PRIVACY POLICY

The company F.B. s.r.l. (VAT No. 03105310134), with registered office in Milan (MI) 20123, via V. Monti, 55, Economic and Administrative Index and Chamber of Commerce of Milan, Monza Brianza, Lodi number MI1874968 and administrative and operational headquarters in Locate Varesino (CO), Via Sacro Monte n. 1 (22070), telephone 0287366253 (Monday to Saturday from 9 a.m. to 10 p.m., excluding Sundays and national holidays in Italy), email: servizioclienti@gioiapura.it (hereinafter, the "Data Controller"), in its capacity as Data Controller pursuant to Articles 4, 7 and 24 of the EU Regulation 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data (hereinafter, the "Regulation") informs you, pursuant to Articles 13 and 14 of the Regulation, that it will process personal data referring to users of the site.

1. PURPOSE OF THE PROCESSING

According to the European Data Protection Regulation, corporate bodies cannot be considered as data subjects and therefore the European Regulation does not apply. However, if personal data referring to a natural person is included in the context of the collection of corporate data, this person shall be considered a data subject within the meaning of the aforementioned regulation.


MARKETING COMMUNICATIONS (via email, SMS and WhatsApp): If you give your consent to receive marketing communications, the Controller will send you newsletters and advertising material to your e-mail address and your telephone number (also by SMS and WhatsApp).
PROFILED COMMUNICATIONS (via email, SMS and WhatsApp): If you give your consent to receive communications profiled according to your interests, the Controller will send you advertising material, in line with your interests and spending habits, to your e-mail address address and your telephone number (including by SMS and WhatsApp).
CONTACT US: If you fill in the contact form we will ask you to provide your full name and email address.
PURCHASE: If you make a purchase we will ask for your personal data and contact information as well as your shipping address.
REGISTRATION: We will ask for your personal data and contact information.
You may also decide to register with the site when you complete your purchase and in this case we will use the data you provide us with when filling out the purchase form. You may also decide to register via social media and in this case your data will be provided to us by Google or Facebook.
WORK WITH US: we will collect the data that will be included in your CV and which will therefore also be your personal and contact details. We may also process special data such as, for example, membership of protected categories.
ABANDONED CART and WISHLIST: we will process your email address.
PRODUCT AVAILABILITY NOTIFICATION: we will process your email address.
REVIEW: we will use your email address to ask you to provide reviews.

In all cases, iwe will process your IP address and browsing logs.

2. LEGAL GROUNDS AND PURPOSE OF PROCESSING

The data will be processed to allow the activities related to the establishment and management of the service requested from the owner to be carried out.
The provision of data is compulsory in all cases in which the legal basis is the execution of the agreement or the fulfilment of legal obligations arising from the purchase, while it is optional in all other cases; in any case, in the event of failure to provide the data, it will not be possible to fulfil the requests.
The data will be processed lawfully, correctly and with the utmost confidentiality, in compliance with the appropriate security measures as provided for by the Code and the Regulations.
The processing will be carried out by analogue/digital means. The data will not, however, be publicly disclosed, with the exception of comments or reviews.
Subject to your prior consent, you may be subject to profiling as better specified in the dedicated paragraph.
Especially:


MARKETING COMMUNICATIONS: Subject to explicit consent, for the sending of newsletters and advertising material relating to products and/or activities of the Controller, by means of automated systems, such as email, SMS and WhatsApp (marketing purposes). of marketing). The legal basis for this processing is your consent. The provision of personal data personal data for this purpose is purely optional. Failure to consent to the processing of data for marketing purposes will make it impossible for you to receive advertising material relating to the Controller's products and/or activities.
PROFILED COMMUNICATIONS: With your explicit consent, for processing your commercial profile, through the detection and processing of your choices, purchasing habits browsing on the Site (also tracked through the use of cookies), in order to send you advertising material relating to the Controller's products and/or activities, in line with your interests and your spending habits, by means of automated systems, such as email, SMS and WhatsApp (profiling purposes). In addition, the Controller may cross-reference elements such as purchase characteristics, average shopping cart, purchase frequency, gender and date of birth or birth or geographical area in order to process your commercial profile. The legal basis for this processing is your consent. The provision of data for this purpose is purely optional. Failure to consent to the processing of your personal data for profiling purposes will make it impossible for the Controller to process your commercial profile, by means of the detection of your choices, purchasing habits and browsing methods on the Site as well as to send you advertising material relating to the Controller's products of your specific interest.
LIGHT/SEGMENTATION PROFILING: : We may carry out a segmentation of our clientele on the basis of some basic information, such as the division into male/female or by age group, and also cross-reference this data with others such as, for example, the number of purchases or their frequency; not obtaining a detailed profile and respecting what may be defined as the legitimate expectations of the interested party and only processing data held by the company, without comparison or interconnection with other systems.
CONTACT US: The legal basis is consent and your data will be processed to enable us to respond to your requests.
PURCHASE: The purpose is to enable you to complete the purchase of our products and allow us to send them to you. The legal basis is the execution of a agreement and the fulfilment of legal obligations (including accounting and tax obligations). Your data will be communicated to the courier company in charge of the shipment, duly appointed as data processor. With purchase, subject to consent, your data will be exported to a CRM for sending commercial information.
REGISTRATION: The purpose is to allow you to enter our site and make purchases more easily as well as manage orders or returns. The legal basis is consent.
WORK WITH US: The purpose is to allow us to evaluate your CV and the legal basis is to be found, for common data, in Article 111bis of Legislative Decree no. 196/03 (execution of pre-contractual measures carried out at the request of the interested party); for special data, in Article 9 lett. b) and therefore necessary to exercise the specific rights of the interested party in the field of labour law.
REVIEW: The legal basis is consent and we will process your data to enable you to carry out these activities.
ABANDONED CART and WISHLIST: The legal basis is the company's legitimate interest in reminding the user to complete an "aborted purchase" and the products in the shopping cart as well as letting users whose products are on the wishlist know about changes to them (for example: availability or price) We believe that the user can reasonably expect such treatment because he or she has interacted with the site by showing interest in certain products. It is understood that you may always object to such processing by exercising your rights under Article 21 GDPR.
NOTIFICATION OF PRODUCT AVAILABILITY: The legal basis is the execution of pre-contractual measures carried out at the request of the data subject and the purpose is to respond to your request.
REVIEW: The legal basis is the legitimate interest of the company in asking you for a review of the products or services rendered; while the legal basis for rendering the review remains consent.

In any case, the data may also be processed in the event of a dispute with the customer, and the legal basis for this processing is the legitimate interest of the owner in legal protection.

IP address and navigation logs: we will process the data based on the legitimate interest of the company and the fulfilment of legal obligations.

Queryo Business Automation service
Within the site there is a tracking script linked to the Queryo Business Automation service, which allows the collection of pseudonymised data regarding purchases made on the e-commerce site. The data collected will be used in aggregate to assess the effectiveness of the data controller's promotional campaigns.

3. PROCESSING METHODS - AND DATA RETENTION PERIOD

The Data Controller will process personal data for the time necessary to fulfil the above purposes and in any case for:

MARKETING AND PROFILED COMMUNICATIONS: We will delete the data after 5 years from the last email sent.
CONTACT US: The data will be used to respond to your requests and will then be deleted. Data obsolescence is checked every 12 months.
PURCHASE: We will keep your data no longer than 10 years after purchase.
REGISTRATION: Until you decide to unsubscribe; we will delete your account 7 years after your last access. Before that and we will send you an email to find out if you want to keep your account active.
WORK WITH US: We will delete your data 24 months after receiving your CV.
ABANDONED CART and WISHLIST: For the abandoned cart we will send you two emails in the next seven days to remind you to pick up where you left off; we will then delete the data. For wishlisted products we will send you a notification each time the product changes.
REVIEW: Reviews will remain online until they are obsolete or you ask us to delete them.

IP address and navigation logs: data will be deleted after 24 months.

Longer data retention periods may be justified by the possibility of litigation; in these cases, the data controller will process the data for as long as it is necessary for the defence in court.

4. COMMUNICATION OF DATA

The Data Controller may communicate the data for the purposes set out in Art. 2 to all parties to whom communication is obligatory by law in order to fulfil the purposes envisaged by the law. The data may be communicated to couriers who will act as data processors and to payment gateways who will process them as autonomous data controllers. The list of data processors can be found at the head office.

5. PLACE OF STORAGE AND DATA TRANSFER

The handling and storage of personal data will also take place on servers located in countries outside the EU (e.g. for sending commercial information). The data controller assures as of now that the transfer of data will take place in accordance with the GDPR through the conclusion of standard contractual clauses.

6. RIGHTS OF THE DATA SUBJECT

The user, in his or her capacity as data subject, has the rights set out in Article 15 of the Regulation, namely:


Also in accordance with Articles 15 et seq. of the GDPR, the user has the right to request at any time, access to the personal data, rectification or erasure of the same, limitation of processing in the cases provided for by Article 18 of the GDPR, obtain in a structured, commonly used and machine-readable format the data concerning him/her, in the cases provided for by Article 20 of the GDPR. At any time, the user may revoke pursuant to Article 7 of the GDPR the consent given; lodge a complaint with the competent supervisory authority pursuant to Article 77 of the GDPR if he or she considers that the processing of his or her data is contrary to the legislation in force. The user may make a request to object to the processing of his or her personal data pursuant to Article 21 of the GDPR in which he or she must give evidence of the reasons justifying the objection: the Data Controller reserves the right to assess the request, which may not be accepted in the event of the existence of compelling legitimate grounds for proceeding with the processing that prevail over the user's interests, rights and freedoms. The data subject may at any time exercise the rights referred to in the previous article by sending a registered letter or email to the addresses indicated above.