Privacy Policy
Information on the processing of personal data under EU Regulation 2016/679 (GDPR).
EU REGULATION 679/2016 ON THE PROCESSING OF PERSONAL DATA — ART. 13
AC Retail Advisory, with registered office in Via Donati, 9 – 21047 – Saronno (VA), Italy, VAT IT04021100120 (hereinafter, the "Controller"), as Data Controller, informs you pursuant to Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 (the "Privacy Code"), and Art. 13 of EU Regulation 2016/679 (the "GDPR") that your data will be processed in accordance with the principles of fairness, lawfulness and transparency, for the purposes and in the manner set out below, collecting them to the extent necessary and accurate for the processing.
1. Subject of the processing
This Privacy Policy concerns the management of the website https://www.acretailadvisory.it/ with reference to the processing of users' personal data. This Privacy Policy refers exclusively to this website (hereinafter, the "site") and does not cover other websites the user may access via links. Further information may be provided where necessary when a specific service is requested.
"Processing of personal data" means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
2. Categories of data collected
Pursuant to EU Regulation 679/2016, when you use our services you accept that our Company collects certain personal data. This notice explains which data we collect, why and how we use them.
We collect and process the following categories of personal data concerning you:
a) Data voluntarily provided by the user: through specific sections of the site (e.g. the "Contact" form) you may voluntarily provide personal data such as: identification data (e.g. first name, surname); contact information (e.g. email address, telephone number). This information may also be provided by sending emails to the addresses indicated on this site.
b) Browsing data: the IT systems and software procedures used to operate this website acquire, during their normal operation, certain identification data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category includes IP addresses or domain names of the computers used by users connecting to the site, URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server's response (success, error, etc.) and other parameters relating to the user's operating system and IT environment. Such data could be used to ascertain liability in the event of computer crimes against the site.
c) Data collected using cookies or similar technologies: for more information on the types of cookies used and how to disable them, please see the .
Please also note that a chat is available as a support tool for user enquiries. The information collected is necessary for the operation of the chat and to provide personalised assistance; the data processed are provided by the data subject when accessing the chat.
3. Purposes of processing and legal basis
Except for browsing data, which are necessary to operate IT and telematic protocols, we will process your personal data for:
3.1) Purposes connected with the provision of the services you request. By way of example: allowing the user to access the site https://www.acretailadvisory.it/; allowing the user to request information; providing assistance to our users; managing any dispute that may arise between us; performing the requested service.
The legal basis is the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).
3.2) In pursuit of our legitimate interest we may also: collect statistical information on the use of the site (most visited pages, number of visitors by time of day, geographical areas of origin, etc.) and improve its usability; defend a legal right of ours in court; carry out IT management, including infrastructure management and IT security.
The legal basis in these cases is the legitimate interest of the Data Controller (Art. 6(1)(f) GDPR).
3.3) To comply with legal obligations, regulations and orders of the Authorities, as well as tax and accounting obligations (e.g. requirements under national and EU legislation and provisions issued by Supervisory and Control Bodies, including in order to ascertain liability in the event of computer crimes against the site).
The legal basis is compliance with a legal obligation to which the Controller is subject (Art. 6(1)(c) GDPR).
4. Processing methods
Your personal data are processed by means of the operations indicated in Art. 4(2) GDPR, namely: collection, recording, organisation, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, erasure and destruction. Your personal data are processed both on paper and electronically and/or by automated means.
5. Access to data and disclosure
Your data may be made accessible, for the purposes referred to in point 3, to: employees and collaborators of the Controller in their capacity as authorised persons and/or internal data processors and/or system administrators; third-party companies or other parties (by way of example: ICT companies, website providers, consultants, professional firms, companies/individuals engaged by the Controller for data storage activities, etc.) performing outsourced activities on behalf of the Controller, in their capacity as external data processors.
The Controller may also disclose your data, for the purposes above, to: supervisory bodies, judicial authorities, police forces, public bodies and all parties to whom disclosure is required by law. Such parties will process the data as independent data controllers.
Your data will not be disseminated.
6. Retention period
Browsing data are kept for the time strictly necessary to carry out the activities described. Upon expiry, the data will be deleted or anonymised, unless further purposes for their retention exist, for example for security reasons where cases of abuse need to be clarified. In such cases, the Controller will retain the personal data acquired for the time necessary to comply with legal obligations and/or to assert or defend a right in the appropriate venues.
Data voluntarily provided by the user will be processed and retained for the period strictly necessary to pursue the purposes for which they were collected, after which they will be deleted or anonymised, unless further retention is necessary for defence purposes in legal proceedings.
7. Data transfer
Personal data are not transferred outside the European Union. However, should it become necessary, any transfer of personal data to non-EEA countries will take place in compliance with applicable law: where the European Commission has recognised that a non-EEA country provides an adequate level of data protection, your personal data may be transferred on that basis; for transfers to non-EEA countries whose level of protection has not been recognised as adequate by the European Commission, we may rely on a derogation applicable to the specific situation and/or adopt the standard contractual clauses approved by the European Commission for the transfer of personal data outside the EU.
8. Nature of data provision
The provision of data for the purposes referred to in point 3 is mandatory for everything required by legal and contractual obligations; any refusal to provide them in whole or in part may make it impossible for the Controller to provide its services.
With reference to the consequences of refusing and/or removing cookies, please see the .
9. Rights of the data subject and how to exercise them
At any time, where the conditions apply, you may exercise your rights under Art. 15 et seq. GDPR: obtain confirmation of whether or not personal data concerning you exist and receive a copy in intelligible form; obtain the updating, rectification or integration of your data; request the erasure of your data, within the limits permitted by law; object, in whole or in part, to the processing of personal data concerning you; restrict the processing in the event of a breach, a request for rectification or an objection; request the portability of electronically processed data provided on the basis of consent or contract; withdraw consent to the processing of your data, where applicable; in relation to fully automated profiling, obtain human intervention by the Controller in order to express your opinion and contest the decision.
Should you deem it appropriate, you may lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
To exercise your rights, you may contact the Data Controller at the following email address: ac@acretailadvisory.it.
Data Controller
AC Retail Advisory — Via Donati, 9, 21047 Saronno (VA), Italy — VAT IT04021100120 — ac@acretailadvisory.it
