Privacy Policy of www.inomluxuryauctions.com
This Application collects some Personal Data of its Users.
This document can be printed using the print command available in the settings of any browser.
Data Controller
INOM S.R.L.
Via Vincenzo Foppa, 25
20144 Milan (MI)
VAT/tax code: 12510780963
Email address of the Data Controller: info@inomluxuryauctions.com
Types of Data Collected
Among the Personal Data collected by this Application, independently or through third parties, there are: name; surname; phone number; company name; profession; email; Tracking Tools; Usage Data. Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific informative texts displayed before the data is collected.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application. Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to provide them, this Application may be unable to provide the Service. In cases where this Application indicates some Data as optional, Users are free to refrain from communicating such Data, without this affecting the availability or operation of the Service.
Users who have doubts about which Data are mandatory are encouraged to contact the Data Controller.
The possible use of Cookies – or other tracking tools – by this Application or by the third-party service providers used by this Application, unless otherwise specified, is aimed at providing the Service requested by the User, in addition to any other purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Application and guarantees that they have the right to communicate or disclose them, releasing the Data Controller from any liability to third parties.
Methods and Place of Processing of the Collected Data
Processing Methods
The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data. Processing is carried out using computers and/or IT-enabled tools, organizational methods, and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) appointed, if necessary, as Data Processors by the Data Controller. The updated list of these parties may be requested from the Data Controller at any time.
Legal Basis of Processing
The Data Controller processes Personal Data relating to the User if one of the following conditions exists:
- The User has given consent for one or more specific purposes. Note: In some legislations, the Data Controller may be permitted to process Personal Data without the User’s consent or another of the legal bases specified below until the User objects (“opt-out”) to such processing. This is not, however, applicable whenever the processing of Personal Data is subject to European data protection law;
- The processing is necessary for the performance of a contract with the User and/or for the pre-contractual obligations;
- The processing is necessary for compliance with a legal obligation to which the Data Controller is subject;
- The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
- The processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.
It is always possible to ask the Data Controller to clarify the concrete legal basis of each processing and, in particular, to specify whether the processing is based on the law, provided for by a contract, or necessary to conclude a contract.
Place
The Data is processed at the Data Controller’s operating offices and in any other places where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the processing location, the User can refer to the section concerning the details on the processing of Personal Data.
The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization of international public law or consisting of two or more countries, such as the UN, as well as regarding the security measures taken by the Data Controller to protect the Data.
The User can check whether one of the above-mentioned transfers takes place by examining the section of this document relating to the details on the processing of Personal Data or request information from the Data Controller by contacting them at the contact details provided at the beginning.
Retention Period
The Data is processed and stored for the time required by the purposes for which it was collected.
Therefore:
- Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until such contract has been fully performed.
- Personal Data collected for the purposes of the legitimate interests pursued by the Data Controller will be retained until such interests are satisfied. The User can obtain further information about the legitimate interests pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
- When processing is based on the User’s consent, the Data Controller may retain Personal Data for a longer period until such consent is revoked. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, Personal Data will be deleted. Therefore, at the end of this term, the right to access, delete, correct, and the right to data portability can no longer be exercised.
Purposes of Processing of the Collected Data
User Data is collected to allow the Data Controller to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect their rights and interests (or those of Users or third parties), detect any malicious or fraudulent activities, and for the following purposes: Contacting the User and Statistics.
For detailed information on the purposes of the processing and on the Personal Data processed for each purpose, the User can refer to the section “Details on the processing of Personal Data”.
Details on the Processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
Contact Form (this Application)
By filling in the contact form with their Data, the User consents to their use to respond to requests for information, quotes, or any other kind indicated by the form header.
Personal Data processed: surname; email; name; phone number; profession; company name.
The services contained in this section allow the Data Controller to monitor and analyze traffic data, and are used to track user behavior.
Google Analytics with anonymized IP (Google Ireland Limited)
Google Analytics is a web analytics service provided by Google Ireland Limited (“Google”). Google uses the Personal Data collected for the purpose of tracking and examining the use of this Application, compiling reports, and sharing them with other services developed by Google. Google may use the Personal Data to contextualize and personalize the ads of its own advertising network.
This integration of Google Analytics anonymizes your IP address. Anonymization works by shortening the IP address of the Users within the borders of the member states of the European Union or in other countries participating in the agreement on the European Economic Area. Only in exceptional cases, the IP address will be sent to Google’s servers and shortened within the United States.
Personal Data processed: Usage Data; Tracking Tools.
Place of processing: Ireland – Privacy Policy – Opt Out.
User Rights
Users may exercise certain rights regarding the Data processed by the Data Controller.
In particular, the User has the right to:
- Withdraw their consent at any time. The User can withdraw their consent to the processing of their Personal Data previously expressed.
- Object to the processing of their Data. The User can object to the processing of their Data when it occurs on a legal basis other than consent. Further details on the right to object are indicated in the section below.
- Access their Data. The User has the right to obtain information about the Data processed by the Data Controller, certain aspects of the processing, and receive a copy of the Data processed.
- Verify and ask for rectification. The User can verify the accuracy of their Data and request its update or correction.
- Obtain the limitation of processing. When certain conditions are met, the User can request the limitation of the processing of their Data. In this case, the Data Controller will not process the Data for any other purpose than their storage.
- Obtain the erasure or removal of their Personal Data. When certain conditions are met, the User can request the erasure of their Data by the Data Controller.
- Receive their Data or have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable when the Data is processed by automated means and the processing is based on the User’s consent, on a contract of which the User is a party, or on contractual measures connected to it.
- Lodge a complaint. Users who believe that the processing of their Personal Data through this site is in violation of the provisions of the Regulation have the right to lodge a complaint with the Guarantor for the protection of personal data, as provided for in Article 77 of the Regulation itself, or to bring the matter before the appropriate judicial authorities (Article 79 of the Regulation).
.
Details on the Right to Object
When Personal Data is processed in the public interest, in the exercise of official authority vested in the Data Controller, or to pursue a legitimate interest of the Data Controller or a third party, Users have the right to object to the processing for reasons related to their particular situation.
Users are reminded that if their Data is processed for direct marketing purposes, they can object to the processing without providing any reasons. To find out if the Data Controller processes data for direct marketing purposes, Users can refer to the respective sections of this document.
How to Exercise Rights
To exercise User rights, Users can make a request to the contact details of the Data Controller provided in this document. Requests are free of charge and processed by the Data Controller as soon as possible, in any case within one month.
Cookie Policy
This Application uses Tracking Tools. For more information, the User can consult the Cookie Policy.
Further Information on Processing
Legal Defense
The User’s Personal Data may be used by the Data Controller in court or in the preparatory stages leading to possible legal action arising from its improper use or that of related services by the User.
The User declares to be aware that the Data Controller may be required to reveal the Data at the request of public authorities.
Specific Information
At the request of the User, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific services, or the collection and processing of Personal Data.
System Logs and Maintenance
For operation and maintenance purposes, this Application and any third-party services it uses may collect system logs, i.e., files that record interactions and that may also contain Personal Data, such as the User’s IP address.
Information Not Contained in this Policy
More information in relation to the processing of Personal Data may be requested at any time to the Data Controller using the contact details.
Response to “Do Not Track” Requests
This Application does not support “Do Not Track” requests.
To find out if any third-party services used support them, Users are encouraged to consult the respective privacy policies.
Changes to this Privacy Policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Application, as well as, if technically and legally feasible, by sending a notice to Users through one of the contact details held by the Data Controller. Therefore, please check this page frequently, referring to the date of the last modification indicated at the bottom.
If the changes affect processing whose legal basis is consent, the Data Controller will collect the User’s consent again, if necessary.
Definitions and Legal References
Personal Data (or Data)
Any information that, directly or indirectly, also in connection with any other information, including a personal identification number, makes an individual identified or identifiable.
Usage Data
Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.
User
The individual using this Application, which must coincide with or be authorized by the Data Subject, to whom the Personal Data refers.
Data Subject
The legal or natural person to whom the Personal Data refers.
Data Processor (or Data Supervisor)
The natural person, legal person, public administration, or any other body, association, or organization authorized by the Data Controller to process the Personal Data in compliance with this privacy policy.
Data Controller (or Owner)
The natural person, legal person, public administration, or any other body, association, or organization with the right, also jointly with another Data Controller, to make decisions regarding the purposes, and the methods of processing of Personal Data and the means used, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.
This Application
The hardware or software tool by which the Personal Data of the User is collected.
Service
The Service provided by this Application as described in the relative terms (if available) and on this site/application.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Cookie
Cookies are Tracking Tools consisting of small sets of data stored in the User’s browser.
Tracking Tool
Any technology – e.g., Cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting – that enables the tracking of Users, for example, by accessing or storing information on the User’s device.
Legal References
This privacy statement is prepared based on multiple legislative systems, including articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy statement solely concerns this Application.