Privacy Policy

Gruppo valige ZoomBags

Indice dei contenuti

Last update 05/08/2021

Data Controller

  • Chiara Caramelli Design Lab
  • Via dell’Argomenna, 28 50065 Pontassieve (Firenze)
  • P.IVA 05550140486
  • C.F. CRMCHR67E57D612X
  • info@zoombags.it

Types of Data Collected

The Personal Data collected by this Website, either independently or through third parties, include: Usage Data, Cookie, name, email, various types of Data, last name, phone number, address, username, password, company name, province, zip code, city, billing address, shipping address and house number.

Comprehensive details on each type of Data collected are provided in the relevant sections of this privacy policy or through specific information texts displayed prior to the collection of such Data.

Personal Data may be freely provided by the User or, in the case of Usage Data, automatically collected during the use of this Web Site.

Unless otherwise specified, all Data requested by this Web Site is mandatory. If you refuse to provide it, it may be impossible for this Web Site to provide the Service. In cases where this Web Site indicates certain Data as optional, Users are free to refrain from providing such Data, without this having any effect on the availability of the Service or its operation.

Users are free to choose whether or not to provide such Data.

Users who are unsure about which Data is mandatory are encouraged to contact the Data Controller.

The possible use of Cookies – or of other tracking tools – by this Website or by the owners of third party services used by this Website, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Website and warrants that he or she has the right to communicate or disseminate it, releasing the Owner from any liability to third parties.

Manner and location of processing of collected Data

Manner of treatment

The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data.

The processing is carried out by means of computer and/or telematic tools, with organizational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other subjects involved in the organization of this Website (administrative, commercial, marketing, legal, system administrators) or external subjects (such as third party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller, may have access to the Data. An updated list of the Data Processors can always be requested from the Data Controller.

Legal basis of the treatment

The Data Controller processes Personal Data relating to the User if one of the following conditions exists:

The User has given consent for one or more specific purposes; Note: in some jurisdictions, the Data Controller may be authorized to process Personal Data without the User’s consent or another of the legal bases specified below, until the User objects (“opts out”) of such processing. This does not apply, however, where the processing of Personal Data is governed by European legislation on the protection of Personal Data.

    • the processing is necessary for the performance of a contract with the User and/or the execution of pre-contractual measures;
    • the processing is necessary for the performance of a legal obligation to which the Controller is subject;
    • the processing is necessary for the performance of a task of public interest or for the exercise of public authority vested in the Data Controller;
    • the processing is necessary for the pursuit of the legitimate interest of the Owner or of third parties.

It is however always possible to ask the Owner to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on the law, provided for by a contract or necessary to conclude a contract.

The processing is necessary for the pursuit of the legitimate interest of the Owner or of third parties.

Location

The Data is processed at the Controller’s operational headquarters and at any other location where the parties involved in the processing are located. For more information, please contact the Data Controller.

Your Personal Data may be transferred to a country other than the country in which you are located. For further information on the processing location, please refer to the section on Personal Data processing details.

You have the right to object to the processing of your Personal Data.

You have the right to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organization under public international law or consisting of two or more countries, such as the UN, as well as about the security measures taken by the Controller to protect the Data.

In the event that one of the transfers just described takes place, the User may refer to the respective sections of this document or request information from the Controller by contacting him at the contact details given at the beginning.

Storage Period

Data is processed and stored for the time required by the purposes for which it was collected.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Controller and the User will be retained until the performance of such contract is completed.
  • Personal Data collected for purposes attributable to the legitimate interest of the Controller will be retained until such interest is satisfied. You may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.

When processing is based on Your consent, the Controller may retain Personal Data for longer until such consent is revoked. In addition, the Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period the Personal Data will be deleted. Therefore, at the end of this period the right of access, cancellation, rectification and the right to Data portability can no longer be exercised.

Purposes of Data Processing

The User’s Data are collected to allow the Data Controller to provide its Services, as well as for the following purposes: Displaying content from external platforms, Statistics, SPAM protection, Contacting the User, Registration and authentication, Interaction with social networks and external platforms, Payment management, Contact management and message sending and Interaction with data collection platforms and other third parties.

To obtain further detailed information on the purposes of the processing and on the Personal Data concretely relevant for each purpose, the User may refer to the relevant sections of this document.

Personal Data Processing Details

Personal Data is collected for the following purposes and using the following services:

Contacting the User

Contact form (this Website)

The User, by filling out the contact form with his or her own Data, consents to their use in order to respond to requests for information, quotes, or any other nature indicated in the header of the form.

Personal Data collected: email, name and various types of Data.

Mailing list or newsletter (this Website)

By registering to the mailing list or newsletter, the User’s email address is automatically added to a list of contacts to whom email messages may be sent containing information, including commercial and promotional information, relating to this Web Site. The User’s email address may also be added to this list as a result of registering with this Web Site or making a purchase.

Personal Data Collected: email.

Contact by phone (this Web Site)

Users who have provided their phone number may be contacted for commercial or promotional purposes related to this Web Site, as well as to fulfill support requests.

Personal Data Collected: phone number.

Managing contacts and sending messages

This type of service allows the management of a database of email contacts, telephone contacts or contacts of any other type used to communicate with the User.

These services may also allow the collection of data relating to the date and time of viewing of messages by the User, as well as the User’s interaction with them, such as information on clicks on links included in messages.

SendInBlue (SendInBlue)

SendInBlue is a service for managing addresses and sending email messages.

Personal data collected: email.

Place of processing: United StatesPrivacy Policy.

Payment management

Payment processing services allow this Website to process payments by credit card, bank transfer or other means. The data used for payment is acquired directly from the operator of the payment service requested without being in any way processed by this Website.

Some of these services may also allow for the scheduled sending of messages to the User, such as emails containing invoices or notifications regarding payment.

PayPal (Paypal)

PayPal is a payment service provided by PayPal Inc., which allows the User to make online payments.

Personal Data collected: various types of Data as specified by the privacy policy of the service.

Place of treatment: See the privacy policy of PayPalPrivacy Policy.

Interaction with data collection platforms and other third parties

This type of service allows Users to interact with data collection platforms or other services directly from the pages of this Website in order to save and reuse data.

If one of these services is installed, it is possible that, even if Users do not use the service, it will collect Usage Data related to the pages where it is installed.

Interaction with social networks and external platforms

This type of service allows for interactions with social networks, or other external platforms, directly from the pages of this Website.

The interactions and information acquired by this Website are in any case subject to the privacy settings of the User relating to each social network.

If a service for interaction with social networks is installed, it is possible that, even if Users do not use the service, it collects traffic data related to the pages where it is installed.

PayPal button and widget (Paypal)

The PayPal button and widget are services for interaction with the PayPal platform, provided by PayPal Inc.
Personal Data Collected: Cookies and Usage Data.

Place of treatment: See the privacy policy of PaypalPrivacy Policy.

Facebook Like Button and Social Widgets (Facebook, Inc.)

The Facebook “Like” button and social widgets are Facebook social network interaction services, provided by Facebook, Inc.

Personal Data Collected: Cookies and Usage Data.

Place of processing: USAPrivacy Policy.

YouTube social button and widgets (Google Inc.)

The YouTube social button and widgets are services for interaction with the social network YouTube, provided by Google Inc.

Personal data collected: Usage data.

Place of processing: USAPrivacy Policy.

SPAM protection

This type of service analyzes the traffic of this Website, potentially containing Personal Data of the Users, in order to filter it from parts of traffic, messages and contents recognized as SPAM.

Google reCAPTCHA (Google Inc.)

Google reCAPTCHA is a SPAM protection service provided by Google Inc. Your use of reCAPTCHA is subject to Google’s privacy policy and terms of use.

Personal Data Collected: Cookies and Usage Data.

Place of processing: USAPrivacy Policy.

Advertisement

These types of services allow the use of User Data for commercial communication purposes in various forms of advertising, such as banners, also in relation to the User’s interests.

This does not mean that all Personal Data is used for this purpose. Data and conditions of use are indicated below.

Some of the services mentioned below may use cookies to identify the User or use the technique of behavioral retargeting, i.e. displaying advertisements tailored to the User’s interests and behavior, also detected outside this Website.

For further information on this subject, we suggest that you check the privacy policies of the respective services.

In addition to the opt-out opportunities offered by the services below, you may opt out of receiving cookies from a third party service by visiting the Network Advertising Initiative opt-out page.

Direct Email Marketing (DEM) (this Website)

This Web Site uses User Data to send marketing messages about services and products provided by third parties or unrelated to the product or service provided by this Web Site.

Personal Data Collected: email.

Registration and authentication

By registering or authenticating, the User allows the Application to identify him/her and give him/her access to dedicated services.

Depending on what is indicated below, the registration and authentication services may be provided with the help of third parties. If this happens, this Website may access some Data stored by the third party service used for registration or identification.

Direct Registration (This Website)

The User registers by filling out the registration form and providing his or her Personal Data directly to this Web Site.

Personal Data collected: zip code, city, last name, email, address, billing address, shipping address, name, street number, phone number, password, province, company name, username and various types of Data.

Google OAuth (Google Inc.)

Google OAuth is a registration and authentication service provided by Google Inc. and connected to the Google network.

Personal Data collected: various types of Data as specified in the privacy policy of the service.

Place of processing: USAPrivacy Policy.

Facebook Login (Facebook Inc.)

Facebook Login is a registration and authentication service provided by Facebook Inc. and connected to the Facebook network.

Personal Data collected: various types of Data as specified by the privacy policy of the service.

Place of processing: USAPrivacy Policy.

Remarketing

This type of service allows this Website and its partners to communicate, optimize and serve advertisements based on your past use of this Website.

This activity is carried out through the tracking of Usage Data and the use of Cookies, information that is transferred to the partners to which the remarketing and behavioral targeting activity is linked.

In addition to the opt-out possibilities offered by the services below, the User may opt out of receiving cookies related to a third-party service by visiting the Network Advertising Initiative opt-out page.

Facebook Remarketing / Facebook Pixel (Facebook, Inc.)

Facebook Remarketing is a remarketing service provided by Facebook, Inc. that links the activity of this Website with the Facebook advertising network.

Personal Data Collected: Cookies and Usage Data.

Place of processing: USAPrivacy Policy.

Facebook Custom Audience (Facebook, Inc.)

Facebook Custom Audience is a remarketing service provided by Facebook, Inc. that links the activity of this Website with the Facebook advertising network.

Personal Data Collected: Cookies and email.

Processing Location: USA – Privacy Policy.

AdWords Remarketing (Google Inc.)

AdWords Remarketing is a remarketing service provided by Google Inc. that links the activity of this Website with the Adwords advertising network.

Personal Data Collected: Cookies and Usage Data.

Place of processing: USAPrivacy Policy.

Remarketing with Google Analytics for display advertising (Google Inc.)

Google Analytics for display advertising is a remarketing service provided by Google Inc. that links the tracking activity performed by Google Analytics and its Cookies with the Adwords advertising network.

Personal Data Collected: Cookies and Usage Data.

Place of processing: USAPrivacy Policy.

Statistics

The services contained in this section allow the Data Controller to monitor and analyze traffic data and serve to track User behavior.

Google Analytics (Google Inc.)

Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google uses the Personal Data collected in order to track and examine the use of this Website, compile reports and share them with other services developed by Google.

Google may use Personal Information to contextualize and personalize ads in its ad network.

Personal Data Collected: Cookies and Usage Data.

Place of processing: USAPrivacy Policy.

Facebook Ads Conversion Tracking (Facebook, Inc.)

Facebook Ads Conversion Tracking is a statistical service provided by Facebook, Inc. that links data from the Facebook Ads network to actions taken within this Website.

Personal Data Collected: Cookies and Usage Data.

Place of processing: USAPrivacy Policy.

Google Analytics (Google Inc.)

Google Analytics is a web analytics service provided by Google Inc. (“Google”). Google uses the Personal Data collected in order to track and examine the use of this Website, compile reports and share them with other services developed by Google.

Google may use Personal Information to contextualize and personalize ads in its ad network.

Personal Data Collected: Cookies and Usage Data.

Place of processing: USAPrivacy Policy.

Google Tag Manager (Google Inc.)

Google Tag Manager is a statistics service provided by Google Inc.

Personal data collected: Cookie and Usage data.

Place of processing: USAPrivacy Policy.

Conversion tracking by Google AdWords (Google Inc.)

Google AdWords conversion tracking is a statistical service provided by Google Inc. that links data from the Google AdWords ad network with actions taken within this Website.

Personal Data Collected: Cookies and Usage Data.

Place of processing: USAPrivacy Policy.

Displaying content from external platforms

This type of service allows to display contents hosted on external platforms directly from the pages of this Website and to interact with them.

If a service of this type is installed, it is possible that, even if Users do not use the service, it will collect traffic data relating to the pages where it is installed.

Google Fonts (Google Inc.)

Google Fonts is a service for displaying font styles managed by Google Inc. which allows this Website to integrate such content into its pages.

Personal data collected: Usage data and various types of data as specified in the privacy policy of the service.

Place of processing: USAPrivacy Policy.

Widget Video YouTube (Google Inc.)

YouTube is a video content display service operated by Google Inc. which allows this Website to integrate such content into its pages.

Personal data collected: Cookie and Usage data.

Place of processing: USAPrivacy Policy.

Widget Google Maps (Google Inc.)

Google Maps is a map display service operated by Google Inc. that allows this Website to integrate such content into its pages.

Personal Data Collected: Cookies and Usage Data.

Place of processing: USAPrivacy Policy.

Google Translate (Google Inc.)

Google Translate is a machine translation service operated by Google Inc. that allows visitors to translate pages into their preferred language.

Personal Data Collected: Cookies and Usage Data.

Place of processing: USAPrivacy Policy.

More about Personal Data

Rights towards the data controller

At any time you may exercise your rights towards the data controller, pursuant to Article 7 of Legislative Decree 196/2003, which for your convenience we reproduce in full:

Legislative Decree n.196/2003: Art. 7 – Right of access to personal data and other rights

1. The interested party has the right to obtain confirmation of the existence or not of personal data concerning him, even if not yet recorded, and their communication in intelligible form.

2. The interested party has the right to obtain the indication:

  • (a) the origin of the personal data;
  • b) the purposes and methods of processing;
  • c) the logic applied in case of processing carried out with the aid of electronic instruments;
  • d) the identity of the owner, manager and the representative appointed under article 5, paragraph 2;
  • e) the entities or categories of entity to whom or which the personal data may be communicated and who or which may get to know said data in their capacity as designated representative(s) in the State’s territory, data processor(s) or person(s) in charge of the processing.

3. The interested party has the right to obtain:

  • a) the updating, rectification or, when interested, integration of data;
  • b) the cancellation, transformation into anonymous form or blocking of data processed unlawfully, including data whose retention is unnecessary for the purposes for which the data were collected or subsequently processed;
  • c) certification to the effect that the operations as per letters a) and b) have been notified, as also related to their contents, to the entities to whom or which the data were communicated or disseminated, unless this requirement proves impossible or involves a manifestly disproportionate effort compared with the right that is to be protected.

4. The data subject has the right to object, in whole or in part:

  • a) for legitimate reasons to the processing of personal data concerning him, even if pertinent to the purpose of collection;
  • b) to the processing of personal data concerning him/her, where it is carried out for the purpose of sending advertising materials or direct selling or else for the performance of market or commercial communication surveys.

Sale of goods and services online

The Personal Data collected is used to provide services to the User or to sell products, including payment and delivery.

The Personal Data collected to finalize the payment may be that of the credit card, bank account used for the transfer or other payment instruments provided. The Payment Data collected by this Website depends on the payment system used.

User Rights

Users may exercise certain rights with reference to the Data processed by the Data Controller.

In particular, the User has the right to:

  • revoke consent at any time. The User may revoke the consent to the processing of their Personal Data previously expressed.
  • oppose the processing of their Data. The User may object to the processing of their Data when it is done on a legal basis other than consent. Further details on the right to object are set out in the section below.
  • access to their Data. The User has the right to obtain information about the Data processed by the Data Controller, certain aspects of the processing and to receive a copy of the Data processed.
  • verify and request rectification. The User may verify the correctness of its own Data and request its update or correction.
  • obtain the limitation of the treatment. When certain conditions are met, the User may request the limitation of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its preservation.
  • obtain the cancellation or removal of their Personal Data. When certain conditions are met, the User may request the deletion of their Data by the Data Controller.
  • receive their Data or have it transferred to another owner. The User has the right to receive his or her Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another owner. This provision is applicable when the Data is processed by automated means and the processing is based on the User’s consent, a contract to which the User is a party or contractual measures related thereto.
  • propose complaint. The User may propose a complaint to the competent data protection supervisory authority or take legal action.

Details of the right to object

When Personal Data are processed in the public interest, in the exercise of public powers vested in the Data Controller or to pursue a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.

Users should note that if their Data were processed for direct marketing purposes, they may object to the processing without providing any reasons. To find out whether the Data Controller processes data for direct marketing purposes, Users may refer to the respective sections of this document.

How to exercise your rights

In order to exercise the User’s rights, Users may address a request to the contact details of the Controller indicated in this document. Requests are filed free of charge and processed by the Controller as soon as possible, in any case within one month.

Cookie Policy

This Website makes use of Cookies. To learn more and to view the detailed information, the User can consult this page dedicated to the Cookie Policy.

More information about the treatment

Shipping service

Sharing data with COURIERS for the purpose of completing the shipment.

Data shared: Full Address, First Name, Last Name, Email, Phone Number.

Shared data with SUPPLIERS for the purpose of completing the shipment.

Shared data: Full Address, First Name, Last Name, Email, Phone Number.

Defense in court

The User’s Personal Data may be used by the Data Controller in legal proceedings or in the preparatory phases of such proceedings in order to defend against abuses in the use of this Website or of the related Services by the User.

The User declares to be aware that the Data Controller may be obliged to disclose the Data by order of public authorities.

Specific disclosures

Upon the User’s request, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

System logs and maintenance

For operational and maintenance purposes, this Website and any third party services used by it may collect system logs, i.e. files that record interactions and may also contain Personal Data, such as the User’s IP address.

Information not contained in this policy

Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

Response to “Do Not Track” requests

This Website does not support “Do Not Track” requests.

To find out whether any third party services used support them, the User is invited to consult their respective privacy policies.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by informing Users on this page and, if possible, on this Website as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details held by the Data Controller. Therefore, please consult this page regularly, referring to the date of last modification indicated at the bottom.

If the changes affect processing whose legal basis is consent, the Data Controller will collect the User’s consent again, if necessary.

Definitions and legal references

Personal Data (or Data)

Personal data is any information that, directly or indirectly, even in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.

Usage Data

This is information collected automatically through this Website (including by third party applications integrated into this Website), including: IP addresses or domain names of computers used by the User who connects with this Website, URI (Uniform Resource Identifier) addresses, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.). ) the country of origin, the characteristics of the browser and the operating system used by the visitor, the various temporal connotations of the visit (e.g. the time spent on each page) and the details of the itinerary followed within the website, with particular reference to the sequence of pages consulted, the parameters relating to the operating system and the User’s IT environment.

User

The individual using this Website who, unless otherwise specified, is the Data Subject.

Interested

The individual to whom the Personal Data relates.

Data Processor (or Manager)

The natural person, legal entity, public administration and any other entity that processes personal data on behalf of the Data Controller, as set forth in this privacy policy.

Data Controller (or Holder)

The natural or legal person, public authority, service or other body which, individually or jointly with others, determines the purposes and means of the processing of personal data and the instruments adopted, including the security measures relating to the operation and use of this Web Site. The Data Controller, unless otherwise specified, is the owner of this Web Site.

This Website (or this Website)

The hardware or software tool by which Users’ Personal Data are collected and processed.

Service

The Service provided by this Website as defined in the relevant terms (if any) on this site/application.

European Union (or EU)

Unless otherwise specified, any reference in this document to the European Union shall be deemed to extend to all current member states of the European Union and the European Economic Area.

Cookie

Small portion of data stored within the User’s device.

Legal references

This Privacy Policy is prepared based on multiple pieces of legislation, including Articles 13 and 14 of Regulation (EU) 2016/679.

Unless otherwise specified, this privacy policy covers this Website only.