Privacy Policy Web
Privacy Policy for the Processing of Personal Data – Website
1. Data Controller
The Data Controller for personal data is Barò Beauty Lab S.r.l., with registered office at Via G. Carducci no. 125 - 20099 Sesto San Giovanni (MI) and operational headquarters and showroom at Piazza Michele Ferrero 8, 12050 Alba (CN), Tax Code and VAT No. 14800490964
The Data Protection Officer (DPO), appointed pursuant to Articles 37 et seq. of EU Regulation 2016/679 (GDPR), is Omniconsulting S.r.l.s., with registered office in Turin, Via Roma 366, Tax Code and VAT No. 11868170017, emaildpo@barocosmetics.it.
2. Types of Data Collected
While browsing the website, various categories of personal data may be collected.
- browsing data (IP address, device information, access logs);
- data voluntarily provided by the user through contact or registration forms;
- data relating to preferences expressed while browsing;
- data collected through analytics tools and cookies.
3. Purposes of Processing
Personal data are processed for the following purposes:
- to enable browsing and the proper functioning of the website;
- to manage requests for information submitted through the website;
- to provide user support;
- to conduct anonymous statistical analyses of website usage;
- to prevent fraudulent use or unauthorized access;
- to send commercial communications where the user has given consent.
4. Legal Basis for Processing
The legal bases for processing personal data are:
- the performance of pre-contractual or contractual measures requested by the user;
- the legitimate interest of the Data Controller in website security and service management;
- the data subject’s consent for marketing purposes or commercial communications.
5. Processing Methods
Personal data are processed using electronic and telematic tools, in compliance with the principles of fairness, lawfulness, and transparency established by the GDPR.
Appropriate technical and organizational measures are adopted to ensure data security and prevent unauthorized access, loss, or unlawful use of the information.
6. Disclosure of Data
Personal data may be disclosed to third parties that provide technical or organizational services necessary for the operation of the website.
- hosting service providers;
- website maintenance and development companies;
- IT service providers;
- technical or legal consultants.
These parties act as data processors pursuant to Article 28 of the GDPR.
7. Data Retention
Personal data are retained for the time strictly necessary to achieve the purposes for which they were collected and in compliance with the obligations established by applicable law.
8. Data Subject Rights
The data subject may exercise the rights provided for under Articles 15–22 of EU Regulation 2016/679 at any time:
- the right to access personal data;
- the right to rectification or updating;
- the right to erasure of data;
- the right to restriction of processing;
- the right to object to processing;
- the right to data portability.
9. Complaint to the Supervisory Authority
The data subject has the right to lodge a complaint with the Italian Data Protection Authority – Piazza Venezia 11, 00187 Rome – www.garanteprivacy.it.