Who we are and what is the purpose of this Privacy Policy?

 

As the data controller, VERNICI SHABBY SRL (“we”, “our”) processes some personal data to allow you to use our e-commerce store located on our website and to use our products. This Privacy Policy describes our processing operations of personal data and provides you with information about your rights regarding your personal data.

This Privacy Policy applies to all websites managed under our domain (Vernicishabby.com), including our e-commerce store and related activities such as delivery organization and marketing operations. Please note that in some cases our websites may include links to third-party external websites that are not managed by us or covered by this Privacy Policy. To learn more about the processing operations of these third parties, we recommend that you review their privacy policies.

In addition, if you order our products through a third-party website (such as Amazon), such third parties may process your personal data for their purposes and act as data controllers. For more information on their data processing operations, please consult their applicable privacy policies.

If you want to learn more about what cookies and similar technologies we use, please kindly refer to our Cookie Policy.

 

What personal data do we process, for what purposes and on what legal bases?

Service provision

It is necessary for VERNICI SHABBY SRL to process your contact details, including name, phone number, email address, and delivery address data, as well as your payment and order data (such as payment method, product information, order date, and shipping method) in order to:

  • execute purchase agreements, including shipping, delivery, and payment processing;
  • respond to information requests, manage your account, and provide other customer services;
  • manage claims and process returns, complaints, and warranty requests;
  • provide non-promotional service communications related to technical, security, and contractual issues (such as fraud notifications, account blocking, or contractual changes);
  • provide additional services requested by you.

In addition, we may process your social security number or date of birth for credit check purposes, if necessary. The legal basis for the processing of this data for the listed purposes is – as per Art. 6(1)(b) GDPR – our Terms of Service.

 

Marketing

We also process your contact information, including email address and phone number, for marketing purposes. To the extent that the content of marketing communications is personalized, we may also process your order history (i.e., previously purchased products), as well as your interests as indicated by the cookies you have accepted (for more information, see the Cookie Policy). Marketing operations include:

  • sending newsletters, reminders, product updates, tips, promotional offers, and other promotional communications to your email address;
  • sending promotional messages via text messages and WhatsApp or Facebook Messenger applications;
  • targeting promotional content to you and third parties on social media platforms including Facebook, Instagram, and TikTok;
  • sending push notifications, including marketing communications.

The applicable legal basis for marketing communications and social media targeting is consent (Art. 6(1)(a) GDPR) or VERNICI SHABBY SRL’s legitimate interests in providing direct marketing (Art. 6(1)(f) GDPR). The applicable legal basis depends on whether you are an existing customer or a new customer, the approach we have chosen, and the content of the promotions. Please note that push notifications require your consent, which is also the legal basis for processing personal data collected to provide such notifications.

When you first sign up for our services, VERNICI SHABBY SRL wants to process your data for marketing communications and social media targeting operations to provide you with information about similar products or services in which you have shown interest. VERNICI SHABBY SRL gives you the opportunity to opt-out of our use of your personal data for marketing operations at the time of registration or at any time thereafter, through the unsubscribe links or by changing the marketing settings in your profile. In case we ask you to opt-in to our marketing operations or you do so later in your profile or through the functions of our website (e.g., to receive a notification when a product is back in stock), the legal basis for processing is your consent.

To enhance your experience, provide you with tailored communications and promotions, as well as to allow you to collect loyalty points and receive personalized discounts, we collect some information to assign you to a customer segment and create a customer profile. In addition to the personal data defined above, including your name and address information, the assigned segment and created profile are based on:

  • Your purchase history;
  • Your device and network information;
  • Your actions on our website and third-party websites, provided that you have accepted cookies;
  • Your interaction with our communications, including social media pages through pixels and custom URLs;
  • Your date of birth, if you have provided it.”

“The legitimate basis for creating these segments and profiles, as well as for their use to personalize services and marketing communications, is our legitimate interest in carrying out personalized marketing and your legitimate interest in receiving personalized discounts and recommendations based on your interests, in accordance with Art. 6(1)(f) GDPR.

 

Community

We hope you are satisfied with our products and welcome your feedback and suggestions for improvements or new products. To this end, we may manage a community of customers on Facebook. We process data relating to the group, including member activity and engagement within the group, in order, for example, to understand how you interact within the group, to see who the most active group members are, and to know which posts have the most engagement. The legal basis for processing such group information is our legitimate interest in accordance with Art. 6(1)(f) GDPR) to interact with our customers in order to create better products, and your legitimate interests in engaging with us and providing feedback.

We have created a referral program where you recommend us and our products to your friends. To do so, you can share your personal code with your friends or provide your friends’ contact data, who will be notified through the specified channel (e.g. via email). The legal basis for such processing is our legitimate interest in reaching out to potential new customers, your legitimate interest in sending recommendations to your friends, and your friends’ legitimate interest in receiving recommendations that may interest them. We will inform your friend of your recommendation and provide adequate information on our privacy practices in the first communication. In the event that your friend does not become a customer, we will not store their contact data. If you choose to share your code and your friend uses it or if you are the friend who uses the code, we will retain this information in your customer profile to provide you with discounts or other benefits associated with code use.

 

Other Purposes

We may also use the categories of personal data listed above, as well as data that may be defined as personal data, collected by our essential cookies, for the following purposes:

  • maintaining the security of our website and services, including the prevention of data breaches;
  • preventing fraud;
  • research and development of our website and services, provided that the data is in summarized, pseudonymized, or anonymous form;
  • compliance with laws or court orders (e.g. to conduct applicable checks against money laundering or to know your customer);
  • establishment, exercise, or defense of legal claims.

For these operations, we rely on our legitimate interests to identify and prevent fraud, maintain the security of our services and improve them, as well as to pursue or defend legal claims in accordance with Art. 6(1)(f) GDPR. Where we need to process your personal data to comply with legal obligations, such as applicable laws and regulations or court orders, the applicable legal basis for processing is the legal obligation under Art. 6(1)(c) GDPR.

Where do we obtain your personal data from and with whom do we share it?

In general, we process personal data that is provided directly by you or that arises from your use of our services. Our business operations also require the use of service providers who assist us in the provision of our services and products and who may, under appropriate agreements and security measures, disclose your personal data to us or with whom we may share your personal data. Such service providers may include:

  • E-commerce platforms;
  • Payment service providers;
  • Credit checking agencies;
  • Customer service and relationship management platforms;
  • Customer support services (e.g. chat providers);
  • Marketing platforms and services, including social media platforms and conversion tracking services;
  • Delivery companies;
  • Collection service providers;
  • Loyalty, reward, and referral program providers;
  • Companies that are part of our group;
  • Third parties in connection with a commercial transaction (e.g. a merger or acquisition or liquidation).

In addition, in the event that we are required by law or by court order to disclose your personal data or if we need to do so to establish, exercise, or defend legal claims, we may transmit your data to the judicial authorities or other interested third parties.

 

Do third parties act as joint controllers?

If personal data from events is processed via Facebook’s social plugins, pixels, or Software Development Kits (SDKs) during the use of Facebook Business Tools services by VERNICI SHABBY SRL, Facebook Ireland acts as a joint controller. This also applies to the processing of personal data in events for Facebook Page Insights, the aggregation of such events, and the provision of such information to Facebook page administrators. For more information on how Facebook processes your personal data, including the legal bases for such processing, and on how you can exercise your rights, please refer to the applicable privacy policy.

 

Where are your personal data processed?

VERNICI SHABBY SRL is a European company located in an EU/EEA country. However, we may transfer your personal data to other countries within the EU/EEA and to third countries. When personal data is transferred to third countries that are not covered by an adequacy decision, relevant, we ensure that a relevant transfer mechanism (such as standard contractual clauses) and any additional technical and organizational security measures required are in place.

 

How are your personal data protected?

VERNICI SHABBY SRL has implemented comprehensive technical and organizational security measures to ensure the security of your personal data. These are regularly reviewed and updated to ensure they are in line with the state of the art. We also examine our suppliers and sign appropriate agreements with them to ensure they comply with our defined security measures.

 

When will we delete your data?

Your personal data is only kept for the time necessary for the purposes defined in this privacy policy. Please note that we deactivate your account and delete relevant data after three (3) years from the end of the year in which you made the last purchase. We will inform you before doing so. We may, however, retain some personal data to comply with our legal obligations, such as providing product warranty or retaining financial documentation.

 

What are your rights regarding our data processing operations and how to contact us?

In addition to your right to receive information in the form of this privacy policy, you have the following rights under the relevant legal conditions:

  • right of access to your data;
  • right to rectify your incorrect or incomplete data;
  • right to erasure (deletion of data/anonymization);
  • right to restrict processing;
  • right to data portability;
  • right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly affects you; and
  • right to lodge a complaint with a supervisory authority, and our main supervisory authority is?

In addition, in case we process your personal data based on legitimate interests, you have the right to object to this processing with effect for the future. If you exercise your right to object, we will stop processing the data in question. However, further processing may occur on Relevant, we ensure that a relevant transfer mechanism (such as standard contractual clauses) and any additional required technical and organizational security measures are in place.

 

How are your personal data protected?

VERNICI SHABBY SRL has implemented comprehensive technical and organizational security measures to ensure the security of your personal data. These are regularly reviewed and updated to ensure compliance with state-of-the-art standards. We also review our suppliers and sign appropriate agreements with them to ensure they comply with our defined security measures.

 

When will your data be deleted?

Your personal data is only stored for the time necessary for the purposes defined in this policy. Please note that we deactivate your account and delete relevant data after three (3) years from the end of the year in which you made your last purchase. We will inform you before doing so. However, we may still retain some personal data to comply with our legal obligations, for example, to provide product warranties or to retain financial documentation.

 

What are your rights in relation to our data processing operations and how can you contact us?

In addition to your right to receive information in the form of this privacy policy, you have the following rights under the relevant legal conditions:

  • right of access to your data;
  • right to rectify your inaccurate or incomplete data;
  • right to erasure (data deletion/anonymization);
  • right to restrict processing;
  • right to data portability;
  • right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly affects you; and
  • right to lodge a complaint with a supervisory authority, and our main supervisory authority is?

Furthermore, if we process your personal data based on legitimate interests, you have the right to object to this processing with effect for the future. If you exercise your right to object, we will stop processing the relevant data. However, further processing may occur under the condition that we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms or if the processing is for certification, exercise or defense of legal rights. If we process your personal data for direct marketing purposes, you have the right to object to such processing at any time, and we will stop processing your personal data for direct marketing purposes.

 

Please note that we do not sell your personal data. However, in the case of a commercial transaction, your personal data may be transferred to a new controlling entity.

To exercise your rights, use our data request tool or email us. VERNICI SHABBY SRL has appointed a Data Protection Officer (DPO) who monitors our privacy compliance officers and can answer any further questions you may have regarding our data processing operations. You can send your questions via email to support@vernicishabby.com.

You can also reach us by mail:

Vernici Shabby srl

Attention: Data Protection Officer

Via Legni Rossi, 2

60037 Monte San Vito (AN) – Italy

Please note that, as an e-commerce operator, we process your data in electronic format and therefore, upon request for access to your personal data, we provide such data in a commonly used format for automatic reading (e.g., PDF).

 

Who is our Data Protection Officer?

Sascha Kremer

c/o KREMER RECHTSANWÄLTE

Brückenstraße 21

D-50667 Cologne

Germany

 

 

When was this Privacy Policy last reviewed?”

This privacy policy was last reviewed and updated in 11/2022. In case of material changes to this privacy policy, we will inform you via the email address you provided.