Privacy policy

PRIVACY POLICY

Alpinestars S.p.A., as data controller, wishes to inform users of the website https://eu.alpinestars.com (hereinafter, the "Website") about the processing of their Personal Data (as defined below), pursuant to Legislative Decree No. 196/2003 - as subsequently amended and supplemented (hereinafter, the "Privacy Code") - and Regulation (EU) No. 679/2016 (hereinafter, the "GDPR").

We are providing this notice not only to comply with the legal obligations regarding the protection of personal data under the GDPR, but also because we believe that the protection of personal data is a fundamental value of our business activities and we want to provide you with any information that may help you protect your privacy and control the use that is made of your personal data.

We may amend or update this privacy policy (hereinafter, the "Privacy Policy") from time to time by posting a new version of this Privacy Policy on the Website, including as a result of any subsequent changes and/or additions to the law. In any event, any changes, or updates to this Privacy Policy will be communicated to you in advance.

  • DATA CONTROLLER

Alpinestars S.p.A., with registered office in V.le Fermi, 5, 31011, Asolo (TV), Italy, Tax Code and VAT No. 01171110263 (hereinafter, the "Company" or "we"), as owner of the Website, is the data controller of your Personal Data (as defined below).

You can contact us at privacy@alpinestars.com.

  • SCOPE OF APPLICATION

This Privacy Policy covers the processing of your Personal Data (as defined below) in connection with:

  1. your use of the Website, when you, for instance:
    1. browse the Website;
    2. register on the Website by creating a personal account;
  • search for products or services;
  1. complete questionnaires or participate in surveys on the Website;
  2. complete forms available on the Website to participate in sweepstakes;
  1. "E-Commerce Activities", when you, for instance:
    1. make purchases on the Website, with or without creating a personal account;
    2. add or remove items from your shopping cart;
  • enter the information necessary to have the product you purchased delivered to the address you chose;
  1. make payments for the purchase of the product of your choice;
  2. make returns of products;
  3. contact our customer service for more information about your orders.
  • WHAT PERSONAL DATA DO WE PROCESS?

We may process the following categories of Personal Data (as defined below) relating to you:

  1. personal data collected automatically in connection with your use of the Website, such as:
    1. connection data;
    2. your IP address, domain name and other parameters relating to your browser, device, computer environment and operating system;
  • your login and passwords;
  1. your history of use of the Website, including the content you have viewed or searched for and the length of time you have been browsing certain pages, and page interaction information (such as scrolling, clicks and cursor movements on pages);
  2. the addresses in URI (Uniform Resource Identifiers) notation of the requested resources; and
  3. the time of the request, the method used to send the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (e.g., successful, error, etc.).

      (hereinafter, jointly referred to as the "Browsing Data").

The Browsing Data collected through cookies will be processed in accordance with the Cookie Policy, available at https://eu.alpinestars.com/pages/cookie-policy.

  1. personal data provided directly by you in connection with the use of the Website and with the E-Commerce Activities, such as:
    1. your first and last name(s);
    2. your date of birth;
  • your postal address;
  1. your email address;
  2. your telephone number;
  3. information relating to your means of payment;
  • any additional data you may provide us in the event of contact and/or information requests, or, for instance, in the event of your participation in surveys, promotions and sweepstakes offered on the Website.

The personal data listed above, together with the Browsing Data, are hereinafter referred to as the "Personal Data".

 

We will not process special categories of Personal Data. The term "special categories of personal data" means data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic and biometric data intended to uniquely identify an individual, and data relating to an individual's health or sexual life or sexual orientation.

  • WHAT ARE THE PURPOSES AND LEGAL BASES OF THE PROCESSING OF PERSONAL DATA?

We carry out the processing of the categories of Personal Data listed above, in the performance of our economic and commercial activities, for specific purposes and under certain legal bases, as better described below.

  1. Contractual Purposes

We will process your Personal Data, on the basis of the need to perform the contract between you and the Company or in order to take steps at your request prior to entering such a contract (Article 6, paragraph 1, letter b) of the GDPR), for the following purposes:

  1. to enable you to use the Website;
  2. in the context of the E-Commerce Activities, including but not limited to:
    1. to conclude, execute and/or terminate the sales contract existing between you and the Company, following a purchase made by you on our Website, with or without the creation of a personal account;
    2. to manage your payments and related invoicing;
  • to manage purchase orders, ship and deliver the products you have purchased and manage purchase returns if requested by you;
  1. to provide you with the information and assistance you request for the use of the Website and in relation to the E-Commerce Activities;
  2. to communicate with you regarding the E-Commerce Activities and the use of the Website; and
  3. to handle any complaints and requests, to send you service communications and updates, both through traditional communication tools such as paper mail and through remote communication tools such as, for instance, telephone, SMS, banners and other remote communication tools.

The purposes listed above are jointly referred to as the "Contractual Purposes" and your express consent is not required, as their pursuit is strictly related to the use of the Website and to the E-Commerce Activities or the execution of pre-contractual measures requested by you. Therefore, the provision of your Personal Data for the above-mentioned purposes is necessary. In case of your refusal, you may not be able to use the Website properly and/or you may not be able to purchase products on our e-commerce.

  1. Purpose of Law

We will process your Personal Data, on the basis of the need to comply with a legal obligation to which we are subject (Article 6, paragraph 1, letter c) of the GDPR), for the following purpose:

  1. to comply with any legal and regulatory obligations.

The purpose listed above is defined as the "Purpose of Law" and your express consent is not required, as its pursuit is strictly related to the fulfilment of the obligations that the law places on the Company. Therefore, the provision of your Personal Data for the above-mentioned purpose is necessary. In case of your refusal, you may not be able to use the Website properly and/or you may not be able to purchase products on our e-commerce.

  1. Purposes of Legitimate Interest

We will process your Personal Data, on the basis of our legitimate interest (Article 6, paragraph 1, letter f) of the GDPR), as follows:

  1. to carry out checks for the purposes of preventing and/or suppressing fraudulent actions to the detriment of the Website, managing its IT resources, and ensuring IT security (unless necessary to comply with legal obligations). In this case, we have a legitimate interest in preventing and/or suppressing fraud and misuse of the Website, administering our IT resources as well as ensuring IT and network security;
  2. to verify the proper functioning of the Website and the services related to the E-Commerce Activities and obtain statistics on its use. In this case, we have a legitimate interest in ascertaining the good use of the Website and related services, and processing for statistical purposes;
  3. to assert and defend our rights, also through third parties (unless necessary to comply with legal obligations). In this case, we have a legitimate interest in enforcing or defending any legal claims;
  4. to carry out activities functional to the completion of a potential merger, demerger, acquisition, sale of assets, transfer of business, business unit or other corporate transaction, communicating and transferring Personal Data to the third party(ies) involved in the aforesaid corporate transaction(s). In this case, we have a legitimate interest in completing a corporate transaction(s) in case of any issues or difficulties to the business or corporate governance, or given changes relating to any business activities, assets, or new strategies, or in view of changes to company market conditions, or to the socio-economic, legislative, or technological environment.

The purposes listed above are defined as the "Purposes of Legitimate Interest" and your express consent is not required. In accordance with the GDPR, we have carried out a balancing analysis of the conflicting interests involved, aimed at protecting and guaranteeing your privacy and fundamental rights. In any event, you have the right to object to the processing of your Personal Data carried out by us for the Purposes of Legitimate Interest in the manner indicated in section 9) below unless the Company has an overriding interest in continuing the processing or such processing is aimed at protecting our rights.

  1. Consent

We will process your Personal Data, on the basis of your consent (Article 6, paragraph 1, letter a) of the GDPR), for the following purposes:

  1. to send you newsletters, commercial communications and market surveys by any means of communication (including email, SMS, social networks, post and telephone), for the promotion of our products and services (hereinafter, the "Marketing Purposes");
  2. to show you or send you, on the Website and/or by any means of communication (including email, SMS, social networks, post and telephone), personalized advertising, containing only offers relevant to you and product recommendations based on your interests (hereinafter, the "Profiling Purposes").

The purposes listed above are defined as the "Marketing and Profiling Purposes" and your express consent is required for their pursuit. When you consent to the processing of your Personal Data for Marketing [and Profiling] Purposes, you may revoke your consent at any time and, in such case, we will cease to process your Personal Data for such purposes.

  • METHODS OF PROCESSING

The processing of your Personal Data will be carried out through electronic, computerized, and manual means, in accordance with the principles of fairness, lawfulness and transparency provided by applicable data protection legislation, including the GDPR, and protecting your privacy by adopting appropriate technical and organizational security measures to ensure an adequate level of security.

These processing operations take place at the Company's registered office and/or at the offices of external data processors who carry out the processing on behalf of the Company, which may include, but are not limited to, payment service providers in charge of processing your payments and logistics companies engaged by us for the purpose of handling and delivering the products you have purchased.

  • TO WHOM DO WE COMMUNICATE YOUR PERSONAL DATA?

In compliance with the principle of minimization and always in pursuit of the purposes of the processing indicated in this Privacy Policy, we may communicate your Personal Data to the following categories of recipients who provide functional services and/or services related to the E-Commerce Activities or to the management of the Website, such as:

  1. directors, employees, collaborators and business partners of the Company, each within the scope of their role and duties;
  2. third party providers, including data processors, of operation (including payment and logistics services), assistance and consulting services with reference to activities in the field of e-commerce and in the fields of, but not limited to, marketing, technological, accounting, administrative, legal, insurance, etc., which have their locations in Italy, Ireland, Denmark, Finland, the Netherlands and other European countries, the United States and Canada;
  3. bodies and authorities whose right of access to Personal Data is expressly recognized by laws, regulations or provisions issued by the competent authorities;
  4. companies or entities that are the transferees of assets, business or business unit, or companies resulting from any mergers, demergers, acquisitions, or other corporate transactions carried out by the Company.
  • TRANSFER OF PERSONAL DATA OUTSIDE THE EUROPEAN ECONOMIC AREA

Your Personal Data is collected and stored by the Company or any appointed data controller within the European Economic Area (hereinafter, the "EEA").

In pursuit of the purposes set out above, we may transfer your Personal Data outside the EEA to third countries (e.g., the United States), in which case we will take the necessary measures to protect your Personal Data, subject to legal safeguards, specifically the Standard Contractual Clauses ("SCCs") approved by the EU Commission, and any other required additional measures (e.g., Transfer Impact Assessment ("TIA")), in accordance with applicable law and in particular Articles 45 and 46 of the GDPR.

You have the right to ask us for more information about the safeguards we have put in place. Contact us at privacy@alpinestars.com, if you would like to receive further information or to request a copy of the relevant safeguards (which may be redacted to ensure confidentiality).

  • HOW LONG DO WE RETAIN YOUR PERSONAL DATA?

We only retain your Personal Data for as long as necessary to pursue the purposes for which it was collected and, in general, to comply with the applicable laws, to defend and file legal actions. In particular:

  1. Personal Data that has been collected for the Contractual Purposes will be retained for a period equal to the duration of the contract entered into with the Company, as well as for 10 (ten) years thereafter (the period in which the statute of limitations for the Company’s contractual liability, if any, accrues), except where retention for a later period is required for any litigation, requests by the competent authorities or pursuant to applicable law;
  2. Personal Data processed for the Purpose of Law shall be retained for the period prescribed for each type of data by the applicable law;
  3. Personal Data processed for the Purposes of Legitimate Interest referred to in point 3., letters a. and b., of section 4) above shall be retained for a period of 7 (seven) days from the time of collection, unless further retention is necessary to ascertain liability in case of hypothetical computer crimes against the Website or to comply with requests by the authorities;
  4. Personal Data processed for the Purposes of Legitimate Interest referred to in point 3., letters c. and d., of section 4) above will be retained for a period of 10 (ten) years from the end of the performance of the E-Commerce Activity to which such Personal Data refer, if the processing is carried out for the purpose of asserting and defending our rights, whereas in the event that the processing is carried out in order to implement and execute activities functional to mergers, demergers, acquisitions, transfers of assets, business or business unit, or other corporate operations, the retention periods listed above shall apply with respect to the main processing that takes place;
  5. Personal Data processed for the Marketing and Profiling Purposes shall be retained until you withdraw your consent to the processing for such purposes and, in any event, no longer than 24 (twenty-four) months for the Marketing Purposes and no longer than 12 (twelve) months for the Profiling Purposes.

After the aforementioned time limits, your Personal Data will be deleted.

  • WHAT ARE YOUR RIGHTS AND HOW CAN YOU EXERCISE THEM?

In accordance with the provisions of the GDPR, at any time and free of charge you have the right to:

  1. receive confirmation of the existence of your Personal Data, how we process it and access to its content;
  2. update, amend and/or correct your Personal Data;
  3. request the deletion of the processing of your Personal Data in certain circumstances, including Personal Data processed in breach of law, Personal Data whose storage is not necessary in relation to the purposes for which the Personal Data were collected or otherwise processed, without prejudice, in particular, to an overriding public interest or a legal obligation of the Company to preserve the Personal Data;
  4. request restriction of processing in certain circumstances. If the processing of your Personal Data has been restricted, we may only, besides storing the data, process your Personal Data with your consent, in order to establish, exercise or defend legal claims or to defend rights of others;
  5. object to the processing, without prejudice to the existence of an overriding legitimate reason for the Company to continue the processing or for our establishment, exercise or defense of legal claims;
  6. revoke the consent to the processing of your Personal Data, where given, without affecting in any way the lawfulness of the processing based on the consent given before its revocation;
  7. receive an electronic copy of your Personal Data in order to transfer them to yourself or to a different service provider, where the processing is carried out on the basis of your consent or the performance of the contract between you and the Company, and your data are processed by automated means;
  8. without prejudice to any other administrative or jurisdictional recourse, if you consider that the processing concerning you violates the legislation on the processing of personal data, you have the right to lodge a complaint with a data protection supervisory authority. The Spanish Data Protection Authority can be found at aepd.es.

In the event of your death, the aforementioned rights relating to your Personal Data may be exercised by those who have an interest of their own, or act as your proxy, or for family reasons worthy of protection. You may expressly prohibit the exercise of some of the rights listed above by your assignees by sending a written declaration to the Company at the e-mail address indicated below. The declaration may be revoked or modified at a later date, in the same manner.

Without prejudice to your right to lodge a complaint with a supervisory authority, you may exercise the aforementioned rights or contact us with questions or comments regarding data protection matters by sending an email to privacy@alpinestars.com.

When contacting us, please be sure to include your name, email/postal address and/or telephone number(s) to ensure that your request can be handled properly.