PRIVACY POLICY

INFORMATION ON THE PROCESSING OF PERSONAL DATA

Pursuant to and for the purposes of Art. 13 of the New European Regulation 2016/679 concerning the protection of individuals with regard to the processing of personal data (GENERAL DATA PROTECTION REGULATION - GDPR)

As required by the General Regulation on the Protection of Personal Data of the European Union (GDPR 2016/679, Article 13), before proceeding with the processing, the interested party (user of the website www.mariateresapellegrino.com) is informed that personal data collected through the site are processed by the company AMBRA S.R.L.S. (owner of the website www.mariateresapellegrino.com as well as licensee of the registered trademark "MARIATERESA PELLEGRINO") using IT and / or telematic tools, for the purposes indicated in this information.

To this end, the data subject is submitted to the Privacy Policy prepared by AMBRA S.R.L.S. (hereinafter also the "Company" or "the Data Controller"), creator and promoter of the activities available on the website www.mariateresapellegrino.com.

Holder of the treatment

The Data Controller of personal data is AMBRA S.R.L.S., with registered office in Via Trento n.12 - 73010, Zollino (LE), VAT number: 04938730753.
The Company has identified a Data Protection Officer pursuant to articles 37 and following of the 2016/679 European Regulation, who identifies himself as Mr. Maurizio Castellano.

This person can be contacted for clarifications and questions relating to the processing of personal data at the address: dpo@mariateresapellegrino.com.
For more information relating to the rights of the interested party, please consider the paragraph called "Rights of the interested parties" of this information.

Treatment information

The personal data being processed are collected directly by AMBRA S.R.L.S. or by third parties expressly authorized by it, or communicated by the Company to such third parties for the pursuit of the purposes described below.

Legal basis and purpose of the processing

The personal data provided by the user when browsing the website www.mariateresapellegrino.com are processed by the Data Controller in accordance with current regulations on the protection of personal data.
The legal basis of the processing is identified in the provision of its services by the Company, in the management and facilitation of the website, as well as in the constitution, execution and possible termination of the online sales contract concluded between the parties and in the obligations to the same contract. connected and / or directly and / or indirectly deriving from the same.
The processing of personal data by AMBRA S.R.L.S. is aimed at pursuing the following purposes:

1) SUBSCRIPTION TO THE NEWSLETTER OF MARIATERESAPELLEGRINO.COM: in the event that the user decides to subscribe to the "Newsletter of MARIATERESA PELLEGRINO", only after a possible and specific consent, the personal data will be processed by the Data Controller for the sending commercial or promotional communications, updates relating, for example, to the latest trends, new arrivals, exclusive offers, special events and promotions. To unsubscribe from the newsletter, simply click on the unsubscribe link at the bottom of the e-mails received or by writing to customer assistance@mariateresapellegrino.com.

The Data Controller, to compare and possibly improve the results of communications, could possibly use systems for sending newsletters and promotional communications equipped with a reporting mechanism, thanks to which the Owner will be able to know, for example: the number of readers, openings and clicks; the type of device used to read the communication (desktop, mobile); the number of pending users who have not yet confirmed their registration; the number of emails sent by date / hour / minute; the details of the emails delivered compared to those sent; the list of unsubscribed from the newsletter; the openings of emails and clicks on individual links; problems displaying the message; link tracking (i.e. the number of clicks made on the links in the message); click tracking (which links were clicked). All these data would be used for the purpose of comparing, and possibly improving, the results of the communications.

2) REGISTRATION ON MARIATERESAPELLEGRINO.COM: in the event that the user decides to register on the mariateresapellegrino.com site, only following a possible and specific consent, the personal data will be processed by the Data Controller for the purposes of registration on mariateresapellegrino.com. In particular, upon the provision of one's name, surname, e-mail address and the setting of an access password, these will be processed for the creation of a personal account, to speed up the purchase procedure, to allow the user to view the status of orders and receive updates on purchases made, set and modify their data and any "Preferences" that will improve navigation, and update the account, view the history of returns and requests for exchange goods, save items favorites in the Wishlist and to offer the possibility of joining loyalty programs at a later time, should the user so wish.

3) SUBSCRIPTION TO LOYALTY PROGRAMS: in the event that you decide to join a loyalty program promoted on www.mariateresapellegrino.com, your personal data will only be processed by the Data Controller for the purposes registration to the program (for which please refer to the website www.mariateresapellegrino.com to view the terms and conditions).

4) ONLINE SHOPPING ACTIVITIES: the personal data provided will be used for the purpose of establishing, managing, executing and / or concluding the online sales contract. The data provided will be processed by the Data Controller for the purposes of managing the purchase order with reference, by way of example, to the payment, shipping, taking charge of any returns, for customer assistance, for the execution of the purposes administrative - accounting related to the management of the order, for the fulfillment of obligations under current legislation. In case of payment by credit card, the fundamental information for the execution of the transaction (credit card holder, credit / debit card number, expiration date, security code) will be processed by SHOPIFY PAYMENTS or, possibly, by companies in charge of anti-fraud control using an encrypted protocol and without third parties being able to access it in any way. However, this information will never be viewed or stored by the seller (AMBRA S.R.L.S.).

5) PROFILING OF THE PHYSICAL PERSON: only after a possible and explicit consent, the personal data provided may be processed by the Data Controller for profiling activities, or for the analysis of preferences aimed at creating customized content and offers.

Nature of the treatment

In relation to the purposes referred to in point 1) of the previous paragraph, the provision of personal data and consent to their processing is optional. Failure to provide consent will make it impossible for AMBRA S.R.L.S. to allow the subscription to the "Newsletter of www.mariateresapellegrino.com", the sending of commercial or promotional communications, updates relating, for example, to the latest trends, new arrivals, exclusive offers, special events and promotions.

In relation to the purposes referred to in point 2) of the previous paragraph, the provision of personal data and consent to their treatment is mandatory. Failure to provide consent will make it impossible for AMBRA S.R.L.S. to allow registration on www.mariateresapellegrino.com, the creation of a personal account, speeding up the purchase procedure, viewing the status of orders and receiving updates on purchases made, the possibility for the user to change settings personal and update the account, to view the history of returns and requests for exchange goods, to save the favorite items in the wish list and to join a loyalty program at a later time, if desired.

In relation to the purposes referred to in point 3) of the previous paragraph, the provision of personal data and consent to their processing is optional.
Failure to provide consent will make it impossible for AMBRA S.R.L.S. to allow joining the loyalty program.

In relation to the purposes referred to in point 4) of the previous paragraph, the provision of personal data and consent to their treatment is mandatory. Failure to provide consent will make it impossible for AMBRA S.R.L.S. to proceed with the establishment, management, execution and / or conclusion of the online sales contract, therefore the impossibility of carrying out, by way of example, the activities related to payment, shipping, taking charge of any returns, customer assistance activities, the execution of the administrative - accounting purposes related to the management of the order, and the fulfillment of obligations under current legislation.

In relation to the purposes referred to in point 5) of the previous paragraph, the provision of personal data and consent to their processing is optional.
Failure to provide consent will make it impossible for AMBRA S.R.L.S. to carry out profiling activities, or to carry out analysis of preferences aimed at creating personalized content and offers.

Personal data processed

The personal data processed by the Data Controller are those provided by the user when browsing the website www.mariateresapellegrino.com, on the occasion of any registration / adhesion to the services / programs made available to AMBRA S.R.L.S. and / or the possible purchase of products made available to AMBRA S.R.L.S., such as, by way of example: name, surname and e-mail address, in addition to the data necessary for the provision of the online sales service such as, for example, those functional to the execution of the payment and to the shipment / exchange of the purchased products.

Methods of data processing and storage

The processing of personal data is carried out by the Data Controller in compliance with the provisions of current legislation on privacy. The Data Controller processes personal data using IT and / or telematic tools and with organizational and logical methods strictly related to the pursuit of the purposes indicated in this information, as well as adopting the appropriate security measures in order to prevent access, disclosure, the unauthorized modification or destruction of personal data, their loss and their illicit and incorrect use. However, the Company cannot guarantee its users that the measures adopted for the security of the site and the transmission of data and information on the site are able to limit or exclude any risk of unauthorized access or loss of data by devices. pertaining to the user. For this reason, users of the site are advised to make sure that their computer is equipped with adequate software for the protection of data transmission over the network (for example updated antivirus) and that their Internet Provider has adopted suitable measures for the security of transmission. of data on the network. The Company also undertakes to process the data according to the principles of correctness, lawfulness and transparency, to collect them to the extent necessary and exact for processing and to allow their use only by authorized personnel. The management and storage of personal data acquired will take place in archives or on servers not located inside of the European Union and not owned by the Owner and / or by third-party companies appointed as External Data Processors and, in any case, not currently located in Italy.

In relation to the various purposes for which they are collected, personal data will be kept for the time strictly necessary to achieve them and, in any case, in compliance with the regulations in force on the subject.

In any case, the Company will take care to avoid the use of the data indefinitely by proceeding, on a periodic basis, to appropriately verify the effective persistence of the interest of the subject to which they refer.

Recipients and data processors

The data collected will not be disseminated in any way, but will be processed within the limits and for the purposes described by the employees of the Company on the basis of adequate operating instructions (for example, administrative, commercial, marketing, legal, system administrators, etc. .). Some data processing may also be carried out by third parties, appointed as External Data Processors, of which the Data Controller makes use or could use in the context of the management of the contractual relationship, the provision of the services offered and for the organizational needs of its business. In particular, the data could be communicated to:

a) subjects, public and private, who can access the data by virtue of the provision of law, regulation or community legislation, within the limits set by these rules;
b) subjects who need to access data for purposes related to the contractual relationship between the parties, within the limits strictly necessary for the performance of auxiliary tasks (such as, for example, banks and credit institutions, technical service providers, hosting providers, IT companies, communication agencies, postal couriers and shipping companies);

c) consultants, within the limits necessary for the performance of their professional duties.

The updated list of External Managers and persons authorized to process the processing is kept at the headquarters of the Data Controller and is available to the interested party, upon request to be made by e-mail to the address dpo@mariateresapellegrino.com

Transfer of data abroad

The management and storage of personal data will take place on the servers of third-party companies duly appointed as External Data Processors located outside the European Union.
Personal data may therefore be transferred abroad, in accordance with the provisions of current legislation, even in countries outside the European Union. The transfer to non-EU countries, in addition to the cases in which this is guaranteed by the Commission Adequacy Decisions, is carried out in such a way as to provide appropriate and appropriate guarantees pursuant to art. 46 or 47 or 49 of the Regulation.

Rights of the interested parties

As an interested party, the user may exercise, at any time, the rights provided for in articles 15, 16, 17, 18, 20 and 21 of the GDPR which confer, in particular, the right to:

a) obtain from the Data Controller, pursuant to Article 15, confirmation that personal data is being processed or not and, in this case, obtain access to the data and information such as: (i) the purposes of the processing; (ii) the categories of personal data; (iii) the recipients or categories of recipients to whom the personal data have been or will be communicated, in particular if they are recipients located in Third Countries or International Organizations; (iv) when possible, the retention period of the personal data envisaged or, if not possible, the criteria used to determine this period;

b) obtain from the Data Controller, pursuant to Article 16, the correction of inaccurate personal data concerning him without undue delay; taking into account the purposes of the processing, the interested party has the right to obtain the integration of incomplete personal data, also by providing a supplementary declaration;

c) obtain from the Data Controller, pursuant to Article 17, the cancellation of personal data concerning him without undue delay. The Data Controller is obliged to delete personal data without undue delay if one of the reasons indicated in paragraph 1 of Article 17 exists; d) obtain from the Data Controller, pursuant to Art. 18, the limitation of processing when one of the hypotheses governed by paragraph 1 of Article 18 occurs;

e) obtain from the Data Controller, pursuant to Article 20, the portability of data, i.e. receiving in a structured format, commonly used and readable by an automatic device, the personal data concerning him provided to a Data Controller. The interested party also has the right to transmit such data to another Data Controller without impediments by the first Data Controller to whom he provided them, if the conditions indicated in Article 20 paragraph 1 are met. Finally, the interested party has the right to obtain the direct transmission of personal data from one Data Controller to another, if technically feasible;

f) object, in whole or in part, pursuant to Article 21, to the processing of personal data concerning him.

To exercise their rights, the user can send their requests to dpo@mariateresapellegrino.com.
It should also be noted that the interested party has the right to revoke the consent at any time without prejudice to the lawfulness of the processing based on the consent given before the revocation, without prejudice to the consequences indicated above regarding any refusal to provide such personal data. . The interested party also has the right to lodge a complaint with a Supervisory Authority.
You can make requests regarding the exercise of these rights by contacting the address: dpo@mariateresapellegrino.com.

AMBRA S.R.L.S. undertakes to respond to requests from the interested party within one month, except in particularly complex cases for which it could take a maximum of three months. In any case, the Data Controller will provide the interested party with evidence of the reason for waiting within one month of the request. The outcome of the request will be provided in writing or electronically. In the event of a request for rectification, cancellation and limitation of processing, the Data Controller undertakes to communicate the results of the requests received from the interested party to each of the recipients of his data, unless this proves impossible or involves a disproportionate effort.

The Company specifies that a possible contribution may be requested from the interested party if the questions are manifestly unfounded, excessive or repetitive; in this regard, the Data Controller will equip itself with a register to track requests for intervention.

Changes to this information

The data controller reserves the right to make changes to this Privacy Policy at any time by giving notice to users on the website www.mariateresapellegrino.com. Therefore, please consult this page often, referring to the date of the last modification indicated at the end of the document. In the event of non-acceptance of the changes made to this Privacy Policy, the interested party may request the Data Controller to delete their personal data. Unless otherwise specified, the previous Privacy Policy will continue to apply to personal data collected up to that time.

Privacy Notice updated on 11/23/2021