Loyalty Program Information

 

“Fidelity” Information

Art. 13 General Data Protection Regulation No. 2016/679 (“GDPR”)

 

Introduction

This information is intended to illustrate the methods by which LAR Italia Srl Unipersonale collects, processes and stores the personal data of people who participate in the loyalty program and collect points on purchases (hereinafter the “ Customers ”).

Data controller

The data controller is LAR Italia Srl Unipersonale, with registered office in Via Visconti di Modrone 28 - 20122 Milan (MI), VAT number 02669650026.

LAR Italia Srl Unipersonale can be contacted:

      by writing an email to privacy@angelico.it ;

      by regular mail, to the office address as indicated above.

Categories of data processed

The categories of data processed are the following:

      personal identification data of Customers; (*)

      Customers' personal contact details; (*)

      additional personal data provided by filling out a specific information request form and/or other similar methods available at the Data Controller's direct stores;

      additional personal data provided in the event of participation in surveys, polls, market research and, more generally, statistical investigations proposed by the Data Controller or by third parties;

      common or particular data shared by the Customer on the basis of free consent.

Purpose, legal basis and retention period

Purpose

Legal basis

Shelf life

(1) Allow the Customer to register for the loyalty program and collect points.

6 (1) (b), for the fulfillment of needs related to the contract and pre-contractual activities

For the entire duration of the membership to the loyalty program, and subsequently for 10 years pursuant to art. 2220 of the Civil Code, except for any obligations that justify its extension.

(2) Allow the execution and finalization of commercial transactions related to the program

6 (1) (b), for the fulfillment of needs related to the contract and pre-contractual activities

For the entire duration of the membership to the loyalty program, and subsequently for 10 years pursuant to art. 2220 of the Civil Code, except for any obligations that justify its extension.

(3) Receive commercial communications from the Data Controller

6 (1) (a), based on the consent expressed by the Customer

Until the consent given is withdrawn

Consequences of failure to provide data

Providing the personal data indicated as mandatory is necessary to achieve the indicated purposes: failure to provide such data will make it impossible to process the data. Providing other personal data is optional .

Categories of subjects who can process personal data, scope of communication or dissemination

Within the limits of the obligations, tasks or purposes indicated above:
• personal data will be processed exclusively by employees and collaborators of the Data Controller, as well as by third parties appointed as Data Processors pursuant to art. 28 GDPR, in compliance with the provisions of the law, including with regard to security measures to protect and safeguard the data;
• the data will not be disclosed in any way, unless the interested party consents.

The list of Data Processors can be requested from the Data Controller.
The Data Controller may communicate personal data to third parties, independent data controllers, for the sole purpose of fulfilling legal obligations, including, for example:
• public and private bodies, including following inspections or audits (for example, Financial Administration, Social Security Institutions);
• subjects who can access the data pursuant to legal provisions (for example, Tax Police Bodies, Judicial Authorities).

International transfers

Personal data will be transferred, where permitted by the technological tools employed, to third countries deemed adequate by the EU Commission, or in any case to entities that have entered into Standard Contractual Clauses or other mechanisms suitable for the transfer of personal data outside the EEA. For further information, please contact the Data Controller.

Rights of the interested party

The interested party may, at any time, exercise the rights provided for by European Regulation no. 2016/679, and in particular the right:
• to access your personal data;
• to obtain the rectification or cancellation of the same or the limitation of the processing;
• to object to the processing, in the event that the Data Controller exercises a legitimate interest;
• to obtain the portability of your data, where applicable;
• to withdraw consent, where applicable: the withdrawal of consent does not affect the lawfulness of the processing based on the consent previously given;

• to lodge a complaint with the supervisory authority: for Italy, the supervisory authority is the Italian Data Protection Authority ( www.gpdp.it) .
The above rights may be exercised by sending an email request to the addresses indicated above.