INFORMATION ON THE PROTECTION OF PERSONAL DATA
This Information on the protection of personal data provides users of this site (hereinafter also the “Site”) with an examination as exhaustive as possible regarding the processing of personal data concerning them, as described below, using the Site under the General Data Protection Regulation (RGPD) (EU) 2016/679 and of the Italian legislation on the protection of personal data.
In compliance with the applicable legislation, this Information on the protection of personal data also indicates:
- the nature of the personal data processed (as defined below);
- the purposes of the processing and the means used in the processing;
- the identity and contact details of the data controllers;
- the contact details of the Data Protection Officer (DPO);
- any third parties involved in the processing activities;
- the retention period of the personal data;
- brief description of the security measures adopted to protect personal data;
- the existence of the right of the interested party to ask the data controller for access to personal data and the rectification or cancellation of the same or the limitation of the processing that concerns him or to oppose their treatment, in addition to the right to the portability of the user data.
This Information on the protection of personal data applies exclusively to the Site and does not concern any website or platform to which the Site may connect.
Users under the age of 14 (fourteen) years cannot give consent to the processing of personal data without the authorization of the holder of parental responsibility.
The browsing data described above are stored only temporarily by applicable regulations.
At the time of verification, the Site requires users to provide personal data for the essential purpose of ensuring the management of purchase orders and respecting the contractual obligations existing with users (the data processed are, for example, name and surname, address and -mail, delivery address, etc.).
These personal data are also essential to allow Customer Service to assist customers with their possible requests and for any related need, before or after the sale (for example, about the delivery status of the order or returns of products).
Personal data relating to orders will be kept for as long as necessary to fulfill contractual obligations and any accounting and tax obligations that may be present.
Failure to transmit/provide the personal data requested at the time of verification will prevent users from completing an order on the Site.
At this juncture, the legal basis for processing personal data is art. 6, point 1. Lett. b) of the GDPR (execution of a contract to which the interested party is a party).
Based on a legitimate interest (Article 6, point 1. letter f) of the RGPD), to improve their relationship with customers, the Joint Controllers will send to customers who have made purchases on the Site communications via e-mail product suggestions, discounts, requests for feedback or other updates. Customers can always object to sending further e-mail communications (for example, by clicking on the “unsubscribe” link at the bottom of each e-mail).
REGISTRATION ON THE SITE
When users decide to create and register a personal account on the Site, they are asked to provide personal data (e.g. date of birth, gender, etc.). The Site indicates which personal data are required (or not) to set up a Site account.
Users must provide truthful and accurate personal data at the time of registration and are encouraged to keep their data provided updated by accessing their account to make, if necessary, any necessary changes.
Users who choose to activate or access their account on the Site via social media must be aware that when they connect their Site account to a social media account, the Site collects certain personal data that the user has already provided to that social media. media (for example, your email address and public profile on Facebook).
NEWSLETTER AND MARKETING COMMUNICATION
On the Site, users can opt to receive newsletters and commercial communications.
In such cases, in addition to their e-mail address, users may be asked to provide personal data (e.g. gender, country of residence, etc.) to receive marketing communications and newsletters tailored to the user profile.
Users can always easily withdraw their consent to receive newsletters and commercial communications in the following ways:
- via their account settings;
- by clicking on the “unsubscribe” link in any of these e-mails;
- by contacting our Customer Service.
STORAGE OF PERSONAL DATA
The Data Controllers will keep personal data for as long as necessary to provide users and customers with the services requested, comply with legal or tax obligations, or for the minimum period prescribed by law. The Data Controllers will promptly delete or anonymize personal data whose retention is no longer necessary/mandatory according to the law.
THE RIGHTS OF THE INTERESTED PARTIES
Users/customers (as interested parties) have the right to receive confirmation of any possession by the Controllers of the data referred to them.
The user, as an interested party, has the right to:
- be informed about the collection and use of personal data concerning him;
- obtain from the data controller confirmation as to whether or not personal data concerning him are being processed and, in this case, to obtain access to personal data and related information:
a) the purposes of the processing;
b) the categories of personal data in question;
c) the recipients or categories of recipients to whom the personal data have been or will be communicated, in particular, if recipients of third countries or international organizations;
d) when possible, the retention period of the personal data envisaged or, if not possible, the criteria used to determine this period;
e) the existence of the right of the interested party to ask the data controller to rectify or delete personal data or limit the processing of personal data concerning him or to oppose their processing;
f) the right to complain to a supervisory authority (in Italy to the Guarantor for the protection of personal data); - obtain the correction or completion of inaccurate or incomplete personal data;
- obtain the cancellation of personal data (“the right to be forgotten”);
- receive in a structured format, commonly used and readable by an automatic device, the personal data concerning him provided to a data controller and the right to transmit such personal data to another data controller without impediments by the data controller to whom he provided them “. (” the right to data portability “);
- under specific conditions, oppose the processing of personal data concerning him;
- object at any time to the use of personal data for “profiling” or “automated decision-making” purposes;
- withdraw consent to the processing of personal data at any time where requested and provided, without prejudice to the lawfulness of the processing before the revocation;
- propose a complaint to the Guarantor for the protection of personal data, Piazza di Montecitorio n. 121, 00186, Rome (RM).
Contact information
Owner and Data Controller
LORETTA CAPONI S.r.l. Unipersonale
Via delle Belle Donne, 28/r
50123 Firenze (FI)
P.IVA 01084950482
Owner contact email: firenze@lorettacaponi.it