The processing of data carried out by MAHR srls, under article 5 of Regulation (EU) 2016/679, is based on the principles of lawfulness, fairness and transparency, compatibility of the processing with the purposes of the collection of the data, data minimization, accuracy and updating of the data, storage limitation, integrity and confidentiality of the data.
The data controller of the data collected through the website www.mahrstore.com is the company Mahr s.r.l.s. VAT no. 15693931006 (hereinafter the “Data Controller” or the “Company“) with registered office in Rome, Via della Farnesina no. 236. The Company operates only in Italy and is subject to Italian law. The email address of the Company is email@example.com, the certified email (“PEC“) address of the Company is firstname.lastname@example.org.
To guarantee the lawfulness of the processing, the Company has appointed a data processor that may be contacted at the following email address email@example.com.
Any data collected and stored by the Company is saved in servers located in the Republic of Italy.
Purposes and legal basis for the processing.
The Company collects data of the users of its website for the following purposes:
- Perform the sales contract concerning its products. For such purpose, it collects the following data: name, surname, email address, place of delivery, telephone number.
- Manage the payment of products through bank transfer. For such purpose, it collects the following data acquired from the bank statement: name, surname, Bank Identifier Code of the payer.
- Manage an informative service via email with the scope of updating the users who request to be updated on products and sales promotions run by the Company. For such purpose, the Company collects the following data: name, surname, email address, municipality of residence.
- Manage any complaints lodged by purchasers. For such purpose, it collects the following data: name, surname, email address, telephone number.
- Return or replace the products. For such purpose, it collects the following data: name, surname, email address, telephone number, and shipping address.
- Deliver pre-contractual services such as the reservation of unavailable products. For such purpose, it collects the following data: name, surname, email address.
The Company uses payment services offered by Paypal and Stripe to provide online payment services. The data relating to the payment methods used, such as credit cards or bank account, are directly acquired by the payment services providers and do not transit on the Company’s servers or are visible to the Company.
The legal basis for the processing carried out by the Company is the performance of a sales contract and the obligations related thereto and arising therefrom, as well as the provision of explicitly requested ancillary services to the sales contract, pursuant to article 6, letter B, of Regulation (EU) 2016/679.
With regard to the newsletter, the legal basis of this processing is the explicit consent given by the user under article 6, letter A of Regulation (EU) 2016/679.
The legal basis for the processing involved in the service for the reservation of unavailable products is the provision of pre-contractual services set forth under article 6, letter B of Regulation (EU) 2016/679.
DURATION OF THE PROCESSING.
The Company stores the data it collects for the time required for the purposes for which the personal data are collected. Specifically, as regards the performance of the sales contract and the subsequent obligations, the Company stores the data until the expiry of the manufacturer’s warranty set forth by the law.
As for the newsletter service, the Company stores the data until the subscribers express their intention to no longer benefit from the newsletter service.
RIGHTS OF THE DATA SUBJECT.
The data subjects to which the data processed by the Company under Regulation (EU) 2016/679 relate are entitled to exercise the following rights in relation to the processed data:
- Right of access to the data to view the data processed by the Company;
- Right to obtain rectification of the data processed by the Company;
- Right to obtain the erasure of the data processed by the Company;
- Right to obtain restriction of processing, i.e., the suspension and/or interruption of the processing of the data collected by the Company;
- Right to data portability in case the processing is based on the explicit consent of the data subject.
All of the abovementioned rights may be exercised at any time by sending a notice to the following email address: firstname.lastname@example.org and specifying the right that the user intends to exercise.
DISCLOSURE AND DISSEMINATION OF THE DATA.
The e-commerce platform used by the Company is provided by Aut O’Mattic A8C – Ireland Ltd.
Business Centre, No.1 Lower Mayor Street
International Financial Services Centre
DHL International GMBH has its registered office in the European Union.
In case any changes should refer to processing based on consent, the Data Controller will collect the user’s consent again if required.
Rome, September 30, 2020