Privacy Policy | Montale Privacy Policy | Montale

Privacy Policy | Montale

pursuant to EU Regulation No. 679/2016 (“GDPR”) and Legislative Decree No. 196/2003 as amended by Legislative Decree No. 101/2018

This policy (hereinafter the “Policy”) describes how MM Profumi S.r.l. (hereinafter the “Data Controller”) collects and processes the personal data of users who browse and/or interact (hereinafter the “Data Subjects”) with the website www.montaleparfums.com/ita/en  (hereinafter the “Website”).

The Policy may be subject to change; therefore, the Data Controller invites users to consult it regularly.

Please note that this Policy applies solely to the aforementioned Website and not to any other websites that the user may access via links.

EXTENDED PRIVACY POLICY

1. Data subject to processing

The Data Controller collects certain categories of personal data (hereinafter referred to as the “Data”) through browsing and use of the Website. In particular:

1.1   personal data, both identifying and non-sensitive (in particular, first name, surname, tax code, VAT number, email address, telephone number) provided directly by Data Subjects when registering on the Website and/or requesting to use the e-commerce service and other individual services offered;

1.2    data provided directly by Data Subjects – and in any event collected within the limits set out in Article 14(5) of the GDPR – the transmission of which is linked to the use of Internet communication protocols (by way of example only: page views, volume of data transferred, status messages regarding access events, session ID numbers, IP addresses, URLs, etc.) . For further information on this type of data and its processing, please refer to the cookies policy: https://montaleparfums.com/ita/en/content/17-cookies-policy

As a general rule, the Data Controller does not process data relating to personal beliefs, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or information relating to health, sex life or sexual orientation (hereinafter “Special Categories of Data”). Should it be necessary to process Special Categories of Data, MM undertakes to process such data in accordance with the applicable legislation.

2. Purposes and legal basis for the processing of Data

The Data Controller processes the Data of Data Subjects for one or more of the purposes set out below.

A) Registration on the Website and/or management of purchase orders and related activities (provision of the e-commerce service, sales and after-sales customer support, communications with the customer regarding order status, payment processing, notifications, home delivery); as well as to ensure proper compliance with legal obligations.

Legal basis: processing is necessary: (i) for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures taken at the data subject’s request; (ii) to comply with a legal obligation to which the data controller is subject (Articles 6(1)(b) and (c) of the GDPR).

B) Sending commercial communications via traditional means (ordinary post and telephone with an operator) or automated means (email, automated telephone calls, SMS, RCS, MMS, fax, social media, WhatsApp, Telegram) relating to the data controller’s products and activities

Legal basis: Consent (Article 6(a) of the GDPR): the data subject has given their consent to the processing of their data.

3. Data retention period

10 years or as otherwise required by law (Article 2220 of the Italian Civil Code) for the purpose set out in point 2 A

2 years, unless the data subject withdraws the consent previously given for the purpose set out in point 2 B

4. Methods of Data Processing

Data processing is carried out by means of the operations set out in Article 4(2) of the GDPR, namely: collection, recording, organisation, storage, consultation, processing, modification, selection, retrieval, comparison, use, interconnection, blocking, disclosure, erasure and destruction of data. The processing of Data shall be based on the principles of fairness, lawfulness and transparency and may also be carried out using automated means designed to store, manage and transmit the Data; it shall be carried out using appropriate tools, insofar as is reasonable and in accordance with the state of the art, to ensure security and confidentiality through the use of suitable procedures that prevent the risk of loss, unauthorised access, unlawful use and disclosure.

5. Recipients or categories of recipients of the Data

The Data provided will be disclosed to recipients who will process the data in their capacity as data processors (Article 28 of EU Regulation 2016/679) and/or as natural persons acting under the authority of the Data Controller and the Data Processor (Article 29 of EU Regulation 2016/679), for the purposes listed above.

Specifically, the data will be disclosed to: - entities providing services for the management of the information system and communication networks (including email); - firms or companies in the context of assistance and consultancy relationships; - competent authorities for the fulfilment of legal obligations and/or provisions issued by public bodies, upon request; - for administrative and accounting purposes, the data may, where necessary, be transmitted to credit reference agencies for the assessment of creditworthiness and payment habits and/or to entities for debt recovery purposes. Entities belonging to the above categories act as Data Processors, or operate entirely independently as separate Data Controllers. The complete and up-to-date list of Data Processors may be requested from the Data Controller using the contact details set out in Article 10 below.

6. Data transfers to a third country

The use of our website and its features may involve data transfers to countries outside the European Union.

In such cases, where those countries do not benefit from an adequacy decision under the GDPR, various measures are put in place to ensure that Personal Data transferred to those countries is adequately protected in accordance with the provisions of the GDPR.

Indeed, if we transfer Personal Data to third parties outside the European Union, this is always in accordance with the provisions of the GDPR and, consequently, we take all appropriate measures to protect Personal Data, in particular by using standard contractual clauses approved by the European Commission.

The transfer of Personal Data from the European Union to the USA also provides for an adequate level of data protection under the Data Privacy Framework adopted by the European Commission on 10 July 2023.

7. Nature of the provision of data

The provision of data for purpose A) of this privacy notice is optional. However, refusal to provide such data will prevent the Data Controller from providing the service. The provision of data for purpose B) – the sending of marketing communications – is optional; should you choose not to provide such data, it will not be processed for that purpose, but refusal to provide it will not affect the provision of the e-commerce service.

8. Absence of automated decision-making

The Data Controller does not use any automated decision-making processes, including profiling as referred to in Article 22(1) and (4) of the GDPR

9. Rights of data subjects

Data subjects have the right to obtain from the Data Controller, in the cases provided for, access to their personal data and the rectification or erasure of such data, or the restriction of processing concerning them, or to object to the processing (Articles 15 et seq. of EU Regulation 679/2016).

They may also object to processing based on legitimate interests at any time.

To exercise these rights, data subjects may contact the Data Controller by email at: privacy@mmprofumi.it, or by sending a written communication to the Data Controller’s registered office as indicated in Article 10 below.

Data subjects also have the right to withdraw their consent at any time, without this affecting the lawfulness of processing based on consent prior to withdrawal, using the contact details provided above.

Data subjects who consider that the processing of their personal data is in breach of the provisions of the Regulation have the right to lodge a complaint with the Data Protection Authority, as provided for in Article 77 of the Regulation, or to bring the matter before the appropriate courts (Article 79 of the Regulation).

10. Data Controller

MM Profumi S.r.l., with its registered office at Corso Garibaldi 50, Milan

The Data Controller’s contact email address is privacy@mmprofumi.it

No Data Protection Officer (DPO) has been appointed, as the conditions set out in Articles 37–39 of EU Regulation 2016/679 are not met.

Loading...
SONDE MONITORING