- General information
Pettenon Cosmetics S.p.A. S.B. (hereinafter also referred to as the “Company” or “Pettenon”) hereby informs you (please note that you are hereinafter also referred to as the “User”), that for the purposes indicated below, it will process your personal data (or that of the Company it represents if acting on its behalf), which you provided. Only the data necessary for the pursuit of the purposes indicated in this notice shall be requested and processed. Please note that you must only provide your own data and/or data of the Company represented by you. If you are acting on behalf of a Company, the activities envisaged in this notice shall be carried out in relation to the Company using the data you have communicated and therefore consenting to the processing (where consent is required) on behalf of the Company you represent.
- Purpose and legal basis
The Company will be processing your data:
A to enable registration to “My Account” as per the registration terms and conditions on this page and therefore to allow users to benefit fully from its use. Please note that by registering you are aware that Pettenon, if the User buys products from Gruppo Sinergia S.r.l. (the company that sells Petteton’s products on their website), may have the data relating to the User’s purchases within their area (e.g., data relating to purchases, shipping data, order management data) and that in case of modification of the data in the private area, the same may be communicated to Gruppo Sinergia S.r.l. in case of future purchases without having to re-enter them. The legal basis of the data processing is the requirement to fulfil contractual obligations.
B to enable the Company to send you advertising messages and/or information on the Company’s products/services/initiatives and those of its partners and involve you in market research and/or interviews to evaluate the Company’s products/services, to the e-mail address you indicated in the form or any other contact details provided later (please note that e-mails and SMS/MMS messages may also be sent through automated tools). The data processing is based on the following legal basis: consent;
C to enable the Company to set up , on the basis of the information on the User in its possession, a User profile (profiling) including a study of consumption habits and choices also deriving, for instance, from the analysis of product choices, purchasing behaviour, site navigation habits, interactions with the Pettenon world, aimed at carrying out Pettenon’s specific marketing, promotion, direct sales and commercial communication activities, in accordance with the specific needs of each User which can be identified from the profiling and also aimed at analysing the choices and consumption habits of customers of Pettenon products. Processing for this purpose will also take place in automated databases. Profiles for single users or of homogeneous classes of users may be set up. Moreover, data from different databases of Pettenon’s partners (Pettenon associated, subsidiaries and controlling companies residing in the European Union) may also be associated and compared against one another. Marketing, promotional, commercial communication and direct sales activities may be carried out only if the user has consented to said processing. The data relating to purchases may also be collected for this purpose, including from Gruppo Sinergia S.r.l. See also point 9. If you do not consent to the processing of your data for this purpose but authorise the use of profiling cookies in the appropriate section of the site, you may still be subject to the activities undertaken through these cookies. Data processing is based on the following legal basis: consent;
D in order to fulfil an obligation imposed by law, regulation or EU legislation ; the legal basis of the data processing is fulfilling a legal obligation;
E for legitimate interests such as to assert or defend a right of Pettenon; the legal basis of the data processing is the pursuit of legitimate interests.
- Compulsory provision of data
- PURPOSE OF POINT 2 letter A
The provision of data to Pettenon from you/the Company that you represent is necessary to register into “My Account” and without providing such data you will be unable to register or activate your My Account. You may at any time request for your account to be deleted.
- PURPOSE OF POINT 2 letter B
You may or may not disclose your personal data/that of the Company you represent to us for the purposes set forth in point 2 (B) of the policy, just as you may or may not provide your consent. Failure to provide consent will therefore have no consequences other than not being subject to the activities referred to in this point on the part of the Company (thus there being no consequence on the other purposes) or not being subject to such activities to the specific addresses you do not wish to provide to us. Furthermore, should you consent to the processing of your personal data for the purposes set forth in point 2 (B) of this notice, you may freely revoke your consent at any time (and thus object to the activities in question) by contacting the Company using the contact details provided in point 6 without giving any reason whatsoever, just as you may inform us that you do not wish to receive communications to certain contact numbers/addresses.
- PURPOSE OF POINT 2 letter C
You may or may not disclose your personal data/that of the Company you represent to us for the purposes set forth in point 2 (D) of the notice, just as you may or may not provide your consent. Failure to provide your consent will therefore have no consequence other than not being subject to the activities referred to in this point on the part of the Company or not being subject to them with respect to the data that you decided not to provide. You may in any event revoke your consent freely and without giving any reason (and thus objecting to the activities in question) by contacting the Company using the contact details provided in point 6;
- PURPOSE OF POINT 2, letter D and E
The provision of data for the purposes referred to in point 2 (D) and (E) of this policy is necessary. Failure to provide such data may make it impossible for Pettenon to carry out the activities referred to in the preceding points.
- Categories of data recipients
For the purposes indicated in point 2 (A), the data will not be disclosed to third parties (except for communication to Gruppo Sinergia S.r.l. in case of data updates as specified in point 2 (A)).
For the purposes indicated in point 2 (B), the data may be disclosed by Pettenon to carriers and forwarding agents and to post offices to arrange the mailing of advertising materials in hard copy.
For the purposes under point 2 (C) the data shall not be disclosed to third parties.
For the purposes under point 2 (D) of this notice, the data may be disclosed by Pettenon to public bodies, judicial and police bodies and to the post office (which may access the relevant address to be able to send any written notices).
For the purposes under point 2 (E) of this policy, the data may be disclosed by Pettenon to lawyers/legal consultants, public bodies, judicial and police bodies and to the post office (which may access the relevant address to be able to send any written notices).
Pettenon shall only disclose data that are necessary for the pursuit of the individual purposes referred to in this policy.
All the parties delegated by the Company (public relations officers, including those external to the Company, information systems officers, including those external to the Company, who may at times perform system administration duties and are in such cases appointed as such, advisors to the Company, including external ones – such as, for example, computer technicians who may at times perform the duties of system administrators and are, in such cases, appointed as such, legal consultants – interns, website management staff, including those external to the Company, marketing staff, including those external to the Company, legal staff, collaborators of the data processors) each in relation to their role, may also have access to the data, on behalf of Pettenon. The data may also be processed, on behalf of the Company, by the data processors appointed by Pettenon (e.g. marketing consultants, IT outsourcers, companies responsible for sending newsletters or notices). The list of data processors may be accessed at any point by contacting the Data Controller using the contact details provided in point 6. The Data Processors shall only process the data necessary to perform the tasks assigned to them.
- Data retention
The data will be retained for as long as is necessary to pursue the purposes contained in this policy. The retention period is as follows:
– in relation to legal obligations, regulations and EU legislation, data may be retained for the time periods required by these regulatory sources;
– in relation to the purposes set out in point 2 (A) of this policy, data may be retained until a request for erasure of the date, or of My Account, is submitted, without prejudice to any retention that is required by legal obligations;
– in relation to the purposes set out in point 2 (B) of this policy, data may be retained until consent is withdrawn or a request for erasure is submitted, without prejudice to retention for evidential purposes for the period provided by the law;
– in relation to the purposes set out in point 2 (C) above, until the revocation of consent/request for erasure or for a maximum of 12 months from the data registration, subject to actual transformation into an anonymous form which does not allow, even indirectly or by linking other databases, the identification of the data subjects;
In any case, all data may be retained for a period necessary to enforce or defend a right of the Company under Italian and European law.
- Data Controller and Data Protection Officer
The data controller is: Pettenon Cosmetics S.p.A. SB with registered office in Via del Palù, 7d, 35018 San Martino di Lupari PD, Tel. +39 049 99888 FAX +39 049 9988809, email@example.com.
As of today, it is not provided for and necessary by law for the Company to have a person in charge of data protection. and in case he/she will become necessary, his/her name will be made known through the Company’s website www.pettenon.it, which users are encouraged to visit periodically, including for any updates to this policy.
We hereby inform you that the GDPR allows the data subject to request to the Data Controller (using the contact details provided above) full access to its personal data and the rectification of such data, the data erasure, a restriction to the data processing, and the right to data portability; the data subject may also object to the processing of its data, again by contacting the Company, and exercise the other rights set forth in Chapter 3, Section 1 of the GDPR, including that of revoking consent, where envisaged: revocation of consent shall not however affect the lawfulness of the processing based on the consent given before revocation.
If the User believes that the processing of its personal data violates the provisions of the GDPR and privacy regulations, it may in any case lodge a complaint with the Italian Data Protection Authority, whose contact details may be found at www.garanteprivacy.it.
- Logic used for profiling
The profiling referred to in point 2(C) above is carried out by the Company through its analysis, including by automated means, of the user’s data and features (e.g. age, geographical area, sex, participation in an event, participation in special initiatives, purchase of certain products, filling in of questionnaires, actions performed while browsing the Company’s websites if the user has accepted profiling cookies). A consumption profile is then created and allocated to specific groups (clusters). Profiling is conducted for the purposes referred to in point 2 (C) above; however, data processing in this case does not give rise to any specific risk for the profiled user, given the basic nature of this type of profiling which does not require data of a particularly sensitive nature or that would enable the identification of any particularly confidential aspects of the user’s private life in detail. However, the user shall in any case have the right to obtain a human intervention in the profiling, to express its opinion, to receive an explanation of the decision taken and to object to the decision.
- Processing procedures
We hereby inform you that the data will be processed on the basis of computerised and paper/manual instruments, and that suitable protection systems will be adopted to safeguard confidentiality. All data shall be stored and processed in a manner that will fully protect confidentiality in compliance with all the regulations in force (and therefore also in accordance with the principles of fairness, lawfulness and transparency and protection of confidentiality and rights) and strictly in the pursuit of the purposes set out in this policy. Only the operations necessary to pursue the purposes set out in this policy shall be carried out on the data. The data shall be stored, as far as the Company is concerned, at its headquarters or server farm and as far as the data processors are concerned, at their headquarters or server farms. Any data disclosed to third parties will be stored and processed by them independently. The data will also be arranged in databases, including computerised databases.
Policy updated as of 12/04/2022