INFORMATION ON THE PROCESSING OF PERSONAL DATA
pursuant to and for the purposes of Art. 13 of the New European Regulation 2016/679 relating to the protection of individuals with regard to the processing of personal data (GENERAL DATA PROTECTION REGULATION - GDPR)
As required by the European Union General Data Protection Regulation (GDPR 2016/679, Article 13), before proceeding with the processing, the interested party (user of the website www.stellabloom.it) is informed that personal data collected through the site, they are processed by the Company using IT and / or telematic tools, for the purposes indicated in this statement.
Holder of the treatment
The Data Controller is SBAM of Anna Rita Calcagno with registered office in Via Eia 120 localita Fontana 43126 Parma - piva 02558190340 and tax code CLCNRT69A48G337M.
The Company has identified a Data Protection Officer pursuant to articles 37 and following of the European Regulation 2016/679, which is identified in Mr. Simone Mora.
This person may be contacted for clarifications and questions regarding the processing of personal data at the address: email@example.com.
For further information relating to the rights of the interested party, please consider the Paragraph called "Rights of the interested parties" of this information.
The personal data being processed are collected directly by SBAM or by third parties expressly authorized by it, or communicated by the Company to these third parties for the pursuit of the purposes described below.
Legal basis and purpose of the processing
The personal data provided by the user when browsing the website www.stellabloom.it are processed by the Data Controller in accordance with the current regulations on the protection of personal data.
The legal basis of the processing is identified in the provision of its services by the Company, in the management and facilitation of the website, as well as in the establishment, execution and possible termination of the online sales contract concluded between the parties and in the obligations under the same contract connected and / or directly and / or indirectly deriving from the same.
The processing of personal data by stellabloom.it is aimed at pursuing the following purposes:
1) REGISTRATION TO THE STELLABLOOM.IT NEWSLETTER: in the event that the user decides to subscribe to the "STELLABLOOM Newsletter", only following a possible and specific consent, personal data will be processed by the Data Controller for sending commercial or promotional communications, updates relating, for example, to the latest trends, new arrivals, exclusive offers, special events and promotions. To unsubscribe from the newsletter, simply click on the unsubscribe link found at the bottom of the e-mails received or by writing to firstname.lastname@example.org.
2) REGISTRATION ON STELLABLOOM.IT: in the event that the user decides to register on the stellabloom.it site, only following a possible and specific consent, personal data will be processed by the Data Controller for the purpose of registration on stellabloom.it. In particular, against the conferment of your name, surname, e-mail address and the setting of an access password, these will be processed for the creation of a personal account, to speed up the purchase procedure, to allow the user to view the status of orders and receive updates on purchases made, change personal settings and update the account, view the history of returns and requests for exchange of goods.
4) ONLINE SHOPPING ACTIVITIES: the personal data provided will be used for the purpose of establishing, managing, executing and / or concluding the online sales contract. The data provided will be processed by the Data Controller for the purpose of managing the purchase order with reference, by way of example, to the activity of payment, shipping, taking charge of any returns, for customer assistance, for the execution of the purposes. administrative - accounting related to the management of the order, for the fulfillment of obligations under current legislation. In case of payment by credit card, the fundamental information for the execution of the transaction (credit / debit card number, expiry date, security code) will be processed by Strype or Paypal or, possibly, by companies in charge of the control anti-fraud through an encrypted protocol and without third parties having access to it in any way. However, this information will never be displayed or stored by the seller (SBAM).
5) PROFILING OF THE PHYSICAL PERSON: only after a possible and explicit consent, the personal data provided can be processed by the Data Controller for profiling activities, or rather of analysis of preferences aimed at creating personalized contents and offers.
Users have full control of their data collected from the www.stellabloom.it site, through your account, being able to recover them or request their cancellation. In fact, in accordance with article 15 of the GDPR, each user can download their stored data by clicking on the "download my data" button in their account. Anyone wishing to receive this information via email, simply click on the "Request my data" button in their account and they will automatically receive an email from the stellabloom.it site with their data (the email will be sent to the address used to register on the site)
Personal data processed
The personal data processed by the Owner are those provided by the user when browsing the website www.stellabloom.it, on the occasion of any registration / subscription to the services / programs made available to STELLABLOOM and / or the possible purchase of products made available to STELLABLOOM, such as, for example: name, surname and e-mail address, in addition to the data necessary for the provision of the online sales service such as, for example, those functional to the execution of the payment and shipping / exchange of purchased products.
Data processing and storage methods
The processing of personal data is carried out by the Data Controller in compliance with the provisions of the current Privacy legislation. The Data Controller performs the processing of personal data using IT and / or telematic tools and with organizational and logical methods strictly related to the pursuit of the purposes indicated in this statement, as well as adopting the appropriate security measures in order to prevent access, disclosure, unauthorized modification or destruction of personal data, their loss and their illegal and incorrect use. However, the Company cannot guarantee its users that the measures adopted for the security of the site and the transmission of data and information on the site are able to limit or exclude any risk of unauthorized access or dispersion of data by devices pertaining to the user. For this reason, users of the site are advised to make sure that their computer is equipped with adequate software to protect the transmission of data on the network (for example updated antivirus) and that their Internet Provider has adopted suitable measures for the security of the transmission. of data on the network. The Company also undertakes to process the data according to the principles of correctness, lawfulness and transparency, to collect them to the extent necessary and exact for the processing and to allow their use only by personnel for the authorized purpose. The management and storage of the personal data acquired will take place in archives or on servers located within the European Union owned by the Data Controller and / or by third-party companies appointed as External Data Processors and, in any case, currently located in Italy.
In relation to the various purposes for which they are collected, personal data will be kept for the time strictly necessary to achieve them and, in any case, in accordance with the current regulatory provisions on the matter.
In any case, the Company will take care to avoid the use of the data indefinitely by proceeding, periodically, to adequately verify the actual persistence of the interest of the subject to which they refer.
Recipients and Data Processors
The collected data will not be disseminated in any way, but will be processed within the limits and for the purposes described by the employees of the Company on the basis of adequate operating instructions (for example, administrative, commercial, marketing, legal, system administrators, etc. .). Some data processing may also be carried out by third parties, appointed as External Data Processors, of which the Data Controller makes use or could make use of in the context of the management of the contractual relationship, the provision of the services offered and for organizational needs of its business. In particular, the data could be communicated to:
a) subjects, public and private, who can access the data by virtue of provisions of law, regulation or community legislation, within the limits provided for by these rules;
b) subjects who need to access data for purposes related to the contractual relationship between the parties, within the limits strictly necessary for the performance of auxiliary tasks (such as, for example, banks and credit institutions, technical service providers, hosting providers, IT companies, communication agencies, postal couriers and forwarding companies);
c) consultants, within the limits necessary for the performance of their professional assignment.
The updated list of External Managers and persons authorized to process is kept at the headquarters of the Data Controller and is available to the interested party, upon request to be made by e-mail at email@example.com
Transfer of data abroad
The management and storage of personal data will take place on the server of the owner and / or third-party companies duly appointed as external data processors located within the European Union.
Personal data may be transferred abroad, in accordance with the provisions of current legislation, even in countries not belonging to the European Union. The transfer to non-EU countries, in addition to the cases in which this is guaranteed by the adequacy decisions of the Commission, is carried out in such a way as to provide appropriate and appropriate guarantees pursuant to art. 46 or 47 or 49 of the Regulations.
Rights of the interested parties
As an interested party, the user can exercise, at any time, the rights provided for in articles 15, 16, 17, 18, 20 and 21 of the GDPR which confer, in particular, the right to:
a) obtain from the Data Controller, pursuant to Article 15, confirmation that personal data is being processed or not and, in this case, obtain access to the data and to information such as: (i) the purposes of the treatment; (ii) the categories of personal data; (iii) the recipients or categories of recipients to whom the personal data have been or will be communicated, in particular if they are recipients located in Third Countries or International Organizations; (iv) when possible, the retention period of the personal data provided or, if not possible, the criteria used to determine this period;
b) obtain from the Data Controller, pursuant to Article 16, the correction of inaccurate personal data concerning him without undue delay; taking into account the purposes of the processing, the interested party has the right to obtain the integration of incomplete personal data, also by providing an additional declaration;
c) obtain from the Data Controller, pursuant to Article 17, the cancellation of personal data concerning him without undue delay. The Data Controller is obliged to delete personal data without undue delay if one of the reasons indicated in paragraph 1 of Article 17 exists;
d) obtain from the Data Controller, pursuant to Art. 18, the limitation of treatment when one of the hypotheses governed by paragraph 1 of Article 18 occurs;
e) obtain from the Data Controller, pursuant to Article 20, the portability of the data or to receive the personal data concerning him provided to a Data Controller in a structured format, commonly used and readable by an automatic device. The interested party also has the right to transmit such data to another data controller without hindrance by the first owner to whom he provided them, if the conditions indicated in Article 20 paragraph 1 are met. Finally, the interested party has the right to obtain the direct transmission of personal data from one Data Controller to another, if technically feasible;
f) object, in whole or in part, pursuant to Article 21, to the processing of personal data concerning him.
For the exercise of their rights, the user can send their requests to firstname.lastname@example.org
It should also be noted that the interested party has the right to withdraw consent at any time without prejudice to the lawfulness of the treatment based on the consent given before the revocation, without prejudice to the consequences indicated above regarding a refusal to provide such personal data . The interested party also has the right to lodge a complaint with a supervisory authority.
You can make requests regarding the exercise of these rights by contacting the address: email@example.com
SBAM undertakes to respond to the requests of the interested party within a period of one month, except in cases of particular complexity for which it could take a maximum of three months. In any case, the Data Controller will provide the interested party with the reason for the wait within one month of the request. The outcome of the request will be provided in writing or electronically. In the event of a request for rectification, cancellation as well as limitation of processing, the Data Controller undertakes to communicate the results of the requests received from the interested party to each of the recipients of his data, unless this is impossible or involves a disproportionate effort.
The Company specifies that a possible contribution may be requested from the interested party if the questions are manifestly unfounded, excessive or repetitive; in this regard, the Data Controller will have a register to track requests for intervention.
Changes to this information