When Users access or browse the Website, certain categories of Personal Data of the Users and/or other data subjects are automatically collected by the Website. In particular, the Website processes information concerning the interaction with the User’s device (e.g., the IP address, information about the browser, operating system and type of device used, the pages visited and the searches performed, etc.
In this case, the processing of Personal Data will be necessary to enable User browsing or to make it smoother.
Moreover, the Website expressly requires Users to communicate their Personal Data during the procedure to sign up to the Website and/or to complete a purchase order on the Website. In these cases, Personal Data will be necessary for registration or ordering purposes.
In other cases, the Website will ask Users for their Personal Data in order to send them various types of communications by e-mail: e.g., to sign up for newsletters, to participate in contests or for the delivery of promotional offers.
Every time, the Website will clearly indicate whether Personal Data are required or optional for a specific purpose.
The User’s denial of consent to the processing of Personal Data for purposes other than registration to the Website and/or the completion of orders on the Website will not have any significant consequences.
Based on the legitimate interest to improve its relationship with customers, the Website may send to customers email communications with product suggestions, discounts, feedback requests or other updates relating to products and services similar to those already purchased on the Website. Customers are always free to unsubscribe from such email communications (for instance, by clicking on the “unsubscribe link” at the bottom of each email).
Personal data are processed in a manner that ensures appropriate security and confidentiality of Personal data, including for preventing unauthorised access to or use of Personal data and the equipment used for the processing. Personal Data are used only when necessary for the purposes for which such Personal data are collected and subsequently processed.
The Data Controller of the Personal Data (“Controller”) is:
via G grandi 19 Milano
The processing of all Personal Data is performed within the Controller’s organization or by third-party suppliers (or partners) under the strict instructions of the Controller.
The Controller will store Personal data for as long as it is needed to provide users and customers with the required services or to meet legal or tax obligations or for the minimum period prescribed by the law.
In order to determine the appropriate retention period for Personal data stored by the Website under user consent, the Controller will take into account multiple factors to ensure that Personal data are not stored for no longer than necessary.
Disclosure of Personal Data
The Controller discloses part of the Personal Data to other subjects, including third parties, involved in the fulfilment of purchase orders or in the after-sale process.
The Controller may transfer Personal data of customers to primary third-party suppliers, acting as “data processors” (the “Processors”), for the main purpose of performing business operations in order to fulfil their contractual obligations (e.g., courier service providers, etc.).
The Controller will make its best effort to ensure that all Processors will apply their industry best practice to protect Personal data and they will not use Personal data for any other purposes than those agreed with the Controllers.
A full and updated list of the Processors may be requested by email at: firstname.lastname@example.org
The foregoing is without prejudice to disclosure of Personal Data where required by law, police forces, judicial authorities, information and security agencies or other government bodies for national security or defence or for the prevention, detection and repression of administrative or criminal offenses, even in cases in which the disclosure or distribution of the Personal Data is prohibited by law.
In all other cases, the disclosure or distribution of Personal Data is subject to User’s express and unequivocal consent.
The Controller will not transfer any Personal data outside the European Economic Area (EEA), unless the concerned User has explicitly authorized such transfer or the transfer of personal information outside the EEA is allowed by the GDPR on another legal basis.
The rights of data subjects
Users are entitled to obtain confirmation of the existence or non-existence of Personal Data processed by the Website that concerns them.
Each User has the right to obtain:
- the updating, correction or, in case of a legitimate interest, supplementing of Personal Data;
- the deletion, anonymisation or blocking of illegally processed Personal Data, including data that does not need to be retained for the purposes for which the data was collected and subsequently processed;
- an attestation that the operations mentioned under a) and b) above have been made known, including with respect to their content, to the recipients of the disclosed Data, unless doing so is impossible or requires using means obviously disproportionate to the protected right;
- That we delete Personal Data, or stop processing it or collecting it, in some circumstances
- interruption of the Personal Data processing, in the cases provided by law;
- the portability of the Personal Data (i.e., the right of Users to receive, in a commonly used and machine-readable structured format, Personal Data supplied to the Controller) to the extent permitted by law;
- The revocation of their consent to the processing of Personal data at any time.
The User has the right to oppose, for legitimate reasons, any or all of the processing of the Personal Data, regardless of whether the Personal data are relevant to the purposes for which they were collected or are used for advertising or marketing purposes.
Moreover, the User has the right to submit complaints related to the collection and processing of Personal Data to any other competent supervisory authority.
For all communications and enquiries regarding the processing of their Personal Data and to exercise their own privacy rights, as indicated above, Users may contact the Controller by e-mail at the following address: email@example.com.