Statement on the processing of personal data (GDPR)
In compliance with the regulations for privacy, we would like to provide you with some information on how personal data processing is carried out when browsing the website https://shop.mealli.it (herein after the “Site”), by our company, GIUSEPPE MEALLI S.r.l., as owner of the web site and data controller.
1. DATA CONTROLLER
Your personal data will be processed by our company GIUSEPPE MEALLI S.r.l., with headquarters in Firenze, Borgo SS. Apostoli, 16/R, Italy;
You can contact the data controllers by writing to the address indicated above. You can also contract the head of data protection directly at the email firstname.lastname@example.org, or by writing to the following address: Responsabile Protezione Dati, presso GIUSEPPE MEALLI S.r.l., with headquarters in Firenze, Borgo SS. Apostoli, 16/R, Italy.
2. PROCESSING PURPOSES
GIUSEPPE MEALLI S.r.l. will use the data collected via the web site exclusively for the following purposes:
a. Registration on the site
You can decide to register on the website by creating a password-protected account with your personal details. By registering on the site, with your consent, Sisley will process your data so that you can take advantage of various services, including viewing outstanding order data and orders that have been processed or recently completed. By registering, you can also manage the consents given to subscribe to the newsletter and profiling.
b. Purposes of the management of the contractual relationship
If you purchase products on our website, you will be asked for some standard personal data (name, surname, home address, email address, data related to the means of payment), to complete the purchase order. Sisley identifies and processes your data to fulfil your purchase, including the subsequent warranty procedures and technical and commercial administrative services, such as preventing crimes and fraud. Your personal data will be passed on to third parties, only as permitted by law, for the purpose of completing of the contact or billing. For example, as part of the order process, the service providers we appoint (for example: carrier, logistics company, banks) receive the data required to complete the order and service. The service providers appointed by us may use the data, transmitted in this way, only for the purpose of fulfilling their tasks.
c. Purposes related to marketing and profiling activities
With your specific consent, the personal data entered on the pages for subscription to the newsletter service and registration on the site, will be used for the following purposes: collection, registration and processing of purchase data, economic and statistical analyses, sending of advertising/information/promotional material, promotional operations and offers.
d. Purposes linked to customer care services
If you want to request any information through the "contact us" section of the website, either in writing or by calling the phone number indicated, you will be asked for some personal data to manage the request, some of which (your name, surname and email address) are mandatory. Your consent to the processing of this data will allow us to process your requests. No other use of the data will be made other than the management of the request submitted.
3. LEGAL BASIS OF DATA PROCESSING
Sisley will process your personal data on the following legal bases:
a. based on your specific consent (e.g. in marketing and profiling cases);
b. because it is necessary for contractual obligations (e.g. if you purchase products via the e-commerce channel);
c. because it is necessary to pursue a legitimate interest (e.g. for anti-fraud checks in the use of payment instruments).
4. METHODS OF USE
Sisley aims to protect your personal data and manages data processing according to the principles of correctness, lawfulness and transparency. We inform you, therefore, that your personal data will be processed, through the use of tools and procedures suitable for guaranteeing security and confidentiality, using IT and on-line tools, as well as hard copies and files. In the case of data communication via on-line tools, Sisley transmits your personal data securely via encryption (e.g. TLS encryption, Transport Layer Security, or SSL, Secure Socket Layer).
5. RETENTION TIME
Sisley will keep your personal data for different periods of time, depending on the purposes for which they were collected:
a. generally speaking, Sisley will keep your personal data only for the time strictly necessary for the management of the requested service or until required by virtue of our legal and contractual obligations worldwide;
b. if you have an account, we will keep your personal data as long as the account remains active and, in any case, no more than two years from when your consent was given or renewed;
c. if you subscribed to the newsletter service and if you gave your consent to profiling, we will keep your data until you have notified us of your intention to cancel your subscription to the service and, in any case, no more than two years after your consent was given or renewed.
6. SHARING THE INFORMATION WITH OTHER PARTIES
For the purposes indicated in this statement, your personal data may be disclosed to other companies managed by the Data Controller or to third parties working in collaboration with the Data Controller to provide services, duly appointed as persons responsible for or in charge of data processing Moreover, for all the purposes indicated in the information policy, your data may also be communicated abroad, inside or outside the European Union, in compliance with the rights and guarantees provided by current legislation and after verification of the adequacy of the level of protection guaranteed by the third country. Finally, your data will be processed by internal resources in the offices of the data controller who have been suitably trained and are authorised to process personal data.
7. DATA SUBJECT’S RIGHTS
We inform you that you have the right to request access to your personal data from Sisley and to correct it if it is inaccurate, to delete or limit its processing if required, or to oppose its processing for legitimate interests pursued by our company, as well as to obtain portability of the data provided, only if subject to automated processing based on your consent or contract. You also have the right to revoke the consent given for processing purposes that require it, without prejudice to the legitimacy of the processing carried out until consent was withdrawn. We inform you that you can exercise your rights by contacting the data controller at the addresses indicated in point 1. We also remind you that you have the right to lodge a complaint with the Antitrust Authority for the protection of personal data (https://www.garanteprivacy.it/en/ ).