Your privacy
Welcome to our website www.spmspa.it (the Site).
Your privacy and the security of your personal data are very important SPM S.p.A., so we collect and manage your personal data with the utmost care and take specific measures to keep it safe.
Below you will find the main information on the processing of your personal data by SPM S.p.A. in relation to your browsing of Site and the use of the services offered according to the provisions of the GDPR EU 679/2016. We also ask you to read the “Cookie Policy”, of the Site, which contain detailed information regarding the conditions relating to our services. Some services may be subject to specific legal terms, in which case we will give you all the appropriate information from time to time.
Who is the Data Controller?
Below is the main information on the processing of your personal data carried out by SPM S.p.A. with headquarters at Via Provinciale, 26 – 21030 Brissago (VA), CF e P.IVA 00201320124 as Data Controller.
For any clarification, question or requirement related to your privacy and the processing of your personal data, you can contact us at any time by sending a request to infospm@spmspa.it
What data do we process and why?
The personal data that SPM S.p.A. processes is that which you provide to us when you conclude an order and purchase goods, and that which we collect as you browse or use the services offered on Site. SPM S.p.A. can then collect data about you, for example, personal details such as name and surname, shipping address and billing address, browsing data and your purchase habits.
Your personal data is processed for the following purpose:
– provide you with the services of Site such as subscription to the newsletter;
In the aforementioned cases, the processing of your personal data is legitimate as it is necessary to provide you with the service that you have specifically requested.
We also conduct statistical surveys and analyses with data in aggregate form to understand how users interact and use the site, in order to improve our offer and our services.
However, only with your express consent will we process your personal data to:
– carry out commercial and promotional communication activities;
Who will process your data?
Your personal data is processed by personnel duly authorised by SPM S.p.A. as Data Controller. For organisational and functional needs related to the provision of services on Site, your data could also be processed by our suppliers. The latter have been evaluated and chosen by SPM S.p.A. for their proven reliability and competence. Some of these subjects may also be based in non-EU countries and, in these cases, the transfer of your personal data in these countries is carried out in compliance with the guarantees provided by GDPR.
How long do we keep your data?
We keep your personal data for a limited period of time depending on the purpose for which it was collected, at the end of which your personal data will be deleted or otherwise rendered anonymous in an irreversible way. The retention period is different depending on the processing purpose: for example, the data is used to send you our newsletter until you ask us to stop sending it (and no more than five years).
What are your rights?
At any time, depending on the specific processing, you may: revoke your consent to the processing, know which of your personal data we have in our possession, its origin and how it is used, request the update, correction or integration and in the cases provided for by the current provisions, the cancellation, the limitation of processing or oppose their processing. If you wish, you can request to receive your personal data in possession of SPM S.p.A. in a format readable by electronic devices and, where technically possible, we can transfer your data directly to a third party indicated by you.
If you believe that the processing of your personal data has been carried out illegally, you can file a complaint with one of the supervisory authorities responsible for compliance with the rules on personal data protection. In Italy, the complaint can be presented to the Italian Data Protection Authority (http://www.garanteprivacy.it/).
This information may be subject to changes and additions over time, so we invite you to check the contents periodically. Where possible, we will try to immediately inform you of any changes made.
Privacy Notice
- General information
Who is the Data Controller?
SPM S.p.A. with headquarters Via Provinciale, 26 – 21030 Brissago (VA), CF e P.IVA 00201320124 is the Data Controller, that is, the subject which decides how and why to process your personal data.
You can always contact SPM S.p.A. by writing to the above address infospm@spmspa.it - What personal data do we collect?
The categories of personal data that SPM S.p.A. collects and processes when you browse or purchase on Site are as follows:
a) we collect your e-mail address when you sign up for our newsletter service;
b) we collect information about your browsing on Site, such as the pages you visit and how you interact with the single page and we save this information on our servers.
We inform you that SPM S.p.A. does not process personal data relating to minors. If you access Site and use the services offered by SPM S.p.A., you declare that you are of legal age. - How do we use the personal data we collect?
SPM S.p.A. collects and processes your personal data for the following purposes:
a) statistical analysis and surveys. We use some information about your use of the site to perform statistical analysis and surveys in order to improve our offer and our services;
b) subject to your express consent, we may use the contact details you have provided for commercial communications on our products and services, in order to update you on news, new arrivals, exclusive products, our offers and promotions. In addition, always with your consent, we will be able to use your contacts as part of market research and surveys for the detection of satisfaction in order to improve our services and the relationship with our users. These communications will take place exclusively with the methods you have chosen (via e-mail, SMS, telephone, paper mail, Whatsapp).
Should you wish to authorize the activities referred to in point b) and subsequently do not wish to receive further communications from SPM S.p.A. or would like to limit the way in which to be contacted, you may interrupt these communications at any time by simply clicking on the appropriate unsubscribe link at the bottom of each communication, accessing your account, contacting SPM S.p.A. by writing to the above address.
We inform you that you may receive further communications from us even after submitting your unsubscription request, as some submissions may have already been planned, our systems may take some time to process your request.
In relation to all the activities mentioned above, we will process your personal data mainly through IT and electronic means; the means we use guarantee high safety standards, in full compliance with current legislation. - Legal basis of the processing
We process your personal data only in the presence of one of the conditions provided for by the law in force, and specifically:We will carry out the following processing only if you have given us your express consent:
• carrying out marketing activities and opinion polls and market research;
• analysis of your browsing and consumption habits in the use of your profile, in order to personalize your experience on our site.
Providing your personal data for these activities is absolutely optional. You are free to provide us with your data for these purposes, but without it, it will not be possible for SPM S.p.A. to carry out marketing activities, opinion polls and market research, and to analyse your habits. - Who will process your data?Your personal data will be processed by SPM S.p.A. internal staff who are specifically trained and authorized to process.
Your personal data will also be transmitted to third parties that we use to provide our services; these subjects have been adequately selected and offer a guarantee of compliance with the rules on the processing of personal data. These persons have been appointed as data controllers and carry out their activities according to the instructions given by SPM S.p.A. and under its control.
The third parties in question belong to the following categories: banking operators, internet providers, companies specialized in IT and telematic services; couriers; companies that carry out marketing activities; companies specialized in market research and data processing.
Your data may be transmitted to police and judicial and administrative authorities, in accordance with the law, for the detection and prosecution of crimes, the prevention and protection from threats to public security, to allow SPM S.p.A. to ascertain, exercise or defend a right in court, as well as for other reasons related to the protection of the rights and freedoms of others.
- Extra-EU data transfer
Some of the third parties listed in the previous paragraph “Who will process your data?” may be located in countries outside the European Union that nevertheless offer an adequate level of data protection, as established by specific decisions of the European Commission (http://www.garanteprivacy.it/home/provvedimenti-normativa/normativa/normativa-comunitaria-e-intenazionale/trasferimento-dei-dati-verso-paesi-terzi#1).
The transfer of your personal data to countries that do not belong to the European Union and that do not ensure adequate levels of protection will be performed only after conclusion between SPM S.p.A. and said subjects of specific agreements, containing safeguard clauses and appropriate safeguards for the protection of your personal data which are so-called “standard model clauses”, also approved by the European Commission, or if the transfer is necessary for the conclusion and execution of an agreement between you and SPM S.p.A. (for the purchase of goods offered on our site, for registration on the website or the use of services on the website) or for the management of your requests.
- How long do we keep the data?
We keep your personal data for a limited period of time, which is different depending on the type of activity that involves the processing of your personal data.
After this period, your data will be permanently erased or otherwise rendered anonymous in an irreversible way.
Your personal data is stored in compliance with the following terms and criteria:
a) data provided for commercial communications activities, opinion polls and market research: up to the request by the user to interrupt the activity and in any case within 2 years from the last interaction of any kind of user with SPM S.p.A.;
b) data used for carrying out market research and surveys for the detection of satisfaction: as long as the user does not request the termination of the activity.
In any case, for technical reasons, the termination of the processing and the subsequent cancellation or irreversible anonymisation of the related personal data will be final within thirty days of the terms indicated above. - Your rights
You can exercise your rights at any time with reference to the specific processing of your personal data by SPM S.p.A.. Below is their general description and how to practice them.
a) Access your data and modify it: you have the right to access your personal data and to request that it be correct, modified or integrated with other information. If you wish, we will provide you with a copy of your data in our possession.
b) Revoke your consent: you can revoke a consent you have given for the processing of your personal data in relation to any activity for marketing purposes at any time. In this regard, we remind you that marketing activities are considered the sending of commercial and promotional communications, the conduct of market research and surveys for the detection of satisfaction for the customisation of the website and commercial offers according to your interests. Once we receive your request, it will be our duty to promptly cease to process your personal data based on this consent, while different processing or that which is based on other assumptions will continue to be carried out in full compliance with the provisions in force.
c) Opposition to the processing of your data: you have the right to object at any time to the processing of your personal data made on the basis of our legitimate interest, explaining the reasons that justify your request; before accepting it, SPM S.p.A. will have to evaluate the reasons for your request.
d) Delete your data: you may request the cancellation of your personal data in the cases provided for by current legislation. Once your request has been received and examined and if it is legitimate, it will be our duty to timely cease to process your personal data and to delete it.
e) Request of restriction of the processing: in this case, SPM S.p.A. will continue to keep your personal data but will not process it, unless it is subject to your different request and the exceptions established by law. Processing of your personal data can be limited when you dispute the accuracy of your personal data, when the processing is illegal but you oppose the cancellation of your data, when we no longer need your personal data but you need to exercise your right in court and when you oppose your processing, in the period in which we evaluate the reasons for your request.
f) Request of data transfer to other party than SPM S.p.A. (“right to data portability”). You can ask to receive your data that we process based on your consent or on the basis of an agreement with you in a standard format. If you wish, where technically possible and at your request, we may transfer your data directly to a third party that you indicate.
In order to exercise some of your rights described above you can access your profile or alternatively you can contact us by writing to the address of the Data Controller above.
In order to ensure that our users’ data is not infringed or illegitimate by third parties, we will ask you for some information to be sure of your identity before accepting your request to exercise one of the rights indicated.
- Security measures
We protect your personal data with specific technical and organisational security measures, aimed at preventing your personal data from being used illegitimately or fraudulently. In particular, we use security measures that guarantee: the pseudonymisation or the encryption of your data; the confidentiality, integrity, availability of your data as well as the resilience of the systems and services that process them; the ability to restore data in the event of a data breach. Furthermore, SPM S.p.A. agrees to test, verify and regularly evaluate the effectiveness of technical and organisational measures in order to guarantee continuous improvement in the security of processing.
- Complaints
If you believe that the processing of your personal data has been carried out illegally, you can file a complaint with one of the supervisory authorities responsible for compliance with the rules on personal data protection.
In Italy, the complaint can be presented to the Italian Data Protection Authority.
More information on the presentation methods are available on the website of the Italian Data Protection Authority, at http://www.garanteprivacy.it.
- Changes to this information
The constant development of our services may lead to changes in the characteristics of the processing of your personal data described up to now. Consequently, this privacy policy may be subject to changes and additions over time, which may also be necessary with regard to new regulatory measures regarding the protection of personal data.
Therefore, we invite you to periodically check the contents: where possible, we will try to inform you promptly on the changes made and their consequences in In any case, the updated version of the privacy statement will be published on this page, with indication of the date of its last update.
- Legislative references and useful links
The processing of your personal data is carried out by SPM S.p.A. in full compliance with the regulations on the matter pursuant to the General Data Protection Regulation (EU) 2016/679, the rules on the processing of Italian personal data and the provisions of the Italian Data Protection Authority (http://www.garanteprivacy.it)