E-COMMERCE INFORMATION NOTICE
PURSUANT TO ARTICLES 13 AND 14 OF REG. (EU) 2016/679 ("GDPR")
La Sportiva S.p.A. provides the following information required by the GDPR regarding the processing of personal data related to the use of the e-commerce platform hosted on the website https://www.lasportiva.com/it owned by La Sportiva (the "Website") and the use of related services by users ("User/s"), particularly for the purchase of "La Sportiva" branded products, as better regulated by the general terms and conditions of sale and the general terms and conditions of purchase and use of Gift Cards, available at the following links https://www.lasportiva.com/en/general-sales-condition, https://www.lasportiva.com/en/gift-card-general-conditions (hereinafter, respectively, "GTC" and "GC Gift Card").
1. Sources and Categories of Data Processed
As indicated in the GTC and GC Gift Card, you can choose to make purchases on the Website by registering and creating a personal account by filling out the appropriate online form. For this purpose, you will be asked to enter your name, surname, email address, and create a password. You may also indicate your date of birth if you wish. Alternatively, you can choose to proceed as an unregistered user ("Guest User").
For the purpose of purchase, you will also need to provide the data necessary for payment and shipping of the products (name and surname, address, phone number, payment method details such as credit card, and, if an invoice is requested, the tax code). The data processed will therefore be as follows:
-
personal, identification, and contact data;
-
credit card data used (card number, name and surname, expiration dates, etc.) or other payment methods;
-
information related to the services provided and used, purchases made, and other non-specific data.
2. Identity and contact details of the Data Controller
The Data Controller is La Sportiva S.p.A., tax code and VAT number IT01039930225, with registered office at Via Ischia n. 2, 38030 - Ziano di Fiemme (TN), ITALY, email address gdpr@lasportiva.com ("La Sportiva" or "Controller").
3. Purposes of Processing, Legal Bases, and Data Retention Periods
|
WHY ARE PERSONAL DATA PROCESSED? |
WHAT IS THE CONDITION THAT MAKES THE PROCESSING LAWFUL? |
HOW LONG DO WE RETAIN PERSONAL DATA? |
|
a. To ensure the User's access to the e-commerce platform of the Website and to allow the management of activities necessary for the completion of the purchase order, payment for the purchased products, shipping and tracking of orders, as well as the management of any returns, refunds, or complaints related to the orders, etc. |
a. The performance of a contract to which the User is a party. |
For the entire duration of the contractual relationship with La Sportiva and for 10 years following the termination of the contract, in compliance with legal obligations in civil and tax matters.
In the event of litigation, data is retained until the expiration of the terms for the exercise of appeal actions. |
|
b. To establish, exercise, or defend the rights of La Sportiva. |
The pursuit of a legitimate interest of the Data Controller. |
In the event of litigation, data is retained until the expiration of the terms for the exercise of appeal actions. |
|
c. To fulfill administrative, accounting, and tax obligations and to comply with further legal requirements, in accordance with current regulations. |
Compliance with a legal obligation to which the Data Controller is subject. |
The data will be retained for 10 years, as the general retention period prescribed by law. |
|
d. To send - to the email address provided by the User in the context of a purchase - promotional communications regarding products identical or similar to those the customer has already purchased from La Sportiva. |
The so-called "soft spam" referred to in Article 130, paragraph 4 of Legislative Decree 196/2003 ("Privacy Code"). |
Until the data subject objects (by clicking on the "unsubscribe" link at the bottom of each communication). |
|
e. Receiving information about the cart (Guest Users) When the User accesses the Site's e-commerce platform as a Guest User, they may select a range of products to add to their cart. Later, in the checkout section, they can enter their email address and proceed with the payment. However, if they choose to leave the section and complete the purchase at a later time, they may receive a reminder about the contents of the products added to the cart. La Sportiva will send two automatic messages: the first, 2 hours after the cart is abandoned; the second, on the following day. |
Performance of pre-contractual measures at the data subject's request, Art. 6(1)(b) GDPR. |
The data strictly necessary for sending reminder communications are retained for 24 hours from the time the cart is abandoned. |
|
f. Receiving information about the cart (registered users) If the User has used the Site's e-commerce platform as a registered user, they may receive reminder communications regarding products added to the cart but not purchased, with the aim of facilitating the completion of the order. In this case, three automatic messages are scheduled: the first two follow the same timing as for Guest Users; the third is sent 3 days after the cart is abandoned and consists of newsletter communication based on the data of the products added to the cart (e.g., similar items and/or relevant product category). This communication will be sent only once, with the purpose of helping complete the purchase. |
Performance of pre-contractual measures at the data subject's request, Art. 6(1)(b) GDPR. |
The data strictly necessary for sending reminder communications are retained for 72 hours from the time the cart is abandoned. |
After the above retention periods have expired, the data will be destroyed, deleted, or anonymized in accordance with the technical timescales for deletion and backup.
4. Provision of Data
The provision of data marked with an asterisk (*) in the purchase form is mandatory to complete the order. These fields are necessary to collect the essential information to: (i) allow you to proceed with the payment and (ii) enable us to finalize the shipment of the purchased products to the address you provided. Information on the processing of browsing data and the use of cookies can be found in the Privacy and Cookie Policy available on the Website.
5. Categories of Data Recipients
Data may be communicated to third parties acting as independent data controllers, such as public authorities and/or professional firms, authorized to receive them. The data is also processed, on behalf of the Data Controller, by third parties designated as data processors pursuant to Article 28 of the GDPR, who perform activities functional to the purposes mentioned above (e.g., e-commerce platform manager, customer care service providers, and IT services).
Additionally, data is processed by La Sportiva employees - belonging to the corporate functions responsible for pursuing the aforementioned purposes - who have been expressly authorized to process the data and have received appropriate operational instructions.
6. Transfer of Data Outside the EEA
Data will be transferred outside the EU, specifically to the United States of America, based on the following guarantees:
-
the provider's adherence to the EU-US Data Privacy Framework;
-
the signing of standard contractual clauses.
7. Rights of Data Subjects
All data subjects (i.e., the individuals to whom the data refers) can exercise the rights provided for in Articles 15-22 of the GDPR by writing an email to: gdpr@lasportiva.com. In particular, data subjects can:
-
obtain confirmation from the Data Controller as to whether or not personal data concerning them is being processed and, if so, request access to the data and the information referred to in Article 15 of the GDPR;
-
obtain the rectification of inaccurate data or the completion of incomplete data pursuant to Article 16 of the GDPR;
-
request the deletion of personal data in the cases provided for by Article 17 of the GDPR;
-
obtain the restriction of processing (i.e., the temporary submission of data to the sole operation of storage), in the cases provided for by Article 18 of the GDPR;
-
object at any time, for reasons related to their particular situation, to the processing of personal data concerning them carried out on the basis of the Data Controller's legitimate interest, pursuant to Article 21 of the GDPR;
-
if the processing is based on consent, contract, or for the execution of pre-contractual measures adopted at the request of the data subjects and is carried out by automated means, request to receive the data in a structured, commonly used, and machine-readable format, and, if technically feasible, to transmit it to another controller without hindrance, pursuant to Article 20 of the GDPR ("right to data portability").
For the purposes referred to in letter d) above, data subjects can object to the processing at any time (also by clicking on the "unsubscribe" link in each email communication).
In any case, data subjects have the right to lodge a complaint with the competent supervisory authority in the Member State where they usually reside or work or in the State where the alleged violation occurred.