, with particular reference to the categories of Personal data concerned, the various processing purposes, the identity and contact details of the Data Controller, the privacy rights of Users and the safety measures the Site adopts to protect such rights.
Users with fewer than 16 (sixteen) years of age are not allowed to consent to the processing of Personal data without parental consent.
Personal data processed by the site. Purpose.
The Site processes various categories of Personal data in relation to different stages of the user journey: when Users browse the Site, complete orders, register to the Site or opt to receive marketing and commercial communications.
In particular, the Site processes a range of browsing data on the User's visits to the Site: for example, their IP address, browse information, operating system, the type of device used, an indication of the Site pages visited, the searches performed and other relevant information.
In such circumstance, the processing activities are fully automatized and only involve Personal data strictly necessary for browsing the Site or to make the User experience smoother in a time of increasingly responsive design.
Furthermore, the Site asks Users to disclose Personal data during the process for registration on the Site and/or to complete a product order. These types of processing activities involve Personal data necessary or useful for the Site to perform a sales contract, supply services or to comply with accounting, tax and legal obligations. The Site always specifies whether the disclosure of Personal data by the User is optional or mandatory.
Users can also opt to receive marketing communications. In such circumstance, they will be asked to submit Personal data (e.g., e-mail address, etc.) and to consent to their processing for marketing and profiling purposes. Without such consent, the Site will never send marketing communications to Users who have never carried out any purchase on the Site nor carry out any profiling activities with respect to their Personal data.
"Profiling" means that, upon explicit consent of Users to the lawful processing of their Personal data, the Site is able to send marketing communications tailored on the browsing activities, interests and purchase preferences of Users, instead of random communications.
The Site makes use of geo-location systems enabling Users to enjoy the "Store Location" feature, which consequently identifies the geographical coordinates of where the User's device is located. Users may enable or disable this feature by changing the settings of their device.
It is possible that the Site will perform checks, either directly or indirectly, on the payment instruments adopted by Users in order to prevent insolvency, fraudulent activities, or in accordance with the regulations on money laundering which may apply at any given time.
Refusal to give consent to the processing of Personal data for purposes that are not necessary to browse the Site, complete orders or use other services provided by the Site will not result in any significant consequences.
Storage of Personal data
The Site stores and retains Personal data in an adequate manner and for an appropriate timeframe in relation to the purposes of processing.
In order to determine the appropriate storage period for Personal data under the GDPR, the Site takes into account various factors to ensure that Personal data is not retained for a period longer than necessary.
Such factors also include the purpose for which the Site holds such Personal data and the type of relationship with Users (how often the User logs into the Site account, how often the User browse or buy on the Site and other aspects).
Users can always withdraw their consent from receiving newsletters and marketing communications in the following ways:
Through their account settings;
By clicking on the â€˜unsubscribe' link at the end of each email;
By contacting the Customer service.
Based on the legitimate interest of improving its services to customers, the Site may send email communications with product promotions, discounts, suggestions, feedback requests or updates to customers. Customers are always free to unsubscribe from such email communications at any time.
The Site will promptly delete or anonymize Personal data that is no longer needed or retained according to the law.
Who is the Data Controller
Tucano Urbano S.r.l. with headquarters in Via della Liberazione, 10 Peschiera Borromeo (MI) , VAT number IT12732100156 (mail: email@example.com)
and Officina Idee Srl with headquarters in Via Spreafico 3, 20052 Monza (MB), Italy, VAT number IT03051020968 (mail:
firstname.lastname@example.org) are the joint Data controllers that determine the purposes and means of the processing of Personal data
To which third parties Personal data is disclosed
The Controllers disclose Personal Data of Users to third-party partners and suppliers involved in the fulfilment of purchase orders, both during and after the sale stage, including, but not limited to, couriers, customer service management companies, advertising and marketing service providers and email service providers.
Personal data is not transferred outside the European Union without the User's consent or unless such transfer is allowed by the applicable law on other grounds.
It is also possible that the information may be disclosed to companies affiliated with or controlled by the Controllers, or to third parties in the event of business restructurings, in full compliance with the applicable regulations.
The foregoing is without prejudice to the communication or disclosure of Personal data when required by the applicable law or when there is a general disclosure obligation.
The rights of Users
Under the GDPR, Users have the right to:
Be informed about how the Site uses Personal data;
Access and receive a copy of any Personal data the Site holds about them;
Have their Personal data rectified when incorrect and/or outdated and/or incomplete;
Ask for the erasure or deletion of Personal data ("the right to be forgotten"), save exceptions: in some cases, the Site holds the right or obligation to retain Personal
data under legal or legitimate grounds;
Object to direct marketing, profiling and automated decision making;
Withdraw consent for Personal data processing based on consent, easily and at any time;
Object to processing of Personal data based on legitimate interests;
Lodge a complaint with the competent supervisory authority;
Move, copy or transfer their Personal data provided to the Site, when processing is based on a contract or on consent, and the processing is carried out by automatic means ("the right to data portability");
Restrict the processing of Personal data in those cases allowed by the GDPR.
For any questions or requests concerning the processing of Personal Data and to exercise the rights mentioned above, Users can contact the Controllers at the following email address: email@example.com
The Site adopts the safety measures required by applicable law to ensure the protection of the User's Personal data. For instance, measures for computer authentication (as necessary), procedures for managing authentication credentials, authorization systems, procedures for storing backups, and restoring access to data and systems have been adopted. Furthermore, personal and identifying data are used only when necessary for the purposes for which they were collected and subsequently processed.
Only authorized employees of the Controllers, and authorized employees of the third-party suppliers, acting as data processors on behalf of the Controller, have access to Personal data related to the Site activities. Data processing agreements are in place with such data processors to ensure that they always meet the level of security required by the GDPR while processing personal Data related to the Site activities.
Cookies are small text strings that the Site sends to the User's device where they are then stored for various purposes ("Cookies").
Certain categories of Cookies function only to allow browsing on the Site or to enable its basic features; it is the case of â€œNavigationâ€�, â€œSessionâ€� or â€œFunctionalâ€� Cookies, allowing the User to navigate on the Site based on a number of selected criteria (such as, for instance, the preferred language or the products which have been selected for purchase). These are usually defined as "Technical" Cookies.
Disabling Technical Cookies may limit the ability to use the Site and to enjoy its features or the services it offers.
Other Cookies used by the Site or by third-parties are permanent cookies to track the User's overall activity online and used for the purpose of profiling a User through the processing of Personal data. They are called "Profiling Cookies".
The User's prior consent is strictly required for the use of Profiling Cookies.
Below follows a full list of the Profiling Cookies used by the Site:
The Site does not have any access or control over Cookies or any other tracking technologies used by third-party websites or platforms that are accessible through the Site, nor can ensure the compliance of such third-parties with the applicable law.
Updated: 25 May 2018.