Privacy Policy

For the purposes of this document, "Privacy Policy" shall mean:

Personal Data (or Data): any information that, directly or indirectly, or in connection with other information, including a personal identification number, allows for the identification or identifiability of a natural person.

Usage Data: information collected automatically through this Website (or third-party applications integrated into this Website), including: IP addresses or domain names of the computers utilized by the User who connects to this Website, URI (Uniform Resource Identifier) addresses, the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's response (successful, error, etc.), the country of origin, the features of the browser and operating system utilized by the visitor, the various temporal details per visit (e.g., the time spent on each page), and the details of the path followed within the Application, with particular reference to the sequence of pages visited, other parameters relating to the operating system and the User's IT environment.

User: the individual who uses this Website who, unless otherwise specified, coincides with the Data Subject.

Data Subject: The natural person to whom the Personal Data refers.

Data Processor (or Processor): The natural person, legal person, public administration, or any other entity that processes Personal Data on behalf of the Data Controller, as described in this privacy policy.

Data Controller (or Owner): The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data and the means used, including the security measures concerning the operation and use of this Website. The Data Controller, unless otherwise specified, is the Owner of this Website.

This Website and/or site and/or Application: The hardware or software tool by which the Personal Data of Users is collected and processed.

Contacting the User

Mailing list or newsletter: personal data (last name; email address; first name; telephone number)

Contact form: personal data (postal code; city; last name; date of birth; Usage Data; email address; User ID; physical address; country; first name; telephone number; province; gender; various types of Data)

Payment processing

PayPal: personal data (email address)

 

Registration and authentication provided directly by this Website

Direct registration: Personal Data (postal code; city; last name; date of birth; Usage Data; email address; User ID; language; country; first name; street number; telephone number; password; province; gender; username)

Platform and hosting services

Shopify: Personal Data (last name; email address; first name; telephone number)

Contact information:

The Data Controller Data is THE BLONDIT SRL with registered office in Largo Palizze n. 1, 67039 Sulmona (AQ), Italy, VAT number 02206190668, Company Register registration no. AQ-217032 e-mail info@theblondit.com, PEC theblonditsrl@pec.it.

Types of Data Collected

Among the Personal Data collected by this Website, either independently or through third parties, there are: email address; first name; last name; phone number; Usage Data; gender; date of birth; username; password; country; province; ZIP/Postal code; city; User ID; house number; language; physical address; various types of Data.

Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed before the Data are collected.

Personal Data may be freely provided by the User, or, in the case of Usage Data, collected automatically when using this Website.

Unless otherwise specified, all Data requested by this Website is mandatory. Failure to provide this Data may make it impossible for this Website to provide its Services. In cases where this Website specifically states that some Data is mandatory, Users are free not to provide this Data without any consequences on the availability or functioning of the Service.

Users who are unsure about which data is mandatory are encouraged to contact the Owner.

Any use of Cookies - or other tracking tools - by this Website or by the owners of third-party services used by this Website is intended to provide the Service requested by the User, in addition to any other purposes described in this document and in the Cookie Policy.

The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Website.

Method and place of processing of collected data

Methods of processing

The Data Controller takes appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.

Processing is carried out using computer and/or IT tools, following organizational methods and modes strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other parties involved in the operation of this website (administrative, sales, marketing, legal, and system administration personnel) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, and communications agencies) may have access to the Data, also appointed, if necessary, as Data Processors by the Data Controller. The updated list of Data Processors may be requested from the Data Controller at any time.

Location

The Data is processed at the Data Controller's operating offices and in any other places where the parties involved in the processing are located. For further information, please contact the Data Controller.

The User's Personal Data may be transferred to a country other than their own. To obtain further information on the place of processing, the User can refer to the section containing details on the processing of Personal Data.

Retention Period

Unless otherwise indicated in this document, Personal Data is processed and stored for the time required for the purpose for which it was collected and may be retained for a longer period due to any legal obligations or based on the User's consent.

Purposes of Processing Collected Data

The User's Data is collected to allow the Owner to provide its Service, comply with legal obligations, respond to requests or enforcement actions, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as for the following purposes: Handling payments, Platform services and hosting, Contacting the User, and Registration and authentication provided directly by this Website.

For detailed information on the purposes of processing and on the Personal Data processed for each purpose, the User may refer to the "Detailed information on the processing of Personal Data" section.

Detailed information on the processing of Personal Data

Personal Data is collected for the following purposes and using the following services:

Contacting the User

Mailing list or newsletter (this Website): By registering for the mailing list or newsletter, the User's email address will automatically be added to a contact list to which email messages containing information, including commercial and promotional information, relating to this Website may be sent. The User's email address may also be added to this list as a result of registering on this Website or after making a purchase.

Personal Data processed: last name; email address; first name; phone number.

Contact form (this Website): By filling out the contact form with their Data, the User consents to their use of this Data to respond to requests for information, quotes, or any other kind of request as indicated by the form's header.

Personal Data processed: ZIP/Postal code; city; last name; date of birth; Usage Data; email address; User ID; physical address; country; first name; phone number; province; gender; various types of Data.

Payment Processing

Unless otherwise specified, this Website processes all payments by credit card, bank transfer, or other means through external payment service providers. Generally, and unless otherwise specified, Users are requested to provide their payment details and personal information directly to these payment service providers.

This Website is not involved in the collection and processing of such information; instead, it will only receive notification from the relevant payment service provider that payment has been successfully completed.

PayPal (PayPal): PayPal is a payment service provided by PayPal Inc., which allows Users to make online payments.

Personal Data processed: email.

Place of processing: See the PayPal privacy policy.

Registration and authentication provided directly by this Website

By registering or authenticating, the User allows this Website to identify them and provide them with access to dedicated services. Personal Data is collected and stored solely for registration or identification purposes. The Data collected is only that necessary to provide the service requested by the User.

Direct registration (this Website)

The User registers by completing the registration form and providing their Personal Data directly to this Website.

Personal Data processed: ZIP code; city; last name; date of birth; Usage Data; email address; User ID; language; country; first name; house number; phone number; password; province; gender; username.

Platform and hosting services

These services are intended to host and operate key components of this Website, enabling the provision of this Website from a single platform. These platforms provide the Owner with a wide range of tools, such as analytics, user registration management, comment and database management, e-commerce, payment processing, etc. The use of these tools involves the collection and processing of Personal Data.

Some of these services operate through geographically distributed servers in different locations, making it difficult to determine the exact location where the Personal Data is stored.

Shopify (Shopify Inc.)

Shopify is a platform provided by Shopify Inc., Shopify Commerce Singapore Pte. Ltd, or Shopify International Limited, depending on how the Owner manages the Data processing, which allows the Owner to develop, operate, and host an e-commerce website.

Personal Data processed: last name; email address; first name; phone number.

Place of processing: Headquarters Shopify

Further information for users

Legal basis for processing

The Data Controller processes Personal Data relating to the User if one of the following applies:

The User has given consent for one or more specific purposes.

 Processing is necessary for the performance of a contract with the User and/or for any pre-contractual obligations thereof;

Processing is necessary for compliance with a legal obligation to which the Data Controller is subject;

Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;

Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.

In any case, the Data Controller may always be asked to clarify the specific legal basis for each processing operation, and in particular whether the processing is a statutory requirement, a contractual requirement, or a requirement necessary to enter into a contract.

Further information on retention periods

Unless otherwise stated in this document, Personal Data is processed and retained for the time required by the purpose for which it was collected and may be retained for a longer period due to any legal obligations or based on the User's consent.

Therefore:

Personal Data collected for purposes related to the performance of a contract between the Owner and the User will be retained until such contract has been fully performed.

Personal Data collected for purposes related to the Owner's legitimate interests will be retained until such interests are fulfilled. Users may obtain further information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.

When processing is based on the User's consent, the Owner may retain Personal Data for a longer period until such consent is withdrawn. Furthermore, the Data Controller may be required to retain Personal Data for a longer period to fulfill a legal obligation or an order of an authority.

At the end of the retention period, Personal Data will be deleted. Therefore, upon expiration of this period, the right to access, erasure, rectification, and the right to data portability can no longer be exercised.

User Rights under the General Data Protection Regulation (GDPR)

Users may exercise certain rights regarding their Data processed by the Data Controller. In particular, within the limits established by law, the User has the right to:

withdraw consent at any time. The User may withdraw previously given consent to the processing of their Personal Data.

object to the processing of their Data. The User may object to the processing of their Data when it occurs pursuant to a legal basis other than consent.

access their Data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing, and to receive a copy of the Data processed.

verify and request rectification. The User can verify the accuracy of their Data and request its updating or correction.

obtain restriction of processing. The User may request the restriction of the processing of their Data. In this case, the Data Controller will not process the Data for any purpose other than its storage.

Obtain the deletion or removal of their Personal Data. The User may request the deletion of their Data from the Data Controller.

Receive their Data or have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transferred to another controller without hindrance.

File a complaint. The User may file a complaint with the competent data protection supervisory authority or take legal action.

Users have the right to obtain information regarding the legal basis for Data transfers abroad, including to any international organization governed by international law or set up by two or more countries, such as the UN, as well as regarding the security measures taken by the Data Controller to protect their Data.

Details on the right to object

When Personal Data is processed in the public interest, in the exercise of official authority vested in the Data Controller, or for the purposes of the legitimate interests pursued by the Data Controller, Users have the right to object to such processing for reasons related to their particular situation.

Users are informed that, if their Data is processed for direct marketing purposes, they can object to that processing at any time, free of charge and without providing any justification. If Users object to processing for direct marketing purposes, the Personal Data will no longer be processed for such purposes. To learn whether the Data Controller is processing Data for direct marketing purposes, Users can refer to the relevant sections of this document.

How to exercise your rights

Any requests to exercise your rights may be directed to the Data Controller using the contact details provided in this document. The request is free of charge, and the Data Controller will respond as quickly as possible, in any case within one month, providing the User with all the information required by law. Any rectifications, erasures, or limitations on processing will be communicated by the Data Controller to each recipient, if any, to whom the Personal Data has been disclosed, unless this proves impossible or involves a disproportionate effort. The Data Controller will inform the User of these recipients upon request.

Further information on data processing

Legal defense

The User's Personal Data may be used by the Data Controller in court or in the preparatory stages leading to possible legal action arising from improper use of this Website or related Services by the User.

The User declares to be aware that the Data Controller may be required to disclose personal data by order of public authorities.

Specific information

Upon the User's request, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services or the collection and processing of Personal Data.

System logs and maintenance

For operation and maintenance purposes, this Website and any third-party services used by it may collect system logs, which are files that record interactions and may also contain Personal Data, such as the User's IP address.

Information not contained in this policy

Further information regarding the processing of Personal Data may be requested from the Data Controller at any time using the contact information.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Website and, if technically and legally feasible, by sending a notification to Users via any contact information available to the Data Controller. Please check this page frequently, referring to the date of the last modification indicated at the bottom.

If the changes affect processing based on consent, the Data Controller will collect the User's consent again, if necessary.