Privacy Policy
Privacy Policy
La presente Privacy Policy è riferita al sito web https://www.kienergy.it/ (di seguito, il “Sito”) e non riguarda altri siti web eventualmente consultabili tramite link a siti/pagine esterni. Essa è da intendersi quale informativa resa ai sensi del Regolamento europeo in materia di protezionale dei dati (di seguito “GDPR”) e della normativa italiana di settore (di seguito, complessivamente, l’uno e l’altra, la “Normativa Applicabile”) nei confronti di coloro che interagiscono con il Sito (di seguito “Utenti” o anche solo al singolare “Utente”), consultando le relative pagine.
Per quanto riguarda i cookie, si prega di fare riferimento alla Cookie Policy, da intendere come parte integrante della presente Privacy Policy.
1. TITOLARE DEL TRATTAMENTO E DETTAGLI DI CONTATTO
Il Titolare del trattamento è la società KI-ENERGY S.R.L., con sede legale in Via Monte Cimone, 47/B – 36073 Cornedo Vicentino (VI), C.F. e P.IVA 04534260247, di seguito anche “Titolare del trattamento” o solo “Titolare”.
Per qualsiasi chiarimento, informazione, esercizio dei diritti elencati nella presente Informativa, è possibile contattare il Titolare del trattamento ai seguenti recapiti: e-mail info@kienergy.it, PEC ki-energysrl@pec.it.
2. DATI PERSONALI OGGETTO DEL TRATTAMENTO
Nel corso della navigazione del sito e dell’utilizzo dei servizi offerti, il Titolare raccoglie diverse tipologie di dati personali.
In particolare, possono essere trattati:
• dati identificativi e di contatto, quali nome, cognome, indirizzo di spedizione, e-mail e numero di telefono, forniti in fase di acquisto o contatto;
• dati fiscali, qualora necessari per l’emissione della fattura;
• dati relativi ai pagamenti: tali informazioni non vengono trattate direttamente dal Titolare, ma sono gestite dai fornitori dei servizi di pagamento (es. PayPal, Wix Payments, Apple Pay, Google Pay);
• dati di navigazione, quali indirizzo IP, informazioni sul dispositivo utilizzato e dati relativi alle modalità di utilizzo del sito;
• dati raccolti tramite cookie e tecnologie analoghe, anche per finalità di analisi e marketing;
• dati conferiti per finalità di marketing, come l’indirizzo e-mail per l’iscrizione alla newsletter o per l’invio di comunicazioni commerciali.
Nel corso delle interazioni con il Titolare (ad esempio tramite form di contatto o e-mail), l’utente potrebbe inoltre comunicare informazioni relative al proprio stato di salute o benessere. Tali dati non sono richiesti né necessari ai fini dell’acquisto dei prodotti e il Titolare invita pertanto gli utenti a non fornirli. Qualora ciò avvenga spontaneamente, tali informazioni saranno trattate esclusivamente nella misura strettamente necessaria per rispondere alla richiesta dell’utente.
Il Titolare del trattamento tratterà i dati dell’Utente nel rispetto della Normativa Applicabile, assumendo che siano riferiti allo stesso Utente o a terzi soggetti (in particolare, familiari e/o amici) che l’abbiano espressamente autorizzato a conferirli o i cui dati personali l’Utente avesse comunque titolo di conferire. Rispetto a tali ipotesi, l’Utente si impegna a sollevare e tenere indenne il Titolare del trattamento da ogni contestazione, pretesa, richiesta di risarcimento del danno da trattamento dei dati personali che dovesse pervenire da tali terzi soggetti.
3. FINALITÀ E BASI GIURIDICHE DEL TRATTAMENTO
Premesso quanto sopra, i dati acquisiti saranno trattati per le finalità e sulla scorta delle basi giuridiche di seguito indicate.
PURPOSE
LEGAL BASIS
a. Execution of the sales contract and management of the relationship with the customer
The personal data provided by the user are processed in order to allow the correct management of orders placed through the site, including, by way of example:
-
the management of purchasing procedures;
-
payment management;
-
the organization and delivery of products;
-
the issuing of any tax documents;
managing support requests and customer service.
Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract [Article 6(1)(b) of the GDPR].
b. Fulfillment of legal obligations
Comply with the legal obligations to which the Data Controller is subject, including responding to any requests from the User to exercise their rights as a data subject under applicable data protection legislation.
Processing is necessary for compliance with a legal obligation to which the Data Controller is subject [art. 6(1)(c) of the GDPR].
c. Direct marketing activities
With the user's prior consent, the Data Controller may use the contact details to send promotional and commercial communications relating to its products and services, through automated tools (such as, for example, email, SMS, or other digital channels).
It is understood that providing data for these purposes is optional and failure to consent will not affect the ability to make purchases on the site.
The consent given may be revoked at any time.
In some cases, in compliance with applicable legislation, the Data Controller may use the email address provided as part of a purchase to send communications relating to products similar to those already purchased, unless the interested party objects (so-called "soft spam").
The data subject's consent [art. 6 (1)(a) of the GDPR.
The legitimate interest of the Data Controller in sending communications relating to products similar to those already purchased via email [art. 6(1)(f) of the GDPR and art. 130, paragraph 4, Legislative Decree 196/2003 (so-called soft spam)].
d. Profiling and remarketing activities
Subject to the user's specific consent, the Data Controller may process personal data to analyze browsing habits, preferences, and behavior, including through tracking tools and third-party technologies (such as, for example, Google Analytics, Meta Pixel, and Google Ads).
Through these activities, the Data Controller can:
-
personalize content and offers;
-
segment users into interest categories;
-
carry out remarketing activities and targeted advertising campaigns.
Profiling is only performed with your explicit consent and can be revoked at any time without affecting your use of the site.
The data subject's consent [art. 6 (1)(a) of the GDPR.
e. Site operation and security
The Data Controller also processes some of users' personal data to ensure the proper functioning of the site, prevent fraud, manage any abuse, and ensure the security of IT systems and infrastructure.
Such processing is limited to what is necessary to protect the legitimate interests of the Data Controller and Users.
The legitimate interest of the Data Controller and the Users themselves in preventing or identifying any fraudulent or otherwise unlawful use of the Site in general [art. 6(1)(f) of the GDPR].
f. Perform statistical research/analysis on aggregate or anonymous data, without, therefore, being able to identify the User and measure traffic and evaluate the use of the site and the interest shown by Users.
The legitimate interest of the Data Controller in verifying the usability and attractiveness of the Site [art. 6(1)(f) of the GDPR].
g. To establish, exercise or defend legal claims or whenever the courts act in a judicial capacity.
To establish, exercise or defend legal claims or whenever the courts act in a judicial capacity.
4. Nature of the provision of personal data
The provision of data by the User is optional. Nevertheless, failure to provide such data, in whole or in part, may make it impossible to respond to any booking requests and/or requests to exercise rights, and/or may make it impossible to send/publish what has been requested. The provision of data for marketing and profiling purposes is, however, optional and does not affect the use of the services.
5. Processing methods of personal data
Data are processed using manual and/or computer-based tools, in any case in manners suitable to guarantee their security and confidentiality. To this end, the Data Controller has adopted and implements technical and organizational security measures appropriate to the level of risk associated with the processing activities carried out. In particular, the Website's functionalities are provided over an encrypted HTTPS connection, and personal data are collected, stored, and kept on secure servers, protected by firewalls, and physically located within the European Union.
6. Recipients of personal data
To pursue the purposes indicated above, the user's personal data may be communicated to third parties acting, as the case may be, as data processors or independent data controllers, in compliance with applicable legislation. In particular, the data may be processed by:
-
technical and IT service providers, such as entities in charge of the installation, management, maintenance, and updating of the website and related infrastructure (e.g., hosting providers, cloud services, web agencies, and software houses), acting as data processors pursuant to Article 28 of the GDPR;
-
e-commerce platform providers (Wix) and other technological tools used for managing online sales;
-
payment service providers, who independently manage payment operations (e.g., PayPal, Wix Payments, Apple Pay, Google Pay);
-
entities involved in the logistics and shipping of products, either directly or through intermediaries (such as Packlink PRO and the designated couriers);
-
marketing and advertising service providers, including platforms such as Google and Meta, used for analysis, profiling, and remarketing activities (subject to the user's prior consent);
-
automation and data management tool providers, such as integration and storage services (for example, Zapier and Google Sheets);
-
consultants and professionals, such as legal, tax, administrative, or technical firms, who support the Data Controller in complying with legal obligations or in the establishment, exercise, or defense of a legal claim;
-
public authorities, bodies, or entities entitled to receive the data by virtue of legal provisions or orders from authorities, as well as for the prevention and suppression of illegal or fraudulent activities.
Entities appointed as data processors are contractually bound to process personal data in compliance with the instructions provided by the Data Controller and the provisions of the GDPR.
7. Transfers to non-EEA countries and/or international organizations
The servers of the Data Controller's hosting provider are located within the territory of the European Union. However, within the scope of the processing operations described above, some of the user's personal data may be transferred to countries located outside the European Economic Area (EEA), particularly when using services and platforms provided by third parties (for example, cloud, marketing, or advertising services offered by providers based in the United States).
In such cases, the Data Controller guarantees that the data transfer takes place in compliance with the conditions laid down in Regulation (EU) 2016/679 and, in particular, that appropriate safeguards are adopted to protect the rights and freedoms of the data subjects.
To this end, transfers may take place:
-
to countries for which the European Commission has adopted an adequacy decision;
-
by signing Standard Contractual Clauses (SCC) approved by the European Commission;
-
where necessary, by adopting supplementary technical and organizational measures suitable to strengthen the level of protection of personal data.
The Data Controller selects its suppliers paying particular attention to the guarantees offered regarding personal data protection. It is understood that, for further information regarding data transfers to third countries and the relevant safeguards, the user may contact the Data Controller at the contact details indicated in this privacy policy.
8. Retention period of personal data
Personal data are stored for a period of time no longer than necessary to achieve the purposes for which they are collected and processed, in compliance with the principles of storage limitation and data minimization referred to in Article 5 of the GDPR.
In particular, personal data are retained according to the following criteria:
-
data processed for the execution of the sales contract and for the management of the customer relationship: retained for the entire duration of the contractual relationship and, subsequently, for the period provided for by the applicable administrative, accounting, and tax legislation;
-
data processed for compliance with legal obligations: retained for the time necessary to fulfill such obligations, within the limits established by applicable legal provisions;
-
data processed for direct marketing purposes: retained until the data subject withdraws consent and, in any case, for a period not exceeding 24 months, in accordance with the guidelines of the Italian Data Protection Authority (Garante per la protezione dei dati personali). This is without prejudice to the Data Controller's right to retain evidence of the provision of consent and its withdrawal for defense purposes in the event of potential disputes;
-
data processed for profiling and remarketing activities: retained until consent is withdrawn and, in any case, for a period not exceeding 12 months, taking into account the guidelines provided by the Italian Data Protection Authority;
-
data processed for the operation of the website and for security purposes: retained for the time strictly necessary for the technical management of the website, as well as for the prevention and management of any abuse or illegal activities;
-
data processed for statistical purposes on an aggregate or anonymized basis: processed in a form that does not allow the identification of the data subject and, therefore, retained also for longer periods, in compliance with the principles of minimization;
-
data processed for the establishment, exercise, or defense of a legal claim: retained for the time necessary to pursue such purposes and, in any case, until the expiration of the limitation periods provided for by applicable legislation.
Once the applicable retention period has expired, personal data will be deleted or anonymized, unless further retention is required in the cases indicated above.
9. Rights of the data subject
The User and/or the third party on whose behalf the User has provided the data has the right to:
-
obtain confirmation as to whether or not personal data concerning them are being processed and, if so, obtain access to such data and to a series of relevant information, including, by way of example, information relating to: a) the purposes of the processing; b) the categories of personal data concerned; c) the recipients or categories of recipients to whom the personal data have been or will be disclosed; d) the data retention period or, if that is not possible, the criteria used to determine that period; e) the source of the personal data, if they were not collected from the user themselves;
-
request and obtain the update, rectification of inaccurate data or, where interested therein, the integration of incomplete data;
-
request and obtain the erasure of data if: a) the data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; b) the User objects to the processing carried out on the basis of a legitimate interest of the Data Controller and there are no overriding legitimate grounds to continue the processing; c) the data have been unlawfully processed; e) the data must be erased by the Data Controller for compliance with a legal obligation;
-
request and obtain the restriction of processing in the event of: a) contesting the accuracy of the data for the time necessary for the Data Controller to perform the required verifications; b) unlawful processing of data by the Data Controller, where the user opposes the erasure of the data and requests the restriction of their use instead; c) establishment, exercise, or defense of a legal claim of the User in court, even though the Data Controller no longer needs them for the purposes of the processing; d) pending the verification of whether the legitimate grounds of the Data Controller override those of the data subject;
-
in cases where the processing is based on a contract and is carried out by automated means, request and receive in a structured, commonly used, and machine-readable format the data concerning them and, if technically feasible, obtain direct transmission from the Data Controller to another controller;
-
object, in whole or in part, on legitimate grounds relating to the User's particular situation, to the processing of personal data concerning them, even if pertinent to the purpose of the collection; where the processing is based on the User's consent, withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal;
-
lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) pursuant to and for the purposes of Article 77 of the GDPR and Articles 140-bis et seq. of the Italian Privacy Code if they believe that their rights under personal data protection legislation have been infringed.
The Data Controller shall communicate any rectification, erasure, or restriction of processing carried out to each of the recipients to whom the personal data have been transmitted, except where this proves impossible or involves a disproportionate effort.
10. Methods for exercising the data subject's rights
As a data subject, the User and/or the third party on whose behalf the User has provided the data may at any time exercise the aforementioned rights by sending an e-mail to the following email addresses: info@kienergy.it, Certified Email (PEC): ki-energysrl@pec.it.
To lodge a complaint with the Italian Data Protection Authority, the forms provided on its official website may be used.
11. Updates to the Privacy Policy
This Privacy Policy may be subject to modifications and/or integrations and/or updates, also as a consequence of updates to the applicable personal data protection legislation.
In such case, the Data Controller will inform the User regarding the modifications and/or integrations and/or updates affecting this Privacy Policy by means of publication on the Website.
Last updated: 04.06.2026
