Privacy policy

Premise

Dear User,

this Privacy Policy is provided to you in accordance with art. 13 of Regulation 2016/679/EU - concerning the protection of natural persons with regard to the processing of personal data, as well as the free circulation of such data (hereinafter also referred to as “the Regulation” or “GDPR”).

Within this Privacy Policy you will find information relating to the processing of your personal data, resulting from browsing within the web spaces and the use of the services made available to you through the website.

You will be provided with specific and/or supplementary information on the processing of your personal data on each occasion we collect them, in your interaction with the website or by virtue of contractual relationships established with our Company.

 

Definitions

Privacy Regulation: The GDPR, the Data Protection Code, the Provisions of the Guarantor and in general all the legislation on the protection of natural persons with regard to the processing of Personal Data.

GDPR or Regulation: European Union Regulation 2016/679 of 27th April 2016 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation).

Personal Data: Any information relating to an identified or identifiable natural person. In addition to the data provided by the User through any forms within the individual areas of the Web Services, the data relating to his/her navigation should also be understood as such.

Data Subject or Interested Party: The identified or identifiable natural person to whom the Personal Data refers.

Browsing data: The computer systems and software procedures used to operate the Web Services acquire, during their normal operation, some data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected to be associated with identified data subjects, but which by their very nature could allow users to be identified through processing and association with data held by third parties.

Browsing data include:

  • the IP addresses or domain names of the computers used by users connecting to the website;
  • the URI (Uniform Resource Identifier) addresses of the requested resources;
  • the time of the request;
  • the method used to submit the request to the server;
  • the size of the file obtained in response;
  • the numerical code indicating the status of the response given by the server (successful, error, etc.);
  • other parameters relating to the operating system and the IT environment of the User.

Data provided by the User: These are the data that the User voluntarily and knowingly transmits by sending communications (e.g., by e-mail, to the addresses present within the web domain) or by filling out the appropriate forms.

The Data provided by the User are only those strictly necessary for the purposes each time pursued. By way of example, such data may be:

  • personal data;
  • regarding contact details (e.g., e-mail address);
  • referable to the contractual position of the User-Customer;
  • geolocation (if the User has given consent to the collection of data relating to his/her location);
  • concerning the use of individual Services made available to the User;
  • regarding facts and events exposed by the User in his/her messages (in this regard, and for his/her greater protection, the User is requested not to provide information that is not strictly pertinent to the subject of the request and the nature of the Services provided by the Company).

Data Controller or Holder: The subject who decides on the purposes and methods of the processing of Personal Data. With reference to the Web Services, it is the Company Beautimport s.r.l. to which this website refers and of which you can find the references at the bottom of each page.

Services or Web Services: The services provided through the internet, used through the website and/or any APP.

User: The interested party (natural person) browsing, consulting, accessing or using the Web Services.

Privacy Guarantor: The Guarantor for the protection of personal data, or the Italian National Supervisory Authority in the field of personal data protection. Consult the website of the Privacy Guarantor.

Cookies: Cookies are information recorded on your device (e.g., within the memory of your browser) when you visit a website or use a web application.

Each cookie can contain different data, such as, for example, the name of the server it comes from, a numeric identifier, etc.

Consult the Cookie Policy for more information.

Disclosure on the processing of the User's personal data

We provide you below with useful information regarding the processing of Personal Data carried out through the Web Services.

In particular, we want to inform you about:

  • the identification and contact details of the Data Controller;
  • the categories of Personal Data processed through the Web Services;
  • the purposes for which such Personal Data are processed each time;
  • the conditions that legitimize the processing of the aforementioned data (so-called legal bases);
  • the duration of their conservation, which is always strictly necessary for the pursuit of the stated purposes;
  • the categories of recipients of the data communication.
Data Controller Registered office

Beautimport s.r.l.

Via Barberia, 13 - 40123 Bologna (IT)

 Categories of Personal Data, purposes and legal bases of the processing and terms of conservation

Categories of personal data Purpose of processing Legal Bases Data retention period
Browsing Data To allow web browsing and the provision of Services Need to execute a contract of which the interested party is a party or to provide a service upon request of the same

For the duration of navigation within the services

  To obtain anonymous statistical information on the use of the Web Services, for the sole purpose of checking their correct functioning to ensure the security and correct functioning of the Web Services, as well as to ascertain responsibility in the event of hypothetical crimes, and in order to consequently protect our rights. Legitimate interest of the Company The collected data are aggregated and made no longer attributable to the single User who browsed 

(60 days) and subsequently for the time strictly necessary for any investigations to be carried out, for the definition of any disputes and, in general, for the protection of our rights.

Data provided by the User: provision of the Web Services Request for information Need to execute requests made by the interested party (pre-contractual phase) or legitimate interest The time needed to provide feedback
  Commercial and promotional communications included newsletter service (for marketing purposes) Consent

2 years or until the revocation of the consent

  Tastes and preferences analysis (for profiling purposes) Consent

1 year or until the revocation of the consent

Providing your Personal Data is free and optional. We remind you, however, that, for the pursuit of certain purposes (for example, to provide you with the appropriate feedback requested) it is essential; if not provided, in such cases, it may not be possible to proceed with the pursuit of the aforementioned purposes.

Failure to provide the data (and the relative consent) for any marketing or profiling purposes, does not affect the other requested Services.

Processing Methods and Recipients of data communication

The above data will not be disclosed and may be known by our Company's collaborators specifically authorized to process them. Processing operations may be carried out by external subjects to whom we entrust the carrying out of activities on our behalf, and with whom we enter into specific agreements aimed at regulating the processing of data.

Lastly, the data may be communicated upon express request to public authorities or law enforcement agencies.

The processing of Personal Data always takes place after the adoption of appropriate security measures to ensure the confidentiality, availability and integrity of the data.

 

Cookies

The Web Services can use technical, analytical and profiling cookies, both from first and third parties. Cookies are essential to improve the Services and to provide products that are always in line with the preferences of the Users. Any use of profiling and/or third-party cookies will always be subject to the release of your prior consent.

To learn more, please click here.

 

Rights of the User (as interested party)

The Privacy Regulation (Articles 15-22 of the Regulation) guarantees the User, as an interested party, the right to access the data concerning him/her, as well as to obtain its correction and/or integration, cancellation or portability. The Privacy Regulation also gives the User the right to request the limitation of data processing and to oppose the processing, as well as the possibility to revoke any consent given (the revocation does not affect the lawfulness of the processing carried out up to that moment).

rights In cosa consiste?

Prerequisites for exercise

Access to Data

The User can request from the Data Controller:

  • the confirmation that he/she is processing data concerning him/her;
  • copy of the data concerning  him/her;
  • information regarding the processing (e.g., legal bases, retention period, categories of data recipients, etc.)

The User can always submit such request.

Rectification or integration of Data

The User can request the Data Controller to:

  • rectify
  • update
  • modify

the Personal Data processed

If the processed data is inaccurate or incomplete

Cancellation of data

The User can request the Data Controller to delete the Personal Data he/she is processing

  • the Personal Data are no longer necessary for the purposes for which they were collected or otherwise processed;
  • the User revokes the consent on which the processing is based, and if there is no other legal basis for the processing;
  • the User opposes the processing pursuant to art. 21 and there is no legitimate overriding reason to proceed with the processing;
  • the Personal Data have been unlawfully processed;
  • the Personal Data must be deleted in order to fulfill a legal obligation under Union or Member State law to which the Data Controller is subject

Limitation of the processing of Personal Data

The User can request the Data Controller not to carry out, with the exception of storage only, any processing operation on his/her Personal Data, except with the User's consent or to protect his/her rights

  • the User disputes the accuracy of the Personal Data, for the period necessary for the Data Controller to verify the accuracy of such Personal Data;
  • the processing is unlawful and the interested party opposes the cancellation of the Personal Data and requests instead that its use be limited;
  • although the Data Controller no longer needs it for the purposes of processing, the Personal Data are necessary for the Interested Party to ascertain, exercise or defend a right in court;
  • the User opposed the processing, pending verification of the possible prevalence of the legitimate reasons of the Data Controller with respect to those of the Interested Party.

Opposition to the processing of Personal Data

The User may object to processing based on legitimate interest (including the sending of promotional communications) or on a public interest.

Where there are reasons related to the particular situation of the User, except if the opposition is to the processing for direct marketing purposes.

Opposition to an automated decision-making process

The User can object to automated decision-making processes. In the event that this process is necessary for the conclusion of a contract, is based on explicit consent, whether authorized by law or regulation of the State or of the European Union, the User has the right to obtain human intervention from the Data Controller, to express his/her opinion and to contest the decision.

There is a decision based solely on automated processing, including profiling, which produces legal effects concerning him/her or which significantly affects the person of the User in a similar way.

Portability of Personal Data

The User has the right to receive Personal Data concerning him in a structured format, commonly used and readable by an automatic device.

Provided that all of the following conditions are met:

  • the data has been provided by the User;
  • the processing is based on consent or on a contract;
  • the processing is carried out by automated means

Revocation of the consent

The User can revoke the consent given. The revocation does not affect the lawfulness of the processing carried out up to that moment.

Always

How to exercise your rights and / or request information on processing

To exercise the rights of the Interested parties, for any doubts or clarifications and to know the updated list of categories of data recipients, you can write to our Privacy Contact:

Privacy Contact

info@beautimport.com

We remind you that the privacy consent (s) you may have issued for commercial and promotional purposes are always revocable, without prejudice to the processing carried out until revocation, by writing to info@beautimport.com.

Without prejudice to your right to contact the Privacy Guarantor, also through a complaint, or to the competent judicial authority, where deemed necessary for the protection of your Personal Data and your rights on the matter.