PRIVACY POLICY AND INFORMATION NOTE ON THE PROCESSING OF PERSONAL DATA (PURSUANT TO ARTICLE 13 OF LEGISLATIVE DECREE NO. 196/2003)

Please read carefully the following information, which applies every time you access, visit or otherwise use the website www.ballerette.com (the "Website"), regardless of whether you buy any products. Please also read the General Terms of Use of the Website, as they contain important additional information on our privacy policy and security systems.

1. Data controller
The data controller for data collected through the Website is Castel S.r.l., a limited liability company whose registered office in Rome, Via Po no. 9, 00198, VAT registration no. IT 12984611009 (hereinafter, "Castel" or the "Data Controller").

2. How and why we process your personal data
Your personal data (i.e., name, contact details, and address, as well as any other information about you which may be derived therefrom, whether directly or indirectly), provided by you and/or collected through "system logs" every time you use the Website - including when you register with the Website, conclude a contract for the purchase of Products on the Website, request information, or simply navigate the Website ", shall be processed by the Data Controller, and/or other persons or entities authorised and appointed by the Data Controller, in accordance with the provisions contained herein and mainly by electronic and computerized means, for the following purposes:

  1. handling your registration with the Website, allowing you to use the services offered on the Website, and carrying out the necessary operations to conclude, manage and execute contracts for the purchase of Products on the Website;
  2. meeting the requests you submit, including with regard to the status of your orders, and pursuing other purposes that essential and/ore closely connected thereto;
  3. fulfilling statutory obligations or complying with instructions issued by the competent authorities;
  4. sending newsletters as well as promotional and information material;
  5. carrying out statistical analysis.

A summary of the specific purposes for which we process your personal data shall be provided, from time to time, in the Information Note prepared pursuant to Article 13 of Legislative Decree 196/2003 and submitted to you every time you provide your personal data. In processing your personal data, Castel conforms to the principle of strict necessity. For this reason we have configured the Website in such a way as to minimise the use of your personal data: accordingly, your data will not be processed when the purposes pursued in single cases can be achieved using anonymous data (such as market surveys to improve services) or other methods that make it possible to identify the party concerned only if needed or at the request of public authorities and police forces.

3. Voluntary or compulsory submission of personal data
The submission of personal data is compulsory for the purposes specified in subsections 2.1, 2.2 and 2.3 above: in those cases, if you refuse to provide your personal data, we will be unable to meet your requests or process your purchase orders.

With regard to the purposes referred to in subsection 2.4 above, whenever we collect data or send you a written communication in order to achieve those purposes, you will have the opportunity to request that we no longer send you said communications, by exercising your rights as specified in section 5 below or as indicated in each communication, in accordance with Article 130(4) of Legislative Decree 196/2003.

Please note that all registration forms contain both compulsory fields (marked by an asterisk [*]) and non-compulsory ones. If you refuse to provide the data marked as compulsory, we will be unable to pursue the main objective of a specific data-gathering task, such as the conclusion of a contract to purchase products from the Website. On the other hand, the provision to Castel of additional data, other than those marked as essential, is voluntary and does not entail any consequences as regards the main purpose of data-gathering.

4. Data processors
Your personal data will not be communicated to third parties without your express consent, except in cases where the law does not require us to obtain your consent or, quite the opposite, imposes on you an obligation to provide it; in those cases, we may make your personal data available to third parties, who will process them solely for the purposes specified in this document (e.g., to execute a purchase contract or fulfil obligations related to the payment of Products, or upon request from law enforcement agencies or the courts).

In order to provide you with the goods and services you request, we may transmit your personal data to third parties who are responsible for and tasked with processing that data; these third parties include B2X S.r.l., a limited liability company whose registered office is in Rome, Via Tiburtina no. 1236, 00131 Rome, VAT no. IT 11020591001 (the "Data Processor"), appointed as data processor pursuant to Article 29 of Legislative Decree 196/2003.

In any case, your personal information shall not be [publicly"] disclosed: the Data Controller and Data Processor will store it in servers/databases located within the European Union.

5. Your rights
Pursuant to Article 7 of Legislative Decree 196/2003, you have the right to obtain confirmation from the Data Controller or Data Processor as to whether your personal data is being processed, as well as to have communicated to you in an intelligible form the personal data that is being processed.

You also have the right to obtain information on: the source of that personal data; the purpose of the processing and the methods used; the rationale applied in case of electronic processing; the details of the data controller and data processors; the entities or categories of entities to which the personal data may be communicated, or which may access them in their in their capacity, for instance, as data processors.

You will find all of the above information in this document. In addition, you are entitled to the following: o updates, corrections or additions to your personal data; o the erasure, anonymisation or block of personal data processed unlawfully, including data whose retention is unnecessary for the purposes for which they have been collected or subsequently processed; o a certification to the effect that the above operations have been notified, including with regard to their contents, to the entities to which the data have been communicated or disseminated, except where this requirement proves impossible or involves an effort that is manifestly disproportionate with respect to the right that must be protected.

Moreover, you are entitled to object, in whole or in part o on legitimate grounds, to the processing of your personal data, despite their relevance to the purpose of data collection; o to the processing of your personal data, where it is carried out for advertising or direct marketing purposes or in order to carry out market or commercial communication surveys You may exercise your rights freely and at any time, by submitting a written request to the Data Controller or Data Processor; the request, as well as any notices regarding the modification or update of your personal data, must be sent at the following address: customer.care@ballerette.com.

Please note that the applicable regulation on the protection of personal data allows the data processor, without your prior consent, to use your data for direct marketing activities related to products similar to those that you have already purchased, provided that you do not object to the use of your e-mail address for said purposes. As a consequence, with regard to the processing of personal data for the purposes specified above, you have the right to object to the processing of your personal data whenever you receive a written communication connected to the aforementioned activities.

You may exercise this right by following the instructions contained in the communication itself. In addition to all of the above, we would like to inform you that you can view, modify, and delete your personal data at any time by accessing your account (if you are a registered user) on our Website, as well as to grant or revoke your consent to data processing.

Moreover, you may request to delete your account sending an email to customer.care@ballerette.com.

6. Our privacy policy in brief
The principles on which our privacy policy is based are as follows o to process data exclusively for the purposes and according to the methods illustrated in the information note presented when they are collected;

o to use data for ends other than those for which the data have specifically been provided, but only with the express consent of the user

o to make the data available to other companies only for purposes connected to the provision of requested services and if said companies are appointed as data processors; not to communicate, sell or transfer data to third parties for further processing without informing users in advance and having obtained their consent o to respond to any requests for the deletion, modification and integration of personal data, or to objections to the processing of data for commercial and advertising purposes;

o to ensure the correct and lawful management of data, protecting the privacy of users, and to adopt appropriate security measures to protect the confidentiality, integrity and availability of the data submitted by users

7. Further information on the processing of personal data
The Data Controller may find itself in the position to process the personal data of third parties after having received them directly by its users, for instance when the person paying for a given product is not the recipient of that product, or when a user wishes to tell a friend about the Website or a given product. In these cases, the user remains responsible for obtaining the consent of the person to whom the data refer prior to communicating them to the Data Controller, as well as for informing that person about this Privacy Section, since the user will be the only person liable for communicating data and information regarding third parties without the latter having expressed their consent, or for the unlawful use, if any, of the data and Website by said third parties. In any case, please note that consent from third parties is not required when their data are communicated solely in order to conclude a contract with Castel for their own benefit. The Data Controller reserves the right to delete one or more accounts and all corresponding data in case of behaviour that is unlawful, harmful to the reputation of Castel and/or its products or those of third parties, or in any case behaviour or contents that are offensive or promote unlawful or defamatory activities or are pornographic, incite violence or promote discrimination on grounds of race, gender, religion and sexual orientation

8. Cookies
Our Website uses automatic systems for the gathering of data that not directly provided by the user, such as cookies.

A cookie is a software device that is transmitted to the user's hard disk; it does not contain intelligible information, but makes it possible to associate the user with the personal information he or she enters on the Website.

The personal information associated to cookies is kept on our server, and no one can access the data contained therein.

Thanks to cookies, we collect information to improve our services and our Website based on the specific needs and preferences of our customers and users. The Website may also Google Analytics, a web analysis service supplied by Google, Inc. ("Google"). Google Analytics uses cookies. The information generated by cookies regarding your use of the Website (including your IP address) will be transmitted to and stored in Google"s servers in the United States. Google will use this information with a view to tracing and examining your use of the website, compiling reports on website activities for website operators and providing other services regarding website activities and Internet use. Google may also transfer this information to third parties if that is required by the law, or when said third parties process this information on behalf of Google. Google will not associate your IP address with any other information in Google's possession. By using this Website, you agree to the processing of your data by Google in the manner and for the purposes specified above. Some Internet browsers allow you to delete cookies after each session, an option which ensures better protection to the privacy of Internet users. This basically means that you can disable the cookies used by most websites; moreover, you can delete cookies after each browsing session. The acceptance of automatic data-gathering procedures and of the use of cookies is required in order to use the Website and its services, including the purchase of products. If you have activated the cookie deletion procedure, we cannot guarantee that you will be able to display all our web pages or access all our services, such as saving and viewing the products you choose during your online purchases.

9. Security measures
We take adequate security measures in order to minimise the risks of destruction or loss - including accidental loss - of data, as well as any access or processing that is unlawful or does not comply with the purposes of data-gathering herein specified. However, we cannot guarantee that the security measures adopted to protect the Website and the transmission of data on the Website eliminate all risks of unauthorised access or data dispersion from the devices of our users. Therefore, we encourage you to check that your computer is equipped with adequate software for the protection of online data transmission, both incoming and outgoing (such as up-to-date antivirus systems) and that your Internet Service Provider has taken suitable measures for the security of online data transmission (such as firewalls and anti-spam filters)

10. Payments
In order to pay by credit card, you must enter your card details on the Website (card number, card holder name, expiry date, security code), which will be transmitted to the payment service provider. The latter acts as an independent data controller, without sharing any information with Castel"s server, which thus will not process your credit card details. Your data will be transmitted in encrypted form, in accordance with the security requirements set out in the ISO 27001 certification. The payment service provider uses the SSL (Secure Sockets Layer) Protocol. This will ensure maximum protection of your data thanks to SSL encryption, a protocol developed for the transmission of documents and/or personal information via the Internet. From our Website, you will be able to save your credit card details for future purchases. However, your data will be stored directly by the payment service provider, while Castel will only save the last four digits of your credit card number, and this solely in order to prevent fraudulent online payments.

11. Links to other websites
The Website may contain hypertext links to third-party websites that are not connected in any way to Castel. Castel does not control or monitor said websites and their contents. As a consequence, Castel shall not be held responsible for third-party websites, their contents, and their terms and conditions of use, including with regard to privacy and the processing of personal data while surfing the Web. Therefore, we encourage you to exercise prudence when accessing third-party websites, whether through the links on our Website or otherwise, and to carefully read their conditions of use and privacy policies. You should keep in mind that the Information Note on the processing of personal data on our Website does not apply to third-party websites. Our Website may provide links to these websites merely as a way to help users in their online searches, facilitate their experience on the Web and, more generally, to make it easier to surf to other websites. The presence of said links on the Website does not indicate any recommendation or encouragement on the part of Castel to access and use the websites, nor does it indicate any endorsement or guarantee as regards their contents and/or the services or goods offered therein. Contacts For further information, please send us an e-mail at customer.care@ballerette.com

12. Applicable Law
Our Privacy Policy is governed by Italian law, in particular by Legislative Decree no. 196 of 30 June 2003, also known as Personal Data Protection Code.

13. Amendments and updates
Castel reserves the right to amend or update, in full or in part, the Privacy section of the Website, to take into account any changes in the laws and regulations on this subject, which protect the rights of our website users, as well as for other reasons. Such amendments and updates shall be effective and binding upon publication on the Website. We therefore suggest that you regularly visit this section of the Website to make sure you are well acquainted with the latest version of applicable terms and of the Information Note on the processing of personal data.