Privacy policy

Privacy Policy of nuvocosmetic.com

This Website collects some of its Users' Personal Data.

 This document can be printed by using the print command in the settings of any browser.

 Summary of the policy


Personal Data processed for the following purposes and using the following services:

  • Contact the User
  • Mailing list or newsletter

Personal Data: Postcode; city; surname; date of birth; usage Data; email; physical address; country; name; phone number; province; gender; Tracking Tools

  • Contact Form

Personal Data: Postcode; city; Tax Code; surname; date of birth; usage Data; email; User ID; physical address; country; name; phone number; province; gender; Tracking Tools; various types of Data

  • Contact by phone

Personal Data: phone number

  • Managing contacts and sending messages
  • Klaviyo

Personal Data: various types of Data

  • Sendgrid

Personal data: surname; date of birth; email; first name; telephone number; gender

  • Payment Management
  • PayPal

Personal data: surname; email; billing address; name; telephone number; various types of Data as specified by the privacy policy of the service

  • Apple Pay e Google Pay

Personal Data: surname; usage Data; email; billing address; shipping address; name; telephone number; various types of Data as specified by the privacy policy of the service

  • Klarna

Personal Data: surname; usage Data; email; billing address; name; various types of Data as specified by the privacy policy of the service

  • Stripe

Personal Data: surname; Usage Data; email; billing address; name; various types of Data as specified by the service's privacy policy

  • Tags Management
  • Google Tag Manager

Personal Data: usage Data; Tracking Tools

  • Management of data collection and online surveys
  • Klaviyo Forms

Personal Data: Data communicated during the use of the service

  • Hosting and backend infrastructure
  • SiteGround

Personal Data: various types of Data as specified by the service's privacy policy

  • Interaction with live chat platforms
  • Shopify Inbox

Personal Data: Data communicated during the use of the service

  • Interaction with social networks and external platforms
  • PayPal button and widget, Linkedin button and social widgets and Facebook Like button and social widgets

Personal data: usage Data: Tracking Tools

  • Collecting privacy preferences
  • Iubenda Consent Solution

Personal Data: Data communicated during use of the service; Tracking Tools

  • Cookie Solution by iubenda

Personal Data: Tracking Tools

  • Registration and authentication
  • Direct registration and profiling

Personal Data: Postcode; Tax Code; surname; date of birth; Usage Data; email; User ID; picture; profile picture; billing address; shipping address; physical address; language; house number; phone number; province; gender; status; username; various types of Data

  • Registration and authentication provided directly by this Website
  • Direct registration

Personal Data: postcode; city; tax code; surname; date of birth; email; user ID; picture; profile picture; billing address; physical address; language; country; name; house number; phone number; area code; province; gender; state; username; various types of Data

  • Remarketing and behavioural targeting
  • Facebook Remarketing, Google Analytics Remarketing and Google Ads Remarketing

Personal Data: usage Data: Tracking Tools

  • Klaviyo segmentation and social advertising

Personal Data: Purchase History; usage Data; Email; Device Information; Tracking Tools

  • Customised Facebook audience

Personal Data: email; Tracking Tools

  • Statistics
  • Google Analytics, Google Analytics with anonymised IP, Meta Events Manager, Facebook Ads conversion tracking (Facebook pixel), Google Ads conversion tracking

Personal Data: usage Data; Tracking Tools

  • Google Analytics 4

Personal Data: device information; number of Users; session statistics; Tracking Tools

  • Reports on Google Analytics demographics and interests

Personal Data: univocal device identifiers for advertising (Google Advertiser ID or IDFA identifier, for example); Tracking Tools

  • Displaying content from external platforms
  • Google Fonts, Font Awesome, Instagram Widget and YouTube Video Widget

Personal data: usage Data; Tracking Tools

Information on how to deactivate interest-based advertisements

In addition to any opt-out functionality provided by any of the services listed in this document, Users can read more about how to disable interest-based advertisements in the relevant section of the Cookie Policy.

Further information on the processing of Personal Data

  • Sale of goods and services online

The Personal Data collected are used for the provision of services to the User or for the sale of products, including payment and possible delivery. The Personal Data collected to finalise payment may be those related to the credit card, bank account used for the transfer or any other payment instrument provided. The Payment Data collected by this Website depend on the payment system used.

Contact Information

  • Data Controller

Dulàc Farmaceutici 1982 srl - Via Albenga, 125 10098 Rivoli - Torino

E-mail address of Data Controller: info@nuvocosmetic.com

Full policy

Data Controller

Dulàc Farmaceutici 1982 srl - Via Albenga, 125 10098 Rivoli - Torino

E-mail address of Data Controller: info@nuvocosmetic.com

Types of Data collected

Among the Personal Data collected by this Website, either independently or through third parties,you will find: Tracking Tools; Usage Data; email; first name; last name; phone number; province; country; postcode; gender; date of birth; city; physical address; various types of Data; Tax Code; User ID; billing address; Data communicated during the use of the service; shipping address; username; status; image; profile picture; street number; language; area code; device information; purchase history; number of Users; session statistics; unique device identifiers for advertising (Google Advertiser ID or IDFA identifier, for example).

Full details on each type of data collected are provided in the dedicated sections of this privacy policy or by means of specific information texts displayed prior to the collection of such data.
Personal Data may be freely provided by the User or, in the case of User Data, automatically collected during the use of this Website.
Unless otherwise specified, all Data requested by this Web Site are mandatory. If the User refuses to provide them, it may be impossible for this Web Site to provide the Service. In cases where this Web Site indicates certain Data as optional, Users are free to refrain from communicating such Data, without this having any consequences on the availability of the Service or its operation.
Users in doubt as to which Data are mandatory are encouraged to contact the Data Controller.
Any use of Cookies - or of other tracking tools - by this Website or by the owners of third party services utilized by this Website, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Website and warrants that he/she has the right to communicate or disseminate them, relieving the Owner from any liability towards third parties.

Method and place of processing the Data collected

Method of Processing

The Data Controller takes appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of Personal Data.
The processing is carried out using computer and/or telematic instruments, with organisational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other subjects involved in the organisation of this Website (administrative, sales, marketing, legal, system administrators), notably external subjects (such as third party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) may also be appointed as Data Processors by the Data Controller and have access to the Data. The updated list of Data Processors can always be requested from the Data Controller.

Legal basis of the processing

The Controller processes Personal Data relating to the User if one of the following conditions is met:

  • the User has given consent for one or more specific purposes; Note: in some jurisdictions, the Controller may be authorised to process Personal Data without the User's consent or another of the legal bases specified below, until the User objects ("opts-out") to such processing. However, this does not apply if the processing of Personal Data is governed by the European legislation on the protection of Personal Data;
  • processing is necessary for the performance of a contract with the User and/or the performance of pre-contractual measures;
  • processing is necessary for the performance of a legal obligation which the Controller is subject to;
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of public authority vested in the Controller;
  • processing is necessary for the pursuit of the legitimate interest of the Controller or of third parties.

However, it is always possible to request the Data Controller to clarify the concrete legal basis of each processing and, in particular, to specify whether the processing is based on law, required by a contract or necessary to finalise a contract.

Location

The Data are processed at the Data Controller's premises and at any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User's Personal Data may be transferred to a country other than the one where the User is located. To obtain further information on the location of the processing, the User may refer to the section on Personal Data processing details.

The User has the right to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organisation under public international law or consisting of two or more countries, such as the UN, as well as about the security measures taken by the Controller to protect the Data.

The User can verify whether one of the transfers just described takes place by examining the section of this document relating to details on the processing of Personal Data, or request information from the Controller by contacting it at the contact details given at the beginning.

Retention period

Data are processed and kept for the time required by the purposes for which they were collected.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the performance of that contract is completed.
  • Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.

When the processing is based on the User's consent, the Data Controller may keep the Personal Data for a longer period of time until such consent is revoked. Moreover, the Controller may be obliged to keep the Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period the Personal Data will be deleted. Therefore, at the end of this period, the right of access, deletion, rectification and the right to Data portability shall no longer be exercised.

Purposes of the Data collected

The User Data are collected to enable the Owner to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect its rights and interests (or those of Users or third parties), detect any malicious or fraudulent activities, as well as for the following purposes: Statistics, Displaying content from external platforms, Tag management, Contacting the User, Contact management and sending messages, Interaction with support and feedback platforms, Payment management, Heat mapping and session recording, Interaction with online survey platforms, Interaction with data collection platforms and other third parties, Management of data collection and online surveys, Management of support and contact requests, Hosting and backend infrastructure, Interaction with live chat platforms, Interaction with social networks and external platforms, Collection of privacy preferences, Registration and authentication, Registration and authentication provided directly by this Website, Remarketing and behavioral targeting and Platform and hosting services.

To obtain detailed information on the purposes of the processing and the Personal Data processed for each purpose, the User may refer to the section "Personal Data Processing Details".

Personal Data Processing Details

Personal Data are collected for the following purposes and using the following services:

  • Contact the User
  • Mailing list or newsletter (this Website)

Mailing list or newsletter (this WebSite)

By registering to the mailing list or newsletter, the User's email address is automatically added to a list of contacts to whom email messages may be sent containing information, including information of a commercial and promotional nature, relating to this Website. The User's email address may also be added to this list as a result of registering on this Website or after making a purchase.

Personal data processed: Postcode; city; surname; date of birth; Usage Data; email; physical address; country; first name; telephone number; province; gender; Tracking Tools.

Contact form (this Website)

The User, by filling in the contact form with his or her Data, consents to their use in order to reply to requests for information, quotations, or of any other nature indicated in the header of the form.

Personal Data processed: Postcode; city; Tax Code; surname; date of birth; Usage Data; email; User ID; physical address; country; name; telephone number; province; gender; Tracking Tools; various types of Data.

  • Contact by telephone (this Website)


Users who have provided their telephone number may be contacted for commercial or promotional purposes related to this Web Site, as well as to fulfil support requests.

Personal Data processed: telephone number.


  • Managing contacts and sending messages

This type of service allows the management of a database of email contacts, telephone contacts or contacts of any other type used to communicate with the User.
These services may also allow the collection of data relating to the date and time the User views the messages, as well as the User's interaction with them, such as information on clicks on links in the messages.

Klaviyo (Klaviyo Inc.)

Klaviyo is an address management and email messaging service provided by Klaviyo Inc.

In order to use the service provided by Klaviyo, the owner generally shares information about users (who make purchases), such as delivery data and purchase history. For further information on the extent of such sharing, please check the information below under the heading "Personal Data Processed".

Personal Data processed: various types of Data.

Place of processing: United States - Privacy Policy – Opt out.


Sendgrid (Sendgrid)

Sendgrid is an address management and email messaging service provided by Sendgrid Inc.

Personal data processed: surname; date of birth; email; name; telephone number; gender.

Place of processing: United States - Privacy Policy – Opt out.

  • Management of payments

Unless otherwise specified, this Website processes all payments by credit card, bank transfer or other means through external payment service providers. In general, and unless otherwise specified, Users are requested to provide payment details and personal information directly to such payment service providers.
This Website is not involved in the collection and processing of such information: instead, it will only receive a notification from the payment service provider in question that the payment has been made.

PayPal (Paypal)

PayPal is a payment service provided by PayPal Inc., which allows the User to make online payments.

Personal Data processed: surname; email; billing address; name; telephone number; various types of Data as specified by the privacy policy of the service.

Place of processing: See Paypal's privacy policy – Privacy Policy.

Apple Pay (Apple Inc.)

Apple Pay is a payment service provided by Apple Inc., which allows the User to make payments using their mobile phone.

Personal Data processed: last name; Usage Data; email; billing address; shipping address; name; phone number; various types of Data as specified by the service's privacy policy.

Place of processing: United States  Privacy Policy.

Google Pay

Google Pay is a payment service provided by Google LLC or Google Ireland Limited, depending on how the Owner manages the processing of Data, which allows the User to make online payments using their Google credentials.

Personal Data processed: surname; Usage Data; email; billing address; shipping address; name; telephone number; various types of Data as specified in the privacy policy of the service.

Place of processing: United States - Privacy Policy; Ireland - Privacy Policy.

Klarna (Klarna AB)

Klarna is a payment service provided by Klarna AB.

Personal Data processed: surname; email; billing address; shipping address; name; telephone number; various types of Data as specified in the service's privacy policy.

Place of processing: Sweden - – Privacy Policy.

Stripe ( Stripe Technology Europe Ltd)

Stripe is a payment service provided by Stripe Technology Europe Ltd.

Personal Data processed: surname; Usage Data; email; billing address; name; various types of Data as specified by the privacy policy of the service.

Place of processing: Ireland - Privacy Policy.

  • Tag management

This type of services is functional for the centralised management of tags or scripts used on this Website.
The use of these services involves the flow of the User's Data through them and, where appropriate, their retention.

Google Tag Manager

Google Tag Manager is a tag management service provided by Google LLC or Google Ireland Limited, depending on how the Owner manages the processing of the Data.

Personal Data processed: Usage Data; Tracking Tools.

Place of Processing: United States - – Privacy Policy; Ireland -Privacy Policy.

  • Management of data collection and online surveys

This type of service allows this Website to manage the creation, implementation, administration, distribution and analysis of online forms and surveys in order to collect, save and re-use Data from Users who respond.
The Personal Data collected depend on the information requested and provided by Users in the corresponding online form.

These services may be integrated with a wide range of third party services to enable the Controller to perform subsequent actions with the processed Data - for example, contact management, message sending, statistics, advertising and payment processing.

Hotjar surveys (Hotjar Ltd.)

Hotjar surveys is a survey generator and data collection platform provided by Hotjar Ltd.
Hotjar surveys may use cookies to track User behaviour. Users can opt-out of Hotjar surveys cookie tracking by visiting this opt-out page.

Hotjar surveys respects the "Do Not Track" option available in most modern browsers which, when activated, sends a special signal to stop tracking User activity. Users can find further information on how to enable the "Do Not Track" option for each supported browser here.

Personal Data Processed: Data communicated during the use of the service.

Place of processing: Malta - Privacy Policy – Opt Out.

Klaviyo Forms (Klaviyo Inc.)

Klaviyo Forms is a form generator and data collection platform provided by Klaviyo Inc.

In order to make use of the service provided by Klaviyo, the Controller generally shares information about Users (who make purchases), such as delivery data and purchase history. For further information on the extent of such sharing, please check the information below under the heading "Personal Data Processed".

Personal data processed: Data communicated during the use of the service.
Place of processing: Unites States - Privacy Policy.

  • Heat mapping and session recording

Heat mapping services are used to identify the areas of this Website that Users interact with most frequently, in order to detect which of them attract the most interest. These services allow us to monitor and analyse traffic data and serve to track User behaviour.
Some of these services may record sessions and make them available for later viewing.

Hotjar Heat Maps & Recordings (Hotjar Ltd.)

Hotjar is a heat mapping and session recording service provided by Hotjar Ltd.
Hotjar respects generic 'Do Not Track' headers. This means that the browser can instruct the script not to collect any user data. This is a setting that is available in all major browsers. More Information on opting out of Hotjar is available here.

Personal data processed: Usage Data; Tracking Tools; various types of Data as specified by the privacy policy of the service.

Place of processing: Malta -Privacy Policy – Opt Out. 

  • Hosting and backend infrastructure

The purpose of these types of services is to host Data and files that enable this Website to function, enable their distribution and provide a ready-made infrastructure to deliver specific functionality of this Website.

Some of the services listed below, if any, may operate on geographically dispersed servers, making it difficult to determine the actual location where Personal Data is stored.

SiteGround

SiteGround is a hosting service

Personal Data processed: various types of Data as specified in the privacy policy of the service.

Place of processing: Italy - Privacy Policy.

  • Interaction with live chat platforms

This type of service allows Users to interact with live chat platforms operated by third parties, directly from the pages of this Website, in order to contact and be contacted by the support service of this Website.
In the event that a service for interacting with live chat platforms is installed, it is possible that, even if Users do not use the service, it will collect Usage Data relating to the pages on which it is installed. In addition, live chat conversations may be recorded.

Spotify Inbox

Spooyify Inbox is an interaction service with the Spotify live chat platform

Personal data processed: Data communicated during the use of the service.

Place of processing: United States -  Privacy Policy.

  • Interaction with social networks and external platforms

This type of service allows you to interact with social networks, or other external platforms, directly from the pages of this Website.
The interactions and information acquired by this Website are in each case subject to the User's privacy settings relating to each social network.
This type of service may still collect traffic data for the pages where the service is installed, even when Users do not use it.
It is recommended to disconnect from the respective services to ensure that the data processed on this Website is not linked back to the User's profile.

 

PayPal Button and Widget (PayPal)

The PayPal button and widget are PayPal platform interaction services, provided by PayPal Inc.

Personal Data Processed: Usage Data; Tracking Tools.

Place of processing: See Paypal -  Privacy Policy.

LinkedIn social button and widgets (LinkedIn Corporation)

LinkedIn's social button and widgets are services for interaction with the Linkedin social network, provided by LinkedIn Corporation.

Personal Data Processed: Usage Data; Tracking Tools.

Place of processing: United States -Privacy Policy.

Facebook Like button and social widgets

Facebook's "Like" button and social widgets are services for interaction with the social network Facebook, provided by Meta Platforms, Inc. or Meta Platforms Ireland Limited, depending on how the Data Controller manages the processing of the Data,

Personal Data processed: Usage Data; Tracking Tools.

Place of Processing: United States - – Privacy Policy; Ireland – Privacy Policy

  • Collection of privacy preferences

This type of service allows this Website to collect and save Users' preferences regarding the collection, use and processing of their personal information, as required by the applicable privacy legislation.

Iubenda's Consent Solution (iubenda srl)

The iubenda Consent Solution allows saving and retrieving the records of Users' consent to the processing of their Personal Information, as well as the information and preferences expressed in relation to the consent provided.
To this end, it makes use of a Tracking Tool that temporarily stores the pending information on the User's device until it is processed by the API. The Tracking Tool (a browser function called localStorage) is then deleted.

Personal Data Processed: Data communicated during the use of the service; Tracking Tools.

Place of processing: Italy - Privacy Policy.

iubenda Cookie Solution (iubenda srl)

The iubenda Cookie Solution allows the Data Controller to collect and save Users' preferences regarding the processing of personal data and in particular the use of Cookies and other Tracking Tools on this Website.

Personal Data Processed: Tracking Tools.

Place of processing: Italy -  Privacy Policy.

  • Registration and authentication

By registering or authenticating, the User allows this Website to identify him/her and give him/her access to dedicated services.
Depending on what is indicated below, the registration and authentication services may be provided with the help of third parties. Where this is the case, this Website may access certain Data stored by the third party service used for registration or identification.
Some of the services mentioned below may also collect Personal Data for targeting and profiling purposes; to learn more, please refer to the description of each service.

  • Direct registration and profiling (this Website)

The User registers by filling in the registration form and providing his or her Personal Data directly to this Website.

Personal Data processed: Postcode; city; Tax Code; surname; date of birth; email; User ID; picture; profile picture; billing address; physical address; language; country; name; house number; telephone number; area code; province; gender; state; username; various types of Data.

  • Remarketing and behavioral targeting

This type of service allows this Website and its partners to communicate, optimise and serve advertisements based on the User's past use of this Website.
This activity is facilitated by tracking Usage Data and using Tracking Tools to collect information that is then transferred to partners that handle remarketing and behavioral targeting activities.
Some services offer a remarketing option based on email address lists.
Generally, services of this type offer the possibility to disable such tracking. In addition to any opt-out function provided by any of the services listed in this document, the User can read more about how to disable interest-based advertisements in the section "How to disable interest-based advertising" in this document.

Facebook Remarketing

Facebook Remarketing is a remarketing and behavioral targeting service provided by Meta Platforms, Inc. or Meta Platforms Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links the activity of this Website with the Facebook advertising network.

Place of Processing: United States -  Privacy Policy – Opt Out; Ireland – Privacy Policy – Opt Out.

Klaviyo segmentation and social advertising (Klaviyo Inc.)

Klaviyo segmentation and social advertising is a remarketing and behavioral targeting service provided by Klaviyo Inc.

Klaviyo segmentation and social advertising uses tracking technology to monitor User behaviour. This Data is then used to personalise the User's experience and to provide targeted advertising. Klaviyo segmentation and social advertising may also connect the accumulated Data with other networks, including advertising networks, and enable these third parties to track and target the User.  The Owner, unless otherwise provided for in this document, has no direct relationship with third parties that Klaviyo sementation and social advertising may include.

In order to make use of the service provided by Klaviyo, the Controller generally shares information about the Users (who make purchases), such as delivery data and purchase history. For further information on the extent of this sharing, please check the information below under the heading "Personal data processed". 

Personal Data Processed: Purchase History; Usage Data; Email; Device Information; Tracking Tools.

Place of processing: United States - Privacy Policy – Opt out.


Facebook Personalized Audiences

Facebook Personalized Audience is a remarketing and behavioural targeting service provided by Meta Platforms, Inc. or Meta Platforms Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links the activity of this Website with Facebook's advertising network.

Users can choose not to use Facebook's Tracking Tools for ad customisation by visiting this opt-out page.

Personal Data Processed: email; Tracking Tools.

Place of processing: United States -  Privacy Policy - Opt Out ; Ireland - Privacy Policy - Opt OutOpt Out.  

Remarketing with Google Analytics

Remarketing with Google Analytics is a remarketing and behavioral targeting service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links the tracking activity performed by Google Analytics and its Tracking Tools with the Google Ads advertising network and the Doubleclick Cookie.

Personal Data processed: Usage Data; Tracking Tools.

Place of processing: United States - Privacy Policy - Opt Out; Ireland - Privacy Policy- Opt OuOpt Out.

Google Ads Remarketing

Remarketing Google Ads is a remarketing and behavioral targeting service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links the activity of this Website with the Google Ads advertising network and the DoubleClick Cookie.

To understand how Google uses the Data, please refer to Google's parner policy.

Users can opt out of Google's Tracking Tools for ad customisation by visiting Google's  Ads Settings.

Personal Data Processed: Usage Data; Tracking Tools.

Place of Processing: United States - Privacy Policy – Opt Out - Ireland -  Privacy Policy – Opt Out

Platform and hosting services

These services are intended to host and operate key components of this Website, making it possible to deliver this Website from a single platform. These platforms provide the Owner with a wide range of tools such as, for example, analytical tools, user registration management, comment and database management, e-commerce, payment processing, etc. The use of these tools involves the collection and processing of Personal Data.
Some of these services operate through servers located geographically in different places, making it difficult to determine the exact location where Personal Data is stored.

WordPress.com (Automattic Inc.)

WordPress.com is a platform provided by Automattic Inc. that enables the Controller to develop, operate and host this Website.

Personal Data processed: various types of Data as specified in the privacy policy of the service..

Place of processing: United States -  Privacy Policy.

  • Statistics

The services contained in this section allow the Data Controller to monitor and analyse traffic data and serve to keep track of the User's behaviour.

Google Analytics

Google Analytics is a web analytics service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, ("Google"). Google uses the Personal Data collected in order to track and examine the use of this Website, compile reports and share them with other services developed by Google.
Google may use Personal Data to contextualise and personalise ads on its advertising network.

Personal Data processed: Usage Data; Tracking Tools.

Place of processing: United States -  Privacy Policy – Opt Out; Ireland -  Privacy Policy – Opt Out

Google Analytics with anonymised IP

Google Analytics is a web analytics service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, ("Google"). Google uses the Personal Data collected in order to track and examine the use of this Website, compile reports and share them with other services developed by Google.
Google may use the Personal Data to contextualise and personalise the advertisements of its advertising network.
This Google Analytics integration anonymises your IP address. The anonymisation works by shortening the IP address of Users within the borders of the member states of the European Union or in other countries which are parties to the Agreement on the European Economic Area. Only in exceptional cases will the IP address be sent to Google's servers and abbreviated within the United States.

Personal Data Processed: Usage Data; Tracking Tools.

Place of processing: United States - Privacy Policy – Opt Out; Ireland - Privacy Policy – Opt Out.

Meta Events Manager (Meta Platforms Ireland Limited)

Meta Events Manager is a statistics service provided by Meta Platforms Ireland Limited. By integrating Meta's pixel, Meta Events Manager may give the Owner information about traffic and interactions on this Website.

Personal Data Processed: Usage Data; Tracking Tools.

Place of processing: Ireland - Privacy Policy.

Facebook Ads conversion tracking (Facebook pixel)

The Facebook Ads conversion tracking (Facebook pixel) is a statistical service provided by Meta Platforms, Inc. or Meta Platforms Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links data from the Meta ad network with actions taken within this Website. The Facebook pixel monitors conversions that can be attributed to Facebook ads, Instagram and the Audience Network.

Personal Data Processed: Usage Data; Tracking Tools.

Place of processing: United States - Privacy Policy; Ireland - Privacy Policy

Google Analytics 4

Google Analytics is a statistical service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, ("Google"). Google uses the Personal Data collected in order to track and examine the use of this Website, compile reports and share them with other services developed by Google.
Google may use Personal Data to contextualise and personalise ads in its advertising network.
In Google Analytics 4, IP addresses are used at the time of collection and then deleted before the data is stored in any data centre or server. To find out more, you can consult Google's official documentation.

Personal Data Processed: Device Information; Number of Users; Session Statistics; Tracking Tools.

Place of processing: United States - Privacy Policy – Opt Out- ; Ireland - Privacy Policy – Opt Out

Google Ads conversion monitoring

Google Ads conversion monitoring is a statistics service provided by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which links the data from the Google Ads ad network with the actions performed within this Website.

Personal Data processed: Usage Data; Tracking Tools.


Place of processing: United States - Privacy Policy; Ireland - Privacy Policy.

Google Analytics Demographics and Interest Reports

Google Analytics Demographic and Interest Data Reports is an advertising report generation feature that makes Demographic and Interest Data available within Google Analytics for this Website (Demographic Data means Age and Gender Data).


Users may opt out of Google's cookies by visiting Google's [Ad Settings] (https://adssettings.google.com/authenticated).

Personal Data Processed: Unique device identifiers for advertising (Google Advertiser ID or IDFA identifier, for example); Tracking Tools.

Place of Processing: United States -  Privacy Policy – Opt Out; Ireland -  Privacy Policy – Opt Out.

Display of content from external platforms

This type of service allows users to view content hosted on external platforms directly from the pages of this Website and interact with them.
This type of service may nevertheless collect data on web traffic related to the pages where the service is installed, even when users are not using it.

Google Fonts

Google Fonts is a font style display service operated by Google LLC or by Google Ireland Limited, depending on how the Data Controller manages the processing of Data, which allows this Website to integrate such content within its pages.

Personal Data processed: Usage Data; Tracking Tools.

Place of processing: United States - Privacy Policy; Ireland - Privacy Policy.

Font Awesome (Fonticons, Inc. )

Font Awesome is a font style display service operated by Fonticons, Inc. that allows this Web Site to integrate such content within its pages.

Personal Data processed: Usage Data; Tracking Tools.

Place of processing: United States -
 Privacy Policy.

Instagram Widget

Instagram is an image display service operated by Meta Platforms, Inc. or Meta Platforms Ireland Limited, depending on how the Data Controller manages the processing of the Data, which allows this Website to integrate such content within its pages.

Personal Data processed: Usage Data; Tracking Tools.


Place of processing: United States - Privacy Policy; Ireland - Privacy Policy.

 

YouTube Video Widget

YouTube is a video content display service operated by Google LLC or Google Ireland Limited, depending on how the Data Controller manages the processing of the Data, which enables this Website to integrate such content within its pages.

Personal Data processed: Usage Data; Tracking Tools.

Place of processing: United States - Privacy Policy; Ireland - Privacy Policy.


Information on how to disable interest-based advertisements

In addition to any opt-out functionality provided by any of the services listed in this document, Users can read more about how to disable interest-based advertisements in the appropriate section of the Cookie Policy.

Further information on the processing of Personal Data

  • Sale of goods and services online

The Personal Data collected is used for the provision of services to the User or for the sale of products, including payment and possible delivery. The Personal Data collected to finalise payment may be that relating to the credit card, bank account used for the transfer or other payment instruments provided. The Payment Data collected by this Website depends on the payment system used.

 

User rights


Users may exercise certain rights with reference to the Data processed by the Data Controller.

In particular, Users are entitled to:

  • withdraw consent at any time. The User may revoke the consent to the processing of its Personal Data previously expressed.
  • object to the processing of their Data. The User may object to the processing of its Data when it is done on a legal basis other than consent. Further details on the right to object are set out in the section below.
  • access to their Data. The User has the right to obtain information on the Data processed by the Controller, on certain aspects of the processing and to receive a copy of the Data processed.
  • verify and request rectification. The User may verify the correctness of its Data and request that it be updated or corrected.
  • obtain the restriction of the processing. When certain conditions are met, the User may request the restriction of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its preservation.
  • obtain the deletion or removal of their Personal Data. When certain conditions are met, the User may request the deletion of its Data by the Data Controller.
  • receive their Data or have them transferred to another Data Controller. The User has the right to receive its Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred without hindrance to another data controller. This provision is applicable when the Data are processed by automated means and the processing is based on the User's consent, on a contract to which the User is party or on contractual measures related thereto.
  • Lodge a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.

Details on the right to object

Where Personal Data are processed in the public interest, in the exercise of public authority vested in the Controller or in pursuit of a legitimate interest of the Controller, Users have the right to object to the processing on grounds relating to their particular situation.

Users are reminded that if their Data are processed for direct marketing purposes, they may object to the processing without giving any reason. To find out whether the Controller processes Data for direct marketing purposes, Users may refer to the respective sections of this document.

How to exercise your rights

In order to exercise their rights, Users may address a request to the contact details of the Controller indicated in this document. Requests are filed free of charge and processed by the Controller as soon as possible, in any case within one month.

Cookie Policy

This Website makes use of Tracking Tools. To find out more, the User can consult the Cookie Policy.

Further information on processing

Legal defence

User's Personal Data may be used by the Data Controller for defence in court or in preparatory stages leading to a possible legal action, against improper use of the same one or related to services by the User. 
The User declares that he/she is aware that the Data Controller may be obliged to disclose the Data upon order of public authorities.

Specific disclosures

Upon the User's request, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

System logs and maintenance

For operation and maintenance purposes, this Website and any third-party services used by it may collect system logs, i.e. files that record interactions and which may also contain Personal Data, such as the User's IP address.

Information not contained in this policy

Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

Responding to "Do Not Track" requests

This Website does not support "Do Not Track" requests.
To find out whether any third party services being used support them, the User is invited to consult their respective privacy policies.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Website as well as, when technically and legally feasible, by sending a notification to Users through one of the contact details in his/her possession. Therefore, please consult this page frequently, referring to the date of lthe ast modification indicated at the bottom.

If the changes affect processing whose legal basis is consent, the Data Controller will collect the User's consent again, if necessary.


Definitions and legal references

Personal Data (or Data)

Personal data is any information which, directly or indirectly, even in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.

Usage Data


This is the information collected automatically through this Website (including by third party applications integrated into this Website), including: IP addresses or domain names of the computers used by the User who connects with this Website, URI (Uniform Resource Identifier) notation addresses, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (successful, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various time connotations of the visit (e.g. time spent on each page) and details of the itinerary of the visit (e.g. time spent on each page) and the time spent on the website. ) the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (e.g. the length of time spent on each page) and the details of the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the operating system and the User's IT environment.


User

The individual who uses this Website which, unless otherwise specified, coincides with the Data Subject.

Data Subject

The natural person to whom the Personal Data refer.

Data Controller (or Processor)

The natural person, legal entity, public administration and any other entity that processes Personal Data on behalf of the Controller, as set out in this privacy policy.

Data Controller (or Owner)

The natural or legal person, public authority, service or other body that, individually or jointly with others, determines the purposes and means of the processing of personal data and the instruments adopted, including the security measures relating to the operation and use of this Website. The Data Controller, unless otherwise specified, is the owner of this Website.

This Website (or this Application)

The hardware or software tool through which Users' Personal Data are collected and processed.

Service

The Service provided by this Website as defined in the relevant terms (if any) on this site/application.

European Union (or EU)

Unless otherwise specified, any reference in this document to the European Union shall be deemed to include all current member states of the European Union and the European Economic Area.

Cookies

Cookies are tracking tools that consist of small pieces of data stored within the User's browser.

Tracking Tool

A Tracking Tool is any technology - e.g. cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting - that allows Users to be tracked, for example by collecting or storing information on the User's device.

Legal references

This Privacy Policy is drafted on the basis of multiple legislative orders, including Articles 13 and 14 of Regulation (EU) 2016/679.

Unless otherwise specified, this privacy policy applies exclusively to this Website.

Additional notice 

This notice is provided by Dulàc Farmaceutici 1982 S.r.l. as the data controller (hereinafter, also "Company" or "Data Controller") of personal data acquired through the website [nuvocosmetic.com], of which it is the owner, pursuant to the in force in the field of privacy and data protection and taking into account the provisions of the Guarantor Authority for the Protection of Personal Data (hereinafter, also "Guarantor"), Regulation (EU) 2016/679 (hereinafter also "Regulation"), Legislative Decree no. 196/2003 and ss.mm.ii. (hereinafter also "Privacy Code") as well as, in general, the applicable reference legislation.

This information is provided to users who browse and use the services available on the website [nuvocosmetic.com].
Your registration on the website [nuvocosmetic.com] is conditional on your prior reading and acceptance of this policy regarding the processing of personal data and your authorization to its processing.

Source and categories of data processed
The personal data that the Company may acquire will be acquired directly from the interested user who browses the [nuvocosmetic.com] website.
The data processed may be by way of example:

Navigation data
The computer systems and software procedures responsible for the operation of this website acquire, in the course of their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected to be associated with identified individuals, but which by its very nature could allow users to be identified. This category of data includes (i) the IP addresses or domain names of the computers used by users connecting to the site, (ii) the URI (Uniform Resource Identifier) notation addresses of the resources requested, (iii) the time of the request, (iv) the method used to submit the request to the server, (v) the size of the file obtained in response, (vi) the numerical code indicating the status of the response given by the server (successful, error) and (vii) other parameters relating to the user's operating system and computer environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of this Website and to check its correct functioning and are deleted immediately after processing.
This Website makes use of its own and third-party technical, analytical, and profiling cookies,

Data provided voluntarily by the user
The optional, explicit and voluntary sending, by the user who browses this website and interacts with it through
- The 10€ off for you form at https://www.nuvocosmetic.com/
- The site registration form at page nuvocosmetic.com/account/login?return_url=%2Faccount
- The purchase form at page https://www.nuvocosmetic.com/en/checkout/
- The return form on page https://www.nuvocosmetic.com/en/returns-refunds
- The contact form on the page nuvocosmetic.com/en/pages/contatti

involves the acquisition and processing by the Controller of such data and any other information contained in such communications for the purposes indicated in the following paragraph.
The data that may be processed are mainly identification, contact and personal data (e.g., first and last name, residential address, telephone number, e-mail address, etc.). Under no circumstances will personal data of a sensitive nature under Article 9 of the Regulations) or judicial data under Article 10 of the Regulations) be processed.

In addition, for needs related to the operation or maintenance of this website, system logs may be processed, i.e. files that record interactions with the user and may also include personal data, including the user's IP address.

Full details on each type of data collected will be provided in the dedicated sections of this privacy policy or through specific informational texts that the user may read before the data is collected.

Purposes of processing
The processing of personal data acquired is carried out to:
(a) outline the authentication profile necessary to access the site and therefore allow the user to register to the same (including for the purpose of issuing the loyalty card), to execute the conditions of use of the site accepted during registration, to allow the use of the services rendered by this site (by way of example, the purchase of products, the shipment of products purchased, manage any returns) following the user's registration, for the management of any requests made by the user through the website. The provision of the data is, as the case may be, a contractual obligation or a pre-contractual measure taken at the request of the data subject and failure to provide the data means that the Company will not be able to give exact execution to what has been outlined above;
b) to fulfill the obligations provided for by provisions of laws and regulations, or to execute an order of the judicial authority or other authorities to which the Data Controller is subject. The provision of the data is a legal obligation and failure to provide it means that the Company will not be able to fulfill exactly the obligations outlined above;
c) allow the Data Controller to carry out direct marketing activities in order to provide the user with information on promotions, discounts, concessions, events, products and other services from the Data Controller, including through the sending of appropriate advertising and/or informational material (e.g. catalogs) in printed and/or electronic form, by means of newsletters (via e-mail) or other tools (e.g. text messages, instant messaging). The provision of data is optional and requires the user's prior consent, which is free and specific, and failure to provide such data will result in the Company's inability to carry out the marketing activities contemplated therein (and will not have any negative consequences regarding the possibility of registering or browsing the website);
d) the collection, analysis of user behavior, profiling, recording and processing of purchase data, including those relating to the details of the frequency, quantity and type of purchases (even if only potential) in order to analyze the propensity to purchase and, in general, user profiling to prepare and propose personalized promotions and offers, as well as for analysis and market research. The provision of data is optional and requires the user's prior consent, free and specific, and failure to provide such data will result in the impossibility for the Company to perform the profiling activities contemplated therein (and will not have any negative consequence regarding the possibility of registering or browsing the website).
e) the transfer of personal data to third parties operating in the field of [-] for marketing purposes, market research or other sample research, for the detection of the degree of satisfaction, to receive informative, promotional, commercial and advertising material or inherent to contests and initiatives, including through the sending of appropriate material (e.g. catalogs, flyers) in paper and/or electronic form, by means of newsletters (e-mail) or other tools (instant messaging). The provision of data is optional and requires the user's prior consent, free and specific, and failure to provide such data will result in the inability of the Company to perform the activities contemplated therein (and will not have any negative consequence regarding the possibility of registering or browsing the website).
f) allow the Data Controller to register, downstream of the user's subscription to the newsletter service or after making a purchase through this website, the user's e-mail address in a contact list to which e-mails containing information also of a commercial and promotional nature may be transmitted. The provision of data is optional and requires the user's prior consent, which is free and specific, and failure to provide such data will result in the inability of the Company to perform the activities contemplated therein (and will not have any negative consequence regarding the possibility of registering or browsing the website).