Privacy Policy

Dear user,
Through this page, the companies identified with the brand Subdued wish to provide you with all the information regarding the processing of data concerning you, in compliance with the provisions of European Regulation 679/16 on the protection of personal data, and in accordance with the Privacy Code (as amended and supplemented by Legislative Decree. 101/18), illustrating to you the modalities, purposes and legal bases of each operation that could be performed on the data you have provided to us or who could provide you with, either on the occasion of using the website, or on the occasion of joining competitions, loyalty programmes or in any case operations involving the processing of personal data proposed by each of the companies mentioned above.
Any processing carried out is based on principles of lawfulness and correctness in compliance with the applicable regulations in force (and therefore in compliance also with the principles of necessity, correctness, lawfulness, transparency and protection of confidentiality) and with logics strictly related to the purposes pursued. Personal data may be processed by the companies identified by the Subdued brand, as autonomous data controllers, or as Joint Data Controllers according to the structure indicated in the dedicated section.
The companies listed below have also agreed to identify a single Data Protection Officer (D.P.O.) to make it easier for data subjects to exercise their rights.

  1. List of companies identified by the SUBDUED brand and perimeter of data co-ownership

    The companies identified by the SUBDUED label are as follows:

    Osit Impresa S.p.A. (Lead-company)

    Zerodieci S.r.l.
    Misotex S.r.l.AG France S.a.r.l.
    Sell Out 2003 S.r.l.BOS S.r.l.
    Tessilgroup GMBHALEGI Svizzera S.A.G.L.
    AG Brux S.p.r.l.AG UK LTD
    AG Iberica 2014 S.L.Alegi Vien GmbH
    AG Netherlands B.V.

    Each company is to be regarded as an autonomous Data Controller for all operations excluded from the scope of co-ownership described below:

    Data TypePerimeter of Co-ownershipShared tools usedNotes
    personal data of customers and potential customers;The master data provided by customers and the data from the tills, as well as from the SHOP ONLINE service, or from any published APPs can be consulted by all the companies in the Group, as all handling activities are performed in a coordinated manner on a single shared database.Customer data are stored within the centralised computer systems provided by the parent company. Each co-owner has a dedicated view of the customers operating at his or her outlets and can still consult the entire database.
    personal data of suppliers and collaborators;Useful' contacts, i.e. all references of professionals and/or companies that are reliable, are shared among all co-owners.Shared folders on parent company infrastructure
    personal data relating to the preferences of the persons concerned;Profiling and the implementation of loyalty cards (currently under evaluation) will be carried out at group level; therefore, all customer data will be shared with all group companies.Customer data are stored within the centralised computer systems made available by the parent company. Each co-owner can still consult the entire database.One of the most external managers contracted by the parent company present.
    personal data collected at the time of registration and in specific areas of the Site instrumental to the use of specific functionalities;The registration activity on the company website will be carried out at group level; therefore, all customer data will be shared with all companies in the group.Customer data are stored within the centralised computer systems made available by the parent company. Each co-owner can still consult the entire database.One of the most external managers contracted by the parent company present.
    personal data collected during the use of the Site;Data from navigation on the Subdued group's website (www.subdued.com and all related third-level domains) are shared with all the group's companies, which may use them to obtain feedback or evaluate any marketing actions carried out.The navigation data are stored within the centralised computer systems made available by the parent company. Each co-owner may, however, consult the entire database of navigation data.One of the most external managers contracted by the parent company present.
    application data (e.g. CVs and the like);Potential candidates who send their CVs via the website (https://careers.subdued.com) are registered on a dedicated CRM.The dedicated CRM is accessible to all group companies, which can consult the profiles and CVs of those who have applied.One of the most external managers contracted by the parent company present.

    Pursuant to recital (48) of European Regulation 679/16 in addition, the individual data controllers mentioned above may have a legitimate interest in passing on personal data within the business group for internal administrative purposes, including the processing of personal data of customers or employees.
    The co-ownership relationship defined through specific intra-group agreements has as its advantages the possibility of:

    • Enable the above companies to manage the data of interested parties in a more uniform and centralised manner, using the main facility of the parent company, Osit Impresa S.p.A. with registered office in Via delle Antille snc - Pomezia.
    • Ensuring faster execution of requests made by customers and stakeholders.
    • Ensuring a very high level of data protection through the adoption of security and cyber security techniques adopted for the protection of data in the centralised IT system.
    • Enabling customers to formulate their requests and exercise their rights to a single entity, which will centrally manage these requests.

    In relation to possible processing operations carried out by group companies, other potential relationships established or to be established are highlighted:

    Data TypeType of ReportTool UsedNotes
    Requests for access to video surveillance systemsEach company in the group identifies the parent company as the Data Processor with regard to the handling of requests that may arrive at the head office in any way. They also identify the parent company as the party that makes the extended information available on the group's website.Contact form on the website, contact e-mail and information pages on the website.
    Data Breach ManagementEach company in the group identifies the parent company as the Data Breach Manager, actively collaborating with the others to analyse and mitigate the risks.N/A
    Management of data relating to disputes (of any nature)Each company in the group identifies the parent company as the Data Processor for the handling of disputes and complaints.N/AOne of the most external managers contracted by the parent company present.
    Managing social activities (contacts, campaigns and the like)Each company in the group identifies the parent company as the Data Processor for the management of activities on all socials (if implemented).N/AOne of the most external managers contracted by the parent company present.

Below you can consult the individual information notices prepared for each processing activity, without prejudice to the possibility of the data subject also exercising his or her rights by contacting any of the companies indicated in the structure defined above, or by using the contact email of the Data Protection Officer: dpo@subdued.com.
As at the date of updating this information page, profiling activities carried out on registered users of the website are limited to the sending of non-invasive advertising and promotional material (discounts at events, abandoned cart management or similar). The legal basis for this processing is the legitimate interest of the Data Controller, according to the Legitimate Interest Assessment (LIA) prepared by the Data Controller and available upon request at dpo@subdued.com. The level of detail of the profiles, as well as their extent, are in fact limited and have the sole purpose of giving access to dedicated discounts for certain profiles.
List of information on data processing activities:

  1. Privacy Policy - Website

    This information is provided pursuant to Art. 13 of the EU Regulation 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter "Regulation" or "GDPR") and the privacy regulations currently in force.
    We are therefore informing you that Osit Impresa S.p.A. (hereinafter referred to as "Data Controller"), will process your data acquired while browsing the website https://www.subdued.com in compliance with the principles set out in art. 5 of the Regulation and guaranteeing the lawfulness of the processing itself, in accordance with art. 6 of the same Regulation.

    In connection with the above, we therefore inform you of the following:
    Identity and contact details of the Data Controller
    The data controller with regard to the management of all information relating to the above-mentioned websites is Osit Impresa S.p.A., VAT No. 10713061009, with registered office at Via Catania, 7/9 - Pavona Albano Laziale - Rome (RM) - contactable at the following e-mail address: infosubduedshop@subdued.com.
    Identity and contact details of the Data Protection Officer
    The Data Protection Manager identified by the Data Controller is STUDIO RIVELLI CONSULTING S.R.L., with registered office in Via G.A. Pasquale n° 40 - 00156 Roma - P.IVA 08087011006, which can be contacted at the email address dpo@subdued.com.
    Purpose and legal basis of processing
    The processing of your personal data, in addition to the purposes provided for by laws, regulations or European standards, is aimed at:
    • a) Managing the registration phases of the Site: purposes related to the use of the Site and instrumental to the use of specific services. If social network platforms or social login services are used, the customer may authorise the provider of these services to communicate certain personal data to the Company, which will be processed on the basis of this policy. The legal basis for this processing is the consent given by the person concerned at the time of registration.
    • b) Handling of data subject requests made through the Website: through specific forms on the websites, the user can interact with the companies identified by the Subdued brand, sending communications or requesting information.
      The legal basis for this processing is the consent provided by the user when using the form.
    • c) Finalize the purchase of products: through the online shop you can purchase Subdued and similar products on the portal. In order to finalise purchases, it is necessary to acquire the user's data (if he/she is registered), or in any case certain data that are strictly necessary to allow orders to be processed and shipped in the case of a "guest" purchaser.

    Categories of personal data processed
    The personal data processed are:

    • Personal data collected when registering on the Site
    • Personal data collected at the time of registration in specific areas of the Site instrumental to the use of specific functionalities
    • Purchase data, payment methods and 'shopping cart' history
    • Personal data collected during use of the Site, including navigation data and user behaviour if dedicated cookies have been accepted.

    Scope of Disclosure of Personal Data
    The personal data required to register on the Website, or necessary to use the contact forms, identified with an asterisk, are necessary to enable us to process your request and give you access to specific website features. This data may be shared with other companies identified by the Subdued brand, within the limits and for the purposes described in the document of co-ownership available in the dedicated section. It is also possible the sharing of data from corporate websites with third parties identified as Data Processors, for software or database technical support purposes. Lastly, in the case of online purchasing activities, it is foreseeable that only the information necessary for the shipment of goods will be transferred to third party companies entrusted with the distribution of goods. Please note that in order to make use of certain payment methods made available by the www.subdued.com website, data relating to orders may also be transferred to the companies that manage the aforementioned payment methods; we therefore invite you to read the Terms and Conditions published.

    Modalities of data processing
    The processing of Personal Data shall be carried out by manual, computerized or telematic means, suitable to guarantee security and confidentiality, and shall be performed by personnel duly trained in compliance with the Applicable Regulations. We also inform you that the Personal Data relating to you will be processed in compliance with the methods indicated by the Regulations, which provide, among other things, that the data shall be:

    • treated lawfully and fairly;
    • collected and recorded for specified, explicit and legitimate purposes;
    • exact and, if necessary, updated;
    • relevant, complete and not exceeding the formalities of the processing;
    • kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are collected or subsequently processed;
    • processed according to unambiguous procedures established by a single supervisory authority ("Lead Authority"), identified by reference to the State where the Controller has its head office.

    Furthermore, the Controller's business processes guarantee the confidentiality and security of information and its storage in compliance with legal requirements and the required security measures.

    Data retention period (criteria for determination)
    Personal data will be kept for the time strictly necessary to achieve the purposes for which they were collected. In particular:

    • for the purpose of point 3.a) the data will be retained until the request to cancel the registration from the website, or in any case after 3 years of account inactivity.
    • For the purposes of point 3.b), data will be retained for 1 year after the data subject's request has been processed, and subsequently anonymised and archived.
    • for the purpose of point 3.c) the data will be retained until the request to cancel the registration from the website, or in any case after 3 years of account inactivity.

    The time limits as described above represent the maximum retention time, unless different limits are imposed by the legislation currently in force.

    Recognised rights
    We inform you that you may exercise the following rights by sending a written request by e-mail to dpo@subdued.com:

    1. Requesting access to your personal data from the Controller;
    2. to request its rectification;
    3. to request the updating and deletion of their data, if incomplete, erroneous or collected in violation of the law;
    4. to request that the processing be limited to a part of the information concerning him/her;
    5. to object to their processing for legitimate reasons (even in part).
    6. to revoke consent at any time without affecting the lawfulness of the processing based on the consent given before revocation;

    In order to assert your rights, you may, in any event, contact the Data Controller or the Data Protection Officer at the contacts listed above.
    You are also reminded that, should the response to your request be deemed unsatisfactory, you have the right to turn to and lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) in the manner provided for by the Applicable Legislation.

  2. Privacy Policy - Cookies

    Information pursuant to Article 13 of EU Regulation 2016/679
    This information is provided pursuant to Art. 13 of the EU Regulation 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter "Regulation" or "GDPR") and the privacy regulations currently in force. We are therefore informing you that Osit Impresa S.p.A., in its capacity as the parent company of the Entrepreneurial Group identifiable with the Subdued brand (hereinafter "Data Controller" or "Owner"), will process your data acquired while browsing the website https://www.subdued.com, in compliance with the principles set out in art. 5 of the Regulation and guaranteeing the lawfulness of the processing itself, in accordance with art. 6 of the same Regulation.
    In connection with the above, we therefore inform you of the following:

    Identity and contact details of the Data Controller
    The data controller with regard to the management of all information relating to the above websites is Osit Impresa S.p.A., VAT No. 10713061009, with registered office in Via Catania 7/9 - 00041 Albano Laziale (Rome) - contacted at +39 0699360000.
    Identity and contact details of the Data Protection Officer
    The Data Protection Manager identified by the Data Controller is STUDIO RIVELLI CONSULTING S.R.L., with registered office in Via G.A. Pasquale n° 40 - 00156 Roma - P.IVA 08087011006, which can be contacted at the email address dpo@subdued.com.
    Purpose and legal basis of processing
    The processing of your personal data, in addition to the purposes provided for by laws, regulations or European standards, is aimed at:
    1. To allow the Site to function properly: this purpose is achieved by means of technical cookies that are indispensable to ensure the maintenance of active sessions, as well as all functions related to languages and dynamic content; in this case, the user's consent is not required in accordance with the "Guidelines for cookies and other tracking tools - 10 June 2021".
    2. Monitoring data traffic and the behaviour of the user navigating on the Site: by means of special temporary cookies, such as Google Analitycs, the Data Controller may acquire information to be used to analyse the performance of the website and/or the effectiveness of the actions carried out in the marketing sphere. The legal basis for this processing is the consent provided by the user in the cookie banner present and updatable at any time.

    Categories of personal data processed

    The personal data processed are personal data collected during navigation on the above-mentioned website, and for which the user has given specific consent.

    Use of cookies
    The above-mentioned website uses cookies to make its services simple and efficient for the users viewing the pages.
    Users viewing the Site will see minimal amounts of information placed on the devices they are using, whether computers or mobile devices, in small text files called "cookies" stored in directories used by the User's web browser. There are various types of cookies, some to make the use of the Site more effective, others to enable certain functionalities.
    By analysing them in detail, the Site's cookies allow us to:

    • store the preferences entered;
    • avoid re-entering the same information several times during the visit, such as user name and password;
    • analyse the use of services and content provided by subdued.com in order to optimise the browsing experience and the services offered.

    Types of cookies

    1. Technical cookies
      This type of cookie allows certain sections of the Site to function properly. They are of two categories: persistent and session:

      1) persistent: once the browser is closed, they are not destroyed but remain until a preset expiry date

      2) session: they are destroyed each time the browser is closed

      These cookies, which are always sent from the domain of the website for which they are set, are necessary to display the site correctly and in relation to the technical services offered, they will therefore always be used and sent, unless the user changes the settings in his or her browser (thus affecting the display of the site's pages).
    2. Analytical cookies
      Cookies in this category are used to collect information on the use of the site.
      The above-mentioned sites will use this information for anonymous statistical analysis in order to improve the use of the Site and to make the content more interesting and relevant to the user's wishes. This type of cookie collects data in an anonymous form on user activity and how users arrived at the Site. Analytical cookies are sent by the Site itself or by third-party domains.
    3. Third-party service analysis cookies
      These cookies are used to collect information on the use of the Site from users in an anonymous form such as: pages visited, time spent, traffic origins, geographical origin, age, gender and interests for the purpose of marketing campaigns. These cookies are sent from third-party domains outside the Site.

    4. D) Cookies for integrating third-party software products and functions
      This type of cookie integrates functionalities developed by third parties within the pages of the Site such as icons and preferences expressed in social networks for the purpose of sharing Site content or for the use of third party software services (such as software to generate maps and other software offering additional services). These cookies are sent from third party domains and partner sites that offer their functionality between the pages of the Site.

    5. E) Profiling cookies
      These are those cookies necessary to create user profiles in order to send advertising messages in line with the preferences expressed by the user within the pages of the Site.

    These are those cookies necessary to create user profiles in order to send advertising messages in line with the preferences expressed by the user within the pages of the Site.

    • by means of specific configurations of the browser used or the relevant computer programmes used to navigate the pages that make up the Site.
    • by modifying the preferences stored through the specific function of the component present in the overlay on each of the pages.

    Either of these solutions may prevent the user from using or viewing parts of the Site.

    Third-party websites and services

    The Site may contain links to other Web sites that have their own data protection policies, which may differ from those adopted by the Company and which are therefore not responsible for these sites.

    Cookie list

    CategoriaCookieDominioDurata della conservazione
    Necessaryapi/err.gifsubdued.comSessione
    NecessaryCookieConsentsubdued.com6 mesi
    Necessaryform_keysubdued.com1 giorno
    Necessaryis_eusubdued.comSessione
    Necessarymage-cache-sessidsubdued.com1 giorno
    Necessarymage-cache-storagesubdued.com1 giiorno
    Necessarymage-cache-storagesubdued.comPermanente
    Necessarymage-cache-storage-section-invalidationsubdued.com1 giorno
    Necessarymage-cache-storage-section-invalidationsubdued.comPermanente
    Necessarymage-cache-timeoutsubdued.comPermanente
    Necessarymage-messagessubdued.com1 giorno
    NecessaryPHPSESSIDsubdued.com1 giorno
    Necessaryproduct_data_storagesubdued.comPermanente
    Necessaryrecently_compared_productsubdued.com1 giorno
    NecessarySERVERID (app3.salesmanago.pl)subdued.comSessione
    NecessarySERVERID (salesmanago.pl)subdued.comSessione
    Preferences_smpssubdued.comPermanente
    Preferencessection_data_idssubdued.com1 giorno 
    Statistics_hjAbsoluteSessionInProgresssubdued.com1 giorno
    Statistics_hjFirstSeensubdued.com1 giorno
    Statistics_hjIncludedInPageviewSamplesubdued.com1 giorno
    Statistics_hjIncludedInSessionSampplesubdued.com1 giorno
    Statistics_hjSession_#subdued.com1 giorno
    Statistics_hjSessionUser_#subdued.com1 anno
    Statistics_hjTLDTestsubdued.comSession
    Statistics_smvssubdued.com1 giorno
    Statistics_smsvsubdued.comPermanente
    Statistics_sp_root_domain_test_#subdued.comSessione 
    Statistics_tt_enable_cookiesubdued.com1 anno
    Statisticsds-view-history-time-decaysubdued.comPermanente
    Statisticsmagepal-enhanced-ecommercesubdued.comSessione
    Statisticsmagepal-enhanced-ecommercesubdued.comPermanente
    Statisticsproduct_data_storagesubdued.com1 giorno
    Statisticsrecently_compared_product_previoussubdued.com1 giorno
    Statisticsrecently_viewed_productsubdued.com1 giorno
    Statisticsrecently_viewed_product_previoussubdued.com1 giorno
    Statisticssmformssubdued.comPermanente
    Marketing_fbpsubdued.com3 mesi
    Marketing_pin_unauthsubdued.com1 anno
    Marketing_smvcsubdued.comPermanente
    Marketing_ttpsubdued.com1 anno
    Marketingapi/r.gifsubdued.comSessione
    MarketingNRBA_SESSION_IDsubdued.comSessione
    Marketingrecently_compared_productsubdued.comPermanente
    Marketingrecently_compared_product_previoussubdued.comPermanente
    Marketingrecently_viewed_productsubdued.comPermanente
    Marketingrecently_viewed_product_previoussubdued.com Permanente
    Marketingsmgsubdued.com10 anni
    Marketingsmuuidsubdued.comPermanente
    Marketingsmvrsubdued.com399 days
    Marketingsmvrsubdued.comPermanente
    MarketingsnowplowOutQueue_#_post2subdued.comPermanente
    MarketingsnowplowOutQueue_#_post2.expiressubdued.comPermanente
    Marketingtt_pageIdsubdued.comSessione
    Marketingtt_pixel_session_indexsubdued.comSessione
    Marketingtt_sessionIDsubdued.comSessione
    Marketingv3subdued.comSessione
    UnclassifiedA/N (6)subdued.com399 days
    Unclassifiedcurrent_countrysubdued.com399 days
    Unclassifiedmgid.#subdued.comPermanente
    Unclassifiedmgid.#.expiressubdued.comPermanente
    Unclassifiedmgses.80e1subdued.comPermanente
    Unclassifiedmgses.80e1.expiressubdued.comPermannete

    About Cookies
    • _gat:The _gat cookie is part of the Google Analytics tracking and analysis service. It is a cookie that expires 10 minutes after being created or updated. It is used to block the number of requests from the analysis scripts so that the user's visits are considered unique.

      developers.google.com › cookie-usage
    • _gid: The _gid cookie is part of the Google Analytics tracking and analysis service. It is a cookie that expires after 24 hours after it has been created or updated. It is used to distinguish users.

      developers.google.com › cookie-usage
    • _ga: The _ga cookie is part of the Google Analytics tracking and analysis service. It is a cookie that expires 2 years after being created or updated. It is used to distinguish users.

      developers.google.com › cookie-usage

    How to disable cookies via browser configuration
    If you would like to learn more about how your browser stores cookies during navigation, the Company invites you to follow these links on the websites of the respective providers.

    Mozilla Firefoxhttps://support.mozilla.org/it/kb/Gestione%20dei%20cookie

    Google Chrome

    https://support.google.com/chrome/answer/95647?hl=it
    Internet Explorerhttps://support.microsoft.com/it-it/windows/eliminare-e-gestire-i-cookie-168dab11-0753-043d-7c16-ede5947fc64d
    Safari 8 o superiorihttps://support.apple.com/it-it/guide/safari/sfri11471/mac
    Safari su iPhone, iPad o iPod touchhttps://support.apple.com/it-it/HT201265

  3. Privacy Policy – APP

    Information pursuant to Article 13 of EU Regulation 2016/679

    A. DATA CONTROLLER
    The Data Controller for the APP used is Osit Impresa S.p.a, parent company of the companies identified by the Subdued brand with registered office in Via Catania, 7/9 - 00041 Albano Laziale (RM) - P. IVA 10713061009.

    B. DATA PROTECTION OFFICER
    The Data Protection Manager identified by the Data Controller is STUDIO RIVELLI CONSULTING S.R.L., with registered office in Via G.A.Pasquale n° 40 - 00156 Roma - P.IVA 08087011006.
    To exercise the above rights or to contact the Data Protection Officer, please send an e-mail to dpo@subdued.com.

    C. PURPOSE OF PROCESSING (APP)
    The APP is used to allow the user to view promotions, events and information in general, as well as to ensure the possibility of making purchases in the online shop, accessing their reserved area, or registering with our databases (account creation). The use of the APP allows the user to access many of the functions provided on the main website www.subdued.com, for which please refer to the dedicated information notice. No profiling activities of any kind are carried out through or by means of the APP itself.

    By using the APP's nearest shop search function, subject to specific consent, data relating to the location of the device deriving from its GPS geographical position may be used, only if this function is enabled through its operating system. Geolocation data will be used exclusively for the purpose of guaranteeing the correct operation of the nearest shop search service and will be processed locally (without acquisition by the Owner) by means of IT tools and stored exclusively and limitedly for the period of time necessary to achieve the purposes for which the data were collected.

    The legal basis for the processing of data for the purpose of using the nearest shop location system is the express consent of the data subject (Art. 6 Comma 1 Let. A of the GDPR) carried out directly on the personal device, while the legal basis for the activities of using the APP, is the execution of a contract between the parties and/or the execution of the related pre-contractual measures (Art. 6 Comma 1 Let. B of the GDPR), as well as the acquisition of a dedicated consent for specific personal data processing activities.

    D. METHODS OF TREATMENT
    Personal data collected through the APP will be processed by electronic means and entered into the Data Controller's Databases. No profiling operations are carried out using data acquired from the APP, and there are no plans to send messages or create personalised views from the clusters that may have been created, even if specific consent has been given. Data relating to Shop Online activities, will be processed exclusively for the correct conclusion of the contract generated between the parties, including dispatch and any customer assistance requested by the data subject (present directly on the APP).

    E. TYPE OF DATA PROCESSED
    The personal data that will be processed are those collected at the time of registration to the Subdued portal, made either through the APP, or through the website www.subdued.com, or at the time of finalizing a purchase, even if made as a guest user. This data will also be used to ensure the proper functioning of the APP or to identify, among other things, the most appropriate language to be used to make the content understood by the user.

    F.NATURE OF DATA PROVISION
    The personal data required to subscribe to the Subdued portal through the APP and identified with an asterisk in the registration forms are necessary to enable registration. Alternatively, it will be possible to use the so-called Social Login to register to the aforementioned portal.
    The contact information provided, where consent has been given, in addition to receiving communications related to the proper functioning of the Subdued APP or services, may be used for further purposes described in the Subdued extended services policy available at www.subdued.com.

    G. COMMUNICATION OF PERSONAL DATA
    The personal data acquired through the APP may be processed by the Persons authorised to process them, both internally and externally, because of the technical requirements for the management of the APP itself, on the basis of specific agreements between the parties that do not, however, entail any processing activities distinct from those indicated in point C of this notice.

    H. RIGHTS OF THE DATA SUBJECT
    By submitting a written request via email to dpo@subdued.com or through the contact form on the APP, you may ask the Data Controller to access your data, to delete it, to rectify inaccurate data, to supplement incomplete data, to restrict processing in the cases provided for by Article 18 GDPR, as well as to object to processing, for reasons related to your particular situation, in cases of legitimate interest of the Data Controller. For the complete information on the services offered by the business group identified with the Subdued brand, please refer to the extended information notice available on the website www.subdued.com

  4. Privacy Policy – Marketing and Profiling Activities

    Information pursuant to Article 13 of EU Regulation 2016/679
    This information is provided pursuant to Art. 13 of the EU Regulation 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "Regulation" or "GDPR") and the privacy regulations currently in force.
    We are therefore informing you that the companies identified by the Subdued brand, in their capacity as Joint Data Processors, according to what reported in the section "List of companies identified by the Subdued brand and perimeter of Joint Ownership" available in the Privacy section of this website, have started a processing activity aimed at preparing marketing campaigns and defining user profiling strategies. Osit Impresa S.p.A. (hereinafter the "Parent Company"), will process the data provided to the companies identified by the Subdued brand in accordance with the principles set out in art. 5 of the Regulation and guaranteeing the lawfulness of the processing itself, in accordance with art. 6 of the same Regulation.
    In connection with the above, we therefore inform you of the following:
    Identity and contact details of the Parent Company
    The companies identified by the Subdued brand, in their capacity as Joint Data Controllers for the marketing and profiling activities described below, have assigned the parent company (Osit Impresa S.p.A., VAT No. 10713061009, with registered office at Via Catania, 7/9 - Pavona Albano Laziale - Rome (RM) - contactable at the e-mail address: dpo@subdued.com) the task of defining the most suitable strategies, purposes and methods of processing, as well as identifying the most effective strategies for mitigating the risks for the data subjects involved.

    Identity and contact details of the Data Protection Officer
    The Data Protection Manager identified by the companies identified by the Subdued brand is STUDIO RIVELLI CONSULTING S.R.L., with registered office in Via G.A. Pasquale n° 40 - 00156 Roma - P.IVA 08087011006, contactable at the email address privacy@studiorivelli.it or at the email address dpo@subdued.com.

    Purpose and legal basis of processing
    The processing relating to the management of Online Shop Accounts involves the use of the applicant's personal data, acquired at the time of registration. This data is used for:

    1. Enforcing the economic and contractual conditions governing the use of Online Shop Accounts, including the activities of collecting points and claiming rewards and benefits (if implemented or active as services);
    2. Marketing activities and sending of advertising material;
    3. Subject to your specific consent, we will profile your consumption choices and preferences in order to adapt the commercial offer as much as possible to your profile and needs, including through the creation of a customer profile based on your preferences, habits, interests, behaviour, products purchased, responses to market research in order to send you personalised commercial communications (e.g. free products, personalised offers and discount vouchers, dedicated flyers). Through the acquisition of information relating to purchases, pages visited on our websites and mobile applications, moreover, your profile may be updated or included in clusters that may have access to dedicated promotions.
    The legal basis for these processing operations is respectively for point a) the execution of an existing contract between the parties, and for points b) and c) the free and express consent of the data subject (optional and revocable at any time).

    As regards the activity referred to in point c), as of the date of updating of this information page, profiling activities carried out on users registered to the website are limited to sending non-invasive advertising and promotional material (discounts at events, management of abandoned shopping carts or similar). The legal basis for this processing is the legitimate interest of the Data Controller, according to the Legitimate Interest Assessment (LIA) prepared by the Data Controller and available upon request at dpo@subdued.com. The level of detail of the profiles, as well as their extent, are in fact limited and have the sole purpose of giving access to dedicated discounts for certain profiles.
    The refusal to provide consent for the processing referred to in points b) and c) does not have any consequence on the use of the services provided by Subdued Online Shop Accounts; therefore, the companies identified by the Subdued brand may still use the personal data provided at the time of subscription only for purposes related to the use and management of the Accounts themselves.

    Further information for the interested party

    MARKETING - Subject to the explicit and optional consent (purpose b), the companies identified by the Subdued brand may process the personal data provided also for sending informative and promotional material or commercial communications. In this regard, the Parent Company will send the data subject commercial and promotional communications through automated contact methods (e-mail or newsletter).

    PROFILING - Subject to explicit and optional consent (purpose c), companies identified by the Subdued brand may process the personal data provided for profiling purposes of the habits and consumption choices of the data subject. Data will be collected, recorded and processed on a computer system containing the customer's consumption choices (CRM) in order to aggregate data in a personalised way, to obtain an in-depth analysis of demand dynamics, from which to prepare a plan of targeted promotional offers. As a result, the person concerned will be able to receive the commercial offers most compatible with his or her preferences. In his or her reserved area, the interested party will be able to view the clusters in which he or she is 'inserted', to receive information on the nature and logic of these clusters, and to modify his or her preferences (by enabling or disabling them) in full autonomy.
    Type of data processed
    The data collected and processed by companies identified by the Subdued brand are data of a personal nature of Subscribers, i.e. information through which a person can be identified as a natural person (e.g. first name, last name, date of birth, residence, e-mail address, telephone number, etc.) and may include, subject to consent, other information such as, for example, shopping habits, indications of preferred products, contents of shopping carts, etc.
    Information relating to the profession, provided by the person concerned on an optional basis, may be used for the activation of special promotions or dedicated discounts.

    Data Communication
    For the purposes of the above-mentioned processing, the data provided may be communicated:
    • to other companies identified by the Subdued trademark;
    • to Data Processors formally appointed by the Controllers in order to manage all and only the processing activities defined in this information notice to carry out activities strictly related to the performance of services connected and instrumental to the management of the after-sales service (customer care services, logistics, etc.);
    • to all those persons entrusted with activities strictly related to the performance of promotion, commercial solicitation and advertising services, where specific consent has been given.

    The data may also be communicated to other entities acting as data controllers, such as, by way of example, banks and credit institutions, supervisory and control authorities and any legitimised public entity, such as judicial and/or public security authorities.

    Modalities and duration of treatment
    Data will be processed in full compliance with the principles of confidentiality, correctness, necessity, relevance, lawfulness and transparency imposed by the Regulation for the time necessary to achieve the purposes for which the data were collected and, in any case, no longer than 10 years from their collection in the case of the purchase of goods (e.g. premiums or similar) for administrative accounting purposes, or for the time necessary to fulfil the contractual conditions relating to the coverage of the legal guarantee.
    For marketing activities, where authorised, data with a lifespan of more than 36 months will be deleted or anonymised and aggregated solely for the purpose of monitoring purchases and stock.
    For profiling activities, where authorised, cluster membership data will be updated at least every six months and deleted when the conditions for membership are no longer met (you will not receive communications about products that are not in line with your choices or preferences, but we will try to adapt the offer to the evolution of your tastes), or if the person concerned decides to disable them.


    Transfer of personal data outside the EU
    The data provided may be processed by IT service providers, in their capacity as acting data processors, but will not be stored or transferred outside the European Economic Area.

    Rights of data subjects
    By submitting a written request, by email, to dpo@subdued.com or via the personal area of the www.subdued.com website, the data subject may exercise all the rights set out in Article 15 et seq. of the Regulation, including the right to:

    • receive confirmation of the existence of your personal data, know the purpose of the processing or the scope of their circulation and access their content;
    • update, modify and/or correct your personal data (including in relation to data that may give access to particular promotions);
      request cancellation, transformation into anonymous form, blocking of data processed in breach of the law or restriction of processing;
    • oppose processing, including profiling, for legitimate reasons;
      object to the processing of data for the purpose of sending advertising or direct sales material or for carrying out commercial communication market research;
    • revoke consent, where given, without prejudice to the lawfulness of the processing based on the consent given before revocation;
    • receive a copy of the data you have provided and request that such data be passed on to another data controller.

    To exercise these rights, you may also contact the Data Protection Officer (DPO) at dpo@subdued.it. This request will be answered within the timeframe provided for by the GDPR. If the data subject discovers that his or her rights have been violated, he or she may still appeal to the competent supervisory authority pursuant to Article 77 of the GDPR, without prejudice to the possibility of appealing directly to the judicial authorities.

  5. Privacy Policy - Video surveillance systems

    This information is provided pursuant to Art. 13 of the EU Regulation 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter "Regulation" or "GDPR") and the privacy regulations currently in force.
    We are therefore informing you that the data relating to the images taken by the video surveillance systems put into service by the company indicated on the signs at the entrance to the Store, in its capacity as Autonomous Data Controller (or "Data Controller"), will be processed in compliance with the principles laid down in Article 5 of the Regulation and guaranteeing the lawfulness of the processing in accordance with Article 6 of the same Regulation, as well as in compliance with the provisions of the Order of the Privacy Authority of 8 April 2010 on video surveillance.

    In connection with the above, therefore, we inform you of the following:

    Identity and contact details of the Data Controller
    The data controller is the company indicated as Autonomous Data Controller in the signs posted at the Point of Sale and belonging to the 'Subdued' group of which Osit Impresa S.p.A. is the parent company, which can be contacted at the following e-mail address: infosubduedshop@subdued.com

    Name and contact details of the Data Protection Officer
    The Data Protection Manager identified (in accordance with the provisions of art. 37, par. 2 of the RGPD) is STUDIO RIVELLI CONSULTING S.R.L., with registered office in Via G.A. Pasquale n° 40 - 00156 Roma - P.IVA 08087011006, which can be contacted at the email address dpo@subdued.com.

    Purpose and legal basis of processing
    The processing of images taken by surveillance cameras, in addition to the purposes provided for by laws, regulations or European standards, is aimed at:

    • protection of real and movable assets owned by the Holder;
    • safety and protection of the safety of employees and third parties;
    • organisational and production needs;
    • acquisition of evidence in the context of defence checks.

    The legal basis for the processing can therefore be found in:

    • legitimate interest of the Controller in the protection of its assets and the prevention of unlawful acts pursuant to Art. 6 para. 1 lit. f) GDPR;

    Categories of personal data processed
    The data processed by the data controller include your image recorded by video surveillance systems and may also include, as a consequence of the video recording, any physical characteristics.

    Modalities of data processing
    We inform you that your data are processed with the aid of electronic tools, in compliance with the Regulations and the applicable Measures of the Data Protection Authority, including, in particular, the aforementioned Measure on video surveillance - 8 April 2010, and Guidelines 3/2019 on the processing of personal data through video devices (adopted on 29 January 2020). The data will be processed in accordance with procedures and methods related to the purposes indicated above. Filming, therefore, will be carried out in such a way as to avoid detailed and invasive images of people's privacy, thus limiting the possibility of identification.

    The Personal Data relating to you will therefore be:

    • processed lawfully and fairly;
    • collected and recorded for specified, explicit and legitimate purposes;
    • relevant, complete and not exceeding the processing formalities;
    • kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are collected or subsequently processed;
    • processed according to unambiguous procedures established by a single supervisory authority ("Lead Authority"), identified by reference to the State where the Controller has its head office.

    Furthermore, the Controller's business processes guarantee the confidentiality and security of information and its storage in compliance with legal requirements and the required security measures.

    Scope of Disclosure of Personal Data
    Your data may be accessed by the following parties exclusively for the purposes described and in compliance with the provisions of the Regulation and the aforementioned Order issued by the Personal Data Protection Authority:

    • Data Processors appointed by the Controller pursuant to Article 28 of the Regulation, including consultants and freelancers;
    • personnel authorised to process data in accordance with Article 29 of the Regulation, in particular with the designation by the Data Controller of the persons authorised to use the facilities and view the recordings, in cases where this is necessary to pursue the purposes set out above;
    • external data controllers appointed by the data controller such as video-surveillance equipment maintenance companies, security institutes, companies managing computer networks and systems;
    • competent authorities (e.g. judicial and police authorities) upon formal request.

    Data retention period
    The maximum retention period for recorded images is 48 hours following detection, after which the recorded data are automatically deleted, without prejudice to specific requirements for further retention in connection with holidays or closures, or in the event of a specific investigative request by the judicial authority or police or in the event of complaints/complaints to the Authority.

    Recognised rights
    We inform you that, as a Data Subject, you may exercise your rights under Articles 15-22 of the Regulation. In particular, in accordance with the applicable regulations, you are granted the following rights:

    1. Requesting access to your personal data from the Controller;
    2. to request the deletion of their data;
    3. to object to their processing for legitimate reasons (even in part).

    To assert your rights, you may contact the Data Controller or the Data Protection Officer at the contact details given above.
    You are also reminded that, should the response to your request be deemed unsatisfactory, you have the right to turn to and lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) in the manner provided for by the Applicable Legislation.

  6. Privacy Policy - Telephone calls to Customer Care

    This information is provided pursuant to Art. 13 of the EU Regulation 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "Regulation" or "GDPR") and the privacy regulations currently in force.
    We are therefore informing you that the companies identified by the Subdued brand, in their capacity as Joint Data Processors, according to what reported in the section "List of companies identified by the Subdued brand and perimeter of Joint Ownership" available in the Privacy section of this website, have started a processing activity aimed at monitoring telephone traffic of the call center.  Osit Impresa S.p.A. (hereinafter the "Parent Company"), will process the data provided to the companies identified by the Subdued brand in accordance with the principles set out in art. 5 of the Regulation and ensuring the lawfulness of the processing itself, in accordance with art. 6 of the same Regulation.

    In relation to the above, we therefore inform you of the following:

    Identity and contact details of the Parent Company
    The companies identified by the Subdued brand, in their capacity as Joint Data Controllers, have assigned the parent company (Osit Impresa S.p.A., VAT No. 10713061009, with registered office in Via Catania, 7/9 - Pavona Albano Laziale - Rome (RM) - contactable at the e-mail address: dpo@subdued.com) the task of defining the most suitable strategies, purposes and methods of processing, as well as identifying the most effective strategies for mitigating the risks for the data subjects involved.


    Identity and contact details of the Data Protection Officer
    The Data Protection Manager identified by the companies identified by the Subdued brand is STUDIO RIVELLI CONSULTING S.R.L., with registered office in Via G.A. Pasquale n° 40 - 00156 Roma - P.IVA 08087011006, contactable at the email address privacy@studiorivelli.it or at the email address dpo@subdued.com.

    Purpose and legal basis of processing
    The processing of your personal data, in addition to the purposes provided for by laws, regulations or European standards, is aimed at:

    1. Monitor the quality of the customer service that contacts the call centre;
    2. Providing the requested services, managing customer relations and handling any complaints/complaints made by the data subject.

    During the telephone call, the user will be warned in advance about the recording by means of a brief information note issued by a recorded voice. If he/she does not intend to interrupt the telephone call, the principle of "continuation of the telephone call/assent" to registration will be manifested.
    The provision of data is optional, but necessary in order to manage control over the quality of the service provided and, if necessary, to formalise, accept and manage the requests made by the person concerned. With regard to the above, the legal bases of the processing are the stipulation and execution of a contract, the fulfilment of legal obligations and the pursuit of the legitimate interests of the Data Controller.

    Categories of personal data processed
    The processing relates to personal data generally consisting of personal identification data collected directly from Data Subjects.

    Scope of communication of Personal Data
    The personal data acquired may be processed not only directly by the Data Controller, but also by personnel authorised by the latter. 
    Personal data may also be communicated to parties external to the Data Controller, who are delegated or authorised by law, or who are linked to the Data Controller by specific relationships, including contractual ones, to whom the Data Controller entrusts certain activities, or part of them, functional to the purposes set out in point 3, such as other companies of the Subdued brand.
    Personal data shall not be subject to dissemination.

    Modalities of data processing
    The processing of Personal Data will be carried out by personnel duly trained in compliance with the applicable legislation by means of manual, computerized or telematic tools suitable to guarantee security and confidentiality. We also inform you that the Personal Data relating to you will be processed in compliance with the methods indicated by the Regulations, which provide, among other things, that the data be

    • processed lawfully and fairly;
    • collected and recorded for specific, explicit and legitimate purposes;
    • accurate and, if necessary, updated;
    • pertinent, complete and not excessive in relation to the formalities of the processing;
    • kept in a form which permits identification of the data subject for no longer than is necessary for the purposes for which they are collected or subsequently processed;
    • processed in accordance with unambiguous procedures established by a single supervisory authority ("Lead Authority"), identified by reference to the State where the Controller has its head office.

    In addition, the Controller's business processes guarantee the confidentiality and security of the information and its storage in compliance with legal requirements and the required security measures.


    Period of data retention (criteria for determination)
    The personal data acquired will be stored for as long as is strictly necessary to process the data subject's requests and for a maximum of 1 year from the date of registration.

    Rights granted
    We inform you that, in accordance with the regulations in force, you are granted the following rights:

    1. To request access to your personal data from the Data Controller;
    2. to request its rectification
    3. to request the updating and deletion of your data, if incomplete, erroneous or collected in violation of the law
    4. to request that the processing be limited to a part of the information concerning them;
    5. to object to their processing for legitimate reasons (even in part).
    6. to withdraw consent at any time without prejudice to the lawfulness of the processing based on the consent given before the revocation;

    In order to assert your rights, you may contact the Data Controller at the contacts listed above.
    We also remind you that, should the response to your request not be considered satisfactory, you have the right to contact and lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) in the manner provided for by the Applicable Regulations.

  7. Privacy Policy - Pickup in Store

    This information is provided pursuant to Articles 13 and 14 of the EU Regulation 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "Regulation" or "GDPR") and the privacy regulations currently in force.
    We are therefore to inform you that the companies identified by the Subdued brand, in their capacity as Joint Data Controllers, according to what reported in the section "List of companies identified by the Subdued brand and perimeter of Joint Ownership" available in the Privacy section of this website, have started a processing activity that has as its purpose the management of the activities of withdrawal of goods ordered online at physical shops.  Osit Impresa S.p.A. (hereinafter the "Parent Company"), will process the data provided to the companies identified by the Subdued brand in accordance with the principles set out in art. 5 of the Regulation and guaranteeing the lawfulness of the processing itself, in accordance with art. 6 of the same Regulation. 
    In connection with the above, we therefore inform you of the following:

    Identity and contact details of the Parent Company
    The companies identified by the Subdued brand, in their capacity as Joint Data Controllers for the marketing and profiling activities described below, have assigned the parent company (Osit Impresa S.p.A., VAT No. 10713061009, with registered office at Via Catania, 7/9 - Pavona Albano Laziale - Rome (RM) - contactable at the e-mail address: dpo@subdued.com) the task of defining the most suitable strategies, purposes and methods of processing, as well as identifying the most effective strategies for mitigating the risks for the data subjects involved.

    Identity and contact details of the Data Protection Officer
    The Data Protection Manager identified by the companies identified by the Subdued brand is STUDIO RIVELLI CONSULTING S.R.L., with registered office in Via G.A. Pasquale n° 40 - 00156 Roma - P.IVA 08087011006, contactable at the email address privacy@studiorivelli.it or at the email address dpo@subdued.com.

    Purpose and legal basis of processing
    The processing of your personal data, in addition to the purposes provided for by laws, regulations or European standards, is aimed at

    1. Correct handling of the sales contract finalised in the online shop;
    2. Correct administrative, fiscal and accounting management of the sales contract finalised in the online shop;
    3. Provide the user with the possibility of collecting the goods directly from one of Subdued's retail outlets (if possible).

    The legal bases for the processing in question are in the performance of obligations arising from a contract (points b and c).

    Categories of personal data processed
    The data processed are personal, of an identifying nature (name, surname, addresses, type and number of identification documents, telephone numbers, e-mail addresses, of a fiscal/invoicing nature or in any case necessary to identify the persons concerned and to be able to deliver the goods), referring to the purchaser and the person delegated to collect the goods.
    Photocopies of identification documents will not be acquired, but only consulted by point-of-sale personnel to verify the identity of delegates and proxies.

    Scope of communication of Personal Data
    The personal data acquired may be processed not only directly by the Controller, but also by personnel authorised by the Controller. 
    Personal data may also be communicated to parties external to the Data Controller, who are delegated or authorised by law, or who are linked to the Data Controller by specific relations, including contractual relations, to whom the Data Controller entrusts certain activities, or part of them, functional to the purposes set out in point 3, such as other companies of the Subdued brand or parties who need to come into possession of these data to ensure that collection operations can be carried out safely (e.g. courtesy service if present or similar).
    Personal data will not be subject to dissemination.

    Modalities of data processing
    The processing of Personal Data will be carried out by personnel duly instructed in compliance with the applicable legislation by means of manual, computerized or telematic tools suitable to guarantee security and confidentiality. We also inform you that the Personal Data relating to you will be processed in compliance with the methods indicated by the Regulations, which provide, among other things, that the data be:

    • treated lawfully and fairly;
    • collected and recorded for specified, explicit and legitimate purposes;
    • exact and, if necessary, updated;
    • relevant, complete and not excessive in relation to the formalities of the processing;
    • kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are collected or subsequently processed;
    • processed according to unambiguous procedures established by a single supervisory authority ("Lead Authority"), identified by reference to the State where the Controller has its head office.

    Furthermore, the Controller's business processes guarantee the confidentiality and security of information and its storage in compliance with legal requirements and the required security measures.

    Data retention period (criteria for determination)
    The personal data acquired will be stored for the time strictly necessary for the execution of the contract and thus for the delivery of the goods in the shop. After 6 months from the date of delivery of the goods, the acquired forms will be destroyed and only the information concerning the chosen delivery method will be stored.

    Recognised rights
    We inform you that, in accordance with current regulations, you are granted the following rights:

    1. Requesting access to your personal data from the Controller;
    2. to request its rectification;
    3. to request the updating and deletion of their data, if incomplete, erroneous or collected in violation of the law;
    4. to request that the processing be limited to a part of the information concerning him/her;
    5. to object to their processing for legitimate reasons (even in part).
    6. to revoke consent at any time without prejudice to the lawfulness of the processing based on the consent given before revocation;

    If you wish to assert your rights, you may contact the Controller at the contacts listed above.
    You are also reminded that, should the response to your request be deemed unsatisfactory, you have the right to turn to and lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) in the manner provided for by the Applicable Legislation.

  8. Privacy Policy - Whatsapp and chatbot

    Privacy Policy pursuant to Art. 13 of EU Regulation 2016/679

    This information is provided pursuant to Art. 13 of EU Regulation 2016/679 concerning the protection of individuals with regard to the processing of personal data, as well as the free movement of such data (hereinafter referred to as the "Regulation" or "GDPR") and the current privacy regulations.

    We hereby inform you that the companies identified by the Subdued brand, as Data Controllers, as stated in the "List of Companies identified by the Subdued brand and scope of joint ownership" available in the Privacy section of this website, have initiated processing activities aimed at allowing users to interact with the contact center made available to customers, through instant messaging services and chatbots. Osit Impresa S.p.A. (hereinafter referred to as the "Parent Company"), will process the data provided to the companies identified by the Subdued brand in compliance with the principles set out in Art. 5 of the Regulation and ensuring the lawfulness of the processing itself, as stated in Art. 6 of the same Regulation.

    In relation to the above, we therefore inform you of the following:

    Identity and contact details of the Parent Company

    The companies identified by the Subdued brand, as Data Controllers, have assigned the parent company (Osit Impresa S.p.A., VAT number 10713061009, with registered office in Via Catania, 7/9 – Pavona Albano Laziale - Roma (RM) - contactable at the email address: dpo@subdued.com) the task of defining the most suitable strategies, purposes and processing methods, as well as identifying the most effective strategies for mitigating risks for the data subjects involved.

    Identity and contact details of the Data Protection Officer

    The Data Protection Officer appointed by the companies identified by the Subdued brand is STUDIO RIVELLI CONSULTING S.R.L., with registered office in Via G.A. Pasquale n° 40 – 00156 Roma – VAT number 08087011006, contactable at the email addresses privacy@studiorivelli.it or dpo@subdued.com.

    Purposes and legal basis of the processing

    The processing of your personal data, in addition to the purposes provided for by laws, regulations or European standards, is aimed at:

    1. a) Monitoring the quality of the customer service provided to those who contact us using instant messaging systems (e.g. WhatsApp or similar).
    2. b) Providing the requested services, managing customer relationships, and managing any disputes/complaints raised by the data subject.

    By selecting the WhatsApp button or following the instructions received during the call to the contact center, you will receive a message that starts the conversation. In this initial phase, you will be asked to read the information and accept its contents.

    The provision of data is optional, but necessary to allow the use of the messaging system and/or chatbot and, if applicable, to formalize, accept, and manage requests submitted by the data subject. With regard to the above, the legal bases for the processing are the express consent through a positive action by the user, the performance of a contract, and compliance with legal obligations.

    Categories of personal data processed

    The processing concerns personal data generally consisting of elements of personal identification collected directly from data subjects.

    Scope of communication of Personal Data

    The personal data acquired may be processed, in addition to directly by the Data Controller, also by authorized personnel thereof.

    The personal data may also be communicated to third parties other than the Data Controller, who are appointed or authorized by law, or who are linked to the Data Controller by specific, including contractual, relationships to which the Data Controller entrusts certain activities, or part of them, functional to the purposes set out in point 3, such as other companies of the Subdued Brand.

    Personal data will not be subject to disclosure.

    Methods of data processing

    The processing of Personal Data will be carried out by personnel duly instructed in compliance with applicable regulations through manual, computerized, or telematic tools, suitable to ensure their security and confidentiality. We also inform you that the Personal Data relating to you will be processed in compliance with the methods indicated by the Regulation, which, among other things, provide that the data must be:

    • processed lawfully and fairly;
    • collected and recorded for specific, explicit, and legitimate purposes;
    • accurate and, if necessary, updated;
    • relevant, complete, and not excessive in relation to the purposes of the processing;
    • kept in a form that allows the identification of the data subject for a period not exceeding that necessary for the purposes for which they are collected or subsequently processed;
    • processed according to procedures established by a single supervisory authority ("Lead Authority"), identified with reference to the State where the Data Controller has its main office.

    In addition, the Data Controller's business processes ensure the confidentiality and security of information and its retention in compliance with legislative prescriptions and required security measures.

    Period of data retention (criteria for determination)

    The personal data acquired will be retained for the time strictly necessary for the processing of the data subject's requests and for a maximum of 1 year from the date of registration.

    Rights recognized

    We inform you that, in accordance with current regulations, you are entitled to the following rights:

    1. Request the Data Controller to access your personal data;
    2. to request correction thereof;
    3. to request the update and deletion of your data if incomplete, incorrect, or collected in violation of the law;
    4. to request that the processing be limited to part of the information concerning you;
    5. to object to their processing for legitimate reasons (even in part).
    6. to revoke consent at any time without prejudice to the lawfulness of the processing based on consent given before the revocation;

    To exercise your rights, you may contact the Data Controller at the above contact details.

    We also remind you that, where the response to the requests cannot be considered satisfactory, the user has the right to contact and lodge a complaint with the Data Protection Authority (www.garanteprivacy.it) in the manner provided for by the Applicable Regulations.

This page was last updated on: 19/02/2024.