Privacy Policy

(pursuant to EU Regulation 2016/679, the "GDPR") This policy describes the personal data we collect when you use this website or visit "Malo" branded points of sale. It also lists the purposes for which the data is used and the rights to which you are entitled as a data subject. The processing operations described in this policy only apply to the services available on the www.malo.it website or in "Malo" branded points of sale. We would like to inform you that the www.malo.it website may contain links to websites owned by third parties, who are directly responsible for the data processing carried out there; we therefore invite you to consult their privacy and cookie policies. DATA CONTROLLER With regard to the personal data collected for the use of the services available on this website and at the "Malo" branded points of sale, the Data Controller is Malo S.p.A. (hereinafter referred to as "Malo"), which has its registered office at 6 Via Gattinella, 50013, Campi Bisenzio (Florence). Malo can be contacted by sending an email to privacy@malo.it WHY WE USE YOUR DATA The following is a list of all the purposes for which we may collect your personal data.
Customer Care Purpose: we provide a support service (via chat, telephone, email, online form and social media) for any requests relating to the purchase of our products or the use of our services. Telephone calls to the Customer Care service are recorded, allowing us to assess how to improve the quality and efficiency of the service provided to our customers. Data processed: the data required to respond to your requests to our Customer Care service (for example, for the chat support service, we will ask you to provide your name and email address; calls subject to recording will be limited to less than 30% of the total calls received on a daily basis). Legal bases: Performance of a contract for the purchase and sale of products or pre-contractual measures taken in response to your request; With regard to the chat support service, legitimate interest in preventing so-called "chat spam"; With regard to the recording of telephone calls, legitimate interest in improving the quality and effectiveness of the service offered. Retention period: the time strictly necessary to fulfil your request; recordings of telephone calls will be retained for no longer than 93 days.
Profiling Purpose: profiling enables us to send you commercial communications that are tailored to your customer profile and your buying and browsing habits, and to develop products and services according to our customers' preferences. Data processed: data relating to your purchases, your country of origin, your gender and age, your interactions with us via our website, via apps – which may be developed by us or by third parties – and via our social media channels (e.g. Facebook, Instagram, etc.). We may also examine data relating to the use of services provided by us. Finally, we may enrich your customer profile with information of a statistical nature that we lawfully acquire from other sources: for example, data on your area of residence (including demographic information, georeferencing data, etc.) or on the electronic tools you use to interact with us. Legal basis: your consent, which you may revoke at any time by writing to privacy@malo.it or via your customer account. Retention period: data relating to your interactions with us will be retained for 12 months from the date of collection; information relating to your purchases will be retained for 3 years from the date of each purchase.
Gifts Purpose: purchases of Malo items that you can send as gifts to the recipients indicated by you. Data processed: the personal and contact data of the gift purchaser, as well as the personal and contact data of the gift recipient (communicated to us by the purchaser or recipient). Legal bases: performance of the contract for the sale and purchase of products; legitimate interest in ensuring delivery of the gift to the recipient. Retention period: the data will be retained for as long as necessary to fulfil the contractual obligations and obligations imposed by law (e.g. tax obligations).
Invoicing Purpose: to issue invoices for purchases made at "Malo" points of sale. Data processed: first name, last name, contact details, billing address, tax code, VAT number, residential address, recipient code (SDI code). Legal bases: fulfilment of regulatory obligations in tax matters; fulfilment of contractual obligations. Retention period: the time required to fulfil the contractual and regulatory obligations relating to the purchase and sale of products (e.g. tax regulations). Data controller: Malo S.p.A.

COOKIES

We use cookies in some areas of the website. We ask that you read our Cookie Policy in conjunction with this policy.

RIGHTS THAT CAN BE EXERCISED BY THE DATA SUBJECT

You can exercise your personal data rights under the GDPR by writing to privacy@malo.it. We undertake to reply to your request as soon as possible, and no later than thirty days after receipt of your request. In certain cases, we may ask you for further information if it is necessary to verify your identity in connection with your request. Specifically, you may exercise the following rights:

  • The right of access , i.e. the right to know whether personal data relating to you is being processed and, if so, to obtain a copy of such data and information concerning: the source of the data, the categories of personal data being processed, the recipients of the data, the purposes of the processing, the use of automated decision-making (including profiling), the data retention period, and your rights under the GDPR.
  • The right to have your data rectified or completed.
  • The right to have your personal data deleted if such data is no longer necessary for the purposes for which it was collected, or if we are no longer authorised to process it.
  • The right to obtain the restriction of processing of personal data in the following cases: i) you have contested the accuracy of the personal data. You may request restriction of the processing for the period necessary to verify the accuracy of the data; ii) we are no longer authorised to process the data and, instead of deleting it, you may ask us to restrict its use; iii) the personal data, which is in our possession but no longer necessary for the purposes for which it was collected, is necessary for you to establish, exercise or defend a legal claim. The right to data portability, i.e. the right to receive the personal data concerning you in a structured, commonly used and machine-readable format, as well as the right to request that such data be transferred to another Data Controller.
  • The right to withdraw your consent for processing based on said consent. You have the right to object to the processing of your personal data based on our legitimate interests at any time.

    You also have the right to lodge a complaint with the competent data protection supervisory authority if you believe that the processing of your data contravenes the provisions of the GDPR.

    We reserve the right to update the content of this page periodically. We encourage you to consult this information regularly in order to stay up to date with any changes that may have occurred since your last consultation.

    Last updated: February 2024