The information is also provided pursuant to art. 13 of EU Regulation 2016/679 applicable from 25 May 2018 – General Regulation for the Protection of Personal Data (hereinafter referred to as GDPR) to those who interact with the web services of ILAIRE ITALIAN COSMETICS SRL accessible electronically from the address https://www.ilaire.com or, alternatively, also reachable from the address https://www.ilaire.it.
The information is provided only for the SITE https://www.ilaire.com (hereinafter referred to as the SITE) and not for other websites that may be consulted by the user through links and complies with Recommendation no. 2/2001 relating to the minimum requirements for online data collection in the European Union, adopted on 17 May 2001 by the Article 29 Working Group.
For the purposes of applicable data protection legislation, it is necessary to take into account the following: when we speak of “personal data” or “personal information”, we mean all information concerning a person that allows him to be identified. This does not include data from which the identity has been removed (anonymous data).
To access some areas of the SITE or make the purchase of products and / or services, some requested data are mandatory and indicated as such. Failure to provide the information marked as mandatory may make it impossible to manage the registration as a customer or the use of services available on the SITE.
As specified in the General Conditions of Sale, the services offered by ILAIRE ITALIAN COSMETICS SRL are aimed at people over the age of 18. Should the Data Controller become aware of the processing of data of minors under 18 years of age without valid consent of the parents or of a legal guardian, it reserves the right to unilaterally interrupt the use of the service offered, as well as to cancel the acquired data.
For anything not expressly defined in this Declaration on the protection of personal data, please refer to the General conditions of sale.
Owner of the data processing
Responsible pursuant to ARTICLE 4, PARAGRAPH 7, OF GDPR 2016/679 and other national data protection laws of the Member States and other data protection regulations is:
ILAIRE ITALIAN COSMETICS SRL
Via Brescia, 7
25081 Bedizzole (BS) – Italy
VAT / CF 04212220984
Responsible for data protection
Dr. Ilaria Prandelli
Via Brescia, 7
25081 Bedizzole (BS) – Italy
Data processing when visiting our site
In principle, it is possible to visit our SITE without providing personal data. It is designed to collect as little data as needed. The data is collected to the extent and for the purposes described below.
Types of data processed
The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected to be associated with identified data subjects, but which by their very nature could, through processing and association with data held by third parties, allow users to be identified.
This category of data includes the IP addresses or domain names of the computers used by users who connect to the SITE, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the user’s IT environment.
Data provided voluntarily
The optional, explicit and voluntary sending of e-mails to the addresses indicated on this SITE entails the subsequent acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data entered therein.
Method and place of processing
Personal data are processed with automated tools for the time necessary to achieve the purposes for which they were collected. Specific security measures are observed to prevent data loss, illicit or incorrect use and unauthorized access.
The data collected by the SITE are processed at the ILAIRE ITALIAN COSMETICS SRL headquarters and at the web hosting datacenter. Siteground web hosting, which is responsible for data processing, processing data on behalf of ILAIRE ITALIAN COSMETICS SRL, is located in the European Economic Area and acts in accordance with European standards.
Collection and purpose of the processing of personal data
The Personal Data provided through the SITE will be processed by ILAIRE ITALIAN COSMETICS SRL for the following purposes:
Services offered on our SITE
When you visit our SITE, we automatically collect and process your data in order to maintain the compatibility of our SITE for as many visitors as possible and to combat abuse and troubleshooting. For this it is necessary to record the technical data of the accessing computer in order to be able to react as soon as possible to display errors, attacks on our IT systems and / or errors in the functionality of our website. Furthermore, we use the data to optimize the WEBSITE and in general to ensure the security of our IT systems. In particular, we collect and process:
- Date and time of access
- The web address from which you arrived on our SITE
- The web pages you visit on our SITE
- Internet browser information (browser type and version)
- The operating system of the device with which you access our SITE and our services
- Your internet service provider
- IP address of your device
The data indicated are processed for the following purposes:
- Ensure a smooth connection to the SITE
- Ensure comfortable use of our SITE
- System security assessment
- Other administrative purposes
The legal basis for data processing to provide our SITE and our services is Article 6 (1) lett. f of the GDPR 2016/679. These data are used only to obtain anonymous statistical information on the use of the SITE and to check its correct functioning and are deleted immediately after processing. The data could be used to ascertain responsibility in the event of hypothetical computer crimes against the SITE: except for this possibility, the data on web contacts do not persist for more than thirty days.
To contact us, there is a contact form on our SITE. We use the data provided via the contact form to process your request. We are not responsible if your data is provided to us without your knowledge by third parties and we will immediately delete it from the moment we become aware of the unlawful communication of the personal data of others.
We only collect and process your personal data if you provide it voluntarily. These include:
- Name and surname
- Telephone number
- Email address
- Company name
- Your message
- Attached file
The legal basis for the processing of user data in order to contact us is Article 6 paragraph 1 lit. a of the GDPR 2016/679 based on your consent voluntarily given. The personal data collected by us for the use of the contact form will be automatically deleted after processing the request.
Offers and orders
In order to process offers and orders, we collect and process the following data, which are necessary to conclude the order and enter into the contract according to the General Conditions of Sale. We only collect and process your personal data if you provide it voluntarily. These include:
- Name and surname
- Company name
- Tax code or VAT number
- Billing address: street, postcode, city, country
- Shipping address: street, post code, city, country
- Telephone number
- Email address
- Attached file
The legal basis for data processing for ordering purposes is Article 6 paragraph 1 lit. a of the GDPR 2016/679 based on consent given voluntarily as well as on article 6 paragraph 1 lett. b of the GDPR 2016/679 to fulfill the contract. The personal data collected by us will be stored until the legal retention period expires and subsequently deleted, unless required to keep them for a longer period of time pursuant to Article 6, paragraph 1, sentence 1 lett. c of the GDPR 2016/679.
Payment for the services provided through our SITE can also be made through PayPal. The provider of this payment service is PayPal (Europe) S.à.rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”). In case of payment via PayPal, the entered payment data will be transmitted to PayPal. Your data will be transmitted to PayPal on the basis of Article 6 paragraph 1 lett. a of the GDPR 2016/679 and Art. 6 Paragraph 1 lett. b of the GDPR 2016/679.
Reserved area (Account)
Registration and access data that you entered on the SITE when creating your Account. Legal basis for the processing of personal data Art. 6 paragraph 1 lett. a of the GDPR 2016/679 (consent through clear confirmation actions or behaviors). The purpose of data processing is to allow you to use a separate access area on our SITE.
If you have forgotten your password or username for this area, you can receive this data again after entering your contact details (e-mail address) and requesting the recovery of your login credentials. Usage data resulting from the use of the login area is collected, saved and processed by us only to combat its misuse, to correct faults or to maintain functionality. The data is not used for other purposes or passed on to third parties.
The collected data will be kept as long as you have a user account with us. The data collected as part of the “Forgot Username or Password” feature will only be used to resend forgotten login details.
The objection and deletion possibilities are based on the general rules for the right of opposition and deletion under the data protection law described below in this data protection declaration.
Sending promotional and commercial material by e-mail
We use the data entered to complete orders that have been contracted in the exercise of a Soft Spam activity (Consent Not Required). The legal basis is to pursue pursuant to article 6 par.1 lett. f) of the GDPR 2016/679 a legitimate interest on the part of the data controller and in accordance with article 130 paragraph 4 of Legislative Decree 196/2003.
To send the newsletter, we use the so-called double opt-in procedure, i.e. we will only send a newsletter by e-mail if you have previously expressly authorized us to activate the newsletter service. We will then send you an e-mail notification and ask you to confirm whether you wish to receive our newsletter by clicking on a link in the e-mail.
When you register for our newsletter, we save your IP address and the registration date. This archive serves only as evidence in the event that a third party misuses your e-mail address to register for the newsletter without your knowledge or authorization. If you later no longer wish to receive newsletters from us, you can unsubscribe at any time via the “Unsubscribe” link in all our promotional and / or commercial e-mails.
At any time, you can request the cancellation of your subscription to the newsletter by writing to email@example.com indicating as subject “Request for Cancellation of Newsletter Subscription” and reporting the e-mail address with which he subscribed.
However, there are also cookies that remain on your hard drive. On another visit, it is automatically recognized that you have already been with us and which entries and settings you prefer (so-called long-term cookies). These long-term cookies therefore make it unnecessary to enter the password or fill in forms with data for subsequent orders.
The legal basis for the processing of data in the form of cookies is Article 6, paragraph 1, clause 1 lett. f of the GDPR 2016/679.
Transfer of data to non-EU countries
Personal data collected through the SITE may be transferred outside the national territory, solely and exclusively for the execution of the services requested through the SITE and in compliance with the specific provisions of the Regulations. Some personal data may be shared with recipients located outside the European Economic Area. ILAIRE ITALIAN COSMETICS SRL ensures that the processing of personal data by these recipients takes place in compliance with the Regulations.
This SITE may share some of the data collected with services located outside the European Union area. In particular, with Google, Facebook (Facebook, Instagram and WhatsApp) Microsoft (LinkedIn) and Twitter through social plugins and the Google Analytics service. The transfer is authorized on the basis of specific decisions of the European Union and the Guarantor for the protection of personal data, in particular decision 1250/2016 (Privacy Shield), for which no further consent is required. The companies mentioned above guarantee their adherence to the Privacy Shield.
In addition to our SITE, we are also represented on the following online platforms and social networks:
We represent our company on these platforms, provide information about our offers and communicate with our customers and potential customers.
We generally only process personal data if you interact with our respective online presence page (Facebook, Instagram), for example if you make a comment, give a “Like” (click the Like button) or send us a message.
The legal basis for the processing of data in this regard is Article 6 paragraph 1 lett. b OF GDPR 2016/679 for requests in relation to contracts or data processing is based on the user’s consent pursuant to article 6 paragraph 1 lett. a of the GDPR 2016/679 when you send a comment, a “Like” or similar.
We analyze calls and interactions about our online presence. For this purpose, only anonymous data is provided to us. Please note that when using and accessing our online presence, your personal data will also be processed by their respective operating companies.
The collection and use of information obtained by means of the plugin are governed by the respective privacy policies of the social networks, to which please refer.
Pursuant to the GDPR and national legislation, the user can, in the manner and within the limits established by current legislation, exercise the following rights in relation to their personal data:
Right to information
According to article 15 of the GDPR 2016/679, you have the right to receive information on which of your data we process. This includes, among other things, information on how long and for what purpose we process the data, where it comes from and to which recipients or categories of recipients we transmit it. You can also receive a copy of this data by making a request.
Right to rectification
According to article 16 of the GDPR 2016/679, you have the right to immediately correct any information that is no longer applicable. You can also request the completion of your incomplete personal data. If this is required by law, we will also notify any third parties to whom your data has been provided.
Right to erasure (“right to be forgotten”)
According to article 17 of the GDPR 2016/679, you have the right to request the immediate cancellation of your personal data if one or more of the reasons indicated in article 17 of the GDPR 2016/679 is applicable.
Right to restriction of processing (blocking)
According to article 18 of the GDPR 2016/679, you have the right to ask us to limit the processing of your personal data if one of the requirements referred to in article 18 of the GDPR 2016/679 is met.
Right to withdraw consent
Pursuant to article 7, paragraph 3, of the GDPR 2016/679, it is possible to withdraw your consent at any time with future effect. This revocation can take the form of an informal message to the contact addresses indicated above.
Right to data portability
According to article 20 of the GDPR 2016/679, you have the right to receive personal data concerning you and that you have provided to us in a structured, common and machine-readable format and to transmit this data to others. Details and restrictions are reported in article 20 of the GDPR 2016/679. Exercising this right does not affect the right to erasure.
Right to lodge a complaint with the supervisory authority
Pursuant to Article 77 of the GDPR 2016/679, you have the right to lodge a complaint with one of the competent supervisory authorities or the respective supervisory authority in the member state of your residence, place of work or place of the alleged violation of the protection of data if you believe that the processing of your personal data violates the requirements of the GDPR 2016/679.
Right to object
Pursuant to article 21 of the GDPR 2016/679, you have the right to object to the processing of your personal data at any time. If the requirements for an effective objection are met, we will no longer process your personal data.
To assert your rights, please contact us at our e-mail address: firstname.lastname@example.org
Requests should be addressed to the Data Controller. In particular, the user can exercise his rights in relation to the processing of his personal data by accessing the address www.ilaire.com , for example by changing your online profile or canceling your subscription to our Newsletter, or by contacting the Data Controller at email@example.com
We will respond to the request in accordance with the provisions of applicable laws. Users are invited to indicate in their request which personal data they wish to be modified, to notify us if they prefer that such data be deleted from our database or to specify what restrictions they wish to place on our use of their personal data.
It is important to keep in mind that we may need to keep some information for registration purposes and / or to complete transactions initiated by users before requesting a change or cancellation.
Your personal data will be encrypted while using our SITE. We use the SSL / TLS (Secure Sockets Layer / Transport Layer Security) encryption system.
We use technical and organizational security measures to protect your personal data from misuse, loss, destruction or access by unauthorized persons. Our security measures correspond to the current state of the art and are continuously improved in line with technological developments.
We are committed to using appropriate organizational, technical and administrative measures in order to protect Personal Data within our organization. However, no data transmission and no archiving system can be guaranteed to be 100% secure. Users who have reason to believe that their interaction with us is no longer secure, please report the problem to us immediately.
The processing is carried out using IT and / or telematic tools, with organizational methods and with logic strictly related to the purposes indicated. In addition to ILAIRE ITALIAN COSMETICS SRL, in some cases, categories of employees involved in the organization of the SITE (administrative, commercial, marketing, legal, system administrators) or external subjects (such as suppliers of third party technical services) may have access to the data. postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller. The updated list of Managers can always be requested from ILAIRE ITALIAN COSMETICS SRL.
Special information for parents
The pages and services of the SITE are not intended for children, as required by applicable laws, and we do not knowingly collect personal data from minors. ILAIRE ITALIAN COSMETICS SRL nevertheless undertakes to comply with the provisions of the law where these require the authorization of a parent or guardian to collect, use or disclose the personal data of minors.
We are committed to protecting the privacy of minors and invite parents and guardians to play an active role in their children’s online activities and interests. If a parent or guardian becomes aware that a minor child has provided us with their personal data without their consent, please contact us at firstname.lastname@example.org . If we become aware that a minor has provided us with their personal data, we will delete them from our files.
Validity, updates and changes
The data protection declaration is currently valid and the last update was made in December 2020.
Due to the further development of our SITE or the implementation of new technologies or changed legal or official requirements, it may be necessary to change this data protection declaration. Therefore, we reserve the right to make changes at any time.
ILAIRE ITALIAN COSMETICS SRL invites users to periodically visit this page to stay updated on any changes. Furthermore, if such changes have an impact on the data relating to the User (for example if ILAIRE ITALIAN COSMETICS SRL intends to process the User’s personal data for purposes other than those previously communicated in this Information), ILAIRE ITALIAN COSMETICS SRL will inform the User before such changes take effect, publishing them with the utmost clarity on its SITE.