INFORMATION TO INDIVIDUALS PURSUANT TO ARTICLES 13 AND 14 OF REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL OF 27 APRIL 2016 (HEREINAFTER THE "INFORMATION")
1. DATA CONTROLLER
The Data Controller is SELMI S.r.l. located in Via Langhe 25, 12042 POLLENZO (CN), VAT number: 02668130046 (hereinafter "SELMI" or Controller), whose data is indicated on the website's Home Page and/or on other web pages of the same.
2. PERSONAL DATA SUBJECT TO PROCESSING
For "Personal Data", any information concerning an identified or identifiable natural person with particular reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more elements characteristic of his or her physical, physiological, mental, economic, cultural, or social identity is intended.
The Personal Data collected by the Site are as follows:
a. Navigation Data
The Site's computer systems collect some Personal Data, the transmission of which is implicit in the use of Internet communication protocols. These are pieces of information that are not collected to be associated with you, but which by their very nature could, through processing and association with data held by third parties, allow you to be identified. These include IP addresses or domain names of the devices used to connect to the Site, URI (Uniform Resource Identifier) notation addresses of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response given by the server (successful, error, etc.), and other parameters relating to your operating system and computer environment.
These data are used to obtain anonymous statistical information about the use of the Site and to monitor its correct functioning; to allow - given the architecture of the systems used - the correct provision of the various functionalities requested by you, for reasons of security and to ascertain responsibility in the event of hypothetical computer crimes against the Site or third parties and are stored by the Site Owner for the period strictly necessary and in any case in compliance with current regulatory provisions.
Data provided voluntarily
Through the Site, you have the opportunity to voluntarily provide Personal Data such as your name, surname, and email address to subscribe to the newsletter service or to contact SELMI through the "Contact Us" form or similar services, your email, your personal or billing data to create an account and access your reserved area and receive merchandise orders that you can make through this site.
SELMI will process this data in compliance with the Applicable Law, assuming that they refer to you or to third parties who have expressly authorized you to provide them based on a suitable legal basis that legitimizes the processing of the data in question. If the data voluntarily provided on the site are not personally related to you, you will be considered an independent data controller of the third-party data you entered on the site and therefore you will assume all the legal obligations and responsibilities. In this sense, you provide the widest indemnity with respect to any dispute, claim, request for compensation for damages arising from the processing, etc. that may be received by SELMI from third parties whose Personal Data have been processed through your use of the Site in violation of the Applicable Law.
None of the personal data collected and processed can be attributed to the definition of "Special categories of data" referred to in Article 9 of EU Regulation 2016/679. In case you transmit such data, in the absence of your explicit written consent, we will immediately delete them.
c. Cookies and similar technologies
3. PURPOSE, LEGAL BASIS AND MANDATORY OR OPTIONAL NATURE OF THE PROCESSING
The Personal Data you provide through the Site will be processed by SELMI for the following purposes:
a) purposes related to the execution of the purchase contract for products presented on this site, as well as to perform all connected and consequent activities, such as billing and shipping, and administrative activities related to the contract of which you are a part; for this purpose, to make purchases on this site, you may be asked to create an account with an email and a temporary password that will be provided by the system. Such data will be processed in accordance with legal provisions and subject to technical and organizational measures to ensure their security;
b) marketing purposes through subscription to newsletters and enrollment in loyalty programs through loyalty cards, in order to obtain exclusive discounts and benefits, discount codes in particular periods of the year (such as Christmas) or on your birthday (for this purpose, if you provide consent for this purpose, your date of birth will be requested), to be contacted again to receive offers that are most suitable for your needs and requirements, subject to your separate and informed consent;
c) purposes of statistical research/analysis on aggregated or anonymous data, without the possibility of identifying the user, aimed at measuring the functioning of the Site, measuring traffic and evaluating usability and interest and to allow you to browse the site and its sections;
d) purposes related to the fulfilment of a legal obligation to which SELMI is subject;
e) purposes necessary to ascertain, exercise or defend a right in court or whenever the judicial authorities exercise their judicial functions.
The legal basis for the processing of Personal Data for the purposes referred to in point a) is the execution of a contract, the provision of a service or the response to a request from the data subject, which does not require consent under the Applicable Regulations. The provision of the data requested in order to make purchases on this site is optional; however, failure to provide them will make it impossible to use the site's services.
The purposes referred to in point b) require your consent, which is given by means of a specific flag in the box, each time it becomes necessary. Your consent is not mandatory and its non-provision only implies the impossibility of receiving commercial and marketing information from the company, subscribing to the newsletter, receiving loyalty points and more advantageous commercial offers, while it will still be possible to make purchases. Consent can be revoked at any time by clicking on the "unsubscribe" link at the bottom of each commercial communication, or by writing to firstname.lastname@example.org indicating CANCEL ME in the subject line of the email.
The purpose referred to in point c) does not involve the processing of Personal Data, while the purposes referred to in points d) and e) represent legitimate processing of Personal Data under the Applicable Regulations because, once the Personal Data has been provided, the processing is necessary to fulfil a legal obligation to which SELMI is subject.
4. PROCESSING METHODS
With regard to the aforementioned purposes, processing takes place using manual, computerized and telematic tools with logic strictly related to the aforementioned purposes and, in any case, in such a way as to guarantee the security and confidentiality of the data themselves and with your commitment to promptly communicate any corrections, modifications and updates. Said processing may be carried out on behalf of the Data Controller for the purposes and with the methods described above and in compliance with criteria suitable to guarantee security and confidentiality, by companies, firms, entities and external collaborators appointed as Data Processors and only with regard to the processing carried out by them.
5. RECIPIENTS TO WHOM DATA MAY BE DISCLOSED
Your Personal Data may be disclosed, for the purposes specified in point 3, to:
• entities necessary for the provision of services offered by the Site, including but not limited to the payment management platform, the courier responsible for delivering the products, the email provider and the analysis of the functioning of the Site, which typically act as independent data controllers or external data processors; SELMI has chosen these partners by verifying their compliance with the applicable data protection regulations;
• individuals authorized by SELMI to process Personal Data who have committed to confidentiality or have an appropriate legal obligation of confidentiality (e.g. employees and collaborators of SELMI);
• Judicial Authorities in the exercise of their functions when required by the applicable regulations.
6. TRANSFERS ABROAD
None of your personal data is transferred outside the European Union. The server hosting this site is located within the European Union. The site communicates with a secure protocol (https), so the data you may enter is protected by encryption.
The Data Controller ensures that the electronic and paper processing of your Personal Data by the Recipients is carried out in compliance with the applicable regulations.
If transfers outside the European economic area were to occur, these transfers will be based alternatively on an adequacy decision or on the Standard Model Clauses approved by the European Commission.
7. DATA RETENTION
SELMI will process your Personal Data for the time strictly necessary to achieve the purposes indicated in point 3.
For example, SELMI will process Personal Data for the newsletter service until you decide to unsubscribe from the service and your account data until you decide to delete it.
Notwithstanding the above, SELMI will process your Personal Data for the time allowed by Italian law to protect its interests (Art. 2947(1)(3) of the Italian Civil Code). Further information regarding the period of retention of Personal Data and the criteria used to determine such period can be requested by writing to SELMI at the email address email@example.com.
8. YOUR RIGHTS
a. Right of access
You may obtain from the Data Controller confirmation as to whether your Personal Data is being processed and, if so, access to the Personal Data and the information provided for in Article 15 of the Regulation, including, for example, the purposes of the processing, the categories of Personal Data processed, etc.
If Personal Data is transferred to a third country or to an international organization, you have the right to be informed of the existence of adequate safeguards relating to the transfer.
If requested, the Data Controller may provide you with a copy of the Personal Data being processed. For any further copies, the Data Controller may charge you a reasonable fee based on administrative costs. If the request is made electronically, and unless otherwise indicated, the information will be provided to you by the Data Controller in a commonly used electronic format.
b. Right of rectification
You may obtain from the Data Controller the rectification of your Personal Data that is inaccurate and, taking into account the purposes of the processing, the completion of incomplete Personal Data by providing a supplementary statement.
c. Right to erasure
You may obtain from the Data Controller the erasure of your Personal Data, if one of the reasons provided for in Article 17 of the Regulation exists, including, for example, if the Personal Data are no longer necessary for the purposes for which they were collected or otherwise processed or if the consent on which the processing of your Personal Data is based has been revoked and there is no other legal basis for the processing.
We inform you that the Data Controller cannot proceed with the erasure of your Personal Data if their processing is necessary, for example, for compliance with a legal obligation, for reasons of public interest, for the establishment, exercise or defense of a legal claim.
d. Right to restriction of processing
You may obtain restriction of processing of your Personal Data if one of the situations provided for in Article 18 of the Regulation exists, including, for example, if you contest the accuracy of your Personal Data being processed or if your Personal Data are necessary for the establishment, exercise or defense of a legal claim, even though the Data Controller no longer needs them for processing purposes.
e. Right to data portability
If the processing of your Personal Data is based on consent or is necessary for the performance of a contract or pre-contractual measures and the processing is carried out by automated means, you may:
• request to receive the Personal Data provided by you in a structured, commonly used and machine-readable format (e.g. computer and/or tablet);
• transmit your received Personal Data to another Data Controller without hindrance from the Controller.
You may also request that your Personal Data be transmitted directly by the Controller to another Data Controller indicated by you, if technically feasible for the Controller. In this case, it will be your responsibility to provide us with all the exact details of the new Data Controller to whom you intend to transfer your Personal Data, providing us with a written authorization.
f. Right to object
You may object at any time to the processing of your Personal Data if the processing is carried out for the performance of a public interest task or for the purposes of the legitimate interests pursued by the Data Controller (including profiling activities).
If you decide to exercise the right to object as described here, the Data Controller will refrain from further processing your personal data, unless there are legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defense of legal claims.
g. Right to lodge a complaint with the Supervisory Authority for the protection of personal data
Without prejudice to your right to lodge a complaint with any other administrative or judicial authority, if you believe that the processing of your Personal Data by the Data Controller is in breach of the Regulation and/or the applicable legislation, you may lodge a complaint with the competent Supervisory Authority for the protection of personal data (www.garanteprivacy.it).
Requests should be addressed via e-mail to: firstname.lastname@example.org