PRIVACY POLICY

Privacy and Security of dietalinea.com
INFORMATION ON THE PROCESSING OF PERSONAL DATA pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR)

Premise

The following information is drawn up pursuant to art. 13 of EU Regulation 2016/679 - Giglio Group SpA Registered Office in Via Dei Volsci 163, 00185 Rome (RM) VAT no. IT 07396371002. REA number: MI - 2091150

1. Identity and contact details of the data controller

Giglio Group SpA (VAT number 07396371002), with registered office in Via Visconti di Modrone 11 , 20123 Milan registered in the Milan Company Register at no., tax code and VAT number IT 07396371002 (hereinafter also “Giglio Group Spa” or the “Owner”), is the owner of the processing of users’ personal data collected during a purchase on the e-shop site www.dietalinea.com (“Site”).

Giglio Group SpA :
Via Dei Volsci 163, 00185 Rome (RM)
Phone number:
email address: dietalinea@giglio.org


2. Contact details of the Data Protection Officer

The Data Protection Officer can be contacted at the Data Controller's headquarters at the address indicated above and/or by email at dpo.gigliogroup@giglio.org

3. Data processing by Giglio Group SpA for the purpose of executing the purchase contract on the Site

Giglio Group SpA in the event of a purchase on the Site, the user's personal data will be processed:

to execute the obligations arising from Giglio Group SpA from the purchase contract on the Site, such as, by way of example, the delivery of the products sold; and to allow the fulfillment of the obligations arising from the purchase contract on the Site by the customer, such as, by way of example, the payment for the products purchased.
The legal basis for this processing is the fulfillment of the contract (art. 6.1.b) of the GDPR.

For this purpose, Giglio Group SpA will retain user data for the time strictly necessary to carry out the individual processing activities (e.g. the data necessary for the execution of the purchase contract on the Site until the delivery of the product), it being understood that, once this period has expired, Giglio Group SpA may retain the data for the purposes and for the maximum retention periods indicated in the subsequent sections of this information notice and/or in any case in the cases established by the GDPR and/or by law.

The provision of data for the above-mentioned purpose is optional, there is no legal or contractual obligation to communicate the data; it is, however, a necessary requirement for the conclusion of the purchase contract on the Site: failure to communicate the data will make it impossible for the user to conclude such contract.

4. Data processing by Giglio Group SpA for assistance/customer care purposes in relation to purchases on the Site

Giglio Group SpA in the event of purchases on the Site, it will process the user's personal data for general assistance and customer care activities in relation to purchases on the Site and therefore to respond to requests for information from users or to respond to complaints, reports and disputes.
The legal basis for this processing is the execution of pre-contractual measures adopted at the request of the interested party (art. 6.1.b GDPR) or, as the case may be, the legitimate interest of Giglio Group SpA (art. 6.1.f GDPR). In fact, it constitutes a legitimate interest of Giglio Group SpA respond to requests for information and/or reports and/or disputes and/or complaints from users of the Site. The legitimate interest of Giglio Group SpA , thus identified, can therefore be considered to prevail over the fundamental rights and freedoms of the interested party, also by reason of such reasonable expectations.
In any case, the customer has the right to object, at any time, for reasons related to his personal situation, to the processing of personal data concerning him for the purpose of assistance and customer care.
To exercise this right, the user can write to Giglio Group SpA , Via Visconti di Modrone 11 , 20122 Milan at the email address dpo.gigliogroup@giglio.org

Learn more

In the event of exercising the right to object to the processing of data for assistance and customer care purposes, Giglio Group SpA refrains from further processing the personal data of users for this purpose, unless they demonstrate the existence of compelling legitimate reasons to proceed with the processing that prevail over the interests, rights and freedoms of the interested party or for the establishment, exercise or defense of a right in court.

For this purpose, Giglio Group SpA will retain customer data for the time strictly necessary to carry out the requested activities (e.g. for the time necessary to provide the requested information).

The provision of data for the above-mentioned purpose is optional, there is no legal obligation or The provision of data for the above-mentioned purpose is optional, there is no legal or contractual obligation to communicate the data; however, considering the purpose of the processing, failure to communicate the data and/or the exercise of the right of opposition, may make it impossible to respond to the customer's requests.

5. Data processing by Giglio Group SpA for administrative/accounting purposes in relation to purchases on the Site

Giglio Group SpA in the event of a purchase on the Site, it will process the user's personal data for the purposes of fulfilling administrative/accounting and/or fiscal obligations connected to the purchase contract on the Site.
The legal basis for this processing is the fulfillment of legal obligations to which Giglio Group SpA is subject to (art. 6.1.c GDPR).
The provision of data for the purpose in question is mandatory, because their processing is necessary to allow Giglio Group SpA to fulfill legal obligations incumbent on it. Any refusal to provide data for this purpose will make it impossible for the user to make purchases on the Site.
For this purpose, Giglio Group SpA will retain the user's data until the expiry of the legal terms provided for the performance of each administrative-accounting and fiscal obligation and/or for the retention periods provided by law.

6. Data processing by Giglio Group SpA in order to allow the user to exercise rights

Giglio Group SpA In the event of a purchase on the Site, it will process user data in order to:

respond to requests to exercise the right of withdrawal and/or requests to exercise the legal guarantee of conformity and/or other rights arising from the purchase contract
carry out any activities that prove necessary as a consequence of the exercise of such rights and to proceed, if applicable, with the related refunds
receive and respond to requests to exercise the rights regarding the protection of personal data provided for by the GDPR. The legal basis for this processing is the fulfillment of legal obligations (art. 6.1c GDPR).
Learn more

The provision of data for the purpose in question is mandatory, because their processing is necessary to allow Giglio Group SpA to fulfill legal obligations as well as the user to exercise the rights that the law or the contract grant to him. Any refusal to provide data for this purpose will make it impossible for the user to exercise such rights.
For this purpose, Giglio Group SpA will retain the user's data until the expiry of the legal terms provided for the exercise of the rights, or for the time necessary to manage and close the practice; in the case of exercising the rights provided for by the GDPR, the data will be processed until the data controller certifies that the request or fulfillment itself has been fulfilled.

7. Data processing by Giglio Group SpA for the purposes of ascertaining, exercising or defending a right in relation to purchases on the Site

Giglio Group SpA in the event of purchase on the Site, it will retain user data for the ascertainment, exercise or defense of a right in all competent venues. The legal basis for this processing is legitimate interest (art. 6.1.f GDPR).
It is a legitimate interest of the data controller to exercise the means of redress to ensure compliance with his contractual rights or to demonstrate that he has fulfilled the obligations arising from the purchase contract on the Site. This legitimate interest is based on the constitutionally protected right to defense and can therefore be considered to prevail over the fundamental rights and freedoms of the interested party.
In any case, the user has the right to oppose, for reasons related to his/her personal situation, the processing of data concerning him/her for this purpose, by writing to Giglio Group SpA at Via Dei Volsci 163, 00185 Rome (RM) or at the e-mail address dpo.gigliogroup@giglio.org

Learn more

The user is informed that Giglio Group Spa will retain the data for the purpose of proving the fulfillment of the purchase contract on the Site and/or to initiate or respond to actions relating to such contract; for this purpose the data will be retained for 10 years from the delivery of the product or from the termination of the contract, in the event of failure to deliver the product. In the event of exercising the rights provided for by the GDPR, the data will be retained for 5 years starting from the certification of having responded to the interested party's request.

Providing data for this purpose is optional: there is no legal or contractual obligation that requires the interested party to provide data for this purpose.

8 Categories of subjects to whom Giglio Group SpA communicates the user's personal data (recipients)

The subjects to whom Giglio Group Spa communicates the data, act as data controllers designated by Giglio Group Spa (“Data Processors”) or persons authorized to process personal data under the direct authority of Giglio Group Spa (“Appointees”), or in the case of third parties used by the Data Controller, as “Sub-Processors”, pursuant to art. 28.4 of the GDPR, except in cases where the recipient acts (also) as an independent data controller, as, for example, in the case of couriers.

Learn more

The personal data provided by the user during a purchase on the Site may be communicated by Giglio Group Spa to the categories of recipients indicated below.

companies of the group to which Giglio Group Spa belongs and/or to employees and/or collaborators of Giglio Group Spa for the performance of administration, accounting and IT and logistics support activities;
to all those subjects (including Public Authorities) who have access to personal data by virtue of regulatory or administrative provisions;
to companies, consultants or professionals possibly responsible for the installation, maintenance, updating and, in general, management of Giglio Group Spa hardware and software, including cloud computing service providers;
to companies or internet providers responsible for sending documentation and/or information material and/or soft-spam emails;
to all those public and/or private entities, natural and/or legal persons (legal, administrative and tax consultancy firms, Judicial Offices, Chambers of Commerce, Chambers and Labor Offices, etc.), if the communication is necessary or functional to the correct fulfillment of the contractual obligations undertaken in relation to the services on the Site, as well as the obligations deriving from the law or in the case of ascertaining, exercising or defending a right.
The list of recipients is available at the Giglio Group Spa headquarters

Data concerning users will not be disclosed.

9. Transfer to third countries

The personal data of customers collected during a purchase on the Site are not transferred to third countries.

10. Rights of the interested party

The interested party has the right to:

ask the Data Controller for confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, to obtain access to the personal data (right of access);
obtain from the Data Controller the rectification of personal data concerning him or her without undue delay. Taking into account the purpose of the processing, the interested party has the right to obtain the integration of incomplete personal data, including by providing a supplementary statement (right to rectification);
obtain from the Data Controller the deletion of personal data concerning him or her without unjustified delay, except in legitimate cases of exemption (right to deletion);
obtain from the Data Controller the limitation of processing when one of the following hypotheses occurs (right to limitation):
      • The data subject contests the accuracy of the personal data, for a period enabling the controller to verify the accuracy of the personal data;
      • The processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
      • Even if the Data Controller no longer needs the personal data for the purposes of the processing, the personal data are necessary for the data subject to ascertain, exercise or defend a right in court;
      • The interested party has objected to the processing in cases of processing based on the legitimate interest of the Data Controller, for reasons related to his particular situation, pending the verification of the possible prevalence of the legitimate reasons of the Data Controller over those of the interested party;
      • from the Data Controller in a structured, commonly used and machine-readable format, the personal data concerning him or her and has the right to transmit such data to another data controller without hindrance (right to data portability);
    Lodge a complaint with a supervisory authority (e.g. the Data Protection Authority) if you believe that the processing of your personal data violates the GDPR.

      To object, for reasons relating to his/her particular situation, to the processing of personal data concerning him/her, which has as its legal basis the legitimate interest of the Data Controller (right to object).

      In the event of exercising the right to object, the Data Controller shall refrain from further processing the personal data, unless he demonstrates the existence of compelling legitimate grounds for processing that prevail over the interests, rights and freedoms of the interested party or for the establishment or defense of a right in court.
      The rights referred to in this section may be exercised with a written request to the Data Controller at Via Dei Volsci 163, 00185 Rome (RM) or at the email address dpo.gigliogroup@giglio.org

      11 Changes

      The Data Controller reserves the right to make changes to this information at any time, giving appropriate publicity to the users of the Site and ensuring in any case adequate and similar protection of personal data. In order to view any changes, users are invited to consult this information regularly.