PRIVACY POLICY UK
This Privacy Policy relates to your use of our website only and describes which of your personal data are collected by Tristate International SA, Tristate Digital SA and Tristate UK Ltd (jointly the ‘Joint Controllers’), for what purposes and how they are processed. Below you will also find the information you need to exercise your rights under the applicable data protection regulations, such as the Swiss Data Protection Act and UK GDPR, each to the extent applicable (the "Applicable Data Protection Regulations").
In general, we collect information about you when you create an account on the https://www.massimoosti.com online shop (the "Store"), when you purchase products offered for sale on the Store, when you subscribe to the newsletter, when you send us emails or contact us for support or information about the availability of a product. Please note that the personal data collected during these processes will be processed for the conclusion, administration and performance of contractual relationships, in order to respond to your requests, to allow you to take advantage of the services offered by the Shop by accessing restricted areas (for example, to process your orders and carry out related activities, including operations necessary for administrative and tax purposes and, where requested by you, sending newsletters and information material) and also to provide better services, marketing and support to you and other customers, as described below.
Given the nature of our website, we do not expect to collect the personal data of anyone under [13] years old. If you are aware that any personal data of anyone under [13] years old has been shared with our website please let us know so that we can delete that data.
This privacy policy relates to your use of our website only.
Throughout our website we may link to other websites owned and operated by certain trusted third parties to make additional products and services available to you. Those third-party websites may also gather information about you in accordance with their own separate privacy policies. For privacy information relating to those third-party websites, please consult their privacy policies as appropriate.
1. Who processes your data: joint controllers
Tristate UK Ltd register n. 13889346, with registered office in 86 Jermyn Street, London SW1Y 6AW (‘Tristate UK’), Tristate International SA, with registered office in Lugano, Via Canova 9, CHE 147076577 ( ‘Tristate’), and Tristate Digital SA, with registered office in Lugano, Via Canova 9, CHE 338710554 (‘Tristate Digital’) pursuant to the Applicable Data Protection Regulations- e.g. Article 26 UK GDPR - are the Joint Controllers of the processing of your personal data, are legally responsible for deciding how and for what purposes it is used, and shall process them in order to: manage and process your purchase orders, ship to you the products that you buy, provide you with the required post-sales assistance, process the product returns procedure, keep you informed about the availability of a product on the Store, comply with all obligations arising from tax law and other applicable laws. Under Article 26 UK GDPR, you may find out the essential content of the agreement between Tristate UK, Tristate Digital and Tristate by contacting us via e-mail at privacy@eu.tristateww.com or customerservice@massimoosti.com
Joint Controllers are the controllers of your personal data and shall process them for managing your Store account, for the Store maintenance, for the management of customers’ requests submitted through Customer Care (either for purchases that you have not made on the Shop or in case of request for information on Tristate's products) and, upon your consent, for marketing purposes, even in profiled mode.
Hereinafter, when we use the expressions ‘Joint Controllers’, ‘We’ or ‘Ours’, we will jointly refer to Tristate, Tristate Digital, and Tristate UK together. Vice-versa, if the information only refers to one of the two data controllers, you will find the reference to either Tristate UK, Tristate Digital or Tristate.
2. Which data we process - Type of processed data
The personal data we collect about you depends on the particular activities carried out through our website. We will collect and use the following personal data about you:
Your contact and purchase data. We will retain the details you provide us with (e.g., your contact and personal data) when you purchase a product, interact with the after-sales service or ask to be updated on the availability of a product in the Store. Tristate will also keep such data when you create an account on the Store, subscribe to the newsletter, participate in Tristate contests or promotions and/or contact Customer Care.
Your payment and invoicing data. Tristate UK will retain the payment and invoicing data that you provide to us with (e.g., your credit card number, contact and personal data) when you purchase a product, in order to process your order and ship the products.
Information on the use of the website and on your activities on the Store. Your use of the website implies the processing of the browsing data and the device that you are using and your IP address (i.e. the number that identifies a specific device connected to the internet and is required in order for your device to communicate with websites). Moreover, Tristate may analyse the website you browsed from, what you did and what you did not do on our website. In order to send you commercial information about products and proposals tailored to your preferences, Tristate may use your email address and your name, as well as browsing data and website behavioural information to understand better which products you prefer, provided that you have previously authorized such processing.
You must provide this personal data to use our website and the services on it unless we tell you that you have a choice.
Sometimes you can choose if you want to give us your personal data and let us use it. Where that is the case we will tell you and give you the choice before you give the personal data to us. We will also tell you whether declining to share that personal data will have any effect on your use of our website or any services on it.
We collect and use this personal data for the purposes described in the section ‘Why and for how long we process your data - Purpose and legal basis for data processing; data retention period’ below.
3. Where do we get your data - Data collection methods:
Directly from you. For instance, if you register in order to make a purchase on the Store, if you create an account, if you participate in a contest, if you ask us a question, subscribe to the newsletter or contact Customer Care. If you do not provide us with your personal data, you will not be able to register on the Store, and you will not be able to purchase any of the products for sale nor make use of the other services provided.
When you register with your social media account, and particularly with your Facebook account, Tristate will get the personal data you choose to share through such social media services based on their privacy settings. We may also use social media plug-ins on the website. The data will be shared with the social media service accordingly and, if applicable, shared on your social media profile. Please refer to the privacy policy of these third-party social media providers to learn more about such policies.
Through the use of Store’s functionalities. Tristate uses cookies and other technologies, such as pixel tags on the website and in emails in order to collect data concerning your behavioural information and to improve promotion targeting. Should you like to learn more, please read our Cookie Policy.
Third party data provided directly by you. The possible provision (e.g., for the shipment of the product) of personal data and contact details of any third party other than you represents a processing of personal data with respect to which you are a data controller, thus assuming all the obligations and responsibilities provided for by current legislation on personal data. On this regard, you guarantee to the Joint Controllers and individually to Tristate, Tristate Digital and Tristate UK that any data of third parties that will be indicated by you have been collected by you in full compliance with current legislation on personal data, and that there is an appropriate legal basis that allows the communication of such third party personal data to Joint Controllers and individually to Tristate, Tristate Digital and Tristate UK, relieving them from any dispute, claim, request for compensation for damages from any third party resulting from the aforementioned communication that may be received by Tristate, Tristate Digital and Tristate UK.
4. Why and for how long we process your data - Purpose and legal basis for data processing; data retention period
a) To provide you with the products and services you purchased and to give you information about your orders and payments. We will use your data to process your order, to confirm your purchase and to manage any service related to it, such as the shipping of purchased products. Without your data, we cannot manage and process your order.
The legal basis of such data processing is the performance of the purchase agreement, which you become a party of since you accept the Store’s general conditions of sale.
The data retention period of your data is equal to the period required to process the order (provided that if other processing activities, such as after-sales assistance and management of the administrative position, are applicable, the retention period shall be that indicated in this notice in relation to such processing).
b) To allow you to register for a Store account. Tristate will use your personal data in order for you to create an account on the Store, whether you make a purchase on the Store or not.
The legal basis of such data processing is the performance of a contractual/pre-contractual request submitted by you.
The retention period of your data, in addition to what is necessary to process your order if any, shall be equal to the period of validity of your account, which shall be in any case deactivated after 24 months from your last access or from the last action taken by you in your account.
c) To give you an update on product availability. Following your explicit request, We will process your personal data to give you an update on the availability of a requested product on the Shop.
The legal basis of such data processing is the performance of a contractual/pre-contractual request submitted by you.
The retention period of your data is equal to the period necessary to process the request.
d) To provide you with the required after-sales assistance in compliance with the applicable legislation related to the product warranty. We will use your data to provide you with support, in order to manage the return and/or repair of the products that you purchased from the Store in accordance with applicable law and the Store’s general conditions of sale.
The legal basis of such data processing is the compliance with legal obligations and the data retention period is equal to that required by law.
e) To manage your administrative status correctly. We will process your data for accounting, administrative and tax purposes, directly connected to Tristate UK and Tristate’s business activities as required by the applicable legislation.
The legal basis of such data processing is the compliance with the legal obligations and the retention period is equal to that required by law (specifically, civil, tax, anti-money laundering, banking and public security law).
f) To let you to interact with customer care operators. We may use your personal and contact data to assist you should you require support while using the products purchased from the Store.
The legal basis of such data processing is the performance of the sale and purchase agreement that you executed with Tristate UK when you accepted the Store’s general conditions of sale and the compliance with the obligations provided for by applicable law in terms of warranties and customer care. The retention period is equal to the time necessary to manage your request (provided that, if other process activities are applicable, the retention period shall be that indicated in this notice in relation to such processing).
Tristate may also process such personal data to assist you with purchases that you have not made on the Store or when you request information about Tristate's products.
The legal basis is the performance of the sales agreement that you have executed with Tristate or the performance of pre-contractual requests. The retention period of your data in relation to such data processing is equal to the time necessary to process your request (provided that, if other processing is applicable, the retention period shall be that indicated in this notice in relation to such processing).
g) To prevent or control unlawful conducts or to protect and enforce rights. We may use your data to prevent infringement of their intellectual property rights (e.g., counterfeiting of our trademarks and/or our partners’) or theft (including credit card cloning and theft that we presume may occur during a contest or an event) or other unlawful acts, as allowed by applicable law.
The legal basis for such data processing is the legitimate interest of the Joint Controllers.
The period of retention of your data is equal to the time reasonably necessary to enforce our rights from the moment we become aware of the offence or the potential commission of it.
h) To update you on your shopping cart. We may process your personal data, in particular your email address, when you have created an account on the Shop, to remind you that the shopping cart on the Shop contains products.
The legal basis for such processing is the legitimate interest of the Joint Controllers to keep you updated about your shopping cart.
The retention period of your data for this purpose is 48 hours from when you left the shopping cart without completing your purchase.
i) For newsletter subscription. Upon your consent, you may be contacted by Tristate by email or other telematic communication means with information or promotions of products and services offered by the Shop, also following your subscription to the newsletter by entering your email address.
The legal basis for such data processing is your explicit consent which, , and as far as only the subscription to the newsletter is concerned, consists of entering your email address.
The retention period of your data is 24 months from the collection of your data.
j) To send you commercial communications and to offer you products aligned with your preferences. Upon your consent, Tristate analyses your personal data and the data concerning your use of the website, preferences and consumption of the products in order to improve its approach towards you and its customers in general, through automated processing activities, including profiling activities. Tristate does so in order to make better decisions related to services, advertising, products and contents, based on a greater awareness of how its customers use its services and to provide you with a more customized user experience. For such purpose, Tristate may also collect your mobile device’s ID for advertising (i.e. IDFA - Identifier for Advertising - for iOS devices and AAID - Google Advertising ID - for Android devices) so that it can always provide you with targeted and relevant advertisements based on your preferences and interests.
The legal basis of such data processing is your explicit consent, which you may withdraw at any time.
The retention period of your data is 12 months from the collection of your data.
k) To allow you to participate to surveys. Tristate may, with your prior consent, which you may withdraw at any time, send you surveys in order to analyse any feedback you voluntarily provide via such surveys, for example, in connection with a customer service contact or a purchase from the Store. The legal basis of such processing is your explicit consent. The retention period is equal to the time required to process your feedback as a result of your participation in the survey.
5. Nature of the provision of personal data
For the purposes of subparagraphs from a) to h) above, the provision of data is necessary to allow you to create an account on the website, make purchases on the Shop and receive other services on the website.
For the purposes of subparagraphs from i) to k), the provision of data is optional, a refusal will not cause any prejudice for the purposes of subparagraphs from a) to h). Data subject, where applicable, may withdraw his/her consent at any time, but this shall not affect the lawfulness of processing carried out by Tristate based on consent before its withdrawal.
6. Where your data are processed – Transfer of data
Data shall be processed and stored at the offices and IT systems of Tristate and Tristate UK.
Personal data may also be disclosed, including for the purpose of customer service interaction, to companies providing services - specifically appointed as data processors pursuant to the Applicable Data Protection Regulations - based in countries outside Switzerland and the UK. In those cases, we will comply with applicable UK laws designed to ensure the privacy of your personal data.
Such data transfers shall be authorized either upon:
- an adequacy decision of the third country to which the data are transferred, adopted by the competent authorities such as the European Commission pursuant to Article 45 of the GDPR, or the UK government pursuant to Article 45 of the UK GDPR, and a list of countries the UK currently has adequacy regulations in relation to is available here; or
- the appropriate or adequate safeguards provided for by the Applicable Data Protection Regulations such as Articles 45, 46, 47 and 49 of the UK GDPR (such as standard contractual clauses approved by the European Commission, binding corporate rules, contractual or covenantal safeguards provided by the data controllers involved, or such as exemptions to the prohibition of transfers applicable in specific situations), as well as on the basis of the right to contact the Joint Controllers to obtain the contact details of the entities to whom the personal data are disclosed, from whom he/she may receive information on how to obtain a copy of the processed data or where the data have been made available.
· If you would like further information about data transferred outside the UK, please contact us (see ‘How to contact us’ below).
7. Who we share your data with – recipients of personal data
Provided that, where required by law, we will obtain your prior consent and complete any formalities required by law, we may share your data with the following third parties (also acting as data processors):
Our service providers. We may share your data with third parties so that they can provide us with services (e.g., providers of IT services for the management of the Shop, providers of profiling services and compliance automation, payment gateways and other entities that provide banking services, couriers, companies that manage warehouses and provide logistics services, legal, tax and accounting consultants) who may act as autonomous data controllers or as data processors: in this second case we will enter into a data processing agreement aimed at protecting your data. These entities will only hold the data necessary to perform their functions and may only use it to perform such services on Our behalf or to comply with legal requirements. You can find out the details of such data processors by contacting us by email at the above-mentioned addresses. If such providers operate outside Switzerland or the European Union, we will meet one of the conditions set out above before disclosing any personal data to them.
Where we deem it necessary in order to comply with legal obligations or to protect Ourselves or third parties from a judicial standpoint. Where permitted or required by law, we may also share the data requested by a government agency or by another authorised third party or organisation, in order to protect or enforce Our rights or those of third parties, or to limit or prevent fraud (including credit card fraud or other fraud, which we believe that may occur during a promotion or an event) and other offences.
8. Minors
Our Store is not intended for minors under the age of 18, but for adults. If you are a parent or guardian and you believe that your child may have sent us some personal data, please contact us.
9. Security Measures
We adopt the security measures required by law, and we limit access to your personal data to those who have a genuine need to access it.
We adopt security measures to protect your data. The standard security measures that we use depend on the type of data that we process, and such measures meet the requirements provided for by UK and European laws and by the standards of British and European government agencies.We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
10. Your rights
You generally have the following rights, which you can usually exercise free of charge:
Access to a copy of your personal data |
The right to be provided with a copy of your personal data | |
Correction (also known as rectification) |
The right to require us to correct any mistakes in your personal data | |
Erasure (also known as the right to be forgotten) |
The right to require us to delete your personal data—in certain situations | |
Restriction of use |
The right to require us to restrict use of your personal data in certain circumstances, eg if you contest the accuracy of the data | |
Data portability |
The right to receive the personal data you provided to us, in a structured, commonly used and machine-readable format and/or transmit that data to a third party—in certain situations | |
To object to use |
The right to object: —at any time to your personal data being used for direct marketing (including profiling) —in certain other situations to our continued use of your personal data, eg where we use your personal data for our legitimate interests unless there are compelling legitimate grounds for the processing to continue or the processing is required for the establishment, exercise or defence of legal claims | |
Not to be subject to decisions without human involvement |
The right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you We do not make any such decisions based on data collected by our website |
|
The right to withdraw consents |
If you have provided us with a consent to use your personal data you have a right to withdraw that consent easily at any time You may withdraw consents Withdrawing a consent will not affect the lawfulness of our use of your personal data in reliance on that consent before it was withdrawn |
|
When you exercise your right of access, you have the right to know whether your data is being processed or not, as well as the purpose of the processing, the categories of data being processed, the recipients or categories of recipients who your data have been disclosed with (and, if they are located in a third country, the guarantees in place), the retention period of your data (or the criteria in order to determine such retention period), whether an automated processing is being carried out or not (e.g., through profiling), the logic involved behind such processing, and the source of the data (when not initially collected by Us).
For further information on each of those rights, including the circumstances in which they do and do not apply, please contact us (see ‘How to contact us’ below). You may also find it helpful to refer to the guidance from the UK’s Information Commissioner on your rights under the UK GDPR.
You have the right to lodge a complaint with the competent data protection supervisory authority, and/or the the Information Commissioner in the UK, which may be contacted using the details at https://ico.org.uk/make-a-complaint or by telephone: 0303 123 1113.
If you would like to exercise any of those rights, please email us at the above-mentioned address or by sending an email to privacy@eu.tristateww.com or to customerservice@massimoosti.com
When contacting us please:
• provide enough information to identify yourself [(eg your full name, address and customer or matter reference number)] and any additional identity information we may reasonably request from you, and
• let us know which right(s) you want to exercise and the information to which your request relates
In any case, you may amend or withdraw your consents by changing Store's settings.
You can withdraw your consent to receive marketing communications including newsletters. In order for you to stop receiving marketing communications, you may access your account and change your settings or follow the instructions shown in the promotional message that you receive. Alternatively, you may withdraw your consent by sending an email to privacy@eu.tristateww.com
A cookie is a small text file which is placed onto your device (eg computer, smartphone or other electronic device) when you use our website. We use cookies on our website. You may control and disable cookies and other profiling tools. To learn how we use cookies and other profiling tools, click here.
As for marketing emails and data processing through profiling, you may amend your preferences in the privacy settings of your account or by sending an email to privacy@eu.tristateww.com
11. What happens if we amend this Policy
We may make amendments to Our privacy policy from time to time — when we make significant changes we will take steps to inform you of any of such changes, in accordance with the law. We will also publish an updated version of it on Our website. It will have a different date and version number from the ones shown below. Please visit the site periodically to check for updates.
Version updated to 04/14/2024