1 Purpose of the processing and type of data
Personal data, common and sensitive, are provided by users (personal data, gender, contact details, bank details or commercial references) with the registration act on the site, or later if the user intends to complete his personal profile or communicate / share it with other users. The data are entered in the data base of the data controller and are collected through the creation of three user profiles: private seller, professional seller, simple buyer. The user who visits the site is not registered and his data will remain anonymous. The data acquired are processed for the main purpose of providing and operating the services requested by users on the gem24k Marketplace through the website www.gem24k.com, for example; to edit and make available on the web pages promoting catalogs and offering products for sale by users or to ban users’ products for sale via an auction managed by the site owner; monitor the correct fulfillment of the execution of the sale even with guarantee deposit services; receive or make payments of the price of the Products sold; estimate products; registration and cataloging of research or exchange of products or contacts for assistance or other communications on the site provided by users for the purposes of observation, statistics, reporting, evaluation and qualification of users of the site, security and protection against untruthful access or not permitted or by actions potentially harmful to users’ rights. Additional personal data, provided by the User for the optional, explicit and voluntary submission of comments to posts, to forums and groups of the site and to comments or reviews of products or to receive e-mail communications to the addresses indicated on the site, entail the subsequent acquisition of the sender’s address, necessary to respond to his requests, as well as any other personal data included in the message. The computer systems and software procedures used to operate this marketplace automatically acquire, during their normal operation, some personal data during navigation, the transmissions of which are implicit in the use of Internet communication protocols. This are information that is not collected to be associated with identified interested parties, but which by their very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of the computers used by users connecting to the site, the addresses in the Uniform Resource Identifier (URI) notation of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (success, error, etc.) and other parameters relating to the operating system and the user’s computer environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the site and to check its correct functioning. The data could be used to ascertain responsibility in case of hypothetical computer crimes to the detriment of the site and be communicated, for this purpose, to the Authorities responsible for preventing and protecting against illegal behavior towards the site, its managers or third parties.
Those who register on the site and consent to this information, authorize the data controller to edit and publish the aforementioned data on the site, without prejudice to the right of the data controller to evaluate the content and not to divulge or disclose it only in part.
2 Consent to the processing of personal data
Those who register on the site express their clear and explicit consent to the information given in point 1 above, and authorize the data controller to process personal data in the manner described in this document. The consent is also issued for:
edit and publish the aforementioned data on the website, without prejudice to the right of the data controller to evaluate the content and not to divulge or disclose it in part;
receive direct or even automated communications (e.g. newsletters) on their e-mail address from the site operator regarding information or offers also for marketing on the services of the site to which they are registered;
complete the profiling of the interested party on the basis of the information provided in this statement and according to the logic of the services offered by the marketplace.
3 Processing of personal data
The personal data being processed are collected and recorded for specific, explicit and legitimate purposes, and used in other processing operations in terms compatible with these purposes, they are relevant, complete and not excessive in relation to the purposes for which they are collected or subsequently processed , are kept in a form that allows the identification of the interested party for a period of time not exceeding that necessary for the purposes for which they were collected or subsequently processed. Personal data is voluntarily provided by the User at the time of its registration on the site www.gem24k.com choosing the profile among those offered by the system: a) the “Buyer” specifies name, surname, email; b) the “Private Seller”; c) the “Professional Vendor”. The Purchaser, by concluding the registration procedure, can immediately operate on the site. The Private Seller and the Professional Vendor must complete all the fields of the form made available for registration, specifying: name, surname, email, landline, mobile phone, address (street, city, country), name and URL of the store to be private seller. All this information are stored on the system in the user profile and all (with the exception of the mobile number, name and surname) associated with the public profile of the Seller, visible to all users of the site in the “Seller’s Shop” section. The user can decide whether or not to display his email in the public information of his store. The system checks the email entered, through a confirmation email sent to the user, and the mobile number, through a verification code sent via SMS. After successful completion of the checks, the system records the user’s profile with the information entered and initiates a second phase of collecting information on the Seller, which he presents for verification the information entered in relation to the user’s Store and asks to specify the online payment methods supported (PayPal and Stripe). For the Professional Vendor, the registration system asks for further information, which will not be displayed on its public profile, with the exception of the operational headquarters: copy of valid identity document (passport, identity card, driving license), company name of the company, VAT number, registered office address, address of any operational office, copy of the Chamber of Commerce Inspection, municipal authorization or other body responsible for issuing a license or other qualification to practice professional or commercial activity, invoice for a user, 4 images of the company’s physical store. All text fields are stored in the user’s profile. All attached documents are sent to the attention of the gem24k marketplace manager. After the registration procedure, established for the chosen profile, the Seller is enabled to operate on the marketplace through the purchase of one of the packages made available.
The data are entered and organized in archives prepared mainly in an automated form for the purposes indicated above, stored on computer media at an external server owned by Siteground (https://www.siteground.it/), located in the cloud in Milan – in Italy (European Union), and processed with the aid of IT and telematics tools according to the logic related to the purposes of the processing in order to guarantee its security, integrity and confidentiality.
The treatments are carried out using computerized methods, on computer systems and servers entrusted with the custody and management by a qualified system administrator, and subjected to appropriate security measures: by the site owner; from the staff (internal and external) in charge of the treatment; by the staff in charge, which the data controller uses, for the administration of the site and its operating system and for the management of the electronic flow of information and data processed, as well as for monitoring and security of relations between users also for the accounting of any economic fees for the services provided by the site. The owner of the data processing and the site collects data related to access and navigation within the site to allow the operation of the services and sections, which require identification of the user, and uses the information collected for the administration site technique and for any statistical analysis about the use of the site itself. The data controller uses global statistics on the type of traffic and other information related to the site.
The data that the individual user has authorized to publish on the site are in fact disseminated online in Italy and in third countries and can be communicated to other users, also based in third countries, according to the access profiles authorized and related to the activities of sale, payment, price and shipping of the product requested by the user: they can also be communicated to the persons in charge of data processing in Italy.
The duration of data retention is linked to the fulfillment of the purposes of the processing and ceases with their conclusion or following termination of the relationship for the services requested to the marketplace holder on withdrawal and request for cancellation of the user or for termination and / or disappearance and / or bankruptcy and / or cancellation of the interested party, resulting from public databases or for cancellation by the data controller against a significant period of unjustified non-use of services, without prejudice to the retention of data to fulfill law or historical archiving.
The portal www.gem24k.com keeps, for the duration allowed by law and by reason of the duration of use of the site, the technical data related to the connections (log) to allow the security checks required by law and in order to improve the quality the services offered and customize them according to the needs of users / visitors.
5 Rights of the interested party
With regard to personal data by virtue of CHAPTER III Rights of the interested party Section I “Transparency and Mode” articles 12 et seq. of the European Union Regulation no. 2016/679 on the protection of personal data, the User may request and obtain confirmation of their existence, even if not yet registered, and their communication in intelligible form. The User has the right to obtain information about: the origin of personal data (subjects from which they are collected), the purposes and methods of processing, the criteria and the logic of the processing carried out with the aid of electronic tools, the details of the owner and of any appointed manager, of the subjects or categories of subjects to whom the data are communicated, of the possible transfer abroad of the data and its modalities, of the retention period of the data or the criteria used to establish it, of any automated decision-making processes including profiling and their expected logic and consequences. The User can also ask: the update; the rectification and integration of incomplete or inaccurate data; their cancellation, transformation into anonymous form or blocking when the treatment violates legal regulations, including those that do not need to be kept for the purposes for which the data were collected or subsequently processed; the attestation that the aforementioned operations have been brought to the attention, even in their content, of those to whom the data have been communicated or disseminated, except in cases where such fulfillment proves impossible or the use of excessively burdensome and disproportionate means with respect to the protected right; portability; the limitation of treatment. The User may object, in whole or in part, to the processing of data for legitimate reasons. The opposition may result in the total or partial impossibility of the data controller to continue to provide the services requested by the User. In case the User is not satisfied with the feedback that will provide the data controller or his / her manager, he / she will be able to appeal / claim to the Guarantor for the protection of personal data as provided for in Chapter VIII articles 77 and following of the EU Regulation European n. 2016/679 on the protection of personal data. Any requests, communications or complaints from the interested party may be addressed to the data controller by e-mail at the address firstname.lastname@example.org.
6.2 Third-party cookies related to Social Media Plug-Ins
The social media plug-ins used by the site come from:
The User who wishes to know more about cookies, including flash cookies / local storage tools, on the following sites can acquire further information:
If the user does not interact with the consent forms and leaves the information by closing it or continuing browsing the site, the consent is intended for all the cookies indicated above.
In addition to the links suggested so far for each type of cookie, each browser offers methods to limit or disable cookies. For more information on cookie management visit the appropriate links:
6.3 Google Analytics
The site uses the analytical cookie of Google Analytics, capable of tracking the IP addresses, configured in such a way as to reduce the possibility of using the user’s data by Google for purposes unrelated to the provision of the service and in particular for purposes remarketing and reporting on advertising of Products or other commercial communications.
7 Obligation to process and consent of the interested party
Common and sensitive data can only be processed with the express consent of the user. The consent is expressed freely by requesting the affixing of a specific flag to the quadrant prepared by the system administrator and can be revoked at any time. Consent is not mandatory but necessary as a refusal may imply the impossibility of carrying out the services provided by the site. On the site, for particular processing purposes or for certain types of data, there are specific information and, where necessary, also express requests for consent or authorization through the request for flagging or replying to messages forwarded by the operating system or directly from the site administrator. The processing of data is lawful and legitimate as performed in fulfillment of contractual obligations and legal obligations.
8 Site security measures
For the management of the site specific security measures have been adopted, aimed at guaranteeing secure access and protecting the information contained therein from risks of loss or destruction, even accidental. The owner of the data processing and the site, while ensuring the adoption of appropriate Antivirus systems, reminds that, in addition to being a legal obligation, it is appropriate for the user to equip their workstation with a prevention system and scan against the virus attack. For access to the dedicated part of the site, an identification code and password are assigned to the users; these passwords are generated at the request of the same users according to criteria established by the site administrator. The user is required to keep the password confidential and failing to assume any responsibility for use by third parties.
The registration to the site and the services provided by it do not involve any participation or activity of the owner of the data processing and of the site to the relationships established or not established thanks to the site. Users are registered on the site at their request and provide their data, including personal data. The system administrator identifies the user through the acquisition of a copy of his identity document or other social documents or of his business activity and if it is necessary to verify its authenticity. The commercial relationships between users, except for online auctions, are carried out outside the site and are brought to the attention of the site only on the initiative of users. The owner of the data and the site does not have any responsibility or obligation regarding behaviors, acts or communications of users that take place in the context of their relations outside the site. The data controller, upon request or notification of a user on behaviors or harmful acts suffered in the course of relationships by another user, reserves the right to evaluate them, verify them and take suspension measures or, in the most serious cases, exclusion user from accessing the site and its services.
The data controller is GEM24K S.r.l. based in Rome Via Cristoforo Colombo n. 177.