Privacy Policy

Information on the processing of personal data pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR). Effective from 20/06/2023

 

INTRODUCTION

This information takes into account the provisions of the GDPR and the Privacy Code (Legislative Decree 30 June 2003 no. 196). The document was also drafted based on the Guidelines of the Privacy Authority (especially the Anti-Spam Guidelines issued by the Privacy Authority on 4 July 2013).

 

Data Controller: Bikilia S.r.l.

Site to which this privacy policy refers: https://yourdeclineoration.com/ (Site).

The Data Controller has not appointed a DPO (Data Protection Officer). Therefore, you can send any information requests directly to the Data Controller.

 

GENERAL INFORMATION

This document describes how the Data Controller processes your personal data provided on the Site.

Below are described the main processing activities of your personal data. In particular, the legal basis for processing is explained, whether providing data is mandatory, and the consequences of failing to provide personal data. To better describe your rights, where necessary, we have specified if and when a certain personal data processing is not carried out. On the Site, you have the possibility to enter personal data of third parties. In this case, you guarantee that you have obtained the consent of these subjects to enter their personal data. Therefore, you agree to indemnify and hold harmless the Data Controller from any liability.

 

Registration on the Site

The information and data requested during registration will be used to allow you both to access the reserved area of the Site and to use the online services offered by the Data Controller to registered users. The legal basis for processing is the necessity for the Data Controller to perform pre-contractual measures adopted at the request of the data subject. Providing data is optional. However, your refusal to provide data will make it impossible to register on the Site.

 

Purchases on the Site

Your personal data will be processed to allow You to make purchases on the Site. In the case of placing an online purchase order, to enable the conclusion of the purchase contract and the correct execution of related operations (and, if necessary according to sector regulations, to fulfill tax obligations). The legal basis for the processing is the Data Controller's obligation to perform the contract with the data subject or to comply with legal obligations. Regardless of the above (and therefore Your consent), the Data Controller may process Your data for so-called "soft-spam" purposes, governed by art. 130 of the Privacy Code. This means that limited to the email You provided in the context of a purchase through the Site, the Data Controller will process the email to allow direct offers of similar products/services, provided that You do not object to such processing as described in this privacy notice. The legal basis for the processing is the legitimate interest of the Data Controller in sending this type of communication. This legitimate interest can be considered equivalent to the data subject's interest in receiving "soft-spam" communications. The Data Controller may send emails to remind the user to complete a purchase. The legal basis for this processing is the legitimate interest of the Data Controller in sending this type of communication.

 

Responding to Your requests

Your data will be processed to respond to Your information requests. Providing data is optional, but refusal will prevent the Data Controller from responding to Your inquiries. The legal basis for the processing is the legitimate interest of the Data Controller in responding to user requests. This legitimate interest is equivalent to the user's interest in receiving a response to communications sent to the Data Controller.

 

General marketing

With Your consent, the Data Controller may process the personal data You provide in order to send You advertising material and/or newsletters related to its own or third-party products. The legal basis for this processing is Your consent. Providing personal data for this purpose is purely optional. Failure to consent to the processing of data for marketing purposes will result in Your inability to receive advertising material related to products/services of the Data Controller and/or third parties, as well as the Data Controller's inability to conduct market research, including surveys to assess user satisfaction, and to send You newsletters.

 

Profiling

Subject to your consent, the Data Controller may process your personal data for profiling purposes, that is, to analyze your consumption choices by revealing the type and frequency of purchases you have made, in order to send you advertising material and/or newsletters related to products of its own or third parties, of your specific interest. The legal basis for this processing is your consent. Providing data for this purpose is purely optional. Failure to consent to the processing of your personal data for profiling purposes will make it impossible for the Data Controller to develop your commercial profile by detecting your purchasing choices and habits as well as to send you advertising material related to products of the Data Controller and/or third parties, of your specific interest.

 

Data transfer

For sending promotional communications, subject to your explicit consent, your personal data may be transferred to "third parties." The legal basis for processing is your consent. Providing personal data for this purpose is purely optional. Failure to consent to the transfer will make it impossible to transfer your personal data to third parties for advertising purposes.

 

Geolocation

The Site does not implement tools for geolocating the user's IP address.

 

Resume

It is not possible to send resumes through the Site. Therefore, your data will not be processed for these purposes.

 

Appointment booking

There are no third-party appointment booking systems active on the Site with the Data Controller. Therefore, your data will not be processed for this purpose. However, you can always contact the Data Controller using the contacts indicated in the header.

 

Communication of personal data

In the course of its ordinary activities, the Data Controller may communicate your personal data to certain categories of parties. See article 2 You can find the list of parties to whom the Data Controller communicates your personal data. To facilitate the protection of your rights, article 2 may specify in some cases when your data is not communicated to third parties.

The "communication" of personal data to third parties is different from the "transfer" (regulated in the preceding point). In fact, in communication, the third party to whom the data is transmitted can only use it for the specific purposes described in the relationship with the Data Controller. In the transfer, however, the third party becomes an independent Data Controller of the personal data. Furthermore, to transfer Your personal data to third parties, Your consent is always required.

Without prejudice to the above, it is understood that the Data Controller may still use Your personal data to properly fulfill the obligations provided by the laws in force.

 

SPECIFIC PRIVACY NOTICE

Art. 1 Processing methods

1.1 The processing of Your personal data will mainly be carried out with the aid of electronic or otherwise automated means, according to methods and tools suitable to guarantee its security and confidentiality in compliance with the GDPR.

1.2 The information acquired and the processing methods will be relevant and not excessive in relation to the type of services provided. Your data will also be managed and protected in secure IT environments appropriate to the circumstances.

1.3 No "special data" are processed through the Site. Special data are those that may reveal racial and ethnic origin, religious, philosophical or other beliefs, political opinions, membership in parties, trade unions, associations or organizations of a religious, philosophical, political or trade union nature, health status, and sexual life.

1.4 No judicial data are processed through the Site.

 

Art. 2 Communication of personal data

The Data Controller may communicate Your personal data to specific categories of entities. Below are the entities to which the Data Controller reserves the right to communicate Your data:

  • The Data Controller may communicate Your personal data to all those entities (including Public Authorities) that have access to personal data by virtue of regulatory or administrative provisions.
  • Your personal data may also be communicated to all those public and/or private entities, natural and/or legal persons (legal, administrative, and tax consultancy firms, Judicial Offices, Chambers of Commerce, Labor Chambers and Offices, etc.), whenever the communication is necessary or functional to the proper fulfillment of obligations arising from the law.
  • The Data Controller employs employees and/or collaborators in any capacity. For the proper functioning of the Site, the Data Controller may communicate Your personal data to these employees and/or collaborators.
  • In its ordinary Site management activities, the Data Controller uses companies, consultants, or professionals responsible for the installation, maintenance, updating, and, in general, management of the Data Controller's hardware and software or those used by the Data Controller to provide its services. Therefore, only for these purposes, Your data may also be processed by these parties.
  • For sending its communications, the Data Controller uses external companies responsible for sending this type of communication (CRM platforms). Your personal data (in particular the email) may therefore be communicated to these companies.
  • For customer support purposes, the Data Controller uses one or more companies appointed to provide customer care services. Only for this purpose, Your personal data may be communicated to these companies.
  • The buyer's personal data may be communicated to post offices, couriers, or shippers responsible for delivering the Products purchased through the Site.

The Data Controller reserves the right to modify the above list based on its ordinary operations. Therefore, You are invited to regularly access this privacy notice to check to which parties the Data Controller communicates Your personal data.

 

Art. 3 Retention of personal data

3.1 This article describes how long the Data Controller reserves the right to retain Your personal data.

  • For marketing purposes, personal data will be retained until consent is revoked. For inactive users, personal data will be deleted one year after the last email possibly viewed was sent.

3.2 Without prejudice to the provisions of article 3.1, the Data Controller may retain Your personal data for the time required by specific regulations, as amended from time to time.

 

Art. 4 Transfer of personal data

4.1 The Data Controller is based within the European Union. Therefore, the processing of Your data is legally secure as it is governed by the GDPR. If the transfer of Your personal data takes place to a non-EU country for which the European Commission has issued an adequacy decision, the transfer is considered legally secure in any case. This article 4.1 indicates, from time to time, the countries to which Your personal data may be transferred and where the European Commission has issued an adequacy decision.

  • Users are therefore invited to regularly access this article to check whether the transfer of their personal data takes place in a country with these characteristics.

4.2 Without prejudice to what is indicated in article 4.1, your data may also be transferred to non-EU countries for which the European Commission has not issued an adequacy decision. You are therefore invited to regularly review this article 4.2 to verify in which of these countries your data may be transferred.

4.3 In this article, the Data Controller indicates the countries to which it may specifically direct its activities. This circumstance may imply the application of the legislation of the reference country, together with that of the GDPR. 

  • At the user's request, the Data Controller will apply the most favorable legislation possibly provided by the user's national law to the processing of personal data.

 

Art. 5. Rights of the data subject

Pursuant to art. 13 of the Privacy Regulation, the Data Controller informs you that you have the right to:

  • request from the Data Controller access to your personal data and the correction or deletion of the same or the restriction of processing concerning you or to object to their processing, as well as the right to data portability
  • withdraw consent at any time without affecting the lawfulness of processing based on consent given before the withdrawal
  • file a complaint with a supervisory authority (e.g., the Data Protection Authority).

The rights mentioned above may be exercised by submitting a request without formalities to the contacts indicated in the Introduction.

 

Art. 6. Changes and Miscellaneous

The Data Controller reserves the right to make changes to this privacy policy at any time, providing appropriate notice to the users of the Site and ensuring in any case adequate and equivalent protection of personal data. To review any changes, you are invited to regularly consult this privacy policy. In case of substantial changes to this privacy policy, the Data Controller may also notify you via email.