Nuova Sangaus S.r.l. is committed to protecting and safeguarding the privacy of the users of its website: this policy statement sets out Nuova Sangaus’s commitment to being transparent with the customer about the data it collects, how it uses it and how it shares it.
The purpose of this document is to provide the data subject with the necessary information so that he or she can express, where necessary, explicit and informed consent to the processing carried out. We hope we can explain this in a clear and understandable manner, but we will provide below the necessary contact details in case you have any questions.
In general, any information or personal data that you provide to Nuova Sangaus through the Site, or that is collected in any other way in the context of the use of the services offered by Nuova Sangaus (the ‘services’), as better defined below, will be processed in accordance with the internationally recognised principles of lawfulness, correctness, transparency, purpose limitation and conservation, data minimisation, accuracy, integrity and confidentiality.
This Policy was prepared on 23 May 2018; from time to time we may need to amend it, including due to changes in applicable legislation. In order to stay up-to-date, we encourage you to visit this section on a regular basis to familiarize yourself with the most recent and up-to-date version of the Policy.
By using our services, you consent to the use of your data by us in accordance with this Privacy Policy. One note: minors under the age of 16 may only register for our website or newsletter with the involvement of a parent or guardian.
If you do not agree with this Privacy Policy, you must stop using our services.
1. Data controller
2. The data being processed
2.a. Name, contact details and other personal data
2.b. Data provided voluntarily by the data subject
2.c. Data of third parties provided by the data subject
2.d. Navigation data
2.e. Cookies
3. Legal basis and obligatory or optional nature of processing
4. Purpose of processing
5. Recipients of personal data
6. Transfers of personal data
7. Processing methods
8. Retention of personal data
9. Social Media
10. Rights of the Data Subject
11. Changes
12. Definitions
The data controller in respect of all personal data processed through the site is Nuova Sangaus S.r.l., Via Lagrange 10 – Turin (TO), Italy, which can be contacted at the following address: info@tonatto.com.
The personal data processed through the Site are as follows:
a. Name, contact details and other personal data
In the ‘create an account’ section of the Site, you will be asked to enter information such as your first name, last name, gender, email address, contact details. In the ‘cart_check out’ section, in addition to the data indicated for the ‘create an account’ section, you will also be asked for a telephone number, any billing details for applicants, and, if applicable, shipping details if this is to be done at a location other than the contact entered. In addition, whenever the Interested Party communicates with Nuova Sangaus via the contacts it finds on the Site, Nuova Sangaus may collect further information that the Interested Party decides to provide.
b. Third-party data provided by the data subject
As already mentioned above, in some parts of the Site, it is permitted to insert text messages, visible to Nuova Sangaus, which may (voluntarily or involuntarily) contain personal data of other persons.
With respect to these hypotheses, the Data Subject must be considered the autonomous data controller, assuming all the resulting legal obligations and responsibilities with respect to the ‘third parties concerned’.
d. Dati di navigazione
d. Navigation data
The computer systems and software procedures used to operate the Site acquire by default, some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified interested parties, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category includes IP addresses, the domain names of the computers used by users who connect to the Website, URI (Uniform Resource Identifier) notation addresses, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the IT environment of the data subject. This data is used for the sole purpose of obtaining anonymous statistical information on the use of the Site, to check that it is working properly, to provide the User with targeted advertising (for a full explanation of these forms of use, please refer to the cookie policy)
and to identify anomalies and/or abuse. To collect information, in aggregate form, on the number of users and how they visit the site, in order to provide targeted advertising, Nuova Sangaus uses
– the Google Analytics service, whose cookie policy can be viewed at https://support.google.com/analytics/answer/6004245
– of Google AdWords, whose privacy policy can be viewed at the following address: https://policies.google.com/technologies/ads?hl=it&gl=it[Studio NV1].
e. Cookies
Information on the use of cookies can be found in the cookie policy below.
The legal bases used by Nuova Sangaus to process personal data for the purposes indicated in Article 4 below are as follows:
– Service provision/fulfilment of contractual obligations: processing for this purpose is necessary for the performance of the contract signed between Nuova Sangaus and the Data Subject, and therefore to be able to provide the contractually agreed services. The provision of personal data for this purpose is not mandatory, but without it it will not be possible to provide any Services.
– Overriding legitimate interest of the data controller: the processing is necessary in order to carry out checks and assessments on the results and progress of the contractual relationship, as well as on the risks associated with it (such as: truthfulness of the data provided, solvency also during the relationship and correct use of products and services).
– Legal obligations: processing for this purpose is necessary for Nuova Sangaus to fulfil any legal obligations. Personal data provided to Systems shall be processed in accordance with applicable legislation, which may entail their storage and communication to the relevant authorities.
– Promotional communications to customers: processing for this purpose is based on the legitimate interest of Nuova Sangaus in transmitting marketing communications regarding products and services similar to those already purchased by our customers. The interested party may, at any time and free of charge, interrupt the receipt of these communications by writing to info@tonatto.com and without prejudice to the lawfulness of the processing during the period of validity of the same consent.
Overriding legitimate interest of the proprietor: the processing of our customers’ data in this case is necessary to improve the efficiency of the products and services offered by Sistemi. To this end, Nuova Sangaus may send out satisfaction questionnaires and market surveys, carry out telephone calls or chat sessions; these questionnaires/market surveys in general will be designed to minimise the use of personal data.
Marketing: The processing for this purpose is based solely on the consent of the Data Subject, which can be freely withdrawn at any time. Minors under the age of 16 may provide their consent only with the involvement of a parent or guardian. The Data Subject may, at any time and free of charge, stop receiving these communications by writing to info@tonatto.com, without prejudice to the legality of the processing during the validity period of the given consent. In the event of withdrawal, Nuova Sangaus will no longer send any further communications.
Here is the English translation:
Nuova Sangaus will process the personal data provided by users solely in the ways outlined in this Privacy Policy and in compliance with current legislation. The personal data collected through the website will be used for the following purposes:
a. **Provision of services/fulfillment of contractual obligations:** For purposes related to the execution of obligations arising from the contract.
b. **Overriding legitimate interest of the controller:** To carry out checks and assessments on the results and progress of the relationship, as well as on the risks associated with it (such as the veracity of the data provided, solvency during the course of the relationship). To compile statistics, anonymously, on the services provided and access to the site, as well as commercial information and participation in fairs, events, seminars, and any other initiatives aimed at promoting Nuova Sangaus’ products and services. To prevent or identify any misuse of the website or any fraudulent activities. To improve the quality of services rendered by sending questionnaires, collecting feedback on participation in events, recording calls, and chats.
c. **Legal obligations to which the controller is subject:** To comply with laws and/or provisions from public authorities that require Nuova Sangaus to collect and/or further process certain types of personal data.
d. **Sending promotional offers to its customers:** To send, via email, SMS, phone calls, banners, instant messaging, operator assistance, traditional mail, and through Nuova Sangaus’ official social media pages (Facebook, Twitter, Pinterest, Instagram, LinkedIn), marketing communications, promotions, and personalized content, provide targeted advertisements regarding products and services similar to those the customer has already purchased.
e. **Marketing:** To send communications, newsletters, promotions, and advertisements, via email, SMS, phone calls, banners, instant messaging, operator assistance, traditional mail, and Nuova Sangaus’ official social media pages (Facebook, Twitter, Pinterest, Instagram, LinkedIn), relating to additional products and services from Nuova Sangaus and third parties to those who have previously given their consent.
In cases related to points a), b), c), and d) of this article, Nuova Sangaus is authorized to process personal data according to applicable data protection laws without needing to obtain specific consent from the data subject. Processing for the purposes outlined in points a), b), and c) is necessary for the provision of services and, therefore, for the execution of the contract itself. Providing data to Nuova Sangaus for these purposes is not mandatory; however, failure to do so will result in the inability to provide any service.
Regarding the purposes mentioned in point d), the data subject may object to their processing at any time and free of charge. If revoked, the data subject will no longer be able to use the aforementioned services.
In cases related to point e) of this article, Nuova Sangaus will process data only after obtaining consent from the data subject. Providing consent, as specified in Article 3 “Legal Basis and Mandatory or Optional Nature of Processing,” is not mandatory. If provided, the data subject is free to withdraw their consent at any time without any consequences (other than no longer receiving marketing communications). Further information regarding the withdrawal of previously given consent is provided in Article 10 of this Privacy Policy.
The personal data of the Data Subject may be shared with the entities listed below (“Recipients”):
• Entities typically acting as data processors, such as: individuals, companies, or professional firms providing assistance and consultancy to Nuova Sangaus in commercial, accounting, administrative, legal, tax, financial matters, debt collection, mailing of promotional materials or contractual communications, event organizing companies, and providers of services for web meetings and training webinars. A complete list of all processors can be requested by contacting the email address: info@tonatto.com.
• Providers of email services (platforms for sending emails), also tasked with managing cancellation requests submitted by users for the processing purposes outlined in point 4, letters d) and e).
• Entities responsible for performing technical maintenance activities (including the maintenance of network devices and electronic communication networks).
• Individuals authorized by Nuova Sangaus to process personal data necessary to perform activities closely related to the provision of products/services; these individuals are legally bound by confidentiality obligations.
• Entities, organizations, or Authorities to which the communication of personal data is mandatory in order to comply with legal obligations, prevent misuse or fraud.
For purposes related to the execution of the contract, certain data may be shared with recipients located outside the European Economic Area (EEA).
Nuova Sangaus ensures that the processing of personal data by these recipients is carried out in compliance with applicable regulations. Transfers are conducted with appropriate safeguards, such as adequacy decisions, Standard Contractual Clauses approved by the European Commission, or other guarantees deemed adequate. For more information, you can contact: info@tonatto.com.
The processing of personal data is carried out through the following operations: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, deletion, and destruction of data.
Personal data is processed both on paper and electronically and/or automatically.
The processing is conducted in a manner that ensures ongoing security and confidentiality.
In compliance with European regulations and national data protection laws, Nuova Sangaus has implemented specific procedures to prevent unauthorized access to data, its misuse or unlawful use, as well as to prevent the accidental destruction or loss of the data.
Only duly authorized personnel can access the data in the course of their duties.
Personal data processed for the purpose of “Provision of Service/Contractual Obligations” will be retained for the time strictly necessary to achieve this purpose.
Personal data processed for “Marketing” purposes will be retained by Nuova Sangaus until the consent provided by the Data Subject is revoked. Once the consent is withdrawn, the use of the data for such purposes will cease, but it may still be kept to protect Nuova Sangaus’ interests against potential liabilities related to these processes.
Personal data processed for the purpose of sending promotional offers to customers will be retained by Nuova Sangaus until the Data Subject objects to the processing by writing to info@tonatto.com.
Personal data processed for the purpose of “Compliance with Legal Obligations” will be retained by Nuova Sangaus for the period mandated by specific legal obligations or applicable regulations.
Personal data processed for the purpose of preventing “Abuse/Fraud” will be retained by Nuova Sangaus for the time strictly necessary to achieve this goal.
Nuova Sangaus uses social media to share content related to its products and services:
https://www.facebook.com/TonattoOfficial/ [NVN2]
https://www.instagram.com/tonattoprofumi/
https://www.pinterest.it/tonatto/
https://twitter.com/tonatto_profumi
Third-party websites accessible through this site are not covered by this Privacy Policy. For information on the privacy policies of these social media platforms, please refer to the following links:
FACEBOOK: https://www.linkedin.com/legal/privacy-policy?_l=it_IT
INSTAGRAM: https://help.instagram.com/519522125107875
PINTEREST: https://policy.pinterest.com/en/privacy-policy
TWITTER: https://twitter.com/it/privacy
The Data Subject has the right to request from Sistemi, at any time:
Access to their personal data (and/or a copy of such data), as well as additional information about the ongoing processing of their data;
Rectification or updating of their personal data;
Deletion of their personal data from Sistemi’s databases;
Restriction of the processing of their personal data by Sistemi;
Data portability, meaning obtaining a copy of their personal data provided to Sistemi in a structured, commonly used, and machine-readable format, or requesting its transmission to another Data Controller;
Opposition to the processing of their personal data;
Revocation of their consent for the specified purposes.
Nuova Sangaus will provide the Data Subject with information regarding one or more of the actions taken from the above list without undue delay and, in any case, no later than one month from the request. This period may be extended by two months, considering the complexity and number of requests, with appropriate notification to the Data Subject regarding such extension and the reasons for the delay, to be provided within one month from the receipt of the request.
The Data Subject also has the right to lodge a complaint with the competent Supervisory Authority (in Italy, the Garante Privacy, ) if they believe that the processing of their personal data violates the applicable regulations.
The exercise of the rights mentioned in this article may be carried out by the Data Subject at the following email address: info@tonatto.com.
This Privacy Policy has been in effect since May 22, 2018. Nuova Sangaus reserves the right to amend or update it, including as a result of regulatory changes or practices issued by the National Supervisory Authority or the European Data Protection Board.
Personal Data: Any information relating to an identified or identifiable natural person (Data Subject); a natural person is considered identifiable if they can be identified, directly or indirectly, particularly by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.
Processing: Any operation or set of operations, performed with or without the use of automated processes, applied to personal data or sets of personal data, such as collection, recording, organization, structuring, storage, adaptation or modification, extraction, consultation, use, communication through transmission, dissemination, or any other form of making available, comparison or interconnection, restriction, erasure, or destruction.
Data Controller: The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; when the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for by Union or Member State law.
Data Processor: The natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
Recipient: A natural or legal person, public authority, agency, or another body to which personal data is disclosed, whether or not it is a third party. However, public authorities that may receive personal data in the framework of a specific investigation in accordance with Union or Member State law are not considered recipients; the processing of such data by those public authorities complies with the applicable data protection rules according to the purposes of the processing.
Third Party: A natural or legal person, public authority, agency, or body other than the Data Subject, the Data Controller, the Data Processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.
Consent of the Data Subject: Any freely given, specific, informed, and unambiguous indication of the Data Subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
Personal Data Breach: A security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.
Binding Corporate Rules: Policies regarding the protection of personal data applied by a controller or processor established in the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings or a group of enterprises engaged in a joint economic activity.
Supervisory Authority: The independent public authority established by a Member State pursuant to Article 51.
Concerned Supervisory Authority: A Supervisory Authority concerned with the processing of personal data because:
The controller or processor is established in the territory of the Member State of that Supervisory Authority;
The data subjects residing in the Member State of that Supervisory Authority are or are likely to be substantially affected by the processing; or
A complaint has been lodged with that Supervisory Authority.
Cross-Border Processing:
a) Processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State; or
b) Processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.
A cookie is a small file that is sent to your browser and saved on your device. Cookies allow the website to function efficiently and improve its performance. Additionally, they provide information to the website owner for statistical or advertising purposes, primarily to personalize your browsing experience by remembering your preferences (e.g., remembering the language and currency you have set). This website uses different types of cookies and similar technologies, each with a specific function.
Types and Functions
Navigation Cookies From the first access, these cookies allow the website to function properly and display content on your device by recognizing the language and market of the country from which you chose to connect. If you are a registered user, they will allow you to be recognized and access the services offered in dedicated areas. Navigation cookies are technical cookies and are necessary for the website to function.
Functional Cookies These cookies allow, at your expressed request, for you to be recognized during subsequent visits so you don’t have to enter your details every time. If you have added items to your shopping cart and closed the session without completing the purchase or removing them, these cookies allow you to resume shopping the next time you access the site and find the selected items. Functional cookies are not essential for the website’s operation but improve the quality and experience of browsing.
Analytical Cookies These cookies are used to perform statistical analyses on user browsing behavior on the website. The website uses some third-party services that independently install their own cookies.
First and Third-Party Marketing and Profiling Cookies These cookies are aimed at creating user profiles to send commercial messages that match preferences expressed during the visit or improve your browsing experience. While you browse our website, these cookies are helpful to show you products of interest or similar to those you viewed. Third-party cookies are those sent by trusted third-party companies. These cookies allow us to offer you our commercial proposals on other affiliated websites (retargeting). We have no control over the information provided by third-party cookies, nor do we have access to such data. These details are fully managed by third parties as described in their respective privacy policies.
Social Network Cookies These cookies are necessary to enable your social account to interact with our website. For example, they allow you to express your appreciation and share it with your social friends. Social network cookies are not necessary for navigation. For more information about cookies and managing your preferences for third-party profiling cookies, we invite you to visit
http://www.youronlinechoices.com
. To disable analytical cookies and prevent Google Analytics from collecting data on your browsing, you can download the browser add-on for deactivating Google Analytics:
https://tools.google.com/dlpage/gaoptout.
No products in the cart.