Information on the processing of personal data.
Effective as of July 26, 2023
PREMISE
This policy takes into account the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and the Italian Data Protection Code (Legislative Decree No. 196 of 30 June 2003). This document has also been drafted in accordance with the Guidelines of the Italian Data Protection Authority (in particular the Guidelines on Anti-Spam issued by the Italian Data Protection Authority on 4 July 2013).
Data Controller: LEANBET srl, a single-member company, with registered office in Bologna, Piazza di Porta Castiglione 14 (40136), certified email address: leanbetsrl@legalmail.it, VAT no. 03931251205, registered with the Bologna Chamber of Commerce, email: info@leanbet.eu.
Website to which this privacy policy refers: https://www.leanbet.eu (Website).
The Data Controller has not appointed a DPO (Data Protection Officer). Therefore, you can send any information requests directly to the Data Controller.
GENERAL INFORMATION
This document describes how the Data Controller processes your personal data provided on the Site.
The main types of processing of your personal data are described below. Specifically, the legal basis for processing is explained, whether providing personal data is mandatory, and the consequences of failure to provide it. To better describe your rights, where necessary, we have specified whether and when a specific processing of personal data is not carried out.
Registration on the Site
The Site does not offer the option to register. Therefore, the Data Controller does not process your personal data for this purpose.
Purchases on the Site
Your personal data will be processed to allow you to make purchases on the Site. If you place an online purchase order, to allow the conclusion of the purchase contract and the correct execution of related transactions (and, where necessary under applicable legislation, to fulfill tax obligations). This processing of personal data also includes the possibility of sending communications (e.g., tracking and order information) via automated tools such as SMS and/or WhatsApp. The legal basis for the processing is the Data Controller's obligation to perform the contract with the data subject or to comply with legal obligations. Regardless of the above (and therefore your consent), the Data Controller may process your data for the purposes of so-called "soft spam," governed by Article 130 of the Privacy Code. This means that, limited to the email address you provide in the context of a purchase through the Site, the Data Controller will process the email address to enable direct offers of similar products/services, unless you object to such processing as set forth in this policy. The legal basis for this processing is the Data Controller's legitimate interest in sending this type of communication. This legitimate interest can be considered equivalent to the data subject's interest in receiving "soft spam" communications. The Data Controller may send emails to remind the user to complete a purchase. The legal basis for this processing is the Data Controller's legitimate interest in sending this type of communication.
Respond to your requests
Your data will be processed to respond to your requests for information. Providing it is optional, but your refusal will make it impossible for the Data Controller to respond to your questions. The legal basis for the processing is the Data Controller's legitimate interest in responding to your requests. This legitimate interest is equivalent to the user's interest in receiving a response to communications sent to the Data Controller.
Generic marketing
With your prior consent, the Data Controller may process the personal data you provide to send you advertising material and/or newsletters relating to its own or third-party products. The legal basis for this processing is your consent. Providing your personal data for this purpose is purely optional. Failure to consent to data processing for marketing purposes will prevent you from receiving advertising material relating to the Data Controller's and/or third-party products/services, as well as preventing the Data Controller from conducting market research, including those aimed at assessing user satisfaction, and from sending you newsletters. These communications will be sent to the email address you provided on the Website.
Profiling
The Data Controller does not perform "profiling" with your personal data. Therefore, it will not send you advertising materials and/or newsletters relating to its own or third-party products of specific interest to you.
Data transfer
The Data Controller does not transfer your personal data to third parties.
Geolocation
The Site does not implement tools for geolocalizing the user's IP address.
Curriculum Vitae
It is not possible to submit resumes via the Site. Therefore, your data will not be processed for these purposes.
Appointment booking
There are no third-party appointment booking systems active on the Site with the Data Controller. Therefore, your data will not be processed for this purpose. However, you can always contact the Data Controller using the contact details provided above.
Communication of personal data
As part of its ordinary activities, the Data Controller may disclose your personal data to certain categories of parties. Article 2 lists the parties to whom the Data Controller discloses your personal data. To facilitate the protection of your rights, Article 2 may specify in certain cases when your data will not be disclosed to third parties.
The "disclosure" of personal data to third parties is different from the "transfer" (regulated in the previous point). In disclosure, the third party to whom the data is disclosed may use it only for the specific purposes described in the relationship with the Data Controller. In the case of transfer, however, the third party becomes the independent Data Controller of the personal data. Furthermore, your consent is always required to disclose your personal data to third parties.
Notwithstanding the foregoing, it is understood that the Data Controller may still use your personal data to properly fulfill the obligations set forth in applicable laws.
SPECIFIC PRIVACY NOTICE
Art. 1 Methods of processing
1.1 Your personal data will be processed primarily using electronic or automated means, using methods and tools that ensure the security and confidentiality of your personal data.
1.2 The information acquired and the methods of processing will be relevant and not excessive in relation to the type of services provided. Your data will also be managed and protected in secure IT environments appropriate to the circumstances.
1.3 The Site does not process "specially identified data." Specially identified data are data that may reveal racial or ethnic origin, religious, philosophical, or other beliefs, political opinions, membership in political parties, trade unions, associations, or organizations of a religious, philosophical, political, or trade union nature, health, or sexual orientation.
1.4 The Site does not process judicial data.
Art. 2 Communication of personal data
The Data Controller may disclose your personal data to certain categories of entities. The following entities may disclose your data to:
The Data Controller may disclose your personal data to all entities (including public authorities) that have access to personal data pursuant to regulatory or administrative provisions.
Your personal data may also be disclosed to all public and/or private entities, natural and/or legal persons (legal, administrative, and tax consulting firms, judicial offices, Chambers of Commerce, Labor Chambers and Offices, etc.), if disclosure is necessary or functional to the proper fulfillment of legal obligations.
The Data Controller employs employees and/or collaborators in any capacity. For the proper functioning of the Website, the Data Controller may disclose your personal data to these employees and/or collaborators.
The Data Controller does not use companies, consultants, or professionals to install, maintain, update, or generally manage the Data Controller's hardware and software. Therefore, your data will not be shared with these categories of parties.
To send its communications, the Data Controller uses external companies tasked with sending this type of communication (CRM platforms). Your personal data (particularly your email address) may therefore be shared with these companies.
The Data Controller does not use external companies to provide customer care services.
Customers' personal data is not shared with couriers or freight forwarders.
The Data Controller reserves the right to modify the above list based on its ordinary operations. Therefore, you are invited to regularly access this privacy policy to check to which parties the Data Controller shares your personal data.
Art. 3 Storage of personal data
3.1 Il presente articolo descrive per quanto tempo il Titolare del Trattamento si riserva il diritto di conservare i Suoi dati personali.
Your personal data will be retained only for the time necessary to ensure the proper provision of the services offered through the Site.
For the purpose of fulfilling the sales contract, the data will be retained for 10 years from the date of receipt of the purchase order. This is to allow the Data Controller to exercise its right of defense and to demonstrate that the contract has been properly performed.
For customer care purposes, the data will be deleted once the customer service has been completed.
For marketing purposes, unless consent is withdrawn prior to this, the data will be retained for 24 months from the date of its provision. After the withdrawal of consent or at the end of the 24-month period, the personal data will be deleted and no longer used for marketing purposes.
As required by Article 2220 of the Italian Civil Code, invoices, as well as all accounting records in general, are retained for a minimum period of ten years from the date of recording, so that they can be presented in the event of an audit.
3.2 Without prejudice to the provisions of Article 3.1, the Data Controller may retain your personal data for the time required by specific regulations, as amended from time to time.
Art. 4 Transfer of personal data
4.1 The Data Controller is based in a country that offers an adequate level of security from a regulatory perspective. If your personal data is transferred to a non-EU country for which the European Commission has expressed an adequacy judgment, the transfer is deemed secure from a regulatory perspective. This Section 4.1 indicates the countries to which your personal data may be transferred and where the European Commission has expressed an adequacy judgment.
We therefore encourage you to regularly review this Section to verify whether your personal data is being transferred to a country with these characteristics.
4.2 Without prejudice to the provisions of Section 4.1, your data may also be transferred to non-EU countries for which the European Commission has not expressed an adequacy judgment. You are therefore encouraged to regularly review this Section 4.2 to verify which of these countries your data may be transferred.
4.3 In this article, the Data Controller indicates the countries in which it may specifically conduct its business. This circumstance may imply the application of the legislation of the relevant country, together with that governing the relationship with the user as indicated in the Introduction.
At the user's request, the Data Controller will apply any more favorable legislation provided by the user's national legislation to the processing of personal data.
Art. 5. Rights of the interested party
The Data Controller informs you that you have the right to:
ask the Data Controller for access to your personal data and to rectify or erase it, limit its processing, or object to its processing, as well as the right to data portability.
withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
lodge a complaint with a supervisory authority.
The above rights may be exercised by submitting a request informally to the contact details indicated in the Introduction.
Art. 6. Amendments and Miscellaneous
The Data Controller reserves the right to make changes to this policy at any time, providing appropriate publicity to Site users and ensuring adequate and comparable protection of personal data. To review any changes, you are invited to consult this policy regularly. In the event of substantial changes to this privacy policy, the Data Controller may also notify you via email.

