reasons relating to your special situation, you can object at any time to the processing of your personal data, if it is based on legitimate interest, by submitting your request to the Data Controller at privacy@armal.biz
You have the right to erase your personal data if there is no legitimate reason that prevails over the reason that gave rise to your request.
Who can you complain to?
Without prejudice to any other administrative or judicial action, you may lodge a complaint with the competent supervisory authority or with the supervisory authority that operates and exercises its powers in Italy where you have your usual residence or work, or, if different, in the Member State where the infringement of Regulation (EU) 2016/679 took place.