My Garage S.r.l., with registered and operational office in Via Carlo Alberto, Turin (TO) – 30027, VAT no. 13263480017 (hereinafter referred to as the “Controller”), owner of the website https://krkwatches.com (hereinafter, the “Website”), in its capacity as Data Controller of the personal data of the Users who browse and, possibly, are also registered on the Website (hereinafter also referred to as the “Users” or “Data Subjects”), hereby provides the following privacy notice pursuant to Article 13 of EU Regulation 2016/679 (hereinafter, the “Regulation” or “Applicable Law” or “GDPR”).
This Website and any services offered through it are reserved for persons aged 18 or older. The Controller does not therefore collect personal data relating to individuals under 18 years of age. In any case, upon specific request, the Controller will promptly delete any personal data inadvertently collected and relating to minors under 18 years of age.
The Controller gives the utmost importance to the right to privacy and the protection of personal data of its Users. For any information regarding this privacy notice, Users may contact the Controller at any time using the methods described in section 4 below.
Purpose of Processing
Users’ personal data will be lawfully processed by the Controller pursuant to Article 6 of the Regulation for the following purposes:
Data Processing Methods and Retention Period
The Controller will process Users’ personal data using manual and electronic tools, applying logic strictly related to the purposes stated above and ensuring the security and confidentiality of the data at all times.
Users’ personal data will be retained for the period strictly necessary to fulfill the purposes outlined in section 1 above, or as long as necessary to protect the interests of both Users and the Controller in civil matters. Regarding the purposes described in points 1.b and 1.h, data will be retained until the User withdraws consent to receive newsletters, either through the unsubscribe link included in each message or by exercising their rights as set out in section 4.
Data Communication and Disclosure
Employees and/or collaborators of the Controller may have access to Users’ personal data as authorized persons, since they are responsible for managing the Website and/or sales operations and/or customer service. These individuals, formally appointed by the Controller as “Authorized Processors,” will process Users’ data solely for the purposes set out in this policy and in compliance with the Applicable Law.
Furthermore, third parties who process personal data on behalf of the Controller as “External Data Processors” (e.g., IT and logistics service providers, outsourcing or cloud computing providers, professionals, and consultants) may also have access to Users’ personal data. Data may also be communicated to the Tax Authority and/or other public authorities if required by law or upon their request.
Data Subjects have the right to obtain a list of all Data Processors appointed by the Controller by making a request to the Controller via the methods indicated in section 4 below.
Rights of Data Subjects
Data Subjects may exercise their rights under the Applicable Law, including the right to request from the Controller access to their personal data, rectification or erasure thereof, restriction of processing, objection to processing, and the right to lodge a complaint with the Data Protection Authority.
You can contact the Controller using the following methods: