Privacy notice

Under this Privacy Notice, we, EyeMed Vision Care Europe, acting as a ‘data controller’, inform you what personal data of yours we collect when you visit our website (“Site”) or use our services, why we collect it, and what we do with it. Your personal data means any information relating to you, in particular your name and contact details such as your home address, your telephone number or your email address.

Please take the time to read this Privacy Notice carefully, it is very important that you fully understand how we are processing your personal data and how we are protecting your privacy.

Our contact details are: EyeMed Vision Care Europe, Piazzale Luigi Cadorna n. 3 Milano Italia

If you have any question regarding our use of your personal data, you can of course contact our Data Protection Officer at <privacy@luxottica.it>

WHERE AND WHAT PERSONAL DATA WE COLLECT

The personal data we collect depends on the point of contact through which you interact with us, as well as the purposes of this interaction as described in this Privacy Notice and are also limited to those which are relevant and appropriate for this interaction.

We use different methods and various sources to collect data from and about you.

Data we collect when you visit and browse our website

  • Provided directly by you: when you contact us for request, feedback or complaint through our contact form or at any other our contact points.
  • Using automatic tracking systems: we use some technologies (e.g., cookies and automatic tracking systems) that automatically collect certain items of information relating to the way in which you utilize the Site. For further information on the use of personal data collected through automatic tracking systems, please read carefully our Cookie Policy available here.
  • From other sources: we may obtain information about you from other sources, such as data analytics providers, or publicity available sources. We create also information based on our analysis of the information we have collected from you.

Provision of your personal data is not required if you only want to visit our Site; only certain navigation information will be collected and processed according to our Cookie Policy..

Data we collect when you contact us.

In case of any request or contact interaction with us, you may provide us with personal data, and we thank you for providing us with complete and accurate data, and also to inform us if your data needs to be updated. If you do not provide us with complete and accurate data, or if you do not inform us that your data needs to be updated, we may not be able to provide you with the services you requested.

We collect the following categories of your personal data:

  • Identification data: including your name and surname, country of residence, e-mail address, and when applicable e.g. because you contact us thought those channels or we need to follow up your request, feedback or complaint by post or phone, postal address and /or phone number.
  • Other information, including data related to your browsing on our website, such as the pages that you accessed, the date and time you accessed to these pages, your search queries, information on your device (hardware model, operating system version, unique device identifiers, Internet protocol address, hardware settings, browser type, browser language), the date and time of your request and referral URL and any other information as described in our Cookie Policy available here..
  • Other information: any information that you may include in your request, feedback or complaint included in the contact form or provided to us through any of our other contact points.

HOW WE USE PERSONAL DATA WE COLLECT

We only use your personal data within the limits authorized by the laws and regulations. Sometimes, we shall use your personal data because the laws and regulations require us to do so. In any case, we do not make any automated decisions solely on automatic processing which may produce legal effects concerning you, or similarly significantly affect you.

We use your personal data for the following purposes:

  • We use your identification data to enable you (i) to contact us via the website, (ii) to make any other request you may have, (iii) to exercise or defend legal claims in court proceedings or in administrative or out-of-court procedures relating to our rights, of our group companies and/or of our representatives, shareholders, officers and directors in relation to your use of the Site. Such a process is based either on a contract executed between us or based on our legitimate interest.
  • We use your IT data (i) to ensure the technical management of the Site (including solving technical issues, ensuring technical security, improvement), (ii) for analytics and other statistical purposes. Such a process is based on our legitimate interest in case of technical cookies or your acceptance of our use of other cookies as described in our Cookies Policy available here.

HOW LONG WE KEEP PERSONAL DATA WE COLLECT

The period for which we store your personal data is shown in the table below:

Category of data

Retention period

Identification data- and Other information

Up to 5 years

IT data

13 months from collection


Unless otherwise require by statutory retention laws.

PERSONAL DATA WE SHARE

We inform you that we may share your personal data with:

  • Others companies of the EyeMed Vision Care Europe Group, for our internal business purposes;
  • Service providers

Companies, organizations, public authorities or individuals outside of the EyeMed Vision Care Europe Group (e.g. hosting providers, market and analyst service providers, database management and maintenance services).

Companies and other organizations that process your personal data on our behalf are expressly appointed as Data Processor and act as a data processor in accordance with the instructions received from us, by virtue of a specific agreement in place per Article 28 of the GDPR, which sets out its obligations and guarantees the implementation of appropriate technical and organizational measures to respect the applicable legislation and the protection of your rights.

We require that any such third-party provider is subject to strict control and implements appropriate guarantees of security and confidentiality of your personal data.

  • Sale or merger

We may also disclose your personal data if we sell, buy, merge with, are acquired by, or partner with other companies or businesses, or sell some or all of our assets. In such transactions, your personal data may be among the transferred assets.

We may share all of the information we collect in connection with a substantial corporate transaction, such as the sale of a website, a merger, consolidation, asset sale, or in the unlikely event of bankruptcy.

  • Legal process

We may disclose your personal data to any authority, court, administrative body, or other authorised third party (including, without limitation, counsel), where the disclosure of personal data is required by law, regulation or court order or where such disclosure is necessary for the protection and defence of our rights.

Some of these recipients of the data may be located in countries outside the European Union/European Economic Area.

For recipients located in the countries indicated at the following link (https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en ), the European Commission has decided that this country ensures an adequate level of protection by reason of its domestic law or of the international commitments it has entered to.

For recipients located outside the abovementioned countries, there is no adequacy decision by the European Commission; this means that the level of data protection in such country is not comparable with the level of data protection in the European Union. Therefore, we use as an appropriate safeguard to secure your personal data such as the EU Standard Contractual Clauses.

HOW WE PROTECT PERSONAL DATA

We have measures in place to protect your personal data against unauthorized access, use, or disclosure, including without limitation:

  • We implement and maintain sophisticated technical measures to ensure that your personal data is recorded and processed in complete confidentiality and security.
  • We implement and maintain appropriate restrictions on access to your personal data, and monitoring of the access, use, and transfer of personal data.
  • All of our employees who have access to your personal data are required to enter into non-disclosure or similar agreements, which imposes obligations on them to comply with our data privacy and confidentiality requirements.
  • We require any business partners and third party service providers with whom we may share your personal data to comply with any applicable data privacy and confidentiality requirements.
  • We provide data privacy training on a regular basis to our employees and third parties who have access to personal data.

WHAT RIGHTS YOU HAVE

Under applicable data protection laws and regulations, you have right:

  • Of access to, rectification of, and/or erasure of your personal data;
  • To restrict or object to its processing;
  • To tell us that you do not wish to receive marketing information;
  • In some circumstances, to require certain of your personal data to be transferred to you or a third party;
  • To the extent our processing of your personal data is based upon your consent, to withdraw your consent, without affecting the lawfulness of our processing based on your consent before its withdrawal

We are committed to enable you exercising your rights: to do so, you can contact us at the details set out at the beginning of this Privacy Notice. Please provide us with the following information, so that we can take your request with all due consideration:

  • Your name and surname, and a copy of your identity card;
  • Your specific petition (in other words, what rights you want to exercise); and
  • The date of the application and your signature (if you sent your application by postal mail).

If you do not get satisfaction by contacting us, you can also lodge a complaint about our processing of your personal data with the relevant data protection competent supervisory authority (in Italy, Garante per la protezione dei dati personali).

In order to exercise your rights, please contact:

privacy@luxottica.it

CHANGES TO THIS PRIVACY NOTICE

We regularly review our compliance with our Privacy Notice, in particular to make it compliant with new laws and regulations regarding data protection. But, even if this Privacy Notice may change from time to time, we will not reduce your rights under this Privacy Notice without your explicit consent.