Privacy policy
Welcome to our website www.parisy.it (hereinafter, the “Site”). For Parisy S.r.l. (hereinafter, “Parisy”) your privacy and the security of your personal data are very important. That is why we collect and manage your personal data with the utmost attention, and adopt specific measures to safely store it.
Below you will find key information about how your personal data is processed when you navigate through the Site and use the services offered. For detailed information about how Parisy processes your personal data, please carefully read this document (Privacy Policy)
Please also read the
This Privacy Policy exclusively refers to the Site, and does not concern any third party websites referred to within the pages of the Site.
1 WHO IS THE CONTROLLER
When you use the Site, access our services or purchase Parisy products, Parisy is the controller of the processing of your personal data. The types of personal data we collect and the purposes for which we process such data are described in detail below.
For any clarification, question, or requirement related to your privacy, or to exercise your rights under the European personal data processing legislation (the General Data Protection Regulation – EU Reg. No. 2016/679, hereinafter “GDPR”) (see point 6) you may use the contact details indicated below.
2 WHAT DATA DO WE PROCESS
As concerns the purposes of the processing indicated in point 3 below, we process various types of personal data concerning you, including:
- your identification information (such as first and last name), your contact details (such as email address and telephone number), shipping address and billing address, payment information (such as the method of payment used, cardholder, card number used). For customer care activities, the information you choose to provide in your communications is also processed;
- if you register on the Site (“Account”), we process your identification information, your email address, and your password, as well as the data needed to provide you with services that are reserved for registered users.
- your geographic location, which is used with your consent by Parisy for any service (that you have requested and that is offered through the Site) to find the Parisy store reseller the closest to you (“Stockists”);
- your identification and contact details may be processed when you give your consent to receive by email, or any other means, marketing communications from or on behalf of Parisy, or communications from or on behalf of commercial partners of Parisy with which, with your express consent, Parisy has shared your personal data in conformity with this Privacy Policy;
- when you have provided the corresponding consent, Parisy also processes the data relating to your preferences and interests, such as products you’ve purchased or added to your wish list, age and gender, your country, and your preferred language and currency and the newsletters you have subscribed to. Parisy process your data to analyze your habits and preferences to offer you personalized services and communications that are in line with your interests;
- your first name, last name, and mailing address, as well as your contact information (such as email address and phone number) in order to send you certain products purchased from the Site. We process your data to fulfill such requests. When you provide us with personal data from third parties, you must do whatever is necessary so that the communication of data to Parisy and our subsequent processing for the purposes specified in this Privacy Policy occur in accordance with the applicable legislation. Therefore, prior to providing us with a third party’s personal information, please ensure that you have their permission to do so and direct them to this Privacy Policy for information about how we will process their personal data.
When you navigate through the Site, we also collect data relating to your navigation, in particular to verify the proper functioning of the Site, to provide you with the best navigation, and to increase the quality of our services. For more information about the technologies used (cookies and similar tools) please consult our Cookie Policy.
3 WHY DO WE PROCESS YOUR DATA AND ON WHAT LEGAL BASIS
3.1 Purposes related to the online sale of products
We process your personal data for the online sale of Parisy products and the relative activities connected thereto. In particular, to:
• enter into and perform a contract for the purchase on the Site of one or more products, for payment, product shipping, any management of the right of withdrawal, return, and the legal warranty. This processing is necessary to perform a contract to which you are party (purchase and sale agreement). You must provide your personal data; otherwise you will not be able to make a purchase on the Site or manage any requests you may have regarding the right of withdrawal, return, and legal warranty, or to receive the dedicated customer service;
• customer care. Processing is necessary to perform a contract to which you are party (provision of customer care). You must provide your personal data; otherwise you will be unable to receive the customer care you requested;
• the fulfillment of the legal obligations relating to the sales activity (such as, for example, issuing and storing the invoice). This processing is necessary to fulfill a legal obligation to which we are subject. It is thus mandatory that you provide your personal data; otherwise you will be unable to make a purchase on the Site;
• register on the Site (“Account”), or use the services that are reserved for registered users (for example: Wishlist, Orders, etc.). This processing is necessary to perform a contract to which you are party (registration on the Site and the relative provision of services). It is mandatory that you provide your personal data; otherwise you will be unable to register on the Site and use the registered user services;
• prevention and suppression of fraud and abusive behaviors (including by third parties) that conflict with the current standards, the applicable contractual provisions, and the rules of correctness and good faith. The lawfulness of this processing is based on our legitimate interests to perform security activities and controls for the purpose of preventing and protecting against fraudulent activities and abusive behaviors. Upon your request, we will be able to provide you with detailed information about the aforementioned legitimate interest and the corresponding so-called balancing test we have undertaken to ensure that your rights and interests are not outweighed by our legitimate interests;
3.2 Marketing purposes
With your consent, Parisy uses your personal data for marketing purposes. Indeed Parisy may send you commercial or advertising communications about its products, services, and events. The marketing activities may also include market research and surveys to determine your level of satisfaction and to conduct statistical analyses, including using aggregated anonymous data. The processing of your data for marketing purposes is based on your voluntary consent, and providing your data for such purposes is optional. Regardless of whether you have consented to such processing for marketing purposes, you will be able to purchase our products online.
With your consent, Parisy uses the data collected online, through this or other sites, or through Parisy accounts on social media, to collect information relating to your preferences, habits, lifestyle, as well as details about what you have purchased. The data is used to create group and/or individual profiles (“profiling”) which allow us to send you personalized communications that are in line with your interests, or to conduct market research and statistical analyses, including with aggregated anonymous data. The processing of your data is based on your voluntary consent, and providing your data is optional. Regardless of whether you have consented to such processing, you will be able to purchase our products online.
With your consent, Parisy s.r.l. shares your personal data with companies (current or future) of Parisy s.r.l. and others operating in the beauty, lifestyle, fashion, food, or sports sector. These companies will process your data for their own marketing purposes, i.e. to send you promotions, commercial or advertising communications about their products, services, events, including market research and surveys to determine your level of satisfaction and to conduct statistical analyses, including with anonymous data, organized in aggregate form. Such processing of your data is based on your voluntary consent; providing your data is optional. Regardless of whether you have consented to such processing, you will be able to purchase our products online.
To send you marketing communications or personalized offers, methods such as email, newsletters, operator-assisted telephone calls, SMS, MMS, chat, instant messaging, social networks and traditional mail are used, including invitations to organized events from Parisy or in which Parisy participates. You may unsubscribe from marketing communications in the corresponding section of your personal account or by clicking the respective link, which appears at the bottom of every commercial communication.
3.3 Other purposes
We may also process your personal data for:
• managing requests to exercise personal data protection rights (further information in point 6). This processing is necessary to fulfill a legal obligation to which we are subject;
• other personal data protection requirements. Under certain circumstances, the personal data protection legislation requires the data controller to use your contact details to provide you with specific information about the processing of your data such as, for example, to inform you of any security violations concerning your information and the measures adopted to address them (so-called data breach), and as well as to inform you of any significant updates to this privacy policy. This processing is therefore necessary to perform a legal obligation to which we subject.
4 WHO WILL PROCESS YOUR DATA
Duly informed personnel (employees and associates) of Parisy, as well as third parties (service providers and/or business partners) who were appropriately selected by us and offer a suitable guarantee of compliance with personal data processing rules, may have access to your personal data. These third parties may conduct their activities as “data processors” (thus under our direct responsibility). For example, we may use the following categories of third party service providers who are our data processors: Internet providers, companies specialized in IT and electronic services, customer care service companies, companies that perform marketing activities, companies specialized in market research and data processing. Some third party service providers act as “independent data controllers” (for example, we may use third party couriers and shippers, bank operators, independent professionals, or consulting, legal or tax assistance firms, on this basis).
Your personal data may also be disclosed to third parties, including in the following cases:
(i) when disclosure is required by the applicable laws and regulations for legitimate third party recipients of communications, such as public entities and authorities that process your data as independent controllers for the respective institutional purposes;
(ii) in case of extraordinary operations (for example mergers, acquisitions, disposal of business, etc.);
Some of the parties indicated above (including various entities constituting Parisy) may also be established outside the European Union (EU) or the European Economic Area (EEA), in countries that do not guaranty an adequate level of protection of personal data according to the standards established by the GDPR. Parisy has adopted the necessary precautions to ensure a lawful transfer of data (in particular, through the use of the Standard Contractual Clauses approved by the European Commission). You may request information about the transfer of your personal data abroad at any time by contacting us using the contact details indicated below.
5 HOW LONG DO WE RETAIN YOUR DATA
We retain your personal data for a limited period of time, which is strictly related to the purpose for which it was collected, and in conformity with the applicable legal or regulatory obligations. At the end of the established retention period, your personal data will be deleted, or in any case irreversibly anonymized, unless Parisy is required to retain the data for an additional period of time to comply with legal or regulatory obligations, or to exercise or defend a right in a judicial proceeding.
The retention period differs according to the purpose of the processing, in particular:
- for the online sale of products and the relative activities connected thereto, your personal data will be retained for the entire duration of the contractual relationship and for 10 (ten) years after the termination thereof, except for registration on the Site (“Account”) and the use of confidential services for registered users (for example: Wishlist, Orders, etc.), in relation to which your personal data will be retained until you request the deletion of your account;
- when Parisy processes your data for personalized marketing or profiling purposes, your data is retained for a period of 7 (seven) years from the time you provide your consent for the aforementioned purposes, following an evaluation of the impact on data protection conducted by Parisy, with the participation of its Data Protection Officer;
- for general marketing activities, your data is retained by Parisy until deletion is requested, consent revoked, or processing opposed; Parisy furthermore wishes to protect your data and ensure that you wish to continue to receive its communications. Therefore, it deletes your data when 4 (four) years have elapsed since your last interaction with the Parisy sphere, for example through purchases made at Parisy stores or the Site, participation in Parisy events or newsletters;
- to comply with legal obligations relating to personal data processing matters, your personal data will be processed by each controller, as concerns their specific area of authority, for the period needed to manage your request to exercise the rights recognized under the GDPR or to meet the legal obligation to which the data controller is subject. The data necessary to demonstrate compliance with the legal obligations to which the controller is subject shall be retained for 10 (ten) years;
- in case of a legal or administrative dispute, your data shall be retained for the time needed for Parisy or a third party to seek legal protection of a right, or within the limits imposed by the legal or administrative authority.
6 WHAT ARE YOUR RIGHTS
You may contact Parisy at any time, using the contact details specified below, to exercise your rights pursuant to the GDPR, and particular:
- to obtain confirmation of whether or not your personal data is being processed and, if it is, to obtain access to or a copy of such personal data (”right of access”);
- correction of your personal data, i.e. to obtain the correction, modification, or updating of any data that is inaccurate or no longer correct, as well as to supplement incomplete personal data, including by providing a supplementary declaration (“right of rectification”);
- to revoke your consent (“right to revoke consent”): you may revoke the consent you have given to process your personal data at any time, including in relation to any activity whatsoever with a marketing purpose, including profiling. To that end, we remind you that marketing activities are considered to be the sending of commercial and advertising communications, the completion of market research and surveys to determine level of satisfaction, and the personalization of commercial offers based on your interests. Once your request has been received, we will cease the processing of your personal data that was based on such consent, while different instances of processing, or processing based on other requirements, will continue to be performed in full compliance with the current provisions;
- to request the deletion of your personal data when such data, in particular, (i) is no longer necessary for the purposes for which it was collected or processed, or (ii) was unlawfully processed, or (iii) must be deleted to perform a legal obligation, or, lastly, (iv) you have opposed such processing (see below “right to object”) and there is no prevailing legitimate reason that would allow us to nevertheless proceed with the processing (“right to erasure” or “right to be forgotten”);
- to obtain a limitation on the processing of your personal data, i.e. that we retain such data, but without being able to use it, save for any requests or exceptions prescribed by law. This right may only be exercised when, in particular (i) you object to the accuracy of the personal data, for the period needed for the controller to verify the accuracy of such personal data, or (ii) the processing of data is unlawful and you ask us to limit its use, instead of deleting it, or (iii) even though the controller no longer needs it for processing purposes, you require the personal data to assess, exercise, or defend a right in a legal proceeding, or (iv) you have opposed its processing (see below “right to object”), while awaiting a verification as to any legitimate grounds of the controller that prevail over those of the data subject (right to restriction);
- to request your data or transfer it to a party other than the controller (“right to data portability”). You may ask to receive the data we process based on your consent or based on a contract entered with you, in a form that is structured, commonly used, and readable on an automatic device. If you so desire, where technically possible, we may, upon your request, transfer your data directly to a third party you indicate;
- submit a claim to one of the competent supervisory authorities on compliance with the personal data protection standards, if you believe that your data was unlawfully processed (“right to submit a claim”). In Italy, a claim may be filed with the Personal Data Protection Authority Garante per la Protezione dei Dati Personali.
Furthermore, as a data subject, you also have the “right to object”, i.e.:
- object at any time, for reasons related to your specific situation, to the processing of your personal data for the purpose of a legitimate interest of the controller or for marketing purposes, including profiling. We shall refrain from further processing your personal data, unless we can demonstrate that there are compelling, legitimate reasons to proceed with the processing that prevail over the interests, rights, and freedoms of the data subject, or to assess, exercise, or defend a right in judicial proceedings.
To ensure full respect of the rights described above, and that our users’ data is not unlawfully accessed or violated by third parties, prior to accepting a request from you to exercise one of the rights indicated, we may ask you for certain information to confirm your identity or clarify the request made.
7 CHANGES TO PRIVACY POLICY
The features, functionalities, and services offered by the Site may undergo changes in the future. Consequently, this Privacy Policy may be changed and supplemented over time. Therefore, we ask that you please periodically check the contents thereof.
8 DATA SECURITY
We adopt specific technical and organizational security measures to safeguard the confidentiality of Site users’ personal data, which are aimed at preventing the unlawful or fraudulent use of their personal data.
We remind you to take suitable precautions when using the Site, such as, for example, keeping your access credentials strictly private, and changing them periodically.
9 CONTACT DETAILS OF THE DATA CONTROLLER AND THE DATA PROTECTION OFFICER
When you interact with the Site, use our services or purchase our products Parisy (along with its affiliated entities worldwide) is responsible for the processing of your personal data, as described herein. Parisy s.r.l., with registered offices in ia Giordano 7, 36071, Arzignano (Vicenza), Italy, VAT number 04470210248 registered in the REA number VI-406468.
Our Data Protection Officer may be contacted at the following email address: customer@parisy.it