中文
Galleria Continua
San Gimignano
Beijing
Les Moulins
Habana
Roma
Sao Paulo
Paris
Dubai

Who we are

Pursuant to article 13 of Regulation (EU) No. 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, also referred to as the General Data Protection Regulation (hereinafter, the “GDPR”), we inform you that the personal data that you voluntarily provide to Galleria Continua (hereinafter, also the “Company” or the “Data Controller”), while visiting the website www.galleriacontinua.com (hereinafter, the “Website”) will be processed in compliance with the current legislation on the protection of personal data, meaning the GDPR, the Legislative Decree No. 196/2003, as amended by the Legislative Decree No. 101/2018 (hereinafter, the “Privacy Code”) as well as the resolutions issued from time to time by the Italian Data Protection Authority (hereinafter, the “Data Protection Authority”), and, in any case, in compliance with the principle of confidentiality that inspires the activity of the Company.

1. Categories of personal data processed

The Data Controller will process the following categories of personal data provided by you:

  • browsing data, such as, merely by way of example, information related to the device used to browse the Website, IP address, cookies, etc.

This information is collected in order to enable the Data Controller to diagnose and manage the Website, as well as to determine how users have reached the Website. With reference to the use of cookies, Galleria Continua informs you that, in accordance with the Resolution of the Data Protection Authority of June 10, 2021, at the following link you can consult the Website Cookie Policy which contains all the information you need to understand, identify, use or delete cookies used on the Website;

  • identification data, such as, merely by way of example, first name, last name, username and password, date of birth;
  • contact details, such as, merely by way of example, e-mail address, telephone number, delivery address, city, or place of residence.

The Data Controller does not collect special categories of personal data (such as, for example, data relating to race or ethnicity, religious or philosophical beliefs, sexual life, sexual orientation, political opinions, union membership, information about your health, as well as genetic and biometric data). Information about criminal convictions and offences are not collected.

2. Purposes and legal basis for the processing

Personal data made available to the Data Controller through the Website may be used for the following purposes:

  1. fulfillments related to the use of the Website, such as, by way of example, the activation by registration, and subsequent technical security management and maintenance, of accounts in order to manage the access to the Website and/or the services made available therein, as well as of passwords or similar authentication credentials, the management and handling of your requests for any information submitted by filling in modules and/or forms on the Website, etc.;
  2. fulfillments related to legal obligations to which the Company is subject, including administrative and/or accounting obligations;
  3. fulfillments related to the need to ascertain, exercise or defend a right in judicial or administrative proceedings as well as in arbitration or conciliation procedures;
  4. carrying out promotional activities (so-called “marketing”) and sending promotional communications concerning the Company’s products and services by mail, Internet, telephone, e-mail – including newsletters and direct e-mail marketing – MMS, SMS.

The processing of your data for the purpose under lett. b) does not require your consent, as it is necessary for compliance with legal obligations to which the Company is subject, pursuant to art. 6, par. 1, lett. c) of the GDPR. The processing for the purposes under lett. a) and lett. c) does not require your consent, as it is necessary for the purposes of the legitimate interests pursued by the Company, pursuant to art. 6, par. 1, lett. f) of the GDPR. The processing for the purpose under lett. d) requires your consent, pursuant to art. 6, par. 1, lett. a) of the GDPR.

3. Methods of processing

The processing of personal data will be carried out through suitable instruments in paper, electronic and/or telematic form, with logics strictly related to the above purposes and, in any case, in a manner that guarantees security and confidentiality of the data.

4. Provision of data and consequences of refusal

The provision of personal data for the purpose under lett. b) of the previous paragraph 2 is necessary for the fulfillment of legal obligations. Any refusal and/or the provision of inaccurate and/or incomplete information could have as possible consequences the inability of the Company to fulfill all the requirements imposed by the current regulations to which it is subject.

The provision of personal data for the purposes under lett. a) and lett. c) of the previous paragraph 2 is necessary for the purposes of the legitimate interests of the Company stated above. Any refusal and/or the provision of inaccurate and/or incomplete information could have as possible consequences:

  1. the inability for the Company to carry out the fulfilments related to the use of the Website, including the management and processing of your requests for information submitted by filling in modules and/or forms on the Website;
  2. the inability of the Company to ascertain, exercise or defend a right in judicial or administrative proceedings as well as in arbitration or conciliation procedures.

The provision of personal data for the purpose under lett. d) of paragraph 2 above is voluntary; however, any refusal and/or the provision of inaccurate and/or incomplete information could have as possible consequences the inability for the Company to contact you and/or send you promotional communications advertising offers of goods and services by Galleria Continua.

5. Recipients or categories of recipients

The following subjects may become aware of your personal data:

  • subjects that provide to the Company services instrumental to the purposes set forth in paragraph 2 above (such as, merely by way of example, subjects, entities and/or companies that manage and/or participate in the management and/or maintenance of the Website) which, as the case may be, will operate as Data Processors pursuant to article 28 of the GDPR duly appointed by the Data Controller or as autonomous data controllers;
  • employees and associates of the Company, who will act as persons authorized to process personal data duly appointed by the Data Controller, and other companies belonging to the same Group of the latter;
  • any other subject to whom the data must be provided on the basis of an express legal provision.

In any case, the data will not be disclosed.

6. Transfer of Data to Third Countries

The data may be communicated and/or transferred abroad, in accordance with current regulations, including to countries outside the European Union.
In all such cases, the transfer is made on the basis of an adequacy decision of the Commission (Article 45 of the GDPR) or in accordance with standard data protection clauses or other appropriate safeguards under Articles 46 or 49 of the GDPR.

7. Duration of processing and retention period

Your personal data will be processed only as long as necessary in order to achieve the purposes for which they are processed.
The data will be retained according to the following criteria:

  • data processed for purposes related to the fulfillment of legal obligations referred to in lett. b) of paragraph 2 “Purposes and legal basis for the processing” of this policy, will be retained for a period of 10 years, unless the need for further retention arises, to enable the Company to defend its rights;
  • the data processed for the marketing purpose referred to in lett. d) of paragraph 2 “Purposes and legal basis for the processing” of this policy, will be retained for a maximum period of 24 months;
  • the data processed for the pursuit of the legitimate interests of the Data Controller referred to in lett. a) and c) of paragraph 2 “Purposes and legal basis for the processing " of this policy, shall be retained for a maximum period of time equal to the period of prescription of the rights enforceable by the Data Controller, as applicable from time to time.

8. Rights of the data subjects

In relation to their personal data, each data subject may exercise the following rights at any time, within the limits and under the conditions set forth in Articles 7 and 15-22 of the GDPR.

In order to exercise these rights, please contact the Data Controller at the email address privacy@galleriacontinua.com. such request will be answered appropriately without delay and, in any case, within one month from the receipt of the request.

Specifically, each data subject has the right to:

  • obtain confirmation as to whether or not personal data concerning him or her are being processed;
  • if a processing is taking place, obtain access to the personal data and information relating to the processing as well as request a copy of the personal data;
  • obtain the rectification of inaccurate personal data and supplementation of incomplete personal data;
  • obtain, if one of the conditions provided for in article 17 of the GDPR is met, the erasure of personal data concerning him/her;
  • obtain, in the cases provided for in article 18 of the GDPR, the restriction of processing;
  • receive the personal data concerning him/her in a structured, commonly used and machine-readable format and request their transmission to another controller, if technically feasible;
  • object at any time to the processing of personal data carried out in pursuit of a legitimate interest of the Data Controller;
  • withdraw at any time any consent that may have been given;
  • lodge a complaint with the Italian Personal Data Protection Authority, if he/she believes that his/her rights under the GDPR have been violated, in the manner indicated on the Data Protection Authority’s website accessible at www.garanteprivacy.it.

9. Data Controller and Data Processors

The Data Controller for the processing of personal data is Galleria Continua S.r.l., in the person of the legal representative pro tempore, with registered office in Via del Castello 11 - San Gimignano, 53037 (SI)(Italy).

The updated list of Data Processors is available at the Data Controller’s office and can be requested by sending a communication to the email address privacy@galleriacontinua.com.

Last Update: april 2023.