Prada S.p.A., with registered office in Milan (Italy), the operating holding company of the Prada Group (defined below) and site manager of www.miumiu.com (the “Website”) together with its subsidiary Prada Australia Pty. Limited, with registered office in Sydney (Australia), the company directly operating the selling of products offered on the Website with shipping in Australia (Prada S.p.A. and Prada Australia Pty. Limited are referred together as “PRADA”), recognise the importance of maintaining the confidentiality, integrity and security of your personal data (hereinafter “Personal Data”), and hereby inform you that any Personal Data which you may provide to PRADA through the Website, as well as any Personal Data which you may provide at a Prada Group store, including through its subsidiaries and/or affiliates (collectively the “Prada Group”) will be processed in compliance with current applicable laws on privacy and with any specific local regulations applicable from time to time, including the Privacy Act 1988 (Cth) (“Privacy Act”) and the European General Data Protection Regulation (Regulation (EU) 2016/679 (“GDPR”), together with the principles and general rules of conduct contained in the Code of Ethics adopted by the Prada Group.
1. Type and source of data
During their normal operation, the computer systems and software procedures used to operate our Website collect certain personal data (log files). The transmission of such data is inherent to the use of internet communication protocols. This information is not collected in order to be associated with specific data subjects. However, due to its nature, this information can allow users to be identified by means of its processing and integration with data held by third parties. Such information includes the IP addresses or domain names of the computers you use to visit our Website, URIs (Uniform Resource Identifiers) of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical status code of the server reply (successful, error, etc.) and other parameters concerning the user's operating system and computer environment. This data is used with the sole purpose of obtaining anonymous statistical information on the use of our Website and to guarantee its correct operation.
Personal Data voluntarily provided by the data subject
PRADA collects and processes the Personal Data that you directly and voluntarily provide through our Website when (i) you place online orders, (ii) register to our Website, (iii) and/or you use other functionalities available on the Website (for example: to subscribe to our newsletter, to send a request to our Client Service, to book an appointment in store, to connect or interact with us through social networks, etc). PRADA may also collect and process the Personal Data that you may provide by filling in and signing our customer card (“Customer Card”) at a Prada Group’s store.
If you decide to register to the Website through the social login function, please be informed that PRADA will have access to the Personal Data of your social account (for example, your email address and your public profile) in accordance with the privacy settings of the applicable social media platform. For more information, please refer to the related privacy statements on the applicable social media platform; PRADA does not oversee or control such social media services or user profiles on these platforms and does not establish privacy settings or rules regarding how Personal Data is used on such platforms.
The items of Personal Data collected may include personally identifiable information (title, first and last name, location and date of birth), contact and billing details (postal address, billing address, email, telephone), details of purchases and/or other information regarding you that you may decide to provide during the interactions with our Client Service or with sale staff.
Furthermore, when you voluntarily send an e-mail through our Website and/or to the addresses indicated in our Website, we collect your e-mail address as well as any additional Personal Data contained in your message, so that we can reply to any request.
If you call our Client Service team or our Client Service team contacts you with the details you have provided to us, please note that calls may be recorded for quality assurance and record-keeping purposes.
In addition, we may also obtain information about you as a result of authentication or identity checks (for example, you will be asked to present your identity document when you pick up your purchase in-store). PRADA uses this information to identify you as a customer, to process your order, to deliver products and services and/or to process payments.
Personal Data of minors
You must be at least 16 years old (or older depending on your country or state of residence – 18 years for Australian residents) in order to provide us with Personal Data and at least 18 years old to purchase products from our Website.
PRADA protects the Personal Data of minors in accordance with the relevant national laws and regulations.
If PRADA discovers that it has collected Personal Data about a minor, it will de-activate the minor’s account and try to delete the data as soon as possible.
2. Purpose and legal bases of the processing
Your Personal Data may be processed and used for the following purposes:
(a) to respond to all your requests and to manage your relationship with PRADA.
(b) to fulfil your online purchase orders and perform all management activities connected with it (including administrative management of the contract, delivery of goods, payment processing, management of any claims and litigation, and fraud prevention), and to comply with any applicable legal or regulatory obligations.
(c) to send by email the newsletters and other marketing communication regarding the Prada Group’s products, services, initiatives and events as a result of your subscription to the service.
Furthermore, if you register to the Prada Group customer database (as a result of your registration to the Website, or your signing the Customer Card at a Prada Group store) your Personal Data will be managed by the holding company Prada S.p.A. and shared with all Prada Group stores globally, and may be processed, together with the details of your purchases online and/or in stores, for the following purposes:
(d) to confirm your identity as a registered Prada Group customer and, consequently, to provide a customized customer care service and post-sales assistance and allow you to access exclusive services and benefits reserved for registered members (e.g. preservation of your purchase order history, faster online checkout, simplified procedures for product repair and warranty, commercial discounts, pre-sale and other promotional events, etc.).
(e) profiling: to perform individual or group studies, surveys, statistical analysis and market research with regards to your preferences for MIUMIU and the other brands, products, and services of the Prada Group, so that a personalised service can be offered and cultural and recreational activities may be promoted based on customers’ interests;
(f) marketing: to contact you and/or send you (by post, telephone, e-mail and any other form of electronic communication or digital means including social networks platforms and other instant messaging applications) information and promotions, including commercial information, newsletters, advertising, catalogues and invitations to events concerning MIUMIU and the other brands, products and services of the Prada Group.
The Personal Data processing referred to in subsections (a), (c) and (d) is necessary to provide the service requested by the data subject. The processing referred to subsection (b) is necessary to execute the contract with the data subject or the related pre-contractual measures and to fulfill the connected legal obligations of an administrative and fiscal nature. Further, the data processing referred to in subsections (e) and (f) is based on the prior consent of the data subject.
3. Nature of the provision of personal data
The provision of Personal Data is optional.
However, if you wish to make a purchase order for products offered on our Website, register to the Prada Group customer database, receive information on Prada Group’s products and services, and/or use any other services offered on the Website, you need to fill in all mandatory fields of the relevant forms, otherwise PRADA cannot proceed with the contractual services requested.
The provision of your Personal Data for the purposes of profiling and marketing indicated at letters (e) and (f) of section 2 above is subject to your prior express consent. If you withhold your consent, we may not be able to proceed with the indicated purposes, including the ability to offer you a personalised service, inform you of any initiatives that may interest you and/or send you any other commercial information on products, initiatives and events of the Prada Group.
You may withdraw or modify your consent to the processing of your Personal Data by us at any time, by sending an email to firstname.lastname@example.org, or by using the “unsubscribe” link included in all of our commercial electronic communication, and/or by using any other appropriate procedures which may be made available to you by PRADA (e.g. by logging into your online account).
4. Processing Methods
Your Personal Data will be processed by suitable electronic or automated means and computerised tools, or manually and on hard copy, exclusively for the purposes for which they have been collected and guaranteeing the security and confidentiality of any processed information through the adoption of appropriate measures to prevent the alteration, cancellation, destruction, unauthorized access or processing or actions not in accordance with the purpose of collection. Your Personal Data will be processed only by the Prada Group’s internal staff committed to the confidentiality and duly authorised to do so under their respective job duties.
5. Transfer and disclosure of data
Whenever necessary and/or instrumental to the above purposes, your Personal Data may be processed on behalf of PRADA by other entities engaged by PRADA in the correct and regular pursuit of the described purposes, including:
• Prada Group companies and franchisees that operate Prada Group stores;
• Third parties service providers, consultants and firms providing advisory and/or consulting activities, or performing related services that are instrumental to data processing on behalf of PRADA (e.g. service providers, carriers, IT technicians or any other suppliers appointed by PRADA to carry out and/or manage any promotional campaigns for PRADA’s products and services, etc.).
These third parties will act on behalf of PRADA as data processor and are under a contractual obligation of confidentiality of the personal information.
As PRADA is part of an international network your Personal Data may be transferred abroad, even temporarily, in accordance with applicable legislation, including to locations outside Australia and the European Union (click here to see the jurisdictions in which the Prada Group and its service providers operate), by adopting all appropriate security measures and safeguards to ensure an appropriate level of data protection and security.
Your Personal Data will not be used for third-party advertising purposes or for the promotion of products, services or initiatives by entities other than the Prada Group, nor shall they be disclosed to unknown persons under any circumstances.
Communication of data to the other PRADA Group companies
Please also note that if you register on the Prada Group customer database for the purposes referred to in sections 2, letters (d)-(f), your Personal Data will be automatically visible to, and shared with, all PRADA Group stores globally to provide you with the same level of service around the world. PRADA will take all appropriate and suitable security and confidentiality measures as required by applicable legislation to ensure an adequate standard of data protection, as well as in compliance with article 49, paragraph 1 letter b) of the GDPR, as the data transfer is necessary for the implementation of pre-contractual and contractual measures adopted at the data subject’s request.
You also acknowledge and agree that in certain circumstances we may disclose personal information relating to you to third parties, for example, in order to conform to requirements of law, to comply with any legal process, for the purposes of obtaining legal advice, for the purposes of credit risk reduction, to prevent and detect fraud and/or to protect and defend the rights and property of Prada Group. At all times where we disclose your information for the purposes of credit risk reduction and fraud prevention we will take all steps reasonably necessary to ensure that it remains secure.
6. Retention period
Your Personal Data will be processed and stored for: (a) as long as required to carry out the purposes for which the Personal Data were collected, (b) in accordance with the storage periods provided for by the applicable laws, or (c) until you revoke your consent to the processing/storage of your Personal Data, if applicable. After the conclusion of such period(s), and where there is no legal or business purpose for retaining your Personal Data, it will be automatically and permanently erased or made anonymous.
In particular, regarding the data processing of registered members into Prada Group customer database:
• Personal Data collected for the purposes of customer management to offer personalized services and advantages reserved for registered members, are kept for a period of 7 years from the date of your last interaction with the Prada Group; and
• Purchase details are kept for a period of 7 years from the date of purchase.
7. Data controllers and contacts
For the purposes referred to in Section 2 letters (a) and (b), the Data Controller is:
Prada Australia Pty. Limited
Level 6, 15 Castlereagh Street,
Sydney, NSW 2000, Australia
For the purposes referred to in Section 2 letters (c) to (f), the Data Controller is:
Via Antonio Fogazzaro 28, Milan (Italy)
Group Data Protection Officer
8. Your rights
Please note that you may exercise your rights under the applicable privacy laws, including the Privacy Act and the GDPR, at any time by contacting the Data Controller at the addresses indicated in the previous paragraph.
In particular, under the Privacy Act, you may exercise your right to access your Personal data and the right to seek correction of your Personal Data.
Under the GDPR, you have the right to request information as to whether your Personal Data is being processed and as to the characteristics of the processing, the right to rectification and erasure of your Personal Data, to limitation of the data processing and/or the right to object to the processing, to request the transmission of your Personal Data to another controller, and/or to lodge a complaint with the competent supervisory authority including the Italian Garante per la protezione dei dati personali (www.garanteprivacy.it) or take legal action if you believe there is non-compliance with the provisions of the applicable laws.
You also have the right to withdraw your consent for the processing of your Personal Data by PRADA at any time, without charge. The withdrawal of your consent will not affect the lawfulness of processing based on your consent before its withdrawal.
If you have any complaint about how we have handled your Personal Data, you may contact us at the contact details above. We will investigate your complaint and will use reasonable endeavours to respond to you in writing as soon as possible. If we fail to respond to your complaint within a reasonable time or you are dissatisfied with the response that you receive from us, you may have the right to make a complaint to the Office of the Information Commissioner (Australia).
Last updated: January 13th, 2020