Privacy Policy

PRIVACY POLICY NOTICE PURSUANT TO ARTICLE 13 OF EU REGULATION 2016/679

regarding data processed via this e-commerce website

We take data protection very seriously and therefore wish to inform you about how your data is processed and the rights you may exercise under current data protection legislation, in particular the EU Regulation 2016/679 (hereinafter also referred to as the “GDPR”), we hereby provide you with the necessary information regarding the processing of the personal data you provide. With regard to the processing of personal data through cookies and other tracking tools, users are invited to read the cookie policy available on this website.

  1. Data Controller

Beautynova S.p.A.
Via Trebazio n. 3
20145 Milan (MI)
E-mail: [email protected]  

Data Protection Officer (DPO)
Vera Cantoni, Solicitor 
Via Turati n. 26, 20121, Milan (MI)
E-mail: [email protected] 

 

  1. The categories of processed personal data

The categories of “personal data” (pursuant to Article 4(1) of the GDPR) processed by the Data Controller may include, by way of example but certainly not limited to:

  • Biographic and identification data (such as, for example, first name, surname, date of birth, etc.);

  • Contact details (such as, for example, address, email address, IP address, telephone number, social media accounts, etc.);

  • Data relating to payments made for purchases made on the website;

  • Personal data necessary for the creation and management of accounts and for purposes related to IT security.

  1. Purposes and legal bases for the processing of personal data

  1. Purposes aimed at fulfilling a legal obligation (Article 6(1)(c) of the GDPR)

  1. Fulfilment of obligations under laws, regulations and EU legislation, or under provisions issued by authorities or supervisory and control bodies in relation to or otherwise connected with the existing and/or future legal relationship (such as, for example, in relation to consumer protection as provided for by Legislative Decree No. 206 of 6 September 2005 and subsequent amendments).


The retention period for personal data, in relation to the purposes set out in this section, is

For purpose (a): 10 years from the end of any contractual relationship or any legal relationship established. This retention period, subject to the deactivation of your account following your request for “deletion” or other instructions communicated by the Data Controller, also applies to the Data contained in the relevant restricted area of the Website.


  1. Purposes relating to the performance of a contract or pre-contractual measures (pursuant to Article 6(1)(b) of the GDPR)

  1. The conclusion and performance of contracts for the purchase of products offered on the Website, including the supply of such products, their dispatch and any returns management;

  2. Management of administrative, accounting, tax and financial processes relating to products purchased by the customer, including invoicing;

  3. Protection of contractual rights or rights otherwise arising from the legal relationships established. Please note that, where the protection of rights is not directly linked to the performance of the contract entered into, the related processing has as its legal basis the legitimate interest (pursuant to Article 6(1)(f) of the GDPR), of a binding nature and arising from the contractual relationship established between the parties;

  4. Handling of enquiries by our Customer Service team, which uses the personal data provided to respond to requests for information and assistance;

  5. Creation and management of the account for the restricted area of the Website.


The retention period for personal data, in relation to the purposes set out in this section, is :

For purposes: a, b, c, d, 10 years from the end of the contractual or legal relationship established (except in the event of any disputes or specific legal provisions to the contrary); 

For the purpose: and until the data subject requests the deletion of the account. If the data subject has not been active on the account for a period exceeding 10 years, the account will be deleted at the initiative of the Data Controller.


  1. Purpose for the pursuit of a legitimate interest (pursuant to Article 6(1)(f) of the GDPR)

  1. Sending newsletters and information material, brochures and invitations to events via email regarding products similar to those already purchased via your account, in the cosmetics and personal care sectors, as well as sending certain reminder emails for purchases left in your basket;

  2. Carrying out anti-fraud activities and checks, and therefore activities to prevent and pursue any fraudulent activities;

  3. Monitoring the proper functioning and security of the Website, and carrying out anonymous statistical analyses regarding the use of the Website.


The retention period for personal data, in relation to the purposes set out in this section, is:

For purpose: a, 24 months from the last purchase made; for other marketing purposes, other than the aforementioned purpose a, this does not constitute an objection to the same and will not result in the cessation of that purpose and related activities; and for any pending purchases, up to 48 hours from the time the shopping basket is filled;

For purpose: b, until the payments relating to the purchases made have been credited and the related administrative and accounting formalities have been completed, as well as until the expiry of the time limits applicable for disputing the payment, and in any case no later than two years from the purchase itself, unless further requirements arise in connection with any disputes, whether already initiated or in the process of being initiated.

For purpose: c, for the duration of the browsing session and until the data is processed, for statistical purposes, in aggregate form, unless their retention for a further period is necessary to protect the rights and interests of the Data Controller (such as, for example, in the event of security incidents).


  1. Purposes covered by the data subject’s consent (pursuant to Article 6(1)(a) of the GDPR)

Personal data may also be processed for specific purposes for which the data subject has given their consent.

  1. Responding to requests or enquiries submitted and sent to the contacts listed on this website, including to receive information about our products ;

  2. Carrying out advertising or promotional activities, in the broadest sense of the term (e.g. sending newsletters and information material, requests for brochures, organising events, etc.) and other marketing activities, via automated means of contact (e.g. email, SMS, and various messaging systems, including instant messaging and internet-based messaging, including to mobile phones) and non-automated means (calls with an operator);

  3. Profiling activities to analyse or predict aspects relating to the data subject’s personal preferences and commercial habits in order to send offers based on the resulting profile.


The retention period for personal data, in relation to the purposes set out in this section, is:

For purpose: a, until the request has been processed, unless the feedback provided and the information exchanged are necessary to demonstrate compliance with any contractual obligations or those arising from any legal relationships established (in which case the retention period will be as indicated in the relevant privacy notices issued in the context of the aforementioned relationships).

For purpose: b, 24 months from the date consent is given;

For purpose: c, 24 months from the date consent is given.

  1. Recipients or categories of recipients of personal data (pursuant to Article 13(1)(e) of the GDPR) *

In connection with the aforementioned purposes, the Data Controller may disclose your data to:

  • Offices and internal departments of the Data Controller;

  • Regulatory and supervisory bodies;

  • Accountants;

  • Companies and professional service providers offering IT services, including electronic data processing, software management, website management and IT consultancy, including mailing companies and hosting providers; 

  • Advertising and communications companies and agencies;

  • Professionals and law firms;

  • Consultants, professionals and firms specialising in corporate compliance;

  • Transport companies, postal couriers and companies involved in product packaging and dispatch;

  • Public administrations, public bodies and agencies within the scope of their institutional duties.


* Further information on the Recipients (pursuant to Article 4.9 of the GDPR) is available from the Data Controller at the contact details provided above.

 

  1. Recipients or categories of recipients of personal data (pursuant to Article 13(1)(f) of the GDPR) and transfer of data to countries outside the EU

The Data Controller hereby informs you that it intends to transfer part of your personal data to countries outside the EU and the EEA**. In particular, your data may be transferred to the United States of America for the purpose set out in point 3.3(a) above, namely for the purpose of “Sending newsletters and information material, brochures and invitations to events via email regarding products similar to those already purchased through your account, in the cosmetics and personal care sectors, as well as sending certain reminder emails regarding purchases left pending in your basket” and for the purpose set out in point 3.4(a), namely “Carrying out advertising or promotional activities, in the broadest sense of the term (e.g. sending newsletters and information material, requests for brochures, organizing events, etc.) and other marketing activities, via automated means of contact (e.g. email, SMS, and various messaging systems, including instant messaging and internet-based messaging, including to mobile phones) and non-automated means (calls with an operator”) to the company The Rocket Science Group LLC (in relation to the MailChimp application), on the basis of the EU–US Data Privacy Framework, to which that company adheres, and therefore pursuant to Article 45 of the GDPR.

In relation to the personal data subject to the aforementioned transfers to non-EU territories, the data subject may obtain information by making a request to the Data Controller via the contact details provided in point 1 of this policy.


** The updated list of non-EEA countries deemed adequate by the European Commission can be obtained from the website: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en.

 

  1. Rights of the data subject

In relation to the personal data covered by this policy, the data subject has the right to exercise the rights provided for by the EU Regulation as set out below:


  • right of access [Article 15 of the EU Regulation] (consisting of the right to be informed about the processing of one’s personal data and, where applicable, to receive a copy thereof);

  • right to rectification of personal data [Article 16 of the EU Regulation] (the data subject has the right to have inaccurate personal data concerning them rectified);

  • the right to erasure of personal data without undue delay (“right to be forgotten”) [Article 17 of the EU Regulation] (the data subject has, and will continue to have, the right to have their data erased);

  • the right to restrict the processing of one’s personal data in the cases provided for in Article 18 of the EU Regulation, including in the event of unlawful processing or where the data subject contests the accuracy of the personal data [Article 18 of the EU Regulation];

  • the right to data portability [Article 20 of the EU Regulation] (the data subject may request their personal data in a structured format in order to transmit it to another data controller, in the cases provided for in that Article);

  • the right to object to the processing of one’s personal data [Article 21 of the EU Regulation] (the data subject has, and will continue to have, the right to object to the processing of their personal data in the cases provided for and regulated by Article 21 of the EU Regulation);

  • the right not to be subject to automated decision-making [Article 22 of the EU Regulation] (the data subject has, and will continue to have, the right not to be subject to a decision based solely on automated processing).


With regard to the purposes for which consent is required, the data subject may withdraw their consent at any time, and the effects shall take effect from the moment of withdrawal, subject to the time limits provided for by law. In general terms, the withdrawal of consent takes effect only for the future.

The aforementioned rights may be exercised in accordance with the provisions of the EU Regulation by sending an email to [email protected] .

The Data Controller, in accordance with Article 19 of the EU Regulation, shall inform the recipients to whom the personal data have been disclosed of any requested rectifications, erasures or restrictions on processing, where this is possible. 

To ensure a quicker response to your requests made in the exercise of the aforementioned rights, these may be addressed to the Data Controller using the contact details provided in point 1.

 

  1. Right to lodge a complaint (pursuant to Article 13(2)(d) of the GDPR)

If the data subject considers that their rights have been infringed, they have the right to lodge a complaint with the Data Protection Authority. 

For further information on your rights and how to exercise them, please visit http://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/4535524 or send a written communication to the Data Protection Authority.

 

  1. Possible consequences of failure to provide data and the nature of the provision of data (pursuant to Article 13(2)(e) of the GDPR)

8.1 In the event of compliance with any legal or contractual obligations

Please be advised that, where the legal basis for the processing purposes is a legal or contractual (or even pre-contractual) obligation, the data subject must necessarily provide the requested data.

Otherwise, the Data Controller will be unable to pursue the specific purposes of the processing.


8.2 In the case of the pursuit of a legitimate interest

Similarly, with regard to purposes based on a legitimate interest and which do not require consent, the data subject’s objection entails or will entail the impossibility of carrying out the respective purposes and any related services to which the data subject has objected, subject to the Data Controller’s overriding legitimate grounds or those aimed at the protection of rights in court proceedings.


8.3 In the event of the data subject’s consent

Please note that the legal basis for the purposes set out above is consent and that, in relation to these purposes, the data subject may withdraw their consent at any time, with effect from the moment of withdrawal, subject to the time limits provided for by law. In general terms, the withdrawal of consent takes effect only for the future. Therefore, processing carried out prior to the withdrawal of consent will not be affected and will remain lawful.

Failure to give consent, or the giving of partial consent (or the withdrawal thereof), may not guarantee the full provision of services or activities, with reference to the specific purposes for which consent is withheld, and shall not constitute a prejudice or impediment to other purposes (and related activities) not involved or expressly affected by the withdrawal of consent or not based on that legal basis.


Please note that with regard to requests for information, whilst consent to the processing of personal data remains free and optional, it is necessary for the request to be processed. Therefore, the submission of the request or an equivalent expression of intent shall be deemed to constitute the granting of consent, which may always be withdrawn with the consequences outlined above.


When data is no longer required, it is routinely deleted; if deletion proves impossible or would require a disproportionate effort due to a particular storage method, the data may not be processed and must be archived in inaccessible areas.

 

  1. Existence of automated decision-making (including profiling)

The use of purely automated decision-making processes, as detailed in Article 22 of the GDPR, is currently excluded. Should it be decided in the future to implement such processes for individual cases, the data subject will be notified separately where required by law or via an update to this policy.


  1. Methods of processing

Personal data will be processed electronically and via telecommunications and entered into the relevant databases, which may be accessed, and thus become known to, by staff expressly designated by the Data Controller as Data Processors and Authorised Persons for the processing of personal data, who may carry out operations of consultation, use, processing, comparison and any other appropriate operation, including automated ones, in compliance with the legal provisions necessary to ensure, amongst other things, the confidentiality and security of the data, as well as the accuracy, updating and relevance of the data in relation to the stated purposes.


Processing of data for browsing purposes

The IT systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.

This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified.

The information that may be collected includes IP addresses, the type of browser or operating system used, URI (Uniform Resource Identifier) addresses, the domain name and the addresses of the websites from which access or exit was made (referring/exit pages), the time at which the request was made to the server, the method used and information on the response received, further information on the user’s navigation of the site (see also the section on cookies) and other parameters relating to the user’s operating system and IT environment.

This same data may also be used to identify and establish liability in the event of any cybercrimes committed against the site.


Notice regarding children under 14

Children under 14 years of age may not provide personal data. Beautynova S.p.A. shall in no way be liable for any collection of personal data, nor for any false statements provided by the child; in any event, should such use be identified, Beautynova S.p.A. will facilitate the right of access and erasure requested by the legal guardian or the person exercising parental responsibility. 


Changes and updates

This policy states the date of its last update in the header. 

Beautynova S.p.A. may also make changes and/or additions to this policy, including as a result of any subsequent changes and/or additions to the relevant legislation.