PRIVACY NOTICES
PRIVACY NOTICE FOR CUSTOMERS
PURSUANT TO ARTICLE 13 OF REGULATION (EU) 2016/679
Dear Customer,
Pè Pè S.r.l., acting as Data Controller, with registered office at Viale dei Mille 51, 27029 Vigevano (PV), Italy, Tax Code and VAT No. 00283040186, telephone +39 0381 310994, email: pepe@pepechildrenshoes.it, hereby informs you, pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter the “Regulation” or “GDPR”), that the personal data provided by you will be processed in compliance with the applicable European and national data protection legislation.
The processing of your personal data will be carried out in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, storage limitation, data minimisation, accuracy, integrity, confidentiality and accountability, while safeguarding your privacy and your rights.
Purposes And Legal Bases Of Processing
The personal data collected will be processed exclusively for the following purposes:
- Management of commercial activities and business relationships with customers, distributors, resellers and commercial partners;
- Management of orders, sales and supply of goods or services;
- Fulfilment of pre-contractual, contractual, legal, tax and administrative/accounting obligations;
- Management of payments, invoicing, accounting activities and related administrative obligations;
- Management of commercial communications and customer support services;
- Protection of the Data Controller’s rights and interests in judicial proceedings, management of disputes, contractual breaches, formal notices, settlements, debt collection procedures and credit protection activities;
- Management of user accounts and restricted areas of the website;
- Management of requests for information and contacts;
- Sending commercial communications relating to products or services similar to those already purchased by the customer pursuant to Article 130(4) of Italian Legislative Decree no. 196/2003 (“soft spam”).
For the above-mentioned purposes, the applicable legal bases for processing, pursuant to Article 6(1) of Regulation (EU) 2016/679, are:
- Article 6(1)(b): performance of a contract or implementation of pre-contractual measures;
- Article 6(1)(c): compliance with a legal obligation to which the Data Controller is subject;
- Article 6(1)(f): legitimate interest pursued by the Data Controller.
Nature Of Data Provision
The provision of personal data is necessary for the management of the above-mentioned purposes and, in particular, for the establishment and management of the commercial and contractual relationship, as well as for compliance with administrative, accounting, tax and legal obligations.
Failure to provide personal data, or providing incomplete or inaccurate data, may result in the impossibility, in whole or in part, of establishing, managing or continuing the contractual relationship and of fulfilling the obligations required by applicable law.
Methods Of Data Processing
The collected data may be processed both electronically and in paper form by personnel specifically authorised by the Data Controller and, where necessary, by third parties appointed as Data Processors pursuant to Article 28 of Regulation (EU) 2016/679.
Personal data shall be processed using appropriate tools and procedures designed to ensure their security, integrity, confidentiality and availability, in compliance with the principles set out by Regulation (EU) 2016/679 and the applicable national legislation.
The Data Controller adopts appropriate technical and organisational measures to protect personal data against risks of loss, unauthorised access, unlawful use, disclosure, alteration or destruction, in accordance with Article 32 GDPR, the provisions issued by the Italian Data Protection Authority and the internal procedures adopted by the Data Controller.
Scope Of Communication And Data Transfers
Personal data may be processed by employees and collaborators expressly authorised by the Data Controller within the scope of their duties and responsibilities.
The collected data may also be communicated to third parties engaged by the Data Controller for the provision of services related to the purposes indicated above, including, by way of example:
- consultants and professional firms;
- tax, legal and accounting advisors;
- banking institutions;
- software and IT service providers;
- technical support providers;
- IT system maintenance companies;
- administrative, organisational or commercial service providers acting on behalf of the Data Controller.
Such parties may process personal data either as Data Processors pursuant to Article 28 GDPR or as independent Data Controllers, in compliance with the applicable legal provisions and according to the instructions received from the Data Controller.
Personal data will not be disclosed to the public.
Personal data will mainly be processed within the European Union. Should it become necessary to transfer personal data to countries outside the European Economic Area (EEA), such transfers will be carried out in compliance with Articles 44 et seq. of Regulation (EU) 2016/679 and subject to the safeguards required by applicable law.
Data Retention Period
Personal data will be retained for the time strictly necessary to achieve the purposes described above and, in any case, for no longer than required to comply with contractual, pre-contractual, administrative, tax and legal obligations applicable to the Data Controller.
In particular, data relating to the management of the commercial, administrative and accounting relationship will generally be retained for a maximum period of 10 years, in compliance with the retention periods established by applicable civil and tax legislation.
In the event of judicial disputes, personal data may be retained for the entire duration of the proceedings and until the expiry of the applicable limitation periods for legal claims and appeals.
At the end of the applicable retention period, the data will be deleted, destroyed or anonymised, in accordance with the technical backup and storage procedures adopted by the Data Controller.
Rights Of The Data Subject
Pursuant to Articles 15-22 of Regulation (EU) 2016/679, data subjects may exercise their rights at any time, including the right to:
- obtain confirmation as to whether or not personal data concerning them are being processed;
- access their personal data;
- request rectification or updating of inaccurate or incomplete data;
- request erasure of personal data;
- request restriction of processing;
- obtain data portability;
- object, where applicable, to the processing of personal data.
Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (“Garante per la Protezione dei Dati Personali”) if they believe that the processing of their personal data infringes the applicable data protection legislation.
For the exercise of their rights or for any further information regarding the processing of personal data, data subjects may contact the Data Controller at:
E-mail: pepe@pepechildrenshoes.it
or by written communication to:
Pè Pè S.r.l.
Viale dei Mille 51
27029 Vigevano (PV)
Italy
Vigevano (PV), //________
THE DATA CONTROLLER
Pè Pè S.r.l.
PRIVACY NOTICE FOR SUPPLIERS
PURSUANT TO ARTICLE 13 OF REGULATION (EU) 2016/679
Dear Supplier,
Pè Pè S.r.l., acting as Data Controller, with registered office at Viale dei Mille 51, 27029 Vigevano (PV), Italy, Tax Code and VAT No. 00283040186, telephone +39 0381 310994, e-mail: pepe@pepechildrenshoes.it, hereby informs you that the personal data provided by you will be processed in compliance with the applicable European and national data protection legislation, including Regulation (EU) 2016/679 (hereinafter the “Regulation” or “GDPR”).
The processing of personal data will be carried out in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, storage limitation, data minimisation, accuracy, integrity, confidentiality and accountability, while safeguarding your privacy and your rights.
Purposes And Legal Bases Of Processing
The personal data collected will be processed exclusively for the following purposes:
- Management of contractual and pre-contractual relationships with suppliers, professionals, consultants and commercial partners;
- Management of orders, supplies, payments and related administrative, accounting and tax activities;
- Fulfilment of obligations established by laws, regulations and applicable legislation;
- Protection of the Data Controller’s rights and interests in judicial proceedings, management of disputes, contractual breaches, formal notices, settlements, debt collection procedures, credit protection activities and arbitration proceedings.
For the above-mentioned purposes, the applicable legal bases for processing, pursuant to Article 6(1) of Regulation (EU) 2016/679, are:
- Article 6(1)(b): performance of a contract or implementation of pre-contractual measures;
- Article 6(1)(c): compliance with a legal obligation to which the Data Controller is subject;
- Article 6(1)(f): legitimate interest pursued by the Data Controller.
Categories Of Data Processed And Nature Of Data Provision
The provision of personal data processed by the Data Controller, including identification data, corporate data, tax data, payment details and contact information, is necessary for the achievement of the purposes described above and for the proper management of the contractual, administrative and accounting relationship with the supplier.
Failure to provide personal data, or providing incomplete or inaccurate data, may result in the impossibility, in whole or in part, of establishing, managing or continuing the relationship with the Data Controller.
Methods Of Processing
The collected data may be processed both electronically and in paper form by personnel specifically authorised by the Data Controller and, where necessary, by third parties appointed as Data Processors pursuant to Article 28 of Regulation (EU) 2016/679.
Personal data shall be processed using appropriate tools and procedures designed to ensure their security, integrity, confidentiality and availability, in compliance with the principles set out by Regulation (EU) 2016/679 and the applicable national legislation.
The Data Controller adopts appropriate technical and organisational measures to protect personal data against risks of loss, unauthorised access, unlawful use, disclosure, alteration or destruction, in accordance with Article 32 GDPR and the provisions issued by the Italian Data Protection Authority.
Categories Of Recipients And Data Transfers
Personal data may be processed by employees and authorised personnel expressly designated by the Data Controller within the scope of their duties and responsibilities.
The collected data may also be communicated to third parties engaged by the Data Controller for activities related to the purposes indicated above, including, by way of example:
- consultants and professional firms;
- tax, legal and accounting advisors;
- banking institutions;
- software providers;
- IT service providers;
- administrative or organisational service providers acting on behalf of the Data Controller.
Such parties may process personal data either as Data Processors pursuant to Article 28 GDPR or as independent Data Controllers, in compliance with the applicable legal provisions and according to the instructions received from the Data Controller.
Personal data will not be disclosed to the public.
Personal data will mainly be processed within the European Union. Should it become necessary to transfer personal data to countries outside the European Economic Area (EEA), such transfers will be carried out in compliance with Articles 44 et seq. of Regulation (EU) 2016/679 and subject to the safeguards required by applicable law.
Data Retention Period
Personal data will be retained for the time strictly necessary to achieve the purposes described above and, in any case, for no longer than required to comply with contractual, administrative, tax and legal obligations applicable to the Data Controller.
In particular, data relating to supplier relationship management will generally be retained for a maximum period of 10 years, in compliance with the retention periods established by applicable civil and tax legislation.
In the event of judicial disputes, personal data may be retained for the entire duration of the proceedings and until the expiry of the applicable limitation periods for legal claims and appeals.
At the end of the applicable retention period, the data will be deleted, destroyed or anonymised, in accordance with the technical backup and storage procedures adopted by the Data Controller.
Rights Of The Data Subject
Pursuant to Articles 15-22 of Regulation (EU) 2016/679, data subjects may exercise their rights at any time, including the right to:
- obtain confirmation as to whether or not personal data concerning them are being processed;
- access their personal data;
- request rectification or updating of inaccurate or incomplete data;
- request erasure of personal data;
- request restriction of processing;
- obtain data portability;
- object, where applicable, to the processing of personal data.
Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (“Garante per la Protezione dei Dati Personali”) if they believe that the processing of their personal data infringes the applicable data protection legislation.
For the exercise of their rights or for any further information regarding the processing of personal data, data subjects may contact the Data Controller at:
E-mail: pepe@pepechildrenshoes.it
or by written communication to:
Pè Pè S.r.l.
Viale dei Mille 51
27029 Vigevano (PV)
Italy
Vigevano (PV), //________
THE DATA CONTROLLER
Pè Pè S.r.l.