(Art. 13 Reg. UE 679/2016)
Pursuant to the Data Protection Act 2018 (“Regulation”), the Luigi Lavazza S.p.A. with registered office in Via Bologna, 32 - 10152 Turin (Italy) as Data Controller of the Personal Data provided by you when participating in the Loyalty Program, provides you with the following information.
Data Protection Officer - DPO
If you wish to contact our Data Protection Officer, also known as DPO with the task of supervising compliance with the Regulation and acting as a point of contact with the data subjects and the Data Protection Authority, you can do so by writing to the e-mail address PrivacyDPO@Lavazza.com.
Data Processors
Your Personal Data may be processed by companies appointed as Data Processors to carry out, on behalf of the Promoter, activities related to the processing of Personal Data. The Data Controller has drawn up a list of Data Processors, which is constantly updated and made available to you by contacting the addresses indicated in the section dedicated to the exercise of rights in this Privacy Policy.
Which categories of personal data we process
- Identification and contact data
- Shipping and delivery data
- Information collected during participation (including but not limited to information contained on any items uploaded by You)
- Consumption habits
What are the purposes and legal bases of the processing
The personal data you are providing us with by joining the Loyalty Program will be used for the following purposes:
- Management of participation in the Loyalty Program: aimed at administration of the Programme, including but not limited to the monitoring, administration and distribution of Beans, Tiers, Benefits, Rewards, Missions and sending communications. Beans, Rewards to receive Rewards The legal basis of the processing is the legitimate interest we hold in ensuring the best possible operation and consumer experience of the Programme and the execution of contractual measures of which the data subject is a party through adherence to the Terms of the Loyalty Program.
- Administrative, accounting and legal: These purposes are related to the management of the Loyalty Program. The legal basis of the processing is the need to comply with obligations provided for by law and to comply with tax or accounting obligations.
- Analysis purposes: The Personal Data you provide in your interactions with the Loyalty Program will be included in our database and will be used anonymously to analyse and improve the services offered, to assess the effectiveness of the activities and initiatives promoted, and to conduct statistical analyses on the composition of the database itself. The legal basis for the processing is the legitimate interest of the Data Controller.
How we process the data
Your Personal Data will be processed in accordance with the provisions of the Regulation, both with the aid of electronic and automated means and with manual methods, with logics strictly related to the purposes of the processing, through databases, electronic platforms managed by Promoter or third parties (appointed as Data Processors), the integrated IT systems of Promoter and the aforementioned third parties, and/or websites owned or used by Promoter.
Your Data will be processed in such a way as to ensure maximum security and confidentiality and only by persons trained and authorized to process it. The Data Controller adopts adequate technical and organizational measures to ensure a level of security appropriate to the risk of the processing.
Retention period
The Data will be stored according to the following criteria:
- Data processed for participation in the Loyalty Program: will be maintained for the duration of the Loyalty Program and for a period of time sufficient to ensure its correct execution. This is without prejudice to the fulfillment of administrative and tax obligations in relation to which the data retention period is that provided for by law.
To whom we communicate personal data
According to our legal and contractual obligations, we may transfer some personal data internally or to selected third parties. By way of example and not limited to, the parties to whom we may disclose your data may include companies belonging to the Lavazza Group, our service providers, entities, bodies or authorities to whom the communication of your personal data is mandatory by virtue of legal provisions or orders of the Authorities or to third parties who fulfil requests that you make, including but not limited to, the delivery of Rewards.
How to exercise your rights and the possibility of making a complaint
You may at any time exercise your rights under Regulation – including access to Personal Data, rectification and, in cases provided for by law, cancellation, limitation of processing and data portability – by writing an e-mail to the DPO at the address PrivacyDPO@lavazza.com
You also have the right to lodge a complaint with the competent supervisory authority if you believe that the processing of your personal data is contrary to the law.
04 December 2024