Privacy Policy GDPR
Privacy Policy
Chrysos S.p.A. (hereinafter "Chrysos" or the "Data Controller") attaches the utmost importance to the protection of its customers' personal data. This policy describes how we handle the personal data of users who make purchases through our e-commerce site and at our flagship stores, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national legislation.
1. Data Controller
The Data Controller is:
Chrysos S.p.A.
Registered office: Via Albertoni 10, Romano d'Ezzelino, 36060
Operational headquarters: Via Vallina Orticella 16, 31030 Borso del Grappa
Tax ID and VAT Number: 01917760249
Phone: 0423 910233
Email: privacy@chrysos.com
Certified Email (PEC): chrysos@legalmail.it
The Data Controller processes personal data through previously authorized and trained internal staff, as well as through external parties appointed, where necessary, as data processors pursuant to Article 28 of the GDPR.
2. Categories of Processed Data, Purposes, and Legal Bases
We collect and process various categories of personal data for specific purposes, as detailed in the following table:
| Category of Personal Data | Purpose of Processing | Legal Basis (GDPR) |
|---|---|---|
| a) Identification and personal details (first name, last name, date of birth, payment information) | Account creation and management; conclusion and performance of the sales contract (online and in-store); payment processing; shipping; returns; customer service; and administrative compliance. | Art. 6, para. 1, subpara. b) – Performance of a contract or pre-contractual measures; Art. 6, para. 1, subpara. c) – Compliance with legal obligations (e.g., tax and accounting obligations). |
| b) Interaction data (information voluntarily provided by the customer during in-store visits, participation in events, preferences, interests, jewellery measurements, information shared with sales assistants) | handling customer enquiries, assisting with product selection, organising appointments and attending events, preparing quotations, managing pre-contractual enquiries and improving the quality of the service provided. | Article 6(1)(b) of the GDPR – the performance of pre-contractual measures taken at the data subject's request or the performance of a contract; Article 6(1)(f) of the GDPR – the Data Controller's legitimate interest in organising and improving the service and managing customer relations, whilst respecting the data subject's fundamental rights and freedoms. |
| c) data relating to commercial preferences and interests | Preferences, interests, purchase history, products viewed or requested, and information relating to interactions with sales staff. | Article 6(1)(a) GDPR – the data subject's freely given, specific, optional and revocable consent. |
| d) data relating to commercial preferences and interests (Name, surname, e-mail address, telephone number, and preferences regarding communication channels) | sending promotional, commercial and informational communications, as well as invitations to events relating to the Data Controller's products and initiatives, through the communication channels selected by the data subject. | Article 6(1)(a) GDPR – the data subject's freely given, specific, optional and revocable consent. |
e) Browsing data: whilst browsing the website, IT systems may automatically collect certain technical data, such as your IP address, browser type, device used, time of the request and information relating to your use of the website. This data is processed to ensure the website's operation and security, to prevent misuse and malfunctions, and to comply with any legal obligations.
3. Methods of Data Processing and Retention
Personal data is processed using computerized, telematic, and manual tools, in accordance with the principles of lawfulness, fairness, transparency, data minimization, accuracy, integrity, confidentiality, and storage limitation.
Personal data will be retained for the time strictly necessary to achieve the purposes for which it was collected, in accordance with the principles of data minimization and storage limitation. Specifically:
- Data related to purchases and contract management: This data will be retained for the entire duration of the contractual relationship and, thereafter, for a period of 10 years following the termination of the relationship, in order to comply with legal obligations (e.g., tax, accounting, and civil law obligations) and to manage any disputes.
- Data for marketing and profiling purposes: This data will be retained for a maximum period of 24 months from the date consent was obtained or from the last significant interaction with the user, unless the data subject revokes consent. In the event of revocation, the data will be deleted or anonymized.
- Browsing and website usage data (non-technical cookies): This data will be retained for the maximum period permitted by applicable law (typically 12 months), unless the user has revoked consent earlier.
- Data for customer support and complaint handling: This data will be retained for the time necessary to handle the request or complaint.
4. Recipients of the Data
Personal data may be disclosed to:
- employees and contractors of Chrysos S.p.A., who have been authorised and trained in advance to process such data;
- service providers, such as courier companies, IT and cloud service providers, marketing agencies, payment service providers and credit institutions, which will process the data, as appropriate, either as data processors appointed in accordance with Article 28 of the GDPR or as independent data controllers;
- companies commissioned to provide support, repair, engraving, personalisation or other processing services requested by the customer;
- public authorities, supervisory bodies and other parties to whom disclosure is mandatory by law or pursuant to a decision by the Authority.
5. Transfer of Personal Data to Countries Outside the EU
Personal data is generally processed and stored within the European Economic Area.
If, for organizational reasons or due to the use of IT services, cloud services, or digital platforms, it becomes necessary to transfer personal data to countries outside the European Economic Area or to international organizations, the transfer will take place in accordance with Articles 44 et seq. of the GDPR, based on adequacy decisions by the European Commission, standard contractual clauses, supplementary measures, or other safeguards provided for by applicable law.
The data subject may request information from the Data Controller regarding the safeguards adopted for transfers to third countries, as well as a copy of such safeguards or an indication of where they are available, by sending a request to the contact information provided in this privacy notice.
6. Children
We do not knowingly contact or collect information from individuals under the age of 16. The Services are not intended for use by individuals under the age of 16. If you are a parent or legal guardian and believe that your child under the age of 16 has provided us with personal information, you may send us an email at privacy@chrysos.com
7. Data Subject Rights
The data subject may exercise the following rights, within the limits and under the conditions set forth by the GDPR:
- the right of access to personal data;
- the right to rectify inaccurate data or complete incomplete data;
- the right to erasure of data, in the cases provided for by law;
- the right to restriction of processing;
- the right to data portability, where applicable;
- the right to object to processing based on legitimate interests;
- the right to withdraw any consent previously given, without affecting the lawfulness of processing carried out prior to the withdrawal;
- the right to lodge a complaint with the Italian Data Protection Authority.
Requests may be sent to the Data Controller at the following contact information:
Email: privacy@chrysos.com
Certified Email (PEC): Chrysos@legalmail.it
Address: Via Vallina Orticella 16, 31030 Borso del Grappa
The data subject also has the right to file a complaint with the Italian Data Protection Authority if they believe that the processing of their personal data violates applicable law.
8. Changes to the Privacy Policy
Chrysos S.p.A. reserves the right to make changes to this privacy policy. Any changes will be posted on our website. We encourage users to check this page periodically.