Privacy and Cookies

  1. DATA CONTROLLER

AMEVISTA S.r.l. (hereinafter also referred to as “Amevista” or the “data controller” or the “company”), represented by its legal representative pro tempore, VAT number 14956881008, with registered and operational office at Via Flaminia 968, Rome, Italy, is the data controller for the purposes of the General Data Protection Regulation 679/2016 (hereinafter also referred to as the “GDPR”).

In its capacity as data controller, AMEVISTA provides data subjects with this Privacy Notice pursuant to Articles 13 and 14 of European Regulation No. 679/2016 on the protection of personal data, with the aim of providing information on how personal data are collected and used when processed through the company’s digital platforms, specifically through the AMEVISTA.com website.

The website and the services provided by AMEVISTA do not intentionally collect data from minors. This document contains technical definitions relating to the legislation in force on the protection of personal data; for an explanation of these definitions, please refer to Annex (A).

For any questions regarding this Privacy Notice, or to exercise the rights provided for under applicable law (described in greater detail below), you may contact AMEVISTA’s Data Protection Officer using the contact details indicated below under point No. 13.

  1. THIRD-PARTY WEBSITES

Our website may contain links to external functionalities (such as virtual eyewear try-on systems and the Trustpilot portal for reviews). If you select a link and access one of these websites, you should refer to the specific security and personal data processing policies implemented by the respective data controllers.

  1. WHAT INFORMATION DO WE COLLECT AND HOW?

Interaction with Amevista takes place through the company’s websites or through direct telephone contacts, in person or at our stores. Through the company’s websites, Amevista processes a range of personal information that may be used for different purposes:

  • to create an account on our website, including in order to place and manage a product order;
  • to interact with Amevista through the various forms available in the different sections of our websites, such as registration forms, reviews, contests and surveys;
  • to subscribe to our newsletter communications, through which you are informed about initiatives and special offers;
  • if you participate in social media contexts and/or in our Community;
  • if you wish to communicate with the company.

The information is collected directly from the data subject and, depending on the reason for contact, may include personal identification data, contact details, data required to make online payments, purchase information and preferences, reviews, data relating to preferences and habits, images and videos. We do not process or store credit or debit card data, as these are handled directly by electronic banking payment platforms.

For certain types of purchases, we may process personal data classified as special categories of data (formerly sensitive data), specifically for the production of prescription lenses based on indications and/or prescriptions provided by the customer.

Each time our websites are accessed, certain information is automatically created and recorded by our IT systems. Such information may include:

  • Cookies: you can obtain further details about cookies by accessing the relevant section or, when accessing one of our websites, by exercising your right to choose which cookies to activate. At any time, you can access the cookie policy and, through the cookie banner, configure the cookies you wish to authorise. These small text files can help improve your experience with the website and make interaction with us easier. For example, they may store your location or language preferences so that you do not have to re-enter the information when you return to the website, or ensure that the items you wish to order do not disappear while you browse between pages on our website. We also use cookies to provide you with advertising tailored to your interests, for example. Please refer to section No. 7 below.
  • Device information: the information provided by the device varies depending on the operating system and device settings and may include one or more of the following: IP address, device location, browser used, mobile network provider (for mobile devices), pages visited, time zone and country location, as well as crash or download error reports.
  1. WHAT DO WE USE PERSONAL DATA FOR?

To register and manage an account on our website, we require your first name and surname, e-mail address, a personal password and other additional data that you may add to your account, such as telephone number, addresses and gender. The legal basis legitimising this data collection derives from the performance of a contract between the parties pursuant to Article 6.1(b) of the GDPR (processing is necessary for the performance of a contract to which the data subject is party, such as registration on an online platform or the placing of online purchase orders).

To proceed with online purchases, the data provided by the data subject are used. The legal bases legitimising such data collection are set out in Article 6.1(b) of the GDPR and in compliance with legal obligations pursuant to Article 6.1(c) of the GDPR (processing is necessary to comply with a legal obligation to which the data controller is subject, such as the issuing of tax documents, payment traceability, credit checks or anti-fraud checks).

To complete an online order, it is also necessary to provide information relating to the credit or debit card used. The required data are the credit or debit card number, expiry date, cardholder’s name and security code. This information is not stored on Amevista’s systems but is handled directly by electronic payment platforms. At the end of the payment process, Amevista is informed whether the payment has been successfully completed or not. The legal bases legitimising such data collection are Article 6.1(b) of the GDPR and Article 6.1(c) of the GDPR.

If the order concerns prescription eyewear, it will also be necessary to send Amevista the relevant medical prescriptions. The legal basis legitimising this collection of information is provided by Article 6.1(b) of the GDPR (processing is necessary for the performance of a contract to which the data subject is party) and Article 9.2(a) of the GDPR (the data subject has given explicit consent to the processing of such personal data for one or more specific purposes).

We use the information for customer care services, assistance and to assess the data subject’s level of satisfaction. In addition to user data, we also use the chronological references and contents of the contacts made. We may retain responses provided to our service quality surveys, both through telephone recordings and through the storage of e-mails or messages exchanged through other instant messaging apps. The legal bases for such collections of personal data are the consent provided by the data subject pursuant to Article 6.1(a) of the GDPR and Amevista’s legitimate interests pursuant to Article 6.1(f) of the GDPR (processing is necessary for the pursuit of Amevista’s legitimate interest while fully respecting the fundamental rights and freedoms of the data subject and protecting his or her personal data).

The data subject may review and publish his or her impressions regarding the experience of using Amevista websites: in this case, the data subject’s name, age range and the contents of the review are processed. The legal basis is the consent provided by you pursuant to Article 6.1(a) of the GDPR.

If the data subject has purchased one of our products or services, we may use the e-mail address provided at the time of purchase to send commercial communications relating to our products or services that are similar to those already purchased, without the need to obtain specific consent, in accordance with the rules applicable to commercial communications concerning similar products (so-called soft spam). Such processing will be carried out in compliance with the rights provided for by applicable law, and the data subject may object at any time, free of charge and in an easy manner, both at the time the e-mail address is collected and in each subsequent communication, by using the unsubscribe link included in the e-mails or by contacting us using the details provided in this Privacy Notice. Any objection will have no effect on the purchase or use of our products and services.

We use the information for advertising and marketing purposes. If the user has stated that he or she wishes to receive marketing communications or has made a purchase using our services, we and our partners will use the user’s personal information (including name, e-mail address and address) to occasionally send updates, news and offers by e-mail, post or other forms of communication. We may use the user’s information (including additional information received from partners that we add to our existing customer information, as described below) to personalise these messages. The user may unsubscribe at any time from one or more of our communication methods by changing the preferences in the profile management section of his or her account, by following the opt-out instructions contained in the promotional messages sent, or by sending a deletion request to privacy@amevista.com.

To comply with legal requests: on certain occasions, we may be required to cooperate with regulatory authorities and law enforcement agencies in different countries due to laws, court orders or other legal proceedings. Unless specifically prohibited, we will inform the data subject of requests for access to personal data received from public authorities. The legal basis for this type of personal data processing is set out in Article 6.1(c) of the GDPR (processing is necessary to comply with a legal obligation to which the data controller is subject).

To produce aggregated statistical reports, we use the history of orders placed by the data subject, excluding information that could allow identification. The legal basis is our legitimate interest in managing our business and improving our website pursuant to Article 6.1(f) of the GDPR.

  1. WITH WHOM DO WE SHARE DATA SUBJECTS’ PERSONAL INFORMATION?

To provide our services and the website, we work with a number of carefully selected third parties which, depending on the type of processing and the nature of their relationship with Amevista, act as independent data controllers or external data processors. Partners are selected according to strict assessment criteria, foremost among which are compliance with the applicable rules on the protection of personal data processed and the territory in which they operate. We choose partners that operate within the European Economic Area or that are subject to security agreements entered into between the EU and the USA. Outside these territories, partner assessment includes strict checks on the security measures implemented and on the guarantees concerning the exercise of the rights to which data subjects are entitled.

Based on obligations arising from the performance of a contract between the parties:

  • We share contact details and delivery addresses with the partner companies we use for the shipment and delivery of ordered products.
  • We share identification and contact data with the partners of the banking networks through which we manage electronic payments. These partners may in turn use anti-fraud and credit check service providers to ensure the security and legitimacy of transactions.
  • We share purchase data with administrative and tax consultants who work with Amevista for all accounting requirements under applicable law.
  • Based on the explicit consent provided by the data subject:
  • We share online browsing data on our websites with analytics providers and search engines, such as Google, which we use to help us improve and optimise the website. These providers are based in the United States and Europe.
  • We share data with consulting providers and marketing tool providers in order to identify strategies, targeted advertising, customer information and surveys.
  • We share data subjects’ data with third parties that manage platforms integrated with the website, such as selected partners that manage product reviews and our Community.
  • Aggregated information with third parties: we may aggregate your information in anonymised form with that of other customers, creating a set of information regarding use of our website, product purchases and other general and grouped information about our customers.

Finally, data subjects’ data may be processed by management software providers, hardware providers, technical IT support providers and project consultants that we use to support, maintain and provide our technology and the IT infrastructure supporting our website and the storage of your information. These providers are appointed as external data processors pursuant to Article 28 of the GDPR, together with appointment as system administrators where applicable.

The updated list of partners with whom we share data subjects’ data is available at our offices.

  1. TRANSFERS OF YOUR PERSONAL DATA

In order to operate our website and services, in accordance with the purposes indicated above, we may transfer and store the personal information we collect from the user to destinations outside the European Economic Area (“EEA”), particularly in the United States, or to one of our Group companies, one of our partners or one of the third parties with whom we work.

Where personal data are transferred to the United States, Amevista verifies the applicability of the adequacy decision relating to the EU-U.S. Data Privacy Framework to the specific recipient. In other cases, the transfer takes place on the basis of the other safeguards provided for under Chapter V of the GDPR, where applicable.

  1. COOKIES

We use technologies such as “cookies” to collect information and store your online preferences. Cookies are small pieces of information sent from a web server to a web browser, allowing the server to uniquely identify the browser on each page. The user may change or withdraw his or her choices at any time through the ‘Manage cookie preferences’ panel, which is always accessible from the website. We use the following categories of cookies on our website:

  • Strictly necessary cookies: these cookies are essential to allow the user to move around the website and use its functions. Without these cookies, services requested by the user, such as storing login details or items in the shopping cart, cannot be provided. These cookies also provide us with information about the user’s behaviour on our website, so that we can do business with the user and protect AMEVISTA and its customers from fraudulent activities.
  • Performance cookies: these cookies collect anonymous information about the use of our website (for example, we use Google Analytics cookies to help us understand how customers arrive at our website, navigate it or use it) and highlight areas that we can improve, such as navigation, the shopping experience and marketing campaigns. The data stored by these cookies do not contain personal information that could be used to identify you. They are also used to measure the effectiveness of an advertising campaign. The user may choose to accept these cookies through browser settings.
  • Functionality cookies: these cookies remember choices made by the user, such as the country from which he or she visits our website, the language and search parameters such as size, colour or product line. This data may be used to provide you with an experience better suited to your choices and to make visits more personalised and enjoyable. The information collected by these cookies may be anonymised and cannot track your browsing activity on other websites. The user may choose not to accept these cookies through browser settings.
  • Targeting or advertising cookies: these cookies collect information about your browsing habits and limited aggregated demographic information in order to make advertising more relevant to you and your interests. They are also used to limit the number of times an advertisement is displayed. Cookies are usually placed by third-party advertising networks. They remember the websites visited by the user and this information is shared with other parties, such as advertisers. For example, we use third-party companies to provide you with more personalised advertising when you visit other websites. The user may consent to these cookies through browser settings.

You may withdraw your consent to these cookies at any time through the options made available by each browser. For specific details of the cookie technologies used on Amevista websites, please refer to Annex (B).

8. HOW LONG DO WE RETAIN YOUR PERSONAL DATA?

We retain the data subject’s personal data only for the time necessary to achieve the purposes for which they were collected, in accordance with the principles of storage limitation and data minimisation set out in Article 5 of the GDPR. In particular:

  • User account data: for the period during which the account remains active; if the account is deleted, the data will be deleted or anonymised, except where retention is necessary to comply with legal obligations or for the establishment, exercise or defence of legal claims.
  • Payment and billing data: for 10 years from the transaction, as required by tax legislation.
  • Data relating to lenses purchased on the basis of medical prescriptions: for 10 years from the issue of the sales documents.
  • Data collected for marketing purposes: until consent is withdrawn and, in any event, no longer than 24 months from the last relevant interaction.
  • Data relating to cookies: in accordance with the information provided in our “Cookies” section or in your browser settings.
  • Data relating to complaints or disputes: until final resolution of the dispute.
  • Data relating to reviews: published reviews and the related personal data are retained for the period necessary for their publication and management. If the account is deleted or consent is withdrawn, the identifying data associated with the review may be deleted and the review will be removed, unless another legal basis exists that permits its retention.

At the end of the periods indicated, the data will be deleted or permanently anonymised.

  1. SECURITY

Ensuring the security of users and their personal data is very important to us. We adopt a number of reasonable measures to help protect the personal information provided by the user, including:

  • Requiring the user to choose a username and a complex password, and encouraging periodic password changes, in order to access his or her account on the AMEVISTA.com website.
  • Not processing data that are not strictly necessary for the provision of the requested services.
  • Not retaining details of the payment instruments used by the data subject.
  • Adopting appropriate security policies to ensure operational continuity and the security of information processed through our IT systems.
  • Encrypting all information in transit between the data subject’s device and Amevista’s systems using SSL/TLS encryption protocols.
  • Applying anonymisation and data minimisation criteria to data processed for statistical reporting.
  • Organising periodic training sessions for personnel authorised to process personal data.

AMEVISTA regularly performs security checks and technical audits to ensure that an adequate level of protection is maintained.

  1. WHAT ARE MY PRIVACY RIGHTS?

The GDPR guarantees that the data subject may exercise a number of rights in relation to data processed by Amevista. Some of these rights may not apply in certain circumstances, such as requesting the deletion of an invoice before the mandatory retention period has expired. Exercising these rights requires the data subject to submit a written request enabling Amevista to verify the identity of the requester, including where the request is received electronically and/or through another duly authorised person. Amevista will respond to requests to exercise these rights without undue delay and within one month (unless it is necessary to extend the period by a further two months due to specific complications). The rights provided for by applicable law are set out in Articles 15 to 22 of the GDPR. In particular:

Right of access to personal data (Article 15 GDPR)

The data subject has the right to obtain from Amevista confirmation as to whether or not personal data concerning him or her are being processed and, if so, to obtain access to the personal data and the following information: the purposes of the processing; the categories of personal data; the recipients or categories of recipients to whom the data have been or will be disclosed, including in third countries; the envisaged retention period or the criteria used to determine that period; the existence of the right to request rectification, erasure or restriction of processing and to object to processing; the right to lodge a complaint with a supervisory authority; where the data are not collected from the data subject, any available information as to their source; the existence of automated decision-making, including profiling, and, at least in such cases, meaningful information about the logic involved, as well as the significance and envisaged consequences for the data subject. Furthermore, where personal data are transferred to a third country or an international organisation, the data subject has the right to be informed of the appropriate safeguards provided for under Article 46.

Right to rectification (Article 16 GDPR)

The data subject has the right to obtain from Amevista, without undue delay, the rectification of inaccurate personal data concerning him or her and, taking into account the purposes of the processing, the right to have incomplete personal data completed, including by providing a supplementary statement.

Right to erasure – “right to be forgotten” (Article 17 GDPR)

The data subject has the right to obtain from Amevista the erasure of personal data concerning him or her without undue delay where one of the grounds provided for by the Regulation applies (e.g. the data are no longer necessary in relation to the purposes, the data subject withdraws consent, objects to processing, the data have been unlawfully processed, etc.). Amevista will erase the data without undue delay unless processing is necessary for exercising the right to freedom of expression, complying with a legal obligation, reasons of public interest, public health or archiving for research/statistical purposes.

Right to restriction of processing (Article 18 GDPR)

The data subject has the right to obtain from Amevista restriction of processing where:

  • the accuracy of the personal data is contested, for the period necessary for the controller to verify their accuracy;
  • the processing is unlawful and the data subject opposes erasure and requests restriction of use instead;
  • the controller no longer needs the data for the purposes of processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;
  • the data subject has objected to processing pursuant to Article 21(1), pending verification of whether the legitimate grounds of the controller override those of the data subject.

During the restriction period, such data may be stored but not otherwise processed unless with the consent of the data subject, for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or a Member State. The controller shall inform the data subject before the restriction is lifted.

 

Obligation to notify recipients of rectification, erasure or restriction of processing (Article 19 GDPR)

Where personal data have been disclosed to other recipients and have subsequently been rectified, erased or subject to restriction of processing pursuant to Articles 16, 17 or 18, Amevista shall inform each recipient of such rectification, erasure or restriction of processing, unless this proves impossible or involves disproportionate effort. Amevista shall provide the data subject with a list of recipients upon request.

Right to data portability (Article 20 GDPR)

The data subject has the right to receive, in a structured, commonly used and machine-readable format, the personal data concerning him or her that have been provided to Amevista and has the right to transmit those data to another data controller without hindrance from the original controller, where:

  • the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a), or on a contract pursuant to Article 6(1)(b);
  • the processing is carried out by automated means. In addition, the data subject has the right to have the data transmitted directly from one controller to another, where technically feasible. This right does not affect the data subject’s right to obtain erasure of personal data concerning him or her (Article 17).

 

Right to object (Article 21 GDPR)

The data subject has the right to object at any time, on grounds relating to his or her particular situation, to the processing of personal data concerning him or her carried out pursuant to Article 6 of the GDPR, including profiling based on those provisions.
Where personal data are processed for direct marketing purposes, the data subject has the right to object at any time to processing for such purposes, including profiling to the extent that it is related to direct marketing; in such cases the personal data will no longer be processed for those purposes.

Right not to be subject to decisions based solely on automated processing, including profiling (Article 22 GDPR)

The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her, unless the decision:

  • is necessary for entering into or performing a contract between the data subject and the data controller;
  • is authorised by Union or Member State law; or
  • is based on the explicit consent of the data subject.

 

Where the decision is permitted under the exceptions above, Amevista adopts appropriate measures to safeguard the data subject’s rights, freedoms and legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.

11. EXERCISING YOUR RIGHTS AND CONTACT DETAILS OF THE DATA PROTECTION OFFICER (DPO)

You may exercise your rights at any time by writing to privacy@amevista.com or by post to AMEVISTA S.r.l. – Via Flaminia 968, 00189 Rome (Italy). You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or, if different, with the supervisory authority of your country of residence.

AMEVISTA has appointed a Data Protection Officer (DPO) pursuant to Article 37 of the GDPR. You may contact the DPO for any request relating to the processing of your personal data at the following address: privacy@amevista.com

12. CHANGES TO THIS PRIVACY NOTICE

This Privacy Notice may be updated periodically to reflect regulatory changes, technological developments or changes in our activities. In the event of substantial changes, we will notify you through the website or other appropriate channels. Users are nevertheless encouraged to review this Privacy Notice periodically.

13. CONTACTS

For any questions or clarification regarding this Privacy Notice, you may contact us at: privacy@amevista.com - AMEVISTA S.r.l., Via Flaminia 968, 00189 Rome, Italy. The Data Protection Officer is available to data subjects and may be contacted by e-mail at DPO@studiocolaluca.it

 

 

 

 

 

 

ANNEX (A) – DEFINITIONS PURSUANT TO ARTICLE 4 OF THE GDPR

  1. Personal data

Any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, by reference to identifiers such as a name, an identification number, location data, an online identifier, or to one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.

  1. Data subject

The natural person to whom the personal data being processed relate.

  1. Processing

Any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

  1. Data controller

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

  1. Data processor

The natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller.

  1. Person authorised to process personal data

The natural person who acts under the authority of the controller or processor, processing personal data on the basis of instructions received and following formal authorisation.

  1. Recipient

The natural or legal person, public authority, agency or another body to which personal data are disclosed, whether or not a third party.

  1. Third party

A natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and the persons authorised to process personal data.

  1. Consent of the data subject

Any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

  1. Special categories of data (sensitive data)

Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade-union membership, as well as genetic data, biometric data, data concerning health or data concerning a person’s sex life or sexual orientation.

  1. Data relating to criminal convictions and offences

Personal data relating to criminal convictions and offences or related security measures (Article 10 GDPR).

  1. Profiling

Any form of automated processing of personal data consisting of the use of such data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning work performance, economic situation, health, preferences, interests, reliability, behaviour, location or movements.

  1. Personal data breach

A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed.

  1. Pseudonymisation

The processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and protected by appropriate technical and organisational measures.

 

  1. Anonymisation

An operation that makes personal data no longer attributable, in any way, to an identified or identifiable person. Anonymised data are not subject to the GDPR.

  1. Restriction of processing

The marking of stored personal data with the aim of limiting their future processing.

  1. Filing system or archiving system

Any structured set of personal data accessible according to specific criteria, whether centralised, decentralised or distributed on a functional or geographical basis.

  1. Transfer to third countries

Any communication or making available of personal data to an entity located outside the European Economic Area (EEA), whether or not by automated means.

  1. Supervisory authority

An independent public authority established by each Member State; in Italy this corresponds to the Garante per la Protezione dei Dati Personali (Italian Data Protection Authority).

  1. Data Protection Officer (DPO)

A person designated by the controller or processor, with advisory, monitoring and cooperation duties vis-à-vis the supervisory authority in matters relating to the protection of personal data (Articles 37–39 GDPR).

  1. Technical and organisational security measures

A set of tools, procedures and policies aimed at ensuring a level of security appropriate to the risk, in accordance with Article 32 of the GDPR.

  1. Record of processing activities

A document required under Article 30 of the GDPR, describing the purposes, categories of data, data subjects, recipients, transfers, retention periods and security measures adopted.

  1. Data retention period

The period during which personal data may be retained in relation to the purposes of processing, in compliance with the principles of storage limitation and data minimisation.

  1. Legal basis for processing

The legal ground that allows personal data to be processed pursuant to Article 6 of the GDPR (e.g. consent, legal obligation, contract, legitimate interest, etc.).

  1. Joint controllers

Two or more controllers who jointly determine the purposes and means of the processing of personal data, defining their respective obligations by means of a written agreement (Article 26 GDPR).

 

 

 

 

 

 

 

 

 

 

ANNEX (B) – SPECIFICATIONS ON COOKIE TECHNOLOGIES USED ON AMEVISTA WEBSITES

We use cookies to personalise content and advertisements and to analyse our traffic. We also share information about your use of our website with our advertising and analytics partners, who may combine it with other information that you have provided to them or that they have collected from your use of their services.