Identity of the owner

The Data Controller is the company Aureal Srls VAT number 02342850506 with registered office in Via Tosco Romagnola Est 471, 56028 San Miniato Basso (Pi) in the person of the legal representative, Email: info@drsvapo.it, Pec: aurealsrls@pec.it .

Identity of the Data Protection Officer

Aureal Srls in the person of its pro tempore legal representative based in Via Tosco Romagnola Est 471, 56028 San Miniato Basso (Pi). Email: administrator@drsvapo.it, Pec: aurealsrls@pec.it.

Source of data and type of data collected

a) Aureal Srls collects personal data provided on a voluntary basis by the user when registering on the website or when the latter performs a transaction through the website, as well as other personal data associated with order processing. Personal data includes: Title, name and surname, date of birth, social security number, gender, e-mail address, username and password, shipping and billing address (including postcode, city and country), telephone and fax number , type and quantity of products ordered, order date, order fulfillment status, date and time of delivery of the service, order value, currency, payment information (credit card number and expiry date), requests of returns or offers for the user and the following information provided on a voluntary basis by the user: how the website became known, company data, number of employees and, for corporate customers, date of foundation of the company (collectively "transaction data").

b) Aureal Srls also collects data on the use of the website by the user, such as IP address, the products displayed and those saved in the shopping cart; if the user reaches the website through a referral page or a link in a promotional e-mail or advertisement on another website that redirects to the website of https://www.drsvapo.it/; the company may also collect information on the referral page and on the promotional e-mail or targeted advertising together with the user's IP address to analyze the effectiveness of marketing operations (collectively "usage data").

Purpose of the processing

Personal data are processed by the Data Controller for:

1) Transaction data will be used to process orders, manage payments, communicate with the user about the order, manage product returns, customer service requests and perform product collection. They will also be used to acquire pre-contractual data and information; exchange information aimed at the execution of the contractual relationship, including pre and post contractual activities; formulate requests or process requests received; manage accounting and tax obligations.

2) The transaction data will also be used to send the interested party personalized messages or invitations to review the products; Usage data, in the case of registered customers, will be used in conjunction with transaction data (except payment information) to show customized products on the website based on the interests expressed by the user.

3) In order to make the marketing communications and the newsletter sent to the user concretely useful, the data on the transactions and the data on the use of the site will be analyzed by Aureal Srls to send personalized commercial communications based on the preferences indicated.

4) Finally, the data will be used to manage and control risks, prevent possible fraud, insolvency or default; prevent and manage possible disputes, take legal action in case of need.

Legal basis of the processing

The legal basis of the processing is as follows:

- the processing is necessary for the execution of a contract of which the interested party is a party or for the execution of pre-contractual measures adopted at the request of the same, as regards the treatments listed in point 1);

- the interested party has given consent to the processing of their personal data for one or more specific purposes, as regards the treatments listed in point 2);

- execution of pre-contractual measures adopted at the request of the interested party and legitimate interest of the owner (the maximization of the effectiveness of communications), as regards the treatments listed in point 3);

- the processing is necessary for the pursuit of the legitimate interest of the data controller (protection and prevention of fraud and insolvency), as regards the treatments listed in point 4).

Data recipients

The personal data processed by the Data Controller are not disclosed, that is, they are not disclosed to indeterminate subjects, in any possible form, including that of making them available or simple consultation. Instead, they can be communicated to workers who work for the Data Controller, or to persons authorized to process the processing as they operate under the authority of the data controller. In this regard, Aureal Srls has engaged third party service providers in relation to the operation of the website, such as hosting service providers, marketing and website service providers, IT maintenance service providers, shipping services and shipping services. VAT verification, as well as service providers that allow the integration into the website of other functions that the user can use at his discretion, for example the chat tool and the product review function. These service providers, designated as Data Processors, are provided only with the personal data they need to provide the corresponding services and they are not allowed to use or disclose the personal data of the data subjects for other purposes, without prior authorization. of the interested party.

If the interested party requests the sending of marketing communications and the newsletter of https://www.drsvapo.it/, his name, e-mail address and other data on transactions and use will be shared with Aureal Srls to allow an analysis of interests of the user and send personalized commercial communications based on the preferences indicated.

The user's transaction data is shared with Aureal Srls to allow the latter to manage any product withdrawals and for Aureal Srls to contact the user in this case.

They may also be communicated, within the strictly necessary limits, to subjects who, for the purpose of fulfilling orders or other requests or services relating to the transaction or contractual relationship with the Data Controller, must supply goods and / or perform on behalf of the Data Controller. performance or services. Finally, they can be communicated to the subjects entitled to access them by virtue of the provisions of the law, regulations, community regulations.

In particular, on the basis of the roles and work duties performed, some workers have been entitled to process personal data, within the limits of their competences and in accordance with the instructions given to them by the Data Controller.

Transfer of data

In no case does the Data Controller transfer personal data to third countries or to international organizations. However, it reserves the right to use cloud services; in which case, the service providers will be selected from among those who provide adequate guarantees, as required by art. 46 GDPR 679/16.

Data retention

The Data Controller keeps and processes personal data for the time necessary to fulfill the purposes indicated. Subsequently, the personal data will be stored, and not further processed, for the time established by the current provisions on civil and fiscal matters.

Rights of the interested party

With reference to articles 15 - right of access, 16 - right of rectification, 17 - right to cancellation, 18 - right to limitation of processing, 20 - right to portability, 21 - right to object, 22 right to object to the automated decision-making process of the GDPR 679 / 16, the interested party exercises his rights by writing to the Data Controller at the above address, or by email, specifying the subject of his request, the right he intends to exercise and attaching a photocopy of an identity document certifying the legitimacy of the request.

The Data Controller reminds in particular that any interested party can exercise the right of opposition in the forms and methods provided for by art. 21 GDPR. Further information on the rights of the data subject can be consulted at the bottom of this section or can be requested at support@drsvapo.it.

Withdrawal of consent

With reference to art. 7 of the GDPR 679/16, the interested party can revoke any consent given at any time.

However, some treatments covered by this information (points 1) and 4)) are lawful and permitted, even in the absence of consent, as they are necessary for the execution of a contract of which the interested party is a party, or for the fulfillment of his requests or to pursue legitimate interests of the data controller.

The withdrawal of consent, where applicable, may limit or compromise the methods of interaction and communication of the customer or user with the owner Aureal Srls.

Proposition of complaint

The interested party has the right to lodge a complaint with the supervisory authority of the state of residence.

Refusal to provide data

Interested parties cannot refuse to provide the Data Controller with the personal data necessary to comply with the laws governing commercial transactions and taxation.

The provision of further personal data may be necessary to improve the quality and efficiency of the transaction.

Therefore, the refusal to provide the data required by law will prevent the fulfillment of orders. The additional data indicated in point a) of the paragraph "Source of data and type of data collected" are provided on a voluntary basis; however, if the interested party decides not to provide the requested data, Aureal Srls may not be able to provide the services, allow the transaction to be completed via the website or process the order.

The data indicated in point b) data are provided voluntarily by the interested party and, if he decides not to provide the requested data, the supply of products and services will not be compromised.

Automated decision-making processes

The Data Controller does not carry out treatments consisting of automated decision-making processes on the data of natural persons, other than those indicated in the paragraph "Data recipients" in relation to those who request the sending of marketing communications and the newsletter.