(VALID FROM 27.09.2021)
The associated Ray-Ban.com website, which can be accessed via the following link ray-ban.com/denmark (hereinafter the "website"), is administered by Luxottica Group S.p.A., who acts as the data controller (hereinafter "Luxottica") in connection with the processing of your personal data in accordance with this data protection policy (hereinafter the "data protection policy").
Read the content of the data protection policy below to find out more about how Luxottica processes your personal data.
1. AN INTRODUCTION TO HOW WE USE YOUR PERSONAL DATA
This data protection policy describes how Luxottica collects and processes your personal data as users of the website (hereinafter, "user", "users", "the registered person" or "you") in accordance with the EU's general data protection regulation 2016/679 (hereinafter "GDPR") and the Italian legislative decree no. 196/2003, as most recently amended and integrated (hereinafter the "legislative decree").
As described in more detail below, Luxottica processes your personal data with a view to supplying products and services to you and to give you the opportunity to take part in initiatives, competitions and events that Luxottica organizes for its customers. If you would like to receive news, offers and campaign e-mails from Luxottica, Luxottica will – with your prior consent – process your personal data with a view to sending you marketing communications that match your preferences and interests. Luxottica will, in all cases, process your personal data securely, including taking all appropriate security precautions, and will only allow authorized persons and third parties in the EU and USA to have access to your personal data using methods that comply with applicable data protection legislation.
All personal data that you have provided via this website shall only be used for the purposes and using the methods described below.
2. WHAT PERSONAL DATA DO WE USE, AND WHERE DOES IT COME FROM?
Luxottica processes your personal data which we obtain directly from you and from other sources according to the descriptions under the categories of personal data listed below (hereinafter collectively "personal data"):
a) Personal data received directly from you
Luxottica processes the following categories of personal data received directly from you:
- Identifying information provided during registration, creation of an account on the website, placing of an order or participation in initiatives, competitions or events organized by Luxottica, for example first name and surname, e-mail address, user ID, access code, gender, country of residence, postal address and phone number;
- financial information and data relating to your credit card for purchasing products from the website;
- information from correspondence or requests that you have sent to Luxottica, or which Luxottica has requested following reports of problems with our service on the website or purchased products;
- information regarding your profile on social media, if this is public, or if you have chosen to log into the website via social media or linked your Luxottica account to your public profiles on social media and share your actions on the website on these channels using the corresponding plug-ins (e.g. Facebook Connect, Likes, FB sharing, etc.). If you choose to share this information, personal data which is published on your social media profile will be collected by the website and processed for the corresponding functions. This means that the use of the above-mentioned plug-ins implies a sharing of the corresponding actions and information on related social media.
b) Personal data obtained from automatic tracking systems when you visit the website and use services on the website.
Luxottica processes the following categories of personal data collected via automatic tracking systems when you visit the website and use services on the website:
- Information relating to your use of the website. For security reasons, Luxottica processes log files for every session when the user logs into their account, and information on payment transactions which must be processed through Luxottica's e-payments provider;
- browsing information when you navigate around the website. Luxottica uses a number of technologies (e.g. cookies and automatic tracking systems) that automatically collect certain types of information relating to the way in which the user uses the website, including the IP address or other unique codes for the device (computer, mobile or other device) that the user is using to visit the website, identification as a registered or non-registered user, technical data which may include the URL address that a user has come from, browser information and language. This information helps us to continuously improve the browsing experience and purchasing procedure for Luxottica products and services and to monitor operation of the website. This information only includes statistical data relating to the user's actions and is not intended to be used to link to the user's identifying information. Browsing data can only be used to identify you when it is matched to your identifying personal data.
3.FOR WHAT PURPOSES DO WE USE YOUR PERSONAL DATA?
Luxottica processes your personal data for the following purposes:
3.1 Contractual purposes – To allow us to deliver products and services to you
Luxottica processes your personal data for the purposes that are necessary to provide the products and services that are sold via the website, specifically for the following contractual purposes:
- To make it possible for you to register on the website and create your own account;
- to provide services that are available via the website (e.g. administration of the registration process and access to the account, account management, reminders about products in the shopping cart, etc.)
- to administer the sale of products and online orders and provide products and services;for at administrere salg af produkter samt online bestillinger og levere produkter og tjenester;
- to process physical and digital payments, including with a view to invoicing obligations;
- to provide sales and after-sales services (for example, fraud prevention, returns, warranty and customer support), including sending operational information to users independently of the product or service, sales and after-sales services;
- to respond to user requests (e.g. management of requests for information, booking of a sight test, making the "share with a friend" function available, sending messages to you with the "back in stock" feature, etc.)
- to give you the opportunity to participate in Luxottica's initiatives;
- to give you the opportunity to take part in competitions and initiatives supported by Luxottica.
Processing of data for contractual purposes is necessary to allow the required products and services to be provided. If you do not want your personal data to be used for these purposes, Luxottica will not be able to provide you with the required products and services.
3.2 Legal purposes – We must ensure that we comply with our legal obligations
Luxottica can process your personal data to ensure that we comply with our legal obligations, especially in relation to the following legal purposes:
- To comply with legal requirements, rules, protocols as well as national and EU legislation;
- to implement decisions made by public authorities.
Processing of data for legal purposes is necessary as it is required by the applicable legislation. If you do not want your personal data to be processed for these purposes, then you cannot use the website.
3.3 Marketing purposes – You can accept or refuse to allow us to use your personal data for marketing-related activities
Luxottica processes your personal data with your prior consent for the following marketing purposes [with the exception of prescription information]:
- To send commercial and promotional information and ongoing updates (e.g. via e-mail, phone, sms/mms, post, social media and newsletter) relating to Luxottica's products, services, initiatives and events. If you are an existing Luxottica customer, Luxottica can also, in accordance with the article 130, subsection 4 of the legislative decree, send commercial information via e-mail about products, events and services similar to those already provided to you, unless you object to such processing at the time of collection and upon receipt of each communication. You can refuse processing at any time by following the instructions in the individual messages;
- to perform statistical analyses of the customer target group.
The processing of data for marketing purposes is discretionary, subject to your prior consent or your refusal under the circumstances mentioned in the above article 130, subsection 4 of the legislative decree. You are free not to provide personal data for marketing purposes, and you are also entitled to later withdraw the consent to process your personal data that you have given previously. In this case, Luxottica will no longer send you marketing communications or inform you of offers and campaigns relating to Luxottica's products, services and initiatives.
3.4 Segmentation and profiling purposes – If you wish, you can choose for marketing communications to be more closely adapted to your personal preferences
If you have given your consent for your personal data to be processed for marketing purposes, Luxottica can process your personal data for segmentation purposes to analyze your personal data as concerns purchase consumption, product categories, date of birth and purchase method in connection with marketing-related activities. This activity performed by Luxottica is based on Luxottica's legitimate interest in providing a service which meets your needs whilst also respecting your rights, as concerns the limited amount of personal data processed. Processing of personal data for segmentation purposes is covered on the grounds of legitimate interest, which we refer to in the following section.
3.5 Purposes with legitimate interest – Your rights and Luxottica's rights are appropriately balanced unless you opt out
In addition to processing your personal data for segmentation and profiling purposes, Luxottica also processes your personal data for other purposes with legitimate interest, including:
- to assert a legal claim or defend a legal claim in legal proceedings or in administrative or extrajudicial proceedings regarding the rights of Luxottica and its companies and/or representatives, shareholders, employees and directors;
- to enable the technical management of the website and features of the website, including the resolution of technical issues, in order to carry out tests, updates and upgrades that cannot be carried out with non-personal data;
- to prevent or identify fraudulent activities or misuse of the website or targeting the Luxottica group and/or users of the website;
- to complete potential mergers, sales of shares, transfer of all or a significant part of its business or a financial transaction, by passing on or transferring the personal data to a third party or parties involved in the transaction as part of the transaction;
- to undertake surveys, including market research, in relation to Luxottica's products and services via post, phone or e-mail; to anonymize personal data in order to carry out statistical analyses.
Processing of your personal data in connection with the above-stated purposes with legitimate interest and segmentation purposes takes place in accordance with article 6, point f) of the GDPR to exercise Luxottica's legitimate interest, which is suitably balanced with your interest, in that the data processing only takes place for the purpose of carrying out such economic activities when this is strictly necessary. Such processing of data is not compulsory, and you can therefore object to the data processing in question at any time using the procedures that are outlined in this data protection policy. In this case, data will not be processed by Luxottica for this purpose, unless Luxottica demonstrates the existence of compelling legitimate grounds or to exercise Luxottica's rights in connection with article 21 of the GDPR.
4.WHAT METHODS DO WE USE WHEN PROCESSING YOUR PERSONAL DATA?
The electronic and manual processing of your personal data takes place exclusively within the limits necessary to fulfill the above purposes.
Luxottica undertakes to protect users' personal data. Luxottica recommends that, among other measures, a password is used to protect the account. Users are therefore encouraged to use a password that is sufficiently secure and to store it somewhere secure on their own PC and browsers where access to it is limited, and to log out again after visiting the website. All personal data relating to users is stored on secure servers with appropriate security measures to protect personal data from any unauthorized access which will ensure the accuracy of the personal data and guarantee proper use of the data. Furthermore, a secure system is used to approve credit card payments and identify fraudulent actions. Luxottica uses standard SSL (Secure Sockets Layer) to protect your personal data.
5. WHO DO WE PROVIDE YOUR PERSONAL DATA TO?
Luxottica can disclose your personal data to:
- third-party service providers who are responsible for data processing activities and provide services or assistance and advice to Luxottica, including but not limited to: technology, accounting, administration, law, insurance, IT, marketing, data analysis;
- companies in the Luxottica group;
- persons and authorities who are authorized by law, rules or regulations issued by legally authorized authorities to access your personal data;
- a potential buyer of Luxottica and their companies, in connection with a merger or transformation that involves Luxottica;
- and competent authorities.
The above receivers will process your personal data as data controllers, data processors or persons with responsibility for data processing, depending on the circumstances.
It is possible to request a copy of a complete list of data processors via the procedures that are outlined in this data protection policy.
6. WHO CAN YOUR PERSONAL DATA BE TRANSFERRED TO?
Luxottica is permitted to transfer your personal data to the above-stated receivers, including receivers outside of the EU and specifically receivers in the USA. For transfers from the EU to countries that are considered by the European Commission to have an insufficient degree of protection, the company has taken the necessary and appropriate precautions to protect personal data. Personal data is thus transferred in accordance with the requirements and obligations of applicable data protection legislation pursuant to Article 44 et seq of the GDPR. For more information on the necessary and appropriate security measures and means, and the procedure the user may follow to obtain a copy of these, the user can contact Luxottica through the channels described in this data protection policy.
7.HOW LONG WILL LUXOTTICA KEEP YOUR PERSONAL DATA?
Luxottica stores personal data for as long as is strictly necessary for the purposes for which the persona data was collected and then processed, including any retention period required by applicable law.
Luxottica will process your personal data for contractual purposes or on grounds of legitimate interest during the term of the contract (in the case of an account created on the website or a purchase or in relation to services provided by Luxottica) and for 10 years from the completion of the purchase or the service provision.
Personal data stored for legal purposes will be retained for as long as is strictly necessary to comply with the applicable law.
Personal data for marketing and profiling purposes, including segmentation purposes, will be processed for seven years after the last purchase and/or last contact with you (e.g. registration for a competition, participation in an event, opening of a newsletter), without prejudice to your right to withdraw your consent at any time or object to the processing of your personal data.
8. ARE YOU UNDER THE AGE OF 16?
The processing of personal data highlighted in this policy does not include minors under the age of 16.
If personal data about minors is inadvertently recorded, Luxottica will ensure this is deleted swiftly at the user's request.
9. HOW CAN YOU EXERCISE YOUR RIGHTS TO YOUR PERSONAL DATA?
You are entitled to exercise the following rights at any time:
- a) Obtain confirmation from Luxottica regarding the existence of personal data and be informed of the content and source, verify its accuracy and request its integration, update or modification;
- b) request the deletion, anonymization or restriction of the processing of personal data, if this is done in breach of applicable legislation;
- c) object, in whole or in part, to the processing of personal data, based on legal considerations;
- d) withdraw consent to the processing of data (if and to the extent that such consent is necessary);
- e) ask Luxottica to limit the processing of your personal data, where:
- you dispute the accuracy of the personal data, until such time as Luxottica has taken sufficient steps to correct and verify its accuracy;
- the processing is unlawful, but you do not want us to delete your personal data;
- Luxottica no longer needs to use your personal data for processing purposes, but you need to use it to establish, exercise or defend legal claims; or
- you have objected to the processing based on legitimate interests and await confirmation as to whether Luxottica has compelling legitimate grounds for continued processing;
f) object to the processing of your personal data in the case of processing based on legitimate interests, unless Luxottica demonstrates the existence of compelling legitimate grounds for the processing or for the purpose of establishing, exercising or defending legal claims;
g) request the deletion of your personal data without undue delay;
h) receive an electronic copy of your personal data if you wish to transfer your personal data to yourself or another provider, when Luxottica is dependent on your consent or the fact that the processing is necessary to be able to provide the services and the personal data is processed automatically; and
i) file a complaint with the relevant data protection supervisory authority.
Pursuant to Article 2l of the legislative decree, the above-stated rights can be exercised by another duly entitled person ("successor") who has their own interests or is acting as a user's representative, or if there are family circumstances that must be protected. The user can expressly circumvent the exercising by a successor of any of the above-stated rights by sending a request to the email address below. The user may withdraw or alter any such request at any time under the same conditions.
You can exercise the above-stated rights at any time by clicking here. Luxottica will respond within a reasonable period of time (and, in all cases, within the time limit set by the applicable legislation) after confirming the user's identity.
Luxottica also provides the user with tools to update and change their personal data. All registered users can update their data at any time (e.g. via their user accounts). Users can also change or update their preferences on how they wish to receive e-mails and other information from Luxottica. The user is entitled to request that information on their account be deleted.
10. HOW TO CONTACT LUXOTTICA
The data controller responsible for processing your personal data is Luxottica Group S.p.A., and its headquarters are at Piazzale Luigi Cadorna, 3, 20123 Milan, Italy.
If you have any questions or comments concerning this data protection policy or the data processing carried out by Luxottica, you can contact Luxottica by clicking the link in the previous section.
11. HOW TO CONTACT OUR DATA PROTECTION OFFICER
Luxottica has appointed a data protection officer in accordance with article 37 of the GDPR, who can be contacted at the following e-mail address: firstname.lastname@example.org or at Luxottica's postal address, which can be found under "HOW TO CONTACT LUXOTTICA" in this data protection policy
12. HOW TO KEEP UP TO DATE WITH CHANGES TO THIS DATA PROTECTION POLICY
This data protection policy is continuously changed for legal or organizational reasons. We therefore recommend that you frequently check for the latest version of this data protection policy. In any case, you will be informed of changes in advance, and an updated version of the data protection policy will be available on the website at all times.