Privacy Policy
Index
Who is the Data Controller?
RI.MOS. S.r.l., with registered office in Via Manunzio, 15 - 41037 Mirandola (MO) (VAT No.: 01846710364) (hereinafter, "Owner")
How can I contact him?
The contact details of the company are:
- Pec: info@pec.rimos.com
- Address: Via Manunzio, 15 – 41037 Mirandola (MO)
Foreword
Under the European Data Protection Regulation (GDPR), legal persons are not considered data subjects and therefore the European regulation does not apply. However, if personal data referring to a natural person is included in the context of the collection of corporate data, that person is to be considered a data subject under the aforementioned regulation with the consequent applicability of the relevant legislation.
What are the processing operations that are carried out through the site? And what are the legal bases, purposes and retention times?
Registration
- PURPOSE: The main purpose is to enable you to register on the site and be able to make purchases more easily. In case of litigation, the data will be processed in order to exercise or defend a right.
- LEGAL BASIS: Consent. Legitimate interest in litigation.
- STORAGE TIME: Your data will be processed until your consent is revoked. In case the account remains inactive for 7 years, we will send you an email to find out if you are still interested in keeping it active; alternatively, the account will be deleted. The data may be processed for a longer period in case of litigation.
- OTHER INFORMATION: Site registration is optional; purchases can also be made in "guest" mode.
- REGISTRATION THROUGH SOCIAL: On the site there is the possibility to register through social. Therefore, the data will not be provided directly by the Data Subject but imported by the social used (Facebook, Google) and therefore processed in accordance with art. 14 GDPR. The data being processed are: personal data and email address.
Purchase
- PURPOSE: The main purpose of data processing is to enable you to purchase and receive the purchased product. In addition, the data are necessary for the fulfillment of legal obligations (including accounting and tax). Finally, they may be needed in case of disputes raised about the proper fulfillment of the contract.
- LEGAL BASIS: Execution of a contract and consequent fulfillment of legal obligations incumbent on the data controller. In case of litigation, the data will be processed to act or defend in court and this corresponds to the legitimate interest of the data controller.
- STORAGE TIMES: The data will be deleted after 10 years from the fulfillment of the contract. They may be kept longer only in case of disputes and thus to exercise or defend a right.
- OTHER INFORMATION: The provision of data is mandatory and in case of refusal to provide it, it will not be possible to purchase the requested products.
Purchase with quick checkout
- PURPOSE: The main purpose of data processing is to enable you to purchase and receive the purchased product. In addition, the data are necessary for the fulfillment of legal obligations (including accounting and tax). Finally, they may be needed in case of disputes raised about the correct fulfillment of the contract.
- LEGAL BASIS: Execution of a contract and consequent fulfillment of legal obligations incumbent on the data controller. In case of litigation, the data will be processed to act or defend in court and this corresponds to the legitimate interest of the data controller.
- STORAGE TIMES: The data will be deleted after 10 years from the fulfillment of the contract. They may be kept longer only in case of disputes and thus to exercise or defend a right.
- OTHER INFORMATION: The provision of data is mandatory as it is necessary for the conclusion of the contract. Refusal to provide the data will result in the inability to proceed with the purchase.
- SOURCE AND CATEGORIES OF DATA PROCESSED: In the case of purchase through quick checkout, personal, shipping, billing and contact information will be imported from Paypal (art. 14 GDPR)
Transactional emails
- PURPOSE: The purpose of data processing is to send you information in connection with your purchase.
- LEGAL BASIS: Contractual performance.
- STORAGE TIME: Until the order is delivered.
- OTHER INFORMATION: Transactional emails are sent to enable better order processing and to provide the Customer with confirmation in relation to purchase and shipment.
Newsletter/DEM/also by automated (email, text message, WhatsApp, social) or traditional means
- PURPOSE: The purpose of data processing is to send you newsletters and DEM through traditional ways or also through automated ways (email, sms, WhatsApp, social network).
- LEGAL BASIS: Consent given by the Data Subject pursuant to Articles 6, co. 1, lett. a) GDPR and 130 co. 1-2 Legislative Decree 196/03
- STORAGE TIME: 5 years from the last submission.
- OTHER INFORMATION: Consent may be revoked at any time. The User has full freedom to release the requested data, as there is no legal obligation to provide it. However, if the User chooses not to provide the data reported as essential, the Data Controller will not be able to fulfill the stated purpose.
Newsletter/DEM “Softspam”
- PURPOSE: The purpose of data processing is to send you newsletters and DEM.
In the case of purchasing our product, your data will be exported to a CRM for sending commercial information about products similar to those you purchased. - LEGAL BASIS: In the case of purchase, your consent is not necessary according to art. 130 c. 4 Legislative Decree no. 196/03.
- STORAGE TIME: 5 years from the last submission.
- OTHER INFORMATION: It is possible to exercise output at any time.
Marketing and profiling through digital platforms
- PURPOSE: The purpose of data processing is to display marketing content based on your interests, as identified by your interactions on our site or social media. This includes the use of retargeting tools from digital platforms to deliver targeted advertising messages.
- LEGAL BASIS: Consent that can be acquired through various methods:
- Through Cookies on our Site: Your consent to marketing and profiling cookies is collected through the cookie settings on our site.
- For Custom Audience CRM Campaigns (Prospecting and Retargeting): For these campaigns, we obtain your explicit consent to use your contact information (e.g., e-mail address) for marketing purposes.
Interaction with Social Pages: If you have consented to the use of profiling cookies on our Site, we may process your contact information and information communicated during your interaction with Social Pages. We use this information, in accordance with your social media privacy settings, to show personalized marketing ads.
STORAGE TIME: Data will be kept until consent is revoked through cookie settings.
- MORE INFO:
Consent acquired through Cookies on our Site: You may manage or revoke this consent at any time, as described in our Cookie Policy. We also inform you. that cookies can be either first-party or third-party and therefore installed, our through, directly by Meta.
Acquired Consent for CRM Custom Audience Campaigns (Prospecting and Retargeting): This consent allows us to process your data to identify similar audiences (lookalikes) and to show targeted advertisements on social media and other digital platforms.
In the case of simple User segmentation, your consent is not required.
Contact us
- PURPOSE: The purpose is to offer the User or Customer the opportunity to contact the Data Controller. If from the exchange or in case of litigation, to exercise or defend a right.
- LEGAL BASIS: Contractual execution or fulfillment of pre-contractual measures carried out at the request of the data subject. In case of litigation, the legal basis is the legitimate interest of the Data Controller.
- STORAGE TIMES: We will process data for as long as necessary to respond to requests and then delete the data. It may be kept longer only in case of possible disputes and thus to exercise or defend a right based on the legitimate interest of the data controller.
- OTHER INFORMATION: The provision of data is optional and in case of refusal to provide it, it will not be possible to contact the Data Controller.
Back in stock
- PURPOSE: The purpose of data processing is to inform you when a terminated product becomes available for purchase again.
- LEGAL BASIS: Execution of pre-contractual measures carried out at the request of the Data Subject.
- STORAGE TIME: Data will be kept for as long as necessary to process the request and in any case no longer than 12 months after it is provided.
- OTHER INFORMATION: The provision of data is optional. However, if the User chooses not to provide the data deemed essential, it will not be possible to contact him/her again.
Abandoned trolley
- PURPOSE: The purpose of data processing is to be able to send n: 3 emails to invite the user to finalize the interrupted purchase on the site.
- LEGAL BASIS: Legitimate interest of the Data Controller in the conclusion of the purchase.
- STORAGE TIME: 72 hours
- OTHER INFORMATION: The provision of data is automatic and follows the partial completion of the shopping cart.
Review - Mode 1
- PURPOSE: The purpose is to share one's experience and publicize the products offered on the ecommerce.
- LEGAL BASIS: Consent of the person concerned.
- STORAGE TIMES: Reviews will be posted on the site until they become obsolete and/or until consent is revoked.
- OTHER INFORMATION: Consent can be revoked at any time.
Review - Mode 2
- PURPOSE: The purpose is to share one's experience and publicize the products offered on the ecommerce.
- LEGAL BASIS: Legitimate interest of the data controller and consent of the data subject given to the tool that deals with the review.
- STORAGE TIME: Reviews will be posted on the site until they become obsolete and/or until consent is revoked.
- OTHER INFORMATION: The provision of data for the request is automatic and follows the purchase of the product.
Navigation data
- PURPOSE: Site security.
- LEGAL BASIS: We will process data based on the company's legitimate interest in cybersecurity and fulfillment of legal obligations. The legal basis for processing cookies other than necessary cookies is consent.
- STORAGE TIME: 24 months.
- FURTHER INFORMATION: Please refer to the appropriate policy on cookies.
What else do I need to know?
The data will be processed lawfully, in accordance with fairness and with the utmost confidentiality, in compliance with the appropriate security measures as required by the Code and the Regulations. The processing will be carried out by digital means. The data will not be subject to public dissemination, with the exception of those related to reviews. In addition, the user will not be subjected to automated decision-making such as profiling unless he/she consents to this through the installation of cookies or other tracking tools for the normalization of which please refer to the appropriate information.
To whom will my data be disclosed?
The Holder may disclose the data to all subjects to whom the disclosure is required by law for the fulfillment of the purposes provided for by law.
The Data Controller also makes use of some companies (ex, the couriers) or IT tools that carry out processing activities on the personal data of the data subjects in the sole interest of the Data Controller, all of which are appropriately appointed as data controllers under article 28 GDPR.
The data will, in addition, be disclosed to payment gateways as autonomous holders.
The list of data processors can be found at the office.
In the event of a merger, sale or any other corporate change and/or in the event of the organization of one of these operations, your data may be shared. In addition, in the event that the company owned by the Data Controller or part of it is sold to a third party, the latter may continue to use your data, again in the manner provided in this privacy policy.
What is the location of data storage and Transfer?
The management and storage of personal data will take place on servers located within and outside the EU (DEM). The Data Controller ensures that non-EU transfers are made in accordance with articles 44-47 Chapter V of the GDPR through the signing of standard contractual clauses and/or through adequacy decisions.
What are my rights and how can I exercise them?
a) Rights of the data subject
The user, in his or her capacity as a data subject, has the rights set forth in Article 15 et seq. of the Regulations, namely:
- RIGHT OF ACCESS (art. 15 GDPR)
The data subject has the right to obtain confirmation of the existence or non-existence of personal data concerning him/her, even if not yet recorded, and its communication in an intelligible form. - RIGHT OF RECTIFICATION (art. 16 GDPR)
The person concerned has the right to obtain the rectification of inaccurate personal data concerning him or her and also the supplementation of incomplete data. - RIGHT TO CANCEL (art. 17 GDPR).
The data subject has the right to obtain the deletion of personal data if there are particular reasons such as revocation of consent, opposition to processing, or if the data are no longer necessary in relation to the purposes for which they were collected and processed or in case of unlawful processing. It will not always be possible to proceed with deletion but certainly it will be the burden of the data controller to provide adequate reasons. - RIGHT TO LIMIT PROCESSING (art. 18 GDPR).
The data subject has the right to obtain the restriction of processing in the presence of special hypotheses, such as, for example, in the case of a request for rectification or opposition during the time of evaluation of requests. - RIGHT TO PORTABILITY (art. 20 GDPR).
If the processing is based on consent or contract and is carried out by automated means, the data subject may receive them in a structured, commonly used and machine-readable format or request that they be transmitted to another data controller. - RIGHT OF OPPOSITION (art. 21 GDPR)
The data subject has the right to object, in whole or in part:- a) for legitimate reasons to process personal data concerning him/her, even if relevant to the purpose of collection;
- b) to the processing of personal data concerning him/her for the pursuit of purposes not covered by art. 2.
The user may make a request to object to the processing of his or her personal data pursuant to article 21 of the GDPR in which to give evidence of the reasons justifying the objection: the Data Controller reserves the right to evaluate the request, which would not be accepted in case of the existence of compelling legitimate reasons to proceed with the processing that override the user's interests, rights and freedoms.
RIGHT TO FILE A COMPLAINT
The data subject has the right to lodge a complaint with the competent supervisory authority under article 77 of the GDPR if he or she believes that the processing of his or her data is contrary to applicable law.
b) Mode of operation
The data subject may at any time exercise the rights referred to in the preceding article by contacting the data controller at the above addresses.
Latest version: 03/02/2025
This policy was prepared by Polimeni.Legal