CUSTOMERS' INFORMATION AND PRIVACY POLICY
(pursuant to Articles 13 and 14 of EU Regulation 2016/679 – “GDPR”)
1. Data Controller
The Data Controller is
Orologeria Luigi Verga Srl, with registered office at
Via Dogana 3 – 20123 Milan, VAT No. 04370140156, email address
info.amministrazione@verga1947.it, certified email address
luigivergaspa@pec.it (hereinafter, “the Controller”).
2. Type of data processed
The Data Controller may process the following personal data, depending on the contact method (physical store or website):
- Personal and contact details (name, surname, address, telephone number, email address);
- Tax and payment information (tax code, VAT number, bank details);
- Purchase and warranty data;
- Browsing data (IP addresses, access logs, browser type and device);
- Data provided via online forms (contact requests, newsletter subscriptions);
- Cookies and other tracking tools (see section 9).
Purpose and legal basis of the Processing
| Purpose |
Legal basis |
| a) Management of sales, invoicing, warranties, and after-sales assistance |
Performance of a contract (Article 6, paragraph 1, letter b) GDPR) |
| b) Fulfillment of tax, accounting, or administrative obligations |
Legal obligation (Article 6, paragraph 1, letter c) GDPR) |
| c) Management of requests for information or quotes via the website |
Implementation of pre-contractual measures (Article 6, paragraph 1, letter b) GDPR) |
| d) Sending communications relating to products similar to those already purchased ("soft marketing") |
Legitimate interest of the Data Controller (Article 6, paragraph 1, letter f) GDPR) |
| e) Sending newsletters or personalized promotional communications |
Express consent of the data subject (Article 6, paragraph 1, letter a) GDPR) |
| f) Anonymous statistical analysis of website visits |
Legitimate interest of the Data Controller (Article 6, paragraph 1, letter f) GDPR) |
| g) Protection of the Data Controller's rights (e.g., handling disputes or complaints)
|
Legitimate interest of the Data Controller (Article 6, paragraph 1, letter f) GDPR) |
4. Methods of processing
Data processing is carried out using computerized, electronic, and paper-based tools, in compliance with the principles of fairness, lawfulness, and transparency.
Adequate technical and organizational security measures are adopted to protect data from unauthorized access or improper use.
5. Nature of data provision
- The provision of data for contractual and legal purposes (points a–b–c) is mandatory. Failure to provide this information will prevent the purchase from being completed or the requested services from being provided.
- The provision of data for marketing purposes (points d–e) is optional and consent may be revoked at any time.
6. Data Recipients
Personal data may be disclosed to:
- tax, accounting, or legal advisors;
- credit institutions and payment service providers;
- IT companies that manage cash register, e-commerce, or hosting systems;
- service centers or suppliers for warranties and repairs;
- public entities or competent authorities within the limits of the law.
The data
will not be disclosed or transferred to third parties for unauthorized commercial purposes.
7. Data Transfer Abroad
Data is processed within the European Economic Area (EEA).
Any transfers to non-EEA countries will be carried out in compliance with Articles 44 et seq. of the GDPR, with adequate security guarantees.
8. Data Retention Period
- Contractual and tax data: 10 years from termination of the relationship.
- Marketing and newsletter data: until consent is revoked.
- Contact details for online requests: for the time necessary to respond to and handle the request.
9. Cookies and browsing data
The site uses
technical cookies necessary for its operation and, with prior consent,
analytical or profiling cookies (e.g., Google Analytics, Meta Pixel).
10. Rights of the Data Subject
The data subject may exercise, at any time, the rights provided for in Articles 15–22 of the GDPR, and in particular:
- right to access their data;
- right to rectification or erasure;
- right to restriction of processing or objection to processing;
- right to data portability;
- right to withdraw consent.
Requests should be sent to
info.amministrazione@verga1947.it
11. Minors
The Data Controller's services are not intended for minors under 18 years of age. Any data of minors will be processed only with the prior consent of their parents or legal guardians.
12. Updates to the Policy
This Policy may be updated at any time. The most recent version will be available at the point of sale and on the website
www.verga1947.it