GDPR Data Processing Information (Addendum)
Regulatory Reference: Regulation (EU) 2016/679 (GDPR)
This document is an addendum to the Flipeando.com Privacy Policy and is primarily intended for residents of the European Economic Area (EEA) and the United Kingdom, fulfilling the transparency obligations required by the General Data Protection Regulation (GDPR).
1. Data Controller and DPO
The Data Controller for your personal data, as described in the Privacy Policy, is:
Flipeando di Miriam Vadillo
Milan - Italy
Email: privacy@flipeando.com
Data Protection Officer (DPO):
The Controller has appointed a Data Protection Officer (DPO), who can be contacted for all matters related to the processing of your personal data and the exercise of your rights:
DPO Email: dpo@flipeando.com
2. Legal Bases for Processing (Art. 6 GDPR)
We process your personal data only when we have a valid legal basis to do so. The legal bases we rely on to process your data include:
- Contractual Necessity (Art. 6(1)(b)): Necessary for the performance of the service contract to which you are a party (e.g., creation and management of the user account, payment processing, and provision of the Flipbook service).
- Legal Obligation (Art. 6(1)(c)): Necessary for compliance with legal obligations (e.g., tax, accounting, or security requirements).
- Legitimate Interest (Art. 6(1)(f)): Necessary for the purposes of our legitimate interests or those of a third party, provided that your interests or fundamental rights do not override those interests. (e.g., service improvement, fraud prevention, statistical analysis).
- Consent (Art. 6(1)(a)): Where no other legal basis applies, we ask for your explicit consent (e.g., for certain types of direct marketing or the use of non-essential cookies). You have the right to withdraw this consent at any time.
3. Purposes of Processing
The purposes of processing are detailed in Section 2 of our Privacy Policy. The purposes are linked to the legal bases as follows (non-exhaustive examples):
- Account and Service Management: Legal Basis: Contractual Necessity.
- Service Improvement and Security: Legal Basis: Legitimate Interest.
- Direct Marketing: Legal Basis: Consent (or Legitimate Interest for existing customers, where applicable).
- Accounting and Fiscal Compliance: Legal Basis: Legal Obligation.
4. Your Rights Under GDPR (Art. 15-22)
As a data subject, you have the following rights, which you may exercise by contacting the Controller or DPO at the email address provided above:
- Right of Access (Art. 15): To obtain confirmation of whether personal data concerning you are being processed, and a copy thereof.
- Right to Rectification (Art. 16): To obtain the correction of inaccurate personal data or the completion of incomplete data.
- Right to Erasure ("Right to be Forgotten") (Art. 17): To request the deletion of your personal data, under specific conditions (e.g., if the data is no longer necessary for the purposes for which it was collected).
- Right to Restriction of Processing (Art. 18): To request restrictions on how we process your personal data in specific cases.
- Right to Data Portability (Art. 20): To receive the personal data provided in a structured, commonly used, and machine-readable format.
- Right to Object to Processing (Art. 21): To object to the processing of your personal data (e.g., for direct marketing purposes).
- Right to Withdraw Consent: To withdraw consent previously given at any time.
We will respond to your requests within the timeframe mandated by law (typically one month from receipt of the request).
5. International Data Transfers (Art. 44)
Your personal data is primarily processed in Italy. However, we may transfer your data to servers or service providers (third parties) located outside the European Economic Area (EEA), such as the United States, for the performance of our services (e.g., hosting, email marketing).
In such cases, we ensure that the transfer complies with legal provisions, guaranteeing an adequate level of personal data protection through the adoption of:
- Adequacy decisions from the European Commission.
- Standard Contractual Clauses (SCCs) approved by the European Commission.
6. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or the place of the alleged infringement, if you consider that the processing relating to you infringes the GDPR.
For Italy, the competent supervisory authority is the Garante per la Protezione dei Dati Personali (Italian Data Protection Authority) (Piazza Venezia n. 11 - 00187 Roma - Fax: (+39) 06.588.1884 - protocollo@pec.gpdp.it).
End of GDPR Data Processing Information (Addendum)