Skip to content

Privacy policy

DATA CONTROLLER

The Data Controller is: Hair Gallery Europe Srl, with registered office in Via Mar Baltico, 56/58 - 63821 Porto Sant'Elpidio (FM); e-mail: info@hair-gallery.it – P.Iva 02388740447 (the “Data Controller”). Data Protection Officer: contactable at the e-mail address rpd@hair-gallery.it or at the address above by inserting the wording: “Regarding Privacy” in the letter.

METHOD OF PROCESSING THE COLLECTED DATA


European Regulation no. 679/2016 (hereinafter also GDPR) establishes rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free circulation of such data aimed at protecting the fundamental rights and freedoms of natural persons and in particular the right to the protection of personal data.
Data protection is of utmost importance for Hair Gallery Europe Srl and this, as Data Controller, wants to guarantee maximum transparency regarding the processing of personal data provided by users/interested parties.
This document illustrates how your personal data is processed and protected.
According to the legislation (art. 5 Reg./EU n. 679/2016) the data processing is based on the principles of lawfulness, correctness and transparency towards the interested party and protection of his privacy and his rights.
This site collects data necessary for navigation and use of the services connected to it.
The processing of such data will be carried out through automated and non-automated tools, in accordance with the purposes indicated and in compliance with the confidentiality requirements and the most suitable security measures, as indicated by the aforementioned Regulation.
In addition to the Data Controller, other parties involved in the organization of this application or external parties appointed as Data Processors by the Data Controller may have access to the data.

PLACE AND PURPOSE OF THE TREATMENT

The processing operations connected to the web service of this site take place at the headquarters of the Data Controller, at the headquarters identified by the website manager and are handled only by personnel authorized and trained by the Data Controller for this purpose for processing, or by persons in charge of occasional maintenance operations. No data deriving from the web service is disclosed. Personal data that forward requests of an informative nature are used to follow up on the requests of the interested party.
The collection and processing of the interested party's personal data will take place in compliance with the principles of necessity, correctness, relevance and non-excess and in particular the data processing will take place to allow the Owner to provide its services for the following purposes:

  • conclude and execute the
  • purchase contract for goods offered on www.hair-gallery.it;
  • manage requests forwarded to our Customer Service;
  • allow registration on the site and use of services reserved for registered users.

In the cases mentioned above, the data processing is legitimate as it is necessary to execute a concluded contract or to provide and supply the service that has been specifically requested. To provide the services of www.hair-gallery.it such as subscription to the newsletter, a specific declaration by the interested party is required that they are at least 16 years old with consent to the processing of their personal data by checking the appropriate box.

DETAILS ON THE PROCESSING OF PERSONAL DATA

More specifically, personal data is collected for the following purposes and using the following services:

Contact form (or “contact form”)
By filling out the contact form with your data, the interested party consents to their use to respond to requests for information regarding the status of your order, for example, to change the address of your order, receive information on shipping or products or other.
Personal data collected: Name, Surname, Email, Request from the interested party.

Account Registration Form
By filling in the account registration form with their data, the interested party consents to their use to proceed with their online orders.
Personal data collected: Name, Surname, Telephone, Address, Date of birth.

LEGAL BASIS FOR THE PROCESSING

The Data Controller processes personal data relating to the interested party if one of the following conditions exists:

  • the interested party has given consent for one or more specific purposes
  • processing of personal data on a legal basis other than consent are the cases in which, for example:

  • processing is necessary for the performance of a contract;
  • processing is necessary to fulfill a legal obligation to which the Data Controller is subject;
  • processing is necessary for the pursuit of the legitimate interest of the Owner or third parties.

The interested party can always ask the Data Controller and/or the Data Protection Officer to clarify the specific legal basis of the processing by referring to the contact details indicated above.

CATEGORIES OF RECIPIENTS OF PERSONAL DATA

The personal data provided may be known and processed for the sole purpose of carrying out the processing activities for which the data were collected. The personal data of the interested party may be known only by personnel authorized and trained for this purpose by the Data Controller as well as by the designated Data Processor. The data of the Data Processor may be known by the interested party by writing to the email address: info@hair-gallery.it
The Data Controller will, if requested, forward such information without delay.

DATA RETENTION PERIOD

Personal data are processed and stored for the time required by the purposes for which they were collected, at the end of which they will be deleted or otherwise rendered anonymous in an irreversible way. Personal data collected for purposes related to the execution of a contract between the owner and the interested party will be retained until the execution of the contract is completed, without prejudice to the right to retain data for the time required by law, in particular by virtue of the fulfillment of accounting and tax obligations as required by current legislation by the Data Controller and by specifically appointed Data Processors.

When the processing is based on the consent of the interested party, the owner can retain the personal data longer unless the consent is revoked.
The data collected to send newsletters are stored until the request to stop sending is made and in any case for a period not exceeding 36 months.

RIGHTS OF THE INTERESTED PARTY

At any time, certain rights may be exercised with reference to the data processed by the Data Controller. In particular, the interested party, pursuant to Reg./EU n. 679/2016 (GDPR), may exercise the following rights:
Right to withdraw consent. The interested party may withdraw consent to the processing of their personal data previously expressed
Right to access your data (art. 15 GDPR). The interested party has the right to obtain information on the data processed by the Data Controller, on certain aspects of the processing and to receive a copy of the data processed, with the right to communicate the following information: a) purposes of the processing; b) categories of personal data processed; c) recipients to whom such data have been or will be communicated; d) period of data retention or the criteria used; e) right to receive information on the origin of the personal data if these have not been collected from the interested party.
Right to rectification (art. 16 GDPR). The interested party may request, without undue delay, the rectification of personal data if they are incorrect, including the right to request the completion of incomplete personal data.
Right to erasure (right to be forgotten pursuant to art. 17 GDPR). The interested party, when certain conditions apply, may request the erasure of their data by the controller if: a) the data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; b) the data have been unlawfully processed; c) the interested party has successfully objected to the processing of personal data; d) the data have been unlawfully processed; e) the data must be erased in compliance with a legal obligation. The right to erasure cannot be applied in cases where the processing is necessary for compliance with a legal obligation or for the performance of a task carried out in the public interest or for the establishment, exercise or defense of a right in court.
Right to restriction (art. 18 GDPR). The interested party has the right to request the restriction of the processing of his/her data. In this case, the Data Controller will not process the data for any purpose other than their conservation if: a) the interested party contests the accuracy of the personal data; b) the processing is unlawful and the interested party opposes the erasure of the personal data and requests that their use be limited; c) although the Data Controller no longer needs the data for the purposes of the processing, the personal data are indispensable to the interested party for the establishment, exercise or defense of a right in court; d) the interested party has opposed the processing pending the verification of the possible prevalence of the legitimate reasons of the Data Controller with respect to those of the interested party.
Right to data portability (art. 20 GDPR). The interested party has the right to have his/her data transferred to another Data Controller. For the purpose in question, the interested party has the right to receive his/her data in a structured, commonly used and machine-readable format.
Right to object (art. 21 GDPR). The interested party, at any time, may object to the processing of their data when it occurs on a legal basis other than consent, unless there are legitimate reasons for the Data Controller to continue the processing that prevail over the interests, rights and freedoms of the interested party or for the establishment, exercise or defense of a right in court.

All the rights of the interested party are exercised with a request addressed to the Data Controller Hair Gallery Europe Srl in written form using the "Form for exercising rights in the field of personal data protection" addressed to the Data Controller and available at the following link: https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/1089924
The deadline for responding to the interested party is, for all rights, one month.
The general right to lodge a complaint with the Personal Data Protection Authority, Piazza di Montecitorio n. 121, 00186, Rome (RM), remains unaffected. The complaint form made available by the Personal Data Protection Authority is available at the following link: https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/4535524
The complaint to the Privacy Authority can be signed directly by the interested party or, on his behalf, by a lawyer, a solicitor, a body, an organisation or a non-profit association.

NOTICE TO CUSTOMER - PRIVACY

The establishment of Hair Gallery Europe Srl requires the transition to the new legal entity of the clientele originally headed by Hair Gallery Store srl. For any information, it is always possible to contact the designated Data Protection Officer via the email address: rpd@hair-gallery.it
The exercise of the rights pursuant to European Regulation no. 679/2016 (GDPR) by customers/users remains unaffected.
In compliance with current legislation, we are always available to our customers to provide the best possible service.

DATA TRANSFER TO A THIRD COUNTRY AND/OR AN INTERNATIONAL ORGANIZATION

The personal data provided will not be transferred to countries outside the EU. To learn about your rights and to always be updated on the legislation regarding the protection of individuals with respect to the processing of personal data, we recommend that you visit the website of the Guarantor for the protection of personal data at www.garanteprivacy.it

EXTENDED INFORMATION ON COOKIES

What are Cookies?

Cookies are small text files that are automatically placed on the navigator's PC inside the browser. They contain basic information on Internet navigation and thanks to the browser they are recognized every time the user visits the site. For example, they can temporarily remember your navigation preferences to avoid selecting the language every time, thus making subsequent visits more comfortable and intuitive. Or they can be used to make "anonymous surveys" on how users navigate through the site, so that it can then be improved starting from real data.

Cookies do not record any personal information about a user and any identifiable data will not be stored. If you wish to disable the use of cookies, you must customize your computer settings by setting the deletion of all cookies or activating a warning message when cookies are being stored.

COOKIES USED ON THIS SITE
This site does not use any type of cookie for user profiling.

Cookies management

Technical cookies
Activities strictly necessary for operation. These cookies are technical in nature and allow the site to function correctly. For example, they keep the user connected during navigation, preventing the site from requiring multiple connections to access subsequent pages.

Preference saving activity
These cookies allow us to remember the preferences selected by the user during navigation, for example, they allow us to set the language.

Statistics and Audience Measurement Activities
These cookies help us understand, through data collected anonymously and in aggregate form, how users interact with the website by providing information relating to the sections visited, the time spent on the site, any malfunctions. This helps improve the performance of the website.

Third-party statistical and audience measurement cookies
These cookies (third-party web services) provide anonymous/aggregated information on how visitors navigate the site.

Social media sharing cookies
These third-party cookies are used to integrate some widespread features of the main social media and provide them within the site. In particular, they allow registration and authentication on the site via Facebook, Instagram and Twitter as well as sharing and commenting on pages of the site on social media, enabling for example the "like" features on Facebook.

Analytical cookies on this site

This site uses the free Google Analytics service. We remind you that the data is used only to have the data of the most visited pages, the number of visitors, the aggregate data of visits by operating system, by browser, etc. These parameters are stored on Google servers that regulate their Privacy according to the guidelines. In addition to the pages visited, the data collected may also include, by way of example and not limited to, the domain names and the type of browser of the computers used to connect to the Site, the URI (Uniform Resource Identifier) ​​addresses of the requested resources, the time of the request, parameters regarding the operating system and the IT environment you use. These data do not allow, in any case, to reach your identity due to their nature and the methods of their treatment and are therefore to be considered anonymous.
Analytics cookies are considered technical if used only for optimization purposes and if the users' IPs are kept anonymous.

USE OF GOOGLE ANALYTICS ON THIS SITE

Google Analytics (hereinafter also simply "Analytics") is a statistics service offered by Google Inc. whose headquarters are at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Analytics allows you to track access to the Site and its administrators to generate and view data in aggregate and anonymous form in order to understand how visitors use the Site and to process statistics.

Sources of personal data

Google Analytics requires, for its operation, the presence on the pages of the website of a so-called tracking code. The purpose of this code is to identify, for the purposes highlighted below, the pages you visit during the browsing session on the Site.
In addition to the pages visited, the data collected may also include, by way of example and not limited to, the domain names and the type of browser of the computers used to connect to the website, the URI (Uniform Resource Identifier) ​​addresses of the resources requested, the time of the request, parameters regarding the operating system and the IT environment you use. These data do not, in any case, allow us to reach your identity due to their nature and the methods of their processing and are therefore to be considered anonymous.
As mentioned, analytics cookies are considered technical if used only for optimization purposes and if the users' IPs are kept anonymous. The interested party is informed that this site uses the free Google Analytics service. We remind you that the data is used only to have the data of the most visited pages, the number of visitors, the aggregate data of visits by operating system, by browser, etc. These parameters are stored on Google's servers which governs their Privacy.
As specified, this site does not use any type of cookie for user profiling. Third-party cookies are used instead, linked to the presence of "social plugins". Google Analytics has been anonymized, which allows statistics to be collected without profiling purposes. From each page of the site, you can access the extended privacy policy.

A user can disable Google Analytics while browsing using the add-on available for Chrome, Firefox, Internet Explorer, Opera and Safari available at this link. Remember that you can also manage your cookie preferences through your browser.

If you are using Internet Explorer
In Internet Explorer, click on “Tools” then “Internet Options”. On the Privacy tab, move the slider up to block all cookies or down to allow all cookies; then click OK.

If you use the Firefox browser
Go to the “Tools” menu of your browser and select the “Options” menu. Click on the “Privacy” tab, uncheck the “Accept cookies” box and click OK.

If you use the Safari browser
From the Safari browser select the “Edit” menu and select “Preferences”. Click on “Privacy”. Set the “Block cookies” setting to always “and click OK.

If you use Google Chrome browser
Go to the Chrome menu on the browser toolbar. Select “Settings.” Click “Show advanced settings.” In the “Privacy” section, click the “Content settings” button. In the “Cookies” section, select “Do not allow sites to store data” and check “Block cookies and third-party site data,” and then click OK.

If you use any other browser, look in the browser settings to see how to manage cookies.

Scalapay SRL

In order to offer you Scalapay SRL payment solutions, we will share some of your personal data with Scalapay, such as contact information and order details. In this way, Scalapay will verify that your purchase meets the criteria for using Scalapay solutions and will be able to offer you personalized payment options.
General information about Scalapay can be found on the website www.scalapay.com. Your personal data is processed in compliance with the applicable data protection legislation and according to the Scalapay privacy policy (www.scalapay.com/it/privacy).