Privacy Policy
Pursuant to art. 13 of the European regulation no. 679/2016, Fabbrica Pelletterie Milano s.p.a. (hereinafter also "Company", and/or "FPM"), VAT Reg. no. 06746000964, with registered office in Milan, Piazza del Carmine, no. 4, hereby informs you that, pursuant to art. 24 of the EU regulation no. 679/2016, it is the Data Controller of your personal data and that it shall process the data you have provided in compliance with the relevant regulations.
Data collected and purposes
The personal data provided by you are collected electronically and processed, also with the aid of electronic means, for the purposes set out below and essentially pertain to:
(1) fulfil legal and tax obligations
The legal basis is the fulfilment of legal obligations.
Data: name and surname, VAT/tax code, address, telephone number, e-mail address, purchase data (e.g. products purchased, place, date and time of purchase, delivery data), products displayed.
Payment details (IBAN, payment card no., expiry date, etc.) are not processed by FPM, but directly through PayPal
(2) register you as a FPM customer, in order to enable you to purchase the products, register them on the site and extend their guarantee.
The legal basis is the performance of a contract to which the data subject is party or the performance of pre-contractual measures taken at the data subject's request (article 6(1)(b) GDPR).
Data: Full name, address, telephone number, e-mail address.
(3) fulfil obligations strictly related to the purchase of a product by a registered customer and any subsequent after-sales assistance, including the procedure for returns (e-commerce management).
The legal basis: performance of a contract to which the data subject is party or performance of pre-contractual measures taken at the data subject's request (article 6(1)(b) GDPR).
Data: Full name, VAT/tax code, address, telephone number, e-mail address, purchase data (e.g. products purchased, place, date and time of purchase, delivery data).
(4) Sales statistics on aggregated and anonymous data (which cannot be traced to the data subject).
(5) Cookies: the site uses cookies to make navigation better and to provide certain functionalities. For more information: https://www.iubenda.com/privacy-policy/30015093/cookie-policy.
(6) Newsletter on products, events and news related to the FPM world
The legal basis: consent of the data subject.
Data: e-mail, full name.
(7) Marketing
The legal basis: consent of the data subject.
Data: e-mail, full name, location and preferences
Please note: FPM does not intend to carry out promotional activities for minors; therefore, the user is required to independently verify this requirement when providing the data for this processing purpose.
(8) "Soft-spam" (the sending of commercial communications relating to products and/or services similar to those already purchased and/or to which the user signed up)
The legal basis: the legitimate interest of the Data Controller and/or on the conditions provided for by specific regulatory provisions (art. 130 (4) of the Privacy Code), unless the interested party objects.
Data: e-mail, full name.
The personal data you provide shall be processed at the offices of FPM Milano and at the offices of the internet and hosting services provider, WebUp S.p.A., and shall be handled by employees and/or professionals expressly authorised to do so.
Nature of data provision
The provision of data is necessary for purposes no. 1, 2 and 3 as it is strictly related to the execution of the contract, the related after-sales service and the fulfilment of legal obligations: any refusal will result in the impossibility of carrying out the contractual relationship and the provision of related services.
With reference to purpose 4, no personal data shall be used, but only aggregated and anonymous data from which the data subject cannot be traced/identified.
The provision of data for purposes 6 and 7 is optional and subject to the express consent of the data subject; therefore, there are no consequences in the event of your refusal, other than the impossibility for FPM to ensure information on the developments of the products and services offered. It should be noted that the data subject has the right to withdraw consent at any time, but this does not affect the lawfulness of the processing prior to revocation.
Methods of processing
Personal data shall be processed in hard copy, computerised and electronic form and entered into the relevant databases (customers, suppliers, administration, etc.), which may be accessed by, and thus become known to, the employees expressly designated by the data controller as authorised/designated to process personal data, in compliance with the legal provisions necessary to guarantee, among other things, the confidentiality and security of the data, as well as their accuracy, updating and relevance to the stated purposes.
Scope of disclosure and dissemination of data
Data are not subject to dissemination.
In relation to the stated purposes, the data may be disclosed to the following parties and/or categories of parties as listed below, or may be disclosed to companies and/or persons who provide services, including external services, on behalf of the Data Controller. Among these*, the following are indicated for greater clarity:
· IT agencies/technicians for user problem solving;
· shipping companies/couriers;
· the competent authorities and/or supervisory bodies for the fulfilment of legal obligations;
· public administrations for their institutional purposes;
· qualified professionals for the purpose of studying and solving any legal and contractual problems.
(*) the list of External Managers/Independent Data Controllers with further useful identification data can be requested by contacting the Company at the addresses given.
To process data we use the Shopify (Shopify International Limited) data centre in ……………., with storage option in EU territory.
In the event of transfer of your personal data to third parties in non-EU countries that do not ensure adequate levels of protection, these shall only be carried out in compliance with the rules contained in Chapter V of the EU Regulation, with the express consent or prior conclusion of specific agreements with the interested data subjects, containing safeguard clauses and appropriate guarantees for the protection of your personal data ("standard contractual clauses"), or if the transfer is necessary for the conclusion and execution of a contract between you and the Data Controller or for the management of your requests.
Duration of processing.
For purposes 1 to 3, your personal data shall be processed for as long as necessary to carry out the existing legal relationship and for a period of ten years from the termination of the relationship/contract to meet legal obligations and from the date of the last registration for administrative-accounting purposes, after which they shall be destroyed or anonymised.
Your personal registration data on the site shall be processed until you decide to cancel your registration on the Site and your profile.
With regard to the newsletter and marketing purposes, your personal data for the stated purposes shall be processed for a maximum period of 36 months, i.e. until you decide to revoke your consent using the modalities set out in this Privacy Policy. In the case of email subscription to the newsletter, you can simply use the "unsubscribe" link.
The personal data for the certification of the originality of the product shall be kept until consent is revoked by the interested buyer.
In relation to the aforementioned processing operations, you may exercise your rights under Chapter III of EU regulation 679/2016 art. 15 - 22, which include:
· obtaining confirmation regarding the existence or lack thereof of data concerning you;
· being notified of the origin of the data, the logic and the purpose on which the processing is based;
· obtaining access, cancellation, transformation into anonymous form or the blocking of the data processed in breach of the law, updating, restriction, rectification, revocation, portability and integration of the data;
· objecting, for legitimate reasons, the processing of such data;
· lodging a complaint with a supervisory authority pursuant to art. 77 of EU Regulation no. 679/2016 (http://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/4535524),
by contacting the Data Controller by calling +(39) 02 36705900 or by sending an e-mail to info@fpm.it.
The Data Protection Officer (DPO) can be reached at: dpo@fpm.it.
Further information regarding the processing and communication of data provided directly or otherwise acquired may be requested at the addresses above.
Having read the Privacy Policy above, aware that my consent is purely optional, as well as revocable at any time, with reference to point 6 of the Purposes of the processing (newsletter):
□ I consent to the processing |
□ I do not consent to the processing |
Having read the Privacy Policy above, aware that my consent is purely optional, as well as revocable at any time, with reference to point 7 of the Purposes of the processing (marketing):
□ I consent to the processing |
□ I do not consent to the processing |