INTRODUCTION

BEAR Projects S.r.l. has always taken the rights of its customers and other stakeholders regarding the protection of personal data and its obligations seriously. This policy clearly describes the types of personal data collected through the website www.holyfreedom.com (hereinafter referred to as the Website) and other tools (e.g., email, social networks, cookies, etc.) and how they are processed, pursuant to the General Data Protection Regulation (EU) 2016/679 (hereinafter referred to as the GDPR) and Legislative Decree 196/2003 (hereinafter referred to as the Privacy Code).

 

DATA CONTROLLER

Upali Arnaldo, as owner and legal representative of BEAR Projects S.r.l., is the data controller (hereinafter referred to as the Controller). Pursuant to the GDPR, the data controller is the entity that, alone or jointly with others, determines the purposes and means of processing personal data. The Data Controller can be contacted by sending an email to info@holyfreedom.com or by sending a registered letter to the following address: BEAR Projects S.r.l., Via San Leonardo, 36, CAP 43122 Parma, Italy.

 

DATA COLLECTED

The Data Controller processes various types of personal, identifying, and non-sensitive data (hereinafter referred to as Personal Data or Data) provided by customers or potential customers, suppliers, collaborators, or other stakeholders (hereinafter referred to as Contact Persons) for the purposes described in this Policy, including:

Contact Person data such as name, surname, company name, tax code and/or VAT number, email address, telephone number, billing and/or shipping address, and bank account details (IBAN), provided by the Contact Person during registration, order completion, or information requests by completing specific forms on the Website, or provided through correspondence via email, telephone, paper, or social media;

Data relating to any transactions carried out by the Contact Person;

Data regarding the Contact Person's use and navigation of our Website, such as IP address and other device identifiers, operating system, and browser type, and information regarding the Website pages visited, collected through cookies or other tracking technologies;

Data collected from third parties, such as data that the Contact Person agrees to share on publicly accessible social networks (e.g., Facebook, Instagram, etc.) and/or that may be collected from other publicly accessible databases.

Personal data required for the proper management of orders or other services is indicated on the Website by the symbol (*). If the necessary personal data is requested through other communication tools, this will be appropriately indicated. The Contact Person is under no obligation to provide personal data; however, providing it is necessary for proper management of the relationship. Failure to provide, or incorrect provision of, any of the required information may prevent the Data Controller from fulfilling its contractual and legal obligations (e.g., processing orders, issuing invoices, paying for supplies, etc.).

 

COOKIES

Information regarding the cookies used on the Website is available at the following link: Cookie policy

 

MINIMUM AGE

The Website and the services offered by the Data Controller are not intended for minors under 18 years of age. If personal information relating to them is inadvertently recorded and the Data Controller becomes aware of it, it will be promptly deleted. By registering or making a purchase on the Website, the Contact Person confirms that he or she has reached the age of majority in his or her country of residence.

PURPOSE AND METHODS OF DATA PROCESSING

The processing of personal data means their collection, recording, organization, storage, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, dissemination, erasure, and destruction, or the combination of two or more of these operations. The Data Controller processes the Contact Person's personal data based on a lawful justification or legal basis for the purposes listed below:

Fulfillment of the sales contract (see Terms and Conditions);

Accounting and administrative management;

Pre- and post-sales assistance;

Marketing activities;

Quality assessment of the products and services offered;

Compliance with legal, administrative, tax, or accounting obligations;

Compliance with legal obligations regarding occupational health and safety;

Recruitment of personnel;

Preparation or exercise of legal action;

Debt collection activities.

Personal data is processed both on paper and electronically and/or automatically, for the time strictly necessary to achieve the purposes for which it was collected. It will be processed only by internal personnel and/or external parties expressly authorized and appointed by the Data Controller.

DISCLOSURE OF DATA TO THIRD PARTIES

Personal data processed by the Data Controller may be disclosed to third parties appointed to process the data (hereinafter referred to as Processors) for the purposes described above, such as:

Transport and shipping service providers;

IT service providers;

Advertising, digital, marketing, or social media service providers;

Legal, administrative, tax, or accounting service providers;

Occupational health or safety service providers;

Electronic payment service providers (e.g., PayPal);

Banks and credit institutions;

Debt collection service providers;

Other public and/or private entities in the event of corporate restructuring;

Other public and/or private entities for the purpose of fulfilling the sales contract;

Other public and/or private entities for which data disclosure is mandatory in compliance with legal obligations.

The Data Controller does not transfer Personal Data outside the European Union unless the Contact Person has explicitly authorized such transfer, or it is permitted by the GDPR on another legal basis. In the event of transfer of Personal Data outside the European Union, the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks apply, using standard clauses approved by the European Commission and adopting the measures permitted by EU legislation to ensure adequate security measures or obtain your consent.

SECURITY MEASURES

In accordance with the GDPR, the Data Controller adopts specific security measures to protect Personal Data in order to prevent its accidental, unauthorized, or unlawful destruction, loss, theft, alteration, and disclosure. However, it is not possible to completely exclude the risks arising from the communication of Personal Data via the Internet or other means. The Data Controller will therefore not hold the Website, the Data Controller, or its Processors liable for any security breaches, unless such breaches are due to negligence or intent. The Website may contain links to third-party websites or platforms. The Data Controller cannot control and/or be held responsible for the conduct of such third-party websites or platforms. Data Controllers are encouraged to read their respective privacy policies to understand how they collect and process personal information.

DATA STORAGE

Personal Data is stored on servers located in the European Union. The Data Controller will retain Personal Data for the time strictly necessary to achieve the purposes for which it was collected, in compliance with legal, administrative, tax, accounting, safety, or occupational health requirements. In order to determine an appropriate retention period, the Data Controller will take into account multiple factors, including:

The purpose for which such Personal Data is retained;

Legal, administrative, tax, accounting, safety, or occupational health obligations related to such Personal Data;

The type of ongoing relationship with the Contact Person (e.g., how frequently they access their Website account, how often they request information, whether they continue to receive marketing communications, etc.);

Any specific requests from the user related to the deletion of personal information;

Legitimate business interests.

RIGHTS OF CONTACTS

Contacts, pursuant to the GDPR, may exercise the following rights:

Be informed about the collection and use of their personal information;

Access their personal information free of charge;

Obtain the rectification or completion of inaccurate or incomplete personal information;

Obtain the erasure of personal information (the right to be forgotten);

Under specific circumstances, obtain the restriction or deletion of their personal information;

Obtain and reuse their personal information for their own purposes across different services when the processing is based on a contract or consent and is carried out automatically (the right to data portability);

Under specific circumstances, object to the processing of their personal information;

Object at any time to the use of personal information for profiling purposes or automated decision-making.

The right to lodge complaints regarding the collection and processing of personal information with the competent supervisory authority;

The right to withdraw consent to the processing of personal data at any time.

Contacts may exercise their privacy rights by sending an email to info@holyfreedom.com or by sending a registered letter to the following address: BEAR Projects S.r.l., Via San Leonardo 36, 43122 Parma, Italy.

CHANGES TO THIS PRIVACY POLICY

Any changes to this Privacy Policy will be posted on the Website and, where necessary, notified to Contact Persons via email.

Product added to wishlist
Product added to compare.