Welcome to the luisaspagnoli.it Website.
1. DATA CONTROLLERS
These are the entities that control the processing.
- Luisa Spagnoli S.P.A. with registered office in Strada Santa Lucia 71, 06125, Perugia; Tax code and VAT number: 02742760545, Economic and Administrative Index No.: PG no. 238003.
Luisa Spagnoli has appointed its own Data Protection Officer, reachable at the e-mail address DPO@luisaspagnoli.it and at the addresses of the company indicated above.
- Triboo Digitale Srl – A Company of the Triboo group - with registered office in Viale Sarca 336, 20126 Milan, Italy, tax code, VAT number and registration number in the Milan Register of Companies 02912880966.
Triboo Digitale has appointed its own Data Protection Officer, reachable at the e-mail address email@example.com and at the addresses of the company indicated above.
2. PROCESSING POLICY AND PRINCIPLES
Each user has the right to the protection of their personal data. Luisa Spagnoli and Triboo Digitale, as independent controllers of the user personal data who interacts with the services of this Website are required to provide the following information.
In processing of the personal data of users, Luisa Spagnoli and Triboo Digitale will apply the principles of lawfulness, fairness and transparency. Personal data will be collected for specific, explicit and legitimate purposes (purpose limitation) and will be adequate, relevant and limited to the purposes for which it is processed (data minimisation). It will always be updated and precise and kept for a period of time not exceeding that necessary for the pursuit of the purpose of the controller (retention limitation), after which it will be deleted. Finally, it will be processed by adopting all the appropriate security measures to ensure its integrity and non-accessibility by unauthorised third parties (integrity, confidentiality and unavailability).
For further information on the processing of personal data, the user can send requests:
- to Luisa Spagnoli, at the e-mail address of its Data Protection Officer DPO@luisaspagnoli.it, or by post to the address of its registered office;
- to Triboo Digitale, at the e-mail address firstname.lastname@example.org, or by post to the address of its registered office.
3. HOW DATA ON THE WEBSITE IS COLLECTED
Data acquired during surfing
The computer systems and software procedures used to operate the Website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified users but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of the computers used by users connecting to the Website, the Uniform Resource Identifier (URI) notification addresses of the requested resources, the time of the request, the method used to submit the request to the server, the file size obtained in response given by the server (successful, error, etc.) and other parameters related to the operating system and the user's computer environment.
This data is used for the sole purpose of obtaining anonymous statistical information on the use of the Website and to check its correct functioning and is deleted immediately after processing. The data could be used to ascertain responsibility in case of hypothetical computer crimes against the site: apart from this possibility, the data will be deleted when it is no longer needed.
Data provided voluntarily by the user
In the event that users, during the use of services and functionality of the Website, provide the personal data of third parties (as in the case of purchase of the "Gift Card"), they ensure that they have provided the information to the interested parties and will have acquired consent to the processing of their personal data, if necessary.
Please refer to the specific Cookies Policy published on the Website for all the necessary information on the type and mode of operation of cookies.
4. CATEGORIES OF DATA PROCESSED
The following categories of data collected and processed on the Website:
- personal data,
- contact information;
- bank details and information relating to sale and invoicing;
- possibly the data of the Amazon account, if it is chosen as an "Amazon Pay" payment option;
- details of purchases.
No particular categories of personal data are processed.
5. DATA OF A THIRD PARTY FOR THE SENDING OF A GIFT CARD
Personal data relating to a third party (the name and e-mail address) chosen to send a "Gift Card", provided during the relative purchase process will be processed exclusively to allow sending by e-mail by Triboo Digital of the "Gift Card" to a third party, its issuing and for compliance with the resulting requirements and obligations by Triboo Digitale. This data (name and e-mail address of the third party) will only be kept until confirmation of issuing of the "Gift Card" by the third party, to be carried out according to the procedures indicated on the Website or, if chronologically later, until expiry of the deadline for exercising of the right of withdrawal by the purchaser of the Gift Card: once the "Gift Card" has been issued, that is, if the term is canceled, once the term for the right of withdrawal by the user has expired, the data relating to the third party being processed for the purposes indicated here will be deleted.
6. PURPOSE OF PROCESSING AND LEGAL BASIS
The personal data of the users of the Website is generally collected and processed in order to manage the interaction of users with the Website, for example registration to the Website as well as the purchase and execution of the respective purchase orders and payments. The data is also processed in order to comply with the obligations imposed by European laws, regulations and rules governing the possible exercise of rights in court. For such activities the provision of data is necessary. Failure to provide it makes it impossible to execute the contract and to provide the requested services. Consent for these processing purposes is not required.
With the consent of users, which is free and optional, your personal data may also be processed for marketing purposes, through telephone, traditional mail, e-mail, newsletters, text messages such as sms and MMS, chat and social networks, information and promotional material on the products of the Website, special initiatives and/or promotions. It is always possible to object to the receipt of promotional communications, in fact in every communication it is specified how to object to such sending and how not to receive such communications. Conferring data for marketing purposes, as specified above, is optional and any refusal will have no consequences with respect to the requests for products, services and other features offered on the Website.
For those who have joined the loyalty program with the issue of a discount card or for persons who have made a purchase on the Website, the purchase preferences will be stored, in order to be able to carry out subsequent commercial and advertising communications, promotions, discounts, and to provide information on other initiatives concerning products related to your preferences. The data collected will be combined with any information obtained from Luisa Spagnoli in their stores. The provision of data for these purposes is optional and any refusal will have no consequences with respect to requests for products, services and other features offered on the Website.
Triboo Digitale is the independent data controller of the processing of personal data of the Website users with respect to all functional activities for the purchase and execution of orders implemented through the Website, including the management of sales and transactions performed on the Website, the delivery of products, the management of returns and guarantees and other activities necessary for the sale of products through the Website.
Luisa Spagnoli is the independent data controller of the users for the marketing and profiling purposes specified above. For marketing purposes, Luisa Spagnoli appointed Triboo Digitale as the entity responsible for the marketing processing, stipulating a specific contract as required by the GDPR.
7. PROCESSING MEANS AND SECURITY MEASURES
Depending on the specific purpose of processing, personal data is accessible to the designated personnel of the above identified controllers, as well as to the data processors, if appointed. To obtain an updated list of those responsible for processing personal data and of the third parties to whom the data is communicated, it is possible to contact Customer Service or to send an e-mail to the following e-mail addresses:
- for Luisa Spagnoli, DPO@luisaspagnoli.it ;
- for Triboo Digitale, email@example.com .
8. STORAGE OF PERSONAL DATA
The user's personal data will be kept for the time strictly necessary in order to manage their interaction with the Website, as well for as the purchase and execution of their orders, without prejudice to the obligations of retention of data required by law for administrative, accounting and tax purposes. In any case, the user's personal data will be erased or irreversibly anonymous after 10 years from the purchase made by the user, that is to say, with elapsing of the limitation period to assert any rights of a contractual nature.
The data processed for marketing purposes and for the purposes of analysis and evaluation of users' purchasing behavior will be erased or irreversibly anonymous and stored for statistical purposes only, after 7 years from the date of their registration, in accordance with the provisions of the relevant Authority for the Protection of Personal Data for the sector of luxury goods and fashion.
9. PERSONAL DATA RECIPIENTS
Users' personal data may be communicated to authorities, public bodies, professionals and to independent collaborators, also in an associated form, to commercial partners, i.e. third parties that provide commercial, professional and technical services for the management of the Website and for the pursuit of the purposes specified above. These third parties are provided solely with the data necessary to execute the contract of which they are parties. Triboo Digitale will communicate to Luisa Spagnoli all the data relating to the sales made on its Website and will process it for the purposes set out above, with the consent of the interested parties. It is a legitimate interest of Luisa Spagnoli that the data is, moreover, made accessible to the group companies also for marketing purposes and for management of the relationship with the users, to guarantee them the same benefits in all the Luisa Spagnoli stores, including overseas.
All the afore-mentioned parties undertake to use the information received only for the processing purposes stated above, to keep it confidential, intact and unavailable to unauthorised third parties. In addition, personal data may be disclosed pursuant to a provision of law or regulation or to execute an order of an administrative or judicial authority.
Third parties to whom the data is communicated process it in the role of controllers, managers or processors, as applicable, for the purposes indicated above and after receiving documented instructions.
Luisa Spagnoli and Triboo Digitale may transfer the data collected on the Website to third countries outside the European Union. In this case they will adopt adequate guarantees to ensure the protection and security of the transferred data.
User data is not disseminated.
10. THE RIGHT OF ACCESS TO DATA AND OTHER RIGHTS
Articles 15 to 22, GDPR confer on the user, as a data subject, the exercise of specific rights.
Article 15 recognises the right of individuals to access their personal data and to obtain a copy thereof. The right to obtain a copy of the data must not affect the rights and liberties of others.
With the application for access, the user has the right to obtain from Triboo Digitale and from Luisa Spagnoli confirmation of whether or not processing is being carried out on their personal data and the right to know the purposes and categories of data being processed, the third parties whose data is communicated and if the data is being transferred to a non-European country with adequate guarantees. The user also has the right to know the retention time of their personal data, with respect to the afore-mentioned purposes.
With respect to personal data, the user has the right to request the correction of inaccurate data and the integration of incomplete data, the cancellation (the right to be forgotten) under the conditions indicated in art. 17, GDPR, treatment limitation and data portability.
The user also has the right to object, at any time to the processing of data concerning themselves for marketing purposes, including profiling in so far as it is related to the activities of direct marketing. In each promotional e-mail the user will find specifications on how to object to the receipt of further communications and may, at any time, also oppose the receipt of promotional communications through all or only some of those procedures.
The user also has the right to withdraw their consent to the processing.
The holder will also provide the user with proof that the operations that follow the above requests have been brought to the attention of those to whom the data has been communicated, except in the case where this fulfillment proves impossible or involves a use of means clearly disproportionate to the protected right.
To exercise the above rights it is necessary to contact the respective data controllers, each for their own relevant scope of processing:
- Luisa Spagnoli, at the e-mail address of its Data Protection Officer DPO@luisaspagnoli.it, or by post to the address of its registered office;
- Triboo Digitale, at the e-mail address firstname.lastname@example.org, or by post to the address of its registered office.
To provide a response, it may be necessary to identify the user by requesting the provision of a copy of an identification document.
The holder will provide written feedback without undue delay and, in any case, no later than one month after receipt of the request.
11. COMPLAINTS TO THE RELEVANT AUTHORITY FOR THE PROTECTION OF PERSONAL DATA.
The user who considers that the processing of their personal data breaches the provisions of the GDPR or the internal regulations regarding the protection of personal data, has the right to lodge a complaint with the Personal Data Protection Authority based in Rome, pursuant to art. 77, GDPR, as well as with the Judicial Authority.