Skip to content

Cart

Your cart is empty

PRIVACY POLICY RELATING TO THE ACTIVITIES

PRIVACY POLICY RELATING TO SITE MANAGEMENT AND MARKETING ACTIVITIES

Balma srl  he takes care  of its customers' personal data and therefore intends to inform and provide them with the maximum possible control over the management of personal information collected through this website (the "Site").

1) Ownership of the data collected and processed on the Site and Data Protection Officer

The Data Controller of the data collected on the Site is:

- Balm  Srl with registered office in viale Amatore Sciesa 2/A, 20135  Milan  (MI) – Milan Company Register, REA 2685106, - VAT number 12804700966, PEC balmasrl@diellepec.it 

2) Category of data processed and purpose of the processing carried out on the Site

Different types of personal data are collected and processed through the Site, for different purposes and in different ways. More precisely:

(a) Cookies : personal data relating to navigation, processed both to allow the correct functioning of the Site and for marketing purposes. In this regard, we invite you to read the specific Cookie Policy [link];

(b) Registration and Services: personal data provided voluntarily by the user (such as, for example, the email address, personal data, password provided by filling in the registration form for the Balma personal account), or otherwise lawfully acquired, to respond to the requests of the latter and offer the services, assistance and information requested about the products.

(c) Social Login : Please note that registration and access via a social profile involve the communication of certain data (including name, surname, email and any other data relating to the user and present on the social network itself) by the chosen social network and require specific authorization to proceed before logging in. In some cases, social networks require obtaining some feedback and information about the use of the log-in. For further information, please refer to the relevant privacy documentation on the social network

Facebook (https://www.facebook.com/about/privacy/update?ref=old_policy)
Google + (https://policies.google.com/privacy)

(d) Marketing : with the express consent of the user, Balma may process the user's personal data for marketing purposes, i.e. to send the user, also via newsletter, email, sms and mms, information and updates on products, sales, promotional campaigns, events and other initiatives promoted by Balma, also in collaboration with its commercial partners, as well as to carry out specific market research.

(e) Study of preferences : with the express consent of the user, Bama may also process the latter's personal data for the purposes of studying consumer habits and choices, to make its products and initiatives more responsive to the tastes and needs of its customers.

(f) Communication to third parties : With the express consent of the user, Balma may transfer the user's personal data to its commercial partners operating in the luxury sector, so that they can process such data for their own commercial and marketing purposes, in order to send the user, both via technological tools, such as newsletters, emails, sms, mms, and traditional tools such as post and telephone, information and updates relating to products, discounts, promotional campaigns, events and other initiatives.

3) Source of personal data and legal basis of processing

Personal data collected and processed by Balma  are provided directly by the user, with the exception of the navigation data referred to in the previous point 2(a) and the data collected in the event of registration and access via social profile, as specified in the previous point 2 (c).

Except for navigation data, regulated by the Cookie Policy, the processing of personal data is based:

-for the purposes of Registration and Services (point 2 b), in the legitimate interest of Balma  to provide information, services and respond to user requests.

- for the purposes of Social log-in (point 2 c), Marketing (point 2 d), Study of preferences (point 2 e) and for the purposes of Communication to third parties (point 2 f), on the specific consent provided by the user.

4) Study of consumer habits and choices

As indicated in the previous point 2 (d) and with the express consent of the user, Balma may process the personal data of the user for the purposes of studying the habits and consumption choices of users to make its products and initiatives more responsive to the tastes and needs of its customers.

The data will be processed with the help of automated tools, through which Balma will process data relating to the value and frequency of purchases (even if these were made during the sales period) as well as the type of products purchased (such as accessories, clothes, etc.) over a specific period of time. The sole objective of this study is to offer customers and users products, services and initiatives that best meet their tastes and needs, and will be done in a non-invasive manner.

As indicated in the previous point 2 (a), with the express consent of the user, Balma may also process the personal data of the user, using automated tools to study cookies in order to verify navigation on the Site and propose services in line with the latter.

5) Methods of processing personal data and retention period

The personal data collected through the Site are processed using mainly computer and telematic methods and tools, adopting security measures in order to reduce to a minimum the risks of destruction or loss, even accidental, of the data themselves, of unauthorized access or of processing not permitted or not compliant with the collection purposes indicated in this Privacy Policy.

However, due to the nature of the online transmission medium, such measures cannot limit or exclude absolutely any risk of unauthorized access or data dispersion. To this end, it is advisable to periodically check that the computer is equipped with adequate software devices for the protection of data transmission on the network, both incoming and outgoing (such as updated antivirus systems) and that the Internet service provider has adopted suitable measures for the security of data transmission on the network (such as firewalls and anti-spam filters).

The personal data provided by the user during navigation and related to navigation itself, will be stored for a period not exceeding 1 (one) year. The data processed to provide feedback to the interested party or to provide a service will be stored for the time necessary to provide the user with the feedback or the requested service and for any additional time necessary to satisfy the need or request received. The data collected for profiling and marketing purposes will be stored within the term of 5 years from the granting of the relevant consent, in line with the reference sector and in consideration of the interest shown by the customer in receiving updates on products and events organized by Balma.

6) Mandatory or optional nature of providing data

Except for navigation data, the provision and collection of which are regulated by the Cookie Policy, the provision of personal data collected through the Site, both to respond to user requests and questions, and for marketing purposes and to study consumer habits and preferences, is free, optional and facultative. Failure to provide such data does not limit the use of the Site, but may make it impossible for Balma to respond to requests for information and questions, or to send information material, updates, newsletters and invitations to events.

7) Scope of communication of personal data

Balm  communicates the personal data of the users of the Site only within the limits permitted by law and in accordance with what is communicated below.

In addition to what is indicated in the previous point 2 (f). (i.e. the communication of personal data to third parties belonging to Balma srl  or to commercial partners with express consent) and to the previous point 2 (c). (i.e. the use of the Social log-in), the personal data will be processed and known not only by (i) employees and consultants of Balma, as persons authorised to process the data and instructed in this sense by the Data Controller, (ii) by companies of the same Group, as data controllers, as well as (iii) by companies that carry out  specific technical and organizational services connected to the Site and to the management of marketing and communication activities, as data controllers.

Furthermore, the data may be communicated to the police or judicial authorities, in accordance with the law and upon formal request by such entities, or in the event that there are well-founded reasons to believe that the communication of such data is reasonably necessary to (1) investigate, prevent or take initiatives relating to suspected illegal activities or assist state control and supervisory authorities; (2) defend itself against any claim or accusation by third parties, or protect the security of its website and company; or (3) exercise or protect the rights, property or safety of the companies of the same group, its affiliates, its customers, its employees or any other subject.

Personal data will not be disclosed and will be transferred abroad, including to non-EU countries, only by ensuring adequate levels of protection and safeguarding in accordance with the law, such as the Standard Contractual Clauses approved by the European Commission.

8) Rights recognized by the privacy law to the user

The user always has the right to obtain  access to personal data concerning him/her, confirmation of the existence or otherwise of such data, even if not yet recorded, and their communication in an intelligible form. He/she also has the right to obtain information about the origin of the personal data; the purpose and method of processing; the logic applied in the event of processing carried out with the aid of electronic instruments; the identification details of the owner and those responsible for processing; the indication of the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of them in their capacity, for example, as managers or persons in charge of processing.

The user also has the right to request the updating, rectification or, when interested, the integration of personal data, the limitation of processing concerning him/her, the cancellation, transformation into anonymous form or blocking of personal data, processed in violation of the law, including those whose retention is not necessary in relation to the purposes for which the data were collected or subsequently processed; certification that the above operations have been brought to the attention, also with regard to their content, of those to whom the data were communicated, except in the case in which such fulfillment proves impossible or involves the use of means manifestly disproportionate to the right protected. The user also has the right to data portability as well as to revoke the consent previously given.

The user has, however, the right to object in whole or in part, for legitimate reasons, to the processing of personal data concerning him/her, even if pertinent to the purpose of the collection, to the processing of personal data concerning him/her for the purpose of sending advertising or direct marketing material or for carrying out market research or commercial communication. The right to object may also be exercised specifically with regard to one or more methods of sending marketing communications.

_____________________________________________________________

PRIVACY POLICY RELATING TO SALES ACTIVITIES ON THE SITE

Balma srl  he takes care  of its customers' personal data and therefore intends to inform and provide them with the maximum possible control over the management of personal information collected through this website (the "Site").

1) Ownership of the data collected and processed on the Site and Data Protection Officer

The Data Controller of the data collected on the Site is:

- Balm  Srl with registered office in viale Amatore Sciesa 2/A, 20135  Milan  (MI) – Milan Company Register, REA 2685106, - VAT number 12804700966, PEC balmasrl@diellepec.it 



2) Type of data collected and purpose of the processing carried out by the Joint Controllers

The Joint Controllers collect personal data directly from users as part of the registration process, sending order forms for purchasing products, concluding e-commerce transactions and interacting with users for activities that are functional and instrumental to sales, as well as for any necessary pre- and post-sales assistance. Further specific purposes may be better illustrated through specific information present from time to time on the Site.

3) Source of personal data and legal basis of processing

The personal data collected and processed by the Joint Controllers are provided directly by the user (through registration on the Site or as part of the sales process). The legal basis for processing for the purpose referred to in the previous point (2) lies in the fulfillment of the contract and the obligation to fulfill pre- and post-contractual obligations.

4) Methods of processing personal data and data retention period

The personal data collected through the Site during activities inherent and instrumental to the sale of products and everything related to it, are processed using mainly computer and telematic methods and tools, adopting security measures in order to reduce to a minimum the risks of destruction or loss, even accidental, of the data themselves, of unauthorized access or of processing not permitted or not compliant with the collection purposes indicated in this Privacy Policy.

However, due to the nature of the online transmission medium, such measures cannot limit or exclude absolutely any risk of unauthorized access or data dispersion. To this end, it is advisable to periodically check that the computer is equipped with adequate software devices for the protection of data transmission on the network, both incoming and outgoing (such as updated antivirus systems) and that the Internet service provider has adopted suitable measures for the security of data transmission on the network (such as firewalls and anti-spam filters).

The personal data provided for sales purposes and any related services are stored for a period not exceeding 10 years, in compliance with tax and civil legislation.

5) Mandatory or optional nature of providing data

The provision of personal data, in particular personal details, email address, postal address and telephone number, as well as bank details in the case of payment by credit card, is necessary with regard to the conclusion of the contract for the purchase of products through the Site.

Some of the aforementioned data may, conversely, be indispensable for the provision of other services provided on the Site and related to sales or to fulfill obligations arising from laws or regulations.

Any refusal to indicate certain data necessary for these purposes could make it impossible to execute the contract for the purchase of products on the Site or to provide other services connected to it - such as assistance services (Customer Service), use of the Wish List - or, again, to correctly fulfill legal and regulatory obligations. Failure to indicate the data may therefore constitute, depending on the case, a legitimate and justified reason for not executing the contract for the purchase of products on the Site or the provision of services connected to it.

The communication of further data, other than those of mandatory provision, for the purposes of fulfilling one's legal or contractual obligations or for the provision of certain services upon request is, however, optional and does not entail any consequences for the purchase of products or for services strictly connected and correlated thereto.

Depending on the case and, if necessary, the mandatory or optional nature of the communication of data will be indicated from time to time, by placing a special character (*) next to the mandatory information or only the data necessary for the provision of services and for the purchase of products on the Site. Failure to indicate optional personal data will not entail any obligation or any disadvantage.

6) Scope of communication of personal data

Personal data may be made available to third-party companies that perform, on behalf of the Joint Controllers, specific services, as Data Processors (such as, for example, logistics services, anti-fraud services and IT services), to companies of the same group and communicated to other recipients of the data collected by the Joint Controllers - whose names will be specified from time to time -, who process the data independently only to execute the contract for the purchase of products on the Site (such as, for example, the credit institution, for the execution of remote electronic payment services, by credit/debit card) and only when such purpose is not incompatible with the purposes for which the data were collected and subsequently processed and, in any case, in a manner compliant with the law.

The data will not be communicated, sold or, in any other way, transferred to other third parties, without the users being previously informed and, with their consent, when this is required by law. The data will not be disseminated in any way and will be transferred abroad, even to non-EU countries (including countries such as Israel, the United States and Nepal for the execution of specific anti-fraud activities) only guaranteeing adequate levels of protection and safeguarding according to the law.

7) Rights recognized by privacy law to the user.

The user always has the right to obtain from the Joint Controllers access to personal data concerning him/her, confirmation of the existence or otherwise of such data, even if not yet registered, and their communication in an intelligible form. He/she also has the right to obtain from the Joint Controllers information about the origin of his/her personal data; the purpose and method of processing of the same; the logic applied in the case of processing carried out with the aid of electronic instruments; the identification details of the Joint Controllers and the data controllers; the indication of the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of them in their capacity, for example, as data controllers or persons in charge of processing.

The user also has the right to request the updating, rectification or, when interested, the integration of his/her personal data, the limitation of the processing of personal data concerning him/her, the cancellation, transformation into anonymous form or blocking of personal data, processed in violation of the law, including those for which conservation is not necessary in relation to the purposes for which the data were collected or subsequently processed; certification that the operations referred to in letters a) and b) have been brought to the attention, also with regard to their content, of those to whom the data were communicated or disseminated, except in the case in which such fulfillment proves impossible or involves the use of means manifestly disproportionate to the right protected. The user also has the right to data portability, to lodge a complaint with the supervisory authority, as well as to revoke the consent previously given.

The user has, however, the right to object in whole or in part, for legitimate reasons, to the processing of personal data concerning him/her, even if pertinent to the purpose of collection, for the purpose of sending advertising or direct marketing material or for carrying out market or commercial research. The right to object may also be exercised specifically with regard to one or more methods of sending marketing communications.