1. Identity and contact details of the Data Controller
The Data Controller is VaporArt S.r.l.
2. Contact details of the Data Protection Officer
As the Data Controller is established in the Italian territory, no representative has been appointed.
The Data Controller can be contacted by email at the following address: email@example.com.
The Data Controller has not a Data Protection Officer (“DPO”).
3. Purpose of processing and legal basis of processing
Your personal data will be processed for the following purposes:
4. Ways of expressing consent
- for contractual purposes, to allow you to purchase services and products through Data Controller’s E-commerce. The legal basis for processing is the need to process your personal data for the performance of the contract. The communication of your personal data is an obligation. If you do not communicate your personal data, no contract can be concluded;
- for purposes related to relevant legal obligations. The legal basis for the processing is the legal obligation of the Data Controller to process personal data in accordance with applicable law.
You will be able to express your consent by signing an electronic document, also through specific flag boxes.
5. Processing methods and logic
6. Automated decision making and profiling
- Personal data will be processed and stored for the purposes under paragraph d), number 3 (legal obligation) through paper tools, automated logic and CRM software to allow the best management of the fulfillment of legal obligations.
If you consent to the Processing of your Personal Data to benefit from personalized services through profiling, your Personal Data may be subject to an automated decision-making process, with a specific algorithm that will decide which communications are best suited to your profile or which may be of most interest to you. The processing carried out in this way has, as expected consequences, by way of example, the sending of highly profiled commercial communications, the sending of discounts, the sending of invitations to events considered of interest, etc.
In accordance with Article 22 GDPR, you have the right to:
7. Source of personal data
- obtain human intervention in decision-making by the Data Controller;
- express your opinion;
- obtain an explanation of the decision reached by the Data Controller;
- challenge the decision itself.
8. Recipients and categories of recipients of personal data
Recipients of personal data may include:
9. Data categories
- communications companies that carry out commercial communication and profiling activities on behalf of the Data Controller, where consent has been given, and which have the status of data processors;
- companies offering information society services, including, in particular, those offering hosting services;
- companies that carry out statistical and market surveys, if consent has been given;
- audit firms;
- partner companies of the Data Controller.
Personal data will be processed. In no case will special personal data defined in Article 9 of the GDPR be processed.
10. Data Transfer
The Data Controller intends to transfer personal data to entities established in a country outside the European Union or to an international organization.
Such parties could be represented, for example, by:
- communications companies that carry out communications activities on behalf of the Data Controller;
- communications company service providers;
- controlled and/or controlling organizations.
The transfer of personal data to such entities, if they are established in a third country or an international organization, is made in the presence of an adequacy decision by the European Commission, which has verified that the third country, the territory or one or more specific sectors within the third country, or the international organization in question guarantee an adequate level of protection of your rights. In any case, the Data Controller, if it deems it appropriate, reserves the right to enter into specific separate agreements obliging such parties to adopt adequate security measures, including organizational measures, aimed at providing appropriate guarantees for your rights. Personal data may thus be transferred to the following countries: United States of America. To obtain a copy of this data or the place where it has been made available, simply send your request to the Controller at the addresses shown above.
11. Personal data retention period
12. Optional consent and consequences of non-consent
- The personal data processed and stored for the purposes referred to in point a) and d), number 3 (contractual and pre-contractual purposes and fulfillment of legal obligations) are processed and stored by the Data Controller in accordance with the provisions of current legislation, however, for a period of time not exceeding 10 years from the cessation of the effects of the contract in case of conclusion of the same, unless otherwise required by law;
- The personal data processed for the purposes referred to in point b) number 3 of this statement (marketing purposes) are processed and stored by the Data Controller until you request their cancellation and / or revocation, as a Data Subject;
- Personal Data processed for the purposes set forth in point c) number 3 (preference determination purposes) are processed and stored by the Data Controller for a period of time not exceeding 12 months from collection.
13. Right of objection
- In relation to personal data processed for the purposes set out in point a) number 3 of this policy (contractual and pre-contractual purposes), the communication of personal data is an obligation. If you do not communicate such personal data, no contract can be concluded.
- In relation to personal data processed for the purposes set out in point b) number 3 of this policy (marketing purposes), the disclosure of personal data is not a contractual obligation. You have the option to provide personal data. If you do not provide such personal data, the Data Controller will not be able to carry out any marketing activities.
- In relation to personal data processed for the purposes set out in point d) number 3 of this policy (legal obligations), the disclosure of personal data is a legal obligation.
As a Data Subject, you have the right to object in the following terms:
14. Other rights
- the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you pursuant to Article 6(1)(e) or (f) of the GDPR. The Data Controller will refrain from further processing your personal data, unless the Data Controller demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims;
- where personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data relating to you carried out for such purposes, including profiling insofar as it is related to direct marketing;
- if you object to the processing of your personal data for direct marketing purposes, your personal data will no longer be processed for such purposes. You may object to the processing of your personal data for direct marketing purposes, even if only in part, for example by objecting to the sending of promotional communications by automated and/or digital means, or to the sending of paper communications and/or the receiving of telephone communications;
- where your personal data is processed for scientific or historical research purposes or for statistical purposes pursuant to Article 89(1) of the GDPR, you have the right, on grounds relating to your particular situation, to object to the processing of personal data, unless the processing is necessary for the performance of a task carried out in the public interest.
The Data Controller would also like to inform you of the existence of the following rights:
15. How to exercise your rights
- Right of access: you have the right to obtain confirmation from the Data Controller that personal data concerning you is or is not being processed, and to access your personal data and specific information, in accordance with Article 15 of the GDPR;
- Right of rectification: you have the right to obtain from the Data Controller the rectification of inaccurate personal data concerning you without undue delay. Taking into account the purposes of the processing, you have the right to obtain the integration of incomplete personal data, including by providing a supplementary declaration, in accordance with Article 16 of the GDPR;
- Right to data erasure, including the right to withdraw consent: you have the right to obtain from the Data Controller the erasure of your personal data without undue delay or to withdraw your consent to the processing, if the grounds defined in Article 17 of the GDPR exist. You have the right to revoke your consent at any time, without affecting the lawfulness of the processing based on the consent you gave before revocation;
- Right to restriction of processing: you have the right to obtain from the Data Controller the restriction of processing, when the cases defined in Article 18 of the GDPR apply;
- Right to data portability: you have the right to receive in a structured, commonly used and machine-readable format, your personal data provided to the Data Controller and you have the right to transmit it to another data controller without hindrance from the Data Controller, as provided for in Article 20 of the GDPR;
- Contractor’s right to object to commercial communications: as a contracting party, you have the right to object at any time, free of charge, to receiving commercial communications from the Data Controller;
- Right to lodge a complaint with the Data Protection Authority: you have the right to lodge a complaint with the Data Protection Authority, to complain about a violation of the rules on the protection of personal data, in accordance with Article 77 of the GDPR.
You may lodge a complaint with the Italian Data Protection Authority as provided in the official website, addressing it to the contact details available at https://www.garanteprivacy.it/home/footer/contatti.
16. Accessibility of information