This policy governs the personal data processing through the use of the website www.sufamilan.com (hereinafter the “Website”).
- Identity and contact details of the personal Data Controller.
Sustainable Fashion Arm Milan S.r.l., with registered office in Via G. De Castillia, 7, 20871, Vimercate (MB), Italy (hereinafter “SUFAM”) is the Data Controller for the data processing related to the Website, including therein, navigation data, marketing data and profiling data.
Since the controller is established in Italy, no representative has been appointed.
- Contact details of the data protection officer.
The Data Controller has not appointed a Data Protection Officer.
- Type of data processing performed on the Website.
3.1 Cookies and environmental data.
The Website uses the following cookies
Purpose: Session identifier
Purpose: Cookie consent preference
Duration: 2 months
Third Parties Cookie
Name: _gid, _ga, _gat
Purpose: Collects statistics on the use and performance of the Website
Third party that retains User information: Google
Navigation, functional, session cookies: allow the Website to work properly. The use of “session cookies” (which are not stored permanently on the device of the user and are automatically deleted when the browser is closed) is strictly limited to the transmission of identifiers of single sessions, and are used to enable the site to be used safely and efficiently.
Delete and deactivate cookies
Delete / disable cookies with Firefox:
Delete / disable cookies with Edge:
Delete / disable cookies with Chrome:
3.2. Data provided voluntarily by the interested party
The data optionally and freely provided by the interested party by sending e-mails to the e-mail addresses on the Website may be acquired for the purposes indicated from time to time.
In particular, in addition to the e-mail address necessary to reply to the sender, any other personal data contained in the relevant communication will be processed.
4.Purpose of the processing and legal basis of the processing
- a) In relation to cookies of a technical nature referred to in point 3.1 and navigation data, the processing of the personal data of the interested party is carried out in order to allow the correct use of the website; its use is necessary for navigation within the Website. In this case, the legitimate interest of the owner constitutes the legal basis of the processing;
- b) In relation to the data provided voluntarily through the "Contacts" function, the processing of personal data allows us to respond to the requests of the interested parties. The legitimate interest of the Data Controller to respond to the interested parties constitutes the legal basis of the processing.
The processing of personal data is also based on:
(a)the consent that the user may provide for the purposes referred to in Article 8, point b) and points d) and e) of the same article;
(b) the legitimate interest of the Data Controller to provide the services of the Webite and of the user in browsing the Website and /or the legitimate interest of the Data Controller to respond to any customer requests;
(c) With reference to art. 8 point (c), the legal basis of the data processing referred to therein lies in the fulfillment of the contract and in the obligation to fulfill the pre and post contractual obligations.
We remind you that, based on the principle of legitimate interest, SUFAM could contact you to offer you services and products similar to those you have previously purchased. Please also note that, according to current legislation, this type of contact does not require consent. However, you can request the interruption of the treatment of your data at any time and SUFAM will do so without delay.
- Method of expressing consent
Consent to the processing of personal data through non-technical cookies may be expressed:
By clicking on a specific box shown within a banner or by checking the flagbox.
- Source from which personal data originate
Data from public accessible sources will not be processed.
- Recipients and any categories of recipients of personal data
The recipients of the user personal data may be:
- Communication agencies that carry out commercial communication and profiling activities on behalf of the Data Controller, which hold the position of data processors;
- companies acting as data processors, that perform specific technical and organizational services connected to the Website (logistics services, IT services and marketing services);
- third parties acting as data processors in order to carry out contractual activities related to the purchase of products on the Website (by way of example, bank and finance companies for the execution of remote electronic payment services by credit / debit card);
- companies that offer information society services, including, in particular, those that offer hosting services, which hold the position of data processors.
- Categories of personal data
The personal data of the interested party will be processed. More precisely:
(a) personal data relating to navigation, which are processed both to allow the Website to work correctly, and to manage the sending of messages relating to purchases and cart, and to allow you to manage contractual relationships with third parties relating to sale, and for marketing purposes;
(b) personal data provided voluntarily by the user (such as, for example, e-mail address, personal data, password provided by filling out the registration form), or in any case legally acquired during the user's visit of the Website, or during the subsequent contact request of the user addressed to email@example.com by telephone or e-mail, to respond to user’s requests and to offer the requested services, assistance and information on products.
(c) personal data provided by the user as part of the online registration processes to the Website, sending purchase orders for products for the conclusion of e-commerce transactions and interaction with users for operational and essential activities related to the sale, as well as for any necessary pre and post sales assistance;
(d) with the user's express consent, the Data Controller may process the user's personal data for marketing purposes, or to send the user information and updates on products, sales, promotional campaigns, events and other initiatives promoted by SUFAM (using traditional tools and through telematic tools such as newsletters, e-mails, sms, smart messages);
(e) with the express consent of the user, the Data Controller may process the user's personal data also for the purpose of studying purchasing habits and choices in order to make products and initiatives more responsive to tastes and the needs of its customers.
- Transfer of data
The Data Controller could transfer personal data to a third country.
These subjects could be represented, by way of example, by:
- communication companies that carry out communication activities on behalf of the Data Controller;
- logistics companies;
- companies that offer information society services, including, in particular, those that offer hosting services;
- SUFAM and its employees and collaborators and consultants;
- Service providers.
The transfer of personal data to these subjects, if established in a third country, is carried out in the according to a decision of the European Commission, which has verified how the third country, the territory or one or more specific territories within the third country, ensure an adequate level of protection of your rights. In any case, the Data Controller - if it deems appropriate in any case - reserves the right to conclude specific separate agreements that oblige these subjects to adopt adequate security measures, including organizational ones, aimed at offering appropriate guarantees regarding their rights. Google Inc., in particular, is contractually bound to ensure appropriate protection of the rights of the data of the interested party. To obtain a copy of such data or the place where they were made available, simply send the relevant request to the following address: firstname.lastname@example.org.
- Retention period of personal data
The personal data processed and stored in order to allow correct use of the Website are processed and stored for a period not exceeding 12 months starting from the date of their collection.
In relation to the data provided on a voluntarily basis via e-mail by the user or through the "Contacts" function, these data are processed and stored until the relevant cancellation and / or revocation of consent is requested by the interested party.
The Data Controller reserves the right, in any case, to request the interested party to renew his consent to the processing and / or to verify the consents already expressed.
- Optional nature of consent and consequences of non-consent
In relation to personal data processed through technical cookies in order to allow correct use of the Website, the communication of personal data is not a contractual obligation, but it is based on the legitimate interest of the owner, since without this treatment it could not be possible to make fully functional the Website.
In relation to the data provided on a voluntarily basis, by e-mail or through the "Contacts" function, failure to communicate them will make it impossible to respond to requests from the interested party.
- Rights of the interested party
12.1 Right to object
The interested party has the right to object, at any time for reasons connected to his/her particular situation, to the processing of personal data concerning him/her, pursuant to article 6, paragraph 1, letters e) or f) of the GDPR, including the profiling on the basis of these provisions. The Data Controller refrains from further processing personal data unless he/she demonstrates the existence of compelling legitimate reasons to proceed with the processing that prevail over the interests, rights and freedoms of the interested party or for the assessment, exercise or defense. of a right in court.
12.2 Other rights
The Data Controller informs the interested party of the existence of the following rights:
(a)right of access of the interested party: the interested party has the right to obtain from the Data Controller confirmation that the processing of personal data concerning him/her is in progress and in this case, to obtain access to personal data and specific information, in accordance with art. 15 of the GDPR;
(b)right of rectification: the interested party has the right to obtain from the Data Controller the correction of inaccurate personal data concerning him/her without undue delay. Taking into account the purposes of the processing, the interested party has the right to obtain the integration of incomplete personal data, also by providing an additional declaration, in accordance with art. 16 of the GDPR;
(c)right to delete data, including the right to withdraw consent: the data subject has the right to obtain from the Data Controller the cancellation of personal data concerning him/her without undue delay and the Data Controller is obliged to cancel the data without undue delay personal data, or to withdraw your consent, if the reasons defined by art. 17 of the GDPR. As regards the right of revocation, the interested party also has the right to revoke the consent at any time without prejudice to the lawfulness of the processing based on the consent given before the revocation;
(d) right to limitation of treatment: the interested party has the right to obtain from the Data Controller the limitation of treatment when the cases defined by art. 18 of the GDPR;
(e)right to data portability: the interested party has the right to receive in a structured format, commonly used and readable by an automatic device, the personal data concerning him provided to the Data Controller and has the right to transmit such data to another holder without impediments by the Owner in the cases and under the conditions specified by art. 20 of the GDPR.
- Exercise of rights
The requests for exercising the rights indicated in this information, including, in particular, the right to cancellation and the right to revoke the consent given must be addressed directly to the Owner at the email address email@example.com. Alternatively, you can exercise your rights by sending the relevant communication by certified email to the following address: firstname.lastname@example.org or registered e-mail to the following address: Via G. De Castillia, 7, 20871, Vimercate (MB), Italy.
- Accessibility of the information
The information is accessible from the owner. If expressly requested by the interested party, the information can also be provided orally, provided that the identity of the interested party is proven, by means of a telephone request to be sent to the following address: email@example.com.
Last update: September 2020