Privacy Notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679
Privacy Policy pursuant to Articles 13 and 14 of Regulation (EU) 2016/679
Pursuant to Articles 13 and 14 of the Regulation (EU) 2016/679 (the “Regulation”), Gallurian srl, below provides its customers, including potential customers, as well as third parties in general (e.g. proxies, legal representatives, etc.) who come into contact with it in representation or on behalf of customers, including potential customers (the “Data Subjects”), with the information required by the regulation regarding the processing of their personal data (“Personal Data”). Translated with DeepL.com (free version)
1.- Data Controller and Data Protection Officer
Gallurian srl (c.f.-p.iva 10168520962), headquartered at Via Giuseppe Dezza 47, 20144 Milan, Italy, in the person of its legal representative pro tempore is the entity that processes the data of the Data Subjects and, for the purposes of the Law, is considered the Data Controller of the Personal Data. In this capacity, it is responsible for ensuring the application of appropriate organizational and technical measures for the protection of data in compliance with the provisions of current legislation.
Gallurian srl has appointed a Data Protection Officer (DPO), in charge of ensuring compliance with the regulations for the protection of Privacy who can be contacted, for matters relating to the processing of Personal Data, at the following address: eshop@minina.it
2.- Methods of Collecting Personal Data
Personal Data subject to processing activities by the Data Controller may be acquired from the Data Subject, including through remote communication techniques that the Data Controller uses (e.g., websites, smartphone and tablet apps, call centers, etc.);
3.- Categories of Personal Data Processed
The Personal Data processed by the Data Controller includes, by way of example:
The Personal Data processed by the Data Controller include, but are not limited to:
i. browsing data (e.g. IP addresses or domain names of the computers used by users connecting to the site, the time of the request, the method used in submitting the request to the server, the numerical code indicating the status of the response given by the server and other parameters related to the operating system and browser used by the user, log);
ii. personal data (e.g., first name, last name, social security number, address, date and place of birth, nationality);
iii. contact data (e.g., telephone numbers, landline and/or mobile, email address);
iv. profiling and marketing data (e.g., interests and passions);
v. other data attributable to the above categories.
4.- Purpose and Legal Basis of Processing
Personal Data, under the specified conditions, will be processed for the following purposes:
- Website Registration and Management of Contact Requests and Information Materials
The processing of the Data Subject’s personal data is carried out to facilitate preliminary and subsequent activities related to website registration, if applicable, as well as to manage requests for information, contact, or the sending of informational materials, and to fulfill any other obligations arising therefrom.
The legal basis for such processing is the fulfillment of obligations related to registration, information requests, and the provision of contact or informational materials, as well as compliance with legal obligations.
The provision of data is optional; however, refusal to provide data will make it impossible for the Controller to fulfill the requested service.
- Contract Execution
Personal Data will be processed for managing contractual relationships (e.g., invoicing, payment processing, handling complaints) and providing the requested services through the website.
The legal basis for such processing is the fulfillment of contractual obligations and compliance with legal obligations.
The provision of data is optional; however, refusal to provide data will make it impossible for the Controller to fulfill the requested service.
- Legal Obligations, Defense of Rights in Court or Out of Court, and Fraud Prevention
Personal Data will be processed to comply with legal obligations, as well as to establish, exercise, or defend the Controller’s rights and/or protect against third-party claims in judicial or extrajudicial proceedings. In particular, the Controller may process Personal Data to comply with accounting and tax obligations and legal orders from judicial authorities aimed at crime prevention and prosecution.
The legal basis for such processing is the legitimate interest of the Controller, considering the balance between the rights of the Controller and the Data Subject.
- Promotional Activities for Services/Products Similar to Those Purchased
Personal Data will be processed to send communications regarding promotions and offers on services/products identical or similar to those currently contracted by the Data Subject, unless the Data Subject has objected to such processing initially or in subsequent communications.
The legal basis for such processing is the legitimate interest of the Controller to promote products or services of potential interest to the customer, considering the balance between the rights of the Data Subject and the Controller.
The Data Subject has the right to object at any time, for reasons related to their personal situation, to the processing of their personal data for this purpose.
- Marketing Activities for Gallurian srl’s Services/Products
Personal Data will be processed, subject to specific consent, for sending promotional and offer communications regarding the Controller’s services/products through traditional methods (e.g., postal mail, calls with an operator) and/or automated methods (e.g., email, SMS, MMS, fax, pre-recorded calls).
The legal basis for such processing is the Data Subject’s prior consent, which may be freely withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal.
- Marketing Activities for Partner Services/Products
Personal Data will be processed, subject to specific consent, for sending promotional and offer communications regarding the services/products of Gallurian srl’s commercial partners through traditional and/or automated methods.
The legal basis for such processing is the Data Subject’s prior consent, which may be freely withdrawn at any time.
- Profiling
The processing of Personal Data, including location data, socio-demographic data acquired during the provision of electronic communication services and from public sources, of the Data Subject is carried out, subject to specific consent, for profiling purposes such as analysis of transmitted data and purchased Services/Products in order to propose advertising messages and/or commercial proposals in line with the choices expressed by the users themselves. This activity will be carried out in aggregated and anonymized form by implementing models for the analysis of customer data using statistical algorithms, predictive models and aggregations only for the time strictly necessary for the purposes pursued, the type of goods marketed or services rendered.
In any case, Personal Data will not be subjected to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect the data subject.
The legal basis for such processing is the consent given by the Data Subject prior to the processing itself, which is revocable freely and at any time, without affecting the lawfulness of the processing previously carried out.
Any refusal by the Interested Party to give consent entails the impossibility of using the relevant services, without this entailing detrimental consequences for the contractual relationship with the owner
5.- Data Recipients Collected
The Personal Data collected may be disclosed to parties who will act as autonomous Data Controllers or Data Processors, as the case may be, for the purposes mentioned above, in fulfillment of legal, regulatory and/or EU law obligations or because they have a legitimate interest.
In particular, Personal Data may be made available to:
- subjects in charge of the execution of activities related and instrumental to the processing (storage service companies, IT service companies, social media management service companies, marketing companies, insurance companies, banking institutions);
- commercial partners of Gallurian srl;
- Public administrations, to Authorities and other entities in fulfillment of legal obligations;
Personal Data will not be disseminated (made available to unspecified parties).
6.- Transfer of data to third countries
The Data Subject's Personal Data is stored in archives located in countries of the European Union. Where necessary for the pursuit of the stated purposes, the Data Subject's Data may be transferred abroad, to countries/organizations outside the European Union that guarantee a level of protection of Personal Data deemed adequate by the European Commission in its own decision, or otherwise on the basis of other appropriate safeguards, such as Standard Contractual Clauses adopted by the European Commission or the consent of the Data Subject. The Data Subject has the right to obtain a copy of any Data transferred abroad, as well as a list of the countries/organizations to which the data has been transferred by writing to eshop@minina.it
7.- Period of storage of personal data
The Data will be kept in a form that allows the identification of the Data Subject for a period of time not exceeding that necessary to achieve the purposes for which it was collected taking into consideration the laws applicable to the activities and sectors in which the Data Controller operates. Once the terms thus established have elapsed, the Data will be deleted or transformed into anonymous form, unless their further storage is necessary to fulfill obligations (e.g. tax and accounting) that remain even after the termination of the contract (art. 2220 c.c.) or to comply with orders issued by Public Authorities and/or Supervisory Bodies.
The duration of cookies used on the site can be found in the appropriate Cookie Policy below.
In case of litigation, the retention time indicated above may be extended up to 10 years from the settlement of the litigation.
8.- Processing Methods
The processing will be carried out by the authorized personnel who need to have knowledge of it in the performance of their activities, with the help of electronic tools, according to principles of lawfulness and fairness, so as to protect at all times the confidentiality and rights of the data subject in compliance with the provisions of current legislation.
Marketing-related profiling (analysis of consumer habits and choices) is carried out by means of an automated process for the purpose of studying and analyzing behavioral profiles and aspects characterizing the customer base in order to optimize promotional activities for products and services.
9.- Data Subject Rights
The Data Subject has the right to request from the Data Controller:
i. confirmation as to whether or not any processing of his or her Personal Data is taking place and, if so, to obtain access to it (right of access);
ii. the rectification of inaccurate Personal Data or the integration of incomplete Personal Data (right of rectification);
iii. the deletion of the Personal Data itself if one of the reasons provided for in the Privacy Regulation exists (right to be forgotten);
iv. the limitation of the processing of the Personal Data when one of the cases provided for in the Privacy Regulation (right to limitation) occurs;
v. to receive in a structured, commonly used and machine-readable format the Personal Data to be provided to the Data Controller and to transmit such data to another Data Controller (right to portability);
vi. to object at any time in whole or in part to processing carried out in pursuit of a legitimate interest of the Data Controller and for marketing and profiling purposes (right to object); and
vii. to revoke any consent to the processing of Personal Data, at any time, without affecting the lawfulness of the processing based on the consent given before revocation.
Consent given for the conduct of marketing activities with automated contact methods (by way of example sms, mms, fax, phonics, e-mail, web applications) also extends to traditional contact methods (paper mail or telephone call with operator). Similarly, your objection to the conduct of marketing activities using automated contact methods also extends to traditional contact methods. This is without prejudice to your right to provide consent or to exercise your right to object in relation to only one of the two ways of carrying out marketing activities.
To exercise his rights, the Interested Party may send a message to the e-mail box eshop@minina.it or a written communication to the Data Controller at the registered office of Gallurian srl
The Interested Party has, in addition, the right to lodge a complaint with the competent supervisory authority on the Italian territory (Guarantor Authority for the protection of personal data) or to the one that performs its duties and exercises its powers in the Member State where the violation occurred, as provided for in Article 77 of the Regulation, as well as to take appropriate legal action pursuant to Articles 78 and 79 of the Regulation.
10.- Cookies
The Cookie Policy can be found at the following link.