PERSONAL DATA PROCESSING NOTICE

provided pursuant to art. 13, EU Regulation 2016/679

The following privacy notice is provided to you by the company Pagani S.p.A., with premises at Via dell’Artigianato, 5 - Vill. La Graziosa 41018 San Cesario sul Panaro (MO) Italy, VAT number: 02054560368 Tel. +39 059 4739201, email: privacy@pagani.com (hereinafter referred to as "Pagani") and by the company Audes Group S.r.l., with premises at Via IV Novembre n. 4, Limena (PD), VAT number 04014850285, email: info@audes.com (hereinafter "Audes") which are acting, each one in accordance with and in relation to the purposes pursued, as autonomous Data Controllers of the personal data collected, whether provided by you or otherwise generated while browsing this website (hereinafter referred to as the "Site") and within the context of the use of the services made available through the Site.

At Pagani, we believe that respect for your privacy is fundamental and therefore we ask you to read this notice carefully. In general, all personal data (hereinafter referred to as the "Personal Data" and/or the "Data") that you provide or which is collected in the context of Site use and use of the services (hereinafter referred to as the "Services" and/or individually as the "Service") - as better defined in the section headed "Personal Data Processing Purposes - will be processed in compliance with the underlying principles of applicable personal data protection legislation, such as the principles of transparency, fairness, lawfulness, data minimisation, purpose and retention restrictions, accuracy, integrity, and confidentiality.

This information is divided into individual sections in order to allow you to read and search the topics as easily as possible.

The Site may contain links to third-party websites or applications; Pagani has no control over and is not responsible or liable, under any circumstances, for the said sites or applications, the content thereof, and/or the Personal Data processing applied and/or carried out thereby.

This Privacy notice may be updated, therefore we advise you to re-read it periodically.

CONTENTS

  1. Data Controller
  2. Data processed
  3. Processing purposes
  4. Legal basis for the processing, required/optional nature of data provision
  5. Personal Data recipients
  6. Transfer of Personal Data
  7. Personal Data retention
  8. Rights of the data subject

1. Data Controller

The following privacy notice is provided to you by the companies Pagani S.p.A., and Audes Group S.r.l., with identification details as stated at the beginning of this policy, which are acting in the capacity of independent Data Controllers, each one for their own separate purposes (better described below) in relation to the Personal Data processed through the Site.

2. Data processed

Your Personal Data may be collected and processed either because you have provided it voluntarily (in order to use the services offered by the Site, such as to purchase Pagani brand products) or because it is collected automatically while you are browsing the Site.

  1. Personal data processed by Pagani S.p.A.

    The Personal Data processed by Pagani S.p.A. through the Site falls into the following categories:

    Contact, identification, and purchase details
    Your Personal Data may be data collected as part of the management of any relationship with Pagani or may be data which you decide to provide when contacting the website using the relative contact details or by filling out the form on the "Contact us" page or, again, by completing the registration form for the ‘Join the Pagani family’ newsletter. Any messages you may send, of your own initiative, to the Pagani contact details given on the site may contain information classified as Personal Data: since there are fields which you may fill in freely, you may provide (even inadvertently) information which falls into particular categories of Personal Data, such as data revealing political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic, biometric, health data or data relating to your sexual relationships or sexual orientation. We, at Pagani, ask you not to disclose any of these types of data unless you deem it strictly necessary for the purpose of the request you have sent to us. Since the provision of such information is, as mentioned, entirely optional, should you choose to do provide it, Pagani may process such information only with your express consent and in compliance with current legislation.
    Pagani will also process your Personal Data in relation to the purchase of Pagani brand products through the Site. This is done exclusively for marketing and profiling purposes subject to specific consent therefor.

    Navigation data and cookies
    During standard operation, the computer systems and software procedures used to operate this Site acquire certain items of Personal Data automatically through the use of Internet communication protocols. This information is not collected by Pagani in order to be associated with identified individuals; however, the nature of this information is such that it could - through processing and association of Data held by third parties - allow users to be identified.
    This kind of data includes IP addresses, domain names of computers used by Users connecting to the Site, as well as the URI (Uniform Resource Identifier) addresses of any resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical code indicating the server reply status (successful, error, etc..) and other parameters relating to the User’s operating system and computer environment.
    This Data is used for the sole purpose of obtaining anonymous statistical information about Site usage, to check that the Site is working properly, and to detect anomalies and /or misuse.
    The Site also uses profiling cookies, including third-party cookies, and similar tracking technologies: further information on the use of cookies is available in the Cookie Policy (https://paganistore.com/pages/cookie-policy) to which reference should be made. You can disable or delete technical and functional cookies, in whole or in part, using the specific features in your browser or the options in the cookie banner. You are advised that disabling technical and functional cookies could make it impossible to use all the features of the Site properly, as well as to view Site contents and use the related Services.

  2. Personal data processed by Audes Group S.r.l.

    The Personal Data processed by Audes as Data Controller (including Data provided by you voluntarily when purchasing products through the Site) fall into the following categories:

    Data relating to the sale of products
    If you decide to make a purchase through the Site, certain kinds of your Data will be processed as necessary to process the order properly, such as your given name, your surname, your email address, telephone number, and billing address and, if different, the delivery address, in addition to the details of the Pagani brand products purchased.
    Further Personal Data could be collected during the handing of any relationship relating to the purchase and may also consist of Data which you provide voluntarily during relations with the Audes Customer Care department, even after completion of the sale.
    As regards Data relating to payments made, it should be noted that the only Data Audes will process is the data received from digital payment companies and institutions that manage credit card payments consisting of payment status feedback, i.e. the outcome of the payment. All information relating to payment card used is stored by the third parties that provide the payment service. More specifically, card payments can be made using Shopify Payments (payment service provider) or through a PayPal or Apple Pay account. For any further information on the Data acquired and processed, please refer to the privacy notice issued by the said service providers.
    With the "express checkout" method, users can also make purchases using their personal GooglePay, PayPal or ShopPay account. In this case, the said service providers will send your Personal Data to Audes automatically. To find out which data will be shared with Audes Group Srl, you can refer to the privacy notice issued by third-party providers’ platforms and the data disclosure options specified therein.
    This Data will be collected and processed by Audes for the purposes set out below in this policy, in the section on the purposes pursued by Audes Group S.r.l. as Data Controller.

3. Processing purposes

Pagani and Audes process your Personal Data, as independent Data Controllers, for the following purposes:

Purposes for which Pagani processes your Data:

  1. to provide assistance relating to use of the Site and Services; to send you any information you have expressly requested by contacting Pagani using the contact details stated on the Site owned thereby; ("Service Provision - Pagani");
  2. to fulfil obligations provided for by laws, EU rules and regulations, or provisions issued by authorities authorised to do so by law and by supervisory and control bodies. ("Legal obligations - Pagani");
  3. to obtain the information needed to detect anomalies, fraudulent activities and/or misuse during Site use, against Pagani or third parties ("Security - Pagani");
  4. to provide information about promotions concerning Pagani products and/or services, as well as to carry out sales, marketing, and market research activities and to measure customer satisfaction levels by sending questionnaires or surveys. Data is processed for this purpose using automated systems without any human intervention (for example, through newsletters), and through conventional contact methods (for example, by post or telephone) ("Marketing - Pagani");
  5. to create user groups by processing the data provided thereby, based on their interests (e.g. previous purchases), in order to send customised sales messages based on the user group. Profiling is a purpose which is also pursued – using cookies and other similar tracking technologies - to analyse how Users use the Site in order to observe the preferences they express and send them advertising messages that are in line with these preferences. For more detailed explanations of how cookies and other similar technologies are sued to make these profiling activities effective, please see the more specific information in the Cookie Policy, including the list of cookies (third-party cookies included) found on the site ("Profiling - Pagani").

Purposes for which Audes processes your Data:

  1. to manage the pre-contractual activities and relationships with potential product users, as well as to ensure the entry into agreements for the online sale of products through the Site in order to fully and correctly process the orders placed through the said channel; to guarantee delivery of the products purchased and verification of the transaction and payment status, to manage requests received through the Customer Care channels ("Pre-contractual measures and performance of the agreement - Audes");
  2. to fulfil obligations provided for by laws, EU rules and regulations, or provisions issued by authorities authorised to do so by law and by supervisory and control bodies, as well as to meet tax and accounting requirements ("Legal obligations - Audes").

4. Legal basis for the processing, required/optional nature of data provision

The legal bases on which Pagani and Audes (each one in the capacity of independent Data Controller) process Personal Data - according to the purposes stated above in "Processing purposes" - are stated below.
The provision of Personal Data and the related processing for the purposes of "Service provision - Pagani" and of "Pre-contractual measures and performance of the agreement - Audes" is strictly functional to the rendering of the Services requested (in particular for activities enabling you to use the Site owned by Pagani and to answer requests received from you using the Pagani contact details found on the Site (as regards the purposes for which Pagani processes the Data) and for the management of pre-contractual and contractual relationships connected to the purchase and sale of products (as regards the purposes for which Audes processes the Data) and correct performance of the pre-contractual and contractual relationship in place with you. Therefore, the provision of data, while given freely, constitutes a necessary condition in order to establish the said contractual relationship and also the legal basis for the processing. Consequently, failure to provide the Personal Data required for this purpose or provision of Data found to be incorrect could make it impossible for Audes and Pagani (each for their own specific purposes) to perform the Service or the contractual relationship and will entitle them to refuse to perform or to interrupt performance of the said relationship.
The provision of Personal Data and the processing thereof for the purposes of "Legal obligations - Pagani" and "Legal obligations - Audes" are necessary in order for Audes and Pagani (each one acting independently and on its own behalf) to correctly perform and fulfil any legal obligations imposed thereupon. The Data will be processed according to applicable legislation, which could involve the Data being retained and disclosed to authorities for accounting or tax requirements or to fulfil other obligations.
Processing for the purposes of "Security - Pagani" is based on Pagani's legitimate interest in identifying and preventing illegal actions, misuse, or fraud and to establish liability in the event of computer crimes against the Site, Pagani, or third parties.
The provision of Personal Data and the processing thereof for the purposes of "Marketing - Pagani" and "Profiling - Pagani" is based on your express consent, including consent given to enable profiling cookies and/or similar technologies, upon clicking the respective "Accept" button on the cookie banner, or by accessing the cookie preferences centre either through the button on the "Preferences" cookie banner or via the "Cookie settings" link in the Site footer while browsing. It is never compulsory to provide such consent and, if you give it, you are free to withdraw it at any time without any consequences. You can withdraw consent given for this purpose by following the instructions given in the Data Subject's Rights Section of this Privacy notice, by following the instructions on how to delete cookies in the Cookie Policy (https://paganistore.com/pages/cookie-policy) or by accessing the cookie preferences centre via the "Cookie settings" link in the Site footer while browsing.

5. Personal Data recipients

Personal Data will be disclosed to the Audes and Pagani staff appointed and authorised to process the Data for the aforesaid purposes, who have either undertaken to maintain confidentiality or are bound to maintain confidentiality by a legal obligation imposed thereupon.
The Personal Data will be disclosed to third parties designated as data processors, in accordance with applicable law, by each of the Data Controllers, which are appointed to process Data on behalf of Pagani or Audes (for example, IT systems and services support companies, email providers, service providers, and consulting companies) with such disclosure being limited to solely that which is necessary in order for them to carry out their appointments for Pagani.
Likewise, the Personal Data may be disclosed to third parties with whom Pagani or Audes entertain contractual relationships concerning services which are functional to the performance of their activities (for example, couriers for the shipment and delivery of products, audit firms, and companies that provide administrative assistance and consultancy, legal, tax, financial and credit services relating to the provision of the Services).
Finally, when required, data will be sent to tax offices and/or other public administration departments in compliance with the laws in force.
The Personal Data processed will not be published or disseminated.

6. Transfer of Personal Data

In consideration of Pagani's international scope of operations and the Site Services aimed at data subjects both inside and outside the EU/EEA, some of your Personal Data is disclosed to recipients (from the categories stated above) located in countries outside the EU or the European Economic Area, including Shopify Inc.
The Data will be processed by these parties solely for the purposes for which it was collected and will be processed in compliance with applicable regulations. Therefore, in the event that data is transferred outside the European Union or European Economic Area, all and any contractual measures deemed suitable and necessary to guarantee an adequate level of protection will be adopted, including – amongst others – adequacy decisions, agreements based on the pro tempore standard contractual clauses in force approved by the European Commission, and/or any other guarantee which may help ensure the level of protection of natural persons guaranteed by EU Regulation 2016/679 is not jeopardised.

7. Personal Data retention

The Personal Data processed for the purposes of "Provision of Services - Pagani" will be kept by Pagani for as long as is strictly necessary to render the Service requested and to perform the pre-contractual and contractual relationship. The requests that you sent using the Pagani contact details found on the Site (and the Data contained in them) will be kept for one year from closure of the request; after that, any Data that allows a natural person to be identified, such as their given name, surname, or email, even indirectly, will be deleted.
The Personal Data processed for the purposes of "Pre-contractual measures and performance of the agreement- Audes" will be kept by Audes for as long as is strictly necessary to perform the contractual relationship with you.
The Personal Data processed for the purposes of "Legal Obligations - Pagani" and "Legal Obligations - Audes" will be kept by the companies (each one acting in the capacity of independent Data Controller) for the length of time provided for by specific legal obligations or applicable legislation.
The Personal Data processed for the purposes of "Security - Pagani" will be kept by Pagani for as long as is strictly necessary to achieve the aforesaid purpose, taking into account needs to retain Data in order to protect oneself in court or to disclose such Data to competent authorities.
Personal Data processed for the purposes of "Marketing - Pagani" and "Profiling - Pagani" will be kept until your consent is revoked, regardless of whether or not you have consented to profiling cookies and similar tracking technologies on the Site. As regards the retention times for Data processed through individual cookies and other similar technologies, we advise you to refer to the list of cookies (including third-party cookies) contained in the Cookie Policy.

8. Rights of the data subject

Pursuant to Arts. 15 - 22 of EU Regulation 2016/679, each data subject has a series of rights which he or she may exercise against Pagani S.p.A and Audes Group s.r.l. at any time, free of charge.
More specifically, you are entitled (in the cases provided for and within the limits set by applicable legislation) to access your Personal Data and have such Data corrected or deleted, as well as to have the processing thereof restricted and to oppose the processing (Arts. 15 et seq. of the Regulation). You are also entitled (where envisaged) to request data portability and, therefore, to receive the Personal Data concerning you in a structured, commonly used, machine-readable format and likewise, you are entitled to request such Data be sent to another data controller.
You may also withdraw consent given for the purposes of "Profiling - Pagani" at any time - regarding the activation of profiling cookies and similar technologies - by clicking on the "Cookies preferences" button in the Site footer and/or following the instructions given in the Cookie Policy.
You may exercise the rights available to you by contacting the data controller at the addresses stated at the beginning of this Privacy notice (preferably, by email at privacy@pagani.com or info@audes.com) - see also the Italian data protection authority website (https://www.garanteprivacy.it/web/garante-privacy-en/home_en).
The data controller will carry out requests from the data subject to exercise the rights thereof in a timely manner and, in any case, within the time limits established by legislation in force.

Right to complain
Data subjects who believe that the way their Personal Data has been processed through this Site breaches the provisions of the Regulation are entitled to file a complaint with the Italian data protection authority, as required by Art. 77 of the Regulations, or to apply to the appropriate judicial authorities (Art. 79 of the Regulation).

Availability