Privacy policy
UltLAST UPDATE: 22 / 11 / 2023
Your privacy and the security of your personal data is very important to the Tod's Group. For this reason, we take the utmost care in collecting and managing the personal data that you provide us with or that we automatically acquire, adopting specific measures to guarantee their security, confidentiality, and integrity, in compliance with the provisions of the Regulation (EU) 2016/679 (hereinafter the "Regulation").
1. WHO IS THE DATA CONTROLLER?
The Data Controller (hereinafter also "Controller") of your personal data is Tod's S.p.A. (hereinafter also "Company", "we", “us” or "our"), with registered office in Via Filippo Della Valle n.1, Sant'Elpidio a Mare (FM) - Italy (EU), contactable at the following e-mail address dataprivacyofficer@todsgroup.com.
2. WHAT KIND OF PERSONAL DATA DO WE COLLECT?
When consulting the pages of our website, some of your personal Data will be collected or, in connection with some services, you will be requested to provide additional personal data.
2.1. Automatically acquired data
(i) Browsing Data - The computer systems and software procedures used to operate the Website acquire, in the course of their normal operation, some data whose transmission is implicit in the use of Internet communication protocols.
(ii) Cookies - to find out more, we invite you to read the section "Cookie Policy - Cookie Setting" available at the bottom of every page on our website. This is information that is not collected in order to be associated with you, but which by its very nature could, through processing and association with data in possession of third parties, allow you to be identified. This category of data includes the IP addresses or domain names of the computers used for navigation and which connect to the Sites, the URI (Uniform Resource Identifier) notation addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the IT environment. These data are not circulated, but are used only to obtain anonymous statistical information on the use of the Site and to check its correct operation, and are kept for the time periods defined by the relevant legal regulations. The data could, however, be used to ascertain responsibility in the event of hypothetical computer crimes to the detriment of the Site. Except in the latter case, such data are not retained for more than fifteen days. For further information and to manage your preferences, we invite you to view the section "Cookie Policy - Cookie Settings", which can be reached via the link available at the bottom of each page of our website.
(iii) Geo-localisation data - The Site's internal search system collects data, exclusively when used and subject to your confirmation, relating to your geographical location, in order to obtain the appropriate search results (e.g., when searching for the boutique nearest to you via the dedicated functionality).
2.2. Data voluntarily provided by you
In order to enable you to take advantage of the various features offered by our website, you may be requested to provide other personal data, such as:
(i) personal data: first name, surname, date of birth, gender;
(ii) contact details: e-mail address, telephone number, address of residence or domicile;
(iii) data relating to purchases made at Tod's Group points of sale or e-commerce sites: date, quantity and type, product code, sale amount, VAT number where applicable, shipping/billing address, data relating to the payment method you wish to use, information on complaints, returns, guarantee, refunds, and other information relating to the sale of products;
(iv) information relating to your interests: services, events, or initiatives of the Tod's Group which you have joined, or expressions of appreciation for products or initiatives of the various Tod's Group brands.
2.3. Personal data collected through social media pages
We may also collect some of your personal data when you interact with our social pages. Some data is submitted directly by you, when you decide to share - through your profile - images published on our social pages, comment on our posts and/or express your approval of one of our products, one of our initiatives or one of our events by selecting the appropriate features, as well as when you decide to write us a message using the private chat or other channels made available on the various social media.
We may also become aware of some data that is indirectly collected as a result of your interaction with our social pages; for example, we may know the time and day when you express your liking to one of our posts or send a request through a mail message.
The knowledge of much of your personal data depends on your chosen social media settings and the content you choose to make public. This data could include your first name, last name, some contact details, and the image associated with your social profile and related information collected through social log-in. We therefore remind you that some of your data may be visible to us should you decide to follow our social pages. For this reason, we invite you to read the privacy policy of the different social media and to check the privacy settings.
2.4. Personal data relating to minors
We would like to point out that the protection of the safety and privacy of minors is very important to the Tod's Group. Therefore, we do not intend to collect and do not intend to voluntarily use any personal data of persons under sixteen (16) years of age, or under any other age limit imposed by the laws in force in your country of residence. We therefore request you to refrain from providing us with any of your personal data if you are under the age of sixteen (16) years or under the age of majority in your country of residence.
3. HOW WE USE YOUR PERSONAL DATA?
Whenever we acquire and process your personal data, this will be done exclusively in accordance with the principles of legitimacy envisaged in the legislation. Your personal data will be processed on the basis of the following principles of lawfulness:
3.1. CONSENT, pursuant to Article 6.1 (a) of the Regulation, in order to
(i) conduct marketing activities, both through automated tools (SMS, MMS, messaging platforms, e-mail, push notifications) and through traditional channels (paper mail, telephone call with operator). The marketing activities may take the form of sending newsletters, promotions, discounts, facilitations, commercial information, and other dedicated services, by paper mail, call with operator, direct sale, through e-mail, pre-recorded calls, 'social' or messaging platforms and SMS/MMS.
In this context, we may also process your personal data in order to invite you to participate in shows and events, to involve you in market research or to notify you of special initiatives dedicated to TOD'S Group customers, in the manner and at the times that we deem most effective based on the various initiatives mentioned;
(ii) analysing some of your personal tastes to identify your preferences, interests, and consumption choices, in order to provide you with services that better meet your expectations and needs.
The profiling activities may take the form of the analysis of information regarding your interests and preferences with regard to our products and services and your consumption choices: for example, by surveying the type and frequency of the purchases you make on our e-commerce sites, through your Personal Account and in "guest" mode, and at our boutiques, in order to be able to guarantee you a personalised service during your future visits to TOD'S Group boutiques. If you have also given your consent to the processing of your personal data for marketing purposes, it will allow us to send you promotions and/or invitations to initiatives that are more in line with your profile, preferences, and expectations.
The provision of your personal data is entirely voluntary, but failure to provide some of them may result in your partial or total inability to be involved in our marketing initiatives. Please note that, should you decide not to consent to the processing of your personal data for marketing purposes, this would prevent us from being able to involve you in our promotional initiatives, including our periodic newsletter updates.
Should you decide not to consent to the processing of your personal data for profiling purposes, this would have no impact on your participation in our promotional communications plan, but would simply result in our inability to send you personalised promotional communications.
- Learn more about how our consent request works
-
When giving your consent, you will be requested to tick the checkbox for each purpose for which you wish to authorise us to process your personal data:
(i) if you tick the consent check box, we will process your personal data for the chosen purpose;
(ii) in the event that you do not tick the consent check box, we will maintain the previous situation, i.e.,
-
if you have previously given us your consent, it shall remain valid until revoked or until the defined 'expiry date';
-
if you have not previously given us your consent, we will continue NOT to use your personal data for the purpose in question.
We would like to remind you that you may revoke previously issued consents at any time by following the instructions given in the remainder of the privacy policy.
3.2. FULFILMENT OF CONTRACT OBLIGATIONS OR CONTRACT MEASURES, pursuant to Article 6.1 (b) of the Regulation, in order to
(i) enable us to respond to your contact request and allow us to provide you with the necessary assistance. The personal data we request you for when filling in the on-line form and/or which will be requested from you by our operators are indispensable to enable us to handle your request;
(ii) enable us to provide you with the services on the Website (hereinafter “Services”) to which you have subscribed. The personal data that we request you to provide when you subscribe to a given service are indispensable for the provision of that service; therefore, failure to provide them may make it impossible, in whole or in part, for you to benefit from them.
The provision of any personal data is voluntary. However, failure to disclose certain personal data could prevent you from partially or fully using Service. Please note that the services available on our website may change over time. Any and all further processing of your personal data, performed by the point of sale you selected, both preparatory and related to the purchase of Tod’s Group products shall be carried out by each retail company of Tod's Group, which, in its role as the Data Controller will provide you with, the necessary information concerning your privacy and the processing of your personal data. In the event that communication channels such as messaging apps (WhatsApp, WeChat, Telegram, etc.) are used for the provision of Services, please also read the privacy policy of the messaging platform used.3.3. LEGAL OBLIGATIONS, pursuant to Article 6.1 (c) of the Regulation, in order to comply with compulsory regulatory provisions to which the Company is subject, including in the tax and administrative area;
3.4. LEGITIMATE INTEREST, within the meaning of Article 6.1 (f) of the Regulation, for the pursuit, under the conditions and within the constraints of the law, of a legitimate interest of ours or of third parties, such as the prevention of fraud, the improvement of management processes, the exercise and defence of a right, the organisational and strategic optimisation of the Company.
4. HOW WE PROTECT YOUR PERSONAL DATA?
The processing will be carried out with the aid of telematic, paper and computer tools; such processing will be based on the principles of correctness, lawfulness, transparency and protection of your rights and confidentiality.
In particular, the processing of your data, including for profiling purposes, may be carried out by means of automated processes, for instance through the comparison and comparative analysis of your purchasing choices (types, quantities, frequency, etc.), during a given period and/or season, and through the analysis of the type and number of your possible requests for information on products made in a predetermined timeframe.
The data will be processed in such a way as to minimise the risks of destruction, loss, unauthorised access, or processing that is not permitted or not in accordance with the purposes of collection.
5. HOW WE SHARE YOUR PERSONAL DATA?
Your personal data will not be disclosed or sold.
To the extent permitted by law, your personal data may be accessible, according to each processing purpose, to
(i) our service providers, including other companies in the Tod's Group, that perform activities of a technical or organisational nature on our behalf;
(ii) third parties in the event of reorganisation, merger, sale, joint venture, assignment, transfer of our business or part thereof (including in connection with bankruptcy or similar proceedings);
(iii) to public authorities, in response to formal and lawful requests from the latter or in execution of regulatory obligations;
(iv) persons authorised by the Company to process personal data necessary to perform activities strictly related to the provision of services, who have committed themselves to confidentiality or have an appropriate legal obligation of confidentiality (e.g., employees of the Company);
(v) Tod's Group companies for internal administrative/organisational purposes.
6. WHERE WE TRANSFER YOUR PERSONAL DATA?
Should it become necessary to transfer your personal data outside the European Economic Area (EEA), to companies of the Tod's Group and/or to third parties who carry out tasks of a technical and organisational nature on our behalf which are consistent with the pursuit of the purposes for which your data have been collected and processed, this will only take place where it is possible to guarantee a level of protection of personal data equivalent to that of the European Community.
In fact, we guarantee that your personal data may only be transferred to a country outside the European Economic Area if at least one of the instruments recognised by the Regulation as guaranteeing an adequate level of protection for the personal data transferred has been adopted, namely:
i. the Adequacy Decisions adopted by the European Commission pursuant to Article 45 of the Regulation;
ii. the provision of specific Standard Contract Clauses, approved by the European Commission, in order to ensure that the level of protection of personal data processed by our partners outside the EEA complies with that guaranteed within the European Economic Area.
We also undertake to carry out, in accordance with the law, any prior risk assessment regarding the transfer of personal data, adopting, where appropriate, any additional security measures in addition to the protections already guaranteed by the aforementioned transfer instruments.
You can receive further information on data protection guarantees in case of transfer to countries outside the European Economic Area contacting our Data Protection Officer (DPO) to the addresses indicated in the Section 9 “HOW TO CONTACT US?” of the privacy policy.
7. HOW LONG WE KEEP YOUR PERSONAL DATA?
Your personal data will be processed by the Company for varying periods of time depending on the different purposes of the processing; in any event, only for the period of time strictly necessary to achieve the purposes for which the data were collected and processed.
For the processing purposes set out below, the processing and storage of your personal data will be as follows:
7.1. Purposes of processing based on 'CONSENT', as referred to in paragraph 3.1 of the privacy policy:
(i) Marketing activities: until consent is revoked;
(ii) Profiling activities: 7 years from the date of issue of your consent, with automatic renewal in the event of a new purchase at a Tod's Group shop or website.
7.2. Processing purposes based on 'FULFILMENT OF CONTRACT OBLIGATIONS OR PRE-CONTRACT MEASURES', referred to in paragraph 3.2 of the privacy policy:
(i) Provision of support services to users of the Web Site: until complete fulfilment of the commitments undertaken following your request for assistance, support, or contact;
(ii) Services available on the Website: until we have fully discharged our obligations in respect of your membership of the chosen service.
7.3. Purposes of processing based on 'LEGAL OBLIGATIONS', as referred to in paragraph 3.3 of the privacy policy: the storage of your personal data may be further extended, with respect to the timeframe indicated above, should the storage of your personal data be required by compulsory legal regulations, within the time limits provided for by the latter.
7.4. Purposes of processing based on 'LEGITIMATE INTEREST', as referred to in paragraph 3.4 of the privacy policy: should the processing activities be conducted on the basis of a legitimate interest, either ours or that of third parties, the retention of your personal data shall be limited to the time strictly necessary to achieve the legitimate interest pursued from time to time.
Should the legitimate interest pursued lie in the exercise and defence of a right of ours in a court of law, the retention of your personal data may extend up to the last instance.
8. WHAT ARE YOUR PRIVACY RIGHTS?
We would like to remind you that you have the right at any time to know what personal data we hold about you and how they are being processed, to request that they be updated or corrected and, in the cases provided for by current legislation, to obtain their deletion, restriction of processing or to object to their processing. If you wish, you may also receive your personal data in electronic format for the purpose of transfer to a third party indicated by you.
You may do so at any time by writing to our Data Protection Officer (DPO) at the addresses indicated in the Section 9 “HOW TO CONTACT US?” of the privacy policy.
You may exercise the rights recognised by the law, with reference to the specific processing operations carried out by us:
8.1. Request to access your personal data as well as receive information on the purpose of the processing, the categories of data processed, the recipients or categories of recipients to whom your personal data may be disclosed, the planned retention period, the application or non-application of profiling mechanisms and automated decision-making processes;
8.2. Request to rectify your personal data. This right allows you to correct or complete the data concerning you, although in some cases a prior verification of the correctness of the new data provided by you is necessary;
8.3. Request to delete your personal data. This right allows you to request the deletion or removal of your personal data if there are no valid reasons for continuing the processing. You also have the right to request the deletion or removal of your personal data if you have exercised your right to object to the processing and there is no other legal basis for us to keep it, or if we have processed your data in violation of the law or if we are obliged to delete your personal data in order to comply with a specific legal provision. Please note that we may not be able to comply with your request for deletion or may only be able to comply with it partially; for example, because of legal, juridical, or fiscal constraints beyond our control that prevent us from deleting all or part of your personal data. The reasons for our total or partial impossibility of fulfilling your request will be submitted to you promptly;
8.4. Request for restriction of personal data processing. Said right enables you to request the suspension of the processing of your personal data in the following cases:
(i) if you request us to determine the correctness of your data.
(ii) if you do not wish your data to be deleted, despite the fact that the use of the data by us is in breach of a regulation.
(iii) if you wish your data to be retained even if the reasons for their retention by us have ceased to exist, because you wish to ascertain, exercise, or defend a legally protected right.
(iv) if you have objected to the use of your data but it is necessary for us to ascertain the existence of legal grounds for their use.
8.5. Request to object to the processing of your personal data. By exercising such right, you may obtain the cessation of the processing of your personal data in relation to the purpose(s) indicated by you. We would like to point out that our granting of your request for objection may or may not take place on the basis of the lawfulness of the processing itself;
8.6. Request for portability of your personal data. We will provide you or a third party indicated by you with your personal data in a structured, commonly used, and machine-readable format. This will only be done, if technically feasible, for personal data whose processing is carried out by automated means and if the processing is based on consent or the performance of a contract;
8.7. Revocation of consent. If the processing is carried out against your explicit consent, we will, within the timeframe provided for by the Regulation, execute your request for revocation and cease the processing in question.
With regard to revoking your consent to the processing of your personal data for marketing and/or profiling purposes, without prejudice to the possibility of exercising this right by writing to the e-mail address dataprivacyofficer@todsgroup.com, we would like to point out that in each of our communications, by e-mail or SMS, of a promotional nature, there is a function through which you may autonomously
(i) proceed to block one or more of the communication channels used by us to contact you;
(ii) withdraw consent to the processing of your data for marketing purposes. In this case, any communication from us of an advertising and/or promotional nature will cease, and any active newsletter service (relating to any Tod's Group brand) will be automatically deactivated;
(iii) withdraw consent for profiling purposes.
The same functions are available within your Personal Account, if you have activated one. In addition, a functionality is available in each of our newsletters through which you can unsubscribe from the newsletter service.
8.8. Refuse to be subject to a decision based solely on automated processing. You may refuse to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
Should the processing be carried out on the basis of a legitimate interest of ours or of a third party, we reserve the right to assess the grounds for your request. Should the reasons for the processing legitimately override your interests, rights, and freedoms, or should it be necessary for us to process such data in order to initiate, execute legal proceedings or defend ourselves in court, we will be obliged to refuse your request, stating the reasons for the refusal.
Finally, we would like to remind you that you may at any time decide to lodge a complaint with the Supervisory Authority, or appeal before the Judicial Authority, in the event of a breach of the rules on the protection of personal data and/or if you consider that one or more of your rights have been violated.
Please note that you will not be discriminated against in any way for having exercised one or more of the rights recognised by the legislation, nor will such exercise have any repercussions on any existing relationship with the Company.
9. HOW TO CONTACT US?
You may exercise these rights at any time by writing to our Data Protection Officer (DPO) at:
by e-mail: dataprivacyofficer@todsgroup.com.
by post: Data Protection Officer - Tod's S.p.A., Via Filippo Della Valle n. 1, 63811 Sant'Elpidio a Mare (FM) - Italy (EU).
You may also contact the DPO for further information or clarification or to be informed of the persons authorised to access your personal data.
When exercising the aforementioned rights, we reserve the right to request you, in the manner we deem most appropriate, for specific information to help us confirm your identity, in order to be reasonably sure that only you have access to your personal data and that they are not disclosed to third parties not entitled to receive them.
We undertake to answer and follow up your request, where well-founded, within one month of receipt of the request to exercise one or more rights. Occasionally, within the time limits granted by law, we may take longer if the request is particularly complex or if you have made several requests. In that case, we will notify you and keep you updated.
The exercise of your rights is completely free of charge.
Should your claims, however, be manifestly unfounded or excessive, particularly due to their repetitive nature, we reserve the right to
the right to charge you a reasonable fee based on the administrative costs incurred in providing you with the information or communication or taking the requested action;
to refuse to comply with your request.
10. AMENDMENT AND UPDATING OF THE PRIVACY POLICY
From time to time, we may make changes to this privacy policy, for example, to comply with new obligations imposed by applicable law or to meet technical provisions or as a result of new services provided by the Site or the Tod's Group.
We therefore invite you to visit this page periodically.
Please refer to the indication 'LAST UPDATED' at the top of the privacy policy.
We may also need to contact you to obtain your consent in order to allow you to continue using the services, if this is necessary due to changes in applicable law.