Pursuant to Regulation (EU) 2016/679 on personal data protection (hereinafter “GDPR”), WYCON SPA, with registered offices in Piazza IV Novembre, 4 - 20124 Milan, VAT ID number 02317910186, hereby informs all data subjects about the types of data it collects, how it uses such data and those with whom it shares it. It also describes the rights of data subjects according to the data processed. The company WYCON SPA shall ensure the processing of the data is compliant with the principles of correctness, lawfulness and transparency, as well as protection of privacy and protection of the rights of data subjects.

A. Data Controller and Data Processors

The data controller (hereinafter the "Data Controller") is the company WYCON SPA with registered office at Piazza IV Novembre, 4 - 20124 Milan, VAT ID number 02317910186.

Data Processors, whose role is defined in Article 28 of the GDPR (hereafter the "Data Processors") are:

-     The company Splio Italia SRL with registered office at via Emilio Motta 10, 20144 Milan, Italy.

B. Type of data processed

The data processing concerns the navigation data to the website www.wyconcosmetics.com through cookies and/or other tracking systems, the personal data communicated by the data subject to register for services and to participate in initiatives promoted by WYCON SPA and/or by third parties as co-promoters. Data concerning the details of purchases made on the website www.wyconcosmetics.com and/or in WYCON cosmetics stores. 

It is specified that this information is not to be considered valid for data collected on other websites non-attributable to the wyconcosmetics.com domain and therefore the Data Controller is not to be considered in any way responsible.

C. Cookies

The www.wyconcosmetics.com site uses cookies and similar technologies to provide certain features in order to understand and measure performance and to offer targeted advertising. For more information on cookies and how to change cookie settings, please see the relevant section at the following link: https://www.wyconcosmetics.com/p/cookie

D. Purpose of the processing of personal data

Personal data shall be processed for the purposes listed below, which do not require the consent of the data subject:

1)  contractual, administrative and accounting purposes representative of registering for services and participating in initiatives promoted by WYCON SPA on its website www.wyconcosmetics.com and in WYCON cosmetics stores, operating and accessing all related ancillary services, as well as for any other accounting, tax, administrative purposes or otherwise required by law in relation to participation in the aforementioned initiatives. (Legal basis of processing: Contract performance)

Furthermore, the Data Controller shall process the data for the following purposes, subject to explicit prior consent:

2)  direct marketing by the sending, including automated sending, of offers, promotions, discounts, concessions, commercial or promotional information, free products, invitations to events or shows, and the reporting of special initiatives regarding products and services marketed by WYCON SPA and/or third parties, via mail, email, SMS, web and/or app push notifications, and social networks. (Legal basis of processing: Processing based only upon prior collection of consent)

 

3)  profiling, by reading and analysing purchasing behaviour, using data relating to purchases, in order to improve the commercial offering and to carry out specific product promotions and commercial offers as far as possible in accordance with the profile and needs of the data subject, and market research, in order to customise the initiatives and product offerings and services marketed by WYCON SPA and/or third parties. (Legal basis of processing: Processing based only upon prior collection of consent).

Finally it shall be processed for: 

4)  any handling and compilation of data collection forms available on the website www.wyconcosmetics.com to request information, make reports and contact the Data Controller, as well as managing and responding to such requests. (Legal basis of processing: Performance of the contract and precontractual measures).

E. Processing methods, circulation and communication of data.

In relation to the aforementioned purposes, the processing of data shall take place with the use of manual, computerised and electronic instruments, directly and/or through third parties, with instruments suitable to guarantee the security and confidentiality of the said information, in compliance with the law. The data subject’s data shall be available to employees of the marketing and market analysis office, as well as employees of the administrative and accounting departments. The Data Controller, with the necessary and explicit prior consent, may provide the personal data of the data subject to the following subjects: third-party suppliers/contractors of goods or services (for example, a mailing company); parent companies, subsidiaries or affiliates of WYCON SPA for administrative and accounting purposes; companies associated with services or commercial initiatives promoted by WYCON S.P.A.; third-party companies that carry out marketing and/or promotional activities. These subjects shall provide adequate guarantees of competence and knowledge of the current legislation regarding the protection of personal data. Personal data is processed in the offices of the Data Controller and of the Data Processor within the European Union. If it is transferred to countries outside the European Union, the data subject shall be informed accordingly.

F. Mandatory or optional nature of providing data

The provision of data is always optional, and if no such provision is made, and for the purposes referred to in the previous point 1) the data subject cannot participate in initiatives promoted by WYCON SPA and use the services associated with them, while for the purposes referred to in points 2) and 3), although they can participate, they will not be able to take advantage of certain benefits specifically reserved for them or receive information on initiatives of interest to them. For the purpose referred to in point 4) the provision of data is optional, and if no such provision is made, we shall not be able to respond to requests and/or reports made by the data subject.

G. Rights of the data subject

The law guarantees the data subject a series of rights including the right to access the data, the right to rectify, the right to remove, the right to obtain the limitation of the processing, the right to oppose the processing for reasons related to a specific situation and the right to the portability of data that the data subject can exercise at any time by writing to WYCON SPA at the address WYCON SPA Via Interporto di Nola - Interporto di Nola- Lotto C3 - 80035 - Nola (NA) - Italy. In addition, the data subject is entitled at all times to withdraw the consent provided, and is entitled to lodge a complaint with the Guarantor for the protection of personal data.

H. Data retention period

Data relating to accounting and other administrative purposes will be kept until the statutory limitation period has expired. For marketing and profiling purposes, the purchase data shall be kept for 24 months from the collection of each data item and personal data up to the revocation of consent.

I. Data Protection Officer

The Data Controller has designated a Data Protection Officer (DPO) that any data subject can contact for all matters relating to the processing of their personal data and the exercising of the rights deriving from the GDPR. You can contact the DPO by sending an email to [email protected] or in writing to WYCON SPA Via Interporto di Nola - Interporto di Nola-Lotto C3 - 80035 - Nola (NA) - Italy.