- If I am a visitor to the Site, what types of data are processed and for what purposes?
If you are a visitor to the Site (whether registered or not), the following types of personal data will be processed, for the following purposes:
During their normal operation, the computer systems and software procedures used for the functioning of this Site acquire some personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes the IP addresses or domain names of the computers and terminals used by users, the URI/URL (Uniform Resource Identifier/Locator) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the user's operating system and computer environment. This data, which is necessary for the use of web services, is also processed in order to: (i) obtain statistical information on the use of services (most visited pages, number of visitors per time slot or per day, geographical areas of origin, etc.); and (ii) check the correct functioning of the services offered. The data could be used to ascertain responsibility in the case of hypothetical computer crimes against the Site. The navigation data is processed for our legitimate interest to ensure the security of the Site, check its correct functioning and obtain statistics relating to its use (art. 6, co. 1, let. (f) of the GDPR).
Data that you can provide voluntarily:
- data in letters/e-mails/faxes spontaneously sent to us: the optional, explicit and voluntary sending of your personal data to the mail, e-mail and fax addresses published on the Site entails the subsequent acquisition of such data, which is required in order to reply to the requests sent by you in relation to the Site (art. 6, co. 1, let. (b) of the GDPR). You are free not to provide such data. However, failure to provide this data may make it impossible to obtain what has been requested;
- data that is transferred during calls made to our telephone numbers: when you contact our telephone numbers or our customer service, we may process personal data that is provided voluntarily by you during the telephone conversation, or data that we may reasonably request in order to process your request (art. 6, co. 1, let. (b) of the GDPR). You are free not to provide such data. However, failure to provide this data may make it impossible to obtain what has been requested;
- data provided through the contact form present on the Site: on our Site there is a contact form (in the section, "Contacts"). If you decide to use this contact form, we will collect and store your data for the sole purpose of responding to your request (art. 6, co. 1, let. (b) of the GDPR). You are free not to provide such data. However, failure to provide this data may make it impossible to obtain what has been requested.
- If I am a registered user of the Site, for what purposes will my personal data be processed?
If you decide to register on the Site, your personal data will also be processed for the following purposes:
- to implement a contract to which you are party and pre-contractual measures taken at your request (art. 6, co.1, let. b) of the GDPR): we will process your data in order to allow you to register on the Website, to provide you with services that are reserved for registered users of the Site, to allow you to make purchases in the Store, in order to comply with the Site's Terms and Conditions and General Terms and Conditions of Sale or with other possible contracts and agreements to which you are a party (such as terms and conditions governing specific initiatives or promotions or the regulations of competitions), as well as to implement any pre-contractual measures taken at your request, such as, for example, when you contact us for information about our products or services before deciding whether to purchase or use them;
- to provide you with the newsletter (art. 6, co.1, let. b) of the GDPR): on the Site you can subscribe to our newsletter. Please note that our newsletter has commercial content, containing offers and promotions related to products or services provided by us. Therefore, by subscribing to the newsletter, you consent to the processing of your e-mail address for marketing purposes (direct sales, sending advertising material, carrying out market research, commercial communication) and to being contacted by e-mail for such purposes. If you do not consent, your ability to browse the Site, create an account on the Site and make purchases on the Site will not be affected in any way or suffer any other detrimental consequence. In any case, you may freely revoke your consent to the processing of your e-mail address for marketing purposes at any time, by making a request to us in the manner indicated in paragraph12 below. You may also revoke your consent to the processing of your e-mail address for marketing purposes by clicking on the opt-out link in each promotional e-mail.
- to fulfil legal obligations (art. 6, co. 1, let. (c) of the GDPR): if you make purchases on the Store, we will process your personal data in order to comply with statutory tax and consumer protection obligations;
- to pursue our legitimate interest in understanding how and how often the Site is used by visitors (art. 6, co. 1, let. f) of the GDPR): in order to pursue our legitimate interest in understanding how and how often the Site is used by visitors, we generate, partly through third party providers, statistical and aggregate data regarding the number of pages viewed on our Site, the number of visitors and, more generally, the ways in which the Site is used, without being able to identify you. In order to generate such statistics and aggregated data, our suppliers use so-called cookies (please see the following paragraphs 7 and 10);
- to pursue our legitimate interest in exercising or defending a right in judicial or extrajudicial proceedings (art. 6, co. 1, let. (f) of the GDPR): we may process your personal data to pursue our legitimate interest in exercising or defending our rights in or out of court, including in the event of a breach of the General Conditions of Use of the Site and Sale or a breach of law;
With your optional consent, we may also process your personal data for marketing and/or profiling purposes. In relation to such processing, please read paragraphs 3 and 4 below.
- Will you also process my data for marketing purposes?
With your optional consent (art. 130 of D. Lgs. 196/2003; art. 6, co. 1, let. a) of GDPR), which can be expressed by ticking the appropriate box online, we will process your data for marketing purposes (direct sales, sending advertising material, carrying out market research, commercial communication, customer satisfaction surveys). With your consent, we may contact you by mail and e-mail to recommend the purchase of products and/or services offered by us, to present you with offers, promotions and commercial opportunities or to invite you to participate in questionnaires, studies, market research or customer satisfaction surveys. By checking the consent box relating to marketing purposes, you consent to be contacted by us via post and e-mail. You may, in any case, freely and free of charge, revoke your consent to the processing of your personal data for marketing purposes at any time, even selectively (for example, by communicating your wish to stop receiving communications by e-mail and to receive only communications by post), by making a request to us in the manner indicated in paragraph12 below. In relation to promotional communications sent by e-mail, you may also withdraw your consent to the processing of your e-mail address for marketing purposes by clicking on the unsubscribe link (opt-out) present in each promotional email.
- Will you also process my data for profiling purposes?
With your optional consent (art. 6, co. 1, let. a) of the GDPR), which can be expressed by checking the appropriate box online, your personal data (i.e. personal data, contact details, and information relating to the goods purchased on the Site) may also be processed by SBS for profiling purposes, i.e. to reconstruct your tastes and consumption habits in order to establish your profile as a consumer, to allow us to send you commercial offers consistent with the profile identified and in particular promotional communications that are personalised on the basis of: (i) the products and services you have purchased on the Site; (ii) the information you voluntarily provided to us during registration on the Site; (iii) the pages you have visited on the Site and the items you have viewed on the Site. Consent to the processing of personal data for profiling purposes is entirely optional, and in the event of non-provision or non-consent the possibility of registering on the Site and purchasing goods on the Site will not be affected in any way. Providing consent for the processing of personal data for profiling purposes also extends to the details of the goods purchased on our Site or at our sales points; however, the data relating to the details of the goods purchased will be kept by SBS, for profiling purposes, until withdrawal of the relevant consent and in any case for a maximum period of 12 months and, for marketing purposes, for a maximum period of 12 months. As specified in paragraph 11 below, you may object at any time to the processing of your personal data for profiling purposes by making a request to us in the manner specified in paragraph 12 below.
- Will my personal data be disclosed to third parties?
It is possible that, at the request of a judicial authority or the judicial police, we may have to communicate data relating to visitors and registered users of the Site, in cases required by law. In this case, we may also, where necessary, disclose your data to lawyers or law firms to pursue our legitimate interest in exercising or defending a right in court.
In addition, your data may be disclosed to banks, payment institutions and other payment intermediaries to the extent necessary to receive a payment from you or to make a payment to you. Where required by law, your personal data relating to a purchase made on the Site may be disclosed to the Inland Revenue Service. Your data may be communicated to the Judicial Authority at its request in the cases provided for by law. Under no circumstances will your data be disclosed to third parties for marketing purposes.
- Who can find out about my data?
Your personal data may be disclosed to our employees and associates who are responsible for the management and maintenance of the Site, for providing assistance to visitors and users of the Site who request information or make other requests to us and for managing purchases from the Store, as well as for sending promotional communications or carrying out profiling activities, on the basis of any optional consent you may have given. Your personal data may also be disclosed to the following categories of persons who, in their capacity as data processors, provide us with services that are instrumental to the performance of our activities: suppliers of IT and logistics services; suppliers of outsourcing and cloud computing services, suppliers of analytics services (who provide us with statistics and aggregate data on the use of the Site); suppliers of management services; external professionals and consultants; and companies appointed to perform marketing activities on our behalf.
- How will my personal data be processed and how long will it be stored?
Your personal data will be processed by automated and non-automated means. Specific security measures are observed to prevent the loss of data, illicit or incorrect use of data, and unauthorised access to data. Navigation data will be stored for a maximum period of 7 (seven) days, unless further storage is necessary to ascertain responsibility in the case of hypothetical computer crimes against the Site or to comply with a request made by a judicial authorities. If you have contacted us by letter, e-mail, fax or through the contact form on the Site to obtain information about the Site and the services offered therein, your data will be stored for a maximum of 60 days from the day upon which we provide the information requested, unless further storage of data is necessary to comply with legal obligations or to exercise or defend our rights in court. If you have contacted us in relation to a purchase made on the Site through one of the contact channels on the Store, we will retain your correspondence for 10 years in accordance with applicable laws regarding the retention of business records and correspondence.
Your data, collected during registration on the Site, will be kept as long as your account remains active and will be deleted immediately after closure of your account.
Data relating to purchases made on the Site will be retained for 10 years, as required by applicable tax law.
Where you have consented to the processing of your personal data for marketing purposes, your personal data will be processed until you have withdrawn your consent to the processing of your data for marketing purposes for all or some of the contact methods. Your contact details will still be retained to pursue any other processing purposes for which they were collected. Data will be processed for profiling purposes for the periods indicated in paragraph 4 above.
- Will my data be transferred outside the European Economic Area?
- What are my rights?
At any time, you have the right to exercise the following rights set out in Articles 15 to 22 of the GDPR free of charge and without any formalities, including: (i) the right to access your personal data (i.e. the right to obtain from us confirmation as to whether or not data relating to you is being processed and, if so, to obtain access to the personal data and to obtain a copy of the data and the information referred to in art. 15 of the GDPR), (ii) the rectification (i.e., the right to obtain the amendment of inaccurate data relating to you or the integration of incomplete data) or erasure of such data, if any of the reasons indicated in art. 17 of the GDPR, or the limitation of the processing that concerns you (i.e. the right to obtain, in the cases indicated by art. 18 of the GDPR, the marking of retained data with a view to limiting its processing in the future), (iii) the right to data portability (i.e. the right, in the cases set out in art. 20 of the GDPR, to receive from us, in a structured, commonly-used and machine-readable format, the data concerning you, as well as to transmit such data to another data controller without hindrance). You also have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data pursuant to article 6(1)(e) (performance of a task carried out in the public interest or in the exercise of official authority) or (f) (legitimate interest) of the GDPR, including profiling on the basis of those provisions. Where personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data carried out for such purposes, including profiling insofar as it relates to such direct marketing. You also have the right to withdraw your consent at any time when a processing operation is based on your consent. Withdrawal of consent will not affect the lawfulness of any processing operations based on consent prior to withdrawal.
- How can I contact you and exercise my rights?
You may exercise your rights by contacting us in writing at the following address: "SBS S.p.A., Via Circonvallazione S/N, 28010 Miasino (NO)" or by e-mail at firstname.lastname@example.org. We remind you that you can always lodge a complaint with the Guarantor for the protection of personal data (www.garanteprivacy.it) or to the Supervisory Authority of the Member State of the European Union in which you reside or work or where the alleged violation occurred.
Last update: March, 2023