- CATEGORIES OF DATA
The Companies collect and process the following categories of data (the "Data" ):
a) personal data and contact details you provide when you create a personal account on the Site;
b) data related to purchases made through the Site;
d) data you provide when you request information or assistance, returns management and product warranty;
e) data you provide during contests, online surveys and/or promotions offered through the Site
The categories of Data mentioned above will only be processed to the extent necessary to the purposes described in paragraph 4.
- PROCESSING OF DATA
Your Data will be processed using electronics means or in paper form and will be protected with the implementation of reasonable security measures to protect the safety and confidentiality of the Data. Specifically, the Companies have implemented technical and organizational measures necessary to ensure that Data are protected against loss, alteration, unauthorised disclosure of, or access to, Data transmitted, stored or otherwise processed by the Companies.
- PURPOSES OF THE PROCESSING
Giuliano Galiano processes your Data for the following purposes
ii. to comply with legal and regulatory obligations ("Legal Purposes" );
iii. to carry out activities which are functional to transfer of branches, acquisitions, mergers, divisions or other changes and to perform such operations ("Legitimate Interest for Business Purposes" ).
Furthermore, Giuliano Galiano processes your Data, with your previous consent for:
a. to send you marketing communications, through paper and electronic means (including email, SMS, MMS, social network, instant messages, mobile applications, banner, fax, mail and phone) relating to its brands, products and/or services, to invite you to events and to conduct market analysis and statistics ("Marketing Purposes" );
b. to analyse your habits, interests and preferences in order to better tailor the abovementioned marketing communications to your specific needs ("Profiling Purposes" );
In addition, data relating to the purchase volume, product category, shop where the purchase was made and date of birth may be processed based on the legitimate interest of Giuliano Galiano to provide a service that is more in line with the needs of data subjects, adequately balanced with the needs to protect the rights of data subjects, as well as to carry out statistical analyses on an anonymous basis on the performance of Giuliano Galiano’s business. ("Legitimate Marketing Interest Purposes").
- LEGAL BASIS FOR THE PROCESSING
Processing of Data for Contractual Purposes is mandatory since it is necessary for the registration on the Site, for the performance of all activities related to the General Terms of Sale of the Site, for the purchase of products online, and to enjoy specific services offered through the Site. Processing of Data for Legal Purposes is mandatory since it is required by the applicable laws. If you do not want your Data to be processed for these purposes, you will not be able to register to the Site, nor to enjoy the services offered by the Companies through the Site
Processing for Legitimate Interests for Business Purposes is carried out according to art. 24 par. 1 d) of the Privacy Code and in order to pursue the legitimate interest of the company and his counterparts to carry out economic operations indicated therein, and according to art. 6 f) of the European Privacy Regulation, properly balanced with your interests, since the processing will only be limited to the extent necessary to perform such operations.
Processing for Marketing and Profiling Purposes is not mandatory, and subject to your prior consent. If you decide not to give your consent however, Giuliano Galiano will not be able to inform you about new product/services, promotions, personalized offers, or to carry out market surveys, or to send other communications and materials in line with your interests.
Processing for Legitimate Interest for Marketing Purposes is functional to the pursuit of a legitimate interest of Giuliano Galiano, properly balanced with the interests of the users and, considering the limitation to this form of processing explained in paragraph 4.
- COMMUNICATIONS OF PERSONAL DATA
The Companies enter into different contracts with selected third parties, who provide different services, for example maintenance of the Site, management of the communications with the customers and other services. The services provided by third parties are: hosting, processing orders, anti-fraud checks, placing order and managing returns, elaboration of payments, customers service, shipment and delivery, correspondence and web marketing. Data collected through the Site can be accessed by said third parties, and only on behalf of the Companies. In any case, those service providers are not allowed by law and contact to use personal data of the users for other purposes. The Companies may also communicate Data to financial institutions or other third parties in relation to payment operations. Data of the users will not be communicated to other third parties, except if it is required by law, in relation to a legal claim or a legal proceeding, or when they are necessary to protect the rights and interests of the Companies.
- OVERSEAS TRANSFER OF PERSONAL DATA
Data can be freely transferred outside the national territory to other European countries, but they may also be transferred to shops belonging to the Giuliano Galiano, which are located outside the European Union, and in particular in the USA and in China. Any transfer of Data outside the European Union, will be carried out by taking reasonable and appropriate safeguards to keep the Data safe, according to art. 44 of the Privacy Code and articles 45 and 46 of the European Privacy Regulation. You will have the right to obtain a copy of the Data held abroad and to receive information on the place where the Data are kept, by asking directly to Giuliano Galiano, through the contact details provided in paragraph 9 of this document.
- DATA SUBJECTS UNDER 18
- YOUR RIGHTS
You will always, and with no additional charge, have the right to: (a) obtain confirmation as to whether or not Data concerning you are being processed, and if this is the case, have access to the Data; (b) know the origin of the data, the purposes and the way in which they are processed and the logic applied to processing by automated means; (c) ask for the update, rectification or, if you are interested, the integration of the Data; (d) ask the erasure, the anonymization or the blocking of Data unlawfully processed or to object to the processing for legitimate reasons; (e) object, fully or partially, to the processing for purposes of direct marketing carried out either through automated or more traditional ways; (f) withdraw your consent at any time, without affecting the lawfulness of processing based on consent before the withdrawal.
At any time and in the manner set out in paragraph 9 above, you may (a) request the restriction of personal data processing in the event that (i) you contest the accuracy of your personal data, for the period necessary to verify the accuracy of such personal data; (ii) the processing is unlawful and you object to the erasure of your personal data and request instead that its use be restricted; (iii) although the company no longer needs them for the purposes of processing, personal data are necessary for you to establish, exercise or defend a right in court; (iv) You have objected to processing pursuant to article 21, paragraph 1, of the GDPR pending verification of whether the legitimate reasons of the data controller prevail over those of the data subject; (b) object at any time to the processing of personal data based on a legitimate interest; (c) request the deletion of personal data relating to you without undue delay; (d) obtain portability of personal data relating to you; (e) lodge a complaint with the Data Protection Authority where applicable.
- RETENTION TERM
The Companies will process Data for the time necessary to fulfil the purposes for which they were initially collected. In any case, the following retention periods shall apply to the processing of Data for each specific purpose:
• Data collected for Contractual Purposes will be retained for the duration of the contract, and then for 10 years after its termination to exercise/defend a right of Company, both in court and outside, where a claim should arise relation to the contract ;
• Data collected for Legal Purposes will be retained in accordance with the specific limitation periods defined by law;
• Data collected for Marketing Purposes of Company, for Profiling Purposes and for Legitimate Interest for Profiling Purposes will be retained for 7 years from the last contact we have with you (e.g. last purchase, last newsletter opened)
• Data collected for Legitimate Interest for Business Purposes will be retained for 10 years from the moment of their collection.
If you have doubts, questions or complaints with regard to the collection and processing of your Data, you may contact the Companies through the contacts section on the Site.