THE DATA CONTROLLER AND THE CONTROLLER’S PRIVACY REPRESENTATIVE
WHAT KIND OF DATA ARE PROCESSED; WHAT ARE THE PURPOSES OF THE DATA PROCESSING
In general, the visit and consultation of the Website does not imply collection and processing of the user’s personal data. The processing of the user’s personal data that visit and consults the Website is limited to the so-named surfing data, namely the data whose transmission to the Website is implicit in the functioning of the information systems in charge of the managing of the Website and in the use of communications protocols peculiar to the Internet. Surfing data are, for example, the IP addresses or the domain names of the computers employed by the user who connects to the Website and other parameters relating to the type and the information operating system employed by the user. Surfing data, such as these above specified and for example the number of visits, the time spent on the Website are collected and processed by igaspofficial exclusively for statistical purposes and in anonymous form in relation to the access and use of the Website for purposes of monitoring the correct functioning of the Website and enhancing the Website functioning and content. Due to the nature itself of surfing data, these data may lead to identification of the users if they are associated with data held by third parties; however, igaspofficial does not collect surfing data in order to associate them with identified the users. Surfing data are deleted after the processing in anonymous form; said data may be used for purposes of assessing possible responsibilities in case of information crimes realised against the Website or through the Website. With the exception of the aforementioned circumstance, igaspofficial keeps the user’s surfing data only for the maximum period of time allowed under applicable laws and then makes said data anonymous.
Furthermore, igaspofficial collects and processes personal data voluntarily provided by the user when the user interacts with the Website functionalities and requests the services offered by the Website, for example upon the user’s subscription to the Website; the user’s subscription to the newsletter or mailing list; the user’s purchase of products through the Website, which includes all activities relating to the purchase of goods, such as for example delivery of goods, billing issues, returning and exchanging of goods, receiving refunds, purchase and use of gift cards and e-gift cards, as applicable, payment related activities, including fraud prevention, and customer support and interaction with our call centre; the user’s participation in promotions and other initiatives realised through the Website such as for example competitions and sweepstakes, the user requests information from igaspofficial or the user sending igaspofficial a question, communication or feedback through traditional mail or through the Website. We will process the user’s personal data to comply with laws, regulations and Community legislation, and to assess and defend a legal right. We may process the user’s personal data also when the user contacts our customer support and call centre, which may communicate with the user and thus process the user’s personal data through email, chat and telephone. The user may finalise the purchase of our products through telephone by contacting our call centre, following the procedure specified in our returns policy. For the processing of your personal data when you make a purchase on our Website, please see our relevant privacy Statement. The call centre will assist the user in closing transactions over the phone and processing the user’s order on the user’s behalf and for said purpose it will collect the user’s personal data and credit/debit card details. The call centre will also register the user’s phone number for the purpose of call-back and back-office services in order to provide the user with the requested support and information. Marketing, statistical and profiling activities as above specified may also be performed by the call centre, with the user’s consent. In some cases, for purposes of internal training, quality control and verification, the call may be recorded and the emails may be saved to the extent not prohibited by applicable laws.
The user will always be informed in advance of the recording of the communication, and the user will have the opportunity to object to such recording, save when this is necessary for verification purposes in relation to your purchase or other reasons, as allowed under applicable laws.
With the user’s consent, which is optional, igaspofficial may further process the user’s personal data for survey purposes and for marketing purposes, that is for sending the user, through email or other electronic communications such as SMS, MMS, fax, etc., promotional information and material on products and services from igaspofficial, on special initiatives on prices and promotions, exhibitions and fairs organised by igaspofficial or in which igaspofficial takes part; and for profiling purposes. For the marketing and profiling activities above defined the user’s personal data may also be shared with other igaspofficial partners. The user will always have the opportunity to object, at any time and for free, to the processing of his/her personal data for the sending of promotional information and material; in each communication there will be a specific section in which are specified the conditions (easy to perform and free of charge) of revoking the consent.
Personal data that igaspofficial collects and processes includes name and contact details such as street address, telephone number, email address and further possible information of an optional nature provided by the user. In the relevant sections of the Website where data is collected a specific information statement is provided. When requested under the Privacy Law, igaspofficial requires the user’s consent before proceeding to process his/her personal data.
PLACES WHERE YOUR DATA IS STORED
‘Session cookies’ are stored in a temporary memory and are deleted when the user closes the browser. Session cookies do not collect any information from the user’s computer.
CONDITIONS AND FEATURES OF THE PERSONAL DATA PROCESSING
Personal data collected by igaspofficial is mainly processed through electronic and automated means but also without the same (paper processing), under procedures and logics that comply with the data processing purposes as herein specified. Personal data of the user is processed according to applicable privacy laws, including security and confidentiality issues, and are kept only for the time strictly functional to achieve the specific data processing purpose from time to time pursued and according to applicable laws.
SECURITY AND QUALITY OF PERSONAL DATA
igaspofficial is committed to protect the security of the user’s personal data. Personal data is processed by i- gasp in compliance with the security provisions as set forth by applicable laws in order to prevent loss and destruction, even accidental, of data, unauthorised access to data, unlawful or unfair use of data. Moreover, information systems and software programs are configured so that personal and identification data is used only when necessary to achieve the specific processing purpose from time to time sought.
igaspofficial deploys a variety of advanced security technologies and procedures to help protection of the user’s personal data against the risks outlined above. For example, personal data provided by the user is stored on secured servers placed in controlled locations. Moreover, for the transmission of some data through the Internet are deployed encryption techniques such as Secure Socket Layer (SSL) protocol.
The user may help igaspofficial to update and maintain accuracy of the personal data provided by the user to igaspofficial by notifying igaspofficial of any amendment relating to the user’s address, title, telephone number or electronic mail (email) address. Registered users may perform the foregoing online following the instructions reported on relevant user profile pages of the Website.
EXTENT OF PERSONAL DATA COMMUNICATION
The user’s personal data may be communicated to institutions, authorities, public entities, banks and financial institutions, professionals, independent consultants, also in associate form, business partners and third party service providers to which igaspofficial may revert to for performance of professional, technical and organisational services functional to the managing of the Website and the activities therein performed, such as for example the sales of goods and related activities, the managing of functionalities offered by the Website and of the initiatives and services that the user may subscribe to and require through the Website, and for services strictly functional to achievement of the other processing purposes herein specified. With specific reference to the purchase of goods, data will be processed by the relevant local igaspofficial entity established in the place where delivery has to take place, acting as controller of your personal data in accordance with applicable privacy laws, for the following purposes: billing issues, despatch of goods, returning and exchanging of goods, receiving refunds, purchase and use of gift cards and e-gift cards as applicable, payment related activities, including fraud prevention. Moreover, for closing transactions and payment processing we revert to third party service providers for managing and support of the e-commerce platform. These service providers are bound by contractual obligations so that they will implement adequate security measures to protect security and confidentiality of the user’s personal data and credit card information.
The third parties receiving the user’s personal data as above specified will process data as Data Controllers, for example igaspofficial local entities, or Processors for example third party services providers, as the case may be, according to applicable data protection laws and for the same purposes above specified. Personal data may also be communicated to third parties in case of mergers, acquisitions and transfer of any of our assets, products, websites or operations. These third parties will be provided only with the information necessary to perform their respective functions; they agree to use the information received only for the processing purposes above specified, to keep it confidential and secure and to comply with applicable law and the instructions received by igaspofficial. The third parties receiving your personal data are established within the European Economic Area and will process them under applicable privacy laws for the purposes above specified.
Except for the foregoing, the user’s personal data will not be shared with third parties, natural persons or legal entities that are unrelated to, or that do not perform a business, professional or technical function for igaspofficial. The user’s personal data may further be communicated to whoever is the legitimate addressee of communications as provided by applicable laws and regulations, thus for example in case of judicial processes, request by competent courts and authorities or other legal obligation, to protect and defend the rights and property of igaspofficial and the Website. The user’s personal data will not be communicated to third parties for their own marketing purposes and will under no circumstance be spread.
PROVIDING OF PERSONAL DATA
Except for the foregoing description in relation to the surfing data (please refer to the above section ‘The nature and kind of data processed’, providing of personal data by the user is necessary for performance of the services and functionalities offered by the Website and required by the user, such as the user’s subscription to the Website, to newsletters or mailing lists, the managing of the user’s purchase of products through the Website and related activities, the managing of the user’s participation in promotions and other initiatives realised through the Website such as for example competitions and sweepstakes, replying to and managing of the user’s request of information, questions, communication or feedback to igaspofficial. Providing of the user’s personal data for the activities necessary to comply with applicable legislation is mandatory. In the above referenced circumstances, denial of providing personal data by the user would make it impossible for igaspofficial to comply with contractual obligations or to provide the user with the requested services, products or information as above specified.
Providing of data by the user for survey purposes, marketing purposes and profiling purposes as above specified is optional; denial of providing personal data by the user in said circumstances will have no consequences on compliance by igaspofficial with its contractual obligations and on providing the user with the services, products or information requested as above specified.
THE USER’S PRIVACY RIGHTS
The user is entitled at any moment to enforce their rights as provided by applicable privacy laws, including but not limited to the right to obtain at any moment confirmation that the user’s personal data exists or does not exist, verify their content, origin and accuracy, ask for their integration, updating, amendment, deletion and the user may oppose for legitimate reasons the data processing (including objecting, at any time and for free, to the processing of his personal data for direct marketing purposes).