Privacy Policy

ARTICLE 13 GENERAL DATA PROTECTION REGULATION (GDPR)

With this information sheet, LASH & BROW di Loredana Atanasiu, CF TNS LDN 88L52 Z129D, with registered office in Piazza Drago 2, Jesolo Lido (VE), e-mail address lorena11658@yahoo.com (hereinafter " LoredanaAtanasiu " or the "Company") wishes to inform you about the processing of your personal data ("Data") and your respective claims and rights in relation to data protection:

1 TYPE OF DATA PROCESSED AND RELATIVE ORIGIN

The Company processes the data received from the user during the relevant visit or purchase on its website www. LoredanaAtanasiu .com (hereinafter the "Website") or on the Webshop-App (hereinafter "Mobileshop"). The Company refrains from collecting or processing any special categories of Personal Data.

Personal Data includes:

Your personal data: e.g. name, address, email address, telephone number and gender

LoredanaAtanasiu user's purchase data: e.g. customer number, UID number, previous purchases,

Invoice number, date and time of purchase, product, quantity and price

Data about the payment method used by the user: e.g. bank details, company issuing the credit card used,...

 

2 PURPOSE AND DURATION OF THE TREATMENT

The User's data is processed by the Company in accordance with the applicable data protection legislation, as well as for specific purposes and periods of time. The most important purposes and duration of processing are listed below. If the Company collects data from the User for other purposes, it will inform the User before collecting such Data.

2.1 PURCHASE ON LoredanaAtanasiu

The Data provided by the user during the purchase of products are processed by the Company for the purpose of fulfilling its contractual obligations towards the user. This includes, for example, the delivery of the goods ordered by the user. Such data are processed by the Company exclusively for the fulfillment of its obligations; in addition, the Company will process the Data exclusively until there are legal obligations in this regard, or for the purpose of exercising or defending legal proceedings.

2.2 CUSTOMER ACCOUNT LoredanaAtanasiu

The Company processes the data provided by the user when creating their LoredanaAtanasiu profile for the provision of LoredanaAtanasiu service offers. Through their LoredanaAtanasiu customer account, the user can process purchases faster, save more than one address, track their orders and much more. In the event of purchasing products online through their customer account, the Company also processes the Data for the purposes of executing and completing the purchase.

The Company will process the Data provided for the LoredanaAtanasiu customer account until the effective deletion of the aforementioned account by the user; beyond that, the Company will need the Data exclusively where there is a legal obligation for the purposes of exercising or defending in the course of legal proceedings.

2.3 NEWSLETTER BY LoredanaAtanasiu

The Company processes the Data provided by the user during registration to the LoredanaAtanasiu Newsletter for direct marketing purposes. The user will receive personalized newsletters via email and will be informed about offers, services and events of LoredanaAtanasiu and its partner companies where, based on the data provided, the Company deems that such information is particularly relevant and interesting for the user.

The Data provided by the user during registration to the LoredanaAtanasiu Newsletter are processed by the Company as long as the user wishes to receive the newsletter, as well as exclusively as long as such Data are necessary for the exercise or defense of legal proceedings.

2.4 CUSTOMER SERVICE LoredanaAtanasiu

When you contact the Company's customer service ("contacts") for requests or problems, the Company processes the Data to fulfill the related requests or to resolve the problems.

The Data provided by the user are processed by the Company exclusively for the duration of the response to the respective requests and the resolution of the respective problems. In addition, the Company will process the Data exclusively for as long as there is a legal obligation to do so, or where such Data is necessary for the exercise or defense of legal proceedings.

2.5 CHAT BY LoredanaAtanasiu

When the user uses the LoredanaAtanasiu Chat for requests or problems, providing his/her Data (name, email address and message), the latter will be processed exclusively to respond to requests or satisfy the user's needs.

The Data provided by the user for the LoredanaAtanasiu Chat will be processed for the entire duration of the response in order to satisfy requests and resolve problems. In addition, the Company will process the Data exclusively as long as there is a legal obligation to do so, or where such Data is necessary for the exercise or defense of legal proceedings and for internal administrative purposes.

 

3 LEGAL BASIS FOR DATA PROCESSING

3.1 BASED ON YOUR CONSENT (ARTICLE 6 (1) (A) GDPR):

If the user has given his/her consent to the processing of his/her Data - for example for the receipt of the LoredanaAtanasiu Newsletter - such processing will be carried out exclusively in accordance with the purposes specified in the respective declaration of consent and to the extent agreed therein.

The user may revoke his/her consent at any time with effect for the future by sending an email or a letter to the Company, at the contact details indicated in point 9. The revocation of consent does not affect the lawfulness of the processing based on the consent given before the same;

3.2 FOR THE PURPOSE OF COMPLIANCE WITH CONTRACTUAL OBLIGATIONS (ARTICLE 6 (1) (B) GDPR):

The Company will process the User's Data in order to fulfill its contractual obligations towards the same. For example, the Company needs the user's name and address for the purposes of shipping the products ordered and issuing the appropriate invoice. In the event of delivery problems or in case of doubts or requests, the Company needs, for example, the user's email address or telephone number to be able to contact him.

3.4 FOR THE PURPOSES OF LEGITIMATE INTEREST (ARTICLE 6 (1) (F) GDPR):

Where necessary for the purposes of the legitimate interests of the Company or any third parties, the processing of User Data occurs:

The legitimate interest of the company in processing your data includes its own and third-party marketing purposes, customer loyalty or direct marketing.

Furthermore, the Company has a legitimate interest in processing your personal data for administrative purposes within LoredanaAtanasiu and its affiliates ( LoredanaAtanasiu ), as well as for the exercise or defense of legal claims.

4 RECIPIENTS OF PERSONAL DATA

Furthermore, your Data will be shared with companies engaged by the Company (in particular IT or payment services and back office providers), if they need it to fulfill their respective tasks. Such providers are obliged to keep all Data strictly confidential, to process it only to the extent necessary for the provision of services and to carry out their processing activities within the European Economic Area. If such companies carry out their processing activities outside the European Economic Area, appropriate safeguards pursuant to Article 46 GDPR exist to ensure an adequate level of data protection.

Your data will be shared with the following recipients:


5 COOKIES


5.1 TECHNICALLY REQUIRED COOKIES

The Company uses cookies on its Website, which are small files stored on your device (e.g. web browser or mobile device). The next time you visit the Website or Mobileshop using the same device, the information stored in the cookies will be sent back to the Company. In addition, as you navigate the Website, the Company collects information about the individual web pages or products you have viewed, the websites or search terms that led you to the Website, and information about how you interact with the Website or Mobileshop. The Company uses the Data collected through these cookies to better represent its Website and Mobileshop and to make its offers more user-friendly, for example to evaluate the use of the Website or Mobileshop. Stored cookies remain on your device until you delete them. They enable the Company to recognize your browser on your next visit. Other cookies are stored exclusively for the duration of your visit.

To collect this Data, the Company uses the following technologies:

"Cookies" are data files that are placed on your device or computer and often include an anonymous unique identifier. For more information about cookies, and how to disable them, visit http://www.allaboutcookies.org.

"Log files" track actions occurring on the Website or Mobileshop, and collect data including your IP address, browser type, referring/exit pages, and date/time stamps.

"Web beacons", "tags" and "pixels" are electronic files used to record information about how you navigate the Website and how you use Mobileshop.

WEBSITE:

Cookies necessary for the operation of the Store:

Cookie name Purpose Storage period
section_data_ids Facilitates caching of content in the browser, allowing pages to load faster. Until the end of the page visit
PHPSESSID The user's session ID on the server. 1 hour
product_data_storage Save the configuration for product data for recently viewed/compared products. Until the end of the page visit
recently_compared_product Stores the product IDs of recently compared products. Until the end of the page visit
recently_viewed_product_previous Stores the product IDs of previously viewed products for easier navigation. Until the end of the page visit
mage-translation-file-version Facilitates the translation of content into other languages. Until the end of the page visit
recently_viewed_product Stores the product IDs of recently viewed products for easier navigation. Until the end of the page visit
form_key Stores randomly generated keys to prevent the use of counterfeit information. 1 hour
Pnctest Please check that cookies are actually supported by your browser. 1 hour
recently_compared_product_previous Stores the product IDs of previously compared products for easier navigation. Until the end of the page visit
mage-cache-storage-section-invalidation Facilitates caching of content in the browser, allowing pages to load faster. Until the end of the page visit
mage-cache-storage Facilitates caching of content in the browser, allowing pages to load faster Until the end of the page visit
mage-messages Contains information about the availability of new messages for the visitor/customer within the store. Until the end of the page visit
mage-translation-storage Facilitates the translation of content into other languages. Until the end of the page visit

All these cookies are technically necessary for the presentation of the Website. The user can deactivate the saving of cookies in the settings of his browser. Please note that a general deactivation of cookies may possibly lead to functional limitations of the Website.


MOBILE SHOP:

Cookie name Purpose Storage period
shopgate_analytics_SHOPNUMMER_uuid Stores anonymous data for creating statistics in the dealer area. 10 years
SSID Done via Facebook and Google listed below. Until the app closes.

Cookies necessary for the operation of the Store:

All these cookies are technically necessary for the presentation of Mobileshop.

In addition, the Company uses pixels and tags from the following third parties (who in turn may insert cookies):

Third parties Description Privacy Policy
Google Analytics The Company uses Google Analytics to measure how users interact with its websites. https://policies.google.com/privacy
Google Ads The Company uses Google Ads to provide targeted advertisements to visitors to its websites. https://policies.google.com/privacy
Facebook The Company uses Facebook Custom Audiences to deliver targeted advertisements to visitors to its websites. https://www.facebook.com/policy.php
Pinterest The Company uses Pinterest Custom Audiences to deliver targeted advertisements to visitors to its websites. https://policy.pinterest.com/en-gb/privacy-policy#section-residents-of-the-eea
Snapchat The Company uses Snapchat Custom Audiences to deliver targeted advertisements to visitors to its websites. https://www.snap.com/en-GB/privacy/privacy-policy
TikTok The Company uses TikTok Custom Audiences to deliver targeted advertisements to visitors to its websites. https://www.tiktok.com/legal/privacy-policy?lang=en
LinkedIn The Company uses Linkedin Custom Audiences to deliver targeted advertisements to visitors to its websites. https://www.linkedin.com/legal/privacy-policy?
PayPal The Company uses PayPal as one of its payment service providers to process orders and capture payments from you. https://www.paypal.com/en/webapps/mpp/ua/privacy-full
Stripes The Company uses Stripe as one of its payment service providers to process orders and capture payments from you. https://stripe.com/privacy-center/legal



5.2 GOOGLE ANALYTICS


The Company also uses Google Analytics cookies, a web analytics service provided by Google LLC (hereinafter “Google”). These cookies transmit data on the use of the Website by the user to a Google server in the United States. However, the IP address will be shortened by Google before transmission and the transmitted data can no longer be associated with the user. Google will use this information to evaluate the general use data of the Company's website and to compile reports on the activities of the same. If the user wishes to prevent the use of Google Analytics cookies on the website, he can do so via the browser settings (see point 5.1), or he can install the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout.

For information about Google and its affiliates' data use and storage practices, please see their privacy policy, currently available at: https://www.google.com/privacy.html.

Google Analytics Cookies Purpose Storage period
_gat Determined by Google Analytics to identify unique sessions 30 minutes
_gid Determined by Google Analytics to identify unique sessions 30 minutes
_ga Determined by Google Analytics to identify unique sessions 30 minutes

Click here to opt-out of Google Analytics.

5.3 FACEBOOK AUDIENCE PIXEL

The Company also uses the Facebook Audience Pixel analysis tool from Facebook Ireland Limited or Facebook Inc. to measure the effectiveness of its advertising. The pixel collects information about the use of the website and mobile app, such as when the website or app is used and whether goods are placed in the shopping cart, by transmitting this information to Facebook servers in Ireland and the United States. This information may also be cross-referenced with other Facebook information or with data about you held by the Company. All data collected by this pixel is encrypted by Facebook using the "hash" method. Facebook Ireland Limited is based in the European Union; Facebook Inc. is based in the United States and has a Privacy Shield certificate, which guarantees the protection of your data.

The collection of data by Facebook Pixel occurs exclusively with the consent of the user. This consent can be revoked by the user at any time. The comparison of the data with the data stored by the Company is based on the legitimate interest of the latter in marketing and customer loyalty.

5.4 SNAPCHAT PIXEL

The Company's website uses the "Snapchat Pixel" provided by Snap Inc, 63 Market Street, Venice, CA 90291, USA ("Snapchat"). This service allows tracking of user behavior after viewing or clicking on a Snapchat ad and being redirected to the Company's website. This process is used to evaluate the effectiveness of Snapchat ads for statistical and market research purposes and can help the Company optimize its advertising efforts. The IP address, pixel ID or website domain may also be transmitted to Snapchat to enable optimized measurement of advertising campaigns. This data is stored and processed by Snapchat, thus enabling a connection to the respective user profile and allowing Snapchat to use the data for its own advertising purposes, in accordance with their Privacy Policy. Whenever Snapchat transfers data of EU users outside of the EU, it must ensure that an appropriate transfer mechanism is in place.

5.5 TIKTOK PIXEL

The Company uses on this website the “TikTok pixel” provided by TikTok (for the EU: TikTok Information Technologies UK Limited, Aviation House, 125 Kingsway Holborn, London, WC2B 6NH.). The Company has implemented this code on its website. The code establishes a connection with TikTok servers when users visit the Company’s website in order to monitor their behavior on that website. This process is used to evaluate the effectiveness of TikTok ads for statistical and market research purposes and can help the Company optimize its advertising efforts. Personal data such as IP address, as well as other information such as device ID, device type and operating system may also be transferred to TikTok to enable optimized targeting of advertising campaigns. TikTok processes this data to identify users of the Company’s website and associate their actions with a TikTok user account. TikTok processes this data to show targeted and personalized advertising to its users.

TikTok's Privacy Policy can be accessed here. Where TikTok transfers personal data to countries outside the EEA, it does so in accordance with the European Commission's model contracts for the transfer of personal data to third countries (i.e. standard contractual clauses) pursuant to Commission Directive 2004/915/EC or 2010/87/EU (as applicable) or in line with any approved replacement mechanism under EU law.

5.6 PINTERST TAG

The website uses conversion tracking technology from the social network Pinterest (Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland), which allows the company to display relevant ads and offers on Pinterest to website visitors who have already shown an interest in the website and the content/offers and are members of Pinterest. For this purpose, a so-called Pinterest conversion tracking pixel is integrated into the pages of the Company's website, through which the Company is informed when a user visits the website to which they have been redirected, as well as which parts of the offer they are interested in. This procedure is used to evaluate the effectiveness of Pinterest ads for statistical and market research purposes and can help to optimize the Company's advertising measures. Personal data such as the IP address, as well as other information such as device ID, device type and operating system may also be transferred to Pinterest to enable optimized measurement of advertising campaigns. Since Pinterest is a global service, it may transfer personal data of EEA residents to a country outside the EEA. When Pinterest transfers information from the EEA to a country that does not provide an adequate level of protection, it will only do so under appropriate safeguards, such as standard contractual clauses. Pinterest's privacy policy is available here.

5.7 LINKEDIN INSIGHT TAG

The Company's website uses the "LinkedIn Insight Tag" function of the LinkedIn network. The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. Each time you access one of the pages containing LinkedIn functions, a connection to LinkedIn's servers is established. LinkedIn receives information (containing your IP address) about your visit to the Company's websites. If you click on the LinkedIn "Recommend button" and are logged into your LinkedIn account, LinkedIn will be able to match the information about your visit to the website to your account. As the provider of this website, the Company would like to point out that it has no knowledge of what data is transmitted or how it is used. By using the LinkedIn Insight Tag, the Company can analyze the success of its campaigns on LinkedIn. LinkedIn is certified under the Privacy Shield agreement. (https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active). For years, LinkedIn has relied on overlapping protections under both the Standard Contractual Clauses (SCCs) and the Privacy Shield statutory frameworks for data transfers. Although the European Court of Justice ruling on July 16, 2020 invalidated the use of the Privacy Shield, the SCCs remain in effect and LinkedIn continues to transfer data from the EU, EEA, and Switzerland under them. LinkedIn is also monitoring the ongoing discussions between the U.S. Department of Commerce and the European Commission regarding the replacement of the Privacy Shield framework. Despite its invalidation as a transfer mechanism, LinkedIn has chosen to maintain its U.S. Department of Commerce Privacy Shield certification.

Privacy Policy: https://www.linkedin.com/legal/privacy-policy, Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

6 OBLIGATION TO PROVIDE DATA

To receive a service – make a purchase, create a customer account or sign up for a newsletter – you are required to provide the Data necessary for the Company to fulfill its contractual obligations towards you and to perform its voluntary services and performances. Mandatory Data is marked with (*). Unless you provide such Mandatory Data, the Company will generally not be able to provide its services.

7 USER RIGHTS IN THE CONTEXT OF DATA PROCESSING

The user has the right to:

request information on the type of Personal Data processed (Article 15 GDPR);

rectify or erase your Data (Article 16 GDPR);

limit the processing of your Data (Article 18 GDPR);

withdraw your consent (art. 7 GDPR);

object to the processing of your Data (art. 21 GDPR);

obtain data portability (Art. 20, GDPR)

If you believe that the Company is infringing your rights under the GDPR or national data protection law by processing your data, please contact the Company. This is the best way to address your concerns as quickly as possible. You also have the right to lodge a complaint with the competent supervisory authority (in Italy: www.dsb.gv.at).

8 AUTOMATED DECISION MAKING

The Company does not use automated decision-making processes or automated profiling procedures pursuant to Article 22 GDPR.

9 CONTACTS

In case of requests or doubts, the user can contact the Company directly by e-mail or by post at the following address:

LASH & BROW by Loredana Atanasiu, CF TNS LDN 88L52 Z129D, with registered office in Piazza Drago 2, Jesolo Lido (VE), e-mail address lorena11658@yahoo.com

Information on the processing of personal data (Privacy information for candidates)

Dear candidate! Dear candidate!

In compliance with the information obligations set out in the General Data Protection Regulation (Articles 13 and 14), we hereby inform you about the processing of your personal data in the context of the application procedure.

Purpose and legal basis of data processing

The data provided by you (for example, your CV, references submitted, application questionnaire, interview, etc.) are processed for the purposes of the selection procedure on the basis of your consent.

 By submitting or transmitting your application documents, you therefore consent to the processing of personal data such as name, title, date of birth, residential address, telephone number, e-mail address, education, professional experience, salary expectations and the data and images contained in the application letter, curriculum vitae, references or other documents submitted or transmitted, for the purpose of registering them in a database of candidates of our company. 

Data transmission

Your data will be treated with absolute confidentiality during the application process and will not be transmitted to third parties under any circumstances without your explicit consent.

 The data will be transmitted during the application process only in exceptional cases and with your consent, for example if this is necessary for the preliminary clarification of an intended job promotion. Possible recipients are in particular.

Duration of data retention

The data provided will be stored in our applicant database for the duration of the selection procedure for the purpose of processing your application. In addition, in the event of a refusal in accordance with the provisions of the Equal Treatment Act, the necessary data will generally be retained for a further six months. In the event of legal proceedings, the data relevant to the proceedings will be retained until the legal conclusion of the proceedings. After the expiry of the applicable deadlines, your data will be deleted, unless you give us consent to retain it for a longer period of time for the purpose of saving the data for future job placements.

 Your rights

Under data protection law, you have the following rights: information, correction, deletion, restriction, objection. Please contact us for these rights.

If you believe that the processing of your data violates data protection law or that your data protection rights have been violated in any other way, you have the right to lodge a complaint with the data protection authority.

You can contact us at the following addresses: 

LASH & BROW by Loredana Atanasiu, CF TNS LDN 88L52 Z129D, with registered office in Piazza Drago 2, Jesolo Lido (VE), e-mail address lorena11658@yahoo.com