This Privacy Policy has been drawn up pursuant to Article 13 of European Regulation no. 679/2016 and applies exclusively to all data collected through the website
www.goovi.com/it. This Privacy Policy is subject to updates that will be published on the website on a timely basis. This Privacy Policy and the
Cookie Policy set out the basis upon which the personal data of the data subject will be processed.
Data controller
The data controller of the data collected from this website is The Good Vibes Company S.r.l., with registered office in Viale Italia, 60 Lainate (MI) - 20045, Italy. The data controller may also be contacted by email:
privacypolicy@sodalisgroup.com
Data Protection Officer (DPO)
In compliance with the provisions of the Regulation, the data controller has appointed a Data Protection Officer (DPO) in accordance with Articles 37-39 of the GDPR, whose task it is to ensure compliance with the Regulation and to act as a point of contact for data subjects, as well as for the Data Protection Authority. The DPO, Mr. Stefano Modena, can be contacted by email: stefano.modena@assiteca.it
Web platform
The website is built with platforms designed to host and operate key components of the website. These platforms may provide analytical tools, as well as tools for managing user registrations, comments databases, in addition to e-commerce and payment processing functions and so on. The use of such tools requires the collection and processing of personal data.
Some of these services operate through servers in different geographical locations, making it difficult to determine the exact location where the personal data are stored.
Personal data processed
The term personal data refers to any information concerning an identified or identifiable natural person (the data subject). An identifiable person is a natural person who can be identified - either directly or indirectly - with reference to a specific identifier such as a name, an identification number, location data, an online identifier, or one or more features of their physical identity.
Category of personal data processed
The personal data processed by this website - either independently or through third parties - include common data such as:
- Biographical data (such as name, surname, date of birth, age, gender, etc.);
- Contact data (email, address, telephone number);
- Geo-localisation data (including "IP" addresses);
- Internet browsing data (including data deriving from the use of social media icons and social media login buttons - e.g. Facebook, Instagram, TikTok, etc. -) collected via cookies installed on your computer or mobile device (for more information, see the Cookie Policy);
- Banking data such as information regarding payment methods or credit card details;
- Data regarding the domicile/residence of the data subject, as well as shipping data, billing address etc.;
- Login and account information, including user name, password and unique user ID;
- Personal data including purchase history;
- Data relating to the data subject's interactions with the data controller's websites, including but not limited to data relating to participation in questionnaires, initiatives, contests, promotions, events (including through our social media channels);
- If a request is sent through the "Contact" section of the website, the provision of certain personal data is necessary in order for the data controller to be able to fulfil the request, and the relevant fields of the registration form are therefore marked as mandatory;
- In addition to the aforementioned categories of personal data, further data directly provided by the data subject may be also be processed (the so-called "Contributions") and shared on social media pages, such as likes, comments, pictures and in general any content and information that the data subject may have posted on the data controller's social media pages;
- Cookies and usage data;
- Personal preferences including the wish list, marketing and cookie preferences.
Personal data processing methods
The personal data provided or acquired will be processed in accordance with the principles of correctness, lawfulness, transparency and protection of confidentiality, pursuant to the laws in force. When processing the personal data of the users, the data controller takes all appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of the personal data. The data processing is carried out using computer-based and/or telematic tools, using organisational methods and approaches that are strictly related to the purposes indicated.
Purpose of the processing of the personal data and legal basis
Personal data may be collected autonomously by the data controller through third parties. In this instance, the computer systems and software procedures used in operating this website acquire certain elements of personal data pertaining to the users; this data is of a technical-IT nature (e.g. IP address, type of browser used, operating system, domain name and addresses of websites from which the website was accessed/left etc.), and its transmission is inherent to the normal operation of the internet. These data may be processed for the sole purpose of obtaining anonymous statistical information on the use of the site and/or to check that it is working correctly, and are deleted immediately after processing.
The data that the data subject chooses to provide voluntarily will be processed in compliance with the conditions of lawfulness
pursuant to Article 6 of the GDPR, and will be processed in order to allow the website to provide its services, as well as for the purposes set out below, and will be kept for as long as necessary for the fulfilment of those purposes. More specifically, the purposes of the processing are as follows:
1) To respond to requests and provide information
The data will be processed with a view to re-contacting the data subject or following up on specific requests made to the data controller by the data subject for communications that relate to the services and/or content provided by the data controller, either via email or via other communication tools such as including telephone contact or WhatsApp Business instant messaging.
Legal basis: this processing is optional and is based upon the consent of the data subject; however, the provision of the data is necessary in order to achieve the stated purpose.
Data retention period: until consent is revoked by the data subject.
2) Registration on the website
Through the creation of a user account or the use of an existing social media account, the registration procedure is designed to enable the use of the website as a "Registered User" and provide access to a series of services offered through the same applications. The data will be processed in order to be registered on the data controller's site for the purchase of the controller's products.
Legal basis: The legal basis for the processing of the data is to carry out pre-contractual measures to which the data subject is party, as well as the consent of the data subject; the latter may always change his or her mind, but the provision of the data is necessary in order to achieve the stated purpose.
Data retention period: until consent is revoked by the data subject.
3) Processing required in the context of a contract
The data shall be processed in order to fulfil the obligations that arise form the contract entered into between the data subject and the data controller for the sale of the products on the website, in order to contact the data subject in relation to the contract and for the management thereof, for the management of requests for legal guarantees, assistance, requests for withdrawal, management and termination of the contract.
Legal basis: this processing is necessary for the fulfilment of the contract to which the data subject is party, for the execution of pre-contractual measures or in order to comply with a legal obligation to which the data controller is subject.
Data retention period: period specified by law and in any case, a maximum period of 10 years, for the purpose of fulfilling related administrative and tax obligations.
4) Fulfilment of any obligations stipulated by applicable laws
The Data will be processed to fulfil any type of obligation provided for under current laws, regulations, related rules, business practices and tax/fiscal measures, including for the purposes provided for by the Italian anti-money laundering legislative decree no. 231/2007 and subsequent amendments.
Legal basis: this processing is necessary to comply with a legal obligation to which the data controller is subject.
Data retention period: period specified by law and in any case, a maximum period of 10 years, for the purpose of fulfilling related administrative and tax obligations.
5) Soft spam
The data will be processed in order to allow the data controller to send the data subject commercial and promotional communications via email concerning products similar to those being sold, without the need for the express and prior consent of the data subject, as provided for by Article 130, paragraph 4 of the Privacy Code as amended by Legislative Decree No. 101 of 2018, and provided that the data subject does not exercise their right to object.
Legal basis: this processing is based on the legitimate interest of the data controller, pursuant to Art. 6, point. F and in light of no. 47 of the GDPR.
Data retention period: until the data subject objects.
6) Marketing
The data will be processed for the direct sale of products, and for market research, sending of communications and promotional, commercial and advertising material or information regarding initiatives and events, via email, Newsletter, SMS, WhatsApp, Chat, Facebook Forms, social media networks or via phone calls, paper mail and other informative material.
Legal basis: this processing is based on the consent freely provided by the data subject, pursuant to Art. 6, para. 1, point A of the GDPR.
Data retention period: until consent is revoked by the data subject.
7) Statistical
The data will be processed in order to carry out statistical analysis on aggregated and anonymous data, in order to analyse the behaviour of the data subject with a view to improving the products and services provided by the data controller and meet the expectations of the data subjects.
Legal basis: this processing is based on the consent freely provided by the data subject.
Data retention period: until consent is revoked by the data subject.
8) Profiling
The data will be processed for the analysis and evaluation of the interests, habits and consumption choices of the data subjects, including the creation of profiles in order to be able to send personalised information and promotional material on the products offered by the data controller.
Legal basis: this processing is based on the consent freely provided by the data subject, pursuant to Art. 6, para. 1, point A of the GDPR.
Data retention period: until consent is revoked by the data subject.
9) Adding to wishlist
The data shall be processed in order to fulfill specific requests made by the data subjects to the data controller to be included on the waiting lists for out-of-stock products, and to be contacted when the product of interest becomes available again.
Legal basis: this processing is optional and is based upon the consent of the data subject; however, the provision of the data is necessary in order to achieve the stated purpose.
Data retention period: until consent is revoked by the data subject.
10) Customer reviews
The data will be processed for the purpose of publishing reviews on the provider's services, in order to share experiences on the purchased services (not for marketing purposes).
Legal basis: this processing is based on the legitimate interest of the data controller, pursuant to Art. 6, point. F and in light of no. 47 of the GDPR.
Data retention period: until the data subject objects.
Communication of data
In addition to the controller, in some cases, the following parties may have access to the data:
a) categories of specially-trained employees involved in the organisation of the website (administrative, sales, marketing and legal staff as well as system administrators);
b) external parties (such as third-party technical service providers, hosting providers, IT companies, communication agencies) who are also appointed as data processors by the data controller. pursuant to Article 28 of the GDPR. The updated list of data processors, where appointed, can always be requested from the data controller;
c) public or private entities that can access the data in compliance with the relevant legal obligations;
d) subjects that perform ancillary and instrumental tasks with respect to the data controller's activity.
Processing times
As expressly provided for under Article 5, paragraph 1, section e) of the GDPR, the data are kept for the time necessary for the processing thereof, in connection with the performance of the service requested by the data subject, or required in accordance with the purposes described above in this document. At the end of the data retention period, the personal data will be deleted, and as such, the rights of access, deletion, rectification and portability of the data can no longer be exercised
Cookie
This website uses cookies. Cookies are small text files that may be used by websites to make the experience more efficient for the data subject, as well as to personalise content and adverts, provide social networking features and analyse site traffic.
Cookie policy
Place of processing and transfer of data abroad
The data are processed at the operational headquarters of the data controller. For further information, please contact the data controller. The data may be processed by natural persons and/or legal entities acting on behalf of the controller and under specific contractual obligations, and based in EU or non-EU Member States. In the event that the data is transferred outside the EEA, the data controller shall take all appropriate contractual measures to ensure adequate data protection.
Exercising the rights of the data subject
The data subject has the right to exercise the rights provided for under Articles 7, 15-22 of the European Regulation 679/2016. More specifically, the data subject has the right to revoke their consent at any time and, upon request to the data controller, may request access to his/her personal data, may receive the personal data provided to the data controller and, where possible, send this to another data controller without hindrance (so-called data portability), as well as obtain the updating, restriction of processing and rectification of the data and the deletion of any data processed in breach of the applicable legislation. For legitimate reasons, the data subject also has the right to object to the processing of personal data concerning them, and to the processing of personal data for the purpose of sending advertising material, for direct sales and for carrying out market research. The data subject also has the right to lodge a complaint with the Italian Data Protection Authority, in that the latter acts as a supervisory authority for the protection of personal data; the data subject may also take legal action. The data subject may exercise their rights by contacting the data controller via email at: privacypolicy@sodalisgroup.com
Tools used for the processing of personal data
CONTACT FORM
By filling in the contact form with their data, the data subject consents to the use thereof in order to respond to requests for information, or for any other purpose indicated on the form header. Personal data collected via contact form: Name and surname, telephone number, email address
OTHER CONTACT TOOLS
WhatsApp Business
WhatsApp Business is an instant messaging service provided by WhatsApp Ireland Limited. For more information on processing methods and purposes, please also refer to the WhatsApp Business Data Processing Terms available at the following link:
https://www.whatsapp.com/legal/business-data-processing-terms/. The data subject's data will be transferred to WhatsApp Business Services in accordance with the terms set out by WhatsApp in the document "WhatsApp Business Terms of Service" at the following link:
https://www.whatsapp.com/legal/business-terms/ . Personal data collected: telephone number, email, usage data, cookies. Place of processing: Ireland -
Privacy Policy (link to be activated https://www.whatsapp.com/legal?eea=0#privacy-policy)
EMAIL ADDRESS MANAGEMENT
These services make it possible to manage a database of email contacts, telephone contacts or contacts of any other kind, used to communicate with the data subject. These services may also allow for the collection of data relating to the date and time of viewing of messages by the data subject, as well as to the data subject's interactions, such as information on clicks on links included in messages.
Newsletters
On registering for the newsletter, the email address of the data subject is automatically included in a list of contacts to whom email messages containing information (including that of a commercial and promotional nature) relating to this website may be sent. The email address of the data subject may also be added to this list following registration on this site or after making a purchase. The data subject may choose at any time to unsubscribe from the newsletter by clicking on the button for this purpose, which can be found in the email. After clicking on this button, the data subject's data will be deleted immediately from the "email marketing" software. Personal data collected: email and name. This website uses the newsletter service provided by:
MailUp (Growens S.p.A.)
This is a service that organises and analyses the distribution of newsletters. If a data subject does not want their data to be handled by Growens S.p.A., they must unsubscribe from the newsletter. For this purpose, a link is provided in each newsletter sent. Personal data collected: email and name. Place of processing: Italy -
Privacy Policy
WEBSITE REGISTRATION
By registering or authenticating themselves, the data subject allows the website to identify them and provide them with access to dedicated services.
The data subject can register directly on the site by filling in the form and providing their data.
The registration and authentication services may also be carried out with the help of third parties. In this instance, the application may have access to certain data stored by the third-party service used for registration and identification. Some of the services mentioned below may also collect personal data for targeting and profiling purposes.
This website uses:
Facebook Connect (Facebook Ireland Ltd)
Facebook Connect is a service provided by Facebook Ireland Ltd that facilitates and integrates the connection of the site with the social media network. This website may request certain permissions from Facebook that permit it to perform actions with the Facebook account of the data subject and to collect information, including personal data, from this account. For further information on the following permissions, the data subject may refer to the
Facebook Privacy Policy (https://www.facebook.com/privacy/explanation).
Access to Google account (Google Ireland Limited)
This service, offered by Google Ireland Limited, enables this website to connect with the Google account of the data subject. Personal data collected: Various types of data, as specified in the Privacy Policy of the service. Place of processing: Ireland -
Privacy Policy
STATISTICS
The statistical services only allow the data controller to monitor and analyse traffic data, and keep track of the behaviour of the data subject. This website uses the following services:
Facebook pixel conversion tracking (Meta Platforms, Inc.)
The Facebook conversion tracking service (Facebook pixel) is a statistics service provided by Facebook. The Facebook pixel monitors the conversions that can be attributed to Facebook advertisements. Personal data collected: Cookies; Usage data. Place of processing: Ireland -
Privacy Policy.
Instagram pixel conversion tracking (Meta Platforms, Inc.)
Instagram's conversion tracking service (Instagram pixel) is a statistics service provided by Meta Platforms, Inc. The Instagram pixel monitors the conversions that can be attributed to Facebook advertisements. Personal data collected: Cookies; Usage data. Place of processing: Ireland -
Privacy Policy
TikTok pixel conversion tracking (TikTok Ireland)
TikTok's conversion tracking service enables the data controller to monitor the conversions of its customers. Personal data collected: Cookies; Usage data. Place of processing: Ireland -
Privacy Policy
INTERACTION WITH SOCIAL MEDIA NETWORKS
These services allow interactions with social networks directly from the pages of this website. Interactions and information acquired by this website are in any case subject to the privacy settings selected by the data subject for each social media network. Where a social network interaction service is installed, it is possible that this will collect traffic data relating to the pages where it is installed even if users do not make use of this service.
Facebook (Meta Platforms, Inc.)
Facebook buttons enable interaction with Facebook, provided by Meta Platforms, Inc. Personal data collected: Cookies and usage data. Place of processing: Ireland -
Privacy Policy
Instagram (Meta Platforms, Inc.)
Instagram buttons enable interaction with Instagram, provided by Meta Platforms, Inc. Personal data collected: Cookies and usage data. Place of processing: Ireland -
Privacy Policy
TikTok (TikTok Technology Limited)
The TikTok buttons are social network interaction services provided by TikTok Technology Limited. Personal data collected: Cookies and usage data. Place of processing: Ireland –
Privacy Policy
REMARKETING AND RETARGETING
These services enable this website to communicate, optimise and deliver advertisements based on past use of the website by the data subject. This activity is carried out through the tracking of usage data and the use of cookies. This website uses the following services:
Facebook Remarketing (Meta Platforms, Inc.)
Facebook Remarketing is a remarketing and behavioural targeting service provided by Facebook, which links the activity of this website with the Facebook advertising network. This website uses the Facebook Pixel tool in order to measure conversions. Thanks to the Facebook Pixel service, the data controller can see the actions users perform on the website. The data collected may be used to:
- ensure that advertisements are shown to the right people;
- create target audience groups for advertisements;
- take advantage of the additional advertising tools of the platform being used for advertising
The information collected is anonymous to the operators of this website, and cannot be used to identify an individual data subject. However, the information is saved and analysed by Facebook, which could link the action back to an individual profile and use this information for internal Facebook advertising purposes, as outlined in Facebook's Privacy Policy. This will permit Facebook to show advertisements both on Facebook and on third-party sites. The site owner has no control over how this data is used. For more information on how users can protect their privacy, please refer to the
Privacy policy of Facebook.
Instagram Remarketing (Meta Platforms, Inc.)
Instagram Remarketing is a remarketing and behavioural targeting service provided by Meta Platforms, Inc. which links the activity of this website with the Instagram advertising network. This website makes use of the Pixel tool in order to measure conversions and understand the actions people carry out on the website. The information collected is anonymous to the operators of this Site and cannot be used to identify an individual data subject. However, the information is saved and analysed by Facebook, which could link the action back to an individual profile and use this information for internal Facebook advertising purposes, as outlined in Facebook's Privacy Policy. For more information on how users can protect their privacy, please refer to the
Privacy Policy of Instagram.
TikTok Ads (TikTok Technology Limited)
TikTok Ads is a remarketing and behavioural targeting service provided by (TikTok Technology Limited) which links the activity of this website with the TikTok advertising network. This website makes use of the Pixel Tracking tool in order to measure conversions and understand the actions people take on the website. For more information on how users can protect their privacy, please refer to the
Privacy Policy of TikTok.
Microsoft Bing ADS (Microsoft Corporation)
Bing ADS is a service provided by Microsoft Corporation that links this website with Microsoft's advertising network. This service enables the display of advertisements based on the personal interests of the data subject, identified through an analysis of the data subject's behaviour on the web, whether on a mobile device or on other devices, via the Bing search engine. Personal data collected: Cookies and usage data. Place of processing: Europe -
Privacy Policy
Facebook Forms (Meta Platforms, Inc.)
Facebook Forms is a service provided by Facebook. The service enables a campaign to be created with a contacts in ad management as an advertising objective; the interactive forms can be selected as the place of conversion. The interactive forms are designed to help generate and qualify contacts, by asking people to complete a form. The site owner has no control over how this data is used. For more information on how users can protect their privacy, please refer to the
Privacy policy of Facebook.
PAYMENT MANAGEMENT
Payment processing services enable this website to process payments by credit card, bank transfer or other tools. The data used for the payment are acquired directly by the operator of the payment service requested, without being processed in any way by this site. Some of these services may also enable the scheduled sending of messages to the data subject, such as emails containing invoices or payment notifications. This website uses the following services:
Scalapay (Scalapay SRL)
Scalapay is a service which allows deferred digital payments and money transfers via the internet. This service is provided by the company Scalapay Srl. Personal data collected: Various types of data, as specified in the Privacy Policy of the service. Place of processing: Italy -
Privacy Policy
PayPal (Paypal Europe S.à.r.l. et Cie, S.C.A Inc.)
PayPal is a payment service provided by PayPal Europe S.à.r.l. et Cie, S.C.A Inc., which enables the data subject to make online payments using his or her PayPal credentials. Personal data collected: Cookies and various types of data, as specified in the Privacy Policy of the service. Place of processing: Luxembourg -
Privacy Policy
Changes to this Privacy Policy
The data controller reserves the right to make changes to this Privacy Policy at any time, publicising any such changes to users on this page. Users are therefore advised to check this page on a regular basis, taking the date of last modification indicated at the bottom of the page as a reference. If the data subject does not accept the changes made to this Privacy Policy, they must stop using this website and may request the removal of their personal data by the data controller. Unless otherwise specified, the previous Privacy Policy shall continue to apply to personal data collected up to that point. The data controller is not responsible for updating all the links contained within this Privacy Policy, and as such, whenever a link is not working and/or updated, users acknowledge and accept that they must always refer to the document and/or section of the websites referred to by that link.
Privacy Policy updated in April 2024