DATA PROCESSING NOTICE
This Website collects certain Personal Data relating to its Users. This information is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679.
Data Controller
DUCATI MOTOR HOLDING and DIAMANT SRL are joint data controllers, by virtue of the arrangement entered into pursuant to Article 26 of Regulation (EU) 2016/679. The information provided in this Privacy Policy and the consent given by the user during registration and purchase operations are valid for both data controllers. Both Data Controllers have each appointed a Data Protection Officer (DPO).
DUCATI MOTOR HOLDING SPA
Via Cavalieri Ducati 3 – 40132 Bologna
The Data Controller and the DPO can be contacted at privacy@ducati.com.
DIAMANT SRL
Viale del Lavoro 8 – 37060 Zona Industriale Bonferraro (VR)
For information, the Data Controller can be contacted through the Privacy Service at privacy@diamantdmt.com.
The DPO can be contacted at dpo@diamantdmt.com.
Types of Data collected
The Personal Data collected by this Website, including the e-commerce section, provided directly by the data subject independently or through third parties are: first name, last name, e-mail, address, telephone number, tax code and other personal data in relation to the purposes described below and the initiatives carried out. Full details on each type of data collected are provided in the dedicated sections of this Privacy Policy or through specific information notices displayed before the data are collected. Personal Data may be provided freely by the User or, in the case of Usage Data, collected automatically when this Website is used. The User assumes responsibility for any third-party Personal Data obtained, published or shared through this Website and warrants that they have the right to communicate or disclose them, releasing the Controller from any liability towards third parties. For management and maintenance purposes, the Website and/or any third-party service providers acting on behalf of the Data Controllers may keep system logs, namely files that record interactions with the Website and that may contain Personal Data, such as the User’s IP address and so on.
Methods, legal basis and place of processing of the data collected, retention period and purposes of processing
Processing methods
The Data Controllers adopt appropriate security measures designed to prevent unauthorised access to, disclosure, alteration or destruction of Personal Data. Processing is carried out using IT and/or electronic tools, in accordance with organisational methods and logic strictly related to the purposes indicated. In addition to the Data Controllers, in certain cases, other parties involved in the organisation of this Website may have access to the Data (administrative, sales and legal staff, system administrators), as may external parties (third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) who may also be appointed, where necessary, as Data Processors by the Data Controllers. An up-to-date list of Data Processors can always be obtained from the respective Data Controllers.
Purposes of Processing of collected Data
The User’s Data are collected to enable the Data Controllers to provide their Services. Express consent to processing is required for certain purposes. It is understood that such consent applies to both joint Data Controllers. In particular:
- The provision of common personal data (including transaction data) has as its main purpose contractual, pre-contractual, managerial or administrative requirements or the fulfilment of legal obligations to which the Data Controllers are subject. The purposes of processing pertain to contractual relationships either directly with the contracting party or with the contracting party through the e-commerce site, whether the relationship is B2B or B2C. If the contractor is a company, it is specified that for the same purposes personal and contact data (such as personal details, company e-mails, company phones, work smartphones, etc.) of your administrators, employees and collaborators may also be processed depending on their roles and tasks with respect to the management and/or performance of the contract.
These contractual purposes also include the management of the warranty for purchased bicycles, including product registration, verification of the requirements for the warranty to apply, handling any requests for assistance, servicing, repair or replacement, and any other activities necessary to fulfil the warranty obligations provided for by law and the applicable contractual terms and conditions. The Data Controllers also offer the option of an extended warranty of up to five years, subject to registration of the bicycle using the dedicated form available on the website. For this purpose, personal and contact details that may already have been collected at the time of purchase are processed, together with the date of purchase and details of the retailer or store where the bicycle was purchased. This data is processed solely to verify and register the right to the extended warranty and to subsequently manage the related warranty coverage. Providing this data does not require consent to its processing. - Management and fulfilment of specific contact requests made by the user.
- Sending newsletters using the e-mail address provided by the user, for which consent to processing is required.
- The e-mail addresses provided in the context of the sale of a product or service may be used to send promotional material by e-mail for commercial communications. This activity, known as “soft spam”, does not require consent to processing as it serves a legitimate interest of the Data Controller. Users are always free to opt out of these direct e-mail communications. Processing is necessary for the purposes of the legitimate interest pursued by the Data Controllers.
- Sending technical/commercial information about our products using data provided by the user (postal address or e-mail address). Consent to processing is required.
- Managing participation in events, competitions or opinion surveys (consent to processing is required).
- Profiling consumption habits (consent to processing is required).
Legal basis of the processing
The Data Controllers process Personal Data relating to the User where one of the following conditions applies:
- the User has given consent for one or more specific purposes;
- processing is necessary for the performance of a contract with the User and/or in order to take pre-contractual steps, including data provided through the e-commerce section;
- processing is necessary for compliance with a legal obligation to which the Data Controllers are subject;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controllers;
- processing is necessary for the purposes of the legitimate interests pursued by the Data Controllers or by third parties.
However, it is always possible to request that the Data Controllers clarify the actual legal basis of each process, and in particular to specify whether the processing is based on law, required by a contract, or necessary to conclude a contract.
Place of processing
Personal data are processed by the Data Controllers through facilities located at their offices, within remote and cloud storage systems, and in any other place where the parties involved in the processing are located. For more specific information on this matter, please contact the Data Controllers by e-mail. Personal data may be transferred outside the European Union where and to the extent that such transfer is permitted by the GDPR. Any transfer of personal data outside the European Union is:
- to countries for which the European Commission has issued an adequacy decision;
- or is subject to data transfer agreements based on the standard contractual clauses approved by the European Commission; or has been explicitly approved by the relevant User;
- or otherwise permitted on another legal basis.
Communication and disclosure
Personal data and the related processing may be communicated to:
- Companies for the performance of economic activities (commercial, management, information system management, insurance, banking or non-banking intermediation, factoring, shipping management, envelope stuffing and correspondence sending activities, services connected with contractual obligations) or for compliance with legal requirements (accounting firms, lawyers).
- Companies involved in administrative management in relation to the purposes for which specific consent is required (management of advertising proposals, profiling, management of participation in competitions or surveys, management of newsletter sending).
The authorised persons and processors involved in processing operations in relation to the purposes listed above may become aware of your data. The list of data processors is available at our offices. The Data Subject’s personal data are stored in paper, computerised and electronic archives located within the European Union. In any case, it is understood that, should this become necessary, the Data Controller reserves the right to move the servers outside the EU. In this case, the Data Controller hereby guarantees that any transfer of data outside the EU will take place in accordance with the applicable legal provisions, subject to the execution of the standard contractual clauses adopted by the European Commission and in any case towards companies that adhere to the “Data Privacy Framework” (to the United States).
Retention period
The Data are processed and stored for the time required by the purposes for which they were collected. Therefore:
- Personal Data collected for purposes connected with the performance of a contract of any kind between the Data Controller and the User shall be retained until the performance of that contract has been completed. Maximum retention period: 10 years.
- Personal Data collected for purposes relating to the legitimate interest of the Data Controllers shall be retained until that interest has been satisfied. The User may obtain further information about the legitimate interest pursued by the Data Controllers in the relevant sections of this document or by contacting the Data Controller.
- When the processing is based on the User’s consent, the Data Controllers may keep the Personal Data longer, until that consent is withdrawn. In addition, the Data Controllers may be required to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period, Personal Data will be erased. Therefore, once that period has expired, the rights of access, erasure, rectification and data portability may no longer be exercised.
Rights of the Data Subject
Users may exercise certain rights with regard to the Data processed by the Data Controllers. The relevant articles are Articles 15, 16, 17, 18, 20, 21 and 22 of Regulation (EU) 2016/679. In particular, the User has the right to:
- Withdraw consent at any time. The User may withdraw consent that was previously given for the processing of their Personal Data.
- Object to the processing of their Data. The User may object to the processing of their Data when it is done on a legal basis other than consent. Further details on the right to object are provided in the section below.
- Access their Data. The User has the right to obtain information about the Data processed by the Data Controller, on certain aspects of the processing, and to receive a copy of the Data processed.
- Verify and request rectification. The User may verify the accuracy of their Data and request that they be updated or corrected.
- Obtain restriction of processing. Where certain conditions apply, the User may request restriction of the processing of their Data. In such cases, the Data Controller shall not process the Data for any purpose other than storage.
- Obtain erasure or removal of their Personal Data. Where certain conditions apply, the User may request the full erasure of their Data by the Data Controller (the right to be forgotten).
- Receive their Data or have them transferred to another data controller. The User has the right to receive their Data in a structured, commonly used and machine-readable format and, where technically feasible, to have them transmitted to another data controller without hindrance. This provision is applicable when the Data are processed by automated means and the processing is based on the User’s consent, a contract the User is a party to or contractual measures related thereto.
- Lodge a complaint. The User may lodge a complaint with the competent personal data protection supervisory authority (Garante per la Protezione dei Dati Personali) or seek a judicial remedy.
Details on the right to object
Where Personal Data are processed in the public interest, in the exercise of official authority vested in the Data Controllers or for the purposes of the legitimate interests pursued by the Data Controllers, Users have the right to object to processing on grounds relating to their particular situation. Users are informed that, where their Data are processed for direct marketing purposes, they may object to processing without providing any specific reason.
How to exercise rights
To exercise their rights, Users may send a request to the contact details provided in this document. Requests are submitted free of charge and handled as quickly as possible, in any event within one month. The contact address is privacy@diamantdmt.com.
Further information on processing
Defence in court
The User’s Personal Data may be used by the Data Controllers in legal proceedings or to prepare such actions for defence against abuses in the use of this Website or related Services by the User. The User declares that they are aware that the Data Controllers may be required to disclose the Data by order of public authorities.
Specific information
Upon the User’s request, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual notices regarding specific Services or the collection and processing of Personal Data.
System logs and maintenance
For needs connected with operation and maintenance, this Website and any third-party services used by it may collect system logs, namely files that record interactions and may also contain Personal Data, such as the User’s IP address.
Information not contained in this policy
Further information regarding the processing of Personal Data may be requested from the Data Controllers at any time using the contact details provided.
Changes to this Privacy Policy
The Data Controllers reserve the right to make changes to this privacy policy at any time, informing Users on this page and where possible on this Website, as well as sending a notification to Users using one of the addresses held by the Data Controllers where technically and legally feasible. Please therefore consult this page regularly, referring to the date of the last change indicated at the bottom. If the changes affect processing whose legal basis is consent, the Data Controllers will request the User’s consent once again if necessary.