Privacy & Cookie Policy

In compliance with Article 13 of EU Regulation 2016/679 on the protection of personal data (hereinafter also referred to as "GDPR") and subsequent national implementing legislation, we provide below general information regarding the processing and protection of the personal data of users who interact with the services accessible via the website atlanticstars.it (hereinafter also referred to as "Site"). Therefore, each user is encouraged to read this policy carefully.

1. Data controller

The Data Controller (hereinafter also referred to as the “Controller”) is:

AS Srl, VAT number 02531390447, with registered office in Via dell'industria, 53, 63900 Fermo (FM) - Italy and email address: shop@atlanticstars.it

                                                                                                                   

2. Categories of personal data

What is personal data?

Personal data (hereinafter also simply “Data”) is any information that, directly or indirectly, allows the user (hereinafter also simply “Data Subject”) to be identified as a natural person.

Data provided voluntarily by the user.

The data provided directly by the user is all personal data entered by the user on the Site (e.g., by completing the contact form; sending email and/or regular mail to the contact details on the Site; sending unsolicited job applications using the contact details on the Site, etc.). Examples of data provided directly by the user include: name, surname, home address, email address, telephone number, payment information, etc. The optional, explicit, and voluntary sending of emails to the addresses indicated on the Site entails the subsequent acquisition of the sender's address, which is necessary to respond to requests, as well as any other data included in the message.

In specific cases, Data may have been provided to us by third parties through the use of a feature or service activated on the Site, such as, for example, sending a gift card or shipping an order to the recipient's address. In such cases, the data provided is processed only if it is relevant to the performance of that feature or service, as indicated in this Privacy and Cookie Policy.

Navigation data.

The computer systems and software procedures used to operate this Site acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. 

This information is not collected to be associated with identified individuals, but by its very nature, it could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of the computers used by individual users connecting to the Site, the URI (Uniform Resource Identifier) ​​addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (successful, error, etc.), and other parameters relating to the operating system and IT environment of the data subject. This data is used solely to obtain anonymous statistical information on the use of the Site, as well as to verify its proper functioning, and is retained 15 days after processing.

Browsing data may also be used to ascertain responsibility in the event of hypothetical computer crimes against the Site (legitimate interest of the Data Controller).

Cookies

The Site uses cookies, as better specified in the specific information to which reference is made https://www.atlanticstars.it

Social Network Plugin

This site also incorporates social media plugins and/or buttons to allow easy sharing of content on your favorite social networks. These plugins are programmed to not set any cookies when accessing the page, to protect user privacy. Cookies are set, if required by the social networks, only when the user actively and voluntarily uses the plugin. Please note that if the user browses while logged in to the social network, they have already consented to the use of cookies delivered through this site when registering with the social network.

The collection and use of information obtained through the plugin are governed by the respective privacy policies of the social networks, to which please refer.

  • Facebook
  • Instagram

- Google

3. Purpose and legal basis of the processing

Without prejudice to the provisions regarding browsing data and cookies, the Data Subject's Data is collected and processed for the purposes indicated below.

A) Execution of pre-contractual measures at the request of the interested party, subsequent execution of the contract and related obligations.

The Data provided by the Data Subject may be processed for purposes strictly related to the fulfillment of purchase orders for products and/or services and the performance of related activities (such as managing payments, communicating order status, delivering products, exchanging goods or returns after purchase and managing related requests, booking products, using other features or services available on the Site, including the live chat service). The legal basis for processing the Data is the implementation of pre-contractual measures and the subsequent performance of the contract (Article 6, paragraph 1, letter b) of the GDPR).

Please note that if, when purchasing one of our products through the Site, you decide to activate the feature that allows us to save your payment card details for future purchases (if this feature is available), we need to process the data you provide to activate and provide this feature. Consent to activate this feature allows us to automatically complete your payment details for subsequent purchases, so you won't have to enter them for each new transaction. This data will be considered valid and effective for future purchases. You can modify or delete the payment card details you entered on the Site at any time, either through the payment information section or through your registered user account on the Site.

The data provided by the Data Subject may also be processed to fulfill obligations under national or EU laws and/or regulations that the Data Controller must comply with in providing the requested services and executing the contract. The legal basis for the processing is the need to fulfill a legal obligation (Article 6, paragraph 1, letter c) of the GDPR). 

Finally, the data provided by the interested party may be processed for the purposes of protecting creditors' claims, exercising the right of defense in court, and for ordinary internal organizational, operational, management, and accounting purposes. The pursuit of the Data Controller's legitimate interest (Article 6, paragraph 1, letter f) of the GDPR) constitutes the legal basis for the processing.

B) Registration for access to the reserved area 

The data provided by the data subject may be processed for registration and access to the Reserved Area on the Data Controller's website, which allows access to services reserved for registered users. The legal basis for the processing is the performance of the contract (Article 6, paragraph 1, letter b) of the GDPR) and the legitimate interest of the Data Controller (Article 6, paragraph 1, letter f) of the GDPR). 

C) Job opportunities (application)

The data provided by users interested in applying for open positions at AS Srl may be processed to evaluate their CV, schedule interviews, and subsequently evaluate their application. The processing of the data provided by the interested party is intended to evaluate their employment proposal (Article 6, paragraph 1, letter f) of the GDPR). Therefore, candidates are encouraged to include in their CV only the data necessary to evaluate their profile and to refrain from providing sensitive data (such as: membership in trade unions or professional organizations; trade union positions; political opinions and membership in political parties, trade unions, associations, or organizations of a religious, philosophical, or political nature; religious, philosophical, or other beliefs; ethnic and racial origin; personal data revealing health and sex life).

D) Direct marketing

Subject to the user's specific consent, the Data may be processed to send newsletters, advertising, informational, commercial, and promotional materials, as well as updates on initiatives, promotions, and offers relating to AS Srl's products and services, for direct sales purposes, market research, and invitations to events in which the user participates or organized by the Data Controller. The legal basis for the processing is express consent (Article 6, paragraph 1, letter a) of the GDPR).

E) Third-party marketing

Subject to the user's specific consent, the Data may be disclosed to third-party companies, who may process it to send commercial and/or promotional communications about products and services, as well as conduct market research.

Your consent (Article 6, paragraph 1, letter a) of the GDPR) constitutes the legal basis for the processing.

F) Profiling

Subject to the user's specific consent, the Data may be processed to analyze purchasing decisions, determine the level of acceptance of products and/or services offered, and determine consumer habits and propensities, with the aim of improving the Data Controller's marketing and services, as well as meeting specific customer needs (hereinafter also referred to as "Profiling"). Consent (Article 6, paragraph 1, letter a) of the GDPR) constitutes the legal basis for the processing. 

 

4. Nature of the provision of Data and consequences of refusal 

Without prejudice to the provisions regarding browsing data and cookies, the provision of Data is necessary for the purposes indicated in Article 3, letters A) and B). Failure to provide the Data will make it impossible to process the Data Subject's pre-contractual/contractual request and execute the contract, access the reserved area, or provide any requested services.

Providing your data for the purposes indicated in Article 3, letter C) is optional. However, failure to provide the data may make it impossible for the Data Controller to review and evaluate your collaboration proposal.

Consent to the processing of your data for the purposes indicated above under Article 3, letters D), E), and F) is optional. Failure to provide consent for the purposes indicated under Article 3, letters D), E), and F) will make it impossible for the Data Controller to process your data for the direct marketing, third-party marketing, and profiling purposes described above, respectively. Failure to provide consent for the purposes referred to in Articles 3, letters D), E), and F) will not prevent the implementation of pre-contractual measures and the subsequent conclusion and execution of the contract. In any case, even once consent has been given for the purposes referred to in Articles 3, letters D), E), and F), the Data Subject may request, at any time, that processing for these purposes be suspended by sending an email to shop@atlanticstars.it or by clicking on the link contained in each email.

 

5. Processing methods 

Personal data is processed using electronic, computerized, telematic, and/or paper-based tools, using methods strictly related to the purposes indicated above, in full compliance with applicable legislation, as well as the principles of lawfulness, transparency, necessity, proportionality, and non-excessiveness, and in a manner that guarantees user confidentiality.

Specific security measures are observed to prevent data loss, illicit or incorrect use of the same, and unauthorized access.

 

6. Retention period

The Data will be retained for the purposes of performing pre-contractual measures and the contract and related regulatory obligations (Article 3, letter A) in compliance with the principle of proportionality and non-excessiveness and, in any case, for a period of time no longer than strictly necessary to achieve the purposes for which they were collected, in compliance with the limitation periods established by the Civil Code. The Data will therefore be processed for the entire time necessary to manage the purchase of products or provide the requested services, including any returns, complaints, or disputes relating to the purchase of the product or service in question.

Regarding the purpose of registration for access to the Reserved Area of ​​the Site (Article 3, letter B), please note that the user may, at any time, request to be removed from the list of registered users using the "unregister" function on the Site.

With regard to the purpose of evaluating the collaboration proposal (Article 3, letter C), the Data will be processed for no longer than is necessary for the purposes for which the data was collected and, in any case, no longer than six months from receipt of the CV. 

Regarding processing for marketing purposes (Article 3, letter D), your Data will be retained by the Data Controller for a maximum period of 24 months from the date of your consent and/or its renewal. You may, however, request, at any time, that we discontinue processing for marketing purposes, in which case your Data will no longer be processed for this purpose.

Regarding processing for profiling purposes (Article 3, letter F), your Data will be retained by the Data Controller for a maximum period of 12 months from the date of consent collection or renewal. You may, however, request, at any time, that processing for profiling purposes be discontinued, in which case your Data will no longer be processed for this purpose.

 

7. Recipients of the data 

To achieve the purposes described in this policy, User Data may be processed by employees, similar personnel, and/or collaborators, as well as partners of the Data Controller, who act, duly appointed, as persons authorized to process personal data pursuant to Article 29 of the GDPR.

Personal data provided by users, customers, and suppliers may also be processed on behalf of AS Srl by third parties duly appointed as Data Processors pursuant to and for the purposes of Article 28 of the GDPR. These third parties include, for example, the following categories: 

a) providers of IT system management services (web hosting); 

b) subjects who handle administrative and/or fiscal obligations;

c) entities providing legal and/or tax consultancy services;

d) parties used by the Data Controller for the purposes of executing the contract (e.g., for shipping and delivery of products), for the correct fulfillment of contractual obligations undertaken, as well as for obligations arising from the law; 

e) advertising and marketing companies for the promotion of AS Srl's activities and the products/services it offers; 

f) third-party companies, in relation to third-party marketing purposes, only if you have given specific consent;

The complete and updated list of Data Processors is available upon user request.

Furthermore, the Data may be disclosed to judicial authorities and/or law enforcement agencies, or to entities to whom there is an obligation to disclose data pursuant to national or EU laws and/or regulations.

 

8. Dissemination of data

Personal data are not subject to disclosure.

 

9. Data transfer abroad

The interested party's data will not be transferred outside the European Union. 

 

10. Rights of the interested party

The GDPR grants users, as data subjects, the exercise of specific rights.

In particular, at any time, the interested party can obtain:

a) to request and obtain access to personal data, confirmation of their existence or otherwise, and communication of such data in an intelligible form; 

b) to obtain information on the origin of the personal data and to verify its accuracy, request its integration and/or updating, or rectification if inaccurate; 

c) to request and obtain the deletion of personal data when no longer necessary for the purposes for which they were collected and processed, the transformation of the same into anonymous form or the blocking of data processed in violation of the law; 

d) to request and obtain the limitation of processing if the personal data is inaccurate, is no longer necessary for the purposes for which it was collected and processed, or in the event of unlawful processing; 

e) to object in any case, for legitimate reasons, to the processing of the data; 

f) to receive the data concerning him/her, provided to the Data Controller and processed by automated means and to transmit them to another data controller, without hindrance from the Data Controller, as well as, if technically feasible, to obtain the direct transmission of the data from the Data Controller to whom he/she provided them to another data controller.

All these rights can be exercised by writing to the Data Controller's email address above.

The Data Controller will take charge of the user's request and provide the latter, without undue delay, with information relating to the action taken regarding his/her request.

Any corrections or deletions of data or limitations on processing, carried out at the user's request and unless this proves impossible or involves a disproportionate effort, will be communicated by the Data Controller to each of the parties to whom the Data has been transmitted. 

Finally, pursuant to Article 13, paragraph 2, letter d) of the GDPR, the interested party may exercise his or her rights by filing a complaint with the Italian Data Protection Authority, located at Piazza di Montecitorio 121, 00186 Rome.

 

This Policy may be subject to periodic updates.