Sito Web Missoni S.p.A.
the following explains how personal data collected automatically or provided by you through the navigation or use of the website https://www.missoni.com/it (hereinafter, the “Website”) is processed.
1. DATA CONTROLLER
The Data Controller is Missoni S.p.A., in the person of its legal representative, with its registered office in Via Luigi Rossi 52, 21040, Sumirago (VA) (hereinafter “Missoni”, “Company” or “Data Controller”).
2. DATA PROTECTION OFFICER
Due to the processing activities carried out, the Company has deemed it necessary to appoint a Data Protection Officer, who can be contacted at email@example.com, Via Amedei 8, Milan or at the email address firstname.lastname@example.org.
3. TYPES OF DATA PROCESSED
In order to allow you to use our Website and its services, including the possibility to make purchases, register and create your personal account, contact us through customer service, as well as obtain a return of a purchased product or a refund (hereinafter, the “Services”), the Data Controller needs to collect and process some of your personal data.
Data voluntarily shared by the user
In order to let you to purchase our products, Missoni needs to know your first name, last name, address, telephone number, email address and payment information.
In addition, in order to let you to create an account to make your purchases easier, Missoni needs to know your gender, first name, last name, email address and date of birth.
Moreover, in order to allow you to get in touch with Missoni through the customer service, the Data Controller needs to process your name, surname, email, telephone number, order number and any other personal data contained in the message you send.
Lastly, in order to allow you to return purchased products or request refunds, Missoni needs to collect your order number, name, surname, email, address and payment details.
The optional, explicit, and voluntary sending of mail involves the collection of your name, your surname, your email address, as well as other personal data included in the requests you submit.
Browsing data The computer systems and software procedures used for the Website operations acquire, during their normal functioning, some personal data whose transmission is implicit in the use of Internet communication protocols.
This category of data includes IP addresses or domain names of computers used by users who connect to the site, URI (Uniform Resource Identifier) of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical code indicating the status of the response from the server (successful, error, etc..) and other parameters regarding the operating system and computer environment.
This data, necessary for the use of the Website, is processed for the sole purpose of obtaining statistical information on the use of the Services (most visited pages, number of visitors per hour or day, geographical areas of origin, etc.) and to check the correct functioning of the Services offered.
The navigation data does not persist for more than seven days and is deleted immediately after their aggregation, except for the possible need to ascertain crimes by the judicial authorities.
Technical Cookies Technical and session cookies are used. They are small text files containing a certain amount of information exchanged between your terminal or browser and the Website, which allow it to function correctly and to be used.
This Website uses first and third-party analytics cookies. The analytics cookies are used to collect information on the use of the Website, in aggregate form, in particular on the number of users and how they visit the Website itself, also providing anonymous statistical analysis in order to improve the use of the Website and make the content more interesting and relevant to the users’ desires. To view links to the privacy policies of third parties, disable all or some of the mentioned cookies, please refer to the following
Profiling Cookies This Website uses first and third-party profiling cookies. These cookies are not essential, but they help to personalize and improve your experience on the Website. For example, they help us to know and remember your preferences and show you relevant, personalized adverts. They also allow us to limit the number of times each ad is shown, measure the effectiveness of the ad campaign, remember your visit, and share the data we collect with third parties such as advertisers.
The deletion of these cookies, therefore, although it does not affect the use of the Website, may nevertheless result in a limitation of certain functionalities.
To view links to the privacy policies of such third parties, disable all or some of the aforementioned cookies, please refer to the following
4. PURPOSES, LEGAL BASIS AND NATURE OF THE PROVISION
|A.||Use of the Website Content and Services(iii) and ensuring network and information security(iv). This purpose includes the possibility to make purchases, register and create your personal account, contact us through customer service, as well as obtain a return of a purchased product or a refund through the Website. In addition, this purpose includes the processing of traffic personal data to the extent strictly necessary and proportionate to ensure network and information security.||(i) Performance of a contract to which you are party (ii) Compliance with legal obligations (iii) Legitimate interest||The provision of your personal data is mandatory. Failure to authorize its processing would make it impossible to use the contents and Services of the Website. Furthermore, failure to authorize its processing would make it impossible to guarantee network and information security.|
|B.||Subscription to the newsletter and receive information of commercial nature(i) and of soft spam(ii). This purpose includes the possibility to subscribe to our newsletter and receive communications and information of commercial, direct marketing and soft spam nature on our Services and offers, on discounts and on any other promotional and loyalty initiative adopted, both through traditional and fully automated contact systems, such as, through the use of your email address.||(i) Consenso espresso (ii) Legittimo interesse||The provision of your data is optional. Failure to authorize the processing of your data, while not preventing you in any way from using the Website, may not allow you to take full advantage of the benefits we offer to our community through information of advertising, commercial, direct marketing and soft spam nature.|
|C.||Receive offers, discounts and other benefits based on profiling(i). This purpose includes the possibility of receiving offers, discounts and any other benefit and promotional initiative modeled on your specific needs and propensity to purchase, including participation in loyalty programs, which provide for the purpose of their operation, the recording, identification and profiling of data relating to your purchase volumes, habits and consumption choices.||(i) Express consent||The provision of your data is optional. Failure to authorize the processing of your data, while not preventing you in any way from using the Website, may not allow us to send you communications that are personalized on your browsing habits and choices.|
5. DATA RETENTION PERIOD
The navigation data and that is acquired through the use of the Website will not be kept for more than seven days.
Regarding the processing of your personal data for direct marketing purposes, the Company has established that it will automatically delete your personal data or transform them into anonymous data in a permanent and non-reversible manner, within 7 years from the registration of the data collected.
With regard to the processing activities of your personal data for profiling purposes, in compliance with regulatory requirements and provided that they have been explicitly authorized by you, the Company has established to provide for the automatic cancellation of your personal data, or their transformation into anonymous form in a permanent and non-reversible way, 7 years after the registration of that used for profiling purposes.
Regarding the other personal data processed, not being able to predetermine accurately their retention period, the Data Controller commits as of now to inspire its processing to the principles of adequacy, accuracy, and minimization of data, as required by the GDPR, checking annually the need for its retention. This, except in the case where it is necessary to maintain such data to fulfill regulatory obligations, or to ascertain, exercise or defend a right in court.
6. CATEGORIES OF RECIPIENTS OF PERSONAL DATA
The personal data processed will not be disclosed to third parties, but may, however, be shared in relation to the purposes of processing set out above to the following subjects:
- those who can access the personal data according to legal provisions provided by the law of the European Union or the law of the Member State to which the Data Controller is subject;
- data controllers belonging to our business group or entities linked to a central body exclusively for internal administrative purposes;
- subjects that perform ancillary purposes to the activities and services referred to in paragraph 4, i.e. companies that offer advertising, marketing and communication services, companies that offer IT infrastructures and IT assistance and consultancy services as well as design and implementation of software and websites, companies that offer services useful to customize and optimize our services, companies that offer data analysis and development services (including those related to user interactions with our services), service centers, companies or consultants responsible for providing further services to the Data Controller, within the limits of the purposes for which they were collected.
7. TRASFER OF PERSONAL DATA EXTRA-EUThe Data Controller may transfer your personal data to third countries outside the European Union, for the purpose of managing Missoni database. Such transfer is always subject to an adequacy decision, under article 45 of the GDPR, or to the Standard Contractual Clauses, under article 46 of the GDPR. For more information about the rules for transferring data to countries outside the European Union, including the mechanisms on which we rely, you can visit the European Commission’s website here. To request a copy of the Standard Contractual Clauses signed by the Data Controller you can send an email to email@example.com.
8. AUTOMATED DECISION-MAKING PROCESSING
9. DATA SUBJECTS’ RIGHTS
Regarding the processing of your personal data, you, as a data subject, have the right to withdraw your consent at any time and to obtain from the Company access to your personal data. You may also request the Company to rectify or erasure your personal data. Furthermore, you have the right to obtain the restriction of the processing of personal data concerning you, as well as the right to data portability. In addition to the above, you have the right to object at any time, on grounds relating to your situation, to the processing of your personal data carried out pursuant to Article 6 para. 1, letter e) or f), including profiling on the basis of these provisions, as stated in Article 21 of the GDPR. In addition, where your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data relating to you carried out for such purposes, including profiling insofar as it is related to such direct marketing. Finally, you have the right to lodge a complaint with a supervisory authority or take legal action if you believe that the processing of your data is in breach of the GDPR. To exercise any of your rights, you may contact the Data Controller, in the person of the legal representative, by addressing a communication to the registered office in Via Luigi Rossi 52, 21040, Sumirago (VA), or by sending an email to firstname.lastname@example.org.