PRIVACY POLICY

POLICY FOR PROCESSING OF PERSONAL DATA
Pursuant to and by the effect of Article 13 of the European Regulation 2016/679 concerning the protection of individuals with regard to the processing of personal data (GENERAL DATA PROTECTION REGULATION – GDPR).
As required by the General Data Protection Regulation of the European Union (GDPR 2016/679, Article 13), before proceeding with processing, the interested party (User of the website www.barrow-bibas.com) is informed that personal data collected through the website are subject to processing by the Company through IT and/or telematic tools, for the purposes indicated in this policy.
To this end, the User is presented with the Privacy Policy prepared by SAILOR’S S.R.L. (hereafter as “BARROWBIBAS” or “the Company” or “the Data Controller”), creator and promoter of the activities available on the website www.barrow-bibas.com.

Data Controller
The Data Controller for personal data is SAILOR’S S.R.L with registered office in Via San Felice 32/a  40122, Bologna, Italia; Partita IVA (Tax ID): 03202470377.
The Data Protection Officer can be contacted for questions or concerns regarding the processing of personal data at the email
customercare@barrowbibas.com
For further information regarding the rights of the interested party, please consider the paragraph entitled “Rights of Interested Party” of this policy

Legal Basis and Purpose of Processing
The personal data provided by the User when browsing the website www.barrow-bibas.com are processed by the Data Controller in accordance with the current regulations for the protection of personal data.
The legal basis of the processing is identified in the provision of its services by the Company, in the management and facilitation of the website, as well as in the establishment, execution and possible termination of online sales contract concluded between the parties, and in the obligations of the same contract connected either directly and/or indirectly deriving from it.
The processing of your personal data by SAILOR’S SRL  is aimed at pursuing the following purposes:

1) SUBSCRIPTION TO THE BARROWBIBAS NEWSLETTER: In the case that you decide to subscribe to the “BARROWBIBAS Newsletter”, only after your express and specific consent, your personal data will be processed by the Data Controller for sending of commercial or promotional communications, relative updates, for example, to the latest trends, new arrivals, exclusive offers, special events and promotions. To unsubscribe from the newsletter simply click on the unsubscribe link at the bottom of the emails received or by writing to customercare@barrowbibas.com.

2) REGISTRATION ON BARROW-BIBAS.COM: In the case that you decide to register on the website www.barrow-bibas.com, only after your express and specific consent, personal data will be processed by the Data Controller for the purpose of registration on www.barrow-bibas.com. In particular, in providing your name, last name, email address and the setting of an access password, these will be processed for the creation of your personal account, to speed up the purchase process, to allow you to view the status of orders and receive updates on purchases made, as well as change personal settings and update your account, view the history of returns and requests for the exchange of goods.

3) ONLINE SHOPPING ACTIVITIES: The personal data you provide will be used for the establishment, management, execution and/or conclusion of the online sales contract. The data you provide will be processed by the Data Controller for the purpose of managing the purchase order with reference to, for example, payment, shipment, management of returns, customer support, administrative and accounting purposes related to the management of the order and the fulfillment of obligations under the current legislation. In case of payment by credit card, the fundamental information for the execution of the transaction (credit/debit card number, expiration date, security code) will be processed by Banca Sella – Worldpay – Adyen or, possibly, by companies in charge of the anti-fraud control using an encrypted protocol and without any third parties being able to access it in any way. This information will never be displayed or stored by the seller LUISA VIA ROMA S.p.A..

4) PROFILING OF THE PHYSICAL PERSON: Only after your express and explicit consent, the personal data you provided may be processed by the Data Controller for profiling activities, or analysis of your preferences aimed at creating personalized content and offers.

5) PERIOD OR CRITERION OF DATA RETENTION.

Your data will be kept for the time necessary to pursue the purposes that have been indicated above.

 

- The data we collect during registration - as a new user - will be kept until we have reason to consider you an active customer; in this sense we will endeavour to delete your profile if we do not record any purchase by you or other type of positive action (eg. modification of personal data) within 3 years, interpreting this inactivity as a desire to cancel your registration;

 

- the data relating to the management of your purchases, including those collected while you interact with our customer service or in the course of any returns or complaints against us, we will take care of

 

to keep them until 10 years after the cessation of processing, also in order to exercise the legitimate right of defence in any actions of contractual liability;

 

- the invoicing data will be kept on file for up to 10 years from the issue of the relative document, in order to comply with the requirements of art. 2220 of the Italian Civil Code;

 

- The personal data or contact data acquired during communications made to request information on products or services, will be kept up to 1 year from the last communication;

 

- your email addresses and other contact information that you provide us to activate the newsletter service will be processed until you request to cancel your subscription by direct request to the owner or by cancellation procedure at the bottom of each communication.

 

- Finally, the navigation data are automatically collected by means of cookies or other tracking technologies that help us to improve the user experience and understand the interactions on the site by users. To find out how long they are stored, please read our cookie policy.

 

6) RECIPIENTS AND OTHER PERSONS TO WHOM THE DATA IS DISCLOSED.

For the above purposes only, your data may be transmitted to:

 

- PERSONS AUTHORIZED TO TREATMENT: these are internal figures, specifically partners and employees of the Owner, who collect or process your data in relation to their respective duties and according to the profiles attributed to them.

 

- RESPONSIBLE OF THE PROCESSING: these are third party collaborators who process data on behalf of the Owner, through the stipulation of a specific agreement for appointment as Manager, by which the operations delegated to the third party are defined, as well as the security measures that the third party must adopt in order to best protect the information obtained from the Owner himself. In particular, they could process your data:

 

Provider of technological services including: the e-mail service Microsoft Outlook (with Data Center in Ireland and the Netherlands, to be considered Appropriate Countries); the e-mail service of Google (Gmail) and the service of Web Analytics of Google (Google Analytics), the latter able to analyze statistics on visitors to a website; in this regard, it should be noted that the company Google, including Google Inc. and its subsidiaries in the United States, has certified its adherence to the relevant principles of Privacy Shield. This certification is available at the following website: https://www.privacyshield.gov/welcome

the provider of the Website Hosting service; the provider of the MailChimp newsletter service, which has certified its compliance with the Privacy Shield; the provider of the cloud software with which we manage customer orders;

Companies, consultants or professionals possibly in charge of the installation, maintenance, updating and, in general, management of the hardware and software that we use for the provision of services;

Suppliers and collaborators of marketing and advertising services;

Our accountant for tax and accounting requirements;

- DESTINATORS: are those who receive communications of personal data from the Owner, but who, as a result of such communication, act as independent Owners. These include

 

Suppliers and collaborators of logistics, transport and delivery services;

Company that provides online payment solutions integrated with the e-commerce platform, calculating in real time the level of risk associated with each transaction;

Banks or credit institutions;

Insurance companies in the event of liability;

Judicial Authority and/or Public Safety Authority, in the cases expressly provided for by law.

 

7) THE RIGHTS OF THE INTERESTED PARTY.

You will always have the right to obtain confirmation from the Data Controller that personal data concerning you are being processed or not and, in this case, to obtain access to the personal data and information indicated in Art. 15 GDPR. Please note that, as a registered user, you can consult the data in our possession, through the section "My personal data" on your account, where you can also change or update the data previously entered.

In general, you also have the right to obtain the rectification, cancellation and limitation to the processing of your personal data held by the Owner. Finally, you have the right to lodge a complaint with the supervisory authority of the Member State in which you reside/work or the place where the alleged breach occurred.