Privacy policy
The purpose of this document is to inform the natural person (hereinafter “Data Subject”) about the processing of his/her personal data (hereinafter “Personal Data”) collected by the data controller, LEMADAME Firenze C/o Materia Prima srl, with registered office in Via Lazio,42, Pieve A Nievole (PT), 51018, Tax Code and VAT number 002007640473, e-mail address info@lemadamefirenze.it, (hereinafter “Data Controller”), through the application www.lemadamefirenze.com (hereinafter “Application”).
Changes and updates shall be binding as soon as they are published on the Application. In case of non-acceptance of the changes made to the Privacy Policy, the Data Subject shall cease using this Application and may request the Data Controller to delete his/her Personal Data.
Categories of Personal Data processed
The Data Controller processes the following types of Personal Data voluntarily provided by the Data Subject:
- Contact Data: first name, last name, address, e-mail, telephone, pictures, authentication credentials, any additional information sent by the Data Subject, etc.
The Controller processes the following types of Personal Data collected in an automated manner:
- Technical Data: Personal Data produced by the devices, applications, tools and protocols used, such as, for example, information about the device used, IP addresses, browser type, Internet Service Provider (ISP) type. Such Personal Data may leave traces that, in particular when combined with unique identifiers and other information received by servers, can be used to create profiles of individuals
- Data on navigation and use of the Application: such as, for example, pages visited, number of clicks, actions performed, duration of sessions, etc.
Failure by the Data Subject to provide Personal Data for which there is a legal or contractual obligation, or if they are a necessary requirement for the conclusion of the contract with the Controller, will result in the impossibility for the Controller to establish or continue the relationship with the Data Subject.
The Interested Party who communicates to the Controller Personal Data of third parties is directly and exclusively responsible for their origin, collection, processing, communication or dissemination.
Cookies and similar technologies
The Application uses cookies, web beacons, unique identifiers and other similar technologies to collect the Data Subject’s Personal Data on the pages, links visited and other actions performed when the Data Subject uses the Application. They are stored and then transmitted the next time the User visits the Application. The full Cookie Policy can be viewed at the following address: lemadamefirenze.com/store/en/cookie-policy/
Legal basis and purpose of processing
The processing of Personal Data is necessary:
- for the performance of the contract with the Data Subject, namely:
- fulfilment of any obligation arising from the pre-contractual or contractual relationship with the Data Subject
- registration and authentication of the data subject: to allow the data subject to register on the Application, access and be identified, including via external platforms
- support and contact with the Data Subject: to respond to the Data Subject’s requests
- for legal obligations, namely:
- the fulfilment of any obligation provided for by current rules, laws and regulations, in particular, in tax and fiscal matters
- on the basis of the legitimate interest of the Data Controller, for:
- marketing purposes via email of the Controller’s products and/or services in order to directly sell the Controller’s products or services using the email provided by the Data Subject in the context of the sale of a product or service similar to the one being sold
- management, optimisation and monitoring of the technical infrastructure: to identify and solve any technical problems, to improve the performance of the Application, to manage and organise information in a computer system (e.g. servers, databases, etc.)
- security and anti-fraud: to guarantee the security of the Data Controller’s assets, infrastructure and networks
- statistics with anonymous data: to perform statistical analyses on aggregated and anonymous data to analyse the behaviour of the Data Subject, to improve the products and/or services provided by the Controller and better meet the Data Subject’s expectations
- on the basis of the Data Subject’s consent, for:
- marketing purposes of the Controller’s products and/or services: to send information or commercial and/or promotional materials, to carry out direct sales activities of the Controller’s products and/or services or to carry out market research using automated and traditional methods
Based on the legitimate interest of the Data Controller, the Application allows interactions with external platforms or social networks whose processing of Personal Data is governed by their respective privacy policies to which please refer. The interactions and information acquired by this Application are in any case subject to the privacy settings that the Data Subject has chosen on such platforms or social networks. This information, in the absence of specific consent to processing for further purposes, is used solely for the purpose of enabling the use of the Application and providing the information and services requested.
The Data Subject’s Personal Data may also be used by the Data Controller to protect itself before the competent courts.
Processing methods and recipients of Personal Data
The processing of Personal Data is carried out by means of paper and computer tools with organisational methods and logics strictly related to the purposes indicated and through the adoption of adequate security measures.
Personal Data are processed exclusively by:
- persons authorised by the Data Controller to process Personal Data who have committed themselves to confidentiality or have an adequate legal obligation of confidentiality;
- subjects operating autonomously as separate data controllers or by subjects designated as data processors by the Data Controller in order to carry out all the processing activities necessary to pursue the purposes set out in this policy (e.g. business partners, consultants, IT companies, service providers, hosting providers);
- subjects or entities to whom Personal Data must be disclosed due to legal obligations or orders by the authorities.
The entities listed above are required to use appropriate safeguards to protect Personal Data and may only access Personal Data that is necessary to perform the tasks assigned to them.
Personal Data will not be disseminated indiscriminately in any way.
Location
If necessary, Personal Data may be transferred to entities located outside the territory of the European Economic Area (EEA). Whenever Personal Data is transferred outside the EEA, the Controller will take all appropriate and necessary contractual measures to ensure an adequate level of protection for Personal Data, including, but not limited to, arrangements based on the standard contractual clauses for the transfer of data outside the EEA, approved by the European Commission. To request information on the specific safeguards adopted, the Data Subject may contact the Controller at the following e-mail address info@lemadamefirenze.it
Personal Data Retention Period
Personal Data will be kept for the period of time necessary to fulfil the purposes for which it was collected, in particular:
- for purposes relating to the performance of the contract between the Data Controller and the Data Subject, it will be kept for the entire duration of the contractual relationship and, after termination, for the ordinary limitation period of 10 years. In the event of legal disputes, for the entire duration of the same, until the time limit for appeals is exhausted
- for purposes relating to the legitimate interest of the Controller, they will be kept until such interest is fulfilled
- for the fulfilment of a legal obligation, by order of an authority and for legal protection, they shall be kept in compliance with the timeframes provided for by said obligations, regulations and, in any case, until the fulfilment of the prescriptive term provided for by the rules in force
- for purposes based on the consent of the data subject, they will be kept until the consent is revoked
At the end of the retention period, all Personal Data will be deleted or stored in a form that does not allow the identification of the Data Subject.
Rights of the Data Subject
Data Subjects may exercise certain rights with respect to the Personal Data processed by the Controller. In particular, the Data Subject has the right to:
- be informed about the processing of his/her Personal Data
- withdraw consent at any time
- limit the processing of their Personal Data
- object to the processing of their Personal Data
- access their Personal Data
- verify and request rectification of your Personal Data
- obtain the restriction of the processing of your Personal Data
- obtain the erasure of your Personal Data
- transfer your Personal Data to another controller
- lodge a complaint with the data protection supervisory authority and/or take legal action.
To exercise their rights, Data Subjects may address a request to the following e-mail address info@lemadamefirenze.it. Requests will be taken up by the Controller immediately and processed as quickly as possible, in any case within 30 days.