Articles 13 and 14 of regulation (EU) 2016/679.
Interested parties: Users of e-commerce services.
“AEFFE SPA”, And "Drop Srl”as Data Controllers of your personal data, pursuant to and for the purposes of EU Regulation 2016/679 hereinafter 'GDPR', hereby inform you that the aforementioned legislation provides for the protection of data subjects with respect to the processing of personal data and that such processing will be based on principles of correctness, lawfulness, transparency and protection of your privacy and your rights. Your personal data will be processed in accordance with the legislative provisions of the aforementioned legislation and the confidentiality obligations provided for therein.
Aeffe Spa
Aeffe SPA is the controller of your personal data relating to registration on the online portal, orders placed and to respond to customer care requests received (points 1, 2, 3 of this information notice) and in general to guarantee the functions available on the website; as well as, subject to your free consent, for the optional marketing and profiling purposes described in points 4 and 5 of this information notice.
Drop Srl
Drop Srl is the owner of the processing of your personal data for the sole purposes necessary to comply with the regulatory obligations in tax and accounting matters arising from purchases made at the online shop of the site.
Legal basis: legal obligation and contractual obligation.
Data source: the data is collected by Aeffe SpA directly from the interested party during registration on the website or during the purchase of a product without registration or even in the context of online promotional campaigns (e.g. campaigns on social networks). Drop Srl acquires the interested party's data, as data controller, through the Aeffe SpA website, following a purchase.
Purpose and legal basis of the processing: your data will be processed to guarantee the available functions, including the management of the shopping cart (Shopping bag), for the selection of one or more items, to store the contents of the cart from the last time you connected, commercial transactions with the payment methods you have chosen and other accessory and functional services to facilitate your choice of items, as well as, when required, invoicing in application of the law, logistics for transport, delivery, collection, and possibly for after-sales activities and verification of the efficiency of the service. The Data Controllers hereby inform you that the authentication process for your account with the payment service provider chosen for the purchase of one or more products from the Store (including PayPal, Scalapay, Klarna, etc.) is managed by the same provider as an independent data controller.
1) Registration on the portal: Registration on the portal is essential for your correct identification in anticipation of and in the face of a purchase. Registration will allow you to create your own user profile without having to re-enter your data for subsequent purchases. Your data relating to your residential address, any shipping address (if different from your residence), your tax code if required by law, and your purchase history will be stored in the user profile. You may request the cancellation of your user profile at any time.
Data Controller: Aeffe SpA
2) Purchase (even without registration): it is possible to make an online purchase even without registering on the portal, the processing of your data will take place exclusively for your correct identification, to allow you to purchase and ship in application of the general conditions of sale, and to allow invoicing in accordance with the law.
Data controller: Aeffe SpA and Drop srl for invoicing.
3) Customer care/Customer service Online shop: management and responses to any reports, requests for post-sale information (including order status and tracking), purchase assistance, returns, refunds, order cancellations and complaints submitted by the Customer, in compliance with the general conditions of sale, via the online forms and paper forms made available by Aeffe SpA on the website. This purpose also includes the processing of photos/images of the products where necessary to process the request, in compliance with the general conditions of sale.
Data Controller: Aeffe SpA
The legal basis for processing for purposes 1, 2, and 3 is pre-contractual and contractual in the terms in which data processing is provided for preliminary operations to the purchase and the purchase itself. To allow invoicing of purchases, the legal basis is the legal obligation.
Consequences of failure to communicate: the processing of data is necessary in response to the customer's request for the purposes indicated, any failure to communicate, or incorrect communication, of one of the mandatory information, may cause the impossibility of the Owners to guarantee the purchase of the products and additional services requested.
Optional purposes: the purposes described below in points 4 and 5 are optional and not mandatory, their implementation is based exclusively on your consent. In particular, two different consents are required: the first (point 4) for the sending of promotional communications by Aeffe SpA as data controller - the second (point 5) for profiling (define your profile, analyze habits or consumption choices, so as to suggest, in various ways, the offers deriving from your preferences). At any time you can revoke the consent given by accessing your personal area, after registration, as well as through the automatic methods present at the bottom of each email received or by sending a request to the contact details of the Data Controller Aeffe SpA privacy@aeffe.com.
4) Direct marketing: subject to your free consent, the Data Controller Aeffe SPA may process your data to satisfy market research, customer satisfaction surveys, statistics, invitations to events and for promotional activities also related to the sending of advertising and promotional material - via email, ordinary mail and/or text messages and/or telephone calls - other than those necessary to ensure the execution of the relationship. Such communications will also be sent via the Whatsapp channel upon express indication by the customer in the data collection form. In relation to the sending of promotional material to your email inbox, interactions with the communications sent may also be processed (e.g. email opening rate, any clicks on links and/or banners and/or buttons).
5) Profiling: in order to improve the search for products that can satisfy you, Aeffe SpA would like to use your data to define your profile, analyze habits or consumption choices, so as to suggest, in various ways, the offers deriving from your preferences, either through e-mails, newsletters or messages dedicated to you. Your data will also be used to personalize online advertisements, for example while browsing search engines or social platforms (e.g. Google, Pinterest, etc.).
The legal basis for processing for purposes 4 and 5 is the consent of the interested party.
Consequences of failure to consent for optional purposes: failure to consent to the optional purposes referred to in purposes 4 and 5 (Direct Marketing and Profiling) does not affect the purchase of products and the provision of the service.
How to withdraw consent: at any time, you may withdraw your consent, including for the use of additional contact channels, either by using the automatic unsubscribe options provided at the bottom of each email received or by sending a request to the Data Controller's contact details. To stop receiving promotional messages via WhatsApp, WeChat, and SMS, you can send a message with the word "STOP".
Treatment methods: the processing is carried out with manual and/or computerized and telematic tools, in order to guarantee the security, integrity and confidentiality of the data in compliance with the physical and logical organizational measures, provided for by the provisions in force, in order to minimize the risks of destruction or loss, unauthorized access, modification and unauthorized disclosure in compliance with the methods set out in articles 5, 32 of the GDPR.
Recipients: in order to carry out certain activities, or to provide support for the operation and organization of the activity, some data may be disclosed or communicated to recipients. These subjects are divided into:
Third parties: (communication to:natural or legal persons, public authorities, agencies or other bodies other than the data subject, the controller, the processor and authorised personsdata controllers) including:
- Aeffe Group companies within the scope of legitimate intra-group communications for internal administrative purposes;
- Drop Srl for the sole purposes necessary to comply with regulatory obligations in tax and accounting matters arising from purchases made at the site's online shop;
- Banking institutions for the management of collections and payments and third-party companies, for the same purposes, such as managers of the payment methods chosen by the interested party (including PayPal, Scalapay, Klarna, etc.);
- Company for the management of regulatory compliance in the tax and accounting fields related to the purchase (e.g. TaxFree compliance...);
- Companies that manage traditional or computerized postal services;
- Consultants and freelancers, including in association in legal matters, etc. as independent owners;
- Subjects/Entities, by legal obligation, possibly whose right to access your data is recognized by legal obligations;
- Any other subjects whose communication of data is necessary for the achievement of the purposes indicated above.
Data controllers: (the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller).
- Companies and other entities, consultants and freelancers who have been given mandates to manage mandatory fiscal, administrative, accounting, legal consultancy, etc. obligations;
- Marketing and online product search improvement service providers;
- Providers of IT, web, or other services necessary to achieve the purposes necessary for managing the relationship.
Inside the company structure: Your data will be processed only by personnel expressly authorised by the individual Data Controllers, with the assurance of adopting a confidentiality agreement.
Transfer of data to third countries: Aeffe SpA uses the hosting provider Cloudflare, Inc., located in the USA, a non-EU country. The Data Controller has verified the existence of adequacy decisions for the recipient country by the Commission, with particular reference to the registration of the provider in the Data Privacy Framework (adequacy decision of 10/07/2023, pursuant to art. 45 of the GDPR, “EU-US Data Privacy Framework”.). Other guarantee measures for the transfer to the recipients, depending on the case, may be: signing standard contractual clauses, verification of the adoption of any additional measures in implementation of recommendation 01/2020 EDPB. In derogation of these guarantees, for data processing (in ref. of art. 49 of the GDPR), where applicable, the existence of a contract or pre-contractual measures in favor of the interested party or consent to the transfer is verified. Your personal data of which Drop Srl is the Data Controller are processed by Drop Srl within the European Union and are not transferred to other non-EU countries.
Diffusion: Your personal data will not be disclosed in any way.
Retention Period: we inform you that, in compliance with the principles of lawfulness, purpose limitation, data minimization, pursuant to art. 5 of the GDPR, the retention period of your personal data necessary to perform the requested services, is established for a period of time not exceeding the achievement of the purposes for which they are collected.
In the event of registration on the portal, your data will be retained until you cancel your user account or following a period of inactivity of 5 years.
Data relating to optional purposes (4.Direct Marketing-5.Profiling) are retained until the consent is revoked, which can be requested either by accessing your personal area, or through the automatic methods present in the emails, or by sending the request to the contact details of the Data Controller. At the end of 2 years from the acquisition of the consent, a communication will be sent to the contact channels provided to allow the revocation of the consent or the continuation of the same.
With the same methods and guarantees of data protection, if you have made a purchase, the same may be stored for a period of time in compliance with the obligations prescribed by the laws in force, for example on the basis of tax legislation for at least 10 years.
Data Controller: the Data Controller, pursuant to the legislation is “AEFFE SPA”, with registered office in Via delle Querce 51 - 47842 San Giovanni in Marignano (RN) VAT number: 01928480407, Tel: +39 0541965211 in the person of its legal representative pro tempore. By sending an email to the following addressprivacy@aeffe.com. You may request further information regarding the data provided.
The Data Protection Officer (“DPO”) for Aeffe SpA is Studio Paci & C. Srl (Contact Dr. Gloriamaria Paci) contactable at the following address: dpo.aeffe@studiopaciecsrl.it, telephone: +39 05411795431, PEC: studiopaciecsrl@pec.it.
Data Controller for the sole purposes related to compliance with regulatory obligations in fiscal and accounting matters arising from purchases made at the site's online shop: the Data Controller is Drop Srl withifde legale in Montegranaro (FM), via Sandro Pertini n.1, postcode 63812, Fiscal Code, registration number in the Marche Companies Register and VAT number 01383870431, E-mail privacy@drop.it.
The Data Protection Officer (“DPO”) for Drop Srl can be contacted at the following email address: dpo@drop.it.
EU Regulation 2016/679: Articles 15, 16, 17, 18, 19, 20, 21, 22 - Rights of the interested party
1. The exercise of rights is guaranteed by both data controllers, respectively for the purposes of their competence, by writing to the contact details indicated above. The interested party has the right to obtain confirmation of the existence or otherwise of personal data concerning him, even if not yet registered, and their communication in an intelligible form.
2. The interested party has the right to obtain the indication:
- of the origin of the personal data;
- the purposes and methods of processing;
- of the logic applied in case of processing carried out with the aid of electronic instruments;
- of the identifying details of the owner, the managers and the designated representative pursuant to Article 5, paragraph 2;
- the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of them in their capacity as designated representative in the territory of the State, managers or persons in charge.
3. The interested party has the right to obtain:
- the updating, rectification or, when there is interest, the integration of the data;
- the cancellation, transformation into anonymous form or limitation of data processed in violation of the law, including data whose retention is not necessary in relation to the purposes for which the data were collected or subsequently processed;
- certification that the operations referred to in letters a) and b) have been brought to the attention, also with regard to their content, of those to whom the data have been communicated or disclosed, except in the case in which such fulfillment proves impossible or involves the use of means manifestly disproportionate to the right protected;
- data portability.
4. The interested party has the right to object, in whole or in part:
- for legitimate reasons to the processing of personal data concerning him/her, even if pertinent to the purpose of the collection;
- to the processing of personal data concerning him/her for the purpose of sending advertising or direct sales material or for carrying out market research or commercial communication.
The interested parties, if the conditions are met, also have the right to lodge a complaint with the Guarantor as the supervisory authority according to the procedures provided. For any further information, and to assert the rights granted to you by the European Regulation, you may contact the data controller at the references above.
Consent - Form for obtaining consent from the interested party
Having acquired the information provided by the data controller through the information notice, your registration to the website will be recorded, identifying the IP address associated with your data, the time and date of registration. Your possible consents to processing for direct marketing and profiling purposes respectively points (4) and (5) will be recorded (IP address, e-mail, date and time) by ticking/clicking the relevant box, and immediately after pressing the "send"/"ok"/"register" button. These consents will be archived to prove their granting, and to allow you to revoke them at any time, in addition to all the other rights set out above.