Online Customer Area Privacy Policy 2F
Code S160222G
Online Information Customer Area 2F
(pursuant to and for the purposes of Article 13 of EU Regulation No. 679/16)
The Data Controller, as set out below, pursuant to EU Regulation No. 679/16 concerning the protection of natural persons with regard to the processing of personal data (hereinafter "Regulation"), informs that it will process data for the purposes and with the methods indicated below.
"Processing" of personal data means any operation or set of operations, performed with or without the aid of automated processes and applied to personal data or sets of personal data, even if not recorded in a database, such as collection, recording, organisation, structuring, storage, processing, selection, blocking, adaptation or alteration, extraction, consultation, use, communication by transmission, dissemination or any other form of making available, comparison or interconnection, restriction, erasure or destruction.
The processing will be carried out manually (e.g., collection of paper forms) and electronically or in any case with the aid of computerised or automated tools.
According to the provisions of the Regulation, the processing will be based on the principles of fairness, lawfulness, transparency and protection of confidentiality. Pursuant to Article 13 of the Regulation, we therefore provide the following information.
1. TYPE OF PERSONAL DATA PROCESSED
The data processed by the Data Controller are:
1.1 identifying personal data: 1 ☒ name; 2 ☒ surname; 3 ☒ date of birth; 4 ☒ place of birth; 5 ☒ tax code; 6 ☒ address; 7 ☒ IBAN/Credit Card; 8 ☒ credentials; 9 ☒ telephone number; 10 ☒ email address; 11 ☐ economic data; 12 ☐ financial data; 13 ☒ images; 14 ☒ IP address.
1.2 special categories of personal data: 1 ☐ biometric; 2 ☐ genetic; 3 ☐ health; 4 ☐ sexual orientation; 5 ☐ political opinions; 6 ☐ trade union membership; 7 ☐ racial origin; 8 ☐ religious or philosophical beliefs;
1.3 judicial personal data: 1 ☐ Criminal convictions/offences
1.4 type of possible profiling: 1 ☐ professional performance; 2 ☐ economic situation; 3 ☐ health; 4 ☐ personal preferences; 5 ☐ interests; 6 ☐ reliability; 7 ☐ behaviour; 8 ☐ location/movements.
Special categories of personal data may be processed with the consent of the data subject. Otherwise, the data will be immediately destroyed. Data processing will take place in accordance with the provisions of the Regulation as specified below.
2. SOURCE OF PERSONAL DATA SUBJECT TO PROCESSING.
The personal data processed are those collected from the data subject.
3. PURPOSE OF DATA COLLECTION (Article 13, paragraph 1, letter c of the Regulation)
The data will be processed exclusively for the following purposes:
4. LEGAL BASIS FOR PROCESSING (Article 13, paragraph 1, letter c of the Regulation)
The lawfulness of the processing of personal data by the Data Controller is guaranteed pursuant to Article 6 of the Regulation as reported in the individual purposes.
5. NATURE OF DATA PROVISION - CONSEQUENCES OF REFUSAL OF CONSENT (Article 13, paragraph 2, letter e) of the Regulation)
In the event that letter b) and/or c) of paragraph 1 of Article 6 of the Regulation apply, the Data Controller is not obliged to acquire specific consent. If the data subject does not intend to provide the above personal data, the consequence would be the impossibility of establishing or continuing the contractual relationship.
Outside of the cases described above, the processing of personal data is optional and freely chosen and can only take place with explicit consent.
6. RECIPIENTS WHO MAY BECOME AWARE OF YOUR PERSONAL DATA (Article 13, paragraph 1, letter e) of the Regulation)
The categories of subjects who may become aware of your personal data are: authorized persons (employees), Data Processors (e.g., service provider collaborators, customers) of the Data Controller, DPO if appointed, any supervisory bodies.
7. TRANSFER OF PERSONAL DATA
7.1 Data will/may be transferred to Member States belonging to the EU ☒YES ☐NO. For further information, please contact the Data Controller.
7.2 Data will/may be transferred to non-EU third countries ☐YES ☒NO. For further information, please contact the Data Controller.
8. PROCESSING
The data processing is carried out for all the purposes listed above and also for research and development carried out using statistical analysis which applies only to a general view of the data without ever delving into the data of individual data subjects; this latter processing has the sole objective of improving the product or service. The processing will be carried out by appointed persons manually and/or automatically in compliance with Articles 30, 32 and 35 of the Regulation under the supervision of the DPO, if appointed. The documents are available at the Data Controller listed in "Box A".
9. RIGHTS OF THE DATA SUBJECT
Articles 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23 of the Regulation confer on the data subject the exercise of specific rights, including:
9.1. Article 12 Information, communications and transparent modalities for the exercise of the rights of the data subject;
9.2. Article 13 Information to be provided where personal data are collected from the data subject;
9.3. Article 14 Information to be provided where personal data have not been obtained from the data subject;
9.4. Article 15 Right of Access: the right to obtain from the data controller confirmation as to whether or not personal data concerning him or her are being processed;
9.5. Article 16 Right to rectification: the right to obtain from the data controller the rectification of inaccurate personal data concerning him or her;
9.6. Article 17 Right to erasure ("right to be forgotten"): the right to obtain from the data controller the erasure of personal data concerning him or her;
9.7. Article 18 Right to restriction of processing: the right to obtain from the controller restricted processing of personal data when the accuracy of the personal data is contested, when the processing is unlawful and if the processing has been objected to;
9.8. Article 19 Right to receive notification from the Data Controller in case of rectification or erasure of personal data or restriction of processing;
9.9. Article 20 Right to data portability: to obtain data portability, i.e., to receive data from a data controller, in a structured, commonly used and machine-readable format, and to transmit them to another data controller without hindrance;
9.10. Article 21 Right to object: to object to processing at any time, including in the case of processing for direct marketing purposes;
9.11. Article 22 Automated individual decision-making, including profiling;
9.12. Article 23 Restriction.
The data subject may lodge a complaint with the Garante per la protezione dei dati personali (Italian Data Protection Authority), following the procedures and indications published on the Authority's official website at www.garanteprivacy.it.
In exercising the rights referred to in Articles 12-23 of the Regulation, the data subject may grant, in writing, a delegation or power of attorney to natural persons or associations. Requests may be forwarded to the data controller or the DPO, if appointed, via the email addresses indicated in boxes A and B.
10. DURATION OF PROCESSING (Article 13, paragraph 2, letter a) of the Regulation)
The data processing will have a duration as indicated in the individual purposes, such duration is calculated from the last interaction between the Controller and the data subject. For technical reasons, the Controller will have another 120 days to verify the various archives and delete the data. However, if the data subject wishes to exercise their rights earlier, they may send a formal request to the address of the Data Controller.
11. DATA CONTROLLER (Article 13, paragraph 1, letter a) of the Regulation)
The identification details of the Data Controller are those indicated in box A
12. DATA PROTECTION OFFICER (DPO) (Article 13, paragraph 1, letter b) of the Regulation)
The identification details of the DPO (Data Protection Officer), if appointed, are indicated in box B.
Box A - Contact details of the Data Controller with
address, phone and/or email or Certified Email
EVO BEAUTY SRL
Via G. Di Vittorio 13-15
15076 Ovada (AL)
Tel 0143 889662
Email clienti@evo-beauty.it
VAT ID 01627390998
Box B - Contact details of the DPO
with address, phone and/or email or Certified Email
NOT APPOINTED
© Copyright – Giuseppe Langellotti – All rights reserved
