Privacy policy

Privacy Policy

The purpose of this document (hereinafter the “Privacy Policy”) is to inform Users about personal data, understood as any information that allows the identification of a natural person (hereinafter the “Personal Data”), collected by the website www .madbagstore.com (hereinafter “Application”).

The Data Controller, as subsequently identified, may modify or simply update, in whole or in part, this Information by informing Users. Changes and updates will be binding as soon as they are published on the Application. The User is therefore invited to read the Privacy Policy each time they access the Application.

In case of non-acceptance of the changes made to the Privacy Policy, the User is required to cease using this Application and may request the Data Controller to remove their Personal Data.

  1. Personal Data collected by the Application

The Data Controller collects the following types of Personal Data:

  1. Content and information provided voluntarily by the User

- Contact data and contents: these are Personal Data that the User voluntarily provides to the Application during its use, such as personal data, contact details, access credentials for the services and/or products provided, personal interests and preferences and others personal content, etc.

- Personal data collected by social media: Users can share data provided to social media with the Application. The User has the right to control the Personal Data that the Application can access through the privacy settings available on the social media in question. By associating accounts managed by social media with the Application and authorizing the Owner to access such Personal Data, the User gives consent to their acquisition, processing and storage in accordance with this Privacy Policy.

Failure by the User to provide Personal Data, for which there is a legal or contractual obligation or if they constitute a necessary requirement for the use of the service or for the conclusion of the contract, will make it impossible for the Owner to fully provide or part of its services.

The User who communicates the Personal Data of third parties to the Owner is directly and exclusively responsible for their origin, collection, processing, communication or dissemination.

  1. Data and content acquired automatically when using the Application:

Technical data: the computer systems and software procedures used to operate this Application may acquire, during their normal operation, some Personal Data whose transmission is implicit in the use of internet communication protocols. This is information that is not collected to be associated with identified Users, but which by its very nature could, through processing and association with Data held by third parties, allow Users to be identified. This category includes IP addresses, or domain names used by Users who connect to the Application, the addresses in URI (Uniform Resource Identifier) ​​notation of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained, etc.

Usage data: Personal Data relating to the use of the Application by the User may also be collected, such as the pages visited, the actions performed, the functions and services used.

  1. Personal data collected via cookies or similar technologies:

The Application uses cookies, web beacons, unique identifiers and other similar technologies to collect Personal Data about the pages, links visited and other actions you take when using our services. They are stored before being re-transmitted on the next visit by the same User.

  1. Purpose

The Personal Data collected may be used for the execution of contractual and pre-contractual obligations and for legal obligations as well as for the following purposes:

External management of payments via credit card, bank transfer or other instruments: to manage User payments via external platforms that acquire payment data without the Application owner having access.

Sending emails or newsletters and managing mailing lists: to contact the User with emails containing commercial and promotional information relating to the Application.

User registration and authentication: to allow the User to register on the Application to access and be identified.

Archiving, hosting and backend infrastructure management: to manage the technical infrastructure for archiving User data.

Monitoring, analysis and tracking of User behavior: to monitor and analyze how he behaves

the User on the Application.

Support and contact with the User: to respond to the User's requests and help him in case of problems.

User Profiling: to automatically group and analyze the User's characteristics or behaviors and provide them with personalized services or messages.

Viewing content from external platforms: to allow the User to view and share content from social networks or other external platforms (e.g. YouTube, Facebook).

  1. Treatment methods

The processing of Personal Data is carried out using IT and/or telematic tools, with organizational methods and with logic strictly related to the purposes indicated.

In some cases, subjects involved in the Data Controller's organization may also have access to Personal Data (such as, for example, personnel management workers, sales area workers, system administrators, etc.) or external parties (such as IT companies, suppliers of services, postal couriers, hosting providers, etc.). If necessary, these subjects may be appointed Data Processors by the Owner, as well as access the Users' Personal Data whenever necessary and will be contractually obliged to keep the Personal Data confidential.

The updated list of Managers can be requested via email at info @ madbagstore.com

  1. Legal basis of the processing

The processing of Personal Data relating to the User is based on the following legal bases:

the consent given by the User for one or more specific purposes;

the processing is necessary for the execution of a contract with the User and/or the execution of pre-contractual measures

the processing is necessary to fulfill a legal obligation to which the Data Controller is subject

the processing is necessary for the execution of a task of public interest or for the exercise of public powers vested in the Data Controller

the processing is necessary for the pursuit of the legitimate interest of the Data Controller or third parties

the processing is necessary for the pursuit of a vital interest of the Owner or of third parties.

However, it is always possible to request the Data Controller to clarify the legal basis of each processing at info @madbagstore .com

  1. Place

Personal Data is processed at the Owner's operational offices and in any other place where the parties involved in the processing are located. For further information, contact the Owner at the following email address info@ madbagstore.com

Personal Data may be transferred to non-EU countries: USA.

For these countries there is an adequacy decision of the European Commission or, in the absence of such a decision, it is possible to request more information from the Data Controller regarding the appropriate guarantees adopted, as well as the means to obtain a copy of such Data or the exact place where they were returned available.

  1. Security measures

The Processing is carried out according to methods and with tools suitable to guarantee the security and confidentiality of the Personal Data, the Data Controller having adopted adequate technical and organizational measures which guarantee, and allow to demonstrate, that the Processing is carried out in compliance with the relevant legislation.

  1. Data retention period

Personal Data will be retained for the period of time necessary to fulfill the purposes for which they were collected.

In particular, Personal Data will be retained for the entire duration of the contractual relationship, for the execution of the obligations inherent and consequent thereto, for compliance with applicable legal and regulatory obligations, as well as for own or third party defensive purposes.

If the processing of Personal Data is based on the User's consent, the Owner may retain the Personal Data until the consent is revoked.

Personal Data may be retained for a longer period if necessary to comply with a legal obligation or by order of an authority.

All Personal Data will be deleted or stored in a form that does not allow identification of the User within 30 days of the end of the retention period. Upon expiration of this period, the right of access, cancellation, rectification and the right to portability of Personal Data can no longer be exercised.

  1. Automated decision-making processes

All Personal Data collected will not be subject to any automated decision-making process, including profiling, which could produce legal effects for the person or which could significantly affect them.

  1. User Rights

Users can exercise certain rights with reference to Personal Data processed by the Owner. In particular, the User has the right to:

revoke consent at any time;

object to the processing of your Personal Data;

access your Personal Data;

verify and request rectification;

obtain the limitation of processing;

obtain the deletion of your Personal Data;

receive your Personal Data or have it transferred to another owner;

lodge a complaint with the Personal Data Protection Supervisory Authority and/or take legal action.

To exercise their rights, Users can direct a request to the contact details of the Owner indicated in this document. Requests are made free of charge and processed by the Data Controller as quickly as possible, in any case within 30 days.

  1. Data Controller

The Data Controller is madbagstore.com

madbagstore

VAT number:

Site:

PEC:

Rea number:

CF:

Unique code:

Email: info@ madbagstore.com

In order to be able to offer you Klarna 's payment methods, we may pass on your personal data to Klarna at checkout in the form of contact details and order details, so that Klarna can assess your suitability for our payment methods. payment methods and customize those payment methods. Your personal data transferred is treated in line with Klarna 's privacy policy.

Privacy Policy of madbagstore.com

This Website collects some Personal Data from its Users.

This document can be printed using the print command in the settings of any browser.

Summary of the policy

Personal Data processed for the following purposes and using the following services:

  • Contact the user
    • Mailing list or newsletter

Personal Data: Postcode; city; surname; date of birth; Usage data; e-mail; physical address; nation; first name; telephone number; province; sex; Tracking Tools

    • Contact form

Personal Data: Postcode; city; Tax ID code; surname; date of birth; Usage data; e-mail; User ID; physical address; nation; first name; telephone number; province; sex; Tracking Tools; various types of Data

    • Contact via telephone

Personal Data: telephone number

 

  • Managing contacts and sending messages
    • Klaviyo

Personal Data: various types of Data

    • Sendgrid

Personal Data: surname; date of birth; e-mail; first name; telephone number; sex

  • Payment management
    • PayPal

Personal Data: surname; e-mail; billing address; first name; telephone number; various types of Data as specified in the privacy policy of the service

    • Apple Pay and Google Pay

Personal Data: surname; Usage data; e-mail; billing address; shipping address; first name; telephone number; various types of Data as specified in the privacy policy of the service

    • Klarna

Personal Data: surname; e-mail; billing address; shipping address; first name; telephone number; various types of Data as specified in the privacy policy of the service

    • Stripe

Personal Data: surname; Usage data; e-mail; billing address; first name; various types of Data as specified in the privacy policy of the service

  • Tag management
    • Google Tag Manager

Personal Data: Usage Data; Tracking Tools

  • Management of data collection and online surveys
    • Klaviyo Forms

Personal Data: Data communicated while using the service

  • Hosting and backend infrastructure
    • SiteGround

Personal Data: various types of Data as specified in the privacy policy of the service

  • Interaction with live chat platforms
    • Shopify Inbox

Personal Data: Data communicated while using the service

  • Interaction with social networks and external platforms
    • PayPal Button and Widgets, Linkedin Social Button and Widgets and Facebook Like Button and Social Widgets

Personal Data: Usage Data; Tracking Tools

  • Collection of privacy preferences
    • Consent Solution by iubenda

Personal Data: Data communicated while using the service; Tracking Tools

    • Cookie Solution by iubenda

Personal Data: Tracking Tools

  • Registration and authentication
    • Direct registration and profiling

Personal Data: Postcode; Tax ID code; surname; date of birth; Usage data; e-mail; User ID; image; profile picture; billing address; shipping address; physical address; tongue; House number; telephone number; province; sex; state; username; various types of Data

  • Registration and authentication provided directly by this Website
    • Direct registration

Personal Data: Postcode; city; Tax ID code; surname; date of birth; e-mail; User ID; image; profile picture; billing address; physical address; tongue; nation; first name; House number; telephone number; prefix; province; sex; state; username; various types of Data

  • Remarketing and behavioral targeting
    • Facebook Remarketing, Remarketing with Google Analytics and Google Ads Remarketing

Personal Data: Usage Data; Tracking Tools

    • Klaviyo segmentation and social advertising

Personal Data: purchase history; Usage data; e-mail; device information; Tracking Tools

    • Facebook Custom Audiences

Personal Data: email; Tracking Tools

  • Statistics
      • Google Analytics, Google Analytics with anonymized IP, Meta Events Manager, Facebook Ads conversion tracking (Facebook pixel), Google Ads conversion tracking

Personal Data: Usage Data; Tracking Tools

    • Google Analytics 4

Personal Data: device information; number of Users; session statistics; Tracking Tools

    • Google Analytics demographics and interests reports

Personal Data: unique device identifiers for advertising (Google Advertiser ID or IDFA identifier, for example); Tracking Tools

  • Viewing content from external platforms
      • Google Fonts, Font Awesome, Instagram Widget and YouTube Video Widget

Personal Data: Usage Data; Tracking Tools

Learn how to opt out of interest-based advertising

In addition to any opt-out feature provided by any of the services listed in this document, Users can read more about how to opt out of interest-based advertising in the appropriate section of the Cookie Policy.

Further information on the processing of Personal Data

    • Sale of goods and services online

The Personal Data collected is used for the provision of services to the User or for the sale of products, including payment and possible delivery. The Personal Data collected to complete the payment may be those relating to the credit card, the current account used for the bank transfer or other payment instruments provided. The Payment Data collected by this Website depends on the payment system used.

contact info

    • Data Controller

madbagstore

VAT number:

Site:

PEC:

Rea number:

CF:

Unique code:

Email: info@ madbagstore.com

Types of Data collected

Among the Personal Data collected by this Website, independently or through third parties, there are: Tracking Tools; Usage data; e-mail; first name; surname; telephone number; province; nation; POSTAL CODE; sex; date of birth; city; physical address; various types of Data; Tax ID code; User ID; billing address; Data communicated during use of the service; shipping address; username; state; image; profile picture; House number; tongue; prefix; device information; purchase history; number of Users; session statistics; unique device identifiers for advertising (Google Advertiser ID or IDFA identifier, for example).

Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed before the data is collected.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Website.
Unless otherwise specified, all Data requested by this Website is mandatory. If the User refuses to communicate them, it may be impossible for this Website to provide the Service. In cases where this Website indicates some Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or its operation.
Users who have doubts about which Data is mandatory are encouraged to contact the Owner.
Any use of Cookies - or other tracking tools - by this Website or by the owners of third-party services used by this Website, unless otherwise specified, has the purpose of providing the Service requested by the User, as well as to the additional purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Website and guarantees that he or she has the right to communicate or disseminate them, freeing the Owner from any liability towards third parties.

Method and place of processing of the collected data

Treatment methods

The Data Controller adopts appropriate security measures aimed at preventing unauthorized access, disclosure, modification or destruction of Personal Data.
The processing is carried out using IT and/or telematic tools, with organizational methods and with logic strictly related to the purposes indicated. In addition to the Owner, in some cases, other parties involved in the organization of this Website (administrative, commercial, marketing, legal, system administrators) or external parties (such as third-party technical service providers, postal couriers) may have access to the Data. , hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller. The updated list of Managers can always be requested from the Data Controller.

Legal basis of the processing

The Owner processes Personal Data relating to the User if one of the following conditions exists:

  • the User has given consent for one or more specific purposes; Note: in some jurisdictions the Owner may be authorized to process Personal Data without the User's consent or another of the legal bases specified below, until the User objects ("opt-out") to this treatment. However, this is not applicable if the processing of Personal Data is regulated by European legislation on the protection of Personal Data;
  • the processing is necessary for the execution of a contract with the User and/or the execution of pre-contractual measures;
  • the processing is necessary to fulfill a legal obligation to which the Data Controller is subject;
  • the processing is necessary for the execution of a task of public interest or for the exercise of public powers vested in the Data Controller;
  • the processing is necessary for the pursuit of the legitimate interest of the Data Controller or third parties.

However, it is always possible to request the Data Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on the law, provided for by a contract or necessary to conclude a contract.

Place

The Data is processed at the Owner's operational offices and in any other place where the parties involved in the processing are located. For further information, contact the Owner.
The User's Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the place of processing, the User can refer to the section relating to the details on the processing of Personal Data.

The User has the right to obtain information regarding the legal basis of the transfer of Data outside the European Union or to an international organization governed by public international law or constituted by two or more countries, such as for example the UN, as well as regarding the security measures adopted by the Data Controller to protect the Data.

The User can verify whether one of the transfers just described takes place by examining the section of this document relating to details on the processing of Personal Data or request information from the Data Controller by contacting him at the details indicated at the beginning.

Retention period

The Data is processed and stored for the time required by the purposes for which it was collected.

Therefore:

  • Personal Data collected for purposes related to the execution of a contract between the Owner and the User will be retained until the execution of this contract is completed.
  • Personal Data collected for purposes attributable to the legitimate interest of the Owner will be retained until such interest is satisfied. The User can obtain further information regarding the legitimate interest pursued by the Owner in the relevant sections of this document or by contacting the Owner.

When the processing is based on the User's consent, the Owner may retain the Personal Data for longer until such consent is revoked. Furthermore, the Owner may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period, the Personal Data will be deleted. Therefore, upon expiry of this deadline the right of access, cancellation, rectification and the right to data portability can no longer be exercised.

Purpose of the Processing of Collected Data

The User's Data is collected to allow the Owner to provide the Service, fulfill legal obligations, respond to requests or enforcement actions, protect their rights and interests (or those of Users or third parties), identify any malicious activities or fraudulent, as well as for the following purposes: Statistics, Displaying content from external platforms, Tag management, Contacting the User, Managing contacts and sending messages, Interaction with support and feedback platforms, Payment management, Heat mapping and session recording, Interaction with online survey platforms, Interaction with data collection platforms and other third parties, Management of data collection and online surveys, Management of support and contact requests, Hosting and backend infrastructure, Interaction with survey platforms live chat, Interaction with social networks and external platforms, Collection of privacy preferences, Registration and authentication, Registration and authentication provided directly by this Website, Remarketing and behavioral targeting and Platform and hosting services.

To obtain detailed information on the purposes of the processing and the Personal Data processed for each purpose, the User can refer to the "Details on the processing of Personal Data" section.

Details on the processing of Personal Data

Personal Data is collected for the following purposes and using the following services:

  • Contact the user

Mailing list or newsletter (this Website)

By registering on the mailing list or newsletter, the User's email address is automatically added to a contact list to which email messages containing information, including commercial and promotional information, relating to this Website may be sent. The User's email address may also be added to this list as a result of registering on this Website or after making a purchase.

Personal Data processed: Postal code; city; surname; date of birth; Usage data; e-mail; physical address; nation; first name; telephone number; province; sex; Tracking Tools.

Contact form (this Website)

By filling in the contact form with their data, the User consents to their use to respond to requests for information, quotes, or any other nature indicated by the header of the form.

Personal Data processed: Postal code; city; Tax ID code; surname; date of birth; Usage data; e-mail; User ID; physical address; nation; first name; telephone number; province; sex; Tracking Tools; various types of Data.

Contact via telephone (this Website)

Users who have provided their telephone number may be contacted for commercial or promotional purposes related to this Website, as well as to fulfill support requests.

Personal Data processed: telephone number.

  • Managing contacts and sending messages

This type of service allows you to manage a database of email contacts, telephone contacts or contacts of any other type, used to communicate with the User.
These services may also allow the collection of data relating to the date and time of viewing of messages by the User, as well as the User's interaction with them, such as information on clicks on links included in messages.

Klaviyo (Klaviyo Inc.)

Klaviyo is an address management and email message sending service provided by Klaviyo Inc.

To use the service provided by Klaviyo, the Owner generally shares information regarding Users (who make purchases), such as delivery data and purchase history. For further information regarding the scope of this sharing, check the information below under the heading "Personal Data processed".

Personal Data processed: various types of Data.

Place of processing: United States – Privacy Policy​​Opt out .

Sendgrid (Sendgrid)

Sendgrid is an address management and email message sending service provided by Sendgrid Inc.

Personal Data processed: surname; date of birth; e-mail; first name; telephone number; sex.

Place of processing: United States – Privacy Policy .

  • Payment management

Unless otherwise specified, this Website processes all payments by credit card, wire transfer or other means through external payment service providers. In general, and unless otherwise indicated, Users are asked to provide payment details and personal information directly to such payment service providers.
This Website is not involved in the collection and processing of such information: instead it will only receive a notification from the payment service provider in question that the payment has been made.

PayPal (Paypal)

PayPal is a payment service provided by PayPal Inc., which allows the User to make online payments.

Personal Data processed: surname; e-mail; billing address; first name; telephone number; various types of Data as specified in the privacy policy of the service.

Place of processing: Consult the PayPal privacy policy – ​​Privacy Policy .

Apple Pay (Apple Inc.)

Apple Pay is a payment service provided by Apple Inc., which allows the User to make payments using their mobile phone.

Personal Data processed: surname; Usage data; e-mail; billing address; shipping address; first name; telephone number; various types of Data as specified in the privacy policy of the service.

Place of processing: United States – Privacy Policy .

Google Pay

Google Pay is a payment service provided by Google LLC or by Google Ireland Limited, depending on how the Owner manages the processing of Data, which allows the User to make online payments using their Google credentials.

Personal Data processed: surname; Usage data; e-mail; billing address; shipping address; first name; telephone number; various types of Data as specified in the privacy policy of the service.

Place of processing: United States – Privacy Policy ; Ireland – Privacy Policy .

Klarna (Klarna AB)

Klarna is a payment service provided by Klarna AB.

Personal Data processed: surname; e-mail; billing address; shipping address; first name; telephone number; various types of Data as specified in the privacy policy of the service.

Place of processing: Sweden – Privacy Policy .

Stripe (Stripe Technology Europe Ltd)

Stripe is a payment service provided by Stripe Technology Europe Ltd.

Personal Data processed: surname; Usage data; e-mail; billing address; first name; various types of Data as specified in the privacy policy of the service.

Place of processing: Ireland – Privacy Policy .

  • Tag management

This type of service is functional to the centralized management of tags or scripts used on this Website.
The use of these services involves the flow of User Data through them and, if applicable, their retention.

Google Tag Manager

Google Tag Manager is a tag management service provided by Google LLC or by Google Ireland Limited, depending on how the Owner manages the processing of Data.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy ; Ireland – Privacy Policy .

  • Management of data collection and online surveys

This type of service allows this Website to manage the creation, implementation, administration, distribution and analysis of online forms and surveys in order to collect, save and reuse the Data of the Users who respond.
The Personal Data collected depends on the information requested and provided by Users in the corresponding online form.

These services can be integrated with a wide range of third-party services to allow the Owner to carry out subsequent actions with the processed Data - for example, contact management, sending messages, statistics, advertising and payment processing.

Hotjar surveys (Hotjar Ltd.)

Hotjar surveys is a survey generator and data collection platform provided by Hotjar Ltd.
Hotjar surveys may use cookies to track User behavior. Users can opt out of Hotjar surveys cookie tracking by visiting this opt-out page .

Hotjar surveys respects the “Do Not Track” option available in most modern browsers which, if activated, sends a special signal to stop tracking the User's activity. Users can find further information here on how to enable the “Do Not Track” option for each supported browser.

Personal Data processed: Data communicated during use of the service.

Place of processing: Malta – Privacy Policy​​Opt Out .

Klaviyo Forms (Klaviyo Inc.)

Klaviyo Forms is a form builder and data collection platform provided by Klaviyo Inc.

To use the service provided by Klaviyo, the Owner generally shares information regarding Users (who make purchases), such as delivery data and purchase history. For further information regarding the scope of this sharing, check the information below under the heading "Personal Data processed".

Personal Data processed: Data communicated during use of the service.

Place of processing: United States – Privacy Policy .

  • Heat mapping and session recording

Heat mapping services are used to identify the areas of this Website with which Users interact most frequently, in order to detect which of them attract the most interest. These services allow you to monitor and analyze traffic data and serve to keep track of the User's behavior.
Some of these services may record your sessions and make them available for you to view later.

Hotjar Heat Maps & Recordings (Hotjar Ltd.)

Hotjar is a heat mapping and session recording service provided by Hotjar Ltd.
Hotjar respects generic “Do Not Track” headers. This means that the browser can tell the script not to collect any user data. This is a setting that is available in all major browsers. More information on opting out from Hotjar is available here.

Personal Data processed: Usage data; Tracking Tools; various types of Data as specified in the privacy policy of the service.

Place of processing: Malta – Privacy Policy​​Opt Out .

  • Hosting and backend infrastructure

This type of service has the function of hosting Data and files that allow this Website to function, allow its distribution and provide a ready-to-use infrastructure to provide specific functions of this Website.

Some services listed below, if any, may operate on geographically distributed servers, making it difficult to determine the actual location where Personal Data is stored.

SiteGround

SiteGround is a hosting service

Personal Data processed: various types of Data as specified in the privacy policy of the service.

Place of processing: Italy – Privacy Policy .

  • Interaction with live chat platforms

This type of service allows you to interact with live chat platforms managed by third parties, directly from the pages of this Website, in order to be able to contact and be contacted by the support service of this Website.
If an interaction service with live chat platforms is installed, it is possible that, even if Users do not use the service, it collects Usage Data relating to the pages on which it is installed. Additionally, live chat conversations may be recorded.

Spotify Inbox

Spoyify Inbox is a service for interacting with the Spotify live chat platform

Personal Data processed: Data communicated during use of the service.

Place of processing: United States – Privacy Policy .

  • Interaction with data collection platforms and other third parties

This type of service allows Users to interact with data collection platforms or other services directly from the pages of this Website for the purpose of saving and reusing data.
If one of these services is installed, it is possible that, even if Users do not use the service, it collects Usage Data relating to the pages on which it is installed.

  • Interaction with social networks and external platforms

This type of service allows you to interact with social networks, or other external platforms, directly from the pages of this Website.
The interactions and information acquired from this Website are in any case subject to the User's privacy settings relating to each social network.
This type of service may still collect traffic data for the pages where the service is installed, even when Users do not use it.
It is recommended to log out of the respective services to ensure that the data processed on this Website is not linked to the User's profile.

PayPal Button and Widget (Paypal)

The PayPal button and widgets are interaction services with the PayPal platform, provided by PayPal Inc.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: Consult the PayPal privacy policy – ​​Privacy Policy .

Linkedin social button and widgets (LinkedIn Corporation)

The LinkedIn button and social widgets are interaction services with the LinkedIn social network, provided by LinkedIn Corporation.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy .

Facebook Like button and social widgets

The "Like" button and Facebook social widgets are interaction services with the Facebook social network, provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Data Controller manages the processing of Data,

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy ; Ireland – Privacy Policy .

  • Collection of privacy preferences

This type of service allows this Website to collect and save Users' preferences relating to the collection, use and processing of their personal information, as required by applicable privacy legislation.

Consent Solution by iubenda (iubenda srl)

The iubenda Consent Solution allows you to save and retrieve records of Users' consent to the processing of Personal Data, as well as the information and preferences expressed in relation to the consent provided.
To this end, it makes use of a Tracking Tool that temporarily stores pending information on the User's device until it is processed by the API. The Tracking Tool (a browser feature called localStorage) is then deleted.

Personal Data processed: Data communicated during use of the service; Tracking Tools.

Place of processing: Italy – Privacy Policy .

Cookie Solution by iubenda (iubenda srl)

The iubenda Cookie Solution allows the Owner to collect and save User preferences relating to the processing of personal data and in particular the use of Cookies and other Tracking Tools on this Website.

Personal Data processed: Tracking Tools.

Place of processing: Italy – Privacy Policy .

  • Registration and authentication

By registering or authenticating, the User allows this Website to identify him and give him access to dedicated services.
Depending on the following, registration and authentication services may be provided with the help of third parties. If this happens, this Website may access some Data stored by the third-party service used for registration or identification.
Some of the services indicated below may also collect Personal Data for targeting and profiling purposes; To find out more, please refer to the description of each service.

Direct registration and profiling (this Website)

By registering or authenticating, the User allows this Website to identify him and give him access to dedicated services. The Owner may process the Data collected at the time of registration or authentication by Users for targeting and profiling purposes; To find out more, Users can contact the Owner using the contact details provided in this document.

Personal Data processed: Postal code; Tax ID code; surname; date of birth; Usage data; e-mail; User ID; image; profile picture; billing address; shipping address; physical address; tongue; House number; telephone number; province; sex; state; username; various types of Data.

  • Registration and authentication provided directly by this Website

By registering or authenticating, the User allows this Website to identify him and give him access to dedicated services. Personal Data is collected and stored exclusively for registration or identification purposes. The Data collected is only that necessary to provide the service requested by the User.

Direct Registration (this Website)

The User registers by completing the registration form and providing his/her Personal Data directly to this Website.

Personal Data processed: Postal code; city; Tax ID code; surname; date of birth; e-mail; User ID; image; profile picture; billing address; physical address; tongue; nation; first name; House number; telephone number; prefix; province; sex; state; username; various types of Data.

  • Remarketing and behavioral targeting

This type of service allows this Website and its partners to communicate, optimize and serve advertisements based on the User's past use of this Website.
This activity is facilitated by tracking Usage Data and the use of Tracking Tools to collect information which is then transferred to partners who manage remarketing and behavioral targeting activities.
Some services offer a remarketing option based on email lists.
Generally, services of this type offer the possibility of deactivating such tracking. In addition to any opt-out feature provided by any of the services listed in this document, you can read more about how to opt-out of interest-based advertising in the "How to opt-out of interest-based advertising" section in this document.

Facebook Remarketing

Facebook Remarketing is a remarketing and behavioral targeting service provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Owner manages the processing of Data, which connects the activity of this Website with the advertising network Facebook.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy​​Opt Out ; Ireland – Privacy Policy​​Opt Out .

Klaviyo segmentation and social advertising (Klaviyo Inc.)

Klaviyo segmentation and social advertising is a remarketing and behavioral targeting service provided by Klaviyo Inc.

Klaviyo segmentation and social advertising uses tracking technology to monitor User behavior. This Data is then used to personalize the User experience and to provide targeted advertising. Klaviyo segmentation and social advertising may also connect the Data accumulated with other networks, including advertising networks, and enable these third parties to track and target the User. The Owner, unless otherwise provided in this document, has no direct relationship with the third parties that Klaviyo segmentation and social advertising may include.

To use the service provided by Klaviyo, the Owner generally shares information regarding Users (who make purchases), such as delivery data and purchase history. For further information regarding the scope of this sharing, check the information below under the heading "Personal Data processed".

Personal Data processed: purchase history; Usage data; e-mail; device information; Tracking Tools.

Place of processing: United States – Privacy Policy​​Opt out .

Facebook Custom Audiences

Facebook Custom Audiences is a remarketing and behavioral targeting service provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Owner manages the processing of Data, which connects the activity of this Website with the Facebook advertising network.

Users may opt out of using Facebook Tracking Tools for ad personalization by visiting this opt-out page .

Personal Data processed: email; Tracking Tools.

Place of processing: United States – Privacy Policy​​Opt Out ; Ireland – Privacy Policy​​Opt Out .

Remarketing with Google Analytics

Remarketing with Google Analytics is a remarketing and behavioral targeting service provided by Google LLC or by Google Ireland Limited, depending on how the Data Controller manages the processing of Data, which connects the tracking activity carried out by Google Analytics and its Tracking Tools Tracking with the Google Ads advertising network and the Doubleclick Cookie.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy​​Opt Out ; Ireland – Privacy Policy​​Opt Out Opt Out .

Google Ads Remarketing

Remarketing Google Ads is a remarketing and behavioral targeting service provided by Google LLC or by Google Ireland Limited, depending on how the Owner manages the processing of Data, which connects the activity of this Website with the Google Ads advertising network and the DoubleClick Cookie.

For an understanding of Google's use of Data, please review Google's partner policies .

Users can opt out of using Google Tracking Tools for ad personalization by visiting Google's Ad Settings .

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy​​Opt Out ; Ireland – Privacy Policy​​Opt Out .

  • Platform and hosting services

These services are intended to host and operate key components of this Website, making it possible to deliver this Website from a single platform. These platforms provide the Owner with a wide range of tools such as, for example, analytical tools, for managing user registration, for managing comments and the database, for e-commerce, for payment processing, etc. The use of these tools involves the collection and processing of Personal Data.
Some of these services work through servers that are geographically located in different locations, making it difficult to determine the exact location where Personal Data is stored.

WordPress.com (Automattic Inc.)

WordPress.com is a platform provided by Automattic Inc. that allows the Owner to develop, operate and host this Website.

Personal Data processed: various types of Data as specified in the privacy policy of the service.

Place of processing: United States – Privacy Policy .

  • Statistics

The services contained in this section allow the Data Controller to monitor and analyze traffic data and serve to keep track of the User's behavior.

Google Analytics

Google Analytics is a web analysis service provided by Google LLC or by Google Ireland Limited, depending on how the Data Controller manages the processing of Data, (“Google”). Google uses the Personal Data collected for the purpose of tracking and examining the use of this Website, compiling reports and sharing them with other services developed by Google.
Google may use Personal Data to contextualize and personalize the ads of its advertising network.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy​​Opt Out ; Ireland – Privacy Policy​​Opt Out .

Google Analytics with anonymized IP

Google Analytics is a web analysis service provided by Google LLC or by Google Ireland Limited, depending on how the Data Controller manages the processing of Data, (“Google”). Google uses the Personal Data collected for the purpose of tracking and examining the use of this Website, compiling reports and sharing them with other services developed by Google.
Google may use Personal Data to contextualize and personalize the ads of its advertising network.
This Google Analytics integration anonymizes your IP address. Anonymization works by shortening the IP address of the Users within the borders of the member states of the European Union or in other countries adhering to the Agreement on the European Economic Area. Only in exceptional cases, the IP address will be sent to Google servers and shortened within the United States.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy​​Opt Out ; Ireland – Privacy Policy​​Opt Out .

Meta Events Manager (Meta Platforms Ireland Limited)

Meta Events Manager is a statistics service provided by Meta Platforms Ireland Limited. By integrating the Meta pixel, Meta Events Manager can provide the Owner with information on traffic and interactions on this Website.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: Ireland – Privacy Policy .

Facebook Ads Conversion Tracking (Facebook Pixel)

Facebook Ads conversion tracking (Facebook pixel) is a statistics service provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Data Controller manages the processing of Data, which connects data from the network Meta ads with actions taken within this Website. The Facebook pixel tracks conversions that can be attributed to Facebook, Instagram and Audience Network ads.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy ; Ireland – Privacy Policy .

Google Analytics 4

Google Analytics is a statistics service provided by Google LLC or by Google Ireland Limited, depending on how the Data Controller manages the processing of Data, (“Google”). Google uses the Personal Data collected for the purpose of tracking and examining the use of this Website, compiling reports and sharing them with other services developed by Google.
Google may use Personal Data to contextualize and personalize the ads of its advertising network.
In Google Analytics 4, IP addresses are used at the time of collection and then deleted before the data is recorded in any data center or server. To learn more, you can consult Google's official documentation .

Personal Data processed: device information; number of Users; session statistics; Tracking Tools.

Place of processing: United States – Privacy Policy​​Opt Out ; Ireland – Privacy Policy​​Opt Out .

Google Ads conversion tracking

Google Ads conversion tracking is a statistics service provided by Google LLC or by Google Ireland Limited, depending on how the Data Controller manages the processing of data, which connects data from the Google Ads advertising network with the actions performed on the site. inside this Website.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy ; Ireland – Privacy Policy .

Google Analytics Demographics and Interest Reports

Google Analytics Demographics and Interest Reporting is an advertising reporting feature that makes Demographic and Interest Data available within Google Analytics for this Website (Demographic Data means age and gender Data ).

Users can choose not to use Google cookies by visiting Google's [Ad Settings] (https://adssettings.google.com/authenticated).

Personal Data processed: unique device identifiers for advertising (Google Advertiser ID or IDFA identifier, for example); Tracking Tools.

Place of processing: United States – Privacy Policy​​Opt Out ; Ireland – Privacy Policy​​Opt Out .

  • Viewing content from external platforms

This type of service allows you to view content hosted on external platforms directly from the pages of this Website and interact with them.
This type of service could still collect data on web traffic relating to the pages where the service is installed, even when users do not use it.

Google Fonts

Google Fonts is a character style visualization service managed by Google LLC or by Google Ireland Limited, depending on how the Data Controller manages the processing of Data, which allows this Website to integrate such content within its pages.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy ; Ireland – Privacy Policy .

Font Awesome (Fonticons, Inc.)

Font Awesome is a font style visualization service managed by Fonticons, Inc. that allows this Website to integrate such content within its pages.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy .

Instagram widgets

Instagram is an image viewing service managed by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Owner manages the processing of Data, which allows this Website to integrate such contents within its pages .

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy ; Ireland – Privacy Policy .

YouTube Video Widget

YouTube is a video content viewing service managed by Google LLC or by Google Ireland Limited, depending on how the Data Controller manages the processing of Data, which allows this Website to integrate such content within its pages.

Personal Data processed: Usage data; Tracking Tools.

Place of processing: United States – Privacy Policy ; Ireland – Privacy Policy .

Learn how to opt out of interest-based advertising

In addition to any opt-out feature provided by any of the services listed in this document, Users can read more about how to opt out of interest-based advertising in the appropriate section of the Cookie Policy.

Further information on the processing of Personal Data

  • Sale of goods and services online

The Personal Data collected is used for the provision of services to the User or for the sale of products, including payment and possible delivery. The Personal Data collected to complete the payment may be those relating to the credit card, the current account used for the bank transfer or other payment instruments provided. The Payment Data collected by this Website depends on the payment system used.

User Rights

Users can exercise certain rights with reference to the Data processed by the Owner.

In particular, the User has the right to:

  • revoke your consent at any time. The User may revoke the previously expressed consent to the processing of their Personal Data.
  • object to the processing of their Data. The User can object to the processing of their Data when it occurs on a legal basis other than consent. Further details on the right to object are set out in the section below.
  • access their Data. The User has the right to obtain information on the Data processed by the Owner, on certain aspects of the processing and to receive a copy of the Data processed.
  • verify and request rectification. The User can verify the correctness of their Data and request its updating or correction.
  • obtain the limitation of treatment. When certain conditions are met, the User can request the limitation of the processing of their Data. In this case the Owner will not process the Data for any purpose other than their conservation.
  • obtain the cancellation or removal of your Personal Data. When certain conditions are met, the User can request the deletion of their Data by the Owner.
  • receive your Data or have it transferred to another owner. The User has the right to receive their Data in a structured, commonly used and machine-readable format and, where technically feasible, to obtain its transfer without obstacles to another owner. This provision is applicable when the Data is processed with automated tools and the processing is based on the User's consent, on a contract of which the User is a party or on contractual measures connected to it.
  • lodge a complaint. The User can lodge a complaint with the competent personal data protection supervisory authority or take legal action.

Details on the right to object

When Personal Data is processed in the public interest, in the exercise of public powers vested in the Owner or to pursue a legitimate interest of the Owner, Users have the right to object to the processing for reasons related to their particular situation.

Users are reminded that, if their Data is processed for direct marketing purposes, they can object to the processing without providing any reason. To find out whether the Owner processes data for direct marketing purposes, Users can refer to the respective sections of this document.

How to exercise your rights

To exercise the User's rights, Users can direct a request to the contact details of the Owner indicated in this document. Requests are filed free of charge and processed by the Data Controller as quickly as possible, in any case within one month.

Cookie Policy

This Website uses Tracking Tools. To find out more, the User can consult the Cookie Policy.

Learn more about the treatment

Defense in court

The User's Personal Data may be used by the Owner in court or in the preparatory stages of its possible establishment for the defense against abuse in the use of this Website or related Services by the User.
The User declares to be aware that the Owner may be obliged to reveal the Data by order of public authorities.

Specific information

Upon request of the User, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

System logs and maintenance

For needs related to operation and maintenance, this Website and any third-party services used by it may collect system logs, i.e. files that record interactions and which may also contain Personal Data, such as the User's IP address.

Information not contained in this policy

Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

Response to “Do Not Track” requests

This Website does not support “Do Not Track” requests.
To find out whether any third-party services used support them, the User is invited to consult the respective privacy policies.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Website as well as, if technically and legally feasible, by sending a notification to Users through one of the extremes contact number he has. Please therefore consult this page frequently, referring to the date of last modification indicated at the bottom.

If the changes affect processing whose legal basis is consent, the Owner will collect the User's consent again, if necessary.

Definitions and legal references

Personal Data (or Data)

Any information which, directly or indirectly, also in connection with any other information, including a personal identification number, makes a natural person identified or identifiable constitutes personal data.

Usage Data

This is information collected automatically through this Website (also by third-party applications integrated into this Website), including: IP addresses or domain names of the computers used by the User who connects to this Website, the addresses in URI (Uniform Resource Identifier) ​​notation, the time of the request, the method used in forwarding the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc. .) the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (for example the time spent on each page) and details relating to the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the operating system and the User's IT environment.

User

The individual who uses this Website who, unless otherwise specified, coincides with the interested party.

Interested

The natural person to whom the Personal Data refers.

Data Controller (or Manager)

The natural person, legal person, public administration and any other body that processes personal data on behalf of the Data Controller, as set out in this privacy policy.

Data Controller (or Data Controller)

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data and the tools adopted, including security measures relating to the operation and use of this Website. The Data Controller, unless otherwise specified, is the owner of this Website.

This Website (or this Application)

The hardware or software tool through which the Personal Data of Users is collected and processed.

Service

The service provided by this Website as defined in the relevant terms (if available) on this site/application.

European Union (or EU)

Unless otherwise specified, any reference to the European Union contained in this document is intended to include all current member states of the European Union and the European Economic Area.

Cookies

Cookies are Tracking Tools that consist of small portions of data stored within the User's browser.

Tracking Tool

Tracking Tool means any technology - e.g. Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting - which allows Users to be tracked, for example by collecting or saving information on the User's device.

Legal references

This privacy information is drawn up on the basis of multiple legislative systems, including articles. 13 and 14 of Regulation (EU) 2016/679.

Unless otherwise specified, this privacy policy applies exclusively to this Website.

Integrations

This information is provided by madbagstore and as data controller (hereinafter also “Company” or “Data Controller”) of the personal data acquired via the website [ madbagstore.com], of which it is the owner, pursuant to the privacy and data protection legislation in force and taking into account the provisions of the Guarantor Authority for the Protection of Personal Data (hereinafter, also "Guarantor"), of Regulation (EU) 2016/679 (hereinafter also “Regulation”), of Legislative Decree no. 196/2003 and subsequent amendments. (hereinafter also “Privacy Code”) as well as, in general, the applicable reference legislation.

This information is provided to users who browse and use the services available on the website.
Your registration on the website is subject to prior reading and acceptance of this information relating to the processing of personal data and your authorization to the relevant processing.

Source and categories of data processed
The personal data that the Company may acquire will be acquired directly from the interested user who browses the website [ madbagstore.com]
The data processed may be, by way of example:

Browsing data
The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of internet communication protocols. This is information that is not collected to be associated with identified subjects, but which by its very nature could allow users to be identified. This category of data includes (i) the IP addresses or domain names of the computers used by users who connect to the site, (ii) the URI (Uniform Resource Identifier) ​​notation addresses of the requested resources, (iii) the time of the request, (iv) the method used to submit the request to the server, (v) the size of the file obtained in response, (vi) the numerical code indicating the status of the response given by the server (successful, error) and (vii ) other parameters relating to the operating system and the user's IT environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of this website and to check its correct functioning and are deleted immediately after processing.
This website uses its own and third-party technical, analytical and profiling cookies.

Data provided voluntarily by the user
The optional, explicit and voluntary sending by the user who browses this website and interacts with it via
• The €10 discount form for you on the page https://www. madbagstore.com/
• The registration form on the site, on the page https://www. madbagstore.com/account/register
• The purchase form on the page https://www. madbagstore.com/it/checkout/
• The return form on the page madbagstore.com/pages/resi-e-rimborsi
• The contact form on the page madbagstore.com/it/pages/contatti

involves the acquisition and processing by the Data Controller of such data and any other information contained in such communications for the purposes indicated in the following paragraph.
The data that may be processed are mainly identification, contact and personal data (for example, name and surname, residential address, telephone number, e-mail address, etc.). Under no circumstances will personal data of a sensitive nature be processed pursuant to art. 9 of the Regulation) or judicial data pursuant to art. 10 of the Regulation).

Furthermore, for needs related to the operation of this website or its maintenance, system logs may be processed, i.e. files that record interactions with the user and which may also include personal data, including the IP address of the user. 'user.

Complete details on each type of data collected will be provided in the dedicated sections of this privacy policy or through specific information texts which the user can view before collecting the data themselves.

Purpose of the processing
The processing of personal data acquired is carried out to:
a) outline the authentication profile necessary to access the site and therefore allow the user to register on the same (also for the purpose of issuing the loyalty card), implement the conditions of use of the site accepted during registration, allow the use of the services provided by this site (for example, the purchase of products, the shipping of purchased products, managing any returns) following the user's registration, for the management of any requests made by the user via the website . The provision of data is, depending on the case, a contractual obligation or a pre-contractual measure adopted at the request of the interested party and failure to provide it will make it impossible for the Company to give exact execution to what has just been outlined;
b) fulfill the obligations established by provisions of laws and regulations, or carry out an order from the judicial authority or other authorities to which the Data Controller is subject. The provision of data is a legal obligation and failure to provide it will make it impossible for the Company to exactly fulfill the obligations outlined above;
c) allow the Owner to carry out direct marketing activities, in order to provide the user with information on promotions, discounts, concessions, events, products and other services by the Owner, also by sending specific advertising material and/or information (e.g. catalogues) in paper and/or electronic form, by means of newsletters (via e-mail) or other tools (e.g. text messages, instant messaging). The provision of data is optional and requires prior consent from the user, free and specific, and failure to provide it will make it impossible for the Company to carry out the marketing activities contemplated therein (and will not have any negative consequences regarding the possibility to register or browse the website);
d) the collection, analysis of user behavior, profiling, recording and processing of purchase data, including those relating to the detail of the frequency, quantity and type of purchases (even if only potential) for the purpose of analyzing the propensity to purchase and, in general, user profiling to prepare and propose personalized promotions and offers, as well as for market analysis and research. The provision of data is optional and requires prior consent from the user, free and specific, and failure to provide it will make it impossible for the Company to carry out the profiling activities contemplated therein (and will not have any negative consequences regarding the possibility to register or browse the website).
e) the transfer of personal data to third parties operating in the sector of [•] for marketing purposes, market research or other sample research, for the detection of the degree of satisfaction, to receive informative, promotional, commercial and advertising or related material to competitions and initiatives, also through the sending of specific material (e.g. catalogues, flyers) in paper and/or electronic form, via newsletter (e-mail) or other tools (instant messaging). The provision of data is optional and requires prior consent from the user, free and specific, and failure to provide it will make it impossible for the Company to carry out the activities contemplated therein (and will not have any negative consequences regarding the possibility of registering or browse the website).
f) allow the Data Controller to register, following the user's subscription to the newsletter service or after making a purchase through this site, their e-mail address in a contact list to which they may be transmitted e-mails containing information of a commercial and promotional nature. The provision of data is optional and requires prior consent from the user, free and specific, and failure to provide it will make it impossible for the Company to carry out the activities contemplated therein (and will not have any negative consequences regarding the possibility of registering or browse the website).

Legal basis of the processing
The legal basis of the data processing is given depending on the processing by law, by the execution of contractual obligations or pre-contractual measures adopted at the request of the interested party as well as by the specific consent possibly given by the same.

Data processing methods and data retention
The processing of personal data will mainly take place using IT or telematic tools, or, as regards the use of personalized services through profiling, where the relevant consent is given, the processing will take place through an automated decision-making process using a specific algorithm which will decide which communications are most suited to the user's profile or which might be of most interest.
In any case, with reference to all the processing referred to herein, the Data Controller will adopt adequate security measures to guarantee the security and confidentiality of your personal data, all in compliance with the provisions of current legislation.
In carrying out processing activities, the Company undertakes, among other things, to:
• adopt suitable security measures to guarantee adequate data protection, in consideration of the potential impacts that the processing entails on the fundamental rights and freedoms of the interested party;
• notify, within the times and in the cases required by mandatory legislation, any violations of personal data to the interested parties;
• guarantee compliance of processing operations with applicable legal provisions.
The personal data of users of the site will be kept for the times strictly necessary to carry out the primary purposes illustrated in this information, or in any case as necessary for the protection of the rights of both the interests of the users and of the Company and in any case, where applicable , until your consent is revoked, which may occur at any time.
Specifically, the data will be processed in compliance with the timescales established within the relevant procedure, to be requested at privacy@.com
With specific reference to the transfer of data to third parties for the aforementioned purposes, please refer to the specific information drawn up by such third parties pursuant to art. 14 of the Regulation. In any case, the user is free, even in this case, to revoke the consent given at any time.

Scope of communication of personal data
In compliance with the minimum security measures, the data may also be communicated to public security entities and other public and private entities for the fulfillment of obligations established by law.
Furthermore, personal data will not be disclosed. However, they may be communicated to the following recipients:
• to companies that the Company uses to carry out tasks of a technical and organizational nature (by way of example but not limited to, companies that provide management services for the information system and communication networks, maintenance and assistance connected to the website );
• third-party companies operating in the review sector for marketing purposes;
• third-party firms or companies in the context of assistance and consultancy relationships;
• third-party companies that support the data controller for the delivery/delivery of purchases (ie couriers).
• third-party companies that allow monitoring of users in a statistical and aggregate manner (e.g. GA4)
The subjects belonging to the aforementioned categories perform the function of Data Processor, or operate in total autonomy as separate Data Controllers.

The data processing will be carried out by personnel employed by the Data Controller, specifically identified by the Data Controller as authorized data processors, who have received adequate training.

In compliance with the conditions and guarantees established by the Regulation, the data may be transferred to countries not belonging to the European Economic Area, including for example the United States of America (USA), which do not offer a level of privacy protection and of personal data protection comparable to that guaranteed by Italian and European laws. Such transfers may only take place in the presence of adequate guarantees or the explicit consent of the user.

Rights of the interested party
The subjects to whom the personal data refer have the right at any time to obtain confirmation as to whether or not personal data concerning them is being processed and, in this case, to obtain access to the data and information referred to in 'art. 15 of the Regulation, to obtain a copy of such data or the related rectification (articles 15 and 16 of the Regulation).
Furthermore, interested parties have the right to request cancellation, limitation of processing, portability of data as well as to lodge a complaint with the supervisory authority and to oppose in any case, for legitimate reasons, to their processing (art. 17 ss. of the Regulation) as well as, more generally, to exercise all the rights recognized by the current legal provisions.
The possibility of denying or revoking the consent previously provided at any time remains without prejudice to the lawfulness of the processing based on the consent before the revocation.
These rights can be exercised by written communication to be sent to: [•]

OWNER AND MANAGER OF THE TREATMENT
The data controller is

madbagstore

VAT number:

Site:

PEC:

Rea number:

CF:

Unique code:

Email: info@ madbagstore.com


A list of External Managers is available at the registered office of the Owner.

Notice regarding children under 14 years of age
Minors under the age of 14 cannot provide personal data. The Company will not be in any way responsible for any collection of personal data, as well as for false declarations, provided by the minor, and in any case, if its use is detected, the Data Controller will facilitate the right of access and cancellation forwarded by of the legal guardian or whoever exercises parental responsibility.

PRIVACY POLICY OF madbagstore.com

For information about your personal data collected, the purposes and the subjects with whom the data are shared, contact the Data Controller.

DATA CONTROLLER

Madbagstore

VAT number:

Site:

PEC:

Rea number:

CF:

Unique code:

Owner's email address: info@ madbagstore.com

TYPES OF DATA COLLECTED

The Owner does not provide a list of types of Personal Data collected.

Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed before the collection of the Data itself.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Application.
Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to communicate them, it may be impossible for this Application to provide the Service. In cases where this Application indicates some Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or its operation.
Users who have doubts about which Data is mandatory are encouraged to contact the Owner.
Any use of Cookies - or other tracking tools - by this Application or by the owners of third-party services used by this Application has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy.

The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Application.

METHOD AND PLACE OF PROCESSING OF COLLECTED DATA

The Data Controller adopts appropriate security measures aimed at preventing unauthorized access, disclosure, modification or destruction of Personal Data.
The processing is carried out using IT and/or telematic tools, with organizational methods and with logic strictly related to the purposes indicated. In addition to the Owner, in some cases, other parties involved in the organization of this Application (administrative, commercial, marketing, legal, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller. The updated list of Managers can always be requested from the Data Controller.

The Data is processed at the Owner's operational offices and in any other place where the parties involved in the processing are located. For further information, contact the Owner.
The User's Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the place of processing, the User can refer to the section relating to the details on the processing of Personal Data.

Unless otherwise indicated in this document, Personal Data is processed and stored for the time required by the purpose for which it was collected and may be stored for a longer period due to any legal obligations or based on the consent of the Users.

This Application uses Tracking Tools. To find out more, Users can consult the Cookie Policy .

This section applies to all users in the European Union, in accordance with the General Data Protection Regulation (the “GDPR”) and, for such Users, supersedes any other possibly divergent or conflicting information contained in the privacy policy. Further details regarding the categories of Data processed, the purposes of the processing, the categories of recipients of the Personal Data, if any, and further information on the Personal Data are available in the "Detailed information on the processing of Personal Data" section within this document .

The Owner processes Personal Data relating to the User if one of the following conditions exists:

  • the User has given consent for one or more specific purposes; Note: in some jurisdictions the Owner may be authorized to process Personal Data without the User's consent or another of the legal bases specified below, until the User objects ("opt-out") to this treatment. However, this is not applicable if the processing of Personal Data is regulated by European legislation on the protection of Personal Data;
  • the processing is necessary for the execution of a contract with the User and/or the execution of pre-contractual measures;
  • the processing is necessary to fulfill a legal obligation to which the Data Controller is subject;
  • the processing is necessary for the execution of a task of public interest or for the exercise of public powers vested in the Data Controller;
  • the processing is necessary for the pursuit of the legitimate interest of the Data Controller or third parties.

However, it is always possible to request the Data Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on the law, provided for by a contract or necessary to conclude a contract.

Unless otherwise indicated in this document, Personal Data is processed and stored for the time required by the purpose for which it was collected and may be stored for a longer period due to any legal obligations or based on the consent of the Users.

Therefore:

  • Personal Data collected for purposes related to the execution of a contract between the Owner and the User will be retained until the execution of this contract is completed.
  • Personal Data collected for purposes attributable to the legitimate interest of the Owner will be retained until such interest is satisfied. The User can obtain further information regarding the legitimate interest pursued by the Owner in the relevant sections of this document or by contacting the Owner.

When the processing is based on the User's consent, the Owner may retain the Personal Data for longer until such consent is revoked. Furthermore, the Owner may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period, the Personal Data will be deleted. Therefore, upon expiry of this deadline the right of access, cancellation, rectification and the right to data portability can no longer be exercised.

USER RIGHTS

Users can exercise certain rights with reference to the Data processed by the Owner.

In particular, within the limits established by law, the User has the right to:

  • revoke your consent at any time. The User may revoke the previously expressed consent to the processing of their Personal Data.
  • object to the processing of your Data. The User may object to the processing of their Data when it occurs on a legal basis other than consent.
  • access your Data. The User has the right to obtain information on the Data processed by the Owner, on certain aspects of the processing and to receive a copy of the Data processed.
  • verify and request rectification. The User can verify the correctness of their Data and request its updating or correction.
  • obtain the limitation of treatment. The User may request the limitation of the processing of their Data. In this case the Owner will not process the Data for any purpose other than their conservation.
  • obtain the cancellation or removal of your Personal Data. The User may request the deletion of their Data by the Owner.
  • receive your Data or have it transferred to another owner. The User has the right to receive their Data in a structured, commonly used and machine-readable format and, where technically feasible, to obtain its transfer without obstacles to another owner.
  • lodge a complaint. The User can lodge a complaint with the competent personal data protection supervisory authority or take legal action.

Users have the right to obtain information regarding the legal basis for the transfer of Data abroad including to any international organization regulated by international law or constituted by two or more countries, such as the UN, as well as regarding the measures of security adopted by the Owner to protect their Data.

When Personal Data is processed in the public interest, in the exercise of public powers vested in the Owner or to pursue a legitimate interest of the Owner, Users have the right to object to the processing for reasons related to their particular situation.

Users are reminded that, if their Data is processed for direct marketing purposes, they can object to the processing at any time, free of charge and without providing any reason. If Users object to processing for direct marketing purposes, the Personal Data will no longer be processed for these purposes. To find out whether the Owner processes Data for direct marketing purposes, Users can refer to the respective sections of this document.

To exercise their rights, Users can direct a request to the Owner's contact details indicated in this document. The request can be filed free of charge and the Owner will respond as quickly as possible, in any case within one month, providing the User with all the information required by law. Any rectifications, cancellations or limitations of processing will be communicated by the Data Controller to each of the recipients, if any, to whom the Personal Data has been transmitted, unless this proves impossible or involves a disproportionate effort. The Owner communicates these recipients to the User if he requests it.

FURTHER INFORMATION FOR USERS IN SWITZERLAND

This section applies to Users in Switzerland and, for such Users, supersedes any other possibly divergent or conflicting information contained in the privacy policy.

Further details relating to the categories of Data processed, the purposes of the processing, the categories of recipients of the personal data, if any, the retention period and other information on the Personal Data can be found in the section entitled "Detailed information on the processing of Personal Data" within this document .

YOUR RIGHTS UNDER THE FEDERAL DATA PROTECTION LAW

Users can exercise some rights relating to their data within the limits of the law, including the following:

  • right of access to Personal Data;
  • the right to object to the processing of their Personal Data (which also allows Users to request the limitation of the processing of Personal Data, the deletion or destruction of Personal Data, the prohibition on disclosure of Personal Data to third parties);
  • right to receive your Personal Data and to transfer it to another data controller (data portability);
  • right to request rectification of incorrect Personal Data.

HOW TO EXERCISE THESE RIGHTS

Any requests to exercise the User's rights can be addressed to the Owner through the contact details provided in this document. These requests are free and the Owner will respond as quickly as possible, providing Users with the information required by law.

ADDITIONAL INFORMATION FOR USERS IN BRAZIL

This section of the document integrates and completes the information contained in the rest of the privacy policy and is provided by the entity that operates this Application and, where applicable, its parent company and its subsidiaries and affiliates (for the purposes of this section collectively referred to as "we ", "our" or "ours").
This section applies to all Users in Brazil (such Users are referred to herein simply as “you”, “your”, “you” or “yours”), pursuant to the “Lei Geral de Proteção de Dados and, for such Users, prevails over any other potentially divergent or conflicting information contained in this privacy policy.
This part of the document uses the term “personal information” as defined by LGPD .

LEGAL BASES ON WHICH WE PROCESS YOUR PERSONAL INFORMATION

We process your personal information only if one of the legal bases for such processing exists. The legal bases are as follows:

  • your consent to the processing activities in question;
  • compliance with legal obligations that we are required to satisfy;
  • the execution of rules dictated by laws or regulations or by contracts, agreements or other similar legal instruments;
  • studies conducted by research institutions, preferably carried out on anonymized personal information;
  • the execution of a contract and related pre-contractual obligations, if you are a party to such contract;
  • the enforcement of our rights in court, administrative proceedings or arbitration;
  • the defense or physical safety of you or a third party;
  • health protection - in the context of procedures implemented by entities or professionals in the healthcare sector;
  • our legitimate interests, provided that your fundamental rights and freedoms do not override such interests; And
  • credit protection.

To find out more about the legal bases, you can contact us at any time using the contact details provided in this document.

CATEGORIES OF PERSONAL INFORMATION PROCESSED

To find out which categories of personal information are processed, you can refer to the "Details on the processing of Personal Data" section in this document.

WHY WE PROCESS YOUR PERSONAL INFORMATION

To find out why we process your personal information, please refer to the “Details on the processing of Personal Data” and “Purpose of the Processing of Collected Data” sections in this document.

YOUR PRIVACY RIGHTS IN BRAZIL, HOW TO SUBMIT A REQUEST AND HOW IT WILL BE HANDLED BY US

YOUR PRIVACY RIGHTS IN BRAZIL

You have the right to:

  • obtain confirmation of the existence of processing activities regarding your personal information;
  • access your personal information;
  • obtain rectification of your incomplete, inaccurate or out-of-date personal information;
  • obtain the anonymisation, blocking or deletion of unnecessary or excessive personal information, or that information which is processed in conflict with the provisions of the LGPD;
  • obtain information regarding the possibility of giving or refusing your consent and the related consequences;
  • obtain information about the third parties with whom we share your personal information;
  • obtain, upon your explicit request, the portability of your personal information (with the exception of anonymized information) to other suppliers of products or services, provided that our commercial and industrial secrets are safeguarded;
  • obtain the deletion of the personal information processed if the processing was carried out on the basis of your consent, unless one or more of the exceptions provided for in Article 16 LGPD apply;
  • withdraw your consent at any time;
  • lodge a complaint regarding your personal information with the ANPD (National Data Protection Authority) or a consumer protection body;
  • oppose processing activities in cases where such processing is not carried out in compliance with the provisions of the law;
  • request clear and adequate information regarding the criteria and procedures used in the context of automated decision-making processes; And
  • request the review of decisions that harm your interests, made exclusively on the basis of automated decision-making processes of your personal information. These include decisions to shape your personal, professional, consumer or creditor profile, or other aspects of your personality.

You will never be discriminated against, nor will you in any way suffer any treatment that is unfavorable to you, following the exercise of your rights.

HOW TO SUBMIT A REQUEST

You can send an explicit request to exercise your rights free of charge, at any time, using the contact details in this document or through your legal representative.

HOW AND HOW LONG WE WILL MANAGE YOUR REQUEST

We will do our best to respond to your request as soon as possible.
In any case, if it is impossible for us to do so, we will make sure to communicate to you the factual or legal reasons that prevent us from immediately satisfying or following up on your request. If your personal information is not processed by us, if we are able to do so, we will indicate to you the natural or legal person to whom your requests should be addressed.

In the event that you decide to submit a request for access or a request for confirmation of the existence of the treatment of personal information, please be sure to specify whether you prefer to receive your personal information in electronic or paper format.
You will also need to let us know if you want an immediate response, in which case you will receive a simplified response, or if you require full disclosure.
In the latter case, we will respond within 15 days from the time of your request, providing you with all the information regarding the origin of your personal information, confirmation or not of the existence of personal information concerning you, all the criteria used for the processing and the purposes of such processing, while safeguarding our commercial and industrial secrets.

In the event that you decide to submit a request for rectification, deletion, anonymization or blocking of personal information , we will ensure that we immediately inform the other parties with whom we have shared your personal information of your request so that they can also comply with your request - except where such communication is impossible or excessively burdensome for us.

TRANSFER OF PERSONAL INFORMATION OUTSIDE BRAZIL IN CASES PERMITTED BY LAW

We may transfer your personal information outside of Brazilian territory in the following cases:

  • when the transfer is necessary for international legal cooperation between intelligence services, investigative and criminal procedural bodies, as provided for by the tools made available by international law;
  • when the transfer is necessary to defend the life or physical safety of you or a third party;
  • when the transfer is authorized by the ANPD;
  • when the transfer arises from an obligation assumed in the context of an international cooperation agreement;
  • when the transfer is necessary for the exercise of public order or for the performance of a public service;
  • when the transfer is necessary for the fulfillment of a legal obligation, the execution of a contract and related pre-contractual obligations, or the normal exercise of rights in judicial, administrative or arbitration proceedings.

FUTHER INFORMATION FOR CALIFORNIA CONSUMERS

This section of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the business running this Application and, if the case may be, its parent, subsidiaries and affiliates (for the purposes of this section referred to collectively as “we”, “us”, “our”).

This section applies to all Users (Users are referred to below, simply as “you”, “your”, “yours”), who are consumers residing in the state of California, United States of America, according to the " California Consumer Privacy Act of 2018 " (the "CCPA"), as updated by the "California Privacy Rights Act" (the "CPRA") and subsequent regulations. For such consumers, this section supersedes any other possibly divergent or conflicting information contained in the privacy policy.

This part of the document uses the term “personal information” as defined in the California Consumer Privacy Act (CCPA/CPRA).

NOTICE AT COLLECTION

CATEGORIES OF PERSONAL INFORMATION COLLECTED, USED, SOLD, OR SHARED

In this section we summarize the categories of personal information that we've collected, used, sold, or shared and the purposes thereof. You can read about these activities in detail in the section titled “Detailed information on the processing of Personal Data” within this document.

INFORMATION WE COLLECT: THE CATEGORIES OF PERSONAL INFORMATION WE COLLECT

We have collected the following categories of personal information about you: .

We do not collect sensitive personal information.

We will not collect additional categories of personal information without notifying you.

WHAT ARE THE PURPOSES FOR WHICH WE USE YOUR PERSONAL INFORMATION?

We may use your personal information to allow the operational functioning of this Application and features thereof (“business purposes”). In such cases, your personal information will be processed in a fashion necessary and proportionate to the business purpose for which it was collected, and strictly within the limits of compatible operational purposes.

We may also use your personal information for other reasons such as for commercial purposes (as indicated within the section “Detailed information on the processing of Personal Data” within this document), as well as for complying with the law and defending our rights before the competent authorities where our rights and interests are threatened or we suffer an actual damage.

We won't process your information for unexpected purposes, or for purposes incompatible with the purposes originally disclosed, without your consent.

HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION?

Unless stated otherwise inside the “Detailed information on the processing of Personal Data” section, we will not retain your personal information for longer than is reasonably necessary for the purpose(s) they have been collected for.

HOW WE COLLECT INFORMATION: WHAT ARE THE SOURCES OF THE PERSONAL INFORMATION WE COLLECT?

We collect the above-mentioned categories of personal information, either directly or indirectly, from you when you use this Application.

For example, you directly provide your personal information when you submit requests via any forms on this Application. You also provide personal information indirectly when you navigate this Application, as personal information about you is automatically observed and collected.

HOW WE USE THE INFORMATION WE COLLECT: DISCLOSING OF YOUR PERSONAL INFORMATION WITH THIRD PARTIES FOR A BUSINESS PURPOSE

We do not disclose your personal information to third parties. For our purposes, the word “third party” means “a person who is not any of the following: a service provider or a contractor, as defined by the CCPA.

NO SALE OF YOUR PERSONAL INFORMATION

We do not sell or share your personal information. In case we should decide to, we will inform you before hand and will grant your right to opt out of such sale.

YOUR PRIVACY RIGHTS UNDER THE CALIFORNIA CONSUMER PRIVACY ACT AND HOW TO EXERCISE THEM

THE RIGHT TO ACCESS PERSONAL INFORMATION: THE RIGHT TO KNOW AND TO PORTABILITY

You have the right to request that we disclose to you:

  • the categories of personal information that we collect about you;
  • the sources from which the personal information is collected;
  • the purposes for which we use your information;
  • to whom we disclose such information;
  • the specific pieces of personal information we have collected about you.

You also have the right to know what personal information is sold or shared and to whom. In particular, you have the right to request two separate lists from us where we disclose:

  • the categories of personal information that we sold or shared about you and the categories of third parties to whom the personal information was sold or shared;
  • the categories of personal information that we disclosed about you for a business purpose and the categories of persons to whom it was disclosed for a business purpose.

The disclosure described above will be limited to the personal information collected or used over the past 12 months.

If we deliver our response electronically, the information enclosed will be "portable", i.e. delivered in an easily usable format to enable you to transmit the information to another entity without hindrance — provided that this is technically feasible.

THE RIGHT TO REQUEST THE DELETION OF YOUR PERSONAL INFORMATION

You have the right to request that we delete any of your personal information, subject to exceptions set forth by the law (such as, including but not limited to, where the information is used to identify and repair errors on this Application, to detect security incidents and protect against fraudulent or illegal activities, to exercise certain rights etc.).

If no legal exception applies, as a result of exercising your right, we will delete your personal information and notify any of our service providers and all third parties to whom we have sold or shared the personal information to do so — provided that this is technically feasible and doesn't involve disproportionate effort.

THE RIGHT TO CORRECT INACCURATE PERSONAL INFORMATION

You have the right to request that we correct any inaccurate personal information we maintain about you, taking into account the nature of the personal information and the purposes of the processing of the personal information.

THE RIGHT TO OPT OUT OF SALE OR SHARING OF PERSONAL INFORMATION AND TO LIMIT THE USE OF YOUR SENSITIVE PERSONAL INFORMATION

You have the right to opt out of the sale or sharing of your personal information. You also have the right to request that we limit our use or disclosure of your sensitive personal information.

THE RIGHT OF NO RETALIATION FOLLOWING OPT-OUT OR EXERCISE OF OTHER RIGHTS (THE RIGHT TO NON-DISCRIMINATION)

We will not discriminate against you for exercising your rights under the CCPA. This means that we will not discriminate against you, including, but not limited to, by denying goods or services, charging you a different price, or providing a different level or quality of goods or services just because you exercised your consumer privacy rights.

However, if you refuse to provide your personal information to us or ask us to delete or stop selling your personal information, and that personal information or sale is necessary for us to provide you with goods or services, we may not be able to complete that transaction.

To the extent permitted by the law, we may offer you promotions, discounts, and other deals in exchange for collecting, keeping, or selling your personal information, provided that the financial incentive offered is reasonably related to the value of your personal information.

HOW TO EXERCISE YOUR RIGHTS

To exercise the rights described above, you need to submit your verifiable request to us by contacting us via the details provided in this document.

For us to respond to your request, it's necessary that we know who you are. Therefore, you can only exercise the above rights by making a verifiable request which must:

  • provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative;
  • describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

We will not respond to any request if we are unable to verify your identity and therefore confirm the personal information in our possession actually relates to you.

Making a verifiable consumer request does not require you to create an account with us. We will use any personal information collected from you in connection with the verification of your request solely for the purposes of verification and shall not further disclose the personal information, retain it longer than necessary for purposes of verification, or use it for unrelated purposes.

If you cannot personally submit a verifiable request, you can authorize a person registered with the California Secretary of State to act on your behalf.

If you are an adult, you can make a verifiable request on behalf of a child under your parental authority.

You can submit a maximum number of 2 requests over a period of 12 months.

HOW AND WHEN WE ARE EXPECTED TO HANDLE YOUR REQUEST

We will confirm receipt of your verifiable request within 10 days and provide information about how we will process your request.

We will respond to your request within 45 days of its receipt. Should we need more time, we will explain to you the reasons why, and how much more time we need. In this regard, please note that we may take up to 90 days to fulfill your request.

Our disclosure(s) will cover the preceding 12-month period. Only with regard to personal information collected on or after January 1, 2022, you have the right to request that we disclose information beyond the 12-month period, and we will provide them to you unless doing so proves impossible or would involve a disproportionate effort .

Should we deny your request, we will explain to you the reasons behind our denial.

We do not charge a fee to process or respond to your verifiable request unless such request is manifestly unfounded or excessive. In such cases, we may charge a reasonable fee, or refuse to act on the request. In either case, we will communicate our choices and explain the reasons behind it.

FURTHER INFORMATION FOR VIRGINIA CONSUMERS

This section of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the controller running this Application and, if the case may be, its parent, subsidiaries and affiliates (for the purposes of this section referred to collectively as “we”, “us”, “our”).

This section applies to all Users (Users are referred to below, simply as “you”, “your”, “yours”), who are consumers residing in the Commonwealth of Virginia, according to the “Virginia Consumer Data Protection Act" (the "VCDPA"), and, for such consumers, it supersedes any other possibly divergent or conflicting information contained in the privacy policy.

This part of the document uses the term “personal data” as defined in the VCDPA.

CATEGORIES OF PERSONAL DATA PROCESSED

In this section, we summarize the categories of personal data that we've processed and the purposes thereof. You can read about these activities in detail in the section titled “Detailed information on the processing of Persona Data” within this document .

CATEGORIES OF PERSONAL DATA WE COLLECT

We have collected the following categories of personal data:

We do not collect sensitive data.

We will not collect additional categories of personal data without notifying you.

WHY WE PROCESS YOUR PERSONAL DATA

To find out why we process your personal data, you can read the sections titled “Detailed information on the processing of Personal Data” and “The purposes of processing” within this document.

We won't process your information for unexpected purposes, or for purposes incompatible with the purposes originally disclosed, without your consent.
You can freely give, deny, or withdraw such consent at any time using the contact details provided in this document.

HOW WE USE THE DATA WE COLLECT: SHARING OF YOUR PERSONAL DATA WITH THIRD PARTIES

We do not share nor disclose your personal data with third parties.

SALE OF YOUR PERSONAL DATA

We do not sell your personal data. In case we should decide to, we will inform you before hand and will grant your right to opt out of such sale.

PROCESSING OF YOUR PERSONAL DATA FOR TARGETED ADVERTISING

We do not process your personal data for targeted advertising. If we decide to do so, we will inform you before hand and will grant your right to opt out of the processing of your personal data for targeted advertising.

YOUR PRIVACY RIGHTS UNDER THE VIRGINIA CONSUMER DATA PROTECTION ACT AND HOW TO EXERCISE THEM

You may exercise certain rights regarding your data processed by us. In particular, you have the right to do the following:

  • access personal data: the right to know. You have the right to request that we confirm whether or not we are processing your personal data. You also have the right to access such personal data.
  • correct inaccurate personal data. You have the right to request that we correct any inaccurate personal data we maintain about you, taking into account the nature of the personal data and the purposes of the processing of the personal data.
  • request the deletion of your personal data. You have the right to request that we delete any of your personal data.
  • obtain a copy of your personal data. We will provide your personal data in a portable and usable format that allows you to transfer data easily to another entity — provided that this is technically feasible.
  • opt out of the processing of your personal data for the purposes of targeted advertising , the sale of personal data , or profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.
  • non-discrimination. We will not discriminate against you for exercising your rights under the VCDPA. This means that we will not, among other things, deny goods or services, charge you a different price, or provide a different level or quality of goods or services just because you exercised your consumer privacy rights. However, if you refuse to provide your personal data to us or ask us to delete or stop selling your personal data, and that personal data or sale is necessary for us to provide you with goods or services, we may not be able to complete that transaction. To the extent permitted by the law, we may offer a different price, rate, level, quality, or selection of goods or services to you, including offering goods or services for no fee, if you have exercised your right to opt out, or our offer is related to your voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program.

HOW TO EXERCISE YOUR RIGHTS

To exercise the rights described above, you need to submit your request to us by contacting us via the contact details provided in this document.

For us to respond to your request, we need to know who you are.

We will not respond to any request if we are unable to verify your identity using commercially reasonable efforts and therefore confirm that the personal data in our possession actually relate to you. In such cases, we may request that you provide additional information which is reasonably necessary to authenticate you and your request.

Making a consumer request does not require you to create an account with us. However, we may require you to use your existing account. We will use any personal data collected from you in connection with your request solely for the purposes of authentication, without further disclosing the personal data, retaining it longer than necessary for purposes of authentication, or using it for unrelated purposes.

If you are an adult, you can make a request on behalf of a child under your parental authority.

HOW AND WHEN WE ARE EXPECTED TO HANDLE YOUR REQUEST

We will respond to your request without undue delay, but in all cases and at the latest within 45 days of its receipt. Should we need more time, we will explain to you the reasons why, and how much more time we need. In this regard, please note that we may take up to 90 days to fulfill your request.

Should we deny your request, we will explain to you the reasons behind our denial without undue delay, but in all cases and at the latest within 45 days of receipt of the request. It is your right to appeal such decision by submitting a request to us via the details provided in this document. Within 60 days of receipt of the appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If the appeal is denied you may contact the Attorney General to submit a complaint .

We do not charge a fee to respond to your request, for up to two requests per year. If your request is manifestly unfounded, excessive or repetitive, we may charge a reasonable fee or refuse to act on the request. In either case, we will communicate our choices and explain the reasons behind them.

FURTHER INFORMATION FOR COLORADO CONSUMERS

This section of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the controller running this Application and, if the case may be, its parent, subsidiaries and affiliates (for the purposes of this section referred to collectively as “we”, “us”, “our”).

This section applies to all Users (Users are referred to below, simply as “you”, “your”, “yours”), who are consumers residing in the State of Colorado, according to the “Colorado Privacy Act" (the "CPA "), and, for such consumers, it supersedes any other possibly divergent or conflicting information contained in the privacy policy.

This part of the document uses the term “personal data” as defined in the CPA.

CATEGORIES OF PERSONAL DATA PROCESSED

In this section, we summarize the categories of personal data that we've processed and the purposes thereof. You can read about these activities in detail in the section titled “Detailed information on the processing of Persona Data” within this document .

CATEGORIES OF PERSONAL DATA WE COLLECT

We have collected the following categories of personal data:

We do not collect sensitive data.

We will not collect additional categories of personal data without notifying you.

WHY WE PROCESS YOUR PERSONAL DATA

To find out why we process your personal data, you can read the sections titled “Detailed information on the processing of Personal Data” and “The purposes of processing” within this document.

We won't process your information for unexpected purposes, or for purposes incompatible with the purposes originally disclosed, without your consent.
You can freely give, deny, or withdraw such consent at any time using the contact details provided in this document.

HOW WE USE THE DATA WE COLLECT: SHARING OF YOUR PERSONAL DATA WITH THIRD PARTIES

We do not share nor disclose your personal data with third parties.
For our purposes, the word "third party" means "a natural or legal person, public authority, agency, or body other than the consumer, controller, processor, or an affiliate of the processor or the controller" as defined by the VCDPA.

For our purposes, the word "third party" means "a person, public authority, agency, or body other than a consumer, controller, processor, or affiliate of the processor or the controller." as defined by the CPA.

SALE OF YOUR PERSONAL DATA

We do not sell your personal data. In case we should decide to, we will inform you before hand and will grant your right to opt out of such sale.

For our purposes, the word "sale", "sell", or "sold" means "the exchange of personal data for monetary or other valuable consideration by a controller to a third party" as defined by the CPA.

Please note that according to the CPA, the disclosure of personal data to a processor that processes personal data on behalf of a controller does not constitute a sale. In addition, other specific exceptions set forth in the CPA may apply, such as, but not limited to, the disclosure of personal data to a third party for the provision of a product or service requested by you.

PROCESSING OF YOUR PERSONAL DATA FOR TARGETED ADVERTISING

We do not process your personal data for targeted advertising. If we decide to do so, we will inform you before hand and will grant your right to opt out of the processing of your personal data for targeted advertising.

For our purposes, the word "targeted advertising" means "displaying to a consumer an advertisement that is selected based on personal data obtained or inferred over time from the consumer's activities across nonaffiliated websites, applications, or online services to predict consumer preferences or interests" as defined by CPA.

Please note that according to the CPA, targeted advertising does not include: “advertisements directed to a consumer in response to the consumer's request for information or feedback; advertisements based on activities within a controller's own websites or online applications or any affiliated website or online application; advertisements based on the context of a consumer's current search query, visit to an internet web site or online application; or processing personal data solely to measure or report advertising frequency, performance or reach”.

YOUR PRIVACY RIGHTS UNDER THE COLORADO PRIVACY ACT AND HOW TO EXERCISE THEM

You may exercise certain rights regarding your data processed by us. In particular, you have the right to do the following:

  • opt out of the processing of your personal data for the purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.
  • access personal data. You have the right to request that we confirm whether or not we are processing your personal data. You also have the right to access such personal data.
  • correct inaccurate personal data. You have the right to request that we correct any inaccurate personal data we maintain about you, taking into account the nature of the personal data and the purposes of the processing of the personal data.
  • request the deletion of your personal data. You have the right to request that we delete any of your personal data.
  • obtain a copy of your personal data. We will provide your personal data in a portable and usable format that allows you to transfer data easily to another entity – provided that this is technically feasible.

In any case, we will not increase the cost of, or decrease the availability of, a product or service, based solely on the exercise of any of your rights and unrelated to the feasibility or the value of a service. However, to the extent permitted by the law, we may offer a different price, rate, level, quality, or selection of goods or services to you, including offering goods or services for no fee, if our offer is related to your voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program.

HOW TO EXERCISE YOUR RIGHTS

To exercise the rights described above, you need to submit your request to us by contacting us via the contact details provided in this document.

For us to respond to your request, we need to know who you are and which right you wish to exercise.

We will not respond to any request if we are unable to verify your identity using commercially reasonable efforts and therefore confirm that the personal data in our possession actually relate to you. In such cases, we may request that you provide additional information which is reasonably necessary to authenticate you and your request.

Making a consumer request does not require you to create an account with us. However, we may require you to use your existing account. We will use any personal data collected from you in connection with your request solely for the purposes of authentication, without further disclosing the personal data, retaining it longer than necessary for purposes of authentication, or using it for unrelated purposes.

If you are an adult, you can make a request on behalf of a child under your parental authority.

HOW AND WHEN WE ARE EXPECTED TO HANDLE YOUR REQUEST

We will respond to your request without undue delay, but in all cases and at the latest within 45 days of its receipt. Should we need more time, we will explain to you the reasons why, and how much more time we need. In this regard, please note that we may take up to 90 days to fulfill your request.

Should we deny your request, we will explain to you the reasons behind our denial without undue delay, but in all cases and at the latest within 45 days of receipt of the request. It is your right to appeal such decision by submitting a request to us via the details provided in this document. Within 45 days of receipt of the appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If the appeal is denied you may contact the Attorney General to submit a complaint.

We do not charge a fee to respond to your request, for up to two requests per year.

FURTHER INFORMATION FOR CONNECTICUT CONSUMERS

This section of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the controller running this Application and, if the case may be, its parent, subsidiaries and affiliates (for the purposes of this section referred to collectively as “we”, “us”, “our”).

This section applies to all Users (Users are referred to below, simply as “you”, “your”, “yours”), who are consumers residing in the State of Connecticut, according to “An Act Concerning Personal Data Privacy and Online Monitoring " (also known as "The Connecticut Data Privacy Act" or the “CTDPA”), and, for such consumers, it supersedes any other possibly divergent or conflicting information contained in the privacy policy.

This part of the document uses the term “personal data” as defined in the CTDPA.

CATEGORIES OF PERSONAL DATA PROCESSED

In this section, we summarize the categories of personal data that we've processed and the purposes thereof. You can read about these activities in detail in the section titled “Detailed information on the processing of Persona Data” within this document .

CATEGORIES OF PERSONAL DATA WE COLLECT

We have collected the following categories of personal data:

We do not collect sensitive data.

We will not collect additional categories of personal data without notifying you.

WHY WE PROCESS YOUR PERSONAL DATA

To find out why we process your personal data, you can read the sections titled “Detailed information on the processing of Personal Data” and “The purposes of processing” within this document.

We won't process your information for unexpected purposes, or for purposes incompatible with the purposes originally disclosed, without your consent.
You can freely give, deny, or withdraw such consent at any time using the contact details provided in this document.

HOW WE USE THE DATA WE COLLECT: SHARING OF YOUR PERSONAL DATA WITH THIRD PARTIES

We do not share nor disclose your personal data with third parties.

For our purposes, the word "third party" means "a person, public authority, agency, or body other than a consumer, controller, processor, or affiliate of the processor or the controller." as defined by the CTDPA.

SALE OF YOUR PERSONAL DATA

We do not sell your personal data. In case we should decide to, we will inform you before hand and will grant your right to opt out of such sale.

For our purposes, the word "sale", "sell", or "sold" means "the exchange of personal data for monetary or other valuable consideration by a controller to a third party" as defined by the CTDPA.

Please note that according to the CTDPA, the disclosure of personal data to a processor that processes personal data on behalf of a controller does not constitute a sale. In addition, other specific exceptions set forth in the CTDPA may apply, such as, but not limited to, the disclosure of personal data to a third party for the provision of a product or service requested by you.

PROCESSING OF YOUR PERSONAL DATA FOR TARGETED ADVERTISING

We do not process your personal data for targeted advertising. If we decide to do so, we will inform you before hand and will grant your right to opt out of the processing of your personal data for targeted advertising.

For our purposes, the word "targeted advertising" means "displaying to a consumer an advertisement that is selected based on personal data obtained or inferred over time from the consumer's activities across non-affiliated websites, applications, or online services to predict consumer preferences or interests " as defined by CTDPA.

Please note that according to the CTDPA, targeted advertising does not include: “advertisements based on activities within a controller's own web sites or online applications; advertisements based on the context of a consumer's current search query, visit to an internet web site or online application; advertisements directed to a consumer in response to the consumer's request for information or feedback; or processing personal data solely to measure or report advertising frequency, performance or reach”.

YOUR PRIVACY RIGHTS UNDER THE CONNECTICUT DATA PRIVACY ACT AND HOW TO EXERCISE THEM

You may exercise certain rights regarding your data processed by us. In particular, you have the right to do the following:

  • access personal data. You have the right to request that we confirm whether or not we are processing your personal data. You also have the right to access such personal data.
  • correct inaccurate personal data. You have the right to request that we correct any inaccurate personal data we maintain about you, taking into account the nature of the personal data and the purposes of the processing of the personal data.
  • request the deletion of your personal data. You have the right to request that we delete any of your personal data.
  • obtain a copy of your personal data. We will provide your personal data in a portable and usable format that allows you to transfer data easily to another entity – provided that this is technically feasible.
  • opt out of the processing of your personal data for the purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.

In any case, we will not increase the cost of, or decrease the availability of, a product or service, based solely on the exercise of any of your rights and unrelated to the feasibility or the value of a service. However, to the extent permitted by the law, we may offer a different price, rate, level, quality, or selection of goods or services to you, including offering goods or services for no fee, if our offer is related to your voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program.

HOW TO EXERCISE YOUR RIGHTS

To exercise the rights described above, you need to submit your request to us by contacting us via the contact details provided in this document.

For us to respond to your request, we need to know who you are and which right you wish to exercise.

We will not respond to any request if we are unable to verify your identity using commercially reasonable efforts and therefore confirm that the personal data in our possession actually relate to you. In such cases, we may request that you provide additional information which is reasonably necessary to authenticate you and your request.

Making a consumer request does not require you to create an account with us. However, we may require you to use your existing account. We will use any personal data collected from you in connection with your request solely for the purposes of authentication, without further disclosing the personal data, retaining it longer than necessary for purposes of authentication, or using it for unrelated purposes.

If you are an adult, you can make a request on behalf of a child under your parental authority.

HOW AND WHEN WE ARE EXPECTED TO HANDLE YOUR REQUEST

We will respond to your request without undue delay, but in all cases and at the latest within 45 days of its receipt. Should we need more time, we will explain to you the reasons why, and how much more time we need. In this regard, please note that we may take up to 90 days to fulfill your request.

Should we deny your request, we will explain to you the reasons behind our denial without undue delay, but in all cases and at the latest within 45 days of receipt of the request. It is your right to appeal such decision by submitting a request to us via the details provided in this document. Within 45 days of receipt of the appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If the appeal is denied, you may contact the Attorney General to submit a complaint .

We do not charge a fee to respond to your request, for up to one request per year.

FURTHER INFORMATION FOR UTAH CONSUMERS

This section of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the controller running this Application and, if the case may be, its parent, subsidiaries and affiliates (for the purposes of this section referred to collectively as “we”, “us”, “our”).

This section applies to all Users (Users are referred to below, simply as “you”, “your”, “yours”), who are consumers residing in the State of Utah, according to the “Consumer Privacy Act" (the “UCPA "), and, for such consumers, it supersedes any other possibly divergent or conflicting information contained in the privacy policy.

This part of the document uses the term “personal data” as defined in the UCPA.

CATEGORIES OF PERSONAL DATA PROCESSED

In this section, we summarize the categories of personal data that we've processed and the purposes thereof. You can read about these activities in detail in the section titled “Detailed information on the processing of Persona Data” within this document .

CATEGORIES OF PERSONAL DATA WE COLLECT

We have collected the following categories of personal data:

We do not collect sensitive data.

We will not collect additional categories of personal data without notifying you.

WHY WE PROCESS YOUR PERSONAL DATA

To find out why we process your personal data, you can read the sections titled “Detailed information on the processing of Personal Data” and “The purposes of processing” within this document.

HOW WE USE THE DATA WE COLLECT: SHARING OF YOUR PERSONAL DATA WITH THIRD PARTIES

We do not share nor disclose your personal data with third parties.

For our purposes, the word "third party" means "a person other than: the consumer, controller, or processor; or an affiliate or contractor of the controller or the processor" as defined by the UCPA.

SALE OF YOUR PERSONAL DATA

We do not sell your personal data. In case we should decide to, we will inform you before hand and will grant your right to opt out of such sale.

For our purposes, the word "sale", "sell", or "sold" means "the exchange of personal data for monetary or other valuable consideration by a controller to a third party" as defined by the UCPA.

Please note that according to the UCPA, the disclosure of personal data to a processor that processes personal data on behalf of a controller does not constitute a sale. In addition, other specific exceptions set forth in the UCPA may apply, such as, but not limited to, the disclosure of personal data to a third party for the provision of a product or service requested by you.

PROCESSING OF YOUR PERSONAL DATA FOR TARGETED ADVERTISING

We do not process your personal data for targeted advertising. If we decide to do so, we will inform you before hand and will grant your right to opt out of the processing of your personal data for targeted advertising.

For our purposes, the word "targeted advertising" means "displaying to a consumer an advertisement that is selected based on personal data obtained or inferred over time from the consumer's activities across nonaffiliated websites, applications, or online services to predict consumer preferences or interests" as defined by UCPA.

Please note that according to the UCPA, targeted advertising does not include: “advertisements based on activities within a controller's own websites or online applications or any affiliated website or online application; advertisements based on the context of a consumer's current search query, visit to a web site or online application; advertisements directed to a consumer in response to the consumer's request for information, product, a service or feedback; or processing personal data solely to measure or report advertising performance, reach or frequency.”

YOUR PRIVACY RIGHTS UNDER THE UTAH CONSUMER PRIVACY ACT AND HOW TO EXERCISE THEM

You may exercise certain rights regarding your data processed by us. In particular, you have the right to do the following:

  • access personal data. You have the right to request that we confirm whether or not we are processing your personal data. You also have the right to access such personal data.
  • request the deletion of your personal data. You have the right to request that we delete any of your personal data.
  • obtain a copy of your personal data. We will provide your personal data in a portable and usable format that allows you to transfer data easily to another entity – provided that this is technically feasible.
  • opt out of the processing of your personal data for the purposes of targeted advertising or the sale of personal data.

In any case, we will not increase the cost of, or decrease the availability of, a product or service, based solely on the exercise of any of your rights and unrelated to the feasibility or the value of a service. However, to the extent permitted by the law, we may offer a different price, rate, level, quality, or selection of goods or services to you, including offering goods or services for no fee, if our offer is related to your voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program.

HOW TO EXERCISE YOUR RIGHTS

To exercise the rights described above, you need to submit your request to us by contacting us via the contact details provided in this document.

For us to respond to your request, we need to know who you are and which right you wish to exercise.

We will not respond to any request if we are unable to verify your identity using commercially reasonable efforts and therefore confirm that the personal data in our possession actually relate to you. In such cases, we may request that you provide additional information which is reasonably necessary to authenticate you and your request. We may retain your email address to respond to your request.

If you are an adult, you can make a request on behalf of a child under your parental authority.

HOW AND WHEN WE ARE EXPECTED TO HANDLE YOUR REQUEST

We will respond to your request without undue delay, but in all cases and at the latest within 45 days of its receipt. Should we need more time, we will explain to you the reasons why, and how much more time we need. In this regard, please note that we may take up to 90 days to fulfill your request.

Should we deny your request, we will explain to you the reasons behind our denial without undue delay, but in all cases and at the latest within 45 days of receipt of the request.

We do not charge a fee to respond to your request, for up to one request per year.

FURTHER INFORMATION ON TREATMENT

The User's Personal Data may be used by the Owner in court or in the preparatory stages of its possible establishment for the defense against abuse in the use of this Application or related Services by the User.
The User declares to be aware that the Owner may be obliged to reveal the Data by order of public authorities.

Upon request of the User, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

For needs related to operation and maintenance, this Application and any third-party services used by it may collect system logs, i.e. files that record interactions and which may also contain Personal Data, such as the User's IP address.

Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Application as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details contact he has. Please therefore consult this page frequently, referring to the date of last modification indicated at the bottom.

If the changes affect processing whose legal basis is consent, the Owner will collect the User's consent again, if necessary.

PERSONAL DATA (OR DATA)

Any information which, directly or indirectly, also in connection with any other information, including a personal identification number, makes a natural person identified or identifiable constitutes personal data.

USAGE DATA

This is information collected automatically through this Application (also by third-party applications integrated into this Application), including: IP addresses or domain names of the computers used by the User who connects with this Application, addresses in URI notation ( Uniform Resource Identifier), the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.) the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (for example the time spent on each page) and details relating to the itinerary followed within the Application, with particular reference the sequence of pages consulted, the parameters relating to the operating system and the User's IT environment.

USER

The individual who uses this Application who, unless otherwise specified, coincides with the interested party.

INTERESTED

The natural person to whom the Personal Data refers.

DATA PROCESSOR (OR MANAGER)

The natural person, legal person, public administration and any other body that processes personal data on behalf of the Data Controller, as set out in this privacy policy.

DATA CONTROLLER (OR OWNER)

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data and the tools adopted, including security measures relating to the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.

THIS APPLICATION

The hardware or software tool through which the Personal Data of Users is collected and processed.

SERVICE

The Service provided by this Application as defined in the relative terms (if available) on this site/application.

EUROPEAN UNION (OR EU)

Unless otherwise specified, any reference to the European Union contained in this document is intended to include all current member states of the European Union and the European Economic Area.


LEGAL REFERENCES

This privacy policy is drawn up on the basis of multiple legislative systems.

Unless otherwise specified, this privacy policy applies exclusively to this Application.