Privacy Policy

INTRODUCTION

This policy considers the provisions of Regulation (EU) 2016/679 of the European Parliament and the Council of 27 April 2016 (GDPR) and the Italian Privacy Code (Legislative Decree 30 June 2003, No. 196). The document has also been prepared in accordance with the guidelines of the Italian Data Protection Authority (particularly the anti-spam guidelines issued by the Data Protection Authority on 4 July 2013).

Data Controller:
WORLD VESTIUM S.R.L.
Via Antonio Cecchi 18, 20146, Milan (MI)
VAT Number: IT13342340968
REA: 2717999
Paid-up Share Capital: €30,,000
Email: info@worldvestium.com

Website referred to in this privacy policy: https://www.worldvestium.com (Website).

The Data Controller has not appointed a Data Protection Officer (DPO). Therefore, any requests for information can be sent directly to the Data Controller.

GENERAL INFORMATION

This document describes how the Data Controller processes your personal data provided on the Website.

Below are the main ways in which your personal data is processed. The legal basis for processing, whether the provision of data is mandatory, and the consequences of not providing personal data are explained. To best describe your rights, we have specified whether and when a particular personal data processing activity is not carried out. On the Website, you may enter personal data of third parties. In such cases, you guarantee that you have obtained the consent of these third parties to the entry of their personal data. Therefore, you agree to indemnify and hold the Data Controller harmless from any liability.

Registration on the Website

The information and data requested upon registration will be used to allow you to access the reserved area of the Website and to use the online services offered by the Data Controller to registered users. The legal basis for the processing is the necessity for the Data Controller to execute pre-contractual measures adopted at the request of the data subject. The provision of data is optional. However, if you refuse to provide data, it will be impossible to register on the Website.

Purchases on the Website

Your personal data will be processed to allow you to make purchases on the Website. In the event of an online purchase order, the data will be processed to conclude the purchase contract and correctly execute the related operations (and, if necessary, to fulfill fiscal obligations according to sector regulations). This data processing includes the possibility of sending communications (e.g., tracking and order information) through automated tools such as SMS and/or WhatsApp. The legal basis for processing is the obligation of the Data Controller to execute the contract with the data subject or to comply with legal obligations. Regardless of the above (and thus your consent), the Data Controller may process your data for "soft-spam" purposes, as governed by Article 130 of the Privacy Code. This means that the Data Controller will process your email, provided during a purchase on the Website, to directly offer similar products/services unless you object to this processing as outlined in this policy. The legal basis for processing is the legitimate interest of the Data Controller to send such communications. This legitimate interest is equivalent to the data subject's interest in receiving "soft-spam" communications. The Data Controller may send emails to remind users to complete a purchase. The legal basis for this processing is the legitimate interest of the Data Controller to send such communications.

Responding to Your Requests

Your data will be processed to respond to your requests for information. Providing data is optional, but refusal to do so will make it impossible for the Data Controller to respond to your inquiries. The legal basis for processing is the legitimate interest of the Data Controller to respond to user requests. This legitimate interest is equivalent to the user's interest in receiving responses to communications sent to the Data Controller.

Generic Marketing

With your consent, the Data Controller may process the personal data you provide to send you advertising materials and/or newsletters about its own or third-party products. The legal basis for this processing is your consent. Providing personal data for this purpose is entirely optional. Failure to consent to data processing for marketing purposes will make it impossible for you to receive advertising material about the Data Controller's and/or third-party products/services and for the Data Controller to conduct market research, including surveys to measure user satisfaction, and send you newsletters. These communications will be sent to the email address you provided on the Website.

Profiling

With your consent, the Data Controller may process your personal data for profiling purposes, i.e., to analyze your consumption choices by identifying the type and frequency of purchases you make, to send you advertising materials and/or newsletters related to its own or third-party products of specific interest to you. The legal basis for this processing is your consent. Providing data for this purpose is entirely optional. Failure to consent to profiling will make it impossible for the Data Controller to process your commercial profile, detect your purchasing choices and habits, and send you advertising material related to the Data Controller's and/or third-party products of specific interest to you. These communications will be sent to the email address you provided on the Website.

Data Sharing

The Data Controller does not share your personal data with third parties.

Geolocation

The Website does not implement IP address geolocation tools.

Curriculum Vitae

You cannot submit your resume via the Website. Therefore, your data will not be processed for these purposes.

Appointment Booking

The Website does not have third-party appointment booking systems with the Data Controller. Therefore, your data will not be processed for this purpose. However, you can always contact the Data Controller using the contact information provided above.

Communication of Personal Data

In the course of its regular business activities, the Data Controller may communicate your personal data to certain categories of recipients. Article 2 provides a list of recipients to whom the Data Controller communicates your personal data. To facilitate the protection of your rights, Article 2 may specify in some cases when your data is not communicated to third parties.

"Communication" to third parties of personal data is different from "transfer" (covered in the preceding section). In communication, the third party to whom the data is transmitted can only use it for the specific purposes described in the relationship with the Data Controller. In transfer, the third party becomes an independent Data Controller of the personal data. Additionally, transferring your personal data to third parties always requires your consent.

Notwithstanding the above, it is understood that the Data Controller may still use your personal data to fulfill legal obligations.

SPECIFIC PRIVACY POLICY

Article 1: Data Processing Methods

1.1 Your personal data will mainly be processed using electronic or automated means, according to methods and tools suitable for ensuring the security and confidentiality of personal data.

1.2 The information acquired and the processing methods will be relevant and not excessive compared to the type of services provided. Your data will also be managed and protected in secure and adequate IT environments.

1.3 No "special data" will be processed through the Website. Special data includes data that may reveal racial and ethnic origin, religious, philosophical or other beliefs, political opinions, membership in parties, unions, religious, philosophical, political, or trade union associations or organizations, health status, and sex life.

1.4 No judicial data will be processed through the Website.

Article 2: Communication of Personal Data

The Data Controller may communicate your personal data to specific categories of recipients. The Data Controller informs users that, when using the YouTube service (operated and owned by Google LLC), certain personal data may be collected and shared. This data collection is essential for providing and improving the user experience on our Website and for enabling video content viewing via the YouTube API. Specifically, when a user views video content through the YouTube API on our Website, the following information may be collected:

  • IP Address: Used to connect the user's device to YouTube for video transmission.
  • Behavioral Data: Includes information on how the user interacts with the videos, which videos are viewed, and for how long.
  • Location Information: Used to provide relevant content based on the user's geographic location.

This data is collected automatically by the system and, in some cases, may be retained to improve user experience and for YouTube's internal analytical purposes. Our Website uses YouTube API services, and by viewing content via these APIs, the user agrees to YouTube's Terms of Service, which can be viewed at https://www.youtube.com/t/terms. For further details on Google's data management, users are encouraged to review Google's privacy policy at http://www.google.com/policies/privacy and YouTube's privacy policy at https://www.youtube.com/intl/ALL_it/howyoutubeworks/our-commitments/protecting-user-data/.

Use of User Data via API

  • User Data: When a user interacts with YouTube videos embedded on our Website, data such as viewing preferences, video viewing history, and video content interactions (likes, comments, shares) may be collected. These data are made available via the YouTube API and help understand how users interact with video content.
  • API Data Access: Our Website may use specific API calls to request and receive data from YouTube. This may occur when a user views a video, with the system automatically logging relevant information.
  • Data Collection: Data is automatically collected by the YouTube system when users interact with YouTube videos on our Website. This process is essential for providing a smooth and personalized user experience.
  • Data Retention: Data collected is securely stored in YouTube systems for a period not exceeding the necessary usage. YouTube takes all necessary security measures to protect this

Article 3 - Retention of Personal Data

3.1 This article describes the duration for which the Data Controller reserves the right to retain your personal data.

Your personal data will be retained only for the time necessary to ensure the correct provision of the services offered through the Website.

  • For marketing purposes, personal data will be retained until the consent is withdrawn. For inactive users, personal data will be deleted one year after the last email viewed, if any.
  • For customer care purposes, data will be deleted once the assistance service is completed and, in any case, within a maximum of 3 months from the last email exchange with the data subject.
  • For the purpose of executing the sales contract, data will be retained for 10 years from the date of receipt of the purchase order. This allows the Data Controller to exercise its right of defense and to demonstrate that the contract was correctly executed.

3.2 Notwithstanding the provisions of article 3.1, the Data Controller may retain your personal data for the time required by specific regulations, as amended from time to time.

Article 4 - Transfer of Personal Data

4.1 The Data Controller is based in a country that presents an adequate level of security from a regulatory point of view. Should the transfer of your personal data occur to a non-EU country for which the European Commission has issued an adequacy decision, the transfer is considered safe from a regulatory point of view. This article 4.1 indicates from time to time the countries to which your personal data may be transferred and where the European Commission has expressed an adequacy decision.

Your personal data may be transferred to the USA based on the European Commission's adequacy decision. With this decision, the European Commission decided that the USA offers data protection equivalent to that offered by the European Union.
To ensure the proper operation of the Website, your personal data may be transferred abroad. This is permitted based on the European Commission's decision of December 20, 2001, No. 2002/2/EC (published in the Official Journal of the European Communities L 2/13 of January 4, 2002), which found that Canada guarantees an adequate level of protection for personal data transferred from the European Union to recipients subject to the Canadian Personal Information Protection and Electronic Documents Act ("the Canadian Act") of April 13, 2000.

4.2 Notwithstanding the provisions of article 4.1, your data may also be transferred to non-EU countries for which the European Commission has not expressed an adequacy decision. You are therefore invited to regularly review this article 4.2 to determine in which of these countries your data may be transferred.

4.3 In this article, the Data Controller indicates the countries to which it specifically directs its activities. This circumstance may imply the application of the laws of the reference country, along with those that govern the relationship with the user as indicated in the Introduction.

At the user's request, the Data Controller will apply the more favorable regulations provided by the user's national legislation to the processing of personal data.

Article 5 - Rights of the Data Subject

The Data Controller informs you that you have the right to:

  • Request access to your personal data and the rectification or deletion of the same or the limitation of the processing that concerns you or to object to their processing, in addition to the right to data portability.
  • Withdraw consent at any time without affecting the lawfulness of the processing based on the consent given before withdrawal.
  • Lodge a complaint with a supervisory authority.

The above rights can be exercised by making a request without formalities to the contacts indicated in the Introduction.

Article 6 - Changes and Miscellaneous

The Data Controller reserves the right to make changes to this information at any time, providing appropriate publicity to the users of the Website and ensuring in any case adequate and similar protection of personal data. To view any changes, you are invited to regularly consult this information. In case of substantial changes to this privacy policy, the Data Controller may also communicate them via email.