Privacy policy

This site respects and protects the confidentiality of visitors and users, making every possible and proportionate effort not to infringe the rights of users, in compliance with the obligations arising from national legislation (Legislative Decree No 196 of 30 June 2003, Protection of Personal Data Act) and EU legislation (European Regulation for the Protection of Personal Data No. 679/2016, GDPR) and subsequent amendment.
This privacy policy applies only to the online activities of this site and is valid for the visitors/users of the site. It does not apply to any information collected through channels other than this website.
The purpose of the privacy policy is to provide maximum transparency regarding the information that the site collects and how it uses it.

Data Controller
The data controller (“Data Controller”) is GFL USA Inc., 254 36th Street Ste 256 Brooklyn, NY 11232, TIN 37-1782608, jointly with its parent company GFL SA, with registered office in Via Sorengo 1, 6900 Lugano (Switzerland), owning 100% of its shares. The Data Controller will process your data in accordance with GDPR 679/2016 (European Union). Data Controller's e-mail address: info@gfl.eu

Legal basis for processing
This website processes data on the basis of your consent. By using or consulting this site, visitors and users explicitly approve this privacy policy and consent to the processing of their personal data in relation to the methods and purposes described below, including any disclosure to third parties if necessary, for the provision of a service.

The provision of data and therefore consent to the collection and processing of data is optional, the User may refuse consent, and may revoke a consent already provided at any time (via e-mail: info@gfl.eu or by clicking on unsubscribe). However, refusing consent may result in the inability to provide certain services and the experience of navigating the site may be compromised.

Data collected and purposes
Where provided, the personal data of customers who are natural persons or natural persons who operate in the name and on behalf of customers who are legal persons, are processed by the Data Controller:
a. administrative and accounting purposes: performance of the online sales contract, accounting and compliance with legal obligations, after-sales services.
b. only with your consent, for marketing purposes: that is, to send targeted advertising or commercial communication material by contact methods such as e-mail. The Data collected for this purpose will be kept until your consent is revoked.

For the purposes of point a. the Data Controller may collect and process the following Personal Data:
• personal data: name, second name, surname, first name and surname in local alphabet;
• contact details: telephone/mobile phone number; email address;
• data concerning purchases made on the online store: shipping and billing address, delivery and payment method, name of credit card holder and credit card expiry date.

In addition to the aforementioned Personal Data, for the purposes referred to in point b., the Data Controller may also collect and process the following Personal Data relating to your profile:
• data on purchases made on the online store: detail of the products purchased, price, discount, number of pieces, color, model, collection, level of expense calculated, abandoned cart;
• information on participation in prize-giving events;

If you are a European resident please note that your information will be transferred outside of Europe, including to Canada and the United States.

Refusal to provide data
The provision of data is mandatory in accordance with legal requirements, regulatory regulations and is a condition for the proper and effective fulfilment of the contractual obligations. The provision of further personal data may be necessary to improve the quality and efficiency of the transaction (purposes point b).
Therefore, refusal to provide further data may wholly or partly compromise the processing of other requests and the quality and efficiency of the transaction itself.
In particular, refusal to consent to the processing of data for the purposes referred to in point b will prevent the provision of the above services, but will not compromise the fulfilment of the contractual obligations. You may revoke your consent to the purposes referred to in point b. at any time by contacting the Data Controllers directly at the above addresses. Failure to provide Personal Data and/or to grant consent will preclude the pursuit of the purposes described in point b but will have no consequences on your ability to complete any purchase of interest to you.

Data Retention
The Data Controller keeps and processes personal data using computerized and paper instruments for the time necessary to fulfil the purposes indicated. Subsequently, the personal data will be stored, but no longer processed, for the time established by the civil and tax provisions in force.

Recipients of the data
The personal data processed by the Data Controller will not be disclosed, or will not be transmitted to undetermined subjects, in any possible form, including that of their provision or simple consultation. They may, however, be disclosed to workers employed by the Data Controller and to certain third parties who work with them. They may also be disclosed, as far as is strictly necessary, to persons who, for the purposes of processing orders or other requests or providing services relating to the transaction or contractual relationship with the Data Controller, must supply goods and/or perform services or services on behalf of the Data Controller.

For example, we use Shopify to power our online store--you can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy. We also use Google Analytics to help us understand how our customers use the Site -- you can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.

Finally, personal data may be disclosed to persons entitled to access them by virtue of the provisions of law, regulations and EU regulations.

In particular, your data will be processed:

• by internal subjects such as the employees of the company or collaborators with other contractual forms under the direct control of the Data Controller;
• by third parties to perform specific activities related to particular professional figures and/or techniques, involving the processing of data. These persons are appointed as external data processors and are therefore subject to the obligations imposed on them by current legislation. Among the external data processors, for example, GFL SA refers to
- banks, entities or other parties to whom the transfer of the above data is necessary for managing transactions and performing activities on our behalf in relation to our fulfilment of the agreements entered into with the customer;
- public bodies and institutions including the Inland Revenue, INPS, INAIL (national insurance and social security bodies, CCIAA (chambers of commerce), Region, Province, Municipalities;
- Debt collection companies;
- Law firms;
- Professional firms;
- Couriers and shipping companies;
- Tax consultancy firms (accountants, tax consultants, etc.).

Rights of the data subject
With reference to Articles 15 to 22 of GDPR 679/16, the person concerned may at any time:
• ask for confirmation of the existence or otherwise of their personal data;
• obtain information on the purposes of the processing, the categories of personal data, the recipients or categories of recipients to whom the personal data have been or will be disclosed and, where possible, the retention period;
• obtain the rectification and erasure of data;
• obtain the restriction of the processing;
• obtain the portability of data, i.e. receive them from a data controller, in a structured, commonly used and machine-readable format, and to transmit those data to another controller without hindrance;
• object to the processing at any time and also in the case of processing for direct marketing purposes;
• object to any automated decision process concerning physical persons, including profiling.
• request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability;
• withdraw consent at any time without prejudice to the lawfulness of the processing based on consent given prior to the withdrawal;
• lodge a complaint with a supervisory authority.

The party concerned may exercise his/her rights by writing to the Data Controller at the above addresses, or by e-mail to the following electronic address info@gfl.eu, specifying the subject of his/her request, the right he/she intends to exercise and attaching a photocopy of an identity document attesting to the legitimacy of the request.

Cookies and Device Information
When you visit the Site, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Site, we collect information about the individual web pages or products that you view, what websites or search terms referred you to the Site, and information about how you interact with the Site. We refer to this automatically-collected information as “Device Information”.
We collect Device Information using the following technologies:
- “Cookies” Cookies are electronic files that are stored on the hard drive of the computers of Internet Users. The purpose of cookies is to keep track of previous visits to the Site by Internet Users. Cookies are used solely by the Vendor to customize the service offered to Internet Users. For more information about cookies, and how to disable cookies, visit http://www.allaboutcookies.org.
- “Log files” track actions occurring on the Site, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
- “Web beacons”, “tags”, and “pixels” are electronic files used to record information about how you browse the Site.

SMS Privacy Policy

This SMS Privacy Policy is a part of our overall Privacy Policy and applies specifically to how we collect, use, and disclose information in connection with our SMS program. By opting in to receive text messages from us, you agree to the terms of this SMS Privacy Policy.

Information We Collect

We may collect the following information in connection with our SMS program:

Phone number
Name (if provided)
Carrier information
Message content
Date and time of messages
Information about your interaction with our text messages (e.g., whether you opened a link in a message)
How We Use Your Information

We may use the information we collect from our SMS program for the following purposes:

To send you text messages related to our services, including promotional offers, appointment reminders, and account updates.
To personalize your experience with our SMS program.
To improve our SMS program.
To comply with the law.
How We Share Your Information

We may share your information with third-party service providers who help us operate our SMS program. These service providers are contractually obligated to keep your information confidential and secure. We will not share your information with any other third parties without your consent.

Your Choices

You can opt out of receiving text messages from us at any time by replying "STOP" to any text message you receive from us. You can also manage your preferences by contacting us at [insert contact information].

Data Retention

We will retain your information for as long as you are subscribed to our SMS program. We will also delete your information upon request.

Security

We take reasonable steps to protect your information from unauthorized access, disclosure, alteration, or destruction. However, no internet or electronic storage system is completely secure.

Changes to this SMS Privacy Policy

We may update this SMS Privacy Policy from time to time. We will notify you of any changes by posting the new SMS Privacy Policy on our website.

Contact Us

If you have any questions about this SMS Privacy Policy, please contact us at retail.usa@gflcosmetics.com