
INGENIOUS DESIGN
Beautifully Practical

AUTHENTIC LUXURY
A Wealth of Skills

CONTEMPORARY YET TIMELESS
The right moment

THE DELIGHT OF BEAUTY
A Tribute to Taste

CONFIDENTIALITY AND DATA PROCESSING POLICY
GENERAL INFORMATION ON DATA PROCESSING
"PRIVACY POLICY"
PIQUADRO GROUP
Last update: June 30, 2026
Data Processing Notice pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (in short "GDPR").
Piquadro S.p.A. (hereinafter "PQ"), Parent Company of the "Piquadro Group", together with The Bridge S.p.A. (hereinafter "TB") and Lancel Sogedi S.A. (hereinafter "LC"), as Joint Controllers, consider privacy and the protection of personal data as fundamental and invite their users and customers to read carefully this Privacy Policy, which contains important information on Data Processing (in short, "Policy" or "Privacy Policy").
This Policy:
· is provided for all companies belonging to the Piquadro Group, which share data with each other for joint purposes common to all;
· is intended for the websites https://www.piquadro.com/it/, https://www.thebridge.it/it and https://www.lancel.com (hereinafter: "Site/s");
· is intended for the mobile Application named "Piquadro" (hereinafter: "App");
· is rendered as an integration of the paper-based data collection and consent form delivered at the points of sale, to which this Policy is linked via a QR code, and contains complete information pursuant to Art. 13 of Regulation (EU) 2016/679;
· constitutes an integral part of the Sites, the App, and the services offered by the Group's companies;
· is provided in accordance with what is described in the General Conditions of Sale and Terms of Use;
· is provided pursuant to Art. 13 of the Regulation, to those who interact with the web services of the Site and of the Joint Controllers, both through simple consultation and through the use of specific services made available via the Site or otherwise arranged by the Group's companies;
· is intended exclusively for adults to whom the services of the Group's companies are addressed.
1) Identity and contact details of the Joint Controllers
Parent Company:
Piquadro S.p.A.
Località Sassuriano, 246
Silla di Gaggio Montano (40041 - BO), Italy
Italian Tax Code (Codice Fiscale) and VAT Registration No. 02554531208
Email: privacy@piquadro.com
Joint Controller:
The Bridge S.p.A.
Registered office in Scandicci (50018 - FI), Italy
Via E. Codignola 14/16
Italian Tax Code (Codice Fiscale) and VAT Registration No. 04253320487
Email: privacy@thebridge.it
Joint Controller:
Lancel Sogedi S.A.
Registered office in 75017 France
48-50 rue Ampere Paris
French Business Activity Code (Code APE): 4772 b - French VAT No. (Numéro TVA) FR 20.612.036.376
Email: privacy@lancel.fr
2) What data we collect and how
2.1) Data voluntarily provided by the data subject
During the use of the Website, the App, and in general the services offered by the Group's companies, we may ask you to provide us with certain personal data or personal information that can be used to identify you, for example via email or online forms, paper forms at the points of sale, through the in-App support feature, through the membership forms for the Clubs and our Services, or through another form of request.
This information may include demographic and contact details, such as name, surname, address, email, and phone number, and some information such as gender and profession.
We process data relating to the products you choose to save in the wishlist, associating them with your account, to allow you to create, consult, and manage your wishlist. Such data are retained for as long as you keep the account or the wishlist itself active. We also process data relating to the preferences you communicate to us regarding the Group's brands to allow you to indicate, freely and separately, for which brands you wish to receive communications and promotional content. This choice is optional, may be expressed separately for each brand and may be modified or withdrawn at any time without prejudice to the lawfulness of processing carried out prior to withdrawal.
Specific summary notices may be made available on the pages of the Site, the App, or in specific forms prepared for particular services on request and for the release of consent for the processing subject to it.
Consumer Users:
For users acting as consumers, the Controller processes common personal data, such as, by way of example: name, surname, shipping and/or billing address, email address, phone number, as well as any further information necessary for managing requests and executing the contractual relationship.
Professional Users:
For users acting as professionals, the Controller may process, in addition to the data indicated above, further information relating to professional activity, such as: type of customer, type of services offered, company name or registered name, VAT number (where requested), as well as professional contact details.
The detailed General Policy on Data Treatment (in short, "Privacy Policy") is always available to the data subject, and we invite you to consult it carefully.
2.2) Automatically collected data
For the purpose of functioning of the services offered, the Website, the Application, and the Software indicated above will automatically collect certain data relating to the user during their normal operation, i.e., data whose transmission is implicit in the use of Internet and mobile telephony communication protocols (so-called log files), data relating to the operating system and the computer environment (IP addresses or domain names, addresses in URI - Uniform Resource Identifier notation), technical data relating to requests (time, method, size, status, outcome, etc.), technical data relating to access and session (e.g., authentication tokens, session identifiers), which may remain active for up to 365 days, to allow you to remain authenticated without having to log in again.
These data are collected through the use of systems capable of storing text files or information, such as Cookies or SDKs (Software Development Kits). This information may include navigation and functionality details, statistical and technical information, and, if opted, some information about the user's preferences to improve their browsing experience or geolocalisation to find the nearest store.
The relevant notice on the processing of automatically collected data (in short, "Cookie Policy") is always available to the user, and we invite you to consult it carefully. The option to manage preferences through the specific online section is also always available.
Some information is necessary to provide the services connected to the Site and the Group's activities, and failure to collect it would result in the impossibility of providing the aforementioned services or the partial functioning of the Site. Optional information does not affect the functioning of the services and can be freely managed by the user. It is always explicitly indicated in the forms and questionnaires which items are mandatory (by means of a * or checkbox symbol). Explicit consent will always be requested, through a specific request, where necessary.
2.3) Data collected through the "Connequ" tracking device
If in use and connected according to the device's instructions of use, the App during its normal operation may automatically collect certain personal data relating to the User, for the purpose of functioning of the requested tracking service. Specifically: data relating to the geographical position of Users when wearing the Products and of the Products themselves in case of loss, MAC address of the Tracker, detection history.
Furthermore, if the User has the Application open in the background on their device with the positioning function active, the Application will collect the data relating to the position of the device used by the User even when the User does not interact directly with the Application. The persistence of the application in the background is notified to the User based on their device's settings.
Such information is necessary to provide the services connected to the Application, and failure to collect it would result in the impossibility of providing the aforementioned services.
2.4) Geolocalisation data
Subject to your explicit consent, the Website and the App may collect on a non-continuous basis data relating to your geographical position (geolocalisation data) in order to provide the services you requested. You can activate or deactivate the collection of such data at any time through the settings of your mobile device.
2.5) Data integrated with third-party platforms
For our activities, we also use tools provided by third parties, including Google LLC and Meta Platforms Inc. To simplify the registration process and subsequent access to the personal Account, we offer the possibility to use the credentials of social accounts managed by third parties, such as Google, Meta (Facebook).
If you choose to use this method, subject to your explicit authorisation provided directly on the third-party provider's platform, the latter will share some of your personal data with our Company. The categories of data that will be transmitted are indicated in the authorization window of the provider itself and typically include name, surname, email address, and a unique identifier associated with the social profile.
The same data together with navigation data may be used, if you have consented through our cookie management banner, through the third-party provider's functionality, for example:
tools provided by Google Signals within the Google Analytics service;
tools provided by Meta, such as the tracking pixel and similar technologies integrated with Facebook and Instagram platforms;
tools provided by Shopify within the Shop service.
These features allow associating information about your navigation collected on our site (such as pages visited, actions performed, technical characteristics of your device, and your IP address) with your account data, provided that you are authenticated on that account and have enabled ad personalization in your settings.
In relation to data collected automatically through systems capable of storing text files or information, such as Cookies or SDKs (Software Development Kits), please refer to the specific policy available online. To understand how these providers process personal data, we invite you to consult their respective privacy policies. The use of the Social login function implies acceptance of the terms of service and privacy policies of said providers. You can at any time disconnect your social account from our user profile, by managing the settings both on our site and on the third-party provider's platform.
2.6) Tracking pixels in emails
Some of the emails we send may contain tracking pixels, which are small graphic elements that allow us to detect information relating to the opening of the message.
Processed Data: information about the opening of the email message (e.g., day and time of opening).
Purposes: We use such tools, only subject to consent, for the following purposes:
measurement of email open rates and optimization of campaigns, including adjusting the frequency of communications;
analysis of behaviors and creation of profiles to send personalized content and offers.
Legal basis: The legal basis of the processing is the consent of the data subject pursuant to Art. 6, par. 1, let. a) of the GDPR. The data subject can deny or withdraw consent at any time, in a granular manner and without losing the possibility to continue receiving our emails, by choosing separately whether to: (i) deactivate tracking pixels; or (ii) completely unsubscribe from communications.
To manage preferences or withdraw consent, the data subject can at any time use the link present in the footer of each email. The data subject retains full control of their personal data at all times and can freely decide not to provide consent or to withdraw it subsequently, without affecting the lawfulness of processing carried out before the withdrawal.
3) Purposes of processing and relative legal basis
Your personal data will be processed, without any obligation of consent, for the following purposes:
|
Purposes of Processing |
Categories of Data Subjects |
Legal Basis |
|
Management of the Site and App, account registration management and connected measures (OTP, email verification), management of various services related to the Site and App (such as registration, language, login or access to reserved functions, selected products), use of Site and App features. |
Consumers / Professionals |
Performance of a contract or pre-contractual measures, satisfaction of a request of the data subject – condition of lawfulness Art. 6, par. 1, let. b) GDPR |
|
Management of contact requests, information, management of customer contacts (email/SMS/WhatsApp). |
Consumers / Professionals |
Pre-contractual measures at the request of the data subject - Art. 6, par. 1, let. b) GDPR; |
|
Account registration, subscription to services (App, Club), integration with chosen social account, Connequ App subscription, profile management. |
Consumers / Professionals |
Performance of a contract or pre-contractual measures - Art. 6, par. 1, let. b) GDPR |
|
Management of orders, purchases, sales, and deliveries of products and relative monitoring, management of payments. |
Consumers / Professionals |
Performance of a contract - Art. 6, par. 1, let. b) GDPR |
|
Customer support, management of requests, complaints, returns, repairs, and technical support, management of vouchers and discounts. |
Consumers / Professionals |
Performance of a contract - Art. 6, par. 1, let. b) GDPR |
|
Customer service management also through help desks, live chats, and AI chatbots. |
Consumers / Professionals |
Performance of a contract or pre-contractual measures - Art. 6, par. 1, let. b) GDPR |
|
Administrative, accounting, and tax compliance (issuing receipts, invoices, preparing payments). |
Consumers / Professionals |
Legal obligation - Art. 6, par. 1, let. c) GDPR |
|
Protection of the Controller's rights and litigation management. |
Consumers / Professionals |
Legal obligation, where applicable - Art. 6, par. 1, let. c) GDPR; |
|
Internal analysis, statistics, and corporate economic management, analysis of software usage and product and service satisfaction, and improvement. |
Consumers / Professionals |
Legitimate interest of the Controller in the improvement of services and corporate organization - Art. 6, par. 1, let. f) GDPR |
|
Service communications (e.g., abandoned cart, abandoned checkout). |
Consumers |
Legitimate interest in facilitating the completion of an initiated purchase - Art. 6, par. 1, let. f) GDPR |
|
Direct marketing of similar products (soft spam). |
Consumers |
Legitimate interest - Art. 6, par. 1, let. f) GDPR; Art. 130, co. 4 of the Italian Privacy Code |
|
Promotional communications to professional customers. |
Professionals |
Legitimate interest in commercial promotion in B2B relations - Art. 6, par. 1, let. f) GDPR |
|
Synchronization of the Tracker with a Product purchased at a Point of Sale, for tracking and retrieval in case of loss. |
Consumers / Professionals |
Performance of a contract or pre-contractual measures, satisfaction of a request of the data subject - Art. 6, par. 1, let. b) GDPR |
The provision of data marked with (*) in the forms for the purposes of the previous section is mandatory, and the lack of data and/or any express refusal to process them will make it impossible for the Controller to perform the contract or pre-contractual measures, to fulfill the obligation or request of the data subject, with possible non-performance and liability of the data subject, including penalties provided by law (e.g., for the application of tax rules or anti-fraud controls), and will affect the operation and use of services offered by the App.
Subject to your consent (Article 7, GDPR), your personal data will be processed for the following purposes:
|
Purposes of Processing |
Categories of Data Subjects |
Legal Basis |
|
Direct marketing activities, including promotion of products and services, sending promotional codes, newsletters, and commercial communications via email, SMS, WhatsApp, push notifications, as well as invitations to complete purchases relating to saved or viewed and not purchased products, abandoned carts, or content generated through AI tools. |
Consumers |
Consent of the data subject - Art. 6, par. 1, let. a) GDPR |
|
Direct marketing activities toward professional users, including promotion of products and services and sending commercial communications. |
Professionals |
Consent of the data subject - Art. 6, par. 1, let. a) GDPR, where required by applicable regulations |
|
Profiling activities, including behavior analysis for promotional purposes, creation of lists for promotional purposes, commercial communication, and sending newsletters, emails, SMS, WhatsApp, push notifications, processing profiles to make available targeted and personalized services and advertisements for the customer's needs, processed through AI tools. |
Consumers / Professionals |
Consent of the data subject - Art. 6, par. 1, let. a) GDPR |
|
Geolocalisation service to identify the nearest affiliated points of sale. |
Consumers / Professionals |
Consent of the data subject - Art. 6, par. 1, let. a) GDPR; Art. 9 of Directive 2002/58/EC |
The provision of data for the purposes of the previous section is optional, with the consequence that you may decide not to provide your consent, or to withdraw it at any time without affecting the lawfulness of the processing based on consent before withdrawal. Failure to provide consent does not affect the use of other services offered.
4) Use of Artificial Intelligence (AI) tools
The Piquadro Group uses Artificial Intelligence (hereinafter "AI") tools and technologies in its operational, commercial, and customer service activities.
Below is a detailed illustration of the purposes, data involved, and legal bases applicable to each processing. In general, the processing activities described in this section do not give rise to decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject under Art. 22 of the GDPR, unless otherwise specified. In any case, in profiling and customer segmentation activities, the data subject retains the right to obtain human intervention, to express their opinion, and to contest the outcome of the processing.
4.1) Analysis of sales data and customer behavior
The Piquadro Group collects and analyzes e-commerce and retail sales data, integrated with behavioral data detected on the Piquadro, The Bridge, and Lancel websites, to identify recurring purchasing patterns and market trends useful for improving the commercial offer.
Processed data: data relating to purchases made (products, amounts, sales channel, date), browsing and behavioral data on the Site, aggregated and statistical data on customer behavior.
Legal basis: legitimate interest of the Controller pursuant to Art. 6, par. 1, let. f) of the GDPR, consisting in the improvement of commercial strategies and management of corporate business. Data are processed in aggregated or pseudonymized form where possible.
4.2) Advanced Profiling
Subject to your explicit and specific consent (Art. 6, par. 1, let. a) GDPR), we may process your data to analyze or predict aspects concerning your personal preferences, interests, and purchasing habits.
Data used for profiling:
The profiling activity is carried out by analyzing data such as: demographic and contact data, purchase history (for example "purchase frequency in the last 12 months", "preferred product category", "valore medio del carrello / average cart value", "interaction with email campaigns"), viewed products, products added to the cart (even if not purchased), interaction with our commercial communications (e.g., email opens, clicks on offers), navigation data on the Site and the App.
Logic used, significance, and envisaged consequences:
• Logic used: Data for advanced profiling purposes are processed with the help of artificial intelligence systems and machine learning algorithms. These systems identify correlations and recurring patterns in user behavior. For example, the algorithm can identify groups of users with similar interests, e.g., "backpacks," "bags," or "suitcases." This segmentation allows us to better understand your preferences and predict which products, services, and offers may be of greatest interest to you.
• Significance and envisaged consequences for the data subject: The main consequence for you is the receipt of commercial communications and the display of personalized content (e.g., advertising banners, product suggestions on the Site/App) that are more in line with your interests. For example, you might receive a discount on a product you have frequently viewed or suggestions for a subsequent purchase. Another consequence is exclusion from promotional campaigns considered irrelevant to you, thus avoiding unnecessary communications.
• Exclusion from the application of Art. 22 GDPR: It is specified that this profiling activity is aimed exclusively at personalizing commercial communications and user experience. It is not based solely on automated decision-making that produces legal effects (e.g., whether or not to conclude a contract) or similarly significantly affects your person (e.g., determining price discrimination or exclusion from essential services) under Art. 22 of the GDPR. All offers and services remain accessible to all users under standard conditions. You have the right to withdraw your consent to profiling at any time, without affecting the ability to use our services. In any case, you have the right to request human intervention, express your opinion, and contest any preliminary evaluation made by the algorithm.
Purposes of processing:
The processing of personal data is aimed at carrying out advanced profiling activities through the use of artificial intelligence systems and machine learning algorithms, aimed at analyzing the behavior, preferences, and interactions of the data subject. This analysis allows the creation of individual or group profiles, functional to the personalization of the services offered, to the proposal of targeted content and promotional initiatives, and to the preparation of products and features that better respond to the needs and interests of the customer.
Legal basis:
The legal basis of the processing is the consent of the data subject pursuant to Art. 6, par. 1, let. a) of the GDPR. The data subject retains full control of their personal data at all times and can freely decide not to provide consent or to withdraw it subsequently, without affecting the lawfulness of processing carried out before the withdrawal. Providing consent to advanced profiling allows benefiting from a personalized experience and services more in line with your preferences, overall improving the quality and relevance of the proposals received.
Security and limitations:
The processing takes place in compliance with the principles of data protection by design and by default (Data Protection by Design and by Default). AI models are trained on previously anonymized datasets. Your data are not used to train new models.
User rights:
The user maintains full control over their data and can withdraw consent at any time, immediately stopping any further processing through artificial intelligence. Objection can be exercised in a simple and immediate manner by deactivating the function via the specific option in the personal area of the account or in the App's configuration settings. Deactivation of the feature will immediately stop any further processing of data for this purpose. The rights provided for in Articles 15 et seq. of the GDPR remain in any case exercisable, such as the right of access, erasure, restriction of processing, and withdrawal of consent, within the limits of applicability. For further information on the processing of personal data and the use of artificial intelligence technologies, you can contact the Controller at privacy@piquadro.com.
4.3) Customer Service Analysis
Data relating to interactions with customer service (messages, support requests, complaints) are analyzed using AI tools in order to identify areas of improvement for the service and optimize the overall customer experience.
Processed data: content of communications with customer service (text of messages, support tickets), customer identification data where necessary to the context of the request.
Legal basis: legitimate interest of the Controller pursuant to Art. 6, par. 1, let. f) GDPR, consisting in improving the quality of the service offered to customers. Data are processed in pseudonymized form where technically possible.
4.4) AI Assistant for Customer Service
To improve the efficiency and quality of the customer support service, the Piquadro Group has implemented artificial intelligence (AI) systems integrated in its communication channels, such as live chats (chatbots) and ticket management systems (help desk), with automated response functionalities for user requests and product suggestions based on the needs expressed by the data subject.
If used through the User's interaction with the AI chatbot system integrated in the customer support platform, the Websites during their normal operation may collect certain personal data relating to the User. Therefore, users are expressly invited not to share personal data that are not necessary for managing their request through these channels.
Processed data:
content of questions and requests formulated by the user in the interaction with the assistant, identification data where provided by the user during the conversation, any further data voluntarily provided by the user during the interaction, data relating to the request (content of the conversation).
The personal data subject to processing include:
• Identification and contact data (e.g., name, surname, email address) provided by you or already associated with your account.
• Content of communications: the text of your requests sent via email, chat, or other contact forms, and the history of previous interactions.
• Data relating to the context of the request: information on orders, purchased or viewed products, and technical navigation data, necessary to understand and resolve your request.
Purposes of processing:
The personal data provided are processed exclusively for customer support purposes, including:
1. Managing information or technical/commercial support requests;
2. Optimizing and automating assistance: providing automatic and immediate answers to frequently asked questions (FAQs) 24 hours a day, 7 days a week, via chatbot;
3. Qualifying and routing requests: analyzing the content of your request to understand the topic and urgency, and automatically routing it to the human operator or the department most competent for resolution;
4. Automated forwarding to a human operator, if necessary;
5. Supporting operators: assisting our customer service staff by suggesting relevant answers, knowledge base articles, or solutions to known problems, in order to accelerate response times and improve service consistency;
6. Improving the service: analyzing, in aggregated and anonymized form, recurring topics and issues emerged from interactions to identify areas of improvement of our products and services, in compliance with the data minimisation principle.
Legal basis:
The legal bases for the processing activities described above are as follows:
• For the purposes under points 1, 2, 3, and 4, the processing is necessary for the performance of a contract to which you are party or for the execution of pre-contractual measures adopted at your request (Art. 6, par. 1, let. b) GDPR). The provision of effective customer support is indeed an integral part of the service offered.
• For the purposes under points 5 and 6, the processing is based on the legitimate interest of the Controller (Art. 6, par. 1, let. f) GDPR) to improve the quality of its services and the overall customer experience. We believe that this interest is balanced with your rights and freedoms, as the processing takes place on aggregated and anonymized data and has no direct impact on your person. You still have the right to object to such processing in accordance with the provided procedures.
Logic used:
AI systems analyze the text of your communications using Natural Language Processing (NLP) technologies. These algorithms are trained to recognize the main topic, the intent (e.g., request for information, reporting a problem), and the tone (sentiment) of your request.
Significance and envisaged consequences:
The main consequence for you is the possibility of receiving faster and more efficient assistance. The system can instantly resolve common doubts or ensure that your request reaches the right person more quickly. It is specified that the AI system acts as a support and qualification tool. Decisions that can produce legal effects or similarly significantly affect your person (e.g., the management of a complex complaint, the decision on a refund) are not based solely on an automated process and always require review and validation by a human operator, in compliance with Art. 22 of the GDPR. In any case, you have the right to request human intervention, express your opinion, and contest any preliminary evaluation made by the algorithm.
Security and limitations:
The processing takes place in compliance with the principles of data protection by design and by default (Data Protection by Design and by Default).
• AI models are trained on previously anonymized datasets. Your conversations are not used to train new models.
• Access to conversation contents by authorized staff is limited solely to assistance and resolution purposes of your specific request.
4.5) Automated translation of digital content
Website content and product sheets are automatically translated into multiple languages using AI tools, in order to make the commercial offer accessible to international markets.
Processed data: textual content of the site and product sheets. This processing does not, as a rule, involve the processing of users' personal data.
Purposes: improvement of the user experience and simplicity of reaching and understanding content.
Legal basis: legitimate interest of the Controller pursuant to Art. 6, par. 1, let. f) GDPR.
5) Intra-group data sharing
This Policy provides summary information on how the Piquadro Group companies share information internally, which is detailedly regulated by reciprocal joint controller agreements.
As the Parent Company, in order to best govern the Group's strategies and efficiently and effectively realize the corporate business, Piquadro has decided to aggregate and unify administrative management and commercial and marketing direction, both regarding offline and online activities carried out through the websites and e-commerce platforms.
Therefore, Piquadro receives information from the Group's companies and shares it with them. Information collected by each company of the Group is shared and mutually used by the others, in order to make available, provide, improve, understand, personalize, support, and market services and offers, including products and the respective Piquadro/The Bridge/Lancel brands, and therefore within the predefined Group purposes under section 3.
Where provided, the data subject can withdraw consent at any time, also with reference to a single brand of the Group, without affecting the lawfulness of the processing carried out before withdrawal. The withdrawal can be exercised in a granular manner and with the same ease with which consent was given.
Further information on the Group and its legal entities is available on the website https://www.piquadro.com/it/struttura-del-gruppo. In the event that the Group is involved in a merger, acquisition, restructuring, or sale of all or part of its assets, information will be shared with the subsequent entities or new owners within the transaction in compliance with applicable data protection laws.
6) Categories of recipients of personal data
For the purposes of the previous paragraph, the personal data provided by you may be communicated or made accessible:
to employees and collaborators of the Controller, in their capacity as authorized data processors (or so-called "persons in charge of processing");
to third parties carrying out outsourcing activities on behalf of the Controller, in their capacity as Processors, including:
- service providers for the management of the information system and telecommunications networks and the company in charge of e-commerce management;
- service providers for the management of paper and/or computerized document archiving (cloud);
- service providers for the management of customer assistance activities, also through websites (e.g., call centers, help desks, chatbots, etc.);
- service providers for the management of commercial communication activities;
- providers of artificial intelligence solutions and platforms used for the purposes under section 4, integrated with corporate systems, which act as Processors pursuant to Art. 28 GDPR based on specific contractual agreements;
professionals, firms, or companies in the context of assistance and consultancy relationships, also for corporate organizational management control;
banks, credit, and insurance institutions for conducting economic activities (payments/collections) and insurance activities;
subjects performing control, audit, and certification activities of Piquadro S.p.A.'s operations also in the interest of customers, fraud detection and prevention agencies;
judicial or supervisory authorities, administrations, public entities, and bodies (national and foreign).
The complete and updated list of Processors can be requested in writing at privacy@piquadro.com.
7) Retention and transfer of personal data abroad
The management and retention of personal data take place in the cloud and on servers located inside and outside the European Union owned by and/or available to the Controller and/or third-party companies appointed, duly designated as Processors.
The transfer of data abroad to countries not belonging to the European Economic Area (EEA) takes place exclusively within intra-group communications for the purposes indicated above or toward contractual partners, in any case in compliance with the provisions of Chapter V, Articles 45 and 46 of the GDPR.
In particular, with reference to international transfers of personal data to third countries, the Piquadro Group adopts the following structured approach:
• Verification of destination: First, we verify whether the destination country benefits from an adequacy decision by the European Commission pursuant to Art. 45 GDPR. Where such a decision exists, the transfer takes place without the need for further specific guarantees.
- For transfers to the United Kingdom and Japan, we rely on the "adequacy decisions" of the European Commission, which recognize an adequate level of data protection in these countries.
- For transfers to the USA, we rely on the "adequacy decisions" of the European Commission, as in the case of transfers to US organizations certified under the "EU-US Data Privacy Framework".
- For transfers to the USA, Russia, China, and other countries without an adequacy decision, the transfer is justified by the necessity to deliver the purchased goods. We inform you that in these countries, data protection laws may not offer the same level of protection as in the European Union. The Group undertakes, where possible, to frame these ongoing relationships through appropriate guarantees such as Standard Contractual Clauses (SCCs).
• Adoption of appropriate guarantees: In the absence of an adequacy decision, the transfer is based on appropriate guarantees pursuant to Art. 46 of the GDPR, mainly through the signing of Standard Contractual Clauses (SCC) adopted by the European Commission with the Decision of 4 June 2021, with the data importing entities.
• Transfer Impact Assessment (TIA) and supplementary measures: In accordance with the jurisprudence of the Court of Justice of the European Union (Schrems II ruling, C-311/18) and the Recommendations 01/2020 of the EDPB, each transfer based on SCC is preceded by a specific impact assessment to verify that the law of the third destination country does not prevent the importer from complying with the contractual obligations assumed. Where necessary, supplementary measures of a technical (e.g., data encryption, pseudonymisation), contractual, and organizational nature are implemented to guarantee a level of protection substantially equivalent to that ensured by the European legal system.
Your personal data will not be disseminated.
8) Period of retention of personal data
The personal data collected automatically by the Site for the purposes indicated in the previous paragraphs will be processed and stored for the time strictly necessary to achieve the purposes for which they were collected and automatically deleted after such period.
Specifically, the period of retention of data starting from the first session/visit of the Site or App, or from the User Account registration, or from the specific consent release, takes place as follows:
|
Type of Data |
Retention Period |
Effective Date |
|
Data provided by the data subject (2.1) |
12 months |
from collection |
|
Data relating to the Account User |
36 months |
from Account registration |
|
Data relating to the Customer |
60 months* |
from Customer registration |
|
Data collected automatically by the Site or App (2.2) |
12 months |
from collection |
|
Data relating to communication and marketing purposes |
60 months* |
from consent collection |
|
Data relating to profiling purposes |
60 months* |
from consent collection |
|
Accounting and billing data |
10 years |
from accounting document issuance |
|
Data relating to potential litigation |
for the time strictly necessary or in relation to statutory limitation periods ex lege |
from the onset of the dispute |
|
Data processed through AI tools for sales analysis, advanced profiling, and customer service |
12 months from collection, unless longer document retention is required |
from acquisition |
|
Data collected through the virtual assistant "Chatbot" |
for the time necessary to process the request and, subsequently, for a maximum period of 12 months |
from acquisition |
* This retention period is considered appropriate in view of the average life cycle of our high-end products and the typical purchase frequency of our customers, thus allowing us to maintain a relevant relationship with the data subject and offer a personalized service over time.
After this retention period, the data will be destroyed or irreversibly anonymized, in accordance with the adopted technical procedures.
Renewal of consent: The 60-month period can be renewed at each significant interaction of the user (e.g., a new purchase, access to the personal area of their account, or active interaction with our communications, such as clicking on a link), or in response to a request by the Controller for a new expression of consent. In the absence of interactions for 60 months or if renewal is not expressed, the consent will be considered withdrawn.
9) Security Measures
Piquadro has implemented appropriate technical and organizational measures for logical and physical data security and to prevent unauthorized processing.
In particular, the following technical and organizational measures are adopted, among others, to guarantee the security (confidentiality, integrity, and availability) of personal data:
all communications between the browser of the Data Subject's device and the servers of the Websites take place via secure communication protocols (HTTPS and TLS) using encryption techniques;
a personnel access control policy is implemented through secure authentication procedures (MFA);
specific procedures are adopted for managing incidents and personal data breaches ("data breach") and, in case of a confirmed breach, timely notification will be given to the Data Subject and/or the Supervisory Authority, in compliance with current regulations;
systems and processes are developed and managed in compliance with the principles applicable to processing and security requirements required by the GDPR.
10) Exercisable Rights
Piquadro implements appropriate technical and organizational measures to guarantee the protection of the Data Subject's rights. In compliance with the provisions of Chapter III, Section 1, of the GDPR, you can exercise the rights indicated therein at any time.
The request can be addressed indifferently to each of the Joint Controllers by simply sending an email to one of the following addresses: privacy@piquadro.com / privacy@thebridge.it / privacy@lancel.fr.
In particular, reference is made to the following requests:
Right of access: Obtain confirmation of whether or not personal data concerning you are being processed and, if so, receive related information, in particular regarding: purposes of the processing, categories of personal data processed, and retention period, recipients to whom they may be communicated (Article 15, GDPR);
Right to rectification: Obtain, without undue delay, the rectification of inaccurate personal data concerning you and the integration of incomplete personal data (Article 16, GDPR);
Right to erasure: Obtain, without undue delay, the erasure of personal data concerning you, in the cases provided for by the GDPR (Article 17, GDPR);
Right to restriction: Obtain the restriction of processing, in the cases provided for by the GDPR (Article 18, GDPR);
Right to data portability: Receive the personal data concerning you in a structured, commonly used, and machine-readable format, as well as obtain that they are transmitted to another controller without hindrance, in the cases provided for by the GDPR (Article 20, GDPR);
Right to object: Object to the processing of personal data concerning you, unless there are legitimate grounds for the Controller to continue processing (Article 21, GDPR);
Right to lodge a complaint with a supervisory authority: Lodge a complaint with a supervisory authority, in particular in the Member State where you habitually reside, work, or where the alleged infringement occurred.
Competent authorities for each State can be found at the following link: [Our Members | European Data Protection Board](https://edpb.europa.eu/about-edpb/board/members_en).
• Italian Supervisory Authority (Garante per la Protezione dei Dati Personali), Piazza Venezia n. 11, Rome - https://www.garanteprivacy.it/ - or
• CNIL: Commission Nationale de l'Informatique et des Libertés - French Supervisory Authority - https://www.cnil.fr.
The designated contact point for data subjects to exercise their rights, although they can be exercised toward any of the Joint Controllers, is the Parent Company Piquadro at the address privacy@piquadro.com.
The Account can be deleted through the dedicated Web and App section.
Global Effectiveness and Country-Specific Information
Our activity is based on transparency and respect for personal data on a global scale. This Policy has been drafted to be clear, complete, and understandable, in line with the highest data protection standards.
We adhere with commitment and professionalism to the GDPR, as the Parent Company is established in the European Union.
Services are provided by companies belonging to the Piquadro Group, operating in different jurisdictions and organized according to a multinational structure. In this context, the processing of personal data can be carried out by one or more entities of the group, which act, depending on the case, as independent controllers or joint controllers pursuant to Art. 26 of Regulation (EU) 2016/679 ("GDPR").
The applicable controller varies depending on the service used, the country where the user is located, and/or the domain or application through which the services are delivered. If multiple entities of the group jointly determine the purposes and means of processing, they operate under a joint controllership regime, governed by specific internal agreements that define in a transparent manner their respective responsibilities in terms of personal data protection.
Personal data may be processed and shared among group companies within the limits strictly necessary for the purposes indicated in this Policy, also for the purpose of centralized management of information systems, customer service, security, regulatory compliance, and service improvement.
It is understood that, regardless of the group entity involved, the data subject can exercise their rights under applicable regulations against the competent controller indicated for their jurisdiction, or by contacting the single reference point indicated in this Policy, which will route the request to the responsible entity. The group's websites may be managed by different legal entities and/or be dedicated to specific geographical areas. The use of a specific domain or application may involve the application of this Policy with reference to the controller indicated for the relative jurisdiction.
Additional Information for Specific Countries
• For data subjects located in the European Economic Area (EEA):
The processing of personal data of users residing in countries belonging to the European Economic Area (e.g., Norway, Iceland, Liechtenstein) takes place in compliance with Regulation (EU) 2016/679 (GDPR), as applied in the Member States and EEA countries. Data subjects benefit from all rights provided by the GDPR, including the right of access, rectification, erasure, restriction of processing, data portability, and objection, by contacting the Controller at the contact details indicated.
• For data subjects located in the United Kingdom (UK):
The processing of personal data of users residing in the United Kingdom takes place in compliance with the UK GDPR and the Data Protection Act 2018. The provisions of this Policy relating to purposes, methods of processing, and data subjects' rights provided under Regulation (EU) 2016/679 (GDPR) remain applicable, in so far as they are compatible. Data subjects can exercise their rights, including access, rectification, erasure, restriction, and objection to processing, by contacting the Controller at the contact details indicated. If you wish to contact us to exercise your rights regarding personal data or to request information on our data processing, you can do so through the following channels: privacy@piquadro.com indicating Piquadro UK in the subject. If you wish to contact us through our UK GDPR representative, you can do so at: Piquadro UK Limited: 67 Regent Street, London, W1B 4EB.
• For data subjects located in Switzerland:
The processing of personal data is carried out in compliance with the Federal Act on Data Protection (FADP) and the relative Ordinance (DPO). The provisions of this Policy relating to purposes, methods of processing, and data subjects' rights provided under Regulation (EU) 2016/679 (GDPR) remain applicable, in so far as they are compatible. Data subjects can exercise their rights, including access, rectification, erasure, restriction, and objection to processing, by contacting the Controller at the contact details indicated. Switzerland is considered by the European Commission as a country with an adequate level of protection.
• For data subjects located in the United States:
The processing of personal data of users residing in the United States takes place in compliance with applicable state data protection regulations, including, where applicable, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), as the reference regulatory standard. In particular, users residing in the United States have the right to:
- know the categories of personal data collected and the purposes of processing;
- request access to personal data;
- request deletion of personal data;
- object to the sale or sharing of personal data ("opt-out");
- not be discriminated against for exercising their rights;
- correct inaccurate personal information;
- limit the use and disclosure of personal information.
The Controller does not sell or share personal data, unless otherwise indicated in this Policy.
• For data subjects located in other countries outside the European Union and the European Economic Area:
For data subjects located in other countries outside the European Union and the European Economic Area, the processing of personal data may also be subject to applicable local regulations. If such regulations provide additional or different rights or protections, they will apply within the limits and in the manner provided by the applicable law.
Supervisory Authorities and Right to Complain
In relation to the processing of personal data carried out within the services offered by the Controller to users located in different jurisdictions, the data subject has the right to lodge a complaint with the competent supervisory authority, in particular in the State where they habitually reside, work, or where the alleged infringement occurred. The right of the data subject to exercise the rights provided by applicable regulations by contacting the Controller directly at the contact details indicated in this Policy remains in any case unaffected.
Identity and contact details of the Controller:
The supervisory authority of the place of the main establishment of the Controller is: Garante per la protezione dei dati personali - https://www.garanteprivacy.it.
Competent authorities for each EU or EEA Member State are: [Our Members | European Data Protection Board](https://edpb.europa.eu/about-edpb/board/members_en). In cases of cross-border processing, the competent supervisory authority operates in cooperation with the other concerned authorities under the "one-stop-shop" mechanism provided by the GDPR, with the identification of the lead authority in the country of the main establishment of the Controller.
The supervisory authority for users residing in the United Kingdom (UK) is: Information Commissioner's Office - ICO - https://www.ico.org.uk.
The supervisory authority for users residing in Switzerland is: Federal Data Protection and Information Commissioner - FDPIC - https://www.edoeb.admin.ch/it.
The supervisory authority for users residing in the United States (USA) is: competent state authorities (such as the Attorneys General or specific authorities provided by state regulations, for example in California - https://oag.ca.gov).
Revisions
Since our activities change constantly, our Privacy Policy is also subject to changes. We suggest checking our site or the App frequently to verify any changes. Our current Privacy Policy applies to all data we have collected, unless otherwise indicated.
Since we respect the promises made, we will not materially change our policies and procedures without the review or consent of the interested customers, where required. In the event of significant changes, the affected users will be informed in appropriate ways and, where necessary, a new review or consent will be requested, also with reference to specific sections applicable to certain geographical areas. Conversely, changes that do not materially affect users' rights or that concern only specific geographical areas do not require a new review by unaffected users. To review previous policies, contact the Controller.