Privacy Policy
PRIVACY NOTICE PURSUANT TO ART. 13 OF EU REGULATION 2016/679 (GDPR)
This privacy notice describes the characteristics of the processing activities carried out by Luiss Guido Carli (hereinafter “LUISS” or the “Data Controller”) on personal data relating to the “Consumer” or “Purchaser” (hereinafter the “Data Subject”) who makes purchases on the Luiss Shop website. This notice is periodically updated to comply with applicable laws or new methods of personal data processing.
For information regarding cookies used by the platform, please refer to the Cookie Policy available on the website.
1. What personal data do we collect?
The Data Controller collects and processes personal data, where “personal data” means any information relating to an identified or identifiable natural person, even indirectly, by reference to any other information in our possession.
In particular, the following personal data provided by the Data Subject through the relevant forms are processed:
- Identification data (first name, last name);
- Contact data (email address, phone and/or mobile number);
- Shipping data (delivery address);
- Order data (purchased products, amounts, dates, and purchase history);
- Billing data (billing address and data required for tax documentation);
- Payment data (information provided to the payment provider to complete the transaction);
- Data provided during interactions with the Data Controller (support requests, post-order communications).
Why do we collect your data and what is the legal basis?
The Data Controller collects and processes the Data Subject’s personal data in order to:
- enable account creation for purchasing merchandising products and manage the user’s e-commerce account, including activities related to order processing and fulfillment (legal basis: Art. 6(1)(b) GDPR);
- manage and fulfill user requests, and provide assistance and support related to the e-commerce platform services (legal basis: Art. 6(1)(b) GDPR);
- carry out direct marketing activities, such as sending promotional and informational communications about the Data Controller’s products, only with the Data Subject’s prior consent (legal basis: Art. 6(1)(a) GDPR);
- perform anti-fraud checks and ensure the security of transactions and the e-commerce platform (legal basis: Art. 6(1)(f) GDPR – legitimate interest in preventing fraud, balanced against the rights of the Data Subject);
- protect the rights and interests of the University, including in judicial or extrajudicial proceedings in case of disputes arising from platform use or product purchases (legal basis: Art. 6(1)(f) GDPR – legitimate interest in legal defense, duly balanced).
Providing personal data for contractual purposes (purchases, account creation, support) is mandatory. Failure to provide such data will make it impossible for the Data Controller to process the data and to provide services related to the e-commerce platform.
2. How do we process your data and how long do we retain it?
Personal data are processed both in paper and electronic form (servers, cloud databases, application software, etc.). Purchase-related data are retained for 10 years for civil and tax purposes; Marketing data are retained until consent is withdrawn and, in any case, no longer than 24 months. At the end of the retention period, personal data will be deleted or anonymized.
3. Who do we share your personal data with?
- Internal recipients
Authorized personnel involved in administrative, commercial, and order management activities of the Luiss Shop may access personal data, as well as employees and collaborators supporting the Data Controller in managing the e-commerce platform and fulfilling orders.
All staff are trained on the importance of complying with data protection regulations.
- External recipients
The Data Controller may share personal data with external individuals or entities engaged to carry out certain activities (e.g., IT service providers, payment providers, shipping companies, administrative and tax consultants), as well as third parties responsible for managing the platform, such as TECH FOR GOODS.
Where providers access personal data, they will do so in compliance with applicable data protection laws and the Data Controller’s instructions. Personal data will not be disclosed to third parties without the Data Subject’s consent, unless required by law or public authorities, for example:
- for national security reasons;
- for reasons of public interest;
- in response to requests from public authorities.
4. Are your data transferred abroad?
Personal data are generally not transferred outside the European Economic Area (EEA). Should such transfer be necessary, it will be carried out in accordance with Chapter V of the GDPR.
5. What are your rights and how can you exercise them?
Under the GDPR, Data Subjects have specific rights, including:
- Right of access: to obtain a copy of the personal data being processed;
- Right to rectification: to correct inaccurate or outdated data;
- Right to object to marketing: to stop receiving marketing communications at any time;
- Right to object to automated decision-making: including profiling;
- Right to withdraw consent: at any time;
- Right to lodge a complaint: with the Data Protection Authority.
Under certain conditions, Data Subjects may also exercise:
- Right to erasure (“right to be forgotten”);
- Right to object to processing;
- Right to restriction of processing;
- Right to data portability.
Data Subjects also have the right to lodge a complaint with the competent Data Protection Authority.
To exercise their rights, Data Subjects may send an email to privacy@luiss.it or write to: Luiss Guido Carli, Viale Pola 12, 00198 Rome, Italy, specifying their request and providing necessary identification details.
The contact details of the Data Protection Officer (DPO) are available on the Data Controller’s website: www.luiss.it .