Privacy Policy

PRIVACY POLICY

PURSUANT TO ARTICLE 13 OF REGULATION (EU) 2016/679 ("GDPR")

The scope of this privacy policy is to describe the purposes and methods of the processing of personal data provided directly by B2B customers (where company-related data relates to natural persons or otherwise falls under the definition of personal data under applicable data protection laws) and/or its representatives, employees, collaborators and contact persons (hereinafter, the "Users") whenever they interact with Böllhoff S.r.l, or automatically collected during the use of Böllhoff S.p.A.'s eShop available at eshop.boellhoff.it (hereinafter, the "eShop").

 

1. DATA CONTROLLER

The data controller is Böllhoff S.r.l., Tax Code and VAT No. 07228650151, located at Via Monferrato, 6/8, 20094, Corsico (Milan), Italy (hereinafter, "Böllhoff", "Company" or "Data Controller"), e-mail: to info_it@bollhoff.com.

 

2. TYPE OF DATA PROCESSED

The eShop process personal data of the Users’s professional activity only to the extent necessary to achieve the purpose pursued with the data processing. Specifically:

  1. Data voluntarily disclosed by Users

The following personal information will be required to register for the eShop:

  • Full name;
  • Corporate name;
  • E-mail address;
  • tax code;
  • VAT number;
  • telephone/fax address.
  1. Navigation data

The computer systems and software procedures used to manage the eShop collect, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols.

This category of personal data includes the IP addresses or domain names of the computers used by Users who connect to the site, to the addresses in URI (Uniform Resource Identifier) notation of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters related to the Users' operating system and computer environment.

These data, necessary for the use of the eShop, are processed for the sole purpose of obtaining statistical information on the use of the services (number of visitors per hour or day, geographical areas of origin, etc.) and to control the proper functioning of the services offered.

Navigation data do not persist for more than 7 days and are deleted immediately after their aggregation unless judicial authorities need to ascertain criminal offenses.

 

Cookie Policy

The eShop uses cookies, which are necessary for the display of the website.

Cookies are text files that are stored in the Internet browser or by the Internet browser on the User's computer system and through which certain information flows to the site that places the cookie.

The eShop does not use cookies for marketing purposes or for advertising tracking. Flash cookies are also not used. The Users data collected by technically necessary cookies are not used to create user profiles. A so-called profiling of the user does not take place.

The following data are stored and transmitted in the cookies, for example:

  • language settings;
  • items in a shopping cart;
  • log-in information;
  • indication of origin of the cookie.

Moreover, technically unnecessary cookies are also used on the eShop within the scope of google Analytics.

However, the provision of all cookies can be disabled by intervening on the settings of your browser. It is worth pointing out, however, how intervening on these settings could make the eShop unusable if you block cookies that are essential for the delivery of our services. In any case, each browser has different settings for disabling cookies. Below are links to instructions for the most common browsers: Microsoft Edge, Apple Safari, Google Chrome, Mozilla Firefox.

The so-called session cookies used by Böllhoff are automatically deleted when you log off or close your browser.

For more information on the Cookie Policy please view the policy found at the following link: https://www.boellhoff.com/it-it/informativa-data-protection/.

 

 

3. PURPOSE, LEGAL BASIS AND NATURE OF DATA PROCESSING

 

Purpose

Legal Basis

Nature

A.

Use the eShop, sign up, place orders.

This purpose includes the processing of personal data carried out to enable you to use the eShop, register, and order products.

 

(i)    Performance of a contract to which the data subject is a party

The provision of your data is mandatory.

Failure to communicate would result in the inability to use the eShop, as well as their services.

B.

Receipt of marketing communications, including newsletters and information with commercial content.

This purpose includes keeping up to date with Böllhoff news through commercial and direct marketing communications and information about our services and offers, discounts and any other promotional and loyalty initiatives adopted, through fully automated contact systems.

(i)             Express consent

Providing your information is optional. However, failure to provide it may result in your inability to stay up to date on Böllhoff news, discounts, and offers.

The only data required for sending the newsletter is your e-mail address. The provision of additional data marked separately (first name, last name) is voluntary and serves to be able to address you personally.

 

C.

Quality surveys.

This purpose includes the ability to evaluate the degree of quality offered through the eShop and improve the services offered, in compliance with company certifications (i.e. ISO).

(ii)            Express consent

The provision of your data is optional.

However, failure to communicate would result in the inability to evaluate the services offered by the eShop.

D.

Suppliers.

This purpose includes: (i) providing information related to User’s requests; (ii) managing administrative, communication and logistics services performed by the Data Controller; (iii) sharing billing data and all procedures related to payments made through the eShop.

(iii)           Performance of a contract to which the data subject is a party

The provision of your data is mandatory.

Failure to communicate would result in the inability to use the eShop, as well as their services.

E.

Exercise of a right in court.

This purpose includes the possibility of processing personal data if it is necessary to exercise a right in the competent courts or by defending ourselves against possible disputes.

(i)          Legitimate interest

The provision of your data is mandatory.

Failure to notify would result in the inability to exercise the Company's right of defense.

 

4. PROCESSING METHODS AND DATA RETENTION PERIOD

The personal data of the Users will be deleted as soon as they are no longer necessary to achieve the purpose for which they were collected. At the end of this period, they will be kept only in execution of the relevant legal obligations, for administrative purposes and/or to assert or defend one's right in court.

Moreover, Users can always withdraw the consent to the processing of their personal data.

Personal browsing data and data acquired using the eShop will not be retained for more than 7 days.

Personal data contained in the account will be deleted only at the request of the person concerned.

 

5. CATEGORIES OF RECIPIENTS OF PERSONAL DATA

The personal data processed may be disclosed to the following parties:

  • those who can access the data by virtue of legal provisions provided for by the law of the European Union or the law of the member state to which the Data Controller is subject;
  • subjects that carry out purposes auxiliary to the activities and services referred to in the appropriate paragraph, e., companies that offer advertising, marketing and communication services, companies that offer IT infrastructure and IT support and consulting services as well as design and implementation is software and Internet sites, the companies that offer services useful to customize and optimize our services, companies that offer data analysis and development services (including those related to users' interactions with our services), service centers, companies or consultants responsible for providing additional services to the Data Controller, within the limits of the purposes for which they were collected almost.

Moreover, our employees may also learn of your personal data, if they are previously designated as individuals acting under the authority of the Data Controller in accordance with Article 29 of the GDPR or as System Administrators.

As for the transfer of personal data to third parties, as general rule, it does not take place. The transmission to third parties is allowed only in the following cases:

  • when there is the express consent of the Users to the processing of their personal data, in compliance with the contractual relationships established between the Company and the Users through the use of the eShop, for example, the data may be communicated to transport companies for the delivery of the ordered goods;
  • when the processing of personal data provided by Users is necessary to fulfill a legal obligation to which the Data Controller is subject, with the express consent of the Users;
  • when disclosure is necessary to safeguard legitimate interests or the fundamental rights and freedoms of the Users that require the protection of personal data.

In addition, the Company does not process personal data of individuals under 14 years of age.

 

6. TRANSFER OF DATA TO THIRD COUNTRIES

In principle, data will not be transferred to third countries outside the European Union ("EU") and/or the European Economic Area ("EEA"). If, due to changed needs, the data should be transferred to entities outside the EU or outside the EEA, the Company ensures that the transfer of personal data to such entities will take place only to countries that guarantee an adequate level of protection, in cases where such adequacy is established by a decision of the European Commission or guaranteed on the basis of contractual instruments that ensure the implementation of technical and organizational security measures suitable for the protection of personal data such as the standard contractual clauses prepared by the EU Commission.

 

7. RIGHTS OF THE DATA SUBJECT

In accordance with the GDPR, if the legal prerequisites are met, Users have the right to ask the Data Controller at any time for access to, rectification or deletion of personal data or to object to the processing in the cases provided by Article 21 of the GDPR.

In addition, the Users have the right to object at any time, on grounds relating to their particular situation, to the processing of personal data carried out in accordance with Article 6, paragraph 1, letters (e) and (f) of the GDPR.  

Furthermore, Users have the right to request the restriction of processing in the cases provided by Article 18 of the GDPR, as well as to obtain in a structured, commonly used and machine-readable format the personal data concerning the Users in the cases provided by Article 20 of the GDPR.

These rights may be exercised within the limits of the provisions of Article 2-undecies (limitations to the rights of the data subject) of the Legislative Decree no. 196/2023 (hereinafter, Privacy Code).

Moreover, Users always have the right to lodge a complaint with the competent supervisory authority (Garante per la Protezione dei Dati Personali), pursuant to Article 77 of the GDPR, if they consider that the processing of the personal data breaches current regulations.

Requests to exercise the above rights and/or any requests for information on the processing of personal data may be addressed to the Data Controller by sending a communication to the registered office at via Monferrato, 6/8 20094 Corsico (Milan), Italy, or by sending an e-mail to info_it@bollhoff.com.

 

8. UP-TO-DATENESS AND AMENDMENT OF THIS PRIVACY POLICY

It should be noted that the Company does not carry out processing operations other than those expressly authorized and/or requested by Users, the Privacy Policy may be subject to change to comply with new legal provisions or the Company's changed personal data processing policies.

Any updated version of this Privacy Policy will be made available on the eShop in the dedicated section.

Moreover, the Company encourages all Users to consult the eShop to be updated on the latest version uploaded.