Pursuant to Article 13 of the EU Regulation No. 2016/679, laying down the provisions for the protection of natural persons with regard to the processing of their personal data, we wish to inform you that the personal data you provide shall be processed in accordance with the above-mentioned legislation and the confidentiality obligations to which NATURALSALUS S.r.l. is bound by.
The Data Controller is NATURALSALUS S.r.l., with its registered office in Via Galvani, 39 Bolzano and with Tax Code 03167530215
Purpose of processing and legal basis
Your personal data shall be processed:
A) without your express consent (article 6.1 (b), (c) GDPR), for the following Service related Purposes:
- a) to enable registration on the Site, which is necessary to deliver and manage the various services offered;
- b) to enable the user to place product orders on the Site;
- c) to provide assistance and respond to user requests in relation to purchased products;
- d) to fulfil pre-contractual, contractual and tax obligations arising from placed orders;
- e) to carry out communications related to orders and shipments (e.g., sending an order confirmation e-mail, a shipment confirmation e-mail, or an e-mail requesting feedback on the service obtained);
- f) to fulfil tax and/or accounting obligations.
- g) to fulfil obligations required by law, regulations, EU legislation or an order of an Authority (such as, for example, in the field of anti-money laundering);
B) only after receiving your specific and distinct consent (article 6.1 (a) GDPR), for the following Marketing related Purposes: to send you by e-mail, mail and/or sms and/or telephone contacts, newsletters, commercial communications and/or advertising material about products or services offered by the Controller. We wish to highlight that if you are already our customer, we may send you commercial communications regarding services and products of the Controller similar to those you have benefitted from before, unless you otherwise object (article 130 Privacy Code) to this.
Processing methods and storage period
Processing of your personal data is carried out by means of the operations indicated in Article 4 (2) GDPR and namely: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, deletion and destruction of data. Your personal data is subject to both paper-based and computerized processing.
The data referred to in 2.A) shall be kept for the duration of the contract and for an additional 10 years after the conclusion of the service.
The data in 2.B) shall be processed for 2 years, unless consent is revoked earlier.
Categories of Personal Data subject to processing
In addition to the Personal Data directly inputted by the users (such as name, surname, postal address, e-mail address, date and time of delivery), when connecting to the Site, the computer system and software procedures in charge of running the Site itself automatically and indirectly acquire other Personal Data whose transmission is implicitly necessary in the use of Internet communication protocols (e.g. IP addresses or domain names of users’ computers connecting to the Site, the URI – Uniform Resource Identifier – addresses of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code about the status of the response rendered by the server, and other parameters relating to the User’s operating system and computer environment).
Scope of communication and dissemination
The Personal Data directly provided by users via the completion of the online forms will in no case be subject to dissemination or communication to third parties, except:
- subjects to whom the right to access the data is set out in provisions of the law or orders of the Authorities,
- subjects to whom communication is necessary to carry out fiscal or administrative obligations,
- subjects to whom communication is necessary to enable the execution of the contract (e.g. order processing, services and payment processing, credit card management, debt collection, operation of the website and e-commerce platform, support services, promotions, website development, e-mail services to send e-mail and/or newsletters)
- controller’s employees, collaborators and internal data processors (if appointed);
- operator of the e-commerce web platform;
Rights of the Data Subject
We inform you that, in relation to the aforementioned processing operations, you may exercise the rights granted to you by the Regulation, in particular the right to:
- access your personal data as well as to receive information regarding the purpose of the processing, the categories of data processed, the recipients and categories of recipients to whom your personal data may be disclosed, expected storage period, application or non-application of profiling mechanisms and authorized decision-making processes;
- obtain the rectification of inaccurate personal data concerning you and/or the deletion of your data in general, without undue delay;
- obtain the restriction of processing;
- object, in whole or in part, for legitimate reasons, to the processing of your personal data, even if relevant to the purpose of collection;
- request the portability of the data that you have provided us, i.e. to receive it in a structured, commonly used and machine-readable format, including for transmission to another data controller, without any hindrance;
- submit a complaint to the competent supervisory authority for the protection of personal data (Information Commissioner Office).
You can exercise your above mentioned rights communicating either in writing to NATURALSALUS S.r.l. at Via Firenze, 34 – 20060 Trezzano Rosa (MI), or by email to email@example.com or alternatively by PEC to firstname.lastname@example.org
Revision of 12/12/2022