PRIVACY Policy

Information on the processing of personal data pursuant to Articles 13 and 14 of the GDPR (EU Regulation 679/2016)

1. General provisions

1.1. This privacy notice, provided pursuant to Articles 13 and 14 of the GDPR, describes how the websites “www.ciessepiumini.com and www.ciessepiuminiproject.com” are managed, with specific reference to the processing of the personal data of visitors and customers who use them (the “Users” or, in the singular, the “User”).

1.2. This notice applies only to the use of the websites “www.ciessepiumini.com and www.ciessepiuminiproject.com” and not to any other websites that the User may access through links.

1.3. By visiting the websites “www.ciessepiumini.com and www.ciessepiuminiproject.com” (the “Website”), the User accepts all the terms and conditions set out below. If the User does not accept these terms, they are requested not to access or use the content and services offered through our Website.

1.4. The Website reserves the right to amend, add or remove parts of this Privacy Policy, informing data subjects by publishing the changes on the Website. Each User is required to check this page periodically to verify whether any changes have been made since their last visit. In any event, use of the Website constitutes acceptance of any changes made to this notice.

2. Data Controller

The Data Controller and operator of the Website is

Sport Fashion Service Srl
Via Matteo Bandello 8 – 20123 Milan (MI)
VAT number and Tax Code: IT09238561006
email: amministrazione@ciessepiumini.com

3. Types of data processed

3.1. Browsing Data

The IT systems and software procedures used to operate this Website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected in order to be associated with identified data subjects, but by its very nature it could, through processing and association with data held by third parties, make it possible to identify Users. This category of data includes in particular:

the IP addresses or domain names of the computers used by Users who connect to the Website;
the URI (Uniform Resource Identifier) addresses of the requested resources;
the time of the request;
the method used to submit the request to the server;
the size of the file received in response;
the numerical code indicating the status of the response provided by the server (successful, error, etc.);
any parameter relating to the User’s operating system and IT environment.

3.2. Data voluntarily provided by the User
While browsing the Website, the User may also voluntarily provide certain personal data (collectively, the “Personal Data”) in order to access the services offered, such as: the Newsletter service; the possibility of registering on the Website by creating a personal account; and the online purchase of products sold by the Data Controller. By way of example and without limitation, such data may include:
– the User’s first name, surname, email address, postal address and telephone number;
– data required to access the account, such as Username, Email Address and Password in a retrievable format.

3.3. Data shared on social networks
The Website owner may acquire personal data contained in the User’s Facebook profile where such data has been made accessible to third parties by the User. By way of example and without limitation, this data may include: first name; surname; email address; profile photo; and friends list. This data is acquired by the Website owner whenever the User interacts with the Data Controller’s Facebook profile (for example, whenever the User posts on the social network profile or downloads content from the profile managed by the Data Controller). To verify whether it is possible to opt out of sharing data contained in the User’s Facebook profile, the User is advised to visit the privacy settings section of the social network.

3.4. Data collected through cookies
As explained in greater detail in the “Cookie Policy”, the Website uses “cookies”, meaning short text files (letters and/or numbers) that allow the web server to store information on the client device (the browser) for reuse during the same visit to the Website (session cookies) or subsequently, during future visits to the same Website (persistent cookies). The information collected through these tools concerns, in particular, the links clicked by the User, the pages visited, the duration of the visit and statistical information relating to the User’s intentions. The Website uses both technical and/or functional cookies, which are necessary to ensure navigation and use of the Website by the User, and third-party profiling cookies. The User has the right to disable technical cookies, as further explained in the “Cookie Policy”, and to withhold consent (and subsequently withdraw at any time any consent initially given) to the use of third-party profiling cookies.

4. Purposes of personal data processing

4.1. The User’s Browsing Data acquired by the Data Controller will be processed exclusively for the purposes listed below.

4.1.1. Proper operation and management of the Website
Browsing Data will be acquired automatically by the IT system because it is necessary for the Website owner to enable the User to browse and use the Website. The personal data acquired in this way may also be used by the Data Controller to establish liability in the event of alleged cybercrimes committed against the Data Controller.

4.1.2. Marketing purposes
Subject to obtaining the User’s consent, Browsing Data is also used for marketing activities and the sending of advertising messages.

4.2. The User’s Personal Data acquired by the Data Controller following the creation of a personal account through the registration process and subscription to the Website mailing list will be processed for the purposes listed below.

4.2.1. Newsletter services and creation of an account on the Website.
Personal Data will be used to allow the User to receive the free newsletter update service and to enable the Data Controller to manage any related issues (such as password recovery or problems receiving emails).

4.2.2. Performance of contractual or pre-contractual measures
The User’s Personal Data is used by the Data Controller to enter into and perform distance contracts for the purchase of goods or services marketed by the Data Controller, or to take any pre-contractual measures requested by the User. By way of example and without limitation, processing in this context is intended to enable contracts to be concluded, payments to be made, order status to be checked, orders to be fulfilled, questions and complaints concerning products to be answered and, more generally, all obligations arising from the distance contract or the law to be fulfilled.

4.2.3. Marketing purposes
Subject to obtaining consent, the Data Controller will process the User’s Personal Data for advertising, information and promotional activities concerning new products and/or services marketed by the Data Controller. For the direct sale of its own products or services, the Data Controller may use the email address supplied by the User in connection with the sale of a product or service without obtaining additional consent, provided that the services are similar to those previously purchased. The User may in any event refuse such use initially or when receiving subsequent communications. The User may withdraw consent to the processing of data for marketing purposes and/or object to such processing at any time by sending an email to info@dot4all.it

4.2.4. Defence of legal claims
The User’s Personal Data may be processed by the Data Controller in order to defend itself in the event of legal proceedings and/or during the preparatory stages preceding such proceedings.

5. Further details concerning the services used by the Data Controller in relation to the purposes of data collection

Further information is provided below regarding the services made available by the Data Controller to the User in relation to the purposes for which Personal Data and Browsing Data are processed.

5.1. Facebook permissions requested by the Website
The Website may request certain Facebook permissions that allow it to perform actions using the User’s Facebook account and collect information from it, including Personal Data. The Personal Data collected by the Website is limited to data that the User has made explicitly public through their Facebook privacy settings (such as, for example, ID, name, profile image and, in some cases, Facebook “Friends”).
These services allow access to the User’s primary email address and the “About Me” section of the Facebook profile.
For further information about these services, the User is invited to consult the Facebook permissions documentation and Facebook’s Privacy Policy.

5.2. Access to accounts on third-party services (Facebook account access)
The Website uses certain services that make it possible to acquire Personal Data from Users’ accounts on third-party services and perform actions using those accounts. These services are not activated automatically and require the User’s express authorisation. The “Facebook account access” service allows the Website to connect to the User’s account on the Facebook social network.
To use this service, the Data Controller has requested the following permissions from Facebook: Email and “About Me”.

5.3. Newsletter activities
By registering for the mailing list or newsletter, the User’s email address will automatically be added to a contact list to which email messages containing information, including commercial and promotional information relating to the Website, may be sent. The User’s email address may also be added to this list as a result of registering on this Website or after making a purchase.

5.4. Payment management activities
The Website uses payment management services that allow it to process payments by credit card, bank transfer or other means. The data used for payment is collected directly by the provider of the requested payment service and is not processed in any way by the Website. Some of these services may also allow scheduled messages to be sent to the User, such as emails containing invoices or payment notifications.
The services used for this purpose are listed below, with reference to their respective privacy notices.

PayPal (PayPal)
PayPal is a payment service provided by PayPal Inc. that allows the User to make online payments using their credentials. The User may consult the relevant Privacy Policy, which specifies the types of data processed.

5.5. Email address management
The services listed below allow the Website to manage a database of email contacts, telephone contacts or other contact details used to communicate with the User and voluntarily provided by the User.
These services may also collect data relating to the date and time at which messages are viewed by the User, the User’s interactions with those services and information about clicks on links included in messages.

Mailchimp (Mailchimp)
Mailchimp is an email address management and email delivery service provided by Mailchimp Inc.
This service processes personal data, more specifically email addresses, in the United States. Please refer to the relevant Privacy Policy.

5.6. Registration and authentication
By registering or authenticating, the User allows the Website to identify them and grant them access to dedicated services. The services indicated may be provided with the assistance of third parties, as described below.
Where this occurs, the Website may access certain Data stored by the third-party service used for registration or identification. – Facebook Authentication (Facebook, Inc.)
Facebook Authentication is a registration and authentication service provided by Facebook Inc. and connected to the Facebook social network. Data will be processed in the United States. Users are advised to consult Facebook’s Privacy Policy at the relevant link.

Google OAuth (Google Inc.)
Google OAuth is a registration and authentication service provided by Google Inc. and connected to the Google network. Data will be processed in the United States. Users are advised to consult the relevant privacy notice concerning the types of data processed: Privacy Policy.

5.7. Telephone communications
Users who provide their telephone number when purchasing a service may be contacted by telephone by one of the Data Controller’s business partners for support purposes connected with this Website and to respond to any support requests made by Users.
Users who do not wish to be contacted are requested not to provide their telephone number. In that case, however, the Data Controller may be unable to provide all or part of the requested Service.
The User retains the right to object at any time to marketing activities carried out by telephone.

6. Legal basis for processing

6.1. Browsing Data and Personal Data are lawfully processed by the Data Controller in compliance with the GDPR and any other applicable legal provisions, on the legal bases provided for by Article 6 of the GDPR, as set out in detail below.

6.1.1. Browsing Data
Without prejudice to the User’s right to disable cookies as provided for in the current Cookie Policy, Browsing Data is processed on the basis of the Data Controller’s legitimate interest (Article 6(1)(f) GDPR), as it is necessary to enable the operation of the Website and its full use by the User.

6.1.2. Personal Data processed for marketing purposes
The User’s Personal Data and Browsing Data used for marketing purposes are processed on the basis of the User’s consent pursuant to Article 6(1)(a) GDPR, until the User exercises the right to withdraw consent or object to the processing. The User’s Personal Data provided when purchasing a service from the Data Controller may be used for marketing purposes concerning products or services similar to those purchased, on the basis of the Data Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR, until the User withdraws the initial consent and/or exercises the right to object to processing for marketing purposes.

6.1.3. Personal Data acquired for subscription to the newsletter service
The User’s Personal Data provided when subscribing to the Website newsletter service is processed on the basis of the User’s consent pursuant to Article 6(1)(a) GDPR, until the User exercises the right to withdraw consent or object to the processing. Such Personal Data will also be used by the Website on the basis of the Data Controller’s legitimate interest in providing the service requested by the User pursuant to Article 6(1)(f) GDPR.

6.1.4. Personal Data acquired for the performance of contractual or pre-contractual measures
Personal Data acquired by the Data Controller in order to perform a contract to which the User is a party, or to take pre-contractual measures at the User’s request, and used to manage online purchases, is processed pursuant to Article 6(1)(b) GDPR and on the basis of the Data Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR, arising from the possible need to protect a right in legal proceedings.

7. Processing methods

Personal Data collected through the Website is processed using automated tools.

8. Transfer of data to countries outside the EU

Personal Data will not be transferred outside the territory of the European Union.

9. Data retention period

9.1. Browsing Data will be deleted immediately and/or retained for a maximum period of seven days from the date on which it is acquired.

9.2. Personal Data collected for the performance of contracts to which the User is a party will be retained until the expiry of the period during which proof of the commercial transaction with the User must be kept by law for accounting, administrative or tax purposes and, in any event, until the expiry of the applicable limitation periods within which claims arising from contractual or non-contractual liability may be brought, where it is necessary to demonstrate the proper performance of the contract and the related legal obligations by the Data Controller.

9.3. Personal Data collected for the purpose of sending newsletters will be retained for the duration of the service.

9.4. Personal Data collected exclusively for marketing purposes will be retained for a period of 24 months from the date on which it is acquired.

9.5. Personal Data acquired in connection with the conclusion of a distance contract with the User will be used for marketing purposes for a maximum period of 24 months after the User ceases to be able to use the purchased service.

10. Security

This Website and the links to other websites contained within it have been reviewed by the Data Controller and do not contain harmful content. In any event, the Data Controller is responsible only for the content of its own websites and cannot be held liable for the content of third-party websites to which an authorised link is provided.

The Data Controller will process the Browsing Data and Personal Data acquired by implementing the security measures necessary to prevent unauthorised access, disclosure, alteration or destruction.

11. Requirement to provide Personal Data

11.1. Browsing Data is acquired automatically by the Website. The provision by the User of Personal Data requested on the various occasions on which data is collected is always optional. However, failure to provide Personal Data will make it impossible for the Data Controller to provide the newsletter service or to enter into and perform contracts with the User.

11.2. Certain data may be required as mandatory at the time of purchase, as specifically indicated by an asterisk, because it is necessary for the Data Controller to provide the services purchased by the User through the Website.

12. Disclosure of personal data to third parties

12.1. The Data Controller discloses Users’ personal data to third parties only where this is necessary and functional to achieving the purpose of the data processing carried out in connection with the service requested by the User.

12.2. In general, data collected through the individual services and for the purposes indicated in this notice is disclosed exclusively to: (i) persons whose right to access the data is granted by law or regulations (public security authorities and police forces); (ii) data processing and IT service companies (e.g. web hosting, data entry, communication agencies, and management and maintenance of IT infrastructure and services); (iii) shipping companies; (iv) administrative service providers; (v) system administrators; (vi) lawyers; (vii) accountants; and (viii) business partners (e.g. advertising agencies). Where considered necessary, some of these parties will be appointed as “Data Processors” pursuant to Article 28 GDPR.
At the User’s request, the Data Controller will provide the periodically updated list of Data Processors.

12.3. Personal data provided by the User may be accessed and processed by specifically authorised personnel of the Data Controller (for example, administrative staff), to the extent necessary for the performance of their duties and solely by carrying out the operations required for that purpose.

12.4. Through the use of third-party cookies, the Data Controller may transmit data to the companies that own the websites to which those cookies relate, as described in the Cookie Policy.

13. Rights of the data subject

In accordance with Chapter III, Section I of the GDPR, the User may exercise the rights set out therein and, in particular:

Right to withdraw consent – Withdraw consent to the Processing of Personal Data at any time (Article 7 GDPR),
Right of access – Obtain confirmation as to whether or not Personal Data concerning the User is being processed and, where that is the case, receive information concerning, in particular: the purposes of the processing, the categories of personal data processed, the retention period and the recipients to whom the data may be disclosed (Article 15 GDPR),
Right to rectification – Obtain, without undue delay, the rectification of inaccurate Personal Data concerning the User and the completion of incomplete personal data (Article 16 GDPR),
Right to erasure – Obtain, without undue delay, the erasure of Personal Data concerning the User in the cases provided for by the GDPR (Article 17 GDPR),
Right to restriction – Obtain from our Company the restriction of processing in the cases provided for by the GDPR (Article 18 GDPR),
Right to data portability – Receive the Personal Data concerning the User that has been provided to our Company in a structured, commonly used and machine-readable format, and have that data transmitted to another controller without hindrance, in the cases provided for by the GDPR (Article 20 GDPR),
Right to lodge a complaint with the supervisory authority – Lodge a complaint with the Italian Data Protection Authority, Piazza di Montecitorio No. 121, 00186 Rome (RM).

The User may exercise these rights simply by sending a request by email to the certified email address sportfashionservice@pec.it of Sport Fashion Service S.r.l., as the Data Controller identified above.

14. Right to object

The User has the right to object to the processing of personal data concerning them, unless the Data Controller has legitimate grounds to continue the processing (Article 21 GDPR).
In particular, the User has the right to object to the processing of personal data for direct marketing purposes, in accordance with the procedures described in the previous section.

15. Place of data processing

Personal data processing connected with the web services of this Website takes place at the operating offices of the Data Controller and is carried out by technical personnel specifically authorised to process the data. Where necessary, the data may be processed by personnel of the company responsible for maintaining the technological components of the Website at that company’s premises.

16. Automated processes and profiling

The User has been informed of the presence of third-party profiling cookies, in relation to which the User may give consent, withdraw it at any time and/or disable those cookies, as specified in the Website’s Cookie Policy.
Last updated: 08/10/2020

PRIVACY Policy

Information on the processing of personal data pursuant to Articles 13 and 14 of the GDPR (EU Regulation 679/2016)

1. General provisions

1.1. This privacy notice, provided pursuant to Articles 13 and 14 of the GDPR, describes how the websites “www.ciessepiumini.com and www.ciessepiuminiproject.com” are managed, with specific reference to the processing of the personal data of visitors and customers who use them (the “Users” or, in the singular, the “User”).

1.2. This notice applies only to the use of the websites “www.ciessepiumini.com and www.ciessepiuminiproject.com” and not to any other websites that the User may access through links.

1.3. By visiting the websites “www.ciessepiumini.com and www.ciessepiuminiproject.com” (the “Website”), the User accepts all the terms and conditions set out below. If the User does not accept these terms, they are requested not to access or use the content and services offered through our Website.

1.4. The Website reserves the right to amend, add or remove parts of this Privacy Policy, informing data subjects by publishing the changes on the Website. Each User is required to check this page periodically to verify whether any changes have been made since their last visit. In any event, use of the Website constitutes acceptance of any changes made to this notice.

2. Data Controller

The Data Controller and operator of the Website is

Sport Fashion Service Srl
Via Matteo Bandello 8 – 20123 Milan (MI)
VAT number and Tax Code: IT09238561006
email: amministrazione@ciessepiumini.com

3. Types of data processed

3.1. Browsing Data

The IT systems and software procedures used to operate this Website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected in order to be associated with identified data subjects, but by its very nature it could, through processing and association with data held by third parties, make it possible to identify Users. This category of data includes in particular:

the IP addresses or domain names of the computers used by Users who connect to the Website;
the URI (Uniform Resource Identifier) addresses of the requested resources;
the time of the request;
the method used to submit the request to the server;
the size of the file received in response;
the numerical code indicating the status of the response provided by the server (successful, error, etc.);
any parameter relating to the User’s operating system and IT environment.

3.2. Data voluntarily provided by the User
While browsing the Website, the User may also voluntarily provide certain personal data (collectively, the “Personal Data”) in order to access the services offered, such as: the Newsletter service; the possibility of registering on the Website by creating a personal account; and the online purchase of products sold by the Data Controller. By way of example and without limitation, such data may include:
- the User’s first name, surname, email address, postal address and telephone number;
- data required to access the account, such as Username, Email Address and Password in a retrievable format.

3.3. Data shared on social networks
The Website owner may acquire personal data contained in the User’s Facebook profile where such data has been made accessible to third parties by the User. By way of example and without limitation, this data may include: first name; surname; email address; profile photo; and friends list. This data is acquired by the Website owner whenever the User interacts with the Data Controller’s Facebook profile (for example, whenever the User posts on the social network profile or downloads content from the profile managed by the Data Controller). To verify whether it is possible to opt out of sharing data contained in the User’s Facebook profile, the User is advised to visit the privacy settings section of the social network.

3.4. Data collected through cookies
As explained in greater detail in the “Cookie Policy”, the Website uses “cookies”, meaning short text files (letters and/or numbers) that allow the web server to store information on the client device (the browser) for reuse during the same visit to the Website (session cookies) or subsequently, during future visits to the same Website (persistent cookies). The information collected through these tools concerns, in particular, the links clicked by the User, the pages visited, the duration of the visit and statistical information relating to the User’s intentions. The Website uses both technical and/or functional cookies, which are necessary to ensure navigation and use of the Website by the User, and third-party profiling cookies. The User has the right to disable technical cookies, as further explained in the “Cookie Policy”, and to withhold consent (and subsequently withdraw at any time any consent initially given) to the use of third-party profiling cookies.

4. Purposes of personal data processing

4.1. The User’s Browsing Data acquired by the Data Controller will be processed exclusively for the purposes listed below.

4.1.1. Proper operation and management of the Website
Browsing Data will be acquired automatically by the IT system because it is necessary for the Website owner to enable the User to browse and use the Website. The personal data acquired in this way may also be used by the Data Controller to establish liability in the event of alleged cybercrimes committed against the Data Controller.

4.1.2. Marketing purposes
Subject to obtaining the User’s consent, Browsing Data is also used for marketing activities and the sending of advertising messages.

4.2. The User’s Personal Data acquired by the Data Controller following the creation of a personal account through the registration process and subscription to the Website mailing list will be processed for the purposes listed below.

4.2.1. Newsletter services and creation of an account on the Website.
Personal Data will be used to allow the User to receive the free newsletter update service and to enable the Data Controller to manage any related issues (such as password recovery or problems receiving emails).

4.2.2. Performance of contractual or pre-contractual measures
The User’s Personal Data is used by the Data Controller to enter into and perform distance contracts for the purchase of goods or services marketed by the Data Controller, or to take any pre-contractual measures requested by the User. By way of example and without limitation, processing in this context is intended to enable contracts to be concluded, payments to be made, order status to be checked, orders to be fulfilled, questions and complaints concerning products to be answered and, more generally, all obligations arising from the distance contract or the law to be fulfilled.

4.2.3. Marketing purposes
Subject to obtaining consent, the Data Controller will process the User’s Personal Data for advertising, information and promotional activities concerning new products and/or services marketed by the Data Controller. For the direct sale of its own products or services, the Data Controller may use the email address supplied by the User in connection with the sale of a product or service without obtaining additional consent, provided that the services are similar to those previously purchased. The User may in any event refuse such use initially or when receiving subsequent communications. The User may withdraw consent to the processing of data for marketing purposes and/or object to such processing at any time by sending an email to info@dot4all.it

4.2.4. Defence of legal claims
The User’s Personal Data may be processed by the Data Controller in order to defend itself in the event of legal proceedings and/or during the preparatory stages preceding such proceedings.

5. Further details concerning the services used by the Data Controller in relation to the purposes of data collection

Further information is provided below regarding the services made available by the Data Controller to the User in relation to the purposes for which Personal Data and Browsing Data are processed.

5.1. Facebook permissions requested by the Website
The Website may request certain Facebook permissions that allow it to perform actions using the User’s Facebook account and collect information from it, including Personal Data. The Personal Data collected by the Website is limited to data that the User has made explicitly public through their Facebook privacy settings (such as, for example, ID, name, profile image and, in some cases, Facebook “Friends”).
These services allow access to the User’s primary email address and the “About Me” section of the Facebook profile.
For further information about these services, the User is invited to consult the Facebook permissions documentation and Facebook’s Privacy Policy.

5.2. Access to accounts on third-party services (Facebook account access)
The Website uses certain services that make it possible to acquire Personal Data from Users’ accounts on third-party services and perform actions using those accounts. These services are not activated automatically and require the User’s express authorisation. The “Facebook account access” service allows the Website to connect to the User’s account on the Facebook social network.
To use this service, the Data Controller has requested the following permissions from Facebook: Email and “About Me”.

5.3. Newsletter activities
By registering for the mailing list or newsletter, the User’s email address will automatically be added to a contact list to which email messages containing information, including commercial and promotional information relating to the Website, may be sent. The User’s email address may also be added to this list as a result of registering on this Website or after making a purchase.

5.4. Payment management activities
The Website uses payment management services that allow it to process payments by credit card, bank transfer or other means. The data used for payment is collected directly by the provider of the requested payment service and is not processed in any way by the Website. Some of these services may also allow scheduled messages to be sent to the User, such as emails containing invoices or payment notifications.
The services used for this purpose are listed below, with reference to their respective privacy notices.

PayPal (PayPal)
PayPal is a payment service provided by PayPal Inc. that allows the User to make online payments using their credentials. The User may consult the relevant Privacy Policy, which specifies the types of data processed.

5.5. Email address management
The services listed below allow the Website to manage a database of email contacts, telephone contacts or other contact details used to communicate with the User and voluntarily provided by the User.
These services may also collect data relating to the date and time at which messages are viewed by the User, the User’s interactions with those services and information about clicks on links included in messages.

Mailchimp (Mailchimp)
Mailchimp is an email address management and email delivery service provided by Mailchimp Inc.
This service processes personal data, more specifically email addresses, in the United States. Please refer to the relevant Privacy Policy.

5.6. Registration and authentication
By registering or authenticating, the User allows the Website to identify them and grant them access to dedicated services. The services indicated may be provided with the assistance of third parties, as described below.
Where this occurs, the Website may access certain Data stored by the third-party service used for registration or identification. – Facebook Authentication (Facebook, Inc.)
Facebook Authentication is a registration and authentication service provided by Facebook Inc. and connected to the Facebook social network. Data will be processed in the United States. Users are advised to consult Facebook’s Privacy Policy at the relevant link.

Google OAuth (Google Inc.)
Google OAuth is a registration and authentication service provided by Google Inc. and connected to the Google network. Data will be processed in the United States. Users are advised to consult the relevant privacy notice concerning the types of data processed: Privacy Policy.

5.7. Telephone communications
Users who provide their telephone number when purchasing a service may be contacted by telephone by one of the Data Controller’s business partners for support purposes connected with this Website and to respond to any support requests made by Users.
Users who do not wish to be contacted are requested not to provide their telephone number. In that case, however, the Data Controller may be unable to provide all or part of the requested Service.
The User retains the right to object at any time to marketing activities carried out by telephone.

6. Legal basis for processing

6.1. Browsing Data and Personal Data are lawfully processed by the Data Controller in compliance with the GDPR and any other applicable legal provisions, on the legal bases provided for by Article 6 of the GDPR, as set out in detail below.

6.1.1. Browsing Data
Without prejudice to the User’s right to disable cookies as provided for in the current Cookie Policy, Browsing Data is processed on the basis of the Data Controller’s legitimate interest (Article 6(1)(f) GDPR), as it is necessary to enable the operation of the Website and its full use by the User.

6.1.2. Personal Data processed for marketing purposes
The User’s Personal Data and Browsing Data used for marketing purposes are processed on the basis of the User’s consent pursuant to Article 6(1)(a) GDPR, until the User exercises the right to withdraw consent or object to the processing. The User’s Personal Data provided when purchasing a service from the Data Controller may be used for marketing purposes concerning products or services similar to those purchased, on the basis of the Data Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR, until the User withdraws the initial consent and/or exercises the right to object to processing for marketing purposes.

6.1.3. Personal Data acquired for subscription to the newsletter service
The User’s Personal Data provided when subscribing to the Website newsletter service is processed on the basis of the User’s consent pursuant to Article 6(1)(a) GDPR, until the User exercises the right to withdraw consent or object to the processing. Such Personal Data will also be used by the Website on the basis of the Data Controller’s legitimate interest in providing the service requested by the User pursuant to Article 6(1)(f) GDPR.

6.1.4. Personal Data acquired for the performance of contractual or pre-contractual measures
Personal Data acquired by the Data Controller in order to perform a contract to which the User is a party, or to take pre-contractual measures at the User’s request, and used to manage online purchases, is processed pursuant to Article 6(1)(b) GDPR and on the basis of the Data Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR, arising from the possible need to protect a right in legal proceedings.

7. Processing methods

Personal Data collected through the Website is processed using automated tools.

8. Transfer of data to countries outside the EU

Personal Data will not be transferred outside the territory of the European Union.

9. Data retention period

9.1. Browsing Data will be deleted immediately and/or retained for a maximum period of seven days from the date on which it is acquired.

9.2. Personal Data collected for the performance of contracts to which the User is a party will be retained until the expiry of the period during which proof of the commercial transaction with the User must be kept by law for accounting, administrative or tax purposes and, in any event, until the expiry of the applicable limitation periods within which claims arising from contractual or non-contractual liability may be brought, where it is necessary to demonstrate the proper performance of the contract and the related legal obligations by the Data Controller.

9.3. Personal Data collected for the purpose of sending newsletters will be retained for the duration of the service.

9.4. Personal Data collected exclusively for marketing purposes will be retained for a period of 24 months from the date on which it is acquired.

9.5. Personal Data acquired in connection with the conclusion of a distance contract with the User will be used for marketing purposes for a maximum period of 24 months after the User ceases to be able to use the purchased service.

10. Security

This Website and the links to other websites contained within it have been reviewed by the Data Controller and do not contain harmful content. In any event, the Data Controller is responsible only for the content of its own websites and cannot be held liable for the content of third-party websites to which an authorised link is provided.

The Data Controller will process the Browsing Data and Personal Data acquired by implementing the security measures necessary to prevent unauthorised access, disclosure, alteration or destruction.

11. Requirement to provide Personal Data

11.1. Browsing Data is acquired automatically by the Website. The provision by the User of Personal Data requested on the various occasions on which data is collected is always optional. However, failure to provide Personal Data will make it impossible for the Data Controller to provide the newsletter service or to enter into and perform contracts with the User.

11.2. Certain data may be required as mandatory at the time of purchase, as specifically indicated by an asterisk, because it is necessary for the Data Controller to provide the services purchased by the User through the Website.

12. Disclosure of personal data to third parties

12.1. The Data Controller discloses Users’ personal data to third parties only where this is necessary and functional to achieving the purpose of the data processing carried out in connection with the service requested by the User.

12.2. In general, data collected through the individual services and for the purposes indicated in this notice is disclosed exclusively to: (i) persons whose right to access the data is granted by law or regulations (public security authorities and police forces); (ii) data processing and IT service companies (e.g. web hosting, data entry, communication agencies, and management and maintenance of IT infrastructure and services); (iii) shipping companies; (iv) administrative service providers; (v) system administrators; (vi) lawyers; (vii) accountants; and (viii) business partners (e.g. advertising agencies). Where considered necessary, some of these parties will be appointed as “Data Processors” pursuant to Article 28 GDPR.
At the User’s request, the Data Controller will provide the periodically updated list of Data Processors.

12.3. Personal data provided by the User may be accessed and processed by specifically authorised personnel of the Data Controller (for example, administrative staff), to the extent necessary for the performance of their duties and solely by carrying out the operations required for that purpose.

12.4. Through the use of third-party cookies, the Data Controller may transmit data to the companies that own the websites to which those cookies relate, as described in the Cookie Policy.

13. Rights of the data subject

In accordance with Chapter III, Section I of the GDPR, the User may exercise the rights set out therein and, in particular:

Right to withdraw consent – Withdraw consent to the Processing of Personal Data at any time (Article 7 GDPR),
Right of access – Obtain confirmation as to whether or not Personal Data concerning the User is being processed and, where that is the case, receive information concerning, in particular: the purposes of the processing, the categories of personal data processed, the retention period and the recipients to whom the data may be disclosed (Article 15 GDPR),
Right to rectification – Obtain, without undue delay, the rectification of inaccurate Personal Data concerning the User and the completion of incomplete personal data (Article 16 GDPR),
Right to erasure – Obtain, without undue delay, the erasure of Personal Data concerning the User in the cases provided for by the GDPR (Article 17 GDPR),
Right to restriction – Obtain from our Company the restriction of processing in the cases provided for by the GDPR (Article 18 GDPR),
Right to data portability – Receive the Personal Data concerning the User that has been provided to our Company in a structured, commonly used and machine-readable format, and have that data transmitted to another controller without hindrance, in the cases provided for by the GDPR (Article 20 GDPR),
Right to lodge a complaint with the supervisory authority – Lodge a complaint with the Italian Data Protection Authority, Piazza di Montecitorio No. 121, 00186 Rome (RM).

The User may exercise these rights simply by sending a request by email to the certified email address sportfashionservice@pec.it of Sport Fashion Service S.r.l., as the Data Controller identified above.

14. Right to object

The User has the right to object to the processing of personal data concerning them, unless the Data Controller has legitimate grounds to continue the processing (Article 21 GDPR).
In particular, the User has the right to object to the processing of personal data for direct marketing purposes, in accordance with the procedures described in the previous section.

15. Place of data processing

Personal data processing connected with the web services of this Website takes place at the operating offices of the Data Controller and is carried out by technical personnel specifically authorised to process the data. Where necessary, the data may be processed by personnel of the company responsible for maintaining the technological components of the Website at that company’s premises.

16. Automated processes and profiling

The User has been informed of the presence of third-party profiling cookies, in relation to which the User may give consent, withdraw it at any time and/or disable those cookies, as specified in the Website’s Cookie Policy.
Last updated: 08/10/2020

Login

Shopping Cart

Close
No products in the cart.
Close

BLACK FRIDAY

30% di sconto su oltre 100 giacche e giubbotti

Se vuoi accedere in anteprima alla promozione, iscriviti ora