Privacy Policy
DP di Ludovico Lo Nigro, with registered office at Via Novara n. 26 (CT), the data controller, is constantly committed to protecting the online privacy of users who use the application and the website www.donpepeshop.com
This document (the "Policy") has been prepared to help you understand how your Personal Data will be processed when using the Application and to provide you with all the information necessary to provide explicit and informed consent to the processing performed.
In general, the processing of any information or Personal Data you provide to the Data Controllers through the application, or that is otherwise collected through the site, will be carried out in accordance with internationally recognized principles of lawfulness, fairness, transparency, purpose and retention limitation, data minimization, accuracy, integrity, and confidentiality and will be aimed at providing the services offered on the site itself, selling Products, and activating an information service with a newsletter service.
1. Data controllers
DP, as identified at the beginning of this Privacy Policy, is the Data Controller for all Personal Data processed through this application.
2. The personal data subject to processing
Following your navigation of the Site, we inform you that the Data Controllers will process your Personal Data, which may consist (also depending on your decisions on how to use the Services) of an identifier such as your name and surname, an identification number, an online identifier or one or more elements characteristic of your physical, physiological, cultural or social identity suitable for making you identified or identifiable (hereinafter only "Personal Data").
Among the Personal Data collected by this Application, either independently or through third parties, there are: Cookies, Usage Data, Email, Password. Other Personal Data collected may be indicated in other sections of this privacy policy or through dedicated information texts displayed together with the Data collection. Personal Data may be freely provided by the User or collected automatically when using this Application. Any use of Cookies - or other tracking tools - by this Application or by the owners of third-party services used by this Application, unless otherwise specified, is intended to identify the User and record their preferences for purposes strictly related to providing the service requested by the User.
Failure by the User to provide certain Personal Data may prevent this Application from providing its services. The User assumes responsibility for the Personal Data of third parties published or shared through this Application and guarantees that he or she has the right to communicate or disseminate such data, thereby releasing the Data Controller from any liability to third parties.
The Personal Data processed through the platform are the following:
a. Name, contact details and other personal data
In various sections of the Site, in particular the one relating to the creation of a personal account and the one for subscribing to the newsletter, you will be asked to enter information such as: Email, Password, name, surname, date of birth, gender.
b. Special categories of personal data
Some sections of the Site Platform include free fields where you can provide the Data Controllers with certain information, which may contain Personal Data.
Since these fields are free, you may use them to disclose (intentionally or inadvertently) certain sensitive categories of Personal Data, such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data intended to uniquely identify a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.
The Data Controllers ask you not to send such Personal Data unless strictly necessary.
Indeed, these special categories of Personal Data may be processed only with your explicit consent (which can be expressed by ticking the box in the specific form) and in compliance with the legislation in force from time to time.
The Data Controllers therefore emphasize the importance of expressing your explicit consent to the processing of special categories of Personal Data, should you decide to share such information.
c. Data provided voluntarily by the interested party
As mentioned above, in some parts of the Site you are allowed to enter text messages or information, visible to the Owners, which may contain Personal Data of other people.
In such cases, you assume the role of independent data controller, assuming all legal obligations and responsibilities. In this regard, you hereby grant the fullest indemnity against any dispute, claim, request for compensation for damages resulting from processing, etc., that may be received by the Data Controllers from third parties whose Personal Data has been processed through your use of the Site's functions in violation of applicable data protection laws.
In any case, if you provide or otherwise process Personal Data of third parties while using the Site, you hereby guarantee (assuming all related liability) that such particular processing is based on the consent of such interested third party or on another appropriate legal basis that legitimises the processing of the information in question.
d. Browsing data
The computer systems and software procedures used to operate the platform acquire, during their normal operation, some Personal Data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of computers used by users connecting to the Site, the URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.), and other parameters relating to the user's operating system and IT environment.
This data is used solely to obtain anonymous statistical information on the use of the Site and to monitor its correct functioning, to identify anomalies and/or abuse, and is deleted immediately after processing.
The data could be used to ascertain responsibility in the event of hypothetical cybercrimes against the platform or third parties.
e. Payment management and data
Payment management services allow this Application to process payments by credit card, bank transfer, or other means. The payment data is acquired directly by the provider of the requested payment service.
Some of these services may also allow the scheduled sending of messages to the User, such as emails containing invoices or notifications regarding payment.
The payment services are Multisafepay and PayPal, which collect data as specified in their privacy policies.
f. Interaction with social networks and external platforms
These services allow interaction with social networks or other external platforms directly from the pages of the Application. The interactions and information acquired by this Application are in any case subject to the User's privacy settings for each social network. If a social network interaction service is installed, it is possible that, even if Users do not use the service, it will collect traffic data relating to the pages on which it is installed.
g. The buttons
Tweet button and Twitter social widgets (Twitter)
The Tweet button and Twitter social widgets are services for interacting with the Twitter social network, provided by Twitter Inc., and the data processed are Cookies and Usage Data. Place of processing: USA – Privacy Policy.
Facebook Like button and social widgets (Facebook, Inc.)
The "Like" button and Facebook social widgets are services of interaction with the social network Facebook, provided by Facebook, Inc. The Personal Data collected are Cookies and Usage Data.
Place of processing: USA Privacy Policy.
Google+ +1 button and social widgets (Google)
The +1 button and Google+ social widgets are services for interacting with the Google+ social network, provided by Google Inc.
Personal data collected are Cookies and Usage Data.
Place of processing: USA Privacy Policy
h. Google Analytics (Google)
Google Analytics is a web analytics service provided by Google Inc. ("Google"). Google uses the Personal Data collected to track and examine the use of this Application, compile reports, and share them with other Google services. Google may use the Personal Data to contextualize and personalize the ads of its own advertising network.
Personal data collected are Cookies and Usage Data.
Place of processing: USA Privacy Policy and Opt Out.
i. Google AdWords Conversion Tracking (Google)
Google AdWords conversion tracking is a statistics service provided by Google, Inc. that connects data from the Google AdWords advertising network with actions performed within this Application.
Personal data collected are Cookies and Usage Data.
Place of processing: USA Privacy Policy.
l. Viewing content from external platforms
These services allow you to view content hosted on external platforms directly from the pages of this Application and interact with them. If a service of this type is installed, it is possible that, even if Users do not use the service, it will collect traffic data relating to the pages on which it is installed.
m. Youtube Video Widget (Google)
YouTube is a video content viewing service managed by Google Inc. that allows this Application to integrate such content within its pages. Personal data collected: Cookies and Usage data.
Place of processing: USA Privacy Policy.
n. Vimeo, LLC
Displaying content from external platforms. Vimeo is a video content viewing service operated by Vimeo, LLC that allows this Application to integrate such content within its pages.
Personal data collected: Cookies and Usage data.
Place of processing: USA Privacy Policy and Cookie Policy.
3. The purposes of the processing
The Data Controllers will use your Personal Data, collected through the Platform, for the following purposes:
Purchase and delivery of products and services: We use your personal data to receive and manage orders, deliver products and services; verify your identity and assist you if you lose or forget your login/password details for your personal account on the platform; purchase a loyalty card; send you the newsletters you have requested as a Service by signing up; allow you to save your favorite items; and provide you with any services you request;
Marketing and remarketing: We use your personal data to show you interest-based advertising related to features, products, and services that may interest you, and to send you promotions via email, SMS, push notifications, telephone, banners, instant messaging, and the Data Controllers' official social media pages, relating to products and/or services, including those of third parties;
Soft spam: processing for this purpose is based on the Data Controllers' interest in sending you marketing communications via email regarding products and services similar to those you have already purchased through the Site. You may opt out of receiving these communications without any consequences for you (other than the fact that you will no longer receive further communications of this kind from the Data Controllers).
compliance: to fulfill legal obligations that require the Data Controllers to collect and/or further process certain types of Personal Data;
Abuse/fraud: to prevent or detect any abuse in the use of the platform, or any fraudulent activity and therefore allow the Owners to protect themselves in court.
4. Legal basis and mandatory or optional nature of the Processing
The legal bases used by the Data Controllers to process your Data, according to the purposes indicated in the previous Paragraph 3, are as follows:
Purchase, delivery, and provision of services and products: processing for this purpose is necessary to provide you with the Services and products and, therefore, to execute the contract entered into with you. It is not mandatory to provide the Data Controllers with your Personal Data for this purpose, but otherwise it will not be possible to provide you with any Services. The same applies to the newsletter service, which arises from your specific request by entering an email address. You can revoke this at any time by following the instructions in Section 7 of this Policy.
Marketing and remarketing: processing for this purpose is based on your consent. It is not mandatory to give your consent to the Data Controllers for this purpose, and you are free to withdraw it at any time without any consequences (except that you will no longer receive marketing communications from the Data Controllers). You can withdraw your previously granted consent by following the instructions in Section 7 of this Privacy Policy.
Soft spam: processing for this purpose is based on the Data Controllers' interest in sending you marketing communications via email regarding products and services similar to those you have already purchased through the Site. You may opt out of receiving these communications without any consequences for you (other than the fact that you will no longer receive further communications of this kind from the Data Controllers).
Compliance: Processing for this purpose is necessary for the Data Controllers to fulfill any legal obligations. When you provide Personal Data to the Data Controllers, it must be processed in accordance with applicable law, which may involve retaining it and disclosing it to authorities for accounting, tax, or other purposes.
Abuse/fraud: the information collected for this purpose will be used exclusively to prevent and/or identify any fraudulent activity or abuse in the use of the Site and therefore allows the Data Controllers to protect themselves in court.
5. Recipients of personal data
Your Personal Data may be shared with the parties indicated below (the "Recipients"):
entities that typically act as data controllers (internal and external), namely: i) individuals, companies, or professional firms that provide assistance and consultancy to the Data Controllers in accounting, administrative, legal, tax, and financial matters;
owners of the websites within the platform;
subjects with whom it is necessary to interact for the provision of the Services;
persons delegated to carry out technical maintenance activities (including maintenance of network equipment and electronic communications networks);
persons authorized by the Data Controllers to process Personal Data necessary to carry out activities strictly related to the provision of the Services, who have undertaken to maintain confidentiality or have an adequate legal obligation of confidentiality (e.g., employees of the Data Controllers);
subjects, entities or authorities to whom it is mandatory to communicate your Personal Data for Compliance, Abuse or Fraud purposes, or by order of the authorities.
6. Retention of Personal Data
Personal Data processed for the purposes of purchasing, delivering, and providing services and products will be retained by the Data Controllers for the time strictly necessary for the aforementioned purpose (e.g., to send the purchased product).
In any case, since such Personal Data is processed to provide you with the Services, the Data Controllers may retain it for a longer period, in particular for as long as may be necessary to protect the Data Controllers' interests from possible complaints relating to the Services.
Personal Data processed for Marketing and remarketing purposes will be retained by the Data Controllers until you withdraw your consent.
In any case, we will remind you of the consent you have given us every 24 months. Once you withdraw your consent, the Data Controllers will no longer use your Personal Data for these purposes, but may still retain it, particularly as may be necessary to protect the Data Controllers' interests from potential complaints based on such processing.
Personal data processed for the purpose of Soft Spam will be retained by the Data Controllers until you object to such processing through the link found at the bottom of each Soft Spam email.
Personal Data processed for Compliance purposes will be retained by the Data Controllers for the period required by specific legal obligations or applicable regulations.
Personal Data processed for the purpose of preventing Abuse/Fraud will be retained by the Data Controllers for the time strictly necessary for the aforementioned purpose and therefore until the Data Controllers are required to retain them for legal protection or to communicate said data to the competent Authorities.
7. Rights of the interested party
You have the right to ask the Data Controllers, at any time:
access to your Personal Data (or a copy of such Personal Data), as well as further information on the processing in progress on them
the rectification or updating of your Personal Data processed by the Data Controllers, where they are incomplete or out of date;
the deletion of your Personal Data from the Data Controllers' databases;
the limitation of the processing of your Personal Data by the Data Controllers;
to obtain the Personal Data concerning you in a structured, commonly used and machine-readable format;
You can also:
object to the processing of your Personal Data by the Data Controllers (e.g. Soft Spam);
withdraw your consent for Marketing and Remarketing purposes.
We inform you that most of the Personal Data you have provided to the Data Controllers can be modified at any time by accessing, where possible, your personal account created on the Site.
When requesting the Services, you may have selected which communication channels you want to be contacted through for Marketing purposes (i.e., telephone, SMS, email, post, push notifications, social media).
You can withdraw your consent for Marketing relating to each of these communication channels through your personal account on the Site by deselecting the relevant options.
You can also withdraw your consent to marketing sent via email and stop receiving soft spam using the appropriate link at the bottom of each email you receive. You can also use the same method to stop receiving the newsletter if you have requested it as a Service.
In addition to the above, you can also exercise your rights by writing to the Data Controllers at the following address: info@donpepeshop.com
In any case, you always have the right to lodge a complaint with the competent Supervisory Authority (Data Protection Authority) if you believe that the processing of your Personal Data violates applicable law.
8. Changes
This privacy policy is effective as of April 19, 2020. The Data Controllers reserve the right to modify or simply update its content, in part or in full, including due to changes in applicable legislation. The Data Controllers will inform you of such changes as soon as they are introduced, and they will be binding as soon as they are published on the Site. The Data Controllers therefore invite you to visit this section regularly to review the most recent and updated version of the privacy policy so that you are always updated on the data collected and how the Data Controllers use it.