The company YOOX NET-A-PORTER GROUP S.p.A., with registered offices at via Morimondo, 17 – Milano 20143, business register number, tax code and VAT number 02050461207, fully paid share capital of EUR 1,338,942.89, only manages the sale of the products and the transactions performed within GAOS, for example management of orders, sales, and delivery of products, management of returned products, guarantees and other activities necessary to the sale of products through GAOS. For performance of activities functional to the sale of products through GAOS, YOOX NET-A-PORTER GROUP S.p.A. processes as data Controller and according to applicable privacy law the users' data such as name and surname, residence, and information on credit card used by users (for example name and surname of cardholder, card number, expiry date, security code).
Data collected and processed by YOOX NET-A-PORTER GROUP S.p.A. for the managing of the sales through GAOS may be communicated to Giorgio Armani. Possible users' data collected by Giorgio Armani are these voluntarily provided by user or lawfully gathered by Giorgio Armani as hereinafter specified.
For further information on the processing of personal data of users who make purchases on GAOS performed by YOOX NET-A-PORTER GROUP S.p.A. please read below.
The data Controller
The Controller of the personal data processing is Giorgio Armani S.p.A., with registered offices at via 450 W. 15th St 3rd Floor New York, NY 10011 New York, Tel: +30.02.72.31.81; email: email@example.com. The data Processor for enforcement of the privacy rights under art. 7 of the Privacy Code currently is the Facility Management Director at Giorgio Armani S.p.A., domiciled for this duty at the data Controller's offices as above specified.
The nature and kind of data processed. The purposes of the data processing
In general, the visit and consultation of the Site does not imply collection and processing of personal data of the user.
The processing of personal data of users that visit and consult the Site is limited to the so named surfing data, namely the data whose transmission to the Site is implicit in the functioning of the information systems in charge of the managing of the Site and in the use of communications protocols proper of the Internet. Surfing data are, for example, the IP addresses or the domain names of the computers employed by the users who connect to the Site and other parameters relating to the type and the information operating system employed by the user. Surfing data are not collected by Giorgio Armani in order to be associated with to users or identified persons, however surfing data for their own nature may allow the identification of the user if they are processed and associated with other data owned by third parties. Surfing data are collected and processed by Giorgio Armani exclusively for statistical purposes and in anonymous form in relation to the access and use of the Site and for purposes of monitoring the correct functioning of the Site and of enhancing the Site functioning and content. Surfing data are deleted immediately after the processing in anonymous form; said data may be used for purposes of assessing possible responsibilities in case of information crimes realized against the Site or through the Site. With the exception of the aforementioned circumstance, Giorgio Armani keeps the users' surfing data only temporarily for a maximum period of seven days or otherwise required under applicable law.
Furthermore, Giorgio Armani collects and processes personal data voluntarily provided by user or collected, also from third parties, in the course of its activity. Personal data may be voluntarily provided by user for example upon interaction of the user with the Site functionalities and request of the services offered by the Site, for example upon user subscription to the Site, to the Armani Club program or to other initiatives offered through the Site, upon user request of information or informative material to Giorgio Armani or user sending to Giorgio Armani of a communication through traditional mail or through the Site. Giorgio Armani will also process user's personal data to assess or defend a legal claim and to comply with laws, regulations and Community legislation.
With the user's consent, that is free and optional, Giorgio Armani may also process user's personal data for purposes of defining of individual and group profiles (profiling), and for marketing purposes, notably to send to user, also through newsletter, emails, sms and mms, information and updates on our products, offers, exclusive sales, promotional campaigns and on events and similar initiatives organized by Giorgio Armani or to which Giorgio Armani takes part to, including possible invitations to said events. User will always have the opportunity to object the processing of his/her personal data for the sending of promotional information through email; in each communication there will be a specific section in which are specified the conditions for revoking the consent and not receiving anymore promotional material and information. It is understood that the profiling activities will in no case be performed with information relating to user's purchase of products of Giorgio Armani through GAOS.
In the relevant sections of the Site where data are collected it is published a specific information statement drafted according to Section 13 of the Privacy Code. When requested under the Privacy Code, Giorgio Armani requires the user's consent before proceeding to the personal data processing.
Place where the data collected are stored
Features and conditions of the personal data processing
Personal data collected by Giorgio Armani are processed mainly with electronic, information and telematic means, according to logics and procedures strictly related to the purpose of processing above reported. Data may also be processed without electronic means through manual means; in any case data are kept only for the time necessary to achieve the specific processing purpose from time to time sought and according to applicable legislation on data protection, including security and confidentiality principles that inspire our activity. We will process data according to applicable security requirements to minimize the risks of data destruction and loss, even accidental, of unauthorized access, unlawful processing or processing that does not comply with the purposes of data collection and of illicit or not correct use of data, with specific but not limited reference to Annex B to the Privacy Code (Technical Specifications on Minimum Data Security Measures). Moreover, information system and programs are configured so as to minimize the use of personal and identification data so that said data are used only when necessary to the specific processing purpose from time to time sought.
Extent of personal data communication
User personal data will be accessible within Giorgio Armani organization by the internal and external personnel that need to access them because of their duties in relation to the processing purposes pursued as persons charged with data processing operations, and by the Processor above specified. The complete and updated list of Processors and of the subjects to which data may be communicated will remain at user disposal upon request at Giorgio Armani or at the Processor.
User personal data may be communicated to professionals, independent consultants, also in associate form, third parties to which Giorgio Armani may revert to in relation to performance of technical and organizational services for the purposes above reported, third parties in case of mergers, acquisitions, sale of business or part of business and other extraordinary operations, and to the legitimate addresses of communications under laws or regulations. For pursuing of the processing purposes above specified user's personal data may be communicated to other companies of the Giorgio Armani group, that will process data under applicable privacy law and that are established within the European Union. For the same purposes user's personal data may also be communicated to the company Giorgio Armani Corporation, with registered offices at New York, 114 5th Ave Fl 17; NY, 10011-5604 ; Tel.: 001.212.366.9720, United States. United States are a third country out of the European Union that does not guarantee an adequate level of data protection according to the standards of the Privacy Code. Data will be transferred to the company Giorgio Armani Corporation with the user's consent, which is free and optional.
The aforementioned subjects that receive user's personal data will process them as Controllers, Processors or persons in charge of processing, as the case may be, for the same purposes above specified and according to applicable data protection law; they are provided only with the information necessary to the relevant functions. It is understood that user's personal data will not be communicated to third parties for their own marketing purposes and will not be spread.
Providing of personal Data
Except for the foregoing description in relation to the surfing data, providing of personal data by user is necessary for performance of the services and functionalities offered by the Site and required by user, such as for example user subscription to the Site, the Armani Club program or other initiatives offered through the Site and relevant management, replying to user's questions, and sending of information and informative material requested by user. Providing of personal data by user is mandatory to assess and defend legal claims and to comply with applicable legislation; denial of providing personal data by user in the above reported circumstances would make it impossible for user to subscribe to the Site, the Armani Club program or other initiatives offered through the Site, to receive the services, functionalities, replies, information and informative material requested to Giorgio Armani.
Providing of personal data by user for profiling and marketing purposes as above specified is free and optional; denial of providing personal data by user for profiling and marketing purposes will have no consequence, for example said denial will have no consequence on the possibility for user to subscribe to the Site, the Armani Club program or other initiatives offered through the Site, to receive the services, functionalities, replies, information and informative material requested to Giorgio Armani.
User is entitled at any moment to enforce his/her rights as provided under Section 7 of the Privacy Code, for example the right to obtain confirmation that user's personal data exist or do not exist, verify their content, origin and accuracy, ask for their integration, updating, amendment, deletion, transformation in anonymous form, block for breach of laws and regulations, and user may oppose for legitimate reason the data processing.
To enforce user's rights and for any query or request relating to the personal data processing by Giorgio Armani, user may contact the data Processor, currently the Information Systems Manager at Giorgio Armani S.p.A., who is odmicilied for this duty at the offices of Giorgio Armani as follows: Giorgio Armani S.p.A., 450 W. 15th St 3rd Floor New York, NY 10011 New York, Tel: +30.02.72.31.81; email: firstname.lastname@example.org.
Since personal data of users and customers of this Site (collectively "Users") may be processed in Italy, any such processing of personal data will be conducted in compliance with applicable European laws as well as the Italian Data Protection Code (Legislative Decree no. 196 dated June 30, 2003). Pursuant to the Italian Data Protection Code, YOOX NET-A-PORTER GROUP S.p.A - an Italian corporation having its registered offices at in via Morimondo, 17 – Milano 20143, Italy, business register number, tax code and VAT number 02050461207, fully paid share capital of EUR 529.825,40 ("YOOX NET-A-PORTER GROUP") - is the data controller of personal data processing regarding services for e-commerce and purchase of products. As used herein, the words "we", "us" or "our" refer solely to YOOX NET-A-PORTER GROUP.
1. Our Policy
2. Who Processes Your Personal Data
YOOX NET-A-PORTER GROUP – pursuant to Italian legislative decree 196/ 2003 (Privacy Code) – is the data controller of www.armaniexchange.com users' personal data, which is collected for conducting, concluding and performing transactions for purchasing products on the aforementioned site ("Commercial Purposes"); YOOX NET-A-PORTER GROUP autonomously determines the purposes and means of processing personal data and the instruments used, including those for security measures. Due to organisational and operational purposes only, we have appointed certain entities that will also process personal data belonging to www.armaniexchange.com's users for purposes strictly connected to the performance of services on www.armaniexchange.com, including the sale of products. The above mentioned processors have been chosen by YOOX NET-A-PORTER GROUP because of their experience in processing personal data and they provide sufficient guarantees regarding compliance with data processing laws (including the technical security measures governing the processing to be carried out). In processing the personal data of www.armaniexchange.com's users, the processors shall act only on instructions from YOOX NET-A-PORTER GROUP. We regularly check that our processors comply with our instructions and that they continue to provide sufficient guarantees regarding their full compliance with the provisions on personal data processing.
Some of the processors of your personal data are:
- United Parcel Service, for purposes related to shipping, delivering and returning products purchased on www.armaniexchange.com;
- BT Italia S.p.A. for purposes related to the maintenance of YOOX NET-A-PORTER GROUP servers;
- Prestige International UK ltd, for purposes connected to providing call centre and Customer Care services to www.armaniexchange.com's users.
When you execute purchasing procedures for products sold on www.armaniexchange.com, we collect your personal data (such as personal details, email address, address, Credit Card numbers, bank code, tax code and telephone number) on your order form only for the purpose of selling the products ordered by you.
Your personal data is mostly processed by electronic means and in some circumstances by paper-based means, such as when the processing of your personal data is required for preventing fraud on www.armaniexchange.com. Your personal data shall be stored in a way which allows YOOX NET-A-PORTER GROUP to identify you for the period necessary for the purposes which the data was collected for and subsequently processed and, in any case, in accordance with applicable law. Please report any modification of your personal data to email@example.com in order to ensure that your personal information is always accurate and up-to-date, relevant and complete. Your personal data shall not be disclosed to third parties for purposes which are not permitted by law or without your explicit consent.
Aside from the companies appointed for personal data processing, your information will be made available also to third parties, autonomous controllers, for purposes related to supplying services requested by user (for example, for purchase transactions). For more information on the matter, see section 5 (To Whom Your Personal Data Will Be Disclosed).
Please contact our Customer Care or send us an email at firstname.lastname@example.org if you would like to receive a full list of our data processors.
Your personal data may only be disclosed to third parties when it is necessary for processing an order. For example, your personal data is disclosed to Banca Sella S.p.A. for the performance of electronic distance payment services using Credit/Debit Card when you purchase a product on www.armaniexchange.com. Moreover, your data may be disclosed to the police or to judicial authorities, according to law and upon a formal request by such entities, for example in the event YOOX NET-A-PORTER GROUP needs to prevent fraud on www.armaniexchange.com (anti-fraud services). Data processors will also have access to your personal data as stated in section 2 for the specific purposes stated therein. In all the above circumstances, your consent for data processing is not required. Your personal data will not be transferred abroad to non-EU countries that do not ensure an adequate level of protection of individuals. Should this be necessary in order to supply services or to execute a contract for the purchase of products, your personal data shall be transferred to such non-EU countries only after the execution of specific contracts between YOOX NET-A-PORTER GROUP and such entities in accordance with applicable law and regulations.
In any event, YOOX NET-A-PORTER GROUP shall fulfil any obligation to inform third parties required by law and, when necessary, shall request their express consent upon registering in its archives the personal information of the user indicated.
3. What Happens if You Do Not Disclose Your Personal Data to YOOX NET-A-PORTER GROUP
Granting your personal data to YOOX NET-A-PORTER GROUP (in particular, your personal details, your email address, your address, your Credit/Debit Card numbers and bank code and your telephone number) is necessary for processing your order for the purchase of products on www.armaniexchange.com, supplying other services provided on the web site upon your request, or when your personal information is needed to fulfil obligations required by law or regulations.
The refusal to provide YOOX NET-A-PORTER GROUP with some of your personal data necessary for performing the above purposes may consequently prevent YOOX NET-A-PORTER GROUP from processing your order for the purchase of products sold on www.armaniexchange.com or fulfilling obligations required by law and other regulations. Therefore, failing to provide data may constitute, in some cases, a legitimate and justified reason for not processing your order for the purchase of products sold on www.armaniexchange.com or not providing www.armaniexchange.com's services. Disclosure of further personal data to YOOX NET-A-PORTER GROUP other than that required for fulfilling legal or contractual obligations is, on the contrary, optional and does not have any effect on the use of the web site and of its services or on the purchase of products on www.armaniexchange.com . In some circumstances and if required, from time to time we will duly inform you if the personal data you are disclosing to YOOX NET-A-PORTER GROUP is compulsory or optional. We will point out to you whether the disclosure of your data is compulsory or optional by marking with an appropriate symbol (*) the information that is compulsory or data needed for the purchase of products on www.armaniexchange.com. Failing to provide optional personal data will not imply any obligation or disadvantage to our users..
4. To Whom Your Personal Data Will Be Disclosed
Personal data will be disclosed to third party companies that provide, on behalf of YOOX NET-A-PORTER GROUP, specific services as data processors or to other recipients of personal data collected by YOOX NET-A-PORTER GROUP that autonomously process your personal data only for the performance of a contract for purchasing products on www.armaniexchange.com (for example, Banca Sella S.p.A.) and only when such purpose does not exceed the purposes for which your personal data was collected and subsequently processed and, in any case, according to applicable laws and regulations. Personal data will not be disclosed to third parties or disseminated or transferred without informing our users of such disclosure/dissemination/transfer, without their consent and, in any case, in accordance with the law.
5. How We Collect Your Data on www.armaniexchange.com
YOOX NET-A-PORTER GROUP directly collects personal data and information from its users when they register online with www.armaniexchange.com or when they send purchase orders of products sold on the web site in order to finalise e-commerce transactions. YOOX NET-A-PORTER GROUP will process such data only for the purposes and within the limits of what is stated in the section regarding data collection.
6. Security Measures
For the best possible protection of your personal data outside the limits of YOOX NET-A-PORTER GROUP's control and management of the same, it is advisable that your computer be provided with software devices that protect network data transmission/receipt (such as updated antivirus systems) and that your Internet service provider take appropriate measures for the security of network data transmission (such as, for example, firewalls and anti-spam filtering).
7. Processing Required by Law
We wish to inform you that YOOX NET-A-PORTER GROUP may process your personal data also without your consent in certain circumstances provided by law.
8. Your Right to Access Personal Data and Further Rights
a) the updating, adjustment or, when you have an interest in such, the integration of your personal data;
b) the deletion, the transformation into an anonymous form or blocking of your personal data (unlawfully processed), including data which does not need to be stored for the purposes for which it was collected and subsequently processed;
c) the confirmation that the operations under letters a) and b) have been reported (together with the contents of the same) to whom the data was disclosed or disseminated, except when it becomes impossible or if the means used are clearly disproportionate to the right's protection.
You are entitled to object, in whole or in part:
a) for legitimate reasons, to the processing of your personal data, even if it is related to the purposes for which it was collected;
b) to the processing of your personal data for advertising or direct marketing purposes or in order to carry out marketing research or commercial communications.
You may freely exercise your rights at any time, provided that you do so in compliance with applicable laws, by sending your request to YOOX NET-A-PORTER GROUP at the following email address: email@example.com. We will reply to you as necessary.
9. Links to Other Web Sites
If you wish to receive further information on how YOOX NET-A-PORTER GROUP processes your personal data, please send an email to firstname.lastname@example.org. Should you require any further information on your rights and on personal data protection law you can contact the personal data protection authority at the following address: www.garanteprivacy.it.
11. Governing Law