PRIVACY POLICY

INFORMATION FOR USERS OF THE SITE

(ART 13 REG. (UE) 2016/679 – GDPR)

 

Salviati s.r.l. with sole shareholder (hereinafter, the “Company” or “Salviati”) is aware of the importance of the protection of the personal data of visitors and users connecting to the website www.salviati.com (hereinafter, the “Site”), through which it provides its services.
Since the Site is used not only as a means of providing information about Salviati but also as a tool for collecting personal data, this information (hereinafter the “Information”) is provided pursuant to and for the purposes of art. 13 of the European Regulation 2016/679 “General Data Protection Regulation” (hereinafter, “GDPR”), and is intended to describe the management of the Site and the services provided through it, as well as to allow visitors and users who consult it to know the purposes and methods of processing of their data.
This information is provided only for the above-mentioned Site and not for other websites that may be consulted by the user through specific links on the Site, nor for any information collected through other channels.
Visitors and users are advised to read the information carefully before proceeding to browse the Site and/or provide any data concerning them.

1. Data Controller

The Data Controller is:

Salviati S.r.l. with sole shareholder – Fondamenta Lorenzo Radi 16 – 30141 Murano-Venezia (VE), C.F./P.IVA 03942240270
Tel.: +39 041 5274085 |e-mail: info@salviati.it

2. Type of data processed, purpose of processing and legal basis
Salviati may collect, exclusively for the purposes specified below, some personal data of the users.
In particular, the following may be processed:

2.1 Navigation data        
The Site collects technical information relating to the hardware and software used by visitors, independently through the use of tools for the analysis of connection files. This category of data includes, for example, IP (Internet protocol) addresses, the domain names of the computers used by users who connect to the Site, the URI (Uniform Resource Identifier) addresses of the resources requested, the type of browser used to access the Site, the time of the request to the server, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server and other parameters relating to the user’s operating system and computer environment.
This information does not provide personal data about the user and is not collected in order to be associated with identified interested parties, but it is technical/computer data collected and used in an aggregate and anonymous manner for the following purposes:

  • to allow the owner to verify the proper functioning and monitor the security of the Site;
  • to improve the quality of the service and provide statistics regarding the use of the Site;
  • to proceed to ascertain responsibility in the event of damage to the Site or any illegal activities (also constituting a crime).

Such data may be processed on the basis of a legitimate interest of Salviati (art. 6, para. 1(f) Reg. (EU) 2016/679), consisting in verifying the proper functioning of the Site or establishing liability in cases of crimes committed against the Site.

2.2 Data provided voluntarily by the user    
These are cases in which it is the user himself who releases his personal data on the Site to access certain services provided by the data controller.
This data includes:

  • identification data such as name, surname, VAT number;
  • contact details (telephone number, email address)
  • shipping address, billing address;
  • purchase orders;
  • access data and use of the private area of the Site (log);
  • other personal data provided voluntarily by the user during the registration phase on the Site and the creation of an account or in the event of a request for information sent to the Site by telephone (e.g. telephone number), email or through the contact forms.

The data collected in this way may be processed by Salviati for the following purposes:

  • to allow the user access to the Site;
  • to allow the user to register on the Site and create an account, and use any services reserved for registered users;
  • to maintain and manage the user’s account;
  • to store data and information in the user’s account;
  • to allow the user to conclude a purchase contract with Salviati through the Website and the proper performance of the obligations arising from such contract, such as, for example, the delivery, billing and payment of products and/or services purchased;
  • manage post-sales support and assistance (e.g. requests for information, complaints);
  • respond to requests for information received by phone, email or through the appropriate contact forms;

In these cases, the provision of data is mandatory and failure to provide such data will make it impossible for the user to access and/or browse the Site and/or register with the Site and create an account and use the services reserved for registered users and/or conclude a purchase contract and/or receive a response to requests made.

With regard to the creation of an account and the conclusion of a purchase contract through the Site and the proper performance of the obligations arising from such contract, the legal basis of processing is the performance of a contract or the execution of pre-contractual measures taken at the request of the data subject (art. 6, para. 1(b) GDPR);

  • to send communications to offer products or services similar to those purchased (so-called soft spam)

Limited to the electronic mail address (email address) provided by the user/customer in the context of purchasing a product through the Site, the data provided may be used to allow the direct offer by Salviati of similar products or services without the need for the user’s express consent, without prejudice to the user’s right to object at any time and without formalities to such processing, by expressing in a suitable and unambiguous way his will (art. 130, c.4, Privacy Code);

  • to send informative and promotional communications (including the newsletter)

The data provided by the user (in particular, name, surname and email address) may also be used to send informative and promotional communications (including the newsletter).
In this case, the provision of data is optional and the processing can only take place with the express consent given by the user by checking the appropriate box or entering the email address (art. 6. para.1(a) GDPR).
The user may revoke at any time the consent given and / or oppose the processing of his data for that purpose. Such revocation/opposition will not have any consequence on the user’s ability to register and/or use the Site or to make purchases on the same;

  • fulfil specific legal obligations

In any case, the personal data provided by the interested party may be used to fulfil specific obligations of an administrative and/or accounting nature connected to the purchase contract concluded through the Site, such as, by way of example, the keeping of accounting records (art. 2220 of the Civil Code) and the issue of the sales invoice.
The legal basis for this processing is the fulfilment of legal obligations to which Salviati is subject (art. 6, para. 1(c) GDPR);

  • pursue one’s own legitimate interests

The data controller may process user data to protect its rights, to prevent fraud (e.g. in case of use of credit card to make purchases on the Site).
The legal basis is the legitimate interest of Salviati (art. 6(1)(f) GDPR).

2.3 Cookies
Cookies are text files that the Site sends to the browser of the device used by the user, in order to store information to be reused during the same visit to the Site (session cookies) or later, even after a few days (persistent cookies). There are different types of cookies. Please refer to the Cookies Policy (www.salviati.com) for a detailed explanation of the type and purpose of the cookies used by this Site.

3. Processing methods
Salviati guarantees that the processing of data will take place in full compliance with the principles of confidentiality, correctness, necessity, relevance, lawfulness and transparency imposed by the General Regulation on the protection of personal data and by the applicable legislation.
Personal data will be processed by personnel authorised to do so, on paper or by computer and telematic means, with the adoption of specific security measures aimed at preventing the loss of such data, unlawful or incorrect use thereof and unauthorised access.
It is the user’s responsibility to verify the correctness of the personal data transmitted and, if necessary, to rectify, update or, in any case, modify the data during processing.

4. Data Retention
Reg. (EU) 2016/679 requires that the personal data being processed be kept for a period of time not exceeding that required to achieve the purposes.
Therefore:

  • personal data collected for purposes related to a legitimate interest of the data controller will be kept until such interest is satisfied, unless the data subject objects;
  • data collected for registration and account creation will be retained until the user closes the account;
  • the personal data processed for the conclusion of the purchase contract through the Site will be kept for the period necessary for the execution of the contract and related activities, it being understood that, once this period has expired, such data may be kept for 10 (ten) years following the conclusion of the contract for the purpose of fulfilling administrative and/or accounting and/or fiscal obligations;
  • personal data may be kept for longer periods if required by law or by order of an Authority;
  • when the processing is based on the user’s consent, the data will be kept until the consent is revoked, and in any case for a period not exceeding 5 (five) years from collection;
  • in the event that the user requests information through the Site, by email or other channels, the data will be kept for the period necessary to provide the service and in any case until the complete fulfillment of the user’s request. Once the requested service has been provided, the data will be kept for a further period not exceeding 24 (twenty-four) months.

At the end of the retention period, personal data will be deleted or made anonymous. Therefore, at the expiry of this period, the right of access, cancellation, rectification and the right to data portability can no longer be exercised by the person concerned.

5. Scope of communication and distribution
The processing operations connected to the services provided through this Site take place at the headquarters of the data controller and at the premises of the suppliers, and the data collected through the Site itself will be processed by personnel authorised to do so in the manner and for the purposes indicated in the previous sections. The data may also be transferred to suppliers based outside the EU with adequate protection guarantees.
Data may be disclosed to third parties, including:

  • IT service providers (e.g. site hosting service provider, newsletter service provider);
  • providers of marketing and/or remarketing and/or advertising services;
  • operators of social networks and external platforms (e.g. Facebook Inc., Twitter Internation Company)
  • communication agencies;
  • companies dealing with warehouse services and/or shipment of goods;
  • administrative and judicial bodies and authorities;
  • consultants and/or freelancers;
  • companies belonging to the same group as the data controller, for the performance of administration, accounting and IT and logistics support activities;
  • credit institutions and companies that offer financial services (e.g. PayPal Holdings Inc.) for the management of payments, to which credit card data may be sent;
  • insurance providers;
  • debt collection companies.

The subjects listed above operate, in some cases, in total autonomy as separate data controllers. In the event that third parties act as data processors, Salviati will be responsible for the appropriate designation pursuant to art. 28 Reg. (EU) 2016/679, ensuring that such entities process the data provided in accordance with the instructions provided and take appropriate measures to ensure the security and confidentiality of the data. The list of recipients is available at the Salviati office.
The data collected will not be distributed.

6. Protection of Minors
Salviati does not intentionally collect or process personal data of persons under the age of 14 in relation to the functions of the Website. In accordance with applicable laws (art. 8, GDPR, art. 2-quinquies Privacy Code), it is important that the parent exercising parental responsibility (or a guardian) provides consent to the collection of personal data of the child who has not reached the age of fourteen years. We therefore require that a minor’s registration on the Site must be authorised by and under the supervision of a parent (or guardian), and for this reason the email address provided must be that of the parent (or guardian). At any time, the parent exercising parental responsibility (or guardian) has the right to view and request the deletion of the child’s personal data.
Finally, please note that only people over the age of 18 can purchase products and/or services offered on the Site.

7. Rights of the interested party
At any time the interested party may exercise – without any constraint of form – the rights provided for by the General Regulation on the protection of personal data.

The user has several options for managing the personal data that will be provided. Specifically, the interested party has the right to:

  • obtain the elimination of their personal data [Art. 17 GDPR];
  • withdraw consent at any time [Art. 7 GDPR];
  • request changes, corrections or updates to personal data [Art. 16 GDPR];
  • oppose the use of personal data by the data controller [Art. 18 GDPR];
  • limit the use of personal data [Art. 21 GDPR];
  • access to personal data processed by the owner [Art. 15 GDPR]
  • receive and/or have personal data transferred in a readable format [Art. 20 GDPR];

These rights may be exercised at any time with regard to the holder by sending a communication to the e-mail address privacy@salviati.it.
The data controller shall provide the data subject with information in relation to a request to exercise the aforementioned rights without undue delay and, in any case, within one month of receipt of the request. That period may be extended by two months if necessary, taking into account the complexity and the number of requests. The data controller shall inform the data subject of this extension, and of the reasons for the delay, within one month of receipt of the request.

If the data subject considers that the processing of his/her personal data is in breach of the applicable legislation, he/she may lodge a complaint with the competent supervisory authority [Art. 77 GDPR].

8. Update
The version published on the Site is the one currently in force.
Salviati reserves the right to make changes and/or updates to this policy, which will be duly communicated through this website.