English
GBP
Privacy Policy - Terms and Conditions of Use
Privacy Policy - Terms and Conditions of Use
Privacy Policy

This Application collects some Personal Data from its Users.
Users may be subject to different levels of protection. Some Users therefore enjoy higher protection.
More information about the protection criteria can be found in the applicability section.

Data Controller

San Ruffino Labs LTD

6 - Mdina Road
cap BZN9031
Balzan
Malta
VAT MT26410906

Owner's email address: info@sanruffinolabs.com

Types of Data collected

Among the Personal Data collected by this Application, either independently or through third parties, there are: Email, Name, Surname, Phone number, Cookies and Usage Data.
Full details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed before the data are collected.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Application.
Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to communicate them, it may be impossible for this Application to provide the Service. In cases where this Application indicates some Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or on its operation.
Users who have doubts about which Data are mandatory are encouraged to contact the Owner.
Any use of Cookies – or other tracking tools – by this Application or by the owners of third-party services used by this Application, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to the other purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Application and guarantees that he/she has the right to communicate or disseminate them, freeing the Owner from any liability towards third parties.

Method and place of processing of the collected data

Treatment methods
The Owner adopts appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data.
The processing is carried out using computer and/or telematic tools, with organizational methods and with logic strictly related to the purposes indicated. In addition to the Owner, in some cases, other parties involved in the organization of this Application (administrative, commercial, marketing, legal, system administration personnel) or external parties (such as third party technical service providers, postal couriers, hosting providers, IT companies, communications agencies) may have access to the Data, also appointed, if necessary, as Data Processors by the Owner. The updated list of Data Processors may always be requested from the Data Controller.

Legal basis for processing
The Data Controller processes Personal Data relating to the User if one of the following conditions exists:

the User has given consent for one or more specific purposes; Note: in some jurisdictions the Owner may be allowed to process Personal Data without the User's consent or any other of the legal bases specified below, until the User objects (“opts-out”) to such processing. However, this does not apply when the processing of Personal Data is regulated by European legislation on the protection of Personal Data;
processing is necessary for the performance of a contract with the User and/or for the execution of pre-contractual measures;
processing is necessary to fulfill a legal obligation to which the Data Controller is subject;
processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
processing is necessary for the pursuit of the legitimate interest of the Owner or third parties.
It is always possible to ask the Owner to clarify the specific legal basis of each treatment and in particular to specify whether the treatment is based on the law, provided for by a contract or necessary to conclude a contract.

Place
The Data is processed at the Data Controller's operating offices and in any other place where the parties involved in the processing are located. For further information, contact the Data Controller.
The User's Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the place of processing, the User can refer to the section concerning the details on the processing of Personal Data.
In case of higher protection, the User has the right to obtain information regarding the legal basis of the transfer of Data outside the European Union or to an international organization of public international law or consisting of two or more countries, such as the UN, as well as regarding the security measures adopted by the Owner to protect the Data.
If one of the transfers described above takes place, the User can refer to the respective sections of this document or request information from the Owner by contacting him at the contact details provided at the beginning.

Retention period
The Data is processed and stored for the time required by the purposes for which it was collected.
Therefore:

Personal Data collected for purposes related to the performance of a contract between the Owner and the User will be retained until the performance of such contract is completed.
Personal Data collected for purposes related to the legitimate interest of the Owner will be retained until such interest is fulfilled. The User can obtain further information regarding the legitimate interest pursued by the Owner in the relevant sections of this document or by contacting the Owner.
When the processing is based on the User's consent, the Owner may retain the Personal Data for a longer period until such consent is revoked. Furthermore, the Owner may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, the Personal Data will be deleted. Therefore, at the end of such period, the right of access, deletion, rectification and the right to portability of the Data can no longer be exercised.

Purpose of the Processing of Collected Data
User Data is collected to allow the Owner to provide its Services, as well as for the following purposes: Contacting the User, Handling payments, Interaction with external social networks and platforms, Displaying content from external platforms and Managing contacts and sending messages.
To obtain further detailed information on the purposes of the processing and on the Personal Data specifically relevant for each purpose, the User can refer to the relevant sections of this document.

Details on the processing of Personal Data
Personal Data is collected for the following purposes and using the following services:

Contact the User
Mailing list or newsletter (this Application)
By registering for the mailing list or newsletter, the User's email address is automatically added to a list of contacts to which email messages containing information, including commercial and promotional information, relating to this Application may be transmitted. The User's email address may also be added to this list as a result of registering for this Application or after making a purchase.

Personal Data collected: last name, email and name.
Contact form (this Application)
By filling in the contact form with their Data, the User consents to their use to respond to requests for information, quotes, or any other nature indicated by the form header.

Personal Data collected: last name, email and name.
Managing contacts and sending messages
This type of service allows you to manage a database of email contacts, telephone contacts or contacts of any other type, used to communicate with the User.
These services may also allow us to collect data relating to the date and time the messages are viewed by the User, as well as the User's interaction with them, such as information on clicks on links inserted in messages.
MailChimp (The Rocket Science Group, LLC.)
MailChimp is an email address management and message sending service provided by The Rocket Science Group, LLC.

Personal Data collected: last name, email and name.
Place of processing: United States – Privacy Policy. Privacy Shield participant.

Payment Management
Payment management services allow this Application to process payments by credit card, bank transfer or other means. The data used for payment are acquired directly by the manager of the requested payment service without being in any way processed by this Application.
Some of these services may also allow the scheduled sending of messages to the User, such as emails containing invoices or notifications regarding payment.
PayPal (Paypal)
PayPal is a payment service provided by PayPal Inc., which allows the User to make online payments.
Personal Data collected: various types of Data as specified in the privacy policy of the service.
Place of processing: See Paypal privacy policy – ​​Privacy Policy.
PayPal Carrier Payments (Paypal)
PayPal Carrier Payments is a payment service provided by PayPal, Inc., which allows the User to make online payments using his mobile operator.
Personal Data collected: phone number and various types of Data as specified in the privacy policy of the service.
Place of processing: See Paypal privacy policy – ​​Privacy Policy.
PayPal Payments Hub (Paypal)
PayPal Payments Hub is a payment service provided by PayPal Inc.
Personal Data collected: various types of Data as specified in the privacy policy of the service.
Place of processing: See Paypal privacy policy – ​​Privacy Policy.

Interaction with social networks and external platforms
This type of service allows interaction with social networks, or other external platforms, directly from the pages of this Application.
The interactions and information acquired by this Application are in any case subject to the User's privacy settings relating to each social network.
If a service for interaction with social networks is installed, it is possible that, even if the Users do not use the service, it collects traffic data relating to the pages on which it is installed.
Facebook Like button and social widgets (Facebook, Inc.)
The “Like” button and Facebook social widgets are services of interaction with the social network Facebook, provided by Facebook, Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy. Privacy Shield participant.
Tweet button and Twitter social widgets (Twitter, Inc.)
The Tweet button and Twitter social widgets are services of interaction with the Twitter social network, provided by Twitter, Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy. Privacy Shield participant.
PayPal button and widget (Paypal)
The PayPal button and widgets are interaction services with the PayPal platform, provided by PayPal Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing: See Paypal privacy policy – ​​Privacy Policy.
+1 button and Google+ social widgets (Google Inc.)
The +1 button and Google+ social widgets are services for interacting with the Google+ social network, provided by Google Inc.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy. Privacy Shield participant.
Linkedin button and social widgets (LinkedIn Corporation)
The LinkedIn button and social widgets are services of interaction with the Linkedin social network, provided by LinkedIn Corporation.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy.
YouTube social button and widgets (Google Inc.)
The YouTube button and social widgets are services of interaction with the YouTube social network, provided by Google Inc.

Personal Data collected: Usage Data.
Place of processing: United States – Privacy Policy. Privacy Shield participant.

Viewing content from external platforms
This type of service allows you to view content hosted on external platforms directly from the pages of this Application and interact with them.
In the event that a service of this type is installed, it is possible that, even if the Users do not use the service, it collects traffic data relating to the pages on which it is installed.
Google Maps Widget (Google Inc.)
Google Maps is a map viewing service managed by Google Inc. that allows this Application to integrate such content within its pages.
Personal Data collected: Cookies and Usage Data.
Place of processing: United States – Privacy Policy. Privacy Shield participant.
Further information on Personal Data

Selling goods and services online
The Personal Data collected are used to provide services to the User or to sell products, including payment and any delivery. The Personal Data collected to complete the payment may be those relating to the credit card, the bank account used for the transfer or other payment instruments provided. The Payment Data collected by this Application depends on the payment system used.
Automated decision-making processes
When a decision that may produce legal effects for the User or may have a similarly significant impact on his person is taken exclusively by technological means and without human intervention, an automated decision-making process occurs.
Within the scope of the purposes described in this document, this Application may use the User's Personal Data to make decisions based entirely or partially on automated processes. This Application uses automated decision-making processes to the extent necessary to conclude or perform a contract between User and Owner, or, where required by law, upon consent given by the User.
Automated decisions depend on technological tools provided by the Owner or by third parties and are generally based on algorithms that respond to predefined criteria. The logic underlying automated decision-making processes aims to:
enable or improve the decision-making process;
guarantee Users fair and impartial treatment;
reduce the potential harm resulting from human error, personal bias or other similar circumstances that could lead to discrimination or imbalance in the treatment of individuals;
reduce the risk of failure by the User to fulfill his/her obligations under a contract.
To obtain further information on the purposes, any third-party services and on the specific logic of the automated decision-making processes adopted by this Application, the User can refer to the respective sections of this document.

Effects of automated decision-making processes and rights of Users subject to them
Users subject to this type of processing may exercise specific rights aimed at preventing or limiting the potential effects of automated decision-making processes. In particular, Users have the right to:
receive an explanation of any decision taken as a result of automated decision-making and express a view on it;
challenge the decision by asking the Data Controller to reconsider it or adopt a new decision on different bases;
request and obtain from the Owner a human intervention in the treatment. To obtain further information on the rights of the Users and on their exercise, the User can refer to the section of this document relating to the rights of the Users.
Personal Data collected through sources other than the User
The Owner of this Application may have legitimately collected Personal Data relating to the User without his involvement, drawing on sources provided by third parties, in accordance with the legal bases described in the section relating to the legal bases of the processing.
If the Owner has collected Personal Data in this way, the User may find specific information regarding the sources in the respective sections of this document or by contacting the Owner.
Analysis of User Data and Predictions (“Profiling”)
The Owner may process the usage data collected through this Application to create or update user profiles. This type of processing allows the Owner to evaluate choices, preferences and behavior of the User for the purposes specified in the respective sections of this document.
User profiles can also be created using automated tools, such as algorithms, which can also be offered by third parties. To obtain further information on the profiling activity, the User can refer to the respective sections of this document.
The User has the right to object to such profiling activity at any time. To learn more about the User's rights and how to exercise them, the User can refer to the section of this document relating to User rights.
User Rights
Users may exercise certain rights with reference to the Data processed by the Owner.
In case of higher protection, the User can exercise all the rights listed below. In any other case, the User can contact the owner to find out which rights are applicable in his case and how to exercise them.
In particular, the User has the right to:

revoke consent at any time. The User may revoke consent to the processing of their Personal Data previously expressed.
object to the processing of your Data. The User may object to the processing of their Data when it occurs on a legal basis other than consent. Further details on the right to object are indicated in the section below.
access their Data. The User has the right to obtain information on the Data processed by the Owner, on certain aspects of the processing and to receive a copy of the Data processed.
verify and request rectification. The User can verify the accuracy of their Data and request its updating or correction.
obtain the limitation of the processing. When certain conditions apply, the User can request the limitation of the processing of their Data. In this case, the Owner will not process the Data for any purpose other than their conservation.
obtain the deletion or removal of their Personal Data. When certain conditions apply, the User may request the deletion of their Data by the Owner.
receive your Data or have it transferred to another owner. The User has the right to receive his/her Data in a structured, commonly used and machine-readable format and, where technically feasible, to obtain the transfer without hindrance to another owner. This provision is applicable when the Data is processed with automated tools and the processing is based on the User's consent, on a contract to which the User is a party or on contractual measures connected to it.
lodge a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.
Details on the right to object
When Personal Data is processed in the public interest, in the exercise of public authority vested in the Owner or to pursue a legitimate interest of the Owner, Users have the right to object to the processing for reasons related to their particular situation.
Users are hereby informed that, if their Data is processed for direct marketing purposes, they may object to the processing without providing any justification. To find out whether the Data Controller processes data for direct marketing purposes, Users may refer to the respective sections of this document.
How to exercise your rights
To exercise User rights, Users may direct a request to the Owner's contact details indicated in this document. Requests are filed free of charge and processed by the Owner as soon as possible, in any case within one month.

Applicability of the higher level of protection
While most of the provisions of this document apply to all Users, some are expressly subject to the applicability of a higher level of protection to the processing of Personal Data.
This higher level of protection is always guaranteed when the processing:

is performed by a Data Controller based in the EU; or
concerns Personal Data of Users located in the EU and is functional to the offer of goods or services for a fee or free of charge to such Users; or
concerns Personal Data of Users who are located in the EU and allows the Owner to monitor the behavior of such Users to the extent that such behavior takes place within the Union.
Cookie Policy
This Application uses Cookies. To learn more and view the detailed information, the User can consult the Cookie Policy.

More information about the treatment

Defense in court
The User's Personal Data may be used by the Owner in court or in the preparatory stages of its possible establishment for the defense against abuse in the use of this Application or related Services by the User.
The User declares to be aware that the Owner may be required to reveal the Data by order of public authorities.

Specific information
Upon request of the User, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

System logs and maintenance
For needs related to operation and maintenance, this Application and any third-party services used by it may collect system logs, which are files that record interactions and may also contain Personal Data, such as the User's IP address.

Information not contained in this policy
Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

Response to “Do Not Track” requests
This Application does not support “Do Not Track” requests.
To find out if any third-party services used support them, the User is invited to consult their respective privacy policies.

Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by giving notice to Users on this page and, if possible, on this Application and, if technically and legally feasible, by sending a notification to Users through one of the contact details held by the Data Controller. Please therefore consult this page regularly, referring to the date of the last modification indicated at the bottom.
If the changes affect treatments whose legal basis is consent, the Data Controller will collect the User's consent again, if necessary.

Definitions and legal references

Personal Data (or Data)
Personal data is any information that, directly or indirectly, even in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.

Usage Data
This information is collected automatically through this Application (also from third-party applications integrated into this Application), including: the IP addresses or domain names of the computers utilized by the User who connects to this Application, the URI (Uniform Resource Identifier) ​​addresses, the time of the request, the method utilized to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server's response (successful, error, etc.), the country of origin, the characteristics of the browser and operating system utilized by the visitor, the various temporal connotations of the visit (for example, the time spent on each page) and the details relating to the itinerary followed within the Application, with particular reference to the sequence of pages visited, the parameters relating to the operating system and the User's IT environment.

User
The individual using this Application who, unless otherwise specified, coincides with the Data Subject.

Interested
The natural person to whom the Personal Data refers.

Data Controller (or Controller)
The natural person, legal person, public administration or any other entity that processes personal data on behalf of the Owner, as set out in this privacy policy.

Data Controller (or Owner)
The natural or legal person, public authority, service or other body which, individually or together with others, determines the purposes and means of the processing of personal data and the tools used, including the security measures relating to the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.

This Application
The hardware or software tool by which the Personal Data of Users is collected and processed.

Service
The Service provided by this Application as defined in the relevant terms (if any) on this site/application.

European Union (or EU)
Unless otherwise specified, any reference to the European Union contained in this document shall be deemed to extend to all current member states of the European Union and the European Economic Area.

Cookie
Small portion of data stored within the User's device.

Legal references
This privacy policy is drafted on the basis of multiple legislative systems, including Articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy policy applies exclusively to this Application.