Privacy policy for site visitors pursuant to Article 13 of the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016

We provide this Privacy Policy (also “Privacy Policy”) to inform you about the needs and methods of use of your personal and / or business data following browsing and purchasing products and / or services on our SITE https://www.ilaire.com (hereinafter referred to as “SITE”)

The information is also provided pursuant to art. 13 of EU Regulation 2016/679 applicable from 25 May 2018 – General Regulation for the Protection of Personal Data (hereinafter referred to as GDPR) to those who interact with the web services of ILAIRE ITALIAN COSMETICS SRL accessible electronically from the address https://www.ilaire.com or, alternatively, also reachable from the address https://www.ilaire.it.

The information is provided only for the SITE https://www.ilaire.com (hereinafter referred to as the SITE) and not for other websites that may be consulted by the user through links and complies with Recommendation no. 2/2001 relating to the minimum requirements for online data collection in the European Union, adopted on 17 May 2001 by the Article 29 Working Group.

For the purposes of applicable data protection legislation, it is necessary to take into account the following: when we speak of “personal data” or “personal information”, we mean all information concerning a person that allows him to be identified. This does not include data from which the identity has been removed (anonymous data).

To access some areas of the SITE or make the purchase of products and / or services, some requested data are mandatory and indicated as such. Failure to provide the information marked as mandatory may make it impossible to manage the registration as a customer or the use of services available on the SITE.

As specified in the General Conditions of Sale, the services offered by ILAIRE ITALIAN COSMETICS SRL are aimed at people over the age of 18. Should the Data Controller become aware of the processing of data of minors under 18 years of age without valid consent of the parents or of a legal guardian, it reserves the right to unilaterally interrupt the use of the service offered, as well as to cancel the acquired data.

For anything not expressly defined in this Declaration on the protection of personal data, please refer to the General conditions of sale.

If you want to forward specific requests, questions or if you intend to exercise any of your rights, please follow the instructions provided in this Privacy Policy.

Owner of the data processing

Responsible pursuant to ARTICLE 4, PARAGRAPH 7, OF GDPR 2016/679 and other national data protection laws of the Member States and other data protection regulations is:

ILAIRE ITALIAN COSMETICS SRL
Via Brescia, 7
25081 Bedizzole (BS) – Italy
VAT / CF 04212220984
Contact options:
E-mail: privacy@ilaire.com

Responsible for data protection

Dr. Ilaria Prandelli
Via Brescia, 7
25081 Bedizzole (BS) – Italy
E-mail: i.prandelli@ilaire.com

Data processing when visiting our site

In principle, it is possible to visit our SITE without providing personal data. It is designed to collect as little data as needed. The data is collected to the extent and for the purposes described below.

Types of data processed

Navigation data

The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected to be associated with identified data subjects, but which by their very nature could, through processing and association with data held by third parties, allow users to be identified.
This category of data includes the IP addresses or domain names of the computers used by users who connect to the SITE, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the user’s IT environment.

Data provided voluntarily

The optional, explicit and voluntary sending of e-mails to the addresses indicated on this SITE entails the subsequent acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data entered therein.
The interested party is invited to read this Privacy Policy when completing the data acquisition forms on the SITE.

Method and place of processing

Personal data are processed with automated tools for the time necessary to achieve the purposes for which they were collected. Specific security measures are observed to prevent data loss, illicit or incorrect use and unauthorized access.
The data collected by the SITE are processed at the ILAIRE ITALIAN COSMETICS SRL headquarters and at the web hosting datacenter. Siteground web hosting, which is responsible for data processing, processing data on behalf of ILAIRE ITALIAN COSMETICS SRL, is located in the European Economic Area and acts in accordance with European standards.

Collection and purpose of the processing of personal data

The treatments connected to the web services of this SITE take place at the headquarters of the owner and of the data processors. No data deriving from the web service is communicated to third parties or disseminated except exclusively for the purpose of completing the order and / or shipping the products. Using third-party cookies, the treatments can also take place outside the European community by Google and the companies that install third-party cookies. In this regard, please refer to the relative Cookie Policy.
The Personal Data provided through the SITE will be processed by ILAIRE ITALIAN COSMETICS SRL for the following purposes:

Services offered on our SITE

When you visit our SITE, we automatically collect and process your data in order to maintain the compatibility of our SITE for as many visitors as possible and to combat abuse and troubleshooting. For this it is necessary to record the technical data of the accessing computer in order to be able to react as soon as possible to display errors, attacks on our IT systems and / or errors in the functionality of our website. Furthermore, we use the data to optimize the WEBSITE and in general to ensure the security of our IT systems. In particular, we collect and process:

  • Date and time of access
  • The web address from which you arrived on our SITE
  • The web pages you visit on our SITE
  • Internet browser information (browser type and version)
  • The operating system of the device with which you access our SITE and our services
  • Your internet service provider
  • IP address of your device

The data indicated are processed for the following purposes:

  • Ensure a smooth connection to the SITE
  • Ensure comfortable use of our SITE
  • System security assessment
  • Other administrative purposes

The legal basis for data processing to provide our SITE and our services is Article 6 (1) lett. f of the GDPR 2016/679. These data are used only to obtain anonymous statistical information on the use of the SITE and to check its correct functioning and are deleted immediately after processing. The data could be used to ascertain responsibility in the event of hypothetical computer crimes against the SITE: except for this possibility, the data on web contacts do not persist for more than thirty days.

Contact form

To contact us, there is a contact form on our SITE. We use the data provided via the contact form to process your request. We are not responsible if your data is provided to us without your knowledge by third parties and we will immediately delete it from the moment we become aware of the unlawful communication of the personal data of others.
We only collect and process your personal data if you provide it voluntarily. These include:

  • Name and surname
  • Telephone number
  • Email address
  • Company name
  • Your message
  • Attached file

The legal basis for the processing of user data in order to contact us is Article 6 paragraph 1 lit. a of the GDPR 2016/679 based on your consent voluntarily given. The personal data collected by us for the use of the contact form will be automatically deleted after processing the request.

Offers and orders

In order to process offers and orders, we collect and process the following data, which are necessary to conclude the order and enter into the contract according to the General Conditions of Sale. We only collect and process your personal data if you provide it voluntarily. These include:

  • Name and surname
  • Company name
  • Tax code or VAT number
  • Billing address: street, postcode, city, country
  • Shipping address: street, post code, city, country
  • Telephone number
  • Email address
  • Attached file
  • Note

The legal basis for data processing for ordering purposes is Article 6 paragraph 1 lit. a of the GDPR 2016/679 based on consent given voluntarily as well as on article 6 paragraph 1 lett. b of the GDPR 2016/679 to fulfill the contract. The personal data collected by us will be stored until the legal retention period expires and subsequently deleted, unless required to keep them for a longer period of time pursuant to Article 6, paragraph 1, sentence 1 lett. c of the GDPR 2016/679.

Payment information

Payment for the services provided through our SITE can also be made through PayPal. The provider of this payment service is PayPal (Europe) S.à.rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”). In case of payment via PayPal, the entered payment data will be transmitted to PayPal. Your data will be transmitted to PayPal on the basis of Article 6 paragraph 1 lett. a of the GDPR 2016/679 and Art. 6 Paragraph 1 lett. b of the GDPR 2016/679.

Reserved area (Account)

Registration and access data that you entered on the SITE when creating your Account. Legal basis for the processing of personal data Art. 6 paragraph 1 lett. a of the GDPR 2016/679 (consent through clear confirmation actions or behaviors). The purpose of data processing is to allow you to use a separate access area on our SITE.
If you have forgotten your password or username for this area, you can receive this data again after entering your contact details (e-mail address) and requesting the recovery of your login credentials. Usage data resulting from the use of the login area is collected, saved and processed by us only to combat its misuse, to correct faults or to maintain functionality. The data is not used for other purposes or passed on to third parties.
The collected data will be kept as long as you have a user account with us. The data collected as part of the “Forgot Username or Password” feature will only be used to resend forgotten login details.
The objection and deletion possibilities are based on the general rules for the right of opposition and deletion under the data protection law described below in this data protection declaration.

Sending promotional and commercial material by e-mail

We use the data entered to complete orders that have been contracted in the exercise of a Soft Spam activity (Consent Not Required). The legal basis is to pursue pursuant to article 6 par.1 lett. f) of the GDPR 2016/679 a legitimate interest on the part of the data controller and in accordance with article 130 paragraph 4 of Legislative Decree 196/2003.

Newsletter

To send the newsletter, we use the so-called double opt-in procedure, i.e. we will only send a newsletter by e-mail if you have previously expressly authorized us to activate the newsletter service. We will then send you an e-mail notification and ask you to confirm whether you wish to receive our newsletter by clicking on a link in the e-mail.

When you register for our newsletter, we save your IP address and the registration date. This archive serves only as evidence in the event that a third party misuses your e-mail address to register for the newsletter without your knowledge or authorization. If you later no longer wish to receive newsletters from us, you can unsubscribe at any time via the “Unsubscribe” link in all our promotional and / or commercial e-mails.

At any time, you can request the cancellation of your subscription to the newsletter by writing to privacy@ilaire.com indicating as subject “Request for Cancellation of Newsletter Subscription” and reporting the e-mail address with which he subscribed.

Use of Cookies

Our SITE uses cookies. Most of the cookies we use are automatically deleted from your hard drive after the end of the browser session (hence session cookies).
However, there are also cookies that remain on your hard drive. On another visit, it is automatically recognized that you have already been with us and which entries and settings you prefer (so-called long-term cookies). These long-term cookies therefore make it unnecessary to enter the password or fill in forms with data for subsequent orders.
You can disable the use of cookies in your browser settings. Without the use of cookies, however, some functions of our SITE may only function to a limited extent.
The legal basis for the processing of data in the form of cookies is Article 6, paragraph 1, clause 1 lett. f of the GDPR 2016/679.

Transfer of data to non-EU countries

Personal data collected through the SITE may be transferred outside the national territory, solely and exclusively for the execution of the services requested through the SITE and in compliance with the specific provisions of the Regulations. Some personal data may be shared with recipients located outside the European Economic Area. ILAIRE ITALIAN COSMETICS SRL ensures that the processing of personal data by these recipients takes place in compliance with the Regulations.
This SITE may share some of the data collected with services located outside the European Union area. In particular, with Google, Facebook (Facebook, Instagram and WhatsApp) Microsoft (LinkedIn) and Twitter through social plugins and the Google Analytics service. The transfer is authorized on the basis of specific decisions of the European Union and the Guarantor for the protection of personal data, in particular decision 1250/2016 (Privacy Shield), for which no further consent is required. The companies mentioned above guarantee their adherence to the Privacy Shield.

Social Network

In addition to our SITE, we are also represented on the following online platforms and social networks:

We represent our company on these platforms, provide information about our offers and communicate with our customers and potential customers.
We generally only process personal data if you interact with our respective online presence page (Facebook, Instagram), for example if you make a comment, give a “Like” (click the Like button) or send us a message.
The legal basis for the processing of data in this regard is Article 6 paragraph 1 lett. b OF GDPR 2016/679 for requests in relation to contracts or data processing is based on the user’s consent pursuant to article 6 paragraph 1 lett. a of the GDPR 2016/679 when you send a comment, a “Like” or similar.
We analyze calls and interactions about our online presence. For this purpose, only anonymous data is provided to us. Please note that when using and accessing our online presence, your personal data will also be processed by their respective operating companies.
This SITE also incorporates plugins and / or buttons for social networks, in order to allow easy sharing of content on your favorite social networks. These plugins are programmed so as not to set any cookies when accessing the page, to safeguard the privacy of users. Eventually cookies are set, if so provided by social networks, only when the user makes effective and voluntary use of the plugin. Please note that if the user browses being logged into the social network then he has already consented to the use of cookies conveyed through this SITE at the time of registration to the social network.
The collection and use of information obtained by means of the plugin are governed by the respective privacy policies of the social networks, to which please refer.

Your rights

Pursuant to the GDPR and national legislation, the user can, in the manner and within the limits established by current legislation, exercise the following rights in relation to their personal data:

Right to information

According to article 15 of the GDPR 2016/679, you have the right to receive information on which of your data we process. This includes, among other things, information on how long and for what purpose we process the data, where it comes from and to which recipients or categories of recipients we transmit it. You can also receive a copy of this data by making a request.

Right to rectification

According to article 16 of the GDPR 2016/679, you have the right to immediately correct any information that is no longer applicable. You can also request the completion of your incomplete personal data. If this is required by law, we will also notify any third parties to whom your data has been provided.

Right to erasure (“right to be forgotten”)

According to article 17 of the GDPR 2016/679, you have the right to request the immediate cancellation of your personal data if one or more of the reasons indicated in article 17 of the GDPR 2016/679 is applicable.

Right to restriction of processing (blocking)

According to article 18 of the GDPR 2016/679, you have the right to ask us to limit the processing of your personal data if one of the requirements referred to in article 18 of the GDPR 2016/679 is met.

Right to withdraw consent

Pursuant to article 7, paragraph 3, of the GDPR 2016/679, it is possible to withdraw your consent at any time with future effect. This revocation can take the form of an informal message to the contact addresses indicated above.

Right to data portability

According to article 20 of the GDPR 2016/679, you have the right to receive personal data concerning you and that you have provided to us in a structured, common and machine-readable format and to transmit this data to others. Details and restrictions are reported in article 20 of the GDPR 2016/679. Exercising this right does not affect the right to erasure.

Right to lodge a complaint with the supervisory authority

Pursuant to Article 77 of the GDPR 2016/679, you have the right to lodge a complaint with one of the competent supervisory authorities or the respective supervisory authority in the member state of your residence, place of work or place of the alleged violation of the protection of data if you believe that the processing of your personal data violates the requirements of the GDPR 2016/679.

Right to object

Pursuant to article 21 of the GDPR 2016/679, you have the right to object to the processing of your personal data at any time. If the requirements for an effective objection are met, we will no longer process your personal data.

Declaration

To assert your rights, please contact us at our e-mail address: privacy@ilaire.com

Requests should be addressed to the Data Controller. In particular, the user can exercise his rights in relation to the processing of his personal data by accessing the address www.ilaire.com , for example by changing your online profile or canceling your subscription to our Newsletter, or by contacting the Data Controller at privacy@ilaire.com

We will respond to the request in accordance with the provisions of applicable laws. Users are invited to indicate in their request which personal data they wish to be modified, to notify us if they prefer that such data be deleted from our database or to specify what restrictions they wish to place on our use of their personal data.
It is important to keep in mind that we may need to keep some information for registration purposes and / or to complete transactions initiated by users before requesting a change or cancellation.

Safety

Your personal data will be encrypted while using our SITE. We use the SSL / TLS (Secure Sockets Layer / Transport Layer Security) encryption system.
We use technical and organizational security measures to protect your personal data from misuse, loss, destruction or access by unauthorized persons. Our security measures correspond to the current state of the art and are continuously improved in line with technological developments.
We are committed to using appropriate organizational, technical and administrative measures in order to protect Personal Data within our organization. However, no data transmission and no archiving system can be guaranteed to be 100% secure. Users who have reason to believe that their interaction with us is no longer secure, please report the problem to us immediately.
The processing is carried out using IT and / or telematic tools, with organizational methods and with logic strictly related to the purposes indicated. In addition to ILAIRE ITALIAN COSMETICS SRL, in some cases, categories of employees involved in the organization of the SITE (administrative, commercial, marketing, legal, system administrators) or external subjects (such as suppliers of third party technical services) may have access to the data. postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller. The updated list of Managers can always be requested from ILAIRE ITALIAN COSMETICS SRL.

Special information for parents

The pages and services of the SITE are not intended for children, as required by applicable laws, and we do not knowingly collect personal data from minors. ILAIRE ITALIAN COSMETICS SRL nevertheless undertakes to comply with the provisions of the law where these require the authorization of a parent or guardian to collect, use or disclose the personal data of minors.
We are committed to protecting the privacy of minors and invite parents and guardians to play an active role in their children’s online activities and interests. If a parent or guardian becomes aware that a minor child has provided us with their personal data without their consent, please contact us at privacy@ilaire.com . If we become aware that a minor has provided us with their personal data, we will delete them from our files.

Validity, updates and changes

The data protection declaration is currently valid and the last update was made in December 2020.
Due to the further development of our SITE or the implementation of new technologies or changed legal or official requirements, it may be necessary to change this data protection declaration. Therefore, we reserve the right to make changes at any time.
ILAIRE ITALIAN COSMETICS SRL invites users to periodically visit this page to stay updated on any changes. Furthermore, if such changes have an impact on the data relating to the User (for example if ILAIRE ITALIAN COSMETICS SRL intends to process the User’s personal data for purposes other than those previously communicated in this Information), ILAIRE ITALIAN COSMETICS SRL will inform the User before such changes take effect, publishing them with the utmost clarity on its SITE.