Dear User,
We care about the security of your personal data and assure you the utmost confidentiality in their processing, in compliance with the principles of fairness, lawfulness, and transparency, in accordance with the EU Regulation 2016/679 ("General Data Protection Regulation" - hereinafter GDPR), and Italian Legislative Decree no. 196 of June 30, 2003, as amended by Legislative Decree no. 101 of August 10, 2018, (hereinafter, "Codice Privacy").
To this end, in accordance with Articles 13 and 14 of the GDPR, we inform you as follows regarding the processing of personal data carried out by DDN Retail S.r.l. Unipersonale through the officinecreative.store website ("Website").
DATA CONTROLLER
The data controller is DDN RETAIL S.R.L. UNIPERSONALE (hereinafter referred to as "DDN" or "Controller"), with registered office at 63018 Montegranaro (FM), Strada Elpidiense 289/C, Italy, VAT/CF no. 01406630432, Tel: +39 0734 891242, pec: ddnretail@pec.it.
CATEGORIES OF PROCESSED DATA
The data processed by DDN, upon their provision by the User through the Website, are:
This site uses certain types of cookies. To learn more, you can consult the extended cookie policy at the following link: https://www.officinecreative.store/pages/cookie-policy
The provision of the aforementioned personal data is always optional on the part of the User, although it may be necessary to purchase the Products through the Website. The refusal to provide data by the User may result in DDN's inability to deliver, in whole or in part, the requested Products and/or to conclude the related contracts.
PURPOSES OF PROCESSING
The aforementioned personal data will be processed for the following purposes:
Purpose 1 - to register and activate the User's account, through which they can access the functions reserved for registered users of the Website (e.g., purchase history, wishlist, shopping cart, etc.);
Purpose 2 - to carry out preliminary and consequent activities related to the purchase of products through the Website, including invoicing and/or payment, as well as fulfilling any other obligations arising from the contract with the User;
Purpose 3 – to handle messages and other information sent by the User through the contact and comment forms inserted on the Website;
Purpose 4 - to send info, promotional materials and/or newsletters, including personalized ones, with the prior consent of the User;
Purpose 5 - to comply with legal obligations, regulations, EU legislation, or an order from Administrative or Judicial Authorities (e.g., administrative, accounting, civil, tax, anti-money laundering obligations, etc.);
Purpose 6 - to manage any disputes, both judicial and extrajudicial, between DDN, the User, and/or any third parties;
Purpose 7 - to send the User email messages regarding offers and information about services and products similar to those provided (Art. 130, paragraph 4, Codice Privacy); the User may object to this purpose at any time by using the cancellation link, unsubscribe option, or equivalent, present at the bottom of each message;
Purpose 8 - to fulfil all operations required by the application of the Management Systems implemented in the company (e.g., according to UNI EN ISO 9001, etc.);
Purpose 9 - to ensure the proper and regular functioning of the Website;
Purpose 10 - to create specific profiles and personalized direct marketing activities, as described in Purpose 4 - this latter purpose is carried out with the consent of the data subject - based on the data provided by the user, such as date of birth (e.g., sending birthday promotions), gender, purchases made, and activities carried out on the site (e.g., visited pages, items added to the cart, etc.).
Regarding the purposes of the cookies and the related legal basis, please refer to the cookie policy at the link mentioned above.
No automated decision-making processes are foreseen.
If DDN intends to further process your personal data for a purpose other than that for which they were collected, before such further processing, we will provide you with information regarding that different purpose and any other relevant information.
LEGAL BASIS OF PROCESSING
According to Article 6 of the GDPR, the legal basis for each processing purpose is as follows:
Purpose 1, 3, 4: The processing is based on the specific consent of the User (Article 6(1)(a) of the GDPR). Consent for these purposes is entirely optional, and in case of non-provision or subsequent withdrawal, it will still be possible to access the Website. The User has the right to withdraw consent at any time without affecting the lawfulness of the processing carried out before the withdrawal. For information on how to exercise the right to withdraw consent, please refer to the section "Exercise of Data Subject Rights";
Purpose 2: The processing is necessary for the performance of a contract between DDN and the User or for the implementation of pre-contractual measures taken at the User's request (Article 6(1)(b) of the GDPR);
Purpose 5: The processing is necessary for compliance with a legal obligation to which the Controller is subject (Article 6(1)(c) of the GDPR);
Purposes 6, 7, 8, 9, and 10: The processing is necessary for the legitimate interests pursued by the Controller (Article 6(1)(f) of the GDPR) in protecting its rights in case of disputes (Purpose 6), sending promotional communications for goods and services similar to those provided (Purpose 7), ensuring proper application of its Management Systems (Purpose 8), maintaining the functioning of the Website (Purpose 9), and processing specific customer profiles. For Purpose 10, the legal basis is the legitimate interest of the Controller in creating specific customer profiles without cross-referencing data from other sources, to the extent strictly necessary for Purpose 4, and subject to the prior consent for Purpose 4. The data subject retains the right to object, in accordance with Article 21 of the GDPR.
DATA RETENTION PERIOD
In the case of account registration, personal data will be retained for the period during which the User keeps the account active, and if subsequent, for a period of 10 years from the termination of the last contractual relationship referred to in Purpose 2. Any additional retention periods required by law are reserved. In the case of purchases not associated with an account, personal data will be retained for a period of 10 years from the completion of the contractual relationship. Any additional retention periods required by law are reserved.
The data transmitted by the User through contact forms (Purpose 3) will be retained for the period necessary to handle the transmitted message and, in the case of contractual or pre-contractual messages, for 10 years following the completion of the respective contract.
The User's email address will also be retained, for Purposes 4 and 7, for the period during which DDN maintains the service or until the withdrawal of consent or exercise of the right to object by the data subject, if earlier. Each message will remind the User of the option to unsubscribe/object to the receipt of further messages through a designated link. If the sending frequency is less frequent, a verification communication containing the unsubscribe/opposition link will be sent to the User at least once every twelve months.
For Purpose 10, the data will be retained and processed for 2 years from the time of collection and/or from the renewal of consent for Purpose no. 4, except for any additional retention periods required for other purposes.
For the retention periods of cookies, please refer to the cookie policy at the above-mentioned link.
DATA DISCLOSURE AND TRANSFER TO NON-EU COUNTRIES
Personal data may be disclosed to external parties who, if processing data on behalf of DDN, will be duly appointed as data processors (Article 28 of the GDPR), as well as to the Public Administration and the Judicial Authority, in compliance with legal or jurisdictional obligations.
In particular, the processed data may be disclosed to the following categories of recipients:
There is no transfer of data to third countries outside the EU or international organizations, except for logistical and operational purposes related to the hosting service. In such cases, personal data may be transferred to countries outside the EU for which there is an adequacy decision by the European Commission or adequate safeguards in accordance with Article 46 of the GDPR.
There is no dissemination of the processed personal data.
SECURITY MEASURES
Personal data will be processed in both paper and electronic formats. All appropriate procedures will be implemented to protect the confidentiality, integrity, and availability of information in accordance with applicable regulations.
RIGHTS OF THE DATA SUBJECT
In accordance with Articles 13-21 of the GDPR and the conditions provided therein, the data subject has the following rights, which can be exercised at any time with respect to DDN Retail S.r.l. Unipersonale:
EXERCISE OF DATA SUBJECT RIGHTS
For any request and to exercise their rights, the data subject can send an email to the Controller at the following address: privacy@officinecreativeitalia.com.
Last updated: June 30, 2023.
KLARNA
In order to be able to offer you Klarna’s payment methods, we may transmit your personal data to Klarna in the form of contact details and order details to Klarna so that Klarna can assess your suitability for its payment methods and customize those payment methods. The personal data of the user transferred are treated in line with Klarna’s privacy policy.