Privacy Notice
Information on Personal Data Held by the Data Subject pursuant to Regulation (EU) 2016/679 (General Data Protection Regulation)
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR: General Data Protection Regulation) and Legislative Decree 196/2003 (as amended by Legislative Decree 101/2018), and in accordance with the principle of transparency, the following information is provided to make the data subject aware of the characteristics and methods of data processing:
a. Identity and contact details
The "Data Controller" is: Soldidesign S.r.L.
Legal Representative: Tommaso Soldi
Headquarters: Calenzano (FI), via di Pratignone n.50, cap: 50041.
Contact details: telephone: +39-055/88.77.499; email address: info@soldidesign.com;
b. Purpose of processing, legal basis, and legitimate interest
The personal data requested from the data subject is processed for the following purposes:
- Product sales through the Shopify portal;
- Performance of the (direct) relationship between Soldidesign S.r.L. and the data subject;
- Communications regarding product information and company activities by Soldidesign S.r.L., through subscription (voluntary) to the data controller's newsletter (data will not be transferred to third parties);
- Any other obligation required by law and which the data controller must comply with for the purposes set out in the preceding points, including communication to specifically appointed parties pursuant to Article 28 GDPR (see §d).
The processing listed above, in relation to points 1), 2) and 4), is necessary for the pursuit of the legitimate interest of the data controller to comply with the contractual obligations entered into between the parties, pursuant to Article 6 GDPR, paragraph 1, letter b), c). In the case of point 3), the lawfulness of the processing is based on the consent of the data subject (required pursuant to letter a) of paragraph 1, Article 6 of Regulation EU 2016/679) and will be the subject of an express request by the Data Controller. In this case, the consent given by the data subject follows the principles set forth in Article 6 GDPR, i.e., it is free, specific, informed, unambiguous, explicit, verifiable, and revocable.
c. Recipients and possible categories of recipients of personal data
The data are processed within the company by specially authorized subjects, under the responsibility of the Data Controller for the purposes stated above. The data may be communicated to External Data Processors (in accordance with the provisions of Article 28 of the GDPR) who have entered into specific agreements, conventions or memoranda of understanding, contracts with the data controller.
d. Data retention period
Personal data will be stored for the period strictly necessary for processing. In particular:
- In the case of subscription to the newsletter, the data necessary for the fulfilment of this purpose will be stored as long as the data subject is subscribed to the newsletter;
- The data relating to purchases made will be stored for the period necessary to achieve the purposes for which they were collected (legal purposes, storage for 10 years for tax purposes).
e. Data rights
The data controller, pursuant to Article 3, paragraph 1 of EU Regulation 2016/679 is obliged to apply the GDPR and, therefore, pursuant to the aforementioned legislation, the following rights may be exercised:
- Right of access to personal data; right to obtain rectification or erasure of the same or restriction of processing concerning them;
- Right to object to processing;
- Right to data portability (right applicable only to data in electronic format), as provided for by Article 20 of the GDPR.
Please note that since the data processing is based on Article 6, paragraph 1, letter a), or Article 9, paragraph 2, letter a) of EU Regulation 2016/679, the data subject has the right to withdraw consent at any time without compromising the lawfulness of the processing based on consent before such withdrawal. With regard to the modalities for exercising the aforementioned rights, the data subject may write to the data controller.
f. Complaints
The data subject has the right to lodge a complaint with the supervisory authority and may contact the data controller at the addresses indicated above. For further information, please consult the institutional website of the Italian Data Protection Authority: www.garanteprivacy.it
g. Data communication
The communication of personal data is a legal or contractual obligation, in any case a necessary requirement for the conclusion of a contract.
h. Provision of data
The provision of data is mandatory as the communication of data is a contractual obligation or, in any case, a necessary requirement for the conclusion of the contract. Failure to provide the data will not allow the data subject to proceed with the completion of the procedure.
i. Different purpose of processing
If the data controller intends to process the personal data for a purpose other than that for which they were collected, prior to such further processing, the data controller shall provide the data subject with information on such different purpose and any further relevant information.
j. Profiling and data transfer to a third country
The Data Controller will not transfer data to a third country or to an international organization outside the territory of the European Union except in the cases expressly provided for by law and/or to execute the contract. The data controller, limited to the purposes for which the data are released, does not use automated processes for profiling. Any changes to the above will be subject to a request for new consent from the Data Controller to the data subject.
"For personal data, pursuant to Article 4, paragraph 1, point (a) of the GDPR, is meant: “any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person".