Privacy Policy

Information pursuant to EU Regulation 2016/679 (“GDPR”)
Last updated [03-03-2021]

1. WHO PROCESS YOUR DATA?

Data Controller

L’Artistica S.r.l.s., with registered office in Via Emilia 80 – 27058 Voghera, Italy and VAT no. 02791280189 (referred to as the “Company”, “we”, “our”, “us”).

Responsible for the protection of personal data (DPO)

We have appointed a data protection officer (Data Protection Officer) pursuant to art. 37 of the General Data Protection Regulation no. 2016/679 (“GDPR”). We remind you that you can contact the DPO at any time and send any question or request relating to your personal data and respect for your privacy by writing to the following email address info@ibuonisiamonoi.it

Other subjects

Your personal data may be brought to the attention of our employees or collaborators, belonging to the categories of administrative, commercial, legal, accounting or IT system administrators, depending on the treatment, who, operating under our direct authority, are appointed as data processors and receive adequate operating instructions in this regard. The recipients of your data also include third party service providers relating to payments, shipments, marketing services, hosting providers and information systems engineering service providers, IT companies or companies specialized in market research and ” processing of data with which we enter into agreements that require them to adopt appropriate technical and organizational measures for the protection of your personal data. Your data may also be transmitted to the police and judicial and administrative authorities in accordance with the law.

We may also transfer your personal data in the event of a sale or transfer of all or part of our business or assets (including in the event of a reorganization, spin-off, dissolution or liquidation).

Under no circumstances do we give or sell your personal data.

Your personal data may be transferred outside the European Union to be processed by some of our service providers. In this case, we make sure that this transfer takes place in compliance with current legislation and that an adequate level of protection of personal data is guaranteed in accordance with the provisions of this Privacy Policy, based on an adequacy decision, on standard clauses defined by the Commission. European or on Binding Corporate Rules. In the event that your personal data is transferred to third party suppliers established in the United States, the data may be transferred to them if they have submitted a self-certification under the Privacy Shield scheme (so-called “Privacy Shield”) in relation to the type of data to be transferred, which requires them to provide similar protection to personal data shared between the EU and the US.

2. WHAT TYPES OF DATA DO WE COLLECT?

Personal data means all information relating to the user that allows us to identify him, such as his name, contact details, payment details and information on his access to the Site. When you register on our Site, you create an account, use our services or contact our support service, we collect some of your personal data. Some of the aforementioned data are provided to us voluntarily by the user himself, while others we collect automatically.

Data provided voluntarily by the user

The Site offers users the possibility to voluntarily provide personal information through, for example, the creation of an account, the purchase / sale of products through our Site, the inclusion of a review or comment, the compilation of the return service. , the compilation of the contact forum or the use of the messaging and chat service with our customer service or how much you contact us to leave us your comments or opinions. In case you need to contact us by phone, we record the call for the purpose of training and improving our services and take notes in connection with your call. We remind you that you can register on the Site and create an account even using a social network account, such as a Facebook account. In the event that you subscribe through this method by releasing the permissions requested during registration, we will receive the information of your social network account, such as name and surname, position, basic personal data.Quando utilizzo il Sito in qualità di Venditore, i contenuti e le immagini inserite nella tua vetrina online saranno visibili anche agli altri utenti; allo stesso modo, quanto lasci commenti e recensioni nelle apposite sezioni del Sito, i contenuti delle tue recensioni, il tuo nominativo e la tua foto (se caricata) saranno visibili a coloro che accedono al Sito.

Dati sensibili

We do not process sensitive data, or details on physical health or mental health, on the alleged commission of crimes or criminal convictions, however, in the event that you spontaneously share any of this information with us, we will only process such data with your explicit consent.

Third party data

If you decide to provide third party data, make sure that these subjects have been previously and adequately informed about the methods and purposes of the processing indicated here. In relation to this hypothesis, you place yourself as an independent data controller, assuming all the obligations and responsibilities of the law.

Data of minors under the age of 16

In this regard, we remind you that if you are under the age of 16 you cannot provide us with any personal data, and in any case we do not assume any responsibility for any false statements provided by you. If we become aware of the existence of untruthful statements, we will proceed with the immediate cancellation of any personal data acquired.

Navigation data

We collect the following data through the services you use:

• technical data: This category of data includes the IP addresses or domain names of the computers you use when you connect to the Site, the URI (Uniform Resource Identifier) ​​addresses of the requested resources, the time of the request, the method used when submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to your operating system and IT environment. These data are used only for statistical information (therefore they are anonymous), to check the correct functioning of the Site and are deleted immediately after processing. The data could be used to ascertain responsibility in the event of hypothetical computer crimes against the site: except for this possibility, the data on web contacts do not persist for more than 7 days.

• data collected using cookies or similar technologies: for more information, please visit the “Cookies” section.

3. FOR WHAT PURPOSES DO WE PROCESS YOUR DATA?

a) To guarantee you access to our Site and the use of our services

When you use our Site and related services, we will use your personal data to allow you to register on the Site and create a personal account, to verify your identity as a user of the Site, to allow you to buy / sell products and, where appropriate, return the products purchased, to provide you with customer assistance service and to solve any problems reported by you, to send you necessary communications (such as confirming the purchase order or confirming the successful completion of the payment or remembering products on your cart) as well as to provide you with all the additional services described in the General Conditions.

b) To inform you about products, services, events and for other promotional purposes

If you have expressly given us your consent or if we have a legitimate interest (pursuant to applicable law), we will use your data to update you about the products and services we offer as well as to inform you about the Company’s promotional, commercial and advertising activities or third-party business partners via e-mail, SMS or whatsapp; only if you are a professional could we notify you of such promotions and events by phone call through an operator or customer care service consisting in the offer of dedicated services in the sales and after sales. Furthermore, always subject to your consent or if we have a legitimate interest (pursuant to applicable legislation), we may use your data in the context of market research and surveys for the detection of your satisfaction, by e-mail, sending SMS or whatsapp, in order to improve our services and the relationship with our users

c) To offer you a personalized service

If you have expressly given us your consent, we use your data to analyze your consumption habits and choices, in order to offer you a personalized service in line with your interests and to improve our commercial offer.

d) To improve the services we offer through the Site

We will use the data provided to improve the services we offer through the Site and your experience of buying / selling products. In particular, we will be able to analyze the use and measure the effectiveness of

our Site and our services for a better understanding of how it is used in order to improve it as well as engage and retain users.

e) To guarantee our rights, ownership or data security

We may also use personal data in connection with the use of our Site to prevent or detect fraud, abuse, illegal use, violations of our General Conditions, and to comply with court orders, government requests or comply with applicable legal provisions.

4. WHAT IS THE LEGAL BASIS FOR THE PROCESSING?

We will only process your personal data in cases where we have a legal basis for doing so.

In most cases, we will process your data to guarantee you access to the Site and the services offered there. In addition, we may process your data for one or more of the following reasons:

With your explicit consent (for example to inform you about our products, services, events and for other promotional purposes, as well as to offer you a personalized service)

To ensure compliance with legal obligations, regulations and community rules (for example to comply with court orders, government requests or comply with applicable legal provisions)

For our legitimate interest (for example to improve the services we offer through the Site or to guarantee the ownership and security of the data we process).

5. IS THE PROVISION OF DATA MANDATORY?

The provision of personal data is mandatory only for the processing necessary to guarantee access to our Site and the services we offer through it. Any refusal to provide the personal data required for this purpose makes it impossible to register on the Site and use the related services. All other provisions of your information are optional but providing them allows us to offer you a better experience.

6. HOW DO WE PROCESS YOUR DATA AND FOR HOW LONG?

The storage of personal data will take place in paper and / or electronic form and for the time strictly necessary to pursue the purpose referred to in point 3 above (“For what purposes do we process your data?”).

In particular, when you register on the Site and create an account, we process and store most of your information in our possession for as long as you actively use the services we offer through the Site. Following the closure of your account, we will keep your personal information for a maximum period of 24 months from the date of cancellation of the account for defense purposes and / or to assert our right in court and / or out of court in the event of legal disputes regarding the execution of our services; your additional personal information relating to transactions carried out through the Site are kept for 10 years in accordance with the law (including tax obligations).

For direct marketing and profiling purposes, we keep your data for a maximum period equal to that provided for by the applicable legislation, respectively equal to 24 and 12 months from the last interaction, of any kind on your part with the Site.

For analysis purposes aimed at improving the service, the user’s personal data will be subject to a maximum retention period of 24 months from the date of their registration.

Upon expiry of the maximum retention period, personal data according to the provisions of this section, we will automatically delete your data or permanently and irreversibly anonymize them.

We remind you that if you do not exercise any active action (such as, use of the services offered by the Site, navigation, searches and / or any other way of using the Site) for a continuous period of 36 months, you will be classified as an inactive user. and, upon written communication regarding the deactivation of your account, we will proceed to keep your personal data for the maximum retention period provided therein.

7. HOW CAN YOU EXERCISE YOUR RIGHTS?

Consistent with the provisions of the GDPR, you have the right to ask us, at any time, to access your personal data, to correct or delete them, to object to their processing or to exercise the right to portability. The applicable legislation on the protection of personal data also allows you to exercise the right to request the limitation of processing in the cases provided for by art. 18 of the GDPR, as well as obtaining the data concerning you in a structured format, commonly used and readable by an automatic device, in the cases provided for by art. 20 of the GDPR.

Requests can be sent to the e-mail address info@ibuonisiamonoi.it. In particular, if you wish to authorize the activities referred to in letters b) (Marketing purposes) in point 3 above (“For what purposes do we process your data?”) And subsequently do not wish to receive further communications from us or would like to limit the methods with to be contacted, you can interrupt these communications at any time by simply clicking on the appropriate “unsubscribe” link at the bottom of each communication.

Finally, we remind you that you always have the right to lodge a complaint with the competent supervisory authority (Guarantor for the Protection of Personal Data), pursuant to art. 77 of the GDPR, if you believe that the processing of your data is contrary to the legislation in force.

8. HOW DO WE GUARANTEE THE PROTECTION OF YOUR DATA?

Your personal data are processed by the subjects indicated in point 1 above (“Who processes your data?”), In compliance with the provisions of current legislation. In particular, to ensure the security of your data taking into account the state of the art and the costs of implementation, as well as the nature, object, context and purposes of the processing, as well as the risk of varying probability and severity for rights and freedoms of individuals, we have adopted adequate technical and organizational measures to ensure a level of security appropriate to the risk.

9. WHEN WAS THIS INFORMATION UPDATED?

This information was published on the date indicated in the header and may undergo changes over time also related to the possible entry into force of new sector regulations, the updating or provision of new services or technological innovations. In this case, the joint controllers will notify you giving you evidence of such updates.

10. ADDITIONAL INFORMATION

(A) Nominations

If the “Work with us” page is active on our Site, you will be able to consult any open professional positions or and send your spontaneous application.

The curricula received, following the communication through the Site of our open professional positions or if you decide independently to send us your resume, will be kept for a maximum period of 6 months from the date of receipt for the sole purpose of evaluating your application or for re-evaluation. for subsequent searches for professional positions compatible with your profile as long as they are activated during the maximum retention period of your data. You can object to the processing of your personal data at any time by writing to info@ibuonisiamonoi.it.

If you apply, remember to include in your curriculum vitae the declaration with which you consent to the processing of personal data for the purpose of selection and avoid entering sensitive personal data (such as health status, religious, philosophical or political beliefs ) not relevant to the job offer.

(b) Third Party Links

This Privacy Policy refers exclusively to the Site. Where the Site contains links to third-party websites, we remind you that we do not exercise any form of control over them and we are not responsible in any way. We therefore invite you to read the respective privacy information on the third-party sites to which you access.

11. DO YOU HAVE FURTHER QUESTIONS?

We welcome questions, comments and concerns about our privacy policy and our privacy practices.

If you wish to provide feedback or if you have any questions or concerns, please contact our DPO or send an email to info@ibuonisiamonoi.it.