Privacy Policy

Privacy Policy

The purpose of this document (hereinafter the “Privacy Policy“) is to inform Users about personal data, understood as any information that allows the identification of a natural person (hereinafter the “Personal Data“), collected by the website getplantabox.com (hereinafter the “Application”).

The Data Controller, as subsequently identified, may amend or simply update all or part of this Policy by informing Users. The amendments and updates will be binding as soon as they are published on the Application. The User is therefore invited to read the Privacy Policy each time the Application is accessed.

In the event of non-acceptance of the changes made to the Privacy Policy, the User must cease to use this Application and may request the Data Controller to remove his/her Personal Data.

  1. Personal data collected by the Application

The Data Controller collects the following types of Personal Data:

    1. Content and information provided voluntarily by the User 
      • Contact and content data: this is the Personal Data that the User voluntarily provides to the Application during its use, such as personal details, contact details, access credentials for the services and/or products provided, personal interests and preferences and other personal content, etc.
      • Personal Data collected by social media: Users may share data provided to social media with the Application. The User can control the Personal Data that the Application can access through the privacy settings available in the social media in question. By associating social media accounts with the Application and authorising the Owner to access this Personal Data, the User consents to the acquisition, processing and storage of this Personal Data in accordance with this Privacy Policy.

Failure by the User to provide Personal Data, for which there is a legal or contractual obligation or if they are a necessary requirement for the use of the service or for the conclusion of the contract, will make it impossible for the Controller to provide all or part of its services.

The User who communicates to the Data Controller the Personal Data of third parties is directly and exclusively responsible for their origin, collection, processing, communication or dissemination.

    1. Data and content acquired automatically when using the Application: 
      • Technical Data: The computer systems and software procedures used to operate this Application may acquire, during their normal operation, some Personal Data whose transmission is implicit in the use of Internet communication protocols. This information is not collected in order to be associated with identified Users, but by its very nature could, through processing and association with Data held by third parties, allow Users to be identified. This category includes IP addresses or domain names used by Users connecting to the Application, URI (Uniform Resource Identifier) notation addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained, etc.
      • Usage Data: Personal Data relating to the use of the Application by the User may also be collected, such as the pages visited, the actions performed, the functions and services used.
    2. Personal data collected through cookies or similar technologies:

The Application uses cookies, web beacons, unique identifiers and other similar technologies to collect Personal Data on the pages, links visited and other actions performed when using our services. They are stored and then retransmitted on the next visit by the same User.

The User can view the full Cookie Policy at the following address: https://getplantabox.com/cookie-policy/.

  1. Purpose

The Personal Data collected may be used for the performance of contractual and pre-contractual obligations and for legal obligations as well as for the following purposes:

    1. User registration and authentication: to allow the User to register on the Application in order to access and be identified.

Personal Data are disclosed to Google Inc., www.google.com/privacy; Facebook Inc. https://www.facebook.com/policy.php

    1. Login through accounts on external platforms: to allow the User to log in to the Application through an account on external platforms (e.g. Google, Facebook).

Personal Data are disclosed to Google Inc., www.google.com/privacy; Facebook Inc. https://www.facebook.com/policy.php

    1. Sending emails or newsletters and managing mailing lists: to contact the User with emails containing commercial and promotional information relating to the Application.

Personal Data is disclosed to Klaviyo Inc., https://www.klaviyo.com/privacy/policy; ActiveCampaign, LLC, https://www.activecampaign.com/legal/privacy-policy.

    1. Communication via live chat: to allow the User to interact with a live chat on the Application.
    2. External processing of payments by credit card, bank transfer or other means: to process Users’ payments via external platforms that acquire payment data without the Application owner having access.

Personal Data is disclosed to PayPal, https://www.paypal.com/it/webapps/mpp/ua/privacy-full; Stripe, https://stripe.com/it/legal.

    1. Statistics with anonymous data only: to carry out statistical analyses based on aggregated data or data that do not allow the User to be identified.
    2. Comment and feedback: to allow the User to submit reviews or comments.

Personal Data is disclosed to the various brands and/or distributors that supply products to PlantaBox

    1. Management of User databases: to organise, access and modify User data.

Personal Data is disclosed to WordPress, https://it.wordpress.org/about/privacy/; Woocommerce, https://docs.woocommerce.com/document/marketplace-privacy/.

    1. Statistics with anonymous data only: to carry out statistical analyses based on aggregated data or data that do not allow the User to be identified.

Personal Data are disclosed to Google Inc., www.google.com/privacy; Facebook Inc. https://www.facebook.com/policy.php

    1. Advertising targeting and remarketing: to show more relevant advertisements to the User based on his browsing behaviour and preferences.

Personal Data are disclosed to Google Inc., www.google.com/privacy; Facebook Inc. https://www.facebook.com/policy.php

    1. Own market research and surveys: to carry out market research and surveys in-house.

Personal Data is disclosed to the various brands and/or distributors that supply products to PlantaBox

    1. Market research and third-party surveys: to conduct market research and third-party surveys.
  1. Treatment modes

The processing of Personal Data is carried out by means of computer and/or telematic tools, with organisational methods and logics strictly related to the purposes indicated.

In some cases, subjects involved in the organization of the Data Controller (such as, for example, personnel management personnel, sales staff, system administrators, etc.) or external subjects (such as IT companies, service providers, postal couriers, hosting providers, etc.) may also have access to Personal Data. These subjects, if necessary, may be appointed as Data Processors by the Data Controller, as well as have access to the Personal Data of the Users whenever necessary and will be contractually obliged to keep the Personal Data confidential.

An up-to-date list of Responsible Persons can be obtained by emailing [email protected]

  1. Legal basis of processing

The processing of Personal Data relating to the User is based on the following legal bases:

    1. the consent given by the User for one or more specific purposes;
    2. processing is necessary for the performance of a contract with the User and/or the implementation of pre-contractual measures
    3. the processing is necessary to comply with a legal obligation to which the Controller is subject
    4. processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller
    5. the processing is necessary for the pursuit of the legitimate interest of the Controller or of third parties
    6. the processing is necessary for the pursuit of a vital interest of the Controller or of a third party.

However, it is always possible to ask the Controller to clarify the legal basis of each processing operation at [email protected]

  1. Location

The Personal Data are processed at the operational headquarters of the Data Controller and in any other place where the parties involved in the processing are located. For further information, please contact the Data Controller at the following email address [email protected] or at the following postal address Via Bellavista 80, Monte di Procida 80070 Italy.

  1. Security measures

The Processing is carried out according to methods and with tools suitable to guarantee the security and confidentiality of Personal Data, the Data Controller having adopted adequate technical and organisational measures that guarantee, and allow to demonstrate, that the Processing is carried out in compliance with the reference legislation.

  1. Period of Data Retention

Personal Data will be kept for the period of time necessary to fulfil the purposes for which they were collected.

In particular, Personal Data will be retained for the entire duration of the contractual relationship, for the performance of the inherent and consequent fulfilments thereof, for compliance with applicable legal and regulatory obligations, as well as for own or third party defence purposes.

Where the processing of Personal Data is based on the User’s consent, the Controller may retain the Personal Data until the consent is revoked.

Personal Data may be kept for a longer period if necessary to fulfil a legal obligation or by order of an authority.

All Personal Data will be deleted or stored in a form that does not allow the User to be identified within 30 days of the end of the storage period. Upon expiry of this period, the right of access, cancellation, rectification and the right to portability of Personal Data may no longer be exercised.

  1. Automated decision-making processes

All Personal Data collected will not be subject to any automated decision-making process, including profiling, which may produce legal effects for the individual or which may significantly affect the individual.

  1. User rights

Users may exercise certain rights with regard to Personal Data processed by the Data Controller. In particular, the User has the right to:

    1. withdraw consent at any time;
    2. oppose the processing of their Personal Data;
    3. access their Personal Data;
    4. verify and request rectification;
    5. obtain the limitation of processing;
    6. obtain the deletion of their Personal Data;
    7. receive their Personal Data or have them transferred to another data controller;
    8. file a complaint with the data protection supervisory authority and/or take legal action.

In order to exercise their rights, Users may address a request to the contact details of the Controller indicated in this document. Requests are made free of charge and processed by the Controller as quickly as possible, in any case within 30 days.

  1. Data Controller

The Data Controller is SCORAP S.R.L., with registered office in Via Bellavista 80, 80070 Monte di Procida , Tax code/VAT number 09763231215, e-mail address [email protected], PEC address [email protected]

Last updated: 23/06/2021