Skip to content

PRIVACY NOTICE UNDER ARTICLES 13-14 OF THE GDPR (GENERAL DATA PROTECTION REGULATION) 2016/679

Cosmofarma srl, VAT number 01491300479, Data Controller, informs you that your data will be processed in the manner and for the purposes set out below.

The Data Controller is committed to protecting the privacy and confidentiality of Personal Data in accordance with the principles of fairness, lawfulness, transparency, and the protection of your rights.

1) TYPE OF DATA PROCESSED

We process personal data provided by you (name, email, company name, phone number, etc.) in response to requests made voluntarily, and data collected automatically by the website.

  • Data provided by you: personal, identifying, and non-sensitive data provided by you for making requests via email, through the contact form, or by phone regarding our products/services.
  • Data we collect automatically: anonymous data collected using cookies or similar technologies: for more information, please see the Cookie Policy below.

Note: Users under 16 years of age may not provide any personal data without the consent of parents or guardians.

 

2) PURPOSES AND LEGAL BASIS FOR THE PROCESSING

We will process your personal data:

A) to fulfill our contractual obligations; respond to your requests for information; prepare a quote you requested; execute contracts for the sale of products or services; provide you with the necessary assistance regarding the products and services purchased.

B) to perform anonymous aggregated statistical analysis to improve our services;

C) for administrative purposes and to fulfill legal obligations, such as accounting, tax obligations, or to comply with requests from judicial authorities.

D) in the case of sending a curriculum vitae, exclusively for recruitment purposes.

 

3) IS PROVIDING DATA MANDATORY?

Providing your data is always optional, but failure to do so may make it impossible to process certain requests, such as those strictly related to fulfilling a contract or providing the services you requested.

4) LOCATION, PROCESSING METHODS, AND RETENTION PERIOD

The processing of your personal data is carried out through the operations specified in Article 4 of the Privacy Code and Article 4, paragraph 2) of the GDPR, specifically: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, deletion, and destruction of data.

Your personal data is stored at the Data Controller’s premises and processed both manually and electronically and/or automatically, with methods strictly related to the purposes indicated and in a way that ensures data security and confidentiality. The data you provide is not saved within our website.

The Data Controller will process the personal data for the time necessary to fulfill the above purposes and, in any case, for no longer than 10 years from the termination of the relationship for purposes under point C, and no longer than 38 months from data collection for purposes under point B.

5) ACCESS TO DATA

Your data may be made accessible for the purposes indicated in point 2:

  • to employees and collaborators of the Data Controller, in their capacity as internal data processors and/or system administrators;
  • to third-party companies or other entities (website provider, cloud provider, e-payment service provider, suppliers, technical support for hardware and software, couriers and carriers, banks, law firms, etc.) performing outsourced activities on behalf of the Data Controller, in their capacity as data processors.

 

6) DATA TRANSFER

Your data will not be disclosed, sold, or exchanged with parties other than the Data Controller, processors, and appointed personnel without your explicit and express consent.

7) YOUR RIGHTS

You have the right to know what personal data is being processed. In particular, you have the right to access, rectify, delete your data, the right to data portability, the right to restrict processing, and the right to object to processing, where applicable.

Below is a brief description of the rights recognized to you in relation to the processing of your personal data:

  • Right of access allows you to obtain confirmation as to whether or not your personal data is being processed by the Data Controller and, if so, access to such data and related information;
  • Right of rectification allows you to obtain the correction of inaccurate personal data concerning you without undue delay and, taking into account the purposes of the processing, to obtain the completion of incomplete personal data;
  • Right to deletion allows you to obtain the deletion of personal data without undue delay (e.g., when the data is no longer necessary for the purposes for which it was collected), subject to the exceptions provided by applicable law (e.g., when the retention of your data is necessary for compliance with legal obligations applicable to the Data Controller). Deletion will be carried out within the technical time limits;
  • Right to data portability allows you, in certain circumstances provided by applicable law, to receive your personal data in a structured, commonly used, and machine-readable format. You may transmit this data to another data controller, as long as such a right is recognized to you under applicable law, provided that it does not harm the rights and freedoms of others;
  • Right to restrict processing allows you, in certain circumstances provided by applicable law, to obtain the restriction of processing of your personal data. In such cases, the Data Controller may continue to process your data only in certain situations, such as for the exercise of legal claims or to protect the rights of another individual or legal entity;
  • Right to object to processing allows you, in certain circumstances provided by applicable law, to object to the processing of your personal data unless there are overriding legitimate grounds, rights, or freedoms that allow the Data Controller to continue processing;

For more information about the processing of your personal data or to exercise your rights, we invite you to contact us.

 

8) CHANGES TO THE NOTICE

This Privacy Notice may undergo changes. Therefore, it is advisable to regularly check this Notice and refer to the most recent version.

Last update: March 2025

 

Back To Top
0
    0
    Il Tuo Carrello
    Il tuo carrello è vuotoTorna allo shop