• Place your order by December 16 to receive your gifts before Christmas
  • Returns extended to January 15 for orders placed between December 2 and 23

INFORMATION NOTICE ON THE PROCESSING OF PERSONAL DATA PURSUANT TO ARTICLES 13 AND 14 OF EU REGULATION 679/2016 (“GDPR”)

 

Your privacy is extremely important to us, please read this information notice carefully.
We wish to inform you in a complete and transparent manner about the personal data processing that the companies listed in paragraph 1 below will carry out on your personal data provided by you and/or collected in the context of the contacts you will possibly have with us, including for example the following:
• contacting our Customer Service;
• visiting the website www.marni.com (hereinafter the “Site”) and/or the other websites referring to the brand, interacting with our pages on the social networks (e.g., Facebook, Twitter, Instagram, we chat, etc.);
• in the context of Marni’s use of content posted by users (“User Generated Content”).
If you provide personal data on behalf of someone else, you must ensure, in advance, that the interested parties have read this information notice.

1. WHO COLLECTS YOUR PERSONAL DATA

The companies collecting and processing personal data as autonomous data controllers (hereinafter the “Data Controllers” or the “Companies”) or as joint controllers are:
• OTB S.p.A. (“OTB”), with registered office in Italy, Breganze (Vi), Via dell’Industria 2, 36042, telephone +390445306555, email privacy@otb.net; OTB’s Data Protection Officer (“DPO”) can be contacted at dpo@otb.net
• Marni Group S.r.l. (“Marni”), with registered office in Italy, Via Sismondi Gian Carlo 70/B, 20133 Milano, telephone + 390271055555, email privacy@marni.com; the Marni’s Data Protection Officer (“DPO”) can be contacted at dpo@otb.net.
OTB and Marni carry out some activities as joint controllers, taking jointly the decisions regarding the purposes and means of personal data processing. Hereafter, the term “Joint Controllers” means Marni and OTB jointly considered when they process data as Joint Controllers.

To facilitate your understanding of the processing activities carried out by the above-mentioned subjects as Controllers or Joint Controllers, we have prepared this document explaining which processing activities are carried out autonomously by each company.

Please consider that said processing activities are not intended for minors and the Data Controllers do not knowingly collect or solicit personal data from anyone under the age of 18. If you are less than 18 years old, please refrain from provide any personal data. This does not affect the applicable contract law such as the rules on the validity, formation or effect of a contract in relation to a child.

2. WHAT PERSONAL DATA WE PROCESS

Each Company collects different categories of personal data according to the purpose for which it processes them.

Herein below we specify which categories of personal data are collected; in the following paragraph we will explain for what purposes each category of data is processed by each Data Controller or by the Joint Controllers as appropriate (hereinafter also “Personal Data” if processed jointly).
• Biographical Data: name, surname, date of birth, gender;
• Contact Data: address of residence (street, city, province, state, zip code), domicile, email address, telephone number, mobile number;
• Tracking of Newsletters and Actions Data: information relating to the opening of newsletters or links;
• Sales Data: shipping and billing address, method of delivery and payment, name of the credit card holder and expiry date of the card, information requested by the customer service, VAT number and/or tax code, passport number (the passport number will be used only for purposes related to payment where required by a law and within the limits of that law), Global Blue card number;
• Purchase Data: detail of the purchased products (e.g., size, price, discount, model, collection, calculated spending level, abandoned cart, etc.);
• Navigation Data: data relating to browsing behaviour and/or use of the websites of the Data Controllers using, for example, cookies or information relating to the pages that have been visited or searched for or related to the wishlist collected while browsing or when shopping on the online store. As for the use of cookies, please refer to the Cookie Policy available at the following Link
• User Generated Content (e.g., user image) used by Marni.

3. FOR WHAT PURPOSES WE PROCESS YOUR PERSONAL DATA

In this paragraph we further explain for what purposes each category of data is processed by each Data Controller or Joint Controller.

3.1 PURPOSES OF MARNI GROUP S.R.L.

Marni is the company that designs and promotes the Brand’s products “Marni”. It is the company maintaining the contacts with you if you decide to purchase the products through the Site or other websites controlled by Marni or through other methods provided for by Marni. Marni will process your Personal Data for the following purposes.

a. Sales activities and response to other requests made by customers
If you purchase Marni’s products through the e-commerce service on the Site, Marni will process your Biographical Data, Contact Data, Sales Data and Purchase Data to conclude the sale, as well as for all activities strictly connected and related to it, such as delivery, in-store collection or other administrative and accounting obligations. These closely related activities include, in particular, contact in the event of an abandoned shopping cart, carried out close to the eventual abandonment of the cart itself, by sending a service email in order to support you in the eventual conclusion of the order. These data will be requested also in case of purchases performed without registration; in this case the Personal Data will be stored exclusively for the time necessary to complete the purchase activity.

Similarly, Marni may need to process your Biographical Data or Contact Data to respond to any further requests that you may formulate through the Site, in the appropriate sections, or through the Customer Service, through telephone or chat, such as requests for information, assistance, or to be notified by email when a desired product or size becomes available again on the Site, thorough the “Notify Me” functionality.

Legal basis: this processing is based on the performance of a purchase contract to which you are a party; the provision of the Personal Data listed above is necessary for this purpose, since otherwise Marni will not be able to process your request.

b. Marketing
Only with your consent, Marni will process the Biographical Data, Contact Data and Purchase Data for marketing purposes, that is for advertising on social networks to which you are registered or sending advertising or direct sales material, carrying out market research, commercial communication with automated contact methods (e-mail, newsletter, SMS, MMS, online messaging platforms, etc.) and traditional contact methods (mail). With reference to advertising activity on social networks, your email address may be shared, through secure and encrypted transmission mechanisms, with the involved social network, so that the latter can match it with the information available on its platform. In this case, the social media provider will compare the data uploaded by Marni with the data it already holds on to its users, and users who match will be added to or excluded from the target audience (i.e., the "group" of people to whom the advertisement will be shown on the social media platform).

Legal basis: this processing is based on the consent you have given.

You can at any time withdraw your consent to receive the above-mentioned communications by clicking on the appropriate option in each marketing email received, as well as by writing to the address privacy@marni.com, or otherwise by contacting the company at the addresses indicated in paragraph 1.

c. Registration on the Site and use of the services offered
Marni will process your Personal Data in order to allow you to register on the Site and use the services offered. Your data will be stored until you request to delete your profile.
Legal basis: this processing is based on the performance of a contract to which you are a party; the provision of the Personal Data is necessary for this purpose, since otherwise Marni will not be able to allow your registration and offer its services.

d. Repost
Marni will process your User Generated Content (e.g., user image) to carry out the repost activity. Indeed, according to the relevant MARNI User Generated Content Terms and Condition, Marni will also process these data on Marni’s official social channels and/or in promotional activities for Marni’s branded products with its customers, provided that you have previously given your consent.

Legal basis: this processing is based on your consent that will be asked each time Marni will want to repost your User Generated Content.

e. Customer satisfaction
Marni may use your Contact Data to conduct surveys to measure the level of satisfaction (i.e., customer satisfaction) with the service provided (by way of example but not limited to: online post-sales surveys; second hand gold shopping surveys etc.). Please note that in any case the communications made for this purpose will not have an advertising content, or direct sales or will be used for market research or commercial communication.

Legal basis: this processing is based on the legitimate interest of Marni to verify and improve the quality of its services.

f. Other administrative-accounting activities

Marni may also process your Personal Data, in aggregated form, for administrative, accounting and internal statistical analysis for business planning purposes.
Legal basis: this processing is based on the legitimate interest of Marni to improve the quality of its services and business.

g. Aggregate analysis for strategic orientation and Business Intelligence

Marni processes Purchase Data and Navigation Data to perform aggregate strategic orientation and “Business Intelligence” analyses on the data and information processed, considering the entrepreneurial and market need to conduct general analysis and forecasting activities. By developing statistical processing and strategic business models, Marni aims to improve the products and services offered to its customers and measure the return on the company’s investments in organized digital campaigns. This type of analysis is carried out based on aggregated/hashed data, where traceability to individuals is merely incidental, and in any case, it is not conducted within the applications used for this purpose.
Legal basis: this processing is based on Marni’s legitimate interest in evaluating the effectiveness of its business strategies and measuring the level of its investments.

3.2 PURPOSES OF THE JOINT DATA CONTROLLERS (MARNI AND OTB)

Marni and OTB operate as Joint Controllers on the basis of a specific agreement for the purpose indicated below.
a. Customer profiling
With your consent, the Joint Controllers will be entitled to process Biographical Data, Contact Data, Sales Data, the Purchase Data, Tracking of Newsletters Data and Actions Data and the Navigation Data for customer profiling purposes and for business analysis, that is for analysis on your purchase preferences consisting of automated processing of the above-mentioned Personal Data. This processing is aimed at analytically knowing or predicting your purchasing preferences also in order to create customer profiles and customize the commercial offer so that it is more in line with your preferences.

Legal basis: this processing is based on the consent you have given.

You will be entitled at any time to withdraw your consent to be subject to customer profiling by writing to privacy@marni.com or otherwise by contacting the Joint Controllers at the addresses indicated in paragraph 1.

3.3 PURPOSES OF ALL DATA CONTROLLERS OR JOINT DATA CONTROLLERS

Finally, each Data Controller or Joint Controller may need to comply with a specific legal provision to which it is subject or to defend its own right in court.

a. Purposes related to the obligations established by laws or regulations, by decisions/requests of competent authorities or by supervisory and control bodies
Each Data Controller or Joint Controller may process your Personal Data to comply with a legal obligation to which it is subject.

Legal basis: compliance with a legal obligation

The provision of data for this purpose is mandatory because in the absence of data the Data Controller or the Joint Controller will not be in a position to comply with their legal obligations.

b. Defence of rights during judicial, administrative or extra-judicial proceedings and in disputes arising in connection with the services offered
Your Personal Data may be processed by each Data Controller or Joint Controller to defend their rights or take legal action or make claims against you or third parties, including the prevention of fraud.

Legal basis: this processing is based on the legitimate interest pursued by the Data Controller or Joint Controller to protect their rights.

4. WHAT PROCESSING ACTIVITIES WE CARRY OUT IF YOU’RE USING OUR WEBSITE AND YOU NAVIGATE WITHOUT BEING LOGGED IN

The Site is owned by Marni. It is possible to browse the Site without having to actively communicate your Personal Data if you are not logged in. In this case, while browsing the Site, we inform you that the computer systems and software procedures used to operate the Site acquire, during their normal operation, some data whose transmission is implicit in the use of Internet communication protocols.

This is information that is not directly associated with identified users, but which by its very nature could, through processing and association with data held by third parties, allow these users to be identified.

This category of data includes the IP addresses or domain names of the computers used by users who connect to the Site, the addresses in URI (Uniform Resource Identifier) notation of the requested resources, information regarding access, information regarding location, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.), the information regarding the user’s visit including data clickstream of the URL, within and from the Site, the duration of the visit on some pages and the interaction on these pages and other parameters relating to the operating system and the user’s IT environment.
These data are collected through the use of “cookies”. We specifically use browser cookies for various purposes, including cookies strictly necessary for the operation of the Site and the use of services through the appropriate features, and the cookies that are used for personalization, performance/analysis and promotional activities. Our Cookie Policy, available at the following Link, contains more information regarding the use of cookies on the Site, as well as the options for accepting or rejecting them.

The data collected while browsing the Site will be processed to (i) manage the Site and resolve any operating problems, (ii) make sure that the content of the Site is presented in the most effective way for its devices, developing, testing and making improvements to the Site, (iii) as far as possible, to keep the Site safe and secure, (iv) to obtain anonymous statistical information on the use of the Site and to check its correct functioning, (v) identify anomalies and/or abuses in the use of the Site. The data could also be used to ascertain responsibility in case of possible computer crimes committed against the Site or third parties and may be presented to the Judicial Authority, if this makes an explicit request.

5. WHAT HAPPENS IF YOU DO NOT PROVIDE PERSONAL DATA

Some Personal Data that we will indicate you from time to time during the registration or purchase process are necessary for the completion of the purchase contract and for administrative and accounting purposes.

In the description of the purposes in paragraph 3, we have specified when it is necessary to provide Personal Data. Where not expressly indicated as mandatory, therefore, the provision of Personal Data is optional and there will be no consequences if you do not provide them, if not the impossibility for the Data Controllers or Joint Controllers to act as described (for example, the impossibility to carry out marketing activities).

6. HOW AND HOW LONG WE WILL PROCESS PERSONAL DATA

The Personal Data provided to and/or collected by the Data Controllers or the Joint Controllers are processed and stored with automated tools and, in some cases, may be processed and stored on a paper backing. In particular, the Personal Data processed for purposes of marketing and customer profiling will be entered and stored in the CRM systems that allow the processing of Personal Data for these purposes.

The Personal Data will be stored for the time necessary to achieve the purposes for which they were collected. In particular, the following rules will apply:
• data collected to enter into and perform purchase contracts on the Site, including payments: up to the conclusion of administrative and accounting obligations. The billing data will be kept for 10 years from the billing date;
• data linked to the registration on the Site: up to the deletion of the account;
• data related to data subjects’ requests: the data will be stored until the request is satisfied;
• data collected and processed for survey of customer satisfaction will be retained for 30 days, except where the data are needed to obtain further feedback from you; in this case, the data will be retained not longer than what is necessary for manage your feedback;
• if you have provided your consent, the data processed for purposes of marketing and customer profiling will be stored for a period of 7 years (also according to an ad hoc provision provided for by the Italian Supervisory Authority, upon Marni’s request) unless you revoke your consent. In any case, you will not be contacted again for marketing and customer profiling activities 7 years after your last interaction with us or even earlier if you revoke the consent previously given. The events that identify this “interaction” may include, but are not limited to, a purchase, opening an email sent, participation in a survey, contest or event, interaction with Customer Service etc. For completeness, we would like to point out that, at any time, it is possible to review and modify your previously expressed consents through the dedicated function on the personal page (“My Personal Data”).

In any case, for technical reasons, the termination of the processing and the consequent cancellation or irreversible anonymization of the related Personal Data will be definitive within thirty days from the terms indicated above.

In any case, for technical reasons, the termination of the processing and the consequent cancellation or irreversible anonymization of the related Personal Data will be definitive within thirty days from the terms indicated above. With particular reference to the judicial protection of our rights or in case of requests from the authority, the data processed will be stored for the time necessary to process the request or to protect the right.

7. WHERE PERSONAL DATA MAY BE TRANSFERRED

For the purposes indicated above, we may also transfer your Personal Data to third countries, not belonging to the European Union, which may possibly do not guarantee the same level of protection. The transfer to third countries will always take place in accordance with the provisions of the GDPR, adopting any other measures necessary to ensure the security of the Personal Data being transferred. These measures possibly include agreements incorporating the so-called “standard contractual clauses” issued by the European Commission. You can ask for information regarding these third countries and how to obtain a copy of the appropriate safeguards using the following email: privacy@marni.com or the contact details indicated in paragraph 1.

8. WHO WILL PROCESS PERSONAL DATA

Personal Data will be processed by:
• employees and collaborators of the Data Controllers or of the Joint Controllers processing data under the authority of the Data Controllers or of the Joint Controllers;
• employees and collaborators of the Data Processors designated by the Data Controllers or Joint Controllers, including (i) the companies managing the online store and who will be entitled to view, modify and update the Personal Data entered in the CRM systems through which the Data Controllers or the Joint Controllers carry out the processing activities for marketing and customer profiling purposes (ii) the companies managing the storage of the Personal Data of the Data Controllers or Joint Controllers based on agreements or local regulations;
• third parties established in the European Union and also outside the European Union, Data Processors, used by the Data Controllers or Joint Controllers in particular for services of: Personal Data acquisition and data entry, shipping, mailing of promotional material, after sales assistance and customer service, market research, management and maintenance of the CRM systems through which the Data Controllers or Joint Controllers carry out processing activities for marketing and customer profiling purposes and of the other corporate information systems of the Data Controllers or Joint Controllers of the processing. The complete list of Data Processors appointed by the Data Controllers or Joint Controllers can be requested to the following email address privacy@marni.com or writing to the postal addresses indicated above.

Personal Data may also be disclosed to third parties, independent Data Controllers, in particular to freelancers or companies providing legal or tax advice and assistance and to companies managing payments made by debit or credit cards or for fraud prevention and management activities.

Personal Data will not be disseminated in any way.

9. YOUR RIGHTS

Pursuant to Chapter III of the GDPR, you have the right to ask each Data Controller or Joint Controller:
• to access to your Personal Data;
• to receive the copy of the Personal Data you provided us (so-called “data portability”) and to have data transmitted to another controller, if technically possible;
• the rectification of the Personal Data in our possession;
• the erasure of any Personal Data in relation to which we no longer have any legal basis for processing;
• the limitation of the way in which we process your Personal Data, within the limits set by the applicable law data protection law.

Right to object: in addition to the rights listed above, you always have the right to object at any time to the processing of your Personal Data carried out by the Data Controller or Joint Controller for the pursuit of its legitimate interest. You have the right to object to direct marketing, which includes customer profiling. If you prefer that the processing of your Personal Data is carried out solely through traditional contact methods, you can object to the processing of your Personal Data carried out through automated contact methods.

You also have the right to withdraw, in whole or in part, the consent to the processing of Personal Data concerning you for the purpose of sending advertisements or direct selling or for carrying out market research or commercial communication with automated contact methods (e-mail, other remote communication systems via communication networks such as, for instance: SMS, MMS, messaging platforms, etc.) and traditional contact methods (mail).

The exercise of these rights, which can be done through the contact details indicated in paragraph 1, is not subject to formal constraints. In the event that you exercise any of the above-mentioned rights, it will be the responsibility of the Data Controller or Joint Controller that you contacted to verify if you are entitled to exercise the right and to provide you with an answer, normally within a month.

As regards the Joint Controllers relationship, please note that OTB and Marni entered into a specific agreement pursuant to article 26 of the GDPR, an extract of which is available for consultation contacting each of the Joint Controllers using the contact details indicated under paragraph 1.

If you believe that the processing of your Personal Data is carried out in breach of the provisions of the GDPR, you have the right to lodge a complaint with the Supervisory Authority or to start the appropriate legal actions before the competent courts.

To exercise your rights, you can send a request to the Data Controllers or Joint Controllers by writing to the addresses indicated in paragraph 1. The OTB and Marni’s Data Protection Officer can be contacted at the email address dpo@otb.net.

LAST UPDATE: OCTOBER 2024