2. DATA CONTROLLER2.1. The Company is the Data Controller of the Data provided or collected through the Site. The Company’s contact details are set out below:Company name: F.S.A. S.R.L.Registered office address: 20123 – Milan (MI), Via Francesco Petrarca, no. 4, ItalyEmail address: email@example.comVAT: 03554300966
4. PURPOSE OF PROCESSING4.1. The Company processes User Data for the following purposes (hereinafter, the “Purpose”): 4.1.1. to enable the creation of User profiles and the sending of emails confirming the registration of the User profile on the Site;4.1.2. to enable the purchase of products through the e-commerce platform on the Site and to complete the transaction, deliver the products purchased, process any exchange and/or return requests or issue refunds;4.1.3. to create of a database of Users interested in the Site and its services;4.1.4. to process technical and commercial request form Users;4.1.5. to comply with legal obligations (including tax obligations) and to protect its prerogatives;4.1.6. to carry out direct marketing by email for products and services similar to those requested by the User (so-called “soft spam”);4.1.7. for marketing purposes, including sending newsletters and/or other promotional messages by email;4.1.8. for profiling purposes, e.g. analysing preferences in order to create content and offers.
5. LEGAL BASIS FOR DATA PROCESSING5.1. The Company shall Process Data:5.1.1. for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR;5.1.2. for compliance with a legal obligation to which the controller is subject, pursuant to Article 6(1)(c) of the GDPR;5.1.3. on the basis of the Company’s legitimate interest, pursuant to Article 6(1)(f) of the GDPR;5.1.4. with the User’s consent, pursuant to Article 6(1)(a) of the GDPR, form marketing and profiling purposes.
6. METHOD AND PLACE OF DATA PROCESSING6.1. Data will be processed by automated means for the time strictly necessary to achieve the Purposes for which they were collected.6.2. The Company has adopted technical solutions and security measures that guarantee the security of Data and prevent their alteration, loss, incorrect processing or unauthorised access.6.3. Processing related to the services of the Site may take place on servers of third party companies that provide hosting services on behalf of the Company.6.4. Where Data is transferred outside the European Union, such transfers will be made pursuant to Articles 45 and 46 of the GDPR, ensuring an adequate level of data protection.
7. DISCLOSURE OF DATA TO THIRD PARTIES7.1. The Data collected and stored in the Company’s databases will be processed by its employees and/or cooperators as persons in charge of processing such data.7.2. The User’s Data may also be processed by third parties whom the Company uses to uses to carry out activities on its behalf (e.g. analyse data, store data, send newsletters or other commercial or non-commercial communications, provide marketing assistance, carry out market analysis, deliver purchased goods, manage the credit card payment platform and other customer services).7.3. The Company provides these parties only with the Data necessary to carry out the agreed activities and they act as data processors (hereinafter, the “Data Processors”). These subjects have been selected because they are considered to have sufficient experience, capacity and reliability, as well as the ability to guarantee applicable privacy regulations. The User may request the list of Data Processors by writing to firstname.lastname@example.org. With regard to the scope of communication of the Data, the Data provided by the User or otherwise collected may be communicated to the following subjects or categories of subjects:7.4.1. Public administrations, in order to fulfil obligations imposed by law, regulation or national or EU legislation;7.4.2. parent, subsidiary or associated companies of the Company;7.4.3. other companies or natural personal contractually linked to the Company and specifically entrusted with the processing of Data on behalf of the Company.
8. NATURE OF DATA PROVISION8.1. Certain required fields on the Site (which may be marked with a star or other symbol) may be mandatory, for example, to enable valid registration on the Site, to provide the products you wish to purchase and to process any requests.8.2. By entering his/her Data on the Site, the User guarantees that the personal information provided is accurate and up-to-date. He/she also acknowledges that he/she is solely responsible for the Data provided, whether personal data, photos, comments or otherwise, and releases the Company from any liability.8.3. The provision of Data that may processed by the Company for marketing and profiling purposes is entirely optional. Failure to consent to the processing of Data for such purposes or the subsequent withdrawal of consent, will not prevent the User from browsing the site and making purchases through it.
9. WITHDRAWAL OF CONSENT9.1. You may withdraw your consent to marketing activities (including the sending of newsletters) or profiling by the Company at any time by sending an e-mail to email@example.com. Withdrawal of consent does not affect the lawfulness of processing based on consent prior to withdrawal.