Code S160222G  

Online Information for Contact Request 1F 

(pursuant to and for the purposes of Art. 13 of EU Regulation No. 679/16)

The Data Controller, as listed below, pursuant to EU Regulation No. 679/16 concerning the protection of natural persons with regard to the processing of personal data (hereinafter referred to as “Regulation”), hereby informs that data will be processed for the purposes and with the methods specified below.  

"Processing" of personal data means any operation or set of operations, performed with or without the aid of automated processes and applied to personal data or sets of personal data, even if not recorded in a database, such as collection, recording, organization, structuring, storage, processing, selection, blocking, adaptation or modification, extraction, consultation, use, communication by transmission, dissemination or any other form of making available, comparison or interconnection, restriction, erasure or destruction.  

Processing will be carried out manually (e.g., collection of paper forms) and electronically or, in any case, with the aid of computerized or automated tools.  

According to the provisions of the Regulation, processing will be based on the principles of correctness, lawfulness, transparency, and protection of confidentiality. Pursuant to Art. 13 of the Regulation, we therefore provide the following information.  

  1. TYPE OF PERSONAL DATA PROCESSED  

The data subject to processing by the Data Controller are:  

1.1. identifying personal data: 1 ☒ name; 2 ☒ surname; 3 ☐ date of birth; 4 ☐ place of birth; 5 ☐ tax code; 6 ☒ address;  7 ☐ IBAN; 8 ☐ credentials; 9 ☒ telephone number; 10 ☒ email address; 11 ☐ economic data; 12 ☐ financial data; 13 ☒ images;  14 ☐ license plate; 15 ☒ IP address; 16 ☐ social account;  

1.2. special categories of personal data: 1 ☐ biometric; 2 ☐ genetic; 3 ☐ health; 4 ☐ sexual orientation; 5 ☐ political opinions; 6 ☐ trade union membership; 7 ☐ racial origin; 8 ☐ religious or philosophical beliefs;  

1.3. judicial personal data: 1 ☐ Criminal convictions/offences  

1.4. type of possible profiling: 1 ☐ professional performance; 2 ☐ economic situation; 3 ☐ health; 4 ☐ personal preferences; 5  ☐ interests; 6 ☐ reliability; 7 ☐ behavior; 8 ☐ location/movements.  

Special categories of personal data may be processed with the prior consent of the data subject. Otherwise, the data will be immediately destroyed.  Data processing will be carried out in accordance with the provisions of the Regulation as specified below.

2. SOURCE OF PERSONAL DATA SUBJECT TO PROCESSING.  

The personal data subject to processing are those collected from the data subject. 

3. PURPOSE OF DATA COLLECTION (Art. 13 para. 1 letter c Regulation) 

    Data will be processed exclusively for the following purposes:  

    3.1 technical-commercial communications (pursuant to Art. 6 letter a of EU Regulation 679/16) to respond to requests received through the contact form or email, etc., and data retention for a maximum of 1 year from the last interaction. If the request comes from an already customer who has already purchased or used a service/product free of charge, then communications will be managed based on Art. 130 paragraph 4 of Legislative Decree 196/03 (defined as soft-spam for a period equal to mandatory obligations).  

    4. LEGAL BASIS FOR PROCESSING (Art. 13 para. 1 letter c Regulation)  

      The lawfulness of personal data processing by the Data Controller is guaranteed pursuant to Art. 6 of the Regulation as reported in the individual purposes.  

      5. NATURE OF DATA PROVISION - CONSEQUENCES OF REFUSAL OF CONSENT (Art. 13 para. 2 letter e) of the Regulation)  In cases falling under letter b) and/or c) of paragraph 1 of Art. 6 of the Regulation, the Data Controller is not obliged to acquire specific consent. If the data subject does not intend to provide the aforementioned personal data, the consequence would be the impossibility of establishing or continuing the contractual relationship.  

        Outside of the cases described above, the processing of personal data is optional and freely chosen and may only take place with express consent.  

        6. RECIPIENTS WHO MAY BECOME AWARE OF YOUR PERSONAL DATA (Art. 13 para. 1 letter e) of the Regulation) The categories of subjects who may become aware of your personal data are: authorized persons (employees), Data Processors (e.g., service provider collaborators, clients) of the Data Controller, DPO if appointed, any supervisory bodies.

        7. TRANSFER OF PERSONAL DATA  

          7.1. Data will/may be transferred to EU member countries ☒YES ☐NO. For further information, please contact the Data Controller.  

          7.2. Data will/may be transferred to non-EU third countries ☐YES ☒NO. For further information, please contact the Data Controller.  

          8. PROCESSING  

            Data processing is carried out for all the purposes listed above and also for research and development through statistical analysis applied only to a general overview of the data, never delving into the data of individual data subjects; this latter processing has the sole objective of improving the product or service. Processing will be carried out by appointed personnel manually and/or automatically in compliance with Articles 30, 32, and 35 of the Regulation under the supervision of the DPO, if appointed. Documents are available from the Data Controller as indicated in "Box A".  

            9. RIGHTS OF THE DATA SUBJECT  

              Articles 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23 of the Regulation grant the data subject the exercise of specific rights, including:  9.1. Art. 12 Information, communications, and transparent modalities for the exercise of the data subject's rights;  

              9.2. Art. 13 Information to be provided where personal data are collected from the data subject;  

              9.3. Art. 14 Information to be provided where personal data have not been obtained from the data subject;  

              9.4. Art. 15 Right of Access: right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed;  

              9.5. Art. 16 Right to rectification: right to obtain from the controller the rectification of inaccurate personal data concerning him or her;  

              Code S160222G  

              9.6. Art. 17 Right to erasure (“right to be forgotten”): right to obtain from the controller the erasure of personal data concerning him or her;  

              9.7. Art. 18 Right to restriction of processing: right to obtain from the controller a limited processing of their data when the accuracy of the personal data is contested, when processing is unlawful, and if processing has been objected to;  

              9.8. Art. 19 Right to receive from the Data Controller notification in case of rectification or erasure of personal data or restriction of processing;  

              9.9. Art. 20 Right to data portability: to obtain data portability, i.e., to receive them from a data controller, in a structured, commonly used and machine-readable format, and to transmit them to another data controller without hindrance;  9.10. Art. 21 Right to object: to object to processing at any time, including in cases of processing for direct marketing purposes;  

              9.11. Art. 22 Automated individual decision-making, including profiling;  

              9.12. Art. 23 Restrictions.  

              The data subject may lodge a complaint with the Italian Data Protection Authority, following the procedures and indications published on the official website of the Authority at www.garanteprivacy.it.  

              In exercising the rights referred to in Articles 12-23 of the Regulation, the data subject may grant, in writing, a proxy or power of attorney to natural persons or associations. Requests may be forwarded to the data controller or the DPO, if appointed, via the email addresses indicated in boxes A and B.  

              10. DURATION OF PROCESSING (Art. 13 para. 2 letter a) Regulation)  

                The data processing will have a duration as reported in the individual purposes, such duration is calculated from the last interaction between the Controller and the data subject. For technical reasons, the Controller will have another 120 days to verify the various archives and delete the data. However, if the data subject wishes to exercise their rights earlier, they may send a formal request to the address of the Data Controller.  

                11. DATA CONTROLLER (Art. 13 para. 1 letter a) Regulation)  

                  The identifying details of the Data Controller are those reported in Box A  

                  12. DATA PROTECTION OFFICER (DPO) (Art. 13 para. 1 letter b) Regulation)  

                    The identifying details of the DPO (Data Protection Officer), if appointed, are reported in Box B.  

                    Box A - Contact details of the Data Controller with address, phone and/or email or Certified Email (PEC)  

                    Evo Beauty Srl Società Benefit

                    Via G. Di Vittorio 13-15  

                    15076 Ovada (AL)  

                    Tel 0143 889662  

                    E-mail clienti@evo-beauty.it 

                    VAT no. 01627390998 

                      

                    Box B - Contact details of the DPO with address, phone and/or email or Certified Email (PEC)  

                    NOT APPOINTED  

                     

                    © Copyright – Giuseppe Langellotti – All rights reserved