PRIVACY STATEMENT CONCERNING THE PROCESSING OF PERSONAL DATA
Having regard to art. 13 of the General Data Protection Regulation (EU) 2016/679 (also called GDPR) and with reference to your personal data, the company Auchan S.p.A. shall process your personal data according to principles of correctness, lawfulness and transparency and also with the aim of protecting your confidentiality and rights. With regard to this, we inform you of the following.
- Identity and contact details of the Data Controller
The Data Controller is Auchan S.p.A., with registered offices in Palazzo N, Strada 8, 20089, Rozzano, (MI), hereinafter the “Controller”. Its contact details are as follows: email@example.com, or the address Palazzo N, Strada 8, 20089, Rozzano, (MI).
- Contact details of the Processor
The Controller has appointed a Processor who you may contact if you have any questions regarding the processing of your personal data and the exercise of your rights deriving from the GDPR. You may contact the Processor by sending an e-mail to firstname.lastname@example.org or a letter to the address Palazzo N, Strada 8, 20089, Rozzano, (MI).
- Purpose and legal basis of the processing
Your personal data, collected when you register on our sites belonging to the domain auchan.it, (the “Sites” or individually the “Site”, we specify that this privacy statement should not be considered valid for other web sites which may be consulted via links present on the Sites and that therefore the Controller cannot be considered in any way responsible for the internet sites of third parties) or when you make on-line purchases on the Sites, will be processed for the following purposes:
- management of the procedure for registering on the Sites and filling in data collection forms available on the Sites to ask for information, file complaints and contact the Controller, and management of complaints, and requests; (Legal basis of the processing: Performance of the contract);
- to allow you to make on-line purchases, regarding specified products and according to the procedures indicated in the sale conditions and to allow the fulfilment of all legal and contractual obligations connected to such purchases and to purchases in general, also of services, including therein home delivery and/or pick-up by you from the agreed point of sale; Performance of the contract)
- sending - by e-mail, postal service, social network, sms, app, and , in any case, via the means of communication expressly indicated - newsletters, offers, promotions, discounts, concessions, commercial or promotional information, free gifts, invitations to exhibitions or events, notification of special events regarding products bearing the Controller’s own Brands and/or the Brands of third parties ; (Legal basis of the processing: processing based only after obtaining Your Consent);
- profiling, by reading and analysing purchasing behaviour, using data referring to your shopping, for the purpose of improving the commercial offer and making specific product promotions and commercial offers which satisfy your profile and needs as much as possible, also through market surveys and research; the profiling will be carried out through computer programs specifically developed for the collection and analysis of information for this purpose: (Legal basis of the processing: processing based only after obtaining Your Consent);
- for sending, exclusively to the e-mail address you provided when purchasing a product or a service from the Sites, promotional messages concerning goods or services similar to those you have purchased, as long as you do no object to the processing with the procedures indicated below, according to that specified by art. 130, paragraph 4, of Law Decree 196/2003 (so-called. soft spamming) and subsequent amendments and integrations (Legal basis of the processing: Legitimate interest);
- browsing on the Sites (Legal basis of the processing: legitimate interest).
- Legal basis of processing and legitimate interest
The legal basis for processing personal data referring to each of the purposes indicated above, is specified at the side of each of them. When consent is indicated as the legal basis of processing, it is understood that the Controller will process the data for such purposes only after having obtained your consent to do so. As far as the indicated legitimate interests are concerned, these refer to the fact that the party concerned has already shown interest in the commodity sector concerned, purchasing specific products or services, and the Controller has a specific and justified interest in continuing to send the data subject communications referring to services or goods similar to those purchased and also the interest of the Controller in encouraging the user to browse.
- Option or obligation to provide the data and consequences of failing to provide them
Providing personal data, for all purposes, is not obligatory. However you must do so in order to register and shop on the Sites. If you do not provide the data you will not be able to make such purchases but will be able to personally visit the nearest Auchan point of sale.
- Recipients or categories of recipients of personal data
Personal data relating to the processing in question, for the purposes mentioned above, may be communicated or made known:
- to those within the Controller’s organisation, including companies of the business group located within the European Union, who need to do so because of their job or hierarchical position. Such subjects are persons authorised to process under the direct authority of the Controller (hereinafter “authorised persons”). The number of such persons shall be limited as much as possible, in relation to their job, and they shall only have access to data pertinent to such a job, i.e. excluding the fact that all the Controller’s authorised persons may have free access to all your data, and they shall be appropriately instructed on how to avoid losses, destruction, unauthorised accesses or processing of such data which is not allowed;
- to Companies belonging to our corporate Group (parent, affiliated or subsidiary companies pursuant to article 2359 of the Italian civil code or companies subject to common control and subjects belonging to consortia, networks of undertakings and temporary groups and associations of undertakings. Given our international nature, such companies may also be located overseas, but within the European Union) and are authorised to process the data for internal administrative purposes;
- to those subjects who, by law, have the right of access, i.e. for whom transfer of the data is necessary in order to fulfil legal or regulatory obligations,
- to subjects whose activity is necessary for the performance of contracts who are part of or for fulfilling requests before conclusion of the contract (e.g.: Transporters, Suppliers of goods and services and Sub-suppliers both national and foreign within the EU, Companies and institutes in the banking, credit and insurance sectors, factoring Companies, financial Intermediaries, Companies providing commercial information, Companies delivering correspondence;
- to third parties to whom the Controller may outsource certain activities and who, consequently, provide certain instrumental services to the writer, co-related to the processing and to the purposes described above, such as, for example, administrative, accounting, fiscal, auditing, services, IT systems management, collection of credit, large-scale filing, call centre services. Such third parties carry out processing on behalf of the Controller and are authorised to process data in the capacity of Processor pursuant to art 28 of the GDPR.
- Period of conservation
The Controller shall keep personal registration data and accounting data referring to purchases for 10 years from the last utilisation. Purchasing data shall be kept for 24 months for marketing and profiling purposes.
- Your rights
The GDPR recognises the following rights referring to your personal data which may be exercised within the limits and in compliance with that laid down by the regulation:
- Right of access to your personal data (art. 15);
- Right to rectification (art. 16);
- Right to erasure (right to be forgotten) (art. 17);
- Right to restriction of processing (art. 18);
- Right to data portability (art. 20);
- Right to object (art. 21); You may object to the processing of Data for the purposes mentioned in point 5) on the auchan.it web site:
- by accessing your own "Reserved Area";
- by selecting the link provided on every e-mail (Newsletter) sent by Auchan S.p.A.;
- through our "Customers Assistance Service”
and will make it impossible for the Controller to send you communications to promote the direct sale of products or services similar to the ones you previously purchased on the Sites (so-called soft spamming).
- Right to object to a decision based solely on automated processing, (art. 22);
- The right, at any time, to withdraw issued consent, without prejudicing the lawfulness of processing based on consent given prior to withdrawal; you main obtain this by sending a written request addressed to the processing Controller to the postal address or by e-mail, as indicated in point A above.
- The right to contact the Processor for all matters relating to the processing of your personal data and exercise of rights deriving from the European Regulation. The Processor can be contacted as indicated in point B above;
trattamento dei suoi dati personali e all’esercizio dei diritti derivanti dal Regolamento Europeo. Il DPO può essere contattato come indicato nel precedente punto B;
- the right to make complaints to the Supervisory Authority if you believe that your data have been processed in breach of applicable legislation. (garanteprivacy.it).