Privacy Policy

Subjects of treatment

The data controller under the laws in force is the site administrator, ELÙ BEAUTY SRL, who can be contacted via the CONTACTS section

Legal basis for processing
This site processes data primarily on the basis of user consent. Consent is given via the banner at the bottom of the page, or through the use or consultation of the site, as a conclusive behaviour. By using or consulting the site, visitors and users approve this privacy policy and consent to the processing of their personal data in the manner and for the purposes described below, including the possible disclosure to third parties if necessary for the provision of a service. Further consents relating to the specific purpose of the service are collected via the communication or service request forms.

The provision of data and therefore consent to the collection and processing of data is optional, the User may deny consent, and may revoke consent already provided at any time (via the banner at the bottom of the page or the browser settings for cookies, or the Contact Us link). However, denying consent may result in the inability to provide certain services and the site navigation experience would be impaired.

Data for site security and for the prevention of abuse and SPAM, as well as data for the analysis of site traffic (statistics) in aggregate form, are processed on the basis of the data controller’s legitimate interest in protecting the site and users. In such cases, the user always has the right to object to the processing of data (see par. User Rights).

Purpose of processing
The processing of the data collected by the site, in addition to the purposes connected with, instrumental to and necessary for the provision of the service, is aimed at the following purposes:

Statistics (analysis)
Collection of data and information in exclusively aggregate and anonymous form for the purpose of verifying the correct operation of the site. None of this information is related to the physical person-user of the site, and does not allow in any way its identification. No consent is required.

– Safety and Security
Collection of data and information in order to protect the security of the site (spam filters, firewalls, virus detection) and of Users and to prevent or unmask fraud or abuse to the detriment of the website. The data are automatically recorded and may possibly also include personal data (IP address) that could be used, in accordance with the laws in force on the subject, to block attempts to damage the site itself or to cause damage to other users, or in any case harmful or criminal activities. Such data are never used for identification or profiling of the User and are deleted periodically. No consent is required.

Ancillary activities
Disclose data to third parties who perform functions necessary or instrumental to the operation of the service (e.g. comment box), and to enable third parties to perform technical, logistical and other activities on our behalf. Providers only have access to personal data that is necessary to perform their tasks, and they undertake not to use the data for any other purpose, and are obliged to process personal data in accordance with applicable regulations.

Data collected
This site collects user data in two ways.

Automated data collection
The following information may be collected during the Users’ navigation and is stored in the log files of the site’s server (hosting):

– Internet Protocol (IP) address;

– type of browser;

– parameters of the device used to connect to the site;

– name of the internet service provider (ISP);

– date and time of visit;

– The visitor’s source (referral) and exit web pages;

– possibly the number of clicks.

This data is used for statistical and analysis purposes, in aggregate form only. The IP address is used solely for security purposes and is not cross-referenced with any other data.

Data provided voluntarily
The site may collect other data in the event of voluntary use of services by users, such as comment services, communication services (contact forms, comment box), and will be used exclusively for the provision of the requested service:

– name;

– email address.

Place of processing
The data is processed at the premises of the Data Controller, and at the Aruba web hosting datacenter. The web hosting Aruba, is responsible for the processing, processing the data on behalf of the owner. Aruba is located in the European Economic Area and acts in accordance with European standards.

Data retention period
The data collected by the site during its operation are kept for the time strictly necessary to carry out the specified activities. On expiry, the data will be deleted or anonymised, unless there is no further purpose for retaining it.

Data (IP address) used for site security purposes (blocking attempts to damage the site) are stored for 30 days.

Data for analytics (statistics) purposes are stored in aggregate form for 24 months.

Transfer of collected data to third parties
The data collected by the site are generally not provided to third parties, except in specific cases: legitimate request by judicial authorities and only in cases provided for by law; when it is necessary for the provision of a specific service requested by the User; for the performance of security checks or site optimisation.

Data transfer to non-EU countries
This site may share some of the data collected with services located outside the European Union. In particular with Google, Facebook and Microsoft (LinkedIn) via social plugins and the Google Analytics service. The transfer is authorised on the basis of specific decisions of the European Union and the Garante per la tutela dei dati personali, in particular decision 1250/2016 (Privacy Shield – here the information page of the Italian Garante), so no further consent is required. The companies mentioned above guarantee their adherence to the Privacy Shield.

Security Measures
We process visitor/user data lawfully and fairly, taking appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of data. We are committed to protecting the security of your personal data during transmission, using Secure Sockets Layer (SSL) software, which encrypts information in transit. Processing is carried out using IT and/or telematic tools, with organisational methods and logic strictly related to the purposes indicated. In addition to the Data Controller, in some cases, categories of persons in charge of organising the site or external parties (such as third-party technical service providers, hosting providers) may have access to the data.

Cookies
This site makes use of cookies, text files that are recorded on the user’s terminal or that allow access to information on the user’s terminal. Cookies make it possible to store information on visitors’ preferences, they are used to check that the site is working properly and to improve its functionality by customising the content of the pages according to the type of browser being used, or to simplify navigation by automating procedures (e.g. login, site language), and finally to analyse visitors’ use of the site.

This site makes use of the following categories of cookies:

technical cookies, used for the sole purpose of carrying out the transmission of an electronic communication, to ensure the correct display of the site and navigation within it. In addition, they make it possible to distinguish between different logged in users in order to provide a requested service to the right user (login), and for site security reasons. Some of these cookies are deleted when the browser is closed (session cookies), others have a longer lifetime (such as the cookie required to store the user’s consent in relation to the use of cookies, which lasts 1 year). No consent is required for these cookies;

analysis cookies, used directly by the site operator to collect information, in aggregate form, on the number of users and how they visit the site. They are assimilated to technical cookies if the service is anonymised.

profiling and marketing cookies, used exclusively by third parties other than the owner of this site to collect information on users’ browsing behaviour, interests and consumption habits, including for the purpose of providing personalised advertising.

By clicking OK on the banner on first access to the site or by browsing the site, the visitor expressly consents to the use of cookies and similar technologies, and in particular to the recording of these cookies on his terminal equipment for the purposes indicated above, or to access via cookies to information on his terminal equipment.

Disabling cookies
The user may refuse the use of cookies and may revoke a consent already given at any time. Since cookies are linked to the browser being used, they CAN BE DISABLED DIRECTLY FROM THE BROWSER, thus refusing/revoking consent to the use of cookies, or via this dedicated area (click here).

DISABILITATION OF COOKIES MAY PREVENT THE CORRECT USE OF CERTAIN FUNCTIONS OF THE SITE ITSELF, in particular services provided by third parties may not be accessible, and therefore may not be viewable:
– videos from YouTube or other video-sharing services;
– social network buttons;
– Google maps.

Instructions for disabling cookies can be found on the following web pages:

Mozilla Firefox – Microsoft Internet Explorer – Microsoft Edge – Google Chrome – Opera – Apple Safari

Third-party cookies
This site also acts as an intermediary for third party cookies (such as social networking buttons), which are used to provide additional services and functionality to visitors and to simplify the use of the site, or to provide personalised advertising. This site has no control over these third party cookies and has no access to the information collected by these cookies. Information on the use of these cookies and their purposes, as well as how to disable them, is provided directly by the third parties on the pages indicated below.

Please note that user tracking generally does not involve identification of the user, unless the user is already subscribed to the service and is also already logged in, in which case it is understood that the user has already given consent directly to the third party when subscribing to the relevant service (e.g. Facebook).

This site uses cookies from the following third parties.

Google Inc.
For information on the use of data and its processing by Google, we recommend that you read Google’s privacy policy and Google’s Terms of Use when using partner sites or apps.

Google Analytics: used to analyse users’ use of the site, compile reports on site activity and user behaviour, check how often users visit the site, how the site is tracked and which pages are visited most frequently. The information is combined with information gathered from other sites in order to create a comparative picture of the use of the site in relation to other sites in the same category.

Data collected: browser ID, date and time of interaction with the site, page of origin, IP address.

Place of data processing: European Union as the anonymisation of the service is active.

The data collected does not allow personal identification of users, and is not cross-referenced with other information relating to the same person. They are processed in aggregate form and anonymised (truncated to the last octet). On the basis of a special agreement (DPA), Google Inc. (the data controller) is prohibited from cross-referencing this data with data from other services.

Further information on Google Analytics cookies can be found on the page Google Analytics Cookie Usage on Websites.

The user can selectively disable (opt out) the collection of data by Google Analytics by installing the appropriate component provided by Google (opt out) on his browser.

Youtube: a platform, owned by Google, for sharing videos. Cookies are set when accessing the page containing the embed, and when starting the video, and do not allow identification of the User unless he/she is already logged into the Google profile.

For videos on the site, the ‘advanced privacy (no cookies)’ option has been activated, which ensures that YouTube does not store information about visitors unless they voluntarily play the video.

Data collected: number and behaviour of users of the service, IP address, information linking site visits to the Google account for logged in users, video viewing preferences.

Place of data processing: USA.

Social Network Plugins
This website also incorporates plugins and/or buttons in order to enable easy sharing of content on your favourite social networks. When you visit a page on our website that contains a plugin, your browser connects directly to the servers of the social network from where the plugin is loaded, which server can track your visit to our website and, where appropriate, associate it with your social network account, particularly if you are logged in at the time of your visit or if you have recently browsed one of the websites containing social plugins. If you do not wish the social network to record data relating to your visit to our website, you must log out of your social network account and, probably, delete the cookies that the social network has installed in your browser.

Plugins are installed on this site with advanced privacy protection functions for Users, which do not send cookies or access cookies on the User’s browser when the page is opened, but only after the plugin is clicked.

The collection and use of information by such third parties is governed by their respective privacy policies to which please refer.

– Facebook (cookie policy link)
– Twitter (cookie policy link)
– LinkedIn (link cookie policy)
– Google+ (link cookie policy).

User rights
Pursuant to European Regulation 679/2016 (GDPR), the User may, in the manner and within the limits provided for by the legislation in force, exercise the following rights:

– object in whole or in part, on legitimate grounds, to the processing of personal data concerning him/her for the purposes of sending advertising or direct sales material or for carrying out market research or commercial communication;
– request confirmation of the existence of personal data concerning him/her (right of access);
– know its origin;
– receive intelligible communication;
– obtain information on the logic, methods and purposes of the processing;
– request the updating, rectification, integration, deletion, transformation into anonymous form, and blocking of data processed in breach of the law, including data no longer necessary for the purposes for which they were collected;
– in cases of consent-based processing, receive, at the sole cost of any support, your data provided to the data controller, in a structured, machine-readable form and in a format commonly used by an electronic device;
– the right to lodge a complaint with the supervisory authority (Garante Privacy – link to the page of the Garante);
– as well as, more generally, to exercise all the rights recognised to him by the applicable legal provisions.

Requests should be addressed to the Data Controller.

Updates
This privacy policy is updated as of 29 November 2018.