PRIVACY POLICY
POLICY FOR PROCESSING OF PERSONAL DATA
Pursuant to and by the effect of Article 13 of the New European Regulation 2016/679 concerning the protection of individuals with regard to the processing of personal data (GENERAL DATA PROTECTION REGULATION – GDPR).

As required by the General Data Protection Regulation of the European Union (GDPR 2016/679, Article 13), before proceeding with processing, the interested party (User of the website rattiboutique.com) is informed that personal data collected through the website are subject to processing by the Company through IT and/or telematic tools, for the purposes indicated in this policy.

To this end, the User is presented with the Privacy Policy prepared by RATTI SRL. (hereafter as “RATTI” or “the Company” or “the Data Controller”), creator and promoter of the activities available on the website rattiboutique.com.
DATA CONTROLLER
The Data Controller for personal data is RATTI SRL. – registered office in Via Rossini, 71 – 61121, Pesaro, Italy – email [email protected].
For further information regarding the rights of the interested party, please consider the paragraph entitled “Rights of Interested Party” of this policy.

INFORMATION PROCESSING
The personal data subject to processing is collected directly by RATTI SRL or by third parties expressly authorized by the Data Controller, or communicated by the Company to such third parties for the pursuit of the purposes described below.

LEGAL BASIS AND PURPOSE OF PROCESSING
The personal data provided by the User when browsing the website rattiboutique.com are processed by the Data Controller in accordance with the current regulations for the protection of personal data.The legal basis of the processing is identified in the provision of its services by the Company, in the management and facilitation of the website, as well as in the establishment, execution and possible termination of online sales contract concluded between the parties, and in the obligations of the same contract connected either directly and/or indirectly deriving from it. The processing of your personal data by RATTI SRL is aimed at pursuing the following purposes:

1 )SUBSCRIPTION TO THE RATTI BOUTIQUE NEWSLETTER:
In the case that you decide to subscribe to the “RATTI BOUTIQUE Newsletter”, only after your express and specific consent, your personal data will be processed by the Data Controller for sending of commercial or promotional communications, relative updates, for example, to the latest trends, new arrivals, exclusive offers, special events and promotions. To unsubscribe from the newsletter simply click on the unsubscribe link at the bottom of the emails received or by writing to [email protected].

2) REGISTRATION ON RATIBOUTIQUE.COM:
In the case that you decide to register on the website rattiboutique.com, only after your express and specific consent, personal data will be processed by the Data Controller for the purpose of registration on rattiboutique.com. In particular, in providing your name, last name, email address and the setting of an access password, these will be processed for the creation of your personal account, to speed up the purchase process, to allow you to view the status of orders and receive updates on purchases made, as well as change personal settings and update your account, view the history of returns and requests for the exchange of goods, save favorite items in your Wishlist and allow you to join at a later time, if the desired, to the loyalty program, RATTIBOUTIQUE VIP PROGRAM.

3) ONLINE SHOPPING ACTIVITIES:
The personal data provided will be used for the establishment, management, execution and/or conclusion of the online sales contract, including the possibility to send e-mails in case the purchase has not been finalized for technical issues or abandoned cart, to inform the clients about it. The data you provide will be processed by the Data Controller for the purpose of managing the purchase order with reference to, for example, payment, shipment, management of returns, customer support, administrative and accounting purposes related to the management of the order and the fulfillment of obligations under the current legislation. In case of payment by credit card, the fundamental information for the execution of the transaction (credit/debit card number, expiration date, security code) will be processed by payment gateway NEXI provided by Intesa San Paolo Bank or using an encrypted protocol and without any third parties being able to access it in any way. This information will never be displayed or stored by the seller RATTI SRL.

4) PROFILING OF THE PHYSICAL PERSON:
Only after your express and explicit consent, the personal data you provided may be processed by the Data Controller for profiling activities, or analysis of your preferences aimed at creating personalized content and offers.

NATURE OF PROCESSING
In relation to the purposes referenced in point 1) of the previous section, providing your personal data and consent to its processing is optional. Failure to provide consent will make it impossible for RATTI SRL to allow you to subscribe to the “RATTI BOUTIQUE Newsletter”, to send commercial or promotional communications, updates on, for example, latest trends, new arrivals, exclusive offers, special events and promotions.

If you decide to proceed with the newsletter subscription through the section of the website solely dedicated to this activity, the provision of your personal data and consent to their treatment is mandatory.

Failure to provide the consent will make it impossible for RATTI SRL to allow you to subscribe to the “RATTI BOUTIQUE Newsletter”, to send commercial or promotional communications, updates on, for example, latest trends, new arrivals, exclusive offers, special events and promotions.

In relation to the purposes referenced in point 2) of the previous section, providing your personal data and consent to its processing is mandatory.

Failure to provide consent will make it impossible for RATTI SRL to allow you to register with rattiboutique.com, create a personal account, speed up the purchase process, view the status of orders and receive updates on purchases, the possibility to update personal settings and account preferences, view the history of returns and exchange requests, save favorite items in the Wishlist or to enroll in later, if you so wish, the loyalty program RATTI BOUTIQUE VIP PROGRAM.

In relation to the purposes referenced in point 3) of the previous section, providing your personal data and consent to its processing is optional.

Failure to provide your consent will make it impossible for RATTI SRL to allow you to join the loyalty program RATTI BOUTIQUE. In relation to the purposes referenced in point 4) of the previous section, providing your personal data and consent to its processing is mandatory.

Failure to provide the consent will make it impossible for RATTI SRL to proceed with the establishment, management, execution and/or conclusion of the online sales contract, therefore making it impossible to perform, for example, activities related to payment, shipment, management of returns, customer support, administrative and accounting purposes related to the management of the order and the fulfillment of obligations under current legislation.

In relation to the purposes referenced in point 5) of the previous section, providing your personal data and consent to its processing is optional.

Failure to provide consent will make it impossible for RATTI SRL to perform profiling activities, or to perform analysis of your preferences aimed at creating personalized content and offers.

PERSONAL DATA PROCESSING
The Data Controller processes the personal data provided by the User when browsing the website rattiboutique.com, in the event of any registration/subscription to the services/programs made available by RATTI SRL and/or the possible purchase of goods made available by RATTI SRL. Examples of personal data are name, last name and email address, in addition to the data necessary for the conclusion of the online sales contract, such as: the functional data for the execution of payment, shipment and exchange of purchased goods.

METHODS OF PROCESSING AND STORING DATA
The processing of personal data is performed by the Data Controller in compliance with the provisions of the current legislation on Privacy. The Data Controller processes personal data using IT and/or telematic tools and with organizational and logical procedures strictly related to the purposes indicated in this policy, as well as adopting the appropriate security measures to prevent access, disclosure, unauthorized modification or destruction of personal data, its loss and its illicit and incorrect use. However, the Company cannot guarantee its Users that the measures taken for website security and the transmission of data and information on the website are capable of limiting or excluding any risk of unauthorized access or loss of data by devices pertaining to the User. For this reason, it is suggested that the Users of the website make sure that their computer is equipped with adequate software to protect the transmission of data (such as updated antivirus) and that its Internet provider has adopted appropriate measures for the security of the transmission of data on the network. The Company also undertakes to process the data according to the principles of correctness, lawfulness and transparency, to collect the data to the extent necessary and exact for processing and to allow its use only by personnel for authorized purposes. The management and storage of personal data acquired will take place in archives or on servers located within the European Union owned by the Data Controller and/or by third-party companies appointed as External Data Processor for processing and, in any case, currently located in Italy.

In relation to the different purposes for which data is collected, personal data will be kept for the time strictly necessary to achieve that purpose and, in any case, in accordance with the current relevant regulations.

In any case, the Company will take care to avoid the use of data indefinitely by proceeding, on a regular basis, to verify appropriately the effective permanence of the interest of the User to which they refer.

DATA PROCESSORS AND RECIPIENTS
The data collected will not be disseminated in any way, but will be treated within the limits and for the purposes described by the employees of the Company on the basis of appropriate operating instructions (for example, administrative, commercial, marketing, legal personnel, system administrators, etc.). Some data processing may also be performed by third parties, appointed as External Data Processors for processing, of which the Data Controller relies on or could be used in the management of the contractual relationship, the provision of services offered and organizational needs of its activities. In particular, the data could be communicated to:

a) Persons, public and private, that can access the data by virtue of the provision of law, regulation or community legislation, within the limits set by these rules;

b) Persons who need access to data for purposes related to the contractual relationship existing between the parties, within the limits strictly necessary for the performance of auxiliary tasks (such as, for example, banks and lenders, technical service providers, hosting providers, IT companies, communication agencies, mail carriers and shipping companies);

c) Consultants, within the limits necessary for carrying out their professional duties.

The updated list of External Data Processors and other persons authorized to process the data is kept at the Data Controller’s registered office and is available to the interested party, following a request sent via email to [email protected].

TRANSFER OF DATA ABROAD
The management and storage of personal data will be carried out on servers of the Owner and/or third-party companies duly appointed as External Data Processors located within the European Union.

Your personal data may be transferred abroad, in accordance with the provisions of current legislation, even in countries outside the European Union.

The transfer to countries outside the EU, in addition to cases in which this is guaranteed by an Adequacy Decisions by the Commission, is carried out in such a way as to provide appropriate and opportune guarantees pursuant to Articles 46, 47 or 49 of the Regulation.

Rights of Interested Party – As the interested party, you may exercise, at any time, the rights provided to you in Articles 15, 16, 17, 18, 20 and 21 of the GDPR which, in particular, confer the rights to:

a) Obtain from the Data Controller, pursuant to Article 15, confirmation of the existence or not of personal data being processed and, in this case, obtain access to the data and information such as: (i) the purposes of the processing; (ii) the categories of personal data; (iii) the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients located in Third Countries or International Organizations; (iv) when possible, the retention period of the personal data provided or, if not possible, the criteria used to determine this period;

b) Obtain from the Data Controller, pursuant to Article 16, the correction of inaccurate personal data without undue delay; taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, by providing an additional declaration;

c) Obtain from the Data Controller, pursuant to Article 17, the deletion of their personal data without undue delay. The Owner has the obligation to cancel, without undue delay, personal data if there is one of the reasons indicated in paragraph 1 of Article 17;

d) Obtain from the Data Controller, pursuant to Article 18, restriction of processing when one of the hypotheses governed by paragraph 1 of Article 18 occurs;

e) Obtain from the Data Controller, pursuant to Article 20, the portability of data or to receive in a structured, commonly used and machine-readable format, their personal data provided to a Data Controller. The Data Subject also has the right to transmit such data to another Data Controller without impediments by the first Data Controller to whom it has provided them, if the conditions indicated in Article 20 paragraph 1 are met. Finally, the Data Subject has the right to obtain the direct transmission of personal data from one Data Controller to another, if technically feasible;

f) Object to, in whole or in part, pursuant to Article 21, the processing of their personal data.

To exercise these rights, the User can send their requests to [email protected].

It should also be noted that the Data Subject has the right to revoke the consent at any time without prejudice to the lawfulness of the processing based on the consent given prior to the revocation, without prejudice to the consequences indicated above regarding a refusal to provide such personal data. The Data Subject also has the right to lodge a complaint with a Control Authority.

You can make requests regarding these rights by contacting the Data Controller at the email address [email protected].

RATTI SRL will respond to requests made by the interested party within one month, except in cases of particular complexity, for which it may take up to a maximum of three months. In any case, the Data Controller will provide the interested party with the reason for the delayed response within one month of the request. The outcome of the request will be provided in writing or in electronic format. In case of request for rectification, cancellation and limitation of processing, the Data Controller will communicate the results of the requests received by the Data Subject to each of the recipients of their data, unless this proves impossible or involves a disproportionate effort.

The Company specifies that a contribution may be requested from the Interested Party if the applications manifest to be unfounded, excessive or repetitive; in this regard, the Data Controller will provide a register to track the requests for intervention.

CHANGES TO THIS POLICY
The data controller reserves the right to make changes to this Privacy Policy at any time by giving notice to users on the website rattiboutique.com. Therefore, please consult this page often, referring to the date of last modification indicated at the bottom of the policy. In case of non-acceptance of the changes made to this Privacy Policy, the Data Subject may request the Data Controller to delete their personal data. Unless otherwise specified, the previous Privacy Policy will continue to apply to personal data collected until then.

Privacy policy updated on 20/10/2020

    • COOKIE POLICY


RATTI Srl, with headquarters in Pesaro, Via Rossini, 71 is the Data Controller.

WHAT COOKIES ARE
Cookies are small text aggregates locally recorded in the temporary memory of the user's browser for variable periods of time depending on the need. Through cookies it is possible to semi-permanently record information related to preferences and other technical data, that allow easier navigation and better ease of use and effectiveness of the site itself. For example, cookies can be used to assess if a connection has already been made between the computer and our website, in order to highlight the news or keep the "login" information. To guarantee the user, only the cookie stored on his/her computer is identified. To make the user's navigation on our website as convenient as possible, and to present our range of products, we use cookies or equivalent computer codes. We also use analysis tools for usability which, by tracking the user actions, allow us to understand how our website is used and improve its functionality and design.

TYPES OF COOKIES
Cookies are divided into two families:

- Those installed by the owner or manager of the website, named first party cookies

- Those installed by managers unrelated to the website, named third-party cookies

The responsibility and management of first-party cookies is directly assumed by the owner.

The responsibility and management of third-party cookies instead falls on their respective owners and managers, who must offer adequate rejection mechanisms in their own privacy policy.

They can also be identified in:

  • NAVIGATION AND FUNCTIONAL COOKIES - Navigation cookies are necessary for the correct functioning of the website and allow to view contents on the device in the language of the country from which the user has chosen to connect. If the user is registered, they allow to access to the services offered and to recognize the visitor during next accesses. The Functional cookies improve the navigation's quality. Other technical cookies can be used to monitor data traffic, in order to identify any fraudulent transaction. Disabling these cookies may not be technically possible because they allow the Owner to try to prevent any fraud
  • PROFILING COOKIES OF THIRD-PARTY COMPANIES - Profiling cookies are used to create the user profile with the purpose of sending commercial messages based on his/her preferences, expressed or detected during the visit to the site, or again, to improve the website's navigation thus providing experiences more aligned with the user's interests. RATTI Srl does not have control of the information provided as it is totally controlled by third-party companies, as described in the corresponding privacy policies.
  • STATISTICAL COOKIES OF THIRD-PARTY COMPANIES - Statistical cookies are used to elaborate statistical analysis based on the users' browsing habits. The results of these analysis are used anonymously and for statistical purposes only. RATTI Srl uses third-party cookies.

 
COOKIES USED BY RATTI SRL AND THEIR PURPOSES
First-party technical cookies for the proper functioning of the site

Nome Cookie

Dominio

Tipo

Durata

_gat

rattiboutique.com

HTTP Cookie

Sessione

_gid

rattiboutique.com

HTTP Cookie

Sessione

_ga

rattiboutique.com

HTTP Cookie

 2 anni

_unam

rattiboutique.com

HTTP Cookie

Sessione

__sharethis_cookie_test_

rattiboutique.com

HTTP Cookie

Sessione

IDE

rattiboutique.com

HTTP Cookie

 

OTHER COOKIES:

Nome Cookie

Dominio

Tipo

Durata

__cfduid

 

HTTP Cookie

Sessione

__stid

.sharethis.com

HTTP Cookie

Sessione

fr

.facebook.com

HTTP Cookie

 2 anni

__cfduid

.tawk.to

HTTP Cookie

Sessione

IDE

.google.com

HTTP Cookie

 2 anni

 

BLOCKING COOKIES THROUGH THE BROWSER SETTINGS
Cookies can be blocked and cancelled with functionalities made available by individual browsers. Links to the main browsers are shown below:


• Internet Explorer - http://windows.microsoft.com/en-gb/windows-vista/block-or-allow-cookies

• Chrome - https://support.google.com/chrome/answer/95647

• Firefox - https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences

• Safari - http://support.apple.com/kb/PH17191