RomaEst

PRIVACY NOTICE

Privacy Policy

This Privacy Policy describes, in compliance with European Regulation 2016/679 (the "GDPR") and applicable national laws, how personal data is processed for visitors and users of the website https://romaest.klepierre.it/ (the "Site").

1. DATA CONTROLLERS

The Data Controllers are: Both parties act as autonomous Data Controllers (together, the "Controllers").

Consorzio degli Operatori del Centro Commerciale Roma Est ("RomaEst" or "Italian Data Controller") – Address: V. Collatina, Km 12.800, 00132 Roma (RM)

Klépierre Management (the "Klépierre" or "French Data Controller") – Address: Boulevard des Capucines n. 26, CS 20062 - 75009 Paris, France.

2. DATA PROTECTION OFFICER (DPO)

The Data Protection Officers (the "DPO") for both Controllers can be contacted via the following email addresses:

Italian Data Controller: info@italambiente.it

French Data Controller: dpo@klepierre.com

3. CATEGORIES OF PERSONAL DATA PROCESSED

The personal data processed (the "Personal Data") is that which you have communicated or that has been lawfully acquired by the Controllers. The types and methods of processing data relating to the websites are described below.

You can deactivate this data sharing by accessing your account settings. For more details, we encourage you to review the website of the social networks you are subscribed to (e.g., www.facebook.com, www.twitter.com, www.youtube.com, www.instagram.com).

Browsing/Operational Data: The IT systems, telecommunication networks, and software procedures used to operate the websites collect, during their normal operation, certain data whose transmission is implicit in the use of web communication protocols. This category of data includes, for example, IP addresses, the date and time of access, the pages visited (URI/URL), the numerical code indicating the server response status, the method used to make the request to the server, the names of the devices used to connect to the websites, and other parameters related to the user's operating system and computing environment.

Voluntarily Provided Data: Certain sections of the website request personal data, for example, to allow you to subscribe to the newsletter or register on the Site.

Cookies and Tracking Tools: For purposes related to the management of consents for tracking, please refer to the "Cookie Policy" section of the Site and the cookie management tool available.

Location Data: The websites may collect location data (approximate) provided by your IP address, subject to your specific consent.

Content Sharing Data via Social Networks: The Site may include plugins and/or buttons to allow sharing content on the Social Networks (e.g., Facebook, Twitter, LinkedIn, YouTube, Instagram) that you use.

4. PURPOSES OF PROCESSING, LEGAL BASIS, AND RETENTION PERIOD

The Controllers process your Personal Data for specific purposes and only when there is a valid legal basis as required by applicable privacy laws.

The Controllers process your Personal Data for the following purposes, legal bases, and retention periods:

a. Site Management and Monitoring: Ensuring the proper functioning and security of the Site:

For cookie-related data, please refer to the "Cookie Policy".

b. User Registration and Access to Exclusive Services: Including participation in satisfaction surveys, event registration, or initiatives that require user registration:

Legal basis: Performance of a contract to which you are a party or in response to a request made by the user.

Retention: Data is stored until you request the cancellation of your registration.

c. Newsletter Subscription:

Legal basis: Consent.

Retention: Data is stored until you request to unsubscribe.

d. Marketing: Including sending commercial communications, promotional material, offers of products and services, and conducting statistical/market research:

Legal basis: Your voluntary, free, and revocable consent at any time.

Retention: Data is stored until consent is withdrawn.

e. Profiling:

Legal basis: Your voluntary, free, and revocable consent at any time.

Retention: Data is stored until consent is withdrawn.

f. Fraud/Abuse Prevention and Detection: Prevention and repression of fraud/abuses/fraudulent activities via the website:

Legal basis: Legitimate interest of the Controllers.

Retention: Data is stored for up to 180 days and then deleted or anonymized.

g. Legal Claims: Investigation, exercise, or defense of a right in judicial proceedings:

Legal basis: Legitimate interest of the Controllers.

Retention: Data is retained for the entire duration of the claim and/or legal proceeding until expiration of judicial protection or appeal actions.

5. DATA PROVISION

The provision of data for purposes based on contract performance or the legitimate interest of the Controllers (Article 6.1(b) and (f) of the GDPR) is necessary to pursue the above-mentioned purposes.

Providing data for purposes based on your consent (Article 6.1(a) of the GDPR) is optional. Failure to provide consent will not affect your ability to register on the Site or use the services provided under contractual terms.

6. RECIPIENTS AND AUTHORIZED PARTIES

Your Personal Data is processed by employees, collaborators, or external parties of the Controllers, who act as authorized persons or data processors and perform technical and organizational tasks on behalf of the Controllers based on specific instructions.

7. DATA TRANSFER OUTSIDE THE EU

The Controllers will not transfer your Personal Data outside the European Union.

8. RIGHTS OF DATA SUBJECTS

By contacting the Controllers at the addresses specified in Article 2, you can request access to your data, deletion, correction of inaccurate data, completion of incomplete data, data portability, limitation of processing under Article 18 of the GDPR, and opposition to processing where legitimate interest applies. For consent management, we encourage you to read the "Cookie Policy" or review the "Profile" section in your account. You also have the right to lodge a complaint with the competent supervisory authority in your country of residence or the country where the alleged violation occurred.

Last Updated: 29/10/2024

Created with Lunacy