Privacy Policy

Who is the Data Controller? [1]

Maison TT Srl with registered office in Viale Ortigara, 5 - 36100, Vicenza (VI) (VAT number: 04487670244) (hereinafter, “Owner”)

How can I contact him?

The company contact details are:

Pec: maisontt@legalmail.it

Address: Viale Ortigara, 5 - 36100, Vicenza (VI)

  1. Premise

According to the European General Data Protection Regulation (GDPR), legal entities are not considered data subjects and therefore the European regulation does not apply. However, if in the context of the collection of company data personal data relating to a natural person are entered, this will be considered data subject according to the aforementioned regulation and the relevant legislation will consequently apply.

  1. What are the treatments that are carried out through the site? And what are the legal bases, purposes and retention times?

 

 

ECOMMERCE REGISTRATION/LOGIN

PURPOSE

The purpose of data processing is to register on the site and be able to make purchases more easily.

LEGAL BASIS

Consent of the interested party.
In the event of litigation, the data will be processed to act and/or defend itself in court based on the legitimate interest of the Data Controller.

 

STORAGE PERIODS

The data will be processed until consent is revoked.
In case the account remains inactive for years, we will send you an email to know if you are still interested in keeping it active; alternatively the account will be deleted.
The data will be processed for a longer period in case of dispute.

MORE INFORMATION

Registration is not mandatory to make purchases, as it is also possible to proceed in “guest” mode.

REGISTRATION VIA SOCIAL MEDIA

On the site there is the possibility to register through your Social account. Therefore, the data will not be provided directly by the interested party but imported from the platform and therefore processed pursuant to art. 14 GDPR. The data subject to processing are: personal data and email address.

 

 

PURCHASE

PURPOSE

The main purpose of data processing is to allow you to purchase and receive the requested product and, furthermore, they are necessary for the fulfillment of legal obligations (including accounting and tax).

The data could be used in the event of disputes raised regarding the correct fulfillment of the contract.

LEGAL BASIS

Execution of a contract and consequent fulfillment of the legal obligations incumbent on the data controller.

In the event of litigation, the data will be processed to act or defend oneself in court and this corresponds to the legitimate interest of the data controller.

 

STORAGE PERIODS

The data will be deleted after 10 years from the fulfillment of the contract.

They may be kept longer only in case of disputes and therefore to exercise or defend a right based on the legitimate interest of the data controller.

MORE INFORMATION

The provision of data is mandatory and in case of refusal to provide it, it will not be possible to purchase the requested products.

In relation to the purchase, the sending of transactional emails or SMS is foreseen for which, therefore, the consent of the interested party is not necessary.

 

 

NEWSLETTER/
DEM
even with automated methods (email, sms, whatsapp, social) or traditional

 

PURPOSE

The purpose of data processing is to send you newsletters and DEMs through traditional methods or even through automated methods (email, SMS, WhatsApp, social networks).

LEGAL BASIS

Consent given by the interested party pursuant to art. 6, co. 1, letter a) GDPR and 20% co. 1-2 Legislative Decree 196/03

 

STORAGE PERIODS

5 years from last submission.

MORE INFORMATION

Consent may be revoked at any time. The User has full freedom to provide the requested data, since there is no legal obligation to provide them. However, if the user chooses not to provide the data marked as essential, the Data Controller will not be able to achieve the indicated purpose.

 

 

NEWSLETTER/
DEM “Softspam”

PURPOSE

The purpose of data processing is to send you newsletters and DEMs.

If you purchase our product, your data will be exported to a CRM to send commercial information on products similar to those purchased.

LEGAL BASIS

In the case of purchase, your consent is not necessary pursuant to art. 20% c. 4 d.lgs. n. 196/03.

 

STORAGE PERIODS

5 years from the last sending. However, it is always possible to opt out.

MORE INFORMATION

You can exercise the output at any time.

 

 

MARKETING AND PROFILING THROUGH DIGITAL PLATFORMS

PURPOSE

The purpose of data processing is to display marketing content based on your interests, as identified by your interactions on our site or social media. This includes the use of retargeting tools on digital platforms to deliver targeted advertising messages.

LEGAL BASIS

Consent that can be acquired through various methods:

  1. Through Cookies on our Site: Your consent to marketing and profiling cookies is collected through the cookie settings on our site.
  2. For Custom Audience CRM Campaigns (Prospecting and Retargeting): For these campaigns, we obtain your explicit consent to use your contact data (e.g. email address) for marketing purposes.

Interaction with Social Pages: If you have given consent to the use of profiling cookies on our Site, we can process your contact details and the information communicated during the interaction with the Social Pages. We use this information, in accordance with your privacy settings on social media, to show personalized marketing announcements.

 

STORAGE PERIODS

The data will be stored until the consent is revoked through the cookie settings.

MORE INFORMATION

  1. Consent acquired through Cookies on our Site: The User can manage or revoke this consent at any time, as described in our Cookie Policy. We also inform you that cookies can be both first and third party and therefore installed, through us, directly by Meta.
  2. Consent acquired for Custom Audience CRM Campaigns (Prospecting and Retargeting): This consent allows us to process your data to identify similar audiences (lookalikes) and to display targeted advertisements on social media and other digital platforms.

In the case of simple segmentation of the User, your consent is not required.

 

 

REVIEW 1

PURPOSE

The purpose of data processing is to share your experience and opinion in relation to the purchased product.

LEGAL BASIS

Consent.

 

STORAGE PERIODS

Reviews will be posted on the site until they become obsolete and/or until consent is revoked.

MORE INFORMATION

Providing data is optional, since there is no legal obligation to release the review. However, if the User chooses not to provide the data deemed essential, it will not be possible to publish the review.

 

 

REVIEW 2

PURPOSE

The purpose of data processing is to share your experience and opinion in relation to the purchased product.

LEGAL BASIS

Legitimate interest of the Data Controller and consent provided to the tool to which the reviews are released.

 

STORAGE PERIODS

Reviews will be posted on the site until they become obsolete and/or until consent is revoked.

MORE INFORMATION

Providing data is optional, since there is no legal obligation to release the review. However, if the User chooses not to provide the data deemed essential, it will not be possible to publish the review.

 

 

ABANDONED CART

PURPOSE

The purpose of data processing is to be able to send 3 emails in one day to invite the user to finalize the interrupted purchase on the site.

LEGAL BASIS

Legitimate interest of the Data Controller in completing the purchase.

 

STORAGE PERIODS

72 hours

MORE INFORMATION

The provision of data is automatic and follows the partial compilation of the shopping cart.

 

 

BACK IN STOCK

PURPOSE

The purpose of data processing is to contact the User who requests it in the event that a product has become available again

LEGAL BASIS

Execution of pre-contractual measures carried out at the request of the interested party.

 

STORAGE PERIODS

The data will be stored for the time necessary to process the request and in any case no longer than 12 months from the provision.

MORE INFORMATION

Providing data is optional. However, if the User chooses not to provide data deemed essential, it will not be possible to contact him/her again.

 

 

CONTACT US

PURPOSE

The purpose of data processing is to allow the sending of requests for information

LEGAL BASIS

Execution of pre-contractual measures carried out at the request of the interested party.

In the event of litigation, the data will be processed to act or defend oneself in court and this corresponds to the legitimate interest of the data controller.

 

STORAGE PERIODS

We will process the data for the time necessary to respond to the requests and subsequently delete the data.

They may be kept longer only in case of possible disputes and therefore to exercise or defend a right based on the legitimate interest of the data controller.

The data obsolescence check is done every 12 months.

MORE INFORMATION

The User has full freedom to provide the requested data, since there is no legal obligation to provide them. However, if the user chooses not to provide the data marked as essential, the Data Controller will not be able to achieve the indicated purpose.

This treatment includes all contact methods (email, telephone, SMS, WhatsApp).

 

 

NAVIGATION DATA

PURPOSE

Site Security

LEGAL BASIS

We will process the data based on the legitimate interest of the company in IT security and compliance with legal obligations. The legal basis for the processing of cookies other than those necessary is consent.

 

STORAGE PERIODS

24 months

MORE INFORMATION

For the regulation on cookies, please refer to the specific information.

 

 

  1. What else do I need to know?

The data will be processed lawfully, fairly and with the utmost confidentiality, in compliance with the appropriate security measures as required by the Code and the Regulation. The processing will be carried out by digital means. The data will not be subject to public disclosure. Furthermore, the user will not be subjected to automated decision-making processes such as profiling unless he/she consents to this by installing cookies or other tracking tools for whose regulation, please refer to the specific information.

 

  1. To whom will my data be communicated?

The Owner may communicate the data to all subjects to whom communication is mandatory by law for the fulfillment of the purposes set out by law.

The Data Controller also uses some companies or IT tools that carry out processing activities on the personal data of the interested parties in the exclusive interest of the owner of the same, such as couriers, all adequately appointed as data controllers pursuant to art. 28 GDPR.

The data will also be communicated to the payment gateways as independent controllers.

The list of data controllers is available on site.

  1. Where is the data stored and transferred?

The management and storage of personal data will take place on servers located in EU and non-EU countries. However, the data may be transferred outside of Europe for the performance of certain activities (newsletter and back in stock). The Data Controller guarantees that the transfer outside the EU takes place in compliance with articles 44-47 Chapter V of the GDPR by signing standard contractual clauses and/or through the adequacy decision of 10 July 2023.

 

  1. What are my rights and how can I exercise them?
  2. a) Rights of the interested party

The user, in his capacity as interested party, has the rights set forth in art. 15 et seq. of the Regulation and specifically:

1. RIGHT OF ACCESS (art. 15 GDPR)

The interested party has the right to obtain confirmation of the existence or otherwise of personal data concerning him, even if not yet registered, and their communication in an intelligible form.

2. RIGHT TO RECTIFICATION (art. 16 GDPR)

The interested party has the right to obtain the rectification of inaccurate personal data concerning him or her and also the integration of incomplete data.

3. RIGHT TO CANCELLATION (art. 17 GDPR)

The interested party has the right to obtain the deletion of personal data in the presence of particular reasons such as the revocation of consent, opposition to the processing or if the data are no longer necessary with respect to the purposes for which they were collected and processed or in the event of unlawful processing. It will not always be possible to proceed with deletion but it will certainly be the responsibility of the data controller to provide adequate motivation.

4. RIGHT TO LIMIT PROCESSING (art. 18 GDPR)

The interested party has the right to obtain the limitation of the treatment in the presence of particular hypotheses such as, for example, in the case of a request for rectification or opposition during the evaluation period of the requests.

5. RIGHT TO PORTABILITY (art. 20 GDPR)

If the processing is based on consent or contract and is carried out with automated tools, the interested party can receive them in a structured, commonly used and machine-readable format or ask to transmit them to another owner.

6. RIGHT TO OBJECT (art. 21 GDPR)

The interested party has the right to object, in whole or in part:

a) for legitimate reasons to the processing of personal data concerning him/her, even if pertinent to the purpose of the collection;

b) to the processing of personal data concerning him/her for the pursuit of purposes not contemplated by art. 2.

The user can formulate a request to oppose the processing of his/her personal data pursuant to Article 21 of the GDPR in which he/she must highlight the reasons justifying the opposition: the Data Controller reserves the right to evaluate the request, which would not be accepted in the event of the existence of compelling legitimate reasons to proceed with the processing that prevail over the interests, rights and freedoms of the user.

7. RIGHT TO SUBMIT A COMPLAINT

The interested party has the right to lodge a complaint with the competent supervisory authority pursuant to Article 77 of the GDPR if he/she believes that the processing of his/her data is contrary to the legislation in force.

 

  1. b) Operating mode:

The interested party may at any time exercise the rights referred to in the previous article by contacting the data controller at the addresses indicated above.

Latest version: April 2024

 

This information has been prepared by Polimeni.Legal

[1] Pursuant to art. 4 n.7 GDPR: the data controller is the person who determines the purposes and means of the processing of personal data and his responsibilities are identified by art.24 GDPR.

If applicable, indicate a different term

If you do not plan to release reviews, leave only the phrase "The data will not be publicly disclosed".