1. Type and source of Data
During their normal operation, the computer systems and software procedures used to operate our Website collect certain personal data (log files). The transmission of such data is inherent to the use of internet communication protocols. This information is not collected in order to be associated to specific data subjects. However, due to its nature, this information can allow users to be identified by means of their processing and integration with data held by third parties. Such information includes the IP addresses or domain names of the computers you use to visit our Website, URIs (Uniform Resource Identifiers) of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical status code of the server reply (successful, error, etc.) and other parameters concerning the user's operating system and computer environment. This data is used with the sole purpose of obtaining anonymous statistical information on the use of our Website and to guarantee its correct operation.
Personal Data voluntarily provided by the data subject
PRADA collects and processes the Personal Data that you directly and voluntarily provide through our Website when you place online orders and/or register to our Website and/or subscribe to our newsletter and/or contact our Customer Service. PRADA also collects and processes the Personal Data that you may provide by filling in our Customer Card at our stores.
The items of data collected include, for example, your first and last name, title, date and place of birth, postal address, email address, landline and mobile phone numbers, and shipping and billing information (“Personal Data”).
Furthermore, when you voluntarily send an e-mail through our Website and/or to the addresses indicated in our Website, we collect your e-mail address so that we can reply to any request, as well as any additional Personal Data contained in your message.
If you call our Client Service team or our Client Service team contacts you with the details you have provided to us, please note that calls may be recorded for quality assurance and record-keeping purposes and stored in the data centre located in the European Union.
In addition, we may also obtain information about you as a result of authentication or identity checks (for example, you will be asked to present your identity document when you pick up your purchase in-store). We use this information to identify you as a customer, to process your order, to deliver products and services, to process payments.
Your credit card data (including credit card numbers and other payment information) are provided to our payment services providers who process payment details further. PRADA does not store or maintain your credit card data or use it directly.
2. Purpose of the processing
Your Personal Data may be processed based on the necessity for the provision of the services for the following purposes:
• (a) to respond to all your requests and to manage your relationship with PRADA;
• (b) to fulfil your online purchase orders and perform all management activities connected with it (including administrative management of the contract, delivery of goods, payment processing, management of any claims and litigation, and fraud prevention), and to comply with any applicable legal or regulatory obligations.
Furthermore, subject to your prior consent, your Personal Data will be included in the Prada Group customer data base, through a Customer Relationship Management System managed by PRADA S.p.A., and processed together with the details of your purchases for the following purposes:
• (c) profiling: to perform individual or group studies, surveys, statistical and/or market researches on your preferences with regards to our products, so that we can offer you a personalised service and promote cultural and recreational activities that may interest you;
• (d) marketing: to contact you and/or send you (by post, telephone, e-mail and any other form of electronic communication or digital means including social network platforms and other instant messaging applications) information and promotions, including commercial information, newsletters, direct marketing material, advertising material, catalogues and invitations to events related to the Prada Group’s products and services.
For the purposes of data processing referred to at letters (c) and (d), your Personal Data will be provided to all Prada Group’s stores globally to provide a global customer service.
3. Processing Methods
In order to prevent the loss, theft, leak, falsification, and destruction of your Personal Data, we have implemented reasonable technical and managerial security measures required under the current applicable laws including the Personal Data (Privacy) Ordinance (Cap. 486 of the laws of Hong Kong), and the European Regulation (EU) 2016/679 on personal data protection. In particular, your Personal Data will be processed by suitable electronic or automated means and computerised tools, or manually and on hard copy, exclusively for the purposes for which they have been collected and guaranteeing the security and confidentiality of any processed information. Your Personal Data will be processed only by the Prada Group’s internal staff duly authorised to do so under their respective job duties. Your Personal Data may also be processed by third parties to the extent necessary and/or instrumental for the above purposes. These third parties will act on behalf of PRADA as data processors (e.g. service providers, carriers, IT technicians or any other suppliers appointed by PRADA to carry out and/or manage any promotional campaigns for PRADA’s products and services, etc.).
Please also note that if you consent to the processing of your Personal Data for the purposes referred to under letters (c) and (d) of paragraph 2 above, your data will be automatically visible to, and shared with, all Prada Group stores, and PRADA will take all appropriate security and confidentially measures required by applicable legislation. confidentially measures required by applicable legislation.
4. Nature of the provision of personal data
The provision of your Personal Data is optional.
However, if you wish to make a purchase order for products offered on our Website, and/or receive information on Prada Group’s products and services, and/or contact our Customer Service and/or use any other services offered by the Prada Group, you need to fill in all mandatory fields of the relevant forms.
The processing of your Personal Data for the purposes indicated at letters (c) and (d) of paragraph 2 above is subject to your prior express consent. If you withhold your consent, we may not be able to offer you a personalised service and inform you of any initiatives that may interest you and/or send you any other commercial information on products, initiatives and events of the Prada Group.
You may withdraw your consent to the processing of your Personal Data by us at any time, by writing to Prada S.p.A., Via A. Fogazzaro 28, 20135 Milan (Italy), by sending an e-mail at email@example.com, or by using the “unsubscribe” link included in all of our commercial electronic communications, and/or by using any other appropriate procedures which may be made available to you.
5. Transfer and disclosure of data
Whenever necessary and/or instrumental to the above purposes, your Personal Data may be processed on behalf of PRADA by other entities acting as data processor, including:
• Prada Group companies and franchisees that operate Prada Group stores;
• companies, consultants and firms providing advisory and/or consulting activities, or performing related services that are instrumental to data processing on behalf of PRADA (“Service Providers”).
As PRADA is part of an international network and uses global services your Personal Data may be transferred abroad in accordance with applicable legislation, including to countries outside Hong Kong and the European Union, where PRADA pursues its interests, by adopting all appropriate security measures and safeguards to ensure an appropriate level of data security.
The Personal Data transferred to the Service Providers will be retained only to the extent necessary for the purposes of the service provided and to meet any regulatory requirements in accordance with any applicable laws.
Your Personal Data will not be used for third-party advertising purposes or for the promotion of products, services or initiatives by entities other than the Prada Group, nor shall they be disclosed to unknown persons under any circumstances.
6. Retention period
Your personal data will be processed and stored for as long as required for the purposes for which they were collected, and in accordance with the storage periods provided for by the applicable laws, or until you revoke your consent to the processing, if applicable. After such period, your Personal Data will be automatically and permanently erased or made anonymous.
7. Data controllers
For the purpose of managing and executing your online purchase orders referred to at letters (a) and (b), of the paragraph 2 above, the Data Controller is Prada Asia Pacific Limited. Please contact the Data Controller by writing to Prada Asia Pacific Limited at Rooms 3601-3606, 3609-10, 36/F, Gloucester Tower, The Landmark, 11 Pedder Street, Central, Hong Kong, or sending an e-mail to firstname.lastname@example.org.
For the other purposes of data processing referred to at letters (c) and (d) of the paragraph 2 above, the Data Controller is Prada S.p.A., which will process your Personal Data in accordance with current European privacy laws (Regulation (EU) 2016/679 – “GPDR”). Please contact the Data Controller or Data Protection Officer (“DPO”) by writing to Prada S.p.A., Via Antonio Fogazzaro 28, Milan (Italy), or by sending an e-mail to email@example.com.
8. Rights of the data subject
Please note that you, or your legal guardian, may exercise the rights under the applicable privacy laws included those of the Articles 15 to 21 GDPR, and specifically the right to request information as to whether your Personal Data is being processed and as to the characteristics of the processing, the right to rectification and erasure of your Personal Data, the right to object to the processing and/or the right to have those Personal Data transmitted to another controller.
You also have the right to withdraw your consent at any time, without charge. The withdrawal of your consent will not affect the lawfulness of processing based on your consent before its withdrawal. You may lodge a complaint with the competent supervisory authority including with the Italian authority (Autorità garante per la protezione dei dati personali) at Piazza di Montecitorio no. 121, 00186, Rome (Italy).
Last updated: 8 June 2018