Privacy Notice for Registration and Purchases
Notice on the processing of personal data pursuant to art. 13 of EU Regulation 2016/679
Data Subjects: Users of the E-commerce registration section.
GA.MA. S.r.l., in the capacity of Data Controller with regard to the processing of your personal data, in accordance with EU Regulation 2016/679 (hereinafter 'GDPR'), with this document informs you that the above-mentioned regulation provides for the protection of data subjects with regard to the processing of personal data, and that such processing shall be carried out according to the principles of propriety, legality, transparency and protection of your confidentiality and rights.
Your personal data (name, surname, address, email address and phone number) will be processed in accordance with the legislative provisions of the above-mentioned regulation and the confidentiality obligations set out therein.
Purpose of the processing: your data will be processed for the following purposes:
a) implementation of contractual obligations:
- executing the transaction that the user is performing;
- providing the service and/or products purchased;
- with regard to contractual and pre-contractual obligations, exclusively for administrative and accounting purposes, including litigation;
- management of sales and related obligations, including pre-contractual activities and shipping;
- customer care.
The legal basis for the processing of your data for the purposes referred to in point a) is the fulfilment of pre-contractual and contractual obligations in accordance with article 6.1.b.) of the GDPR.
b) connected to the implementation of legal requirements:
- performance of legal obligations;
- operational, regulatory, tax and management requirements.
The legal basis for the processing of your data for the purposes referred to in point b) is the fulfilment of legal obligations in accordance with article 6.1.b.) of the GDPR.
c) sending commercial and marketing communications containing informational, commercial and promotional messages related to the business and products of GA.MA S.r.l., in full compliance with the principles of legality and propriety, and the provisions of the law. At any time you may object to the processing of your data by using the link "CLICK HERE" at the bottom of the email, or by sending a request to the Data Controller at the contact details in this notice. The legal basis for the processing of your data for the purposes referred to in point c) is your consent, in accordance with article 6.1.a.) of the GDPR.
Processing method: your personal data may be processed in the following ways:
- • cookies (as further explained in the Cookie Policy available on the website)
- software systems managed by third parties;
- processing by means of electronic calculators;
- manual processing by means of printed archives;
- in the event of consent given for marketing purposes, using traditional methods (phone contact and individual emails) or through automated contact methods (automated email campaigns, SMS and social networks);
- • in the event of consent given for marketing purposes, in order to compare and eventually improve the results of communications, the Data Controller uses systems with reports to send newsletters and promotional messages. Thanks to these reports, the Data Controller will be able to see, for example: the number of readers, openings, unique "clickers" and clicks; devices (IPhone, Blackberry, Nokia...) and operating systems (Windows, Apple, Linux, Android...) used to read the message; the details of the emails sent by date/hour/minute/viewing location; the details of delivered and undelivered messages, and those that have been forwarded; the list of unsubscribers from the newsletter; link tracking (in other words, the number of clicks made on links in the message); click tracking (which links have been clicked on and by whom). All of this data is used for the purpose of comparing, and eventually improving the results of communications.
All processing is carried out in accordance with the methods referred to in art. 6 and 32 of the GDPR, and with the adoption of the adequate security measures indicated.
Notice: your data will be communicated exclusively to competent, duly appointed individuals for the fulfilment of the services necessary for correct management of the relationship, with a guarantee of protection of the data subject's rights.
Your data will only be processed by staff expressly authorised by the Data Controller, in particular the following categories of operators:
- Marketing Office,
- Commercial Office,
- Administrative Office,
- Information Systems.
Your personal data may be processed by third parties belonging, for example, to the following categories:
- companies performing routine and extraordinary maintenance on the website
- banks and credit institutions including Visa, Mastercard and American Express for credit card or prepaid card payments
- in the context of public and/or private entities for which the communication of data is mandatory or necessary to fulfil legal obligations, or is in any case instrumental to the administration of the relationship
- shippers, hauliers, owner-drivers, postal services, logistics companies
- providers of technical assistance services
- public financial entities
- consultants and freelance professionals, including associations
- In the event of consent given for marketing purposes, to the providers of the platforms used to send commercial information.
The parties belonging to the above-mentioned categories operate, in certain instances, in the capacity of data processors specifically appointed by the Data Controller in accordance with article 28 of the GDPR, and in other instances with full autonomy as separate data controllers, with the understanding that, in this latter case, the communication of your personal data to such independent data controllers is carried out solely for the purpose of fulfilling the purposes indicated in this notice.
The list of these third parties is available upon request, sent to the contact details indicated in this notice.
Distribution: Your personal data will not be distributed in any way.
Transfer of personal data: For technical and organisational reasons, your data will be kept within the European Union, and in the event of your consent to its use for marketing purposes, to send corporate communications, your data will be transferred to countries outside the European Union: this second transfer is in any case lawful as it is guaranteed by the existence of decisions on its adequacy issued by the European Commission and/or protection clauses on the basis of models adopted by the European Commission in accordance with art. 46 of the GDPR.
You may request from the Data Controller a copy of the safeguarding measures adopted for the transfer of your personal data outside the EU, as well as information on the places where the latter has been made available, by sending a specific request to the Data Controller using the email address privacy@gama.eu.
Storage Period: We would like to inform you that, in accordance with the principles of legality, limitation of purposes and minimisation of data, and pursuant to art. 5 of the GDPR, the period for which your personal data will be stored is:
- for the purposes referred to in letter a), the entire duration of the contractual relationship and, after the termination of the latter, it will extend for the period of time required by legal obligations
- for the purposes referred to in letter b), in accordance with legal requirements
- for the purposes referred to in letter c), until the exercise of your right to revoke consent or object to the processing of your data. At any time you may exercise the rights referred to in this section using the link at the bottom of the emails received, or by sending a request to the Data Controller at the contact details indicated in this notice. Your data will be kept until you decide to cancel your subscription to the service.
Data Controller
The Data Controller is GA.MA S.r.l., with registered office in via Sant'Alberto, 1714 – 40018 San Pietro in Casale (BO) – Italy, e-mail privacy@gama.eu – tel. + 39 051 6668811 in the person of its legal representative pro-tempore.
You have the right to request the deletion (right to be forgotten), limitation, update, rectification or porting of or express your objection to the processing of your personal data by the Data Controller, as well as having the right in general to exercise all the rights provided for by art. 15 et seq. of European Regulation 2016/679, by writing to privacy@gama.eu or contacting the Data Controller at the company contact details provided in this document. The Data Subject has the right to lodge a complaint with the Supervisory Authority
EU Reg. 2016/679: Articles 15, 16, 17, 18, 19, 20, 21, 22 - Rights of the Data Subject
- The Data Subject has the right to obtain confirmation of the existence or otherwise of personal data concerning them, even if not yet recorded, its disclosure in an intelligible format, and may make a complaint with the supervisory authority
- The data subject has the right to obtain information concerning:
- the origin of the personal data, the purposes and methods of the processing;
- logic applied in the event of processing performed with the aid of electronic instruments
- the details of the identity of the data controller, the processors, and the representative mandated pursuant to Article 5, paragraph 2;
- for entities or categories of entities to which the personal data may be submitted or which may become aware thereof, in the capacity of designated representative in the territory of the State, managers or personnel authorised to process personal data.
- The data subject has the right to obtain:
- the update, rectification or, if interested, integration of the data;
- deletion, transformation into anonymous form or blocking of data processed unlawfully, including data whose retention is unnecessary for the purposes for which data were collected or subsequently processed;
- certification that the operations referred to in letters a) and b) have been brought to the attention, also as regards their contents, of those to whom the data have been communicated or provided, except in the case in which this requirement proves impossible to meet or involves the use of means manifestly disproportionate to the protected right;
- data portability.
- The data subject has the right to object, in whole or in part:
- to processing of personal data concerning them for legitimate reasons, even if relevant for the purpose of collection;
- to processing of personal data concerning them for the purpose of sending advertising materials or direct selling or for carrying out market or commercial communication surveys