Privacy Policy
INFORMATION NOTICE ON THE PROCESSING OF PERSONAL DATA
(Articles 13 and 14 of Regulation (EU) 2016/679 – GDPR) – Form IS01-18
Introduction
This information notice is intended for users who visit and interact with the Eleveit (Eleveit.it) e-shop (the “E-shop”), through which products can be purchased online. The Data Controller is Mandelli S.r.l., with registered office at Via Tommaso Grossi 5, 20841 Carate Brianza (MB). The E-shop is managed, on behalf of the Data Controller, by B2VIBE S.R.L., with registered office at Via Paradiso 5, 20831 Seregno (MB), Tax Code and VAT no. 14234560960, in the person of its legal representative pro tempore Luigi Cattaneo, which handles the management of sales and transactions carried out in the context of the Eleveit (Eleveit.it) e-shop (for example: order management, sale and delivery of products, management of returns and warranties, and other activities necessary for the sale of products through the e-shop) as a data processor formally appointed and held accountable by the writing company. Please note that Mandelli S.r.l. and B2VIBE S.R.L. have entered into a contract by which they have defined their respective responsibilities regarding compliance with the obligations arising from the European Regulation; adequate information on the essential content of the contract will be made available to you by contacting the Data Controller, whose details are set out below. This Privacy Policy is governed by Regulation (EU) 2016/679 (the “GDPR”) and by Legislative Decree no. 196 of 30 June 2003 (the “Privacy Code”). The GDPR and the Privacy Code ensure that the processing of personal data is carried out with respect for human dignity and for the fundamental rights and freedoms of the individual, with particular reference to confidentiality, personal identity and the right to the protection of personal data.
1. SUBJECT MATTER OF THE PRIVACY POLICY
This Privacy Policy applies to the processing of personal data relating to the use of the platforms, websites, apps, pages and social media profiles attributable to Mandelli S.r.l. and linked to this notice (the “Platforms”). Personal data means information that identifies you personally, such as your name, your location, your photographs and your contact details, or other data that may be linked to such information in order to identify you, directly or indirectly.
2. WHAT PERSONAL DATA WE PROCESS
By way of example: identification data; contact data; billing and delivery data; payment data; transaction data; technical data (IP, logs, browser, device); profile/preference data; usage data; marketing and communications data; cookies and similar technologies; further data provided voluntarily.
Some of the personal data requested on the Platforms, such as your first name and surname, telephone number and email address, may be indicated as “mandatory” [for example, when marked with an (*)] as they are necessary to access the services of the Platforms that you wish to use (for example, if you place an order). Failure to provide the data marked as “mandatory” will make it impossible to provide you with the service. Failure to provide the data marked as “optional”, on the other hand, will have no consequences.
3. HOW WE COLLECT YOUR DATA
(i) Data provided directly by the user (account registration, purchases, support requests, newsletter, applications); (ii) Data received from contracted third parties; (iii) Data collected automatically during browsing (see cookies).
4. HOW WE USE YOUR PERSONAL DATA
Purposes and legal bases: (a) performance of a contract or pre-contractual measures; (b) compliance with legal obligations; (c) consent (e.g. marketing); (d) the Data Controller’s legitimate interest (e.g. security, fraud prevention, service improvement, protection of rights).
5. COMMUNICATION AND DISCLOSURE OF PERSONAL DATA
Data may be communicated to authorised internal parties and to external data processors (e.g. IT suppliers, payment service providers, consultants). Data may be communicated to the competent authorities in the cases provided for by law. No general dissemination of the data is envisaged.
6. TRANSFER OF PERSONAL DATA
Personal data may be transferred to countries outside the EEA. In this case, the Data Controller ensures that personal data is properly protected, by verifying:
– That the European Commission has adopted an adequacy decision in respect of such countries;
– the implementation of additional measures (e.g. standard contractual clauses) for non-EEA countries that require them.
7. DATA STORAGE AND RETENTION PERIOD
Data is retained for as long as is necessary for the stated purposes, in accordance with applicable legislation and taking into account: legal obligations; limitation periods; defensive needs; guidelines of the Authorities. Internal policies define the criteria and timeframes for deletion/anonymisation.
8. YOUR RIGHTS
You may exercise the rights set out in Articles 15 et seq. of the GDPR by contacting the Data Controller at the email address info@mandelli.net. You have the right, at any time, to request access to your personal data (Art. 15), rectification (Art. 16), erasure thereof (Art. 17) and restriction of processing (Art. 18). The Data Controller communicates (Art. 19) any rectifications, erasures or restrictions of processing carried out to each of the recipients to whom the personal data has been disclosed. The Data Controller informs the data subject of those recipients if the data subject so requests.
In the cases provided for, you have the right to the portability of your data (Art. 20), in which case it will be provided to you in a structured, commonly used and machine-readable format. You have the right to object (Art. 21), at any time, to processing based on legitimate interest and, in cases where the legal basis is consent, you have the right to withdraw the consent given without prejudice to the lawfulness of the processing based on consent before its withdrawal.
To stop receiving automated direct marketing communications (email, instant messaging) or to withdraw consent to (non-automated) profiling, we invite you to contact the Data Controller at the address: info@mandelli.net.
If you believe that the processing of personal data carried out by the Data Controller is in breach of the provisions of Regulation (EU) 2016/679, you, as a data subject, have the right to lodge a complaint with the supervisory authority, in particular in the Member State in which you habitually reside or work or in the place where the alleged breach of the regulation occurred (Italian Data Protection Authority, https://www.garanteprivacy.it/), or to bring the matter before the appropriate courts.
9. DATA SECURITY
The Data Controller adopts appropriate technical and organisational measures (e.g. access control, encryption, logging, backups, hardening, training, internal policies) to ensure the confidentiality, integrity and availability of the data, in accordance with Article 32 of the GDPR.
10. COOKIES
Cookies are text files that are placed on your computer and may be used to store information about you. We use cookies to provide you with content in line with your interests and to track your use of the Platforms. You can set your browser to refuse all or some cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some sections of the Platforms may become inaccessible or may not function correctly. For further information on the cookies we use, please consult our Cookie Policy.
11. PROFILING
Any profiling activities (personalisation of offers/communications) are carried out in compliance with Articles 21–22 of the GDPR and the EDPB Guidelines. The user may object or withdraw consent at any time. No solely automated decisions producing legal effects are made unless specific information indicates otherwise.
12. CHILDREN’S PRIVACY
The Platforms are not intended for children under the age of 14. In the event of unauthorised registrations, the Data Controller will delete the account and the associated data as soon as it becomes aware of the matter.
13. LINKS TO THIRD-PARTY SITES
This notice does not apply to third-party sites that may be accessible via links present on the Platforms. Please consult their respective privacy notices.
14. CHANGES TO THE PRIVACY POLICY
The updated version of this notice is published on the Platforms. In the event of significant changes, dedicated communications may be provided.
15. CONTACTS
For clarifications or to exercise your privacy rights:
Data Controller
Email: info@mandelli.net
Postal address: Via Tommaso Grossi 5, 20841 Carate Brianza (MB)
External data processor under Art. 28
Email: privacy@b2vibe.com
Postal address: Via Paradiso 5, 20831 Seregno (MB)





