FREE SHIPPING for orders over 40 € (valid on Italy orders only)

FREE SHIPPING for orders over 40 € (valid on Italy orders only)

Privacy Policy Newsletter

 

De Fonseca, with registered offices in Viale Italia, n. 73, 10040 – Leinì (TO), VAT No. 08210280015 and Fiscal Code No. 13005000156, registered with the Company Register of Turin (Italy) under No. 954207 (hereinafter the “Controller”), manager of the internet website https://www.defonseca.com/ (hereinafter, the “Website”), in its capacity as data controller in relation to personal data pertaining to the users using the Website (hereinafter, the “Users”) hereby provides the privacy policy pursuant to art. 13 of the Regulation EU 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, “Regulation” or “Applicable Law”).

The Controller takes the outmost account to the privacy rights and to the protection of its Users’ personal data. For any information in relation to this privacy policy at any time whatsoever, the Users may contact the Controller using the following modalities:

  • Sending a registered letter to the registered office of the Controller (Viale Italia, n. 73, 10040 – Leinì (TO));
  • Sending an email to privacy@defonseca.it.

The Controller did not appoint a Data Protection Officer (DPO), because the Controller is not subject to the mandatory obligation to appoint it pursuant to art. 37 of the Regulation.

1. Purposes of data processing

The Users’ personal data will be processed by the Controller lawfully pursuant to art. 6 of the Regulation for the following processing purposes:

a)      executing the User’s request: the personal data of the User are collected by the Controller to execute the User’s request to receive the newsletter. Therefore, the User will receive a periodic newsletter from the Controller that will contain information regarding news concerning the sector relative to the Website activities (shoes sale). Without prejudice to what is stipulated elsewhere, under no circumstances the Controller will make the personal data accessible to other Users and/or third parties.

b)     accounting-administrative purposes, or in order to carry out organisational, administrative, financial and accounting activities, as internal organisational activities and activities aimed at fulfilling contractual and precontractual obligations;

c)      legal obligations, or in order to fulfil obligations provided by the law or the European laws and regulations.

Providing the personal data for the processing purposes specified above is optional but necessary, since failing to provide the same imply the impossibility for the User to receive the newsletter from the Controller. In case of consent, the User may at any time revoke the same, making a request to the Controller in the manner indicated in paragraph 4 below.

The User can also easily oppose further sending of newsletter communications also by clicking on the appropriate link for the revocation of consent, which is present in each e-mail containing the newsletter. Once the consent has been revoked, the Controller will send the User an e-mail message confirming the revocation of the consent.

The Controller hereby informs that, following the exercise of the right to object to the sending of newsletter communications, it could be possible due to technical issues (i.e. sending list already completed a little before the receipt by the Controller of the objection request) the User continues receiving further newsletter messages. In the event that the User continues receiving newsletter messages once elapsed 24 hours from the exercise of the objection right, please flag such issue to the Controller, using the contacts specified under the following paragraph 4.

A star in the registration form identifies the personal data, which are necessary for purporting the processing purposes described under this paragraph 1.

2. Processing methods and data retention

The Controller will carry out the processing of Users’ personal data by manual and IT instruments, applying logics strictly connected to the purposes and, in any case, so that the safety and confidentiality of the relevant data is guaranteed.

Users’ personal data will be retained for the time strictly necessary to carry out the relevant purposes described in the previous paragraph 1, and in any case for the time necessary for the protection of the civil interests of the Users and of the Controller.

3. Data disclosure and dissemination

Controller’s employees and/or workers appointed to manage personal data may become aware of any Users’ personal data. Such subjects, who are formally appointed by the Controller as persons in charge for the processing, will process the relevant User’s data exclusively for the purposes specified under this policy and in compliance with the provisions of the Applicable Law.

Furthermore, third parties which may process personal data for the account of the Controller may become aware of any Users’ personal data in their capacity as “external data processor”, such as, including, but not limited to, providers of logistics and IT services functional for the Website operational, outsourcing or cloud computing services providers, professionals and advisors, companies entrusted with the sending of marketing e-mails for the account of the Controller.

Users have the right to obtain a list of the data processor (if any) appointed by the Controller upon a specific request to be made to the Controller following the modalities specified under the following paragraph 4.

4. Data subjects’ rights

Users may exercise the rights granted to them by the Applicable Law, contacting the Controller with the following modalities:

  • Sending a registered letter to the registered office of the Controller (Viale Italia, n. 73, 10040 – Leinì (TO));
  • Sending an email to privacy@defonseca.it.

Pursuant to the Applicable Law, the Controller hereby informs that any Users has the right to obtain the indication of (i) the source of the personal data; (ii) the purposes and methods of the processing; (iii) the logic applied to the processing, if the latter is carried out with the help of electronic means; (iv) the identification data concerning data controller and data processors; (v) the entities or categories of entity to whom or which the personal data may be communicated and who or which may get to know said data in their capacity as designated data processor(s) or person(s) in charge of the processing.

Furthermore, data subjects have the right to obtain:

a) access, updating, rectification or, where interested therein, integration of the data;

b) erasure, anonymization or blocking of data that have been processed unlawfully, including data whose retention is unnecessary for the purposes for which they have been collected or subsequently processed;

c) certification to the effect that the operations as per letters a) and b) have been notified, as also related to their contents, to the entities to whom or which the data were communicated or disseminated, unless this requirement proves impossible or involves a manifestly disproportionate effort compared with the right that is to be protected.

Furthermore, Users have:

a) the right to withdraw the consent at any time, when the processing is based on consent;

b) the right to data portability (if applicable), that is the right to receive all the personal data concerning the User, in a structured, commonly used and machine-readable format; the right to restriction of processing of the personal data; the right to erasure (right to be forgotten).

c)the right to object:

i) in whole or in part, on legitimate grounds, to the processing of personal data concerning him/her, even though they are relevant to the purpose of the collection;

ii) in whole or in part, to the processing of personal data concerning him/her, where it is carried out for the purpose of sending advertising materials or direct selling or else for the performance of market or commercial communication surveys;

iii) if personal data are processed for direct marketing purposes, to object at any time to the processing for such marketing, which includes profiling to the extent that is related to such direct marketing.

d) the right to lodge a complaint with a supervisory authority (in the Member State of him or her habitual residence, place of work or place of the alleged infringement) if the User considers that the processing of personal data relating to him/her infringes the Regulation. The Italian Data Protection Authority is the Garante per la protezione dei dati personali, with registered office in Piazza di Monte Citorio, n. 121, 00186 – Rome (http://www.garanteprivacy.it).

The Controller is not responsible for updating all links that can be viewed in this Privacy Policy, therefore whenever a link is not functional and/or updated, Users acknowledge and accept that they must always refer to the document and/or section of the websites referred to such link.