PRIVACY POLICY
INTRODUCTION.
This document is the privacy policy set forth under articles 13 and following of Regulation (EU) 2016/679 of April 27, 2016, that MAHR srls (Tax code no. 15693931006) with registered office in Rome, Via della Farnesina no. 236, provides to the users of its website www.mahrstore.com to ensure the best possible protection of their personal data.
This privacy policy contains all the information concerning the processing of the users’ personal data and the modalities to exercise the rights under Regulation (EU) 2016/679. It is downloadable by clicking on the link found at the end of the website page www.mahrstore.com.
A separate document downloadable by clicking on the link found at the end of the website page www.mahrstore.com describes the cookie policy adopted by MAHR srls. The purposes and types of cookies adopted are specified therein.
The processing of data carried out by MAHR srls, under article 5 of Regulation (EU) 2016/679, is based on the principles of lawfulness, fairness and transparency, compatibility of the processing with the purposes of the collection of the data, data minimization, accuracy and updating of the data, storage limitation, integrity and confidentiality of the data.
Data Controller.
The data controller of the data collected through the website www.mahrstore.com is the company Mahr s.r.l.s. VAT no. 15693931006 (hereinafter the “Data Controller” or the “Company“) with registered office in Rome, Via della Farnesina no. 236. The Company operates only in Italy and is subject to Italian law. The email address of the Company is info@mahrstore.com, the certified email (“PEC“) address of the Company is mahr@legalmail.it.
To guarantee the lawfulness of the processing, the Company has appointed a data processor that may be contacted at the following email address info@mahrstore.com.
Any data collected and stored by the Company is saved in servers located in the Republic of Italy.
Purposes and legal basis for the processing.
The Company collects data of the users of its website for the following purposes:
- Perform the sales contract concerning its products. For such purpose, it collects the following data: name, surname, email address, place of delivery, telephone number.
- Manage the payment of products through bank transfer. For such purpose, it collects the following data acquired from the bank statement: name, surname, Bank Identifier Code of the payer.
- Manage an informative service via email with the scope of updating the users who request to be updated on products and sales promotions run by the Company. For such purpose, the Company collects the following data: name, surname, email address, municipality of residence.
- Manage any complaints lodged by purchasers. For such purpose, it collects the following data: name, surname, email address, telephone number.
- Return or replace the products. For such purpose, it collects the following data: name, surname, email address, telephone number, and shipping address.
- Deliver pre-contractual services such as the reservation of unavailable products. For such purpose, it collects the following data: name, surname, email address.
The Company uses payment services offered by Paypal and Stripe to provide online payment services. The data relating to the payment methods used, such as credit cards or bank account, are directly acquired by the payment services providers and do not transit on the Company’s servers or are visible to the Company.
The legal basis for the processing carried out by the Company is the performance of a sales contract and the obligations related thereto and arising therefrom, as well as the provision of explicitly requested ancillary services to the sales contract, pursuant to article 6, letter B, of Regulation (EU) 2016/679.
With regard to the newsletter, the legal basis of this processing is the explicit consent given by the user under article 6, letter A of Regulation (EU) 2016/679.
The legal basis for the processing involved in the service for the reservation of unavailable products is the provision of pre-contractual services set forth under article 6, letter B of Regulation (EU) 2016/679.
DURATION OF THE PROCESSING.
The Company stores the data it collects for the time required for the purposes for which the personal data are collected. Specifically, as regards the performance of the sales contract and the subsequent obligations, the Company stores the data until the expiry of the manufacturer’s warranty set forth by the law.
As for the newsletter service, the Company stores the data until the subscribers express their intention to no longer benefit from the newsletter service.
RIGHTS OF THE DATA SUBJECT.
The data subjects to which the data processed by the Company under Regulation (EU) 2016/679 relate are entitled to exercise the following rights in relation to the processed data:
- Right of access to the data to view the data processed by the Company;
- Right to obtain rectification of the data processed by the Company;
- Right to obtain the erasure of the data processed by the Company;
- Right to obtain restriction of processing, i.e., the suspension and/or interruption of the processing of the data collected by the Company;
- Right to data portability in case the processing is based on the explicit consent of the data subject.
All of the abovementioned rights may be exercised at any time by sending a notice to the following email address: info@mahrstore.it and specifying the right that the user intends to exercise.
DISCLOSURE AND DISSEMINATION OF THE DATA.
The e-commerce platform used by the Company is provided by Aut O’Mattic A8C – Ireland Ltd.
Business Centre, No.1 Lower Mayor Street
International Financial Services Centre
Dublin 1, Ireland. The Company does not intentionally and directly send any of the data collected to Aut O’ Matic A8C – Ireland Ltd, which, however, could acquire, directly and automatically, some of the data due to the use of the platform provided by the latter. Please find the privacy policy of Aut O’Mattic A8C – Ireland Ltd at the following address https://automattic.com/privacy/.
In order to guarantee safe and swift payment methods, the Company uses the professional services rendered by third-party providers, and specifically, by Paypal Europe S.à.r.l. S.C.A., 22-24-Boulevard Royal L-2449, Luxemburg – Please find its privacy policy at the following address https://www.paypal.com/it/webapps/mpp/ua/privacy-full – and Stripe Payments Europe, Ltd – 1 Grand Canal Street Lower, Grand Canal Dock, Dublin – Please find its privacy policy at the following address https://stripe.com/it/privacy#benvenuti-su-stripe.
In order to provide shipping services, the Company uses the professional services offered by DHL International GMBH, to which – to enable the delivery of the products – it transfers the following data: name, surname, shipping address, and telephone number. Please find DHL International GMBH’s privacy policy at the following address: https://www.dhl.com/it-it/home/footer/local-privacy-notice.html
DHL International GMBH has its registered office in the European Union.
Klarna Privacy Policy
“In order to be able to offer you Klarna’s payment methods, we may pass your personal data to Klarna in the form of contact details and order details to Klarna at checkout so that Klarna can assess your suitability for its payment methods and customize those payment methods. The personal data of the user transferred are treated in line with Klarna’s privacy policy. “
CHANGES TO THE PRIVACY POLICY
The Data Controller reserves the right to amend this privacy policy at any time. The users will be notified of such changes on this webpage and, if possible, on Tannico. Also, where technically and legally feasible, the Company will inform the users of any changes by sending them a notification to one of the contact details in its possession. Therefore, please visit this page frequently and refer to the date it was last updated found below.
In case any changes should refer to processing based on consent, the Data Controller will collect the user’s consent again if required.
Rome, September 30, 2020