INFORMATION ON THE PROCESSING OF PERSONAL DATA
DEALER (MULTIBRAND SHOP)
Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
Object
Information on the processing of personal data pursuant to articles 13 and 14 of the Regulation (EU) 2016/679 regarding the Management of Retail Companies.
Premise
The Regulation (EU) 2016/679 ("General Data Protection Regulation", hereinafter GDPR) provides for the protection of individuals with reference to the processing of personal data. According to this legislation, the processing of personal data relating to a subject, to be specifically defined as "interested", is based on principles of correctness, lawfulness and transparency, as well as protection of the privacy and rights of the data subject.
This is to inform you, in compliance with the aforementioned rule, that in relation to the relationship or relationship you have with our structure as a Customer Reseller, our organization is in possession of some data relating to you, which have been acquired, including verbally, directly or through third parties that carry out operations that concern you or that, to satisfy your request, acquire and provide us with information.
Pursuant to the GDPR, given that this information relates to you, it must qualify as "personal data", and must therefore benefit from the protection provided by these provisions. Specifically, according to the aforementioned legislation, you are the interested party who benefits from the rights placed to protect your personal data.
Pursuant to the articles 13 and 14 GDPR our structure, as owner, will process the personal data you provide in compliance with the law, with the utmost care, implementing effective management procedures and processes to ensure the protection of your personal data. To this end, the writer, using material and management procedures to safeguard the data collected, undertakes to protect the information communicated, so as to avoid unauthorized access or disclosure, as well as to maintain data accuracy and also to guarantee use appropriate of the same.
In compliance with this premise, the following information is provided:
Personal data collected
The writer, as owner, uses your personal data to best operate in the performance of his business.
The following data may be requested, even partially, from:
• personal data, fiscal code, VAT number, name, registered office, residence and domicile and contact details;
• data relating to the contractual relationship describing the type of contract, as well as information relating to its execution and necessary for the fulfillment of the contract;
• accounting data relating to the economic relationship, the amounts due and payments, creditworthiness also through the consultation on commercial information platforms, their periodic performance, the summary of the accounting status of the relationship;
• data to make the relationship with our structure more defined and our collaboration and operational efficiency more effective;
• data relating to: your employees and / or collaborators, information on the profession carried out or on your company.
Storage times for your data
The data collected will be kept for the duration of the relationship or collaboration with our organization and for 10 years from the date of termination of the relationship. If in the course of the contractual relationship data not related to the administrative and accounting obligations connected to it are processed, these data will be kept for the time necessary to achieve the purpose for which they were collected and then deleted. The storage times for such data will be communicated to you when these data are collected with specific information.
Mandatory or optional nature of providing data and consequences of a possible refusal
The data must be given to the writer of the essential data for the performance of the contractual relationship, as well as the data necessary to fulfill obligations provided for by laws, regulations, community regulations, or by provisions of Authorities legitimated by law and by supervisory bodies and control.
The non-essential data for the performance of the contractual relationship must be qualified and considered as supplementary information and their provision, if requested, is optional. Your refusal to provide such data, however, will result in lower efficiency of our structure in the conduct of relations with third parties.
In the case in which sensitive data are essential or whose treatment presents specific risks for the performance of the relationship or for the performance of specific services as well as legal obligations, the conferment of such data will be obligatory and since their treatment is allowed only prior written consent of the interested party (pursuant to articles 9 and 10 of the GDPR), you must also consent to their processing.
Specifically, on an optional and non-mandatory basis, the Customer has the right to provide the writer with their own geolocation data, in order to insert the same in the company website www.lilimill.it and www.lilimill.com including the card of the Shop, which also contains the identification data as a business name, address, telephone, email, etc .; all of this for advertising and indirect promotion of the Shop (facilitating the end customer to identify the store closest to their position).
Processing methods
Pursuant to and for the purposes of art. 13 and 14 of the GDPR, we wish to inform you that the personal data you communicate will be recorded, processed and stored in our archives, both paper and electronic, in compliance with the appropriate technical and organizational measures pursuant to art. 32 of the GDPR. The processing of your personal data may consist of any operation or set of operations among those indicated in the art. 4, paragraph 1, point 2 of the GDPR.
The processing of personal data will take place through the use of appropriate tools and procedures to guarantee security and confidentiality and can be carried out, directly and / or through delegated third parties, either manually through paper supports, or through the use of IT means or electronic tools. The data, for the purposes of the correct management of the relationship and the fulfillment of legal obligations, may be included in the internal documentation of the Data Controller and, if necessary, also in the records and registers required by law. The Vueffe Personnel involved in the treatment phases has been trained and instructed, and will adhere to organizational and behavioral measures that comply with the principles of the GDPR.
Activities possibly outsourced
The data you provide will be treated preferably in the EU. Should your data be processed in a non-EU state in the course of a contractual relationship, the rights granted to you by EU legislation will be guaranteed and you will be given timely notice.
In particular, in the event that you decide optionally and with the express consent to use the Geolocation of Your Shop on the www.lilimill.it and www.lilimill.com site, your data will be delivered to a sub-supplier, qualified as External Processing Manager, who could transfer your data outside the European Community, preferably in the USA, Switzerland and Israel. Specifically, the same Supplier certifies that cross-border transfers will guarantee the same rights to processing in the EU, following adherence to US and Swiss Privacy Shields. For this reason, we request your express consent at the bottom of this form so that the Sub Supplier can transfer your data to countries outside the EU, solely for the technical purpose of not disclosing your data to third parties.
Purposes of the processing of personal data
The main purpose of processing your personal data that the writer intends to carry out is to allow a regular establishment and / or evolution, as well as a correct administration of the relationship specified in the introduction.
In particular, the purposes of the processing are as follows:
Administrative and accounting and in particular:
• Fulfillment of tax or accounting obligations;
• Management of professional customers - multi-brand retailers (customer administration; administration of contracts, orders, shipments and invoices; reliability and solvency control);
• Dispute management (contractual defaults; warnings; transactions; debt collection; arbitration; legal disputes);
• Internal control services (security, productivity, quality of services, asset integrity);
• Marketing business management (market analysis and surveys);
• Promotional activities;
• Detection of customer satisfaction.
Marketing activity (optional with consent)
• Geolocation and Customer Card presence on www.lilimill.it and www.lilimill.com website
Personal data will be processed to fulfill legal obligations, as well as to fulfill administrative, insurance and tax obligations required by current legislation and also to fulfill accounting and commercial purposes, or to be able to regularly fulfill contractual and legal obligations arising from the legal relationship existing with the interested party.
Furthermore, the data provided may also be used to contact the interested party in the context of market research regarding products or services or in the context of offers or commercial campaigns.
Furthermore, for the optional purpose of geolocation, your data will be processed exclusively upon prior collection of the express consent.
The interested party may in any case freely choose not to give his consent for such purposes. In this case your references will not be published on the Company's website, while existing commercial activities will continue. It may also indicate the methods with which to be contacted or with which to receive commercial information.
Your data may be communicated by the writer:
• to subjects that can access the data according to the provision of the law, regulation or community legislation, within the limits set by these rules;
• to subjects who need to access your data for purposes auxiliary to the relationship between you and us, within the limits strictly necessary to carry out the auxiliary tasks (credit institutions and forwarding agents are cited as an indication);
• to our consultants and / or professionals, to the extent necessary to carry out their duties in our or their organization, subject to our appointment as a manager who imposes the duty of confidentiality and security;
• to subjects providing ICT services external to the writer, for the processing of your position data (optional option)
In any case, your data will not be communicated except to operators for the execution of acts regarding the fulfillment of the relationships that should intervene with the interested parties to whom the data refer.
Dissemination - The writer will not disclose your data indiscriminately, or in other words, he will not disclose it to undetermined subjects, also through making it available or consulting.
Confidence and confidentiality - The writer considers the trust shown by the parties who have consented to the processing of their personal data to be valuable and therefore undertakes not to sell, rent or rent personal information to others.
Rights pursuant to Articles 15 et seq. GDPR
Pursuant to art. 15 GDPR You have the right to obtain confirmation of the existence or not of a processing of personal data concerning you, even if not yet registered. The exercise of the rights is subject to verification of the identity of the interested party, by delivery of the identity document, which will not be kept by the writer, but only consulted for the purpose of verifying the legitimacy of the request.
You have the right to access personal data and the following information:
a) the purposes of the processing;
b) the categories of personal data being processed;
c) the recipients or categories of recipients to whom the personal data have been or will be communicated, in particular if they are recipients of third countries or international organizations;
d) when possible, the period of storage of personal data provided or, if this is not possible, the criteria used to determine this period;
e) if the data is not collected from the interested party, all available information on their origin;
f) the existence of an automated decision-making process, including the profiling referred to in Article 22, paragraphs 1 and 4, and, at least in such cases, significant information on the logic used, as well as the importance and expected consequences of such treatment for the interested party
If the data is transferred to a third country or to an international organization you have the right to be informed of the existence of adequate guarantees pursuant to art. 46 of the GDPR.
You have the right to ask the data controller for the correction or cancellation, even partial, of personal data or the limitation of the processing of personal data concerning you or to object, in whole or in part, to their processing.
To exercise these rights, you can contact our "Data Controller" at info@lilimill.it or by calling 0735.735119 or by sending a letter to Ufficio Privacy Vueffe srl, via Valtesino 313 - 63066 Grottammare (AP). The Owner will answer you within 30 days of receiving your formal request.
We remind you that in the event of a violation of your personal data, you can file a complaint with the competent authority: "Guarantor for the protection of personal data".
Data controller
The data controller is the writer: Vueffe srl, via Valtesino 313 - 63066 Grottammare (AP) telephone: 0735.735119.
Data processors
The external companies with which a contractual relationship has been established have the role of Data Processors and which, in order to fulfill these agreements, need to receive your personal data, such as, by way of example and not limited to, Commercial Consultants, Law Offices, Trade Unions, ICT company, etc.
To know the data processors if they were appointed and to know the people who will be appointed in the future for this function, any interested party may send a request letter to the Data Controller of personal data, at the above address
It is intended to point out that the Managers indicated above do not deal with fulfilling the requests to exercise the rights of the interested parties pursuant to articles 15 and ss. of the GDPR. This activity is carried out exclusively by the writer as Data Controller.
Treatments without the need for the data subject's consent
It should be noted that the writer, even in the absence of your consent, will be entitled to process your personal data if this is necessary for:
• fulfill an obligation provided by law, regulation or community legislation;
• carry out obligations deriving from a contract to which you are a party or to fulfill, before the conclusion of the contract, specific requests.
Furthermore, your express consent is not required when the processing:
a) regards data coming from public registers, lists, deeds or documents available to anyone, without prejudice to the limits and methods that the laws, regulations or legislation establish for the knowledge and publicity of data or data relating to the performance of activities economic, treated in compliance with current legislation on business and industrial secrecy;
b) it is necessary for the protection of the life or physical safety of a third party (in this case, the holder is obliged to bring the subject concerned to the attention of the treatment of personal data through the information even after the treatment itself, but without delay In this case, therefore, consent is expressed following the presentation of the information);
c) with the exclusion of disclosure, it is necessary for the purposes of carrying out defensive investigations pursuant to the law of 7 December 2000, n. 397, or, in any case, to assert or defend a right in judicial proceedings, provided that the data are processed exclusively for these purposes and for the period strictly necessary for their pursuit, in compliance with the current legislation on business and industrial secrecy;
d) with the exclusion of dissemination, it is necessary, in the cases identified by the Guarantor on the basis of the principles sanctioned by the law, to pursue a legitimate interest of the data controller or third party recipient of the data, also in reference to the activity of banking groups and companies subsidiaries or associated companies, if the fundamental rights and freedoms, the dignity or a legitimate interest of the interested party do not prevail.
The treatments which require the express consent of the interested party:
a) in order for the writer to be able to register on his / her website www.lilimill.it and www.lilimill.com the references of your Shop (Geolocation and Point of Sale information), you need his Express Consent that will be collected beforehand, in writing, at the bottom of the present information.