Be advised that changing your location while shopping will remove all the contents from your shopping bag.
Full disclosure - Gift Card
Who are we, and what do we do with your personal data?
The Company NOMINATION SRL, Via F.lli Bandiera 22, 50019 Sesto Fiorentino (FI) (hereinafter also referred to as the Owner), as data controller, is concerned with the confidentiality of your personal
data and with guaranteeing that they are protected from any event that might put them at risk of being breached.
To this end, the Owner implements policies and practices concerning collecting and using personal data and exercising your rights under applicable law. The Owner ensures the updating of the policies
and practices adopted for the protection of personal data whenever necessary and, in any case, in the event of regulatory and organisational changes that may affect the processing of your personal data.
The Owner has appointed a data protection officer (DPO) whom you can contact if you have any questions about its policies and practices.
You can contact the DPO/DPO at the addresses and contact information below:
How does the Owner collect and process your data?
The Owner collects and/or receives information about you, such as:
Personal information about you will be processed for:
1) the management of the contractual relationship and the consequent fulfilments, including regulatory ones
The processing of your personal data takes place for carrying out the preliminary and subsequent activities for the management of the relationship established, for the management of the gift card,
payments in the event of purchase, the processing of complaints, as well as for the fulfilment of any other obligations arising from the relationship, such as the registration and archiving of your personal data.
The obligations to be fulfilled by the Controller in connection with the relationship established and the specific regulations governing it are, inter alia, those of
- bookkeeping (only in the case of a purchase via a gift card).
Your personal data is also processed to prevent fraud, including contractual fraud. Finally, your data (such as your e-mail address) will be processed to provide you with assistance on the services covered by the contract, including customer service via whats app business.
Your personal data may also be used to send you specific communications and information relating to contractual obligations or deadlines, the way the service is provided or any operational needs of the company. Subject to necessity, relevance and non-excessiveness, such notices may be made by telematic means (e-mail).
2) Disclosure to third parties and recipients
Your personal data is processed in connection with the contract and the obligations arising from there, including statutory and/or regulatory obligations.
Your data will not be disclosed to third parties/ recipients for their own purposes unless:
- you give permission.
Your data will specifically be disclosed to third parties/recipients if:
- It is necessary for the fulfilment of obligations relating to the contract and the laws governing it (e.g. for the defence of your rights, for reporting to the supervisory authorities, etc.);
- communication is made to IT Consultants, Consultants possibly involved in administrative and accounting management.
3) for information security purposes
The Owner processes, including through its suppliers (third parties and/or recipients), your personal data to the extent strictly necessary and proportionate to ensure the security and ability of a network
or servers connected to it to resist, at a given level of security, unforeseen events or unlawful or malicious acts that compromise the availability, authenticity, integrity and confidentiality of the personal data retained or transmitted.
For these purposes, the Owner provides procedures for handling data breaches.
What happens if you do not provide your data?
If you do not provide your personal data, the Owner will not be able to carry out the processing linked to the management of the contract and the servic
The Owner intends to carry out certain processing operations in accordance with certain legitimate interests that do not affect your right to privacy, such as those that:
- enable the prevention of IT incidents and the notification to the supervisory authority or the communication to users, if necessary, of the personal data breach;
- allow communication to third parties/recipients for activities related to those of contract
management.
How, where and for how long are your data stored?
How
Data is processed using paper or computer procedures by specially authorised and trained internal persons. They are allowed access to your personal data to the extent and within limits necessary for the performance of the processing activities concerning you. The Data Controller periodically checks how your data are processed and the security measures foreseen for them and provide for them to be constantly updated; checks, also through the persons authorised to process them, that no personal data are collected, processed, filed or stored, that do not need to be processed; checks that the data are stored with a guarantee of integrity and authenticity and that they are used for the processing carried out.
Where
The data are stored in paper, computer and electronic archives located within the European Economic Area, except for the cases mentioned below, and adequate security measures are ensured.
How long
Personal data processed by the Controller are stored:
-If no purchase is made with the gift card until the expiry of the terms indicated on the card and after that until 1 month after expiry;
- if at least one purchase is made through the gift card for the time necessary to carry out the activities connected with the management of the contract with the Holder and for up to ten years after its conclusion (Art. 2946 of the Civil Code) or from when the rights that depend on it can be enforced (under Art. 2935 civil code); as well as for the fulfilment of obligations (e.g. tax and accounting obligations) that remain even after the conclusion of the contract (art. 2220 civil code), for which the Controller must only retain the data necessary for their fulfilment. This is without prejudice to cases in which the rights arising from the contract need to be asserted in court, in which case your data, only those necessary for such purposes, will be processed for the time necessary for their pursuit.
However, this does not affect your right to object at any time to processing based on legitimate interests for reasons related to your particular situation.
What are your rights?
Essentially, at any time and free of charge and without any specific charges or formalities for your request, you can;
- obtain confirmation of the processing carried out by the Owner;
- access your personal data and find out their origin (when the data are not obtained from you directly), the purposes and aims of the processing, the data of the persons to whom they are disclosed, the period of retention of your data or the criteria for determining this period;
-revoke consent at any time, in the event that this constitutes the basis for processing. The revocation of consent, however, does not affect the lawfulness of the processing based on consent carried out before the revocation itself;
- update or rectify your personal data so that they are always accurate and precise;
- delete your personal data from the Data Controller's databases and/or archives, including backup archives, in the event, among others, that they are no longer necessary for the purposes of the processing or if the processing is assumed to be unlawful, and provided that the conditions provided for by law are met; and in any case if the processing is not justified by another, equally legitimate reason;
- limit the processing of your personal data in certain circumstances, for example where you have contested its accuracy, for the period necessary for the Controller to verify its accuracy. You must also be informed promptly when the period of suspension has expired or the cause of the restriction on processing has ceased to exist, and the restriction has therefore been lifted;
- obtain your personal data, if received or processed by the Owner with your consent and/or if they are processed on the basis of a contract and by automated means, in electronic format also for the purpose of transmitting them to another data controller.
The Owner shall do so without delay and, in any event, no later than one month after receipt of your request. The deadline may be extended by two months, if necessary, considering the complexity and number of requests received by the Owner. In such cases, the Owner shall inform you within one month of receiving your request and let you know the reasons for the extension.
For any further information and to send your request, please get in touch with the Owner at the following e-mail address privacy@nomination.com
How and when can you object to the processing of your personal data?
For reasons relating to your specific situation, you may object, at any time, to the processing of your personal data if it is based on legitimate interest or if it concerns the processing of personal data whose supply is subject to your consent, by sending your request to the Owner at privacy@nomination.com
You have the right to delete your personal data if there is no legitimate reason other than that which gave rise to your request and, in any case, if you have objected to the processing.
Who can you complain to?
Notwithstanding any other administrative or judicial action, you may lodge a complaint with the competent supervisory authority or with the authority which carries out its duties and exercises its powers in Italy, where you have your habitual residence or work or, if this differs, in the Member State in which the breach of EU Regulation 2016/679 occurred.
Any updates to this policy will be communicated to you promptly and by appropriate means. You will also be informed if the Owner processes your data for purposes other than those set out in this policy before doing so and in time to give your consent if required.