Access your Reserved Area to send your request
in accordance with Article 13 of the General Data Protection Regulation (EU) 679/2016 ("GDPR")
This Privacy Policy is valid from the date of publication (latest update: February 7, 2024). The Controller may make changes and/or additions to this Privacy Policy, including as a result of any subsequent regulatory changes and/or additions.
DATA CONTROLLER
Cap Design S.p.A. a socio unico with sole shareholder ("Cappellini" or "Controller"), a company subject to management and coordination activity by Haworth Italy Holding S.r.l. VAT no. 00976180968 with registered office in Via Busnelli, no. 5, 20821 Meda (MB) E-mail [email protected] .
DATA PROTECTION OFFICER
The Controller has appointed a Data Protection Officer ("DPO"), who can be contacted at the following address: [email protected].
DATA COLLECTION SOURCE
Your personal data (the "Personal Data" or the "Data") may be collected directly from you when you visit one of our showrooms located in the various countries of the world (the "Showroom"), during our events, when you browse on our website (the "Website"), or when you purchase one of our products (the "Products") at our Showrooms or through the Website.
***
1 - DESCRIPTION OF THE PROCESSING
The Data collected will be entered into our central database and we will process them, in the capacity of autonomous controller, to manage the sale of the Product online, for marketing and profiling purposes. The Data may also be collected by our associated and/or subsidiary companies and by our retailers or commercial partners that operate in Italy and abroad and in that case, they will be designated by us as processors.
With reference, on the other hand, solely to the management of sales and after-sales activities at some of our showrooms, the companies listed below will collect and process the Data in the capacity of autonomous controllers, in accordance with what is indicated in this privacy policy, where applicable (point 1.A and 1.D).
1.A - DATA PROCESSING CARRIED OUT FOR THE MANAGEMENT OF SALES AT THE SHOWROOMS
DATA CATEGORIES - PERSONAL AND CONTACT DATA name, surname, tax code, e-mail, address, telephone number, billing address, passport details for the Tax Free/Refund service - PURCHASE DATA type and price of Products purchased.
PROCESSING PURPOSE - To carry out the sale of Products at our Showrooms and to manage after-sales services (for example, returns, refunds, repairs, etc.).
MANDATORY OR OPTIONAL PROVISION OF DATA - Necessary. If you do not wish to provide your Data, the Controller will not be able proceed with the corresponding order or to manage the related Product after-sales services.
LEGAL BASIS OF PROCESSING - The need to perform a contract or to take steps prior to entering into a contract to which you are party, as well as the need to comply with legal obligations.
DATA STORAGE PERIOD: The Controller undertakes to erase your Data from its systems provided for the execution of the sale and management of the after-sales services 10 years after the date of the last purchase or from the last interaction with the Controller.
***
1.B - DATA PROCESSING CARRIED OUT ON THE WEBSITE
DATA CATEGORIES - PERSONAL AND CONTACT DATA name, surname, tax code, e-mail, telephone number, address, shipping address - PURCHASE DATA type and price of Products purchased - OTHER DATA personal data communicated on the specific text form on the Website.
PURPOSE OF PROCESSING - To carry out sales of Products on the Website (therein including, for example, the entry of Products on the wish list, the sharing at your request of the configuration of Products selected by you with the local retailer, delivery, etc.) and management of after-sales services (for example, returns, refunds, repairs, etc.).
MANDATORY OR OPTIONAL PROVISION OF DATA - Necessary. If you do not wish to provide your Data, the Controller will not be able proceed with the corresponding order or manage your request to share the chosen Products with the local retailer or manage the related Product after-sales services.
LEGAL BASIS OF PROCESSING - The need to perform a contract or to take steps prior to entering into a contract to which you are party, as well as the need to comply with legal obligations.
DATA STORAGE PERIOD: The Controller undertakes to erase your Data from its systems provided for the execution of the sale and management of the after-sales services 10 years after the date of the last purchase or from the last interaction with the Controller.
***
CATEGORIES OF DATA - PERSONAL AND CONTACT DATA name, surname, email, address, telephone number - OTHER DATA contractual and design documentation referring to you.
PURPOSE OF PROCESSING - To allow you to register as a customer on the Website and purchasing as a registered customer, and to access one of the reserved areas of the Website in order to use the respective services.
MANDATORY OR OPTIONAL PROVISION OF DATA - Necessary. If you do not wish to provide your Data, you will not be able to register as a customer or use the related services in the reserved areas of the Website.
LEGAL BASIS OF PROCESSING - The need to perform a contract or to take steps prior to entering into a contract to which you are party, as well as the need to comply with legal obligations.
DATA STORAGE PERIOD - The Controller undertakes to erase your Data from its systems provided for your registration and access to the reserved areas of the Website and for use of the related services, 10 years after the date of cancellation of the relevant registration.
***
CATEGORIES OF DATA - PERSONAL AND CONTACT DATA name, surname, email, phone number, country, region, city. Personal data communicated in the specific text form on the Website or to the mailbox of the Controller.
PURPOSE OF PROCESSING - To manage contact requests made via the specific Website page ("contacts") or by email to the Controller.
MANDATORY OR OPTIONAL PROVISION OF DATA - Necessary. If you do not provide these Data, it will not be possible for the Controller to process the requests sent.
LEGAL BASIS OF PROCESSING - The need to perform a contract or to take steps prior to entering into a contract to which you are party, as well as the need to comply with legal obligations.
DATA STORAGE PERIOD - The Controller undertakes to erase your Data from its systems provided in relation to requests submitted via the Website or by email 1 year after the date of provision.
***
APPLICATIONS - If you would like to submit to the Controller, via the Website, your application for a job with the Controller or one of the companies of the group to which the Controller belongs, your Data will be processed in accordance with the respective privacy policy, available at the following link: https://careers.poltronafrau.com/
***
1.C - DATA PROCESSING CARRIED OUT BY MEANS OF THE CUSTOMER RELATIONSHIP MANAGEMENT SYSTEM "CRM"
1) REGISTRATION AS A CUSTOMER
CATEGORIES OF DATA - PERSONAL AND CONTACT DATA name, surname, date of birth, email, address, telephone number.
PURPOSE OF PROCESSING - To allow you to register as a customer and to use the respective services (for example to participate to one of our events). You may make this registration to our Website without having to make an online purchase, at one of our showrooms or during one of our events.
MANDATORY OR OPTIONAL PROVISION OF DATA - Necessary. If you do not wish to provide your Data, you will not be able to register as a customer or to use the related services.
LEGAL BASIS OF PROCESSING - The need to perform a contract or to take steps prior to entering into a contract to which you are party, as well as the need to comply with legal obligations.
DATA STORAGE PERIOD - The Controller undertakes to erase your Data from its systems provided for your registration 10 years after the date of cancellation of the relevant registration.
2) MARKETING
CATEGORIES OF DATA - PERSONAL AND CONTACT DATA name, surname, email, address, telephone number.
PURPOSE OF PROCESSING - To send you marketing information about collections, exhibitions, and events, including through our newsletter, or allow you to participate in any customer satisfaction surveys and market research to improve the Products. These communications will be sent by email or telephone, including by automated means (SMS, social media messaging systems). We will carry out communications by automated means approximately no more than 2 times a month or on the occasion of particular initiatives (eg Salone del Mobile). You can also choose to be contacted exclusively via traditional methods, expressing your opposition to receiving communications through automated methods, by writing to [email protected].
MANDATORY OR OPTIONAL PROVISION OF DATA - Optional. If you do not wish to provide your Data, the Controller will be unable to keep you constantly updated on the special offers and promotions for its customers, or use the Data for market research, and statistical and customer satisfaction analyses.
LEGAL BASIS OF PROCESSING - Your explicit consent to the processing of Data for this purpose. If you have given your consent, you can withdraw it at any time by clicking on the unsubscribe button contained in the emails or newsletters received or sending an email to [email protected].
DATA STORAGE PERIOD - The Controller will erase the Data processed in order to send you marketing information, including customised information following classification or profiling based on the parameters described above, about collections, exhibitions, and events, as well as for the participation in customer satisfaction surveys and market research, 10 years after the collection of the Data, or until you object. To that end, the Controller has taken into consideration the type of goods offered for which it considers an average frequency of purchase by customers of one or a maximum two products per capita every 6-7 years. Therefore, shorter timescales for data analysis would prevent the offer of customised services. In any case, the Data will be stored for 10 years for the purposes of sales management and after-sales services.
3) COMMUNICATE DATA TO OTHER COMPANIES OF THE GROUP FOR MARKETING PURPOSES
CATEGORIES OF DATA - PERSONAL AND CONTACT DATA name, surname, email, address, telephone number
PURPOSE OF PROCESSING - To communicate your Data to other companies of the Group to which the Controller belongs, so that they can send you marketing information about collections, exhibitions, and events, including through newsletters in relation to its products and services, and to participate in any customer satisfaction surveys and market research to improve the Products.
MANDATORY OR OPTIONAL PROVISION OF DATA - Optional. If you do not wish to provide your Data, the Controller will not be able to communicate the Data to the other group companies for such purposes.
LEGAL BASIS OF PROCESSING - Your explicit consent to the processing of Data for this purpose. If you have given your consent, you can withdraw it at any time by clicking on the unsubscribe button contained in the emails or newsletters you receive or by writing to [email protected].
DATA STORAGE PERIOD - The Controller will erase the Data processed in order to send you marketing information, including customised information following classification or profiling based on the parameters described above, about collections, exhibitions, and events, as well as for the participation in customer satisfaction surveys and market research, 10 years after the collection of the Data, or until you object. To that end, the Controller has taken into consideration the type of goods offered for which it considers an average frequency of purchase by customers of one or a maximum two products per capita every 6-7 years. Therefore, shorter timescales for data analysis would prevent the offer of customised services. In any case, the Data will be stored for 10 years for the purposes of sales management and after-sales services.
4) CLASSIFICATION OF CUSTOMERS
CATEGORIES OF DATA - PERSONAL AND CONTACT DATA name, surname, age bracket, email, telephone number, country of residence - Product purchase channel (e.g., web, showroom).
PURPOSE OF PROCESSING - Classification of customers based upon a series of parameters, for the purposes of sending targeted commercial communications relating to the requirements of a certain category or bracket of which you form part (e.g., customers aged from 50 to 70 years old, residents of a specific region, etc.).
MANDATORY OR OPTIONAL PROVISION OF DATA - Optional. If you wish to object to the processing of your Data, it will not be possible for the Controller to keep you constantly updated on offers and promotions dedicated to certain categories of customers. If you have given your consent to receive promotional information in any case, you may therefore only receive generic newsletters.
LEGAL BASIS OF PROCESSING - The legitimate interest of the Controller in achieving the maximum efficiency of its marketing activities. We will send promotional communications taking account of your bracket or category only with your prior consent, which may be withdrawn at any time and without prejudice. You can exercise your right to object to the receipt of these communications at any time, immediately or at a later date, by clicking the unsubscribe button contained in the emails or newsletters you receive or by writing to [email protected].
DATA STORAGE PERIOD - The Controller will erase the Data processed in order to send you marketing information, including customised information following classification or profiling based on the parameters described above, about collections, exhibitions, and events, as well as for the participation in customer satisfaction surveys and market research, 10 years after the collection of the Data, or until you object. To that end, the Controller has taken into consideration the type of goods offered for which it considers an average frequency of purchase by customers of one or a maximum two products per capita every 6-7 years. Therefore, shorter timescales for data analysis would prevent the offer of customised services. In any case, the Data will be stored for 10 years for the purposes of sales management and after-sales services.
5) PROFILING OF CUSTOMERS
CATEGORIES OF DATA - PERSONAL AND CONTACT DATA name, surname, date of birth, age bracket, email, telephone number, country of residence - OTHER DATA profession, frequency and Product purchase channels (e.g., web, showroom), products viewed, catalogues requested, interests and data relating to your behaviour on our Website.
PURPOSE OF PROCESSING - Profiling of customers to assess your preferences, interests, characteristics, and consumption habits based upon a series of parameters, for the purposes of sending customised promotional communication or for a personalised purchasing experience in our Showrooms.
MANDATORY OR OPTIONAL PROVISION OF DATA - Optional. If you do not wish to provide your Data, it will not be possible for the Controller to keep you constantly updated on offers and targeted promotions with respect to your preferences, interests, characteristics, and consumption habits or to offer you a personalised purchase experience at our Showrooms. If you have given your consent to receive promotional information in any case, you may therefore only receive generic newsletters.
LEGAL BASIS OF PROCESSING - Your explicit consent to the processing of Data for this purpose. If you have provided consent, you may withdraw it at any time by writing to [email protected].
DATA STORAGE PERIOD - The Controller will erase the Data processed in order to send you marketing information, including customised information, following classification or profiling based on the parameters described above, about collections, exhibitions, and events, as well as for the participation in customer satisfaction surveys and market research, 10 years after the collection of the Data, or until you object. To that end, the Controller has taken into consideration the type of goods offered for which it considers an average frequency of purchase by customers of one or a maximum two products per capita every 6-7 years. Therefore, shorter timescales for data analysis would prevent the offer of customised services. In any case, the Data will be stored for 10 years for the purposes of sales management and after-sales services.
***
1.D - DATA PROCESSING CARRIED OUT FOR MARKETING PURPOSES FOLLOWING A SALE AT THE SHOWROOM OR ON THE WEBSITE
CATEGORIES OF DATA - PERSONAL AND CONTACT DATA name, surname, e-mail - PURCHASE DATA type of Products purchased.
PURPOSE OF PROCESSING - The sending of communications containing marketing offers related to Products similar to those already purchased (soft spam).
MANDATORY OR OPTIONAL PROVISION OF DATA - Optional. If you wish to object to the processing of your Data, it will not be possible for the Controller to keep you constantly updated on offers and promotions of products related to those already purchased.
LEGAL BASIS OF PROCESSING - The Controller's legitimate interest in developing relationships with its customers and increasing the volume of requests and sales of the Products. You can exercise your right to object to the receipt of these communications at any time, immediately or at a later date, by clicking the unsubscribe button contained in the emails or newsletters you receive or by writing to [email protected].
DATA STORAGE PERIOD - The Controller will erase the Data processed for the purposes of sending communications containing marketing offers related to Products similar to those already purchased (soft spam), 24 months after the date of each purchase, unless any objection is made before that period elapses and without prejudice to their storage for 10 years for the purposes of executing the sale and for the management of after-sales services.
***
2 – DATA PROCESSING METHODS AND ANY FURTHER STORAGE OF DATA
The Data will be collected and processed in compliance with the principles of fairness, lawfulness, and transparency, through manual or automated methods, always within the limits of the processing purposes described above and, in any case, in order to ensure the security and confidentiality of the Data. With respect to the storage of the data, the Controller has indicated the respective timescales in correspondence with each processing activity and it undertakes, in any case, to base the Data processing on principles of adequacy and minimisation, checking annually the need to store the Data for a period of time not exceeding what is necessary for the achievement of the purposes for which they were collected and processed. The Controller may store the Data to fulfil regulatory obligations, or to establish, exercise or defend a legal claim. Upon achieving the purposes for which the Data were collected and processed, the Controller will take the appropriate measures to make the Data anonymous, so as to prevent your identification, notwithstanding its right to continue using the Data anonymously for statistical purposes.
3 - ANY AUTOMATED DECISION-MAKING PROCESSES
As indicated above, the Controller carries out, based upon its legitimate interest, a classification of its customers for the purpose of sending information of a commercial nature on collections, exhibitions and events targeted relative to the needs of a certain category or bracket of which you form part. That process is carried out by breaking down the data subjects into non-invasive and non-discriminatory categories, such as country of residence (residents in the Lombardy region when, for example, identifying a category of data subjects interested in the opening of a new store in Milan), age bracket (e.g. customers aged from 50 to 70 if, for example, the product is aimed statistically at this age bracket), and purchase channels of Products (e.g. differentiating communications sent to mainly web customers from those who prefer physical stores). Following this analysis, which may also be carried out in automated form, the user may be classified into one or more groups with different characteristics and may receive from the Controller communications dedicated to that category which the Controller believes are in line with its requirements. In relation to this processing, the Controller has successfully conducted a balancing test in order to determine that the processing linked to the classification in question is carried out on the legal basis of the legitimate interest of the Controller in achieving maximum efficiency in its marketing activities. The Controller may also, with your consent, analyse your consumer habits over time, to assess in more depth what may be possible with a simple categorisation, such as products or initiatives responding to your tastes and preferences (for example, if, during a timeframe of 2 years, you demonstrate interest in one of our particular products or the line created by one of our designers, we will send you offers dedicated to that type of product and not others in which you are not interested or that do not meet your tastes and preferences). In this way we will be able to offer you a unique and customised purchasing experience even if you come to see us at one of our showrooms. In that case, our sales assistant will be able to recognise you and direct you in the most efficient manner to the product that you prefer. Of course, you can always ask our sales staff to show you different proposals. It is noted that the Controller has carried out a specific impact assessment of the personal data processing necessary for the profiling activities to guarantee respect of the principles of the GDPR, including non-discrimination, effectiveness, and absence of harmful consequences for the data subject.
4 - PERSONS AUTHORISED TO PROCESS THE DATA
The Data may be processed by persons appointed by the Controller who have been expressly authorised and have received adequate operating instructions in relation to the processing purposes set out above.
5 - POSSIBLE DATA RECIPIENTS
The Data will not be disseminated. The following entities may become aware of the Data in relation to the processing purposes outlined above and may process them, independently, as separate Data Controllers or as Data Processors duly appointed by the Controller (the list of those entities can be requested from the Controller by writing to [email protected]):
· Retailers or commercial partners of the Controller or Companies of the group to which the Controller belongs which, on our behalf, will collect the Data to be inserted in our customer relationship management system "CRM"; those entities will act as processors.
· Companies of the group of which the Controller is part to which we will communicate your Data for sending marketing information on collections, exhibitions, and events, by the aforementioned companies, in relation to their products and services; those entities will act as autonomous Data controllers and they will receive the same only where you have provided consent to the communication of Data.
· Companies of the group to which the Controller belongs for administrative and accounting purposes; those entities will act in the capacity of processors.
· Entities that may access the Data by virtue of EU law or the law of the Member State to which the Controller is subject; those entities will act in the capacity of autonomous controllers.
· Companies that carry out and provide additional services related to the processing purposes, banking operators, electronic payment carriers, credit card issuers, internet providers, couriers and shipping agents, companies that manage events or carry out newsletter mailing or market research activities, companies that offer data analysis services, companies that offer IT infrastructures and IT support and consulting services, legal or accountancy firms, and auditors; those entities will act in the capacity of processors or in some cases autonomous controllers;
· Purchasers or successors of the Controller in cases of merger, transfer, restructuring, reorganisation, dissolution or other sale or transfer of some or all of the assets of the Controller, in which the Data may be transferred; those entities will act as autonomous controllers and we will only communicate to them the Data necessary for the assessment of the operation based upon our legitimate interests.
6 - TRANSFER OF PERSONAL DATA ABROAD
Your Data will be processed and stored in our management and CRM database, whose servers are located in the territory of the European Union.
The Controller may share your Data with entities which may, however, be situated both inside and outside your country of residence and both inside and outside the EEA, as the Controller offers its products to customers in all countries in which it is present. In particular, your Data may be accessible to the sales managers and/or representatives at our showrooms for marketing and profiling purposes. For example: if you visit a showroom in a country other than your country of residence, the personal information will also be accessible by that showroom, so as to offer you products most in line with your requirements. In such a case, the Controller undertakes to:
· Ensure that the country to which the Data will be sent guarantees an adequate level of protection, as provided under Article 45 of the GDPR; or
· Comply with the standard contractual clauses for Data protection approved by the European Commission as to the transfer of personal Data outside the EEA in accordance with Article 46.2 of the GDPR.
For further information on the entities and countries involved, please send a request to the following email address: [email protected].
7 - YOUR RIGHTS IN THE CAPACITY OF DATA SUBJECT - COMPLAINT TO A SUPERVISORY AUTHORITY
In relation to the above Data processing, you can exercise at any time, by sending an email to [email protected], the following rights under the conditions and within the limits indicated in Articles 12 and 13 of the GDPR:
· Right of access (Art. 15 GDPR).
· Right of rectification of inaccurate data and completion of incomplete data (Art. 16 GDPR).
· Right to erasure of Data (Art. 17 GDPR).
· Right to restriction of processing (Art. 18 GDPR).
· Right to object to processing carried out in accordance with Art. 6, paragraph 1, letters e) or f) GDPR.
You also have the right to lodge a complaint with the Supervisory Authority, i.e., the Italian Data Protection Authority (known as (“Privacy Guarantor”) and/or other competent supervisory authorities (Art. 77 GDPR).
Moreover, if the processing is based on consent or a contract and is carried out by automated means, you have the right to receive your Data in a structured, commonly used, and machine-readable format and, if technically feasible, to transmit those Data to another Data Controller without hindrance under Article 20 of the GDPR.
You also have the right to object at any time to the processing of the Data, immediately or after the transfer of the Data, in relation to the sending by the Controller of unsolicited communications containing marketing offers related to Products similar to those already purchased (soft spam) directly to the email address provided during the purchase of Products, pursuant to Art. 130, paragraph 4 of Italian Legislative Decree no. 196/2003, as amended by Italian Legislative Decree no. 101/2018.
You can also choose to be contacted for marketing purposes exclusively via traditional methods, expressing your opposition to receiving communications through automated methods.
You have the right to withdraw the consent provided for marketing and/or profiling purposes at any time.
8 – MINORS
The Website and the Products are in no way intended for minors under the age of 18; therefore, the Controller does not carry out any collection and/or processing of personal data relating to such minors. In the event that personal data relating to minors are entered on the Website, the Controller will erase them.
Access your Reserved Area to send your request