INFORMATION NOTICE ON THE PROCESSING OF PERSONAL DATA.
Before you provide us with your personal data, in accordance with the General Data Protection Regulation (EC) 2016/679 (hereafter the “Regulation” or “GDPR”), pursuant to Legislative Decree no. 196 of 30 June 2003, as updated by Leg. Decree no. 101 of 10 August 2018, the objective of which is to protect the fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data, it is important that you read the information provided herein aimed at guaranteeing that the processing of your person data1 is carried out in accordance with your fundamental rights and freedoms.
Fabbrica d’Armi Pietro Beretta S.p.A. (hereinafter, "Beretta" or "we" or “Data Controller”) is committed to protecting your personal data and strives to provide you with the best possible experience so that you can enjoy our service today and in the future. The following privacy Information Notice (hereinafter the Information Notice”), provided pursuant to art. 13 of the Regulation, describes how we collect, use, store or otherwise process (jointly "process") the personal data of the My Beretta Community2 users3 (hereinafter “Community”)
1.Introduction 2
2.Data Controller 2
3.Data Protection Officer (DPO) 2
4.Purpose of the processing and legal basis 2
5.Personal data processed and methods of processing personal data. 3
6.Processing of anonymised data 6
7.Nature of the conferral of personal data and consequences of refusals 6
8.Communication and dissemination of personal data 6
9.Minors 6
10.Personal data retention period 6
11.Data subject rights 7
12.Third party websites and services 7
13.Corporate aspects 7
- Introduction
The Community allows users to enjoy various exclusive services, and access, browse and download dedicated content (hereinafter jointly the “My Beretta Services”). For further details regarding how the Community operates and the terms and conditions of regulating the use of the same, please read our Terms & Conditions.
- Data Controller
The data controller4 is Fabbrica d’Armi Pietro Beretta S.p.A. (Tax Code and VAT no. IT01541040174), with registered office in Gardone Val Trompia (BS), via Pietro Beretta, 18. The Data Controller can be contacted at the following email: privacy@beretta.com.
- Data Protection Officer (DPO)
Beretta has designated a Data Protection Officer (DPO) who can be contacted at the following email address: dpo.fda@beretta.com
- Purpose of the processing and legal basis
Please find below more details about the purposes for which we process your personal information.
- Scope and purpose:
- Community registration and correct provision of My Beretta services, to:
- enable user profile management
- enable the user to update, amend and manage his or her profile
- allow the user to take advantage of the My Beretta Services
- allow us to communicate with the user regarding the use of the My Beretta services
- enable us to perform all activities necessary or useful for the continuous improvement of the My Beretta Services
- Compliance with all legal obligations
- Sending of information and promotional communications to improve the user experience (Direct Marketing)
- Sending information notices, promotional communications and customised recommendations according to the tastes and preferences expressed by the user in the Community as well as the My Beretta services used (Direct Profile Marketing).
- Troubleshooting, technical support, and Community support
- Prevent threats to the integrity, availability and confidentiality of personal data, combat spam and other malware and, more generally, detect, prevent, and mitigate security risks (Information security)
- Prevention of fraud and, more generally, access to the My Beretta Services provided by the Community by persons intending to compromise its security (Fraud prevention)
- Community registration and correct provision of My Beretta services, to:
- Legal Basis:
- The processing carried out for this purpose is mandatory to execute the contractual obligations. The Data Controller has identified the legal basis of the processing pursuant to art.6 (b) of the Regulation
- The processing carried out for this purpose is mandatory to execute all obligations foreseen by the laws in force. The Data Controller has identified the legal basis of the processing pursuant to art.6 (c) of the Regulation
- The processing carried out for these purposes is performed pursuant to your prior, specific and informed consent for each of the listed purposes, in accordance with Article 6(a) of the Regulation. You are entitled to revoke each individual consent at any moment in time by accessing the “My Profile” section of the Community
- The processing carried out for these purposes is necessary for the purposes of the legitimate interest of the Data Controller, in accordance with Article 6 (f) of the Regulation
- Personal data processed and methods of processing personal data.
The processing of personal data is carried out using electronic or automated means and transmitted via electronic network systems. The Data Controller implements all appropriate technical and organisational measures to guarantee an adequate level of security in relation to the type of data being processed.
Below are further details on the personal data undergoing processing.
- Community registration and user profile management
- Mandatory: Name, surname, country, date of birth and email address
- Optional: Phone number
- Correct provision and use of the My Beretta Services
- Maintenance: Booking of firearm maintenance packages or specific interventions at a selected gun shop
- Mandatory: Name, surname, email address, telephone number, firearm serial number, selected gun shop for intervention
- Warranty registration: Registration of the warranty for the purchased firearm and activation of the warranty extension to 3 years (2 + 1)
- Mandatory: Name, surname, date of birth, e-mail, country of residence, serial number, gun shop from where the firearm was purchased, date of purchase, purchase document
- Optional: purchase price
- Support: Opening a support request with Beretta
- Mandatory: Name, surname, firearm serial number, description of the problems encountered
- Optional: Any photos, videos or documents that best describe the case in question and the need for support
- Content downloads: Content download pages (e.g. catalogues, manuals) and video tutorials
- Dealer Locator: Dealer locator service with geographic map location
- Firearm configurator: Save your configured firearm in the Community section
- Mandatory: Specifications of the user’s firearm configuration
- Mandatory: Specifications of the user’s firearm configuration
- Beretta E-Store processing of personal data necessary to receive and manage orders placed by the user on the Beretta e-commerce site www.estore.beretta.com. For further details on the personal data collected and processed, the relative purposes and the processing methods, users are invited to read the privacy Information Notice which can be found at the following link.
- Maintenance: Booking of firearm maintenance packages or specific interventions at a selected gun shop
- Marketing and profiling
With specific regard to the processing of personal data carried out for marketing and profiling purposes, the conferral of personal data is entirely optional and the processing is subject to users granting their specific and informed consent to the processing of their personal data for each of the purposes described in paragraph 4, c) and d). In any case, users are entitled to revoke each individual consent at any moment in time and change their privacy settings by accessing the “My Profile” section of the Community- Marketing:
- Conferred data: Contact information, name, surname, additional personal data provided by you to enhance the user profile, purchase price of the firearm if registered under warranty
- Data collected: Details of orders placed on the Beretta E-Store as well as products placed in the shopping cart
- Profiling:
- Information on how to use the My Beretta Services, types of content viewed or with which the user interacts, actions carried out by the user in the Community, time, frequency and duration of the user's activities in the Community, data related to orders placed on the Beretta E-Store as well as products placed in the shopping cart
- Information on how to use the My Beretta Services, types of content viewed or with which the user interacts, actions carried out by the user in the Community, time, frequency and duration of the user's activities in the Community, data related to orders placed on the Beretta E-Store as well as products placed in the shopping cart
- Marketing:
- Information security & Fraud prevention
As you use the Community, we may automatically collect certain information as detailed in the table below.- Personal Data we collect: Technical information (for example: Community page response times, download errors, browsing time on certain Community pages, information on interactions with certain Community pages, such as scrolling, clicking, etc.); The IP address of the user and details on the operating system of the device used to access the Community
- Reason why we collect: We collect this information to ensure your use of the My Beretta Services is secure and protected against fraud, as well as to provide the user with technical support or assistance concerning any other issues the same may be experiencing. In addition, the processing of these data allows us to block access to the My Beretta Servizi by subjects who threaten the security of the same and pose threats to the integrity, availability and confidentiality of personal data, combat spam and other malware and, more generally, detect, prevent, and mitigate security risks.
- Processing of anonymised data
Anonymous data refers to information that is altered by a specific processing method in such a way as to make it impossible to relate it to an identified or identifiable natural person. Therefore, the Regulation does not apply to the processing of such anonymous data.
We may use anonymous or aggregated data for various purposes, for instance to better understand the needs and behaviours of the user base, to improve our Community and My Beretta Services, conduct business intelligence and marketing activities, and detect security threats.
The user should note that, except for this section, none of the other provisions of this Information Notice apply to anonymous and/or aggregated data.
- Nature of the conferral of personal data and consequences of refusals
The conferral of the personal data defined as necessary is essential in order to pursue the purposes illustrated in paragraph 4 points (A) and B).
Failure, partial or inaccurate conferral of the aforementioned personal data may make it impossible to enjoy the My Beretta Services.
However, the conferral of personal data for the purposes described in points C), D) and E) of paragraph 4 of this Information Notice, is optional and any refusal shall mean that the Data Controller is unable to pursue such purposes and shall not, in any manner, affect the ability of the user to enjoy the My Beretta Services.
- Communication and dissemination of personal data
Personal data shall be processed by persons authorised to carry out such processing and by designated data processors6 pursuant to Art. 28 of the GDPR, in order to carry out the processing activities necessary to pursue the purposes illustrated in paragraph 4 of this Information Notice. The latter are direct collaborators of Beretta and their list is constantly updated and available by sending a request to privacy@beretta.com
The user should note that personal data are processed within the territory of the European Union and, if necessary, for technical or operational reasons, Beretta may decide to transfer such personal data to countries outside the European Union, pursuant to the existence of an "adequacy decision" or on the basis of appropriate safeguards, or in the cases specifically provided for in the Regulation.
No personal data shall be subject to dissemination.
- Minors
The Community is not intended for use by subjects under 16 years of age, and we do not intentionally collect personal data from subjects under 16 years of age. However, despite Beretta’s efforts to control and prevent the registration of persons under the age of 16, it is not possible to guarantee the complete absence of registered users under 16 years of age.
If a user under the age of 16 has provided personal information without the prior consent of the holders of parental responsibilities, the latter or those exercising parental rights shall kindly request, at any moment in time, the erasure of the personal data provided by the minor by sending an email to the following address: privacy@beretta.com
- Personal data retention period
Personal data are retained for the period of time strictly necessary to pursue the purposes illustrated in paragraph 4 of this Information Notice, except where longer retention periods are required by law.
In particular, as regards to:
- the purposes referred to in point 4 (a) of this Information Notice, personal data shall be retained for the period of time strictly necessary for the correct provision of the individual My Beretta Services or until the account is eliminated by the user. The Data Controller shall automatically eliminate the user profile if the user does not access the Community for a period of over 24 months.
- the purposes referred to in point 4 (b) of this Information Notice, the Data Controller shall retain the personal data for the period of time strictly necessary for Beretta to fulfill its statutory obligations;
- the purposes referred to in points 4 c) and (d) of this Information Notice, the Data Controller shall retain personal data , respectively, for direct marketing purposes for no longer than 24 (twenty-four) months and for direct profile marketing purposes for no longer than 12 (twelve) months, both calculated from the time of collection. After this retention period, the data will be deleted in a secure manner or rendered irreversibly anonymous.
- the purposes referred to in points 4 E), F) and G) of this Information Notice, the personal data shall be retained in accordance with the provisions of the applicable regulations, and for no longer than is strictly necessary for the purposes for which such data were collected.
- Data subject rights
Pursuant to arts. 15, 16, 17, 18, 20 and 21 of Regulation (EU) 2016/679 (GDPR), the Data Controller also informs users how and when they are allowed to exercise the data subject rights envisaged by the Regulation to obtain:
- access your personal data;
- rectification of personal data;
- erasure of personal data, for the cases envisaged by the GDPR;
- restriction of processing, under the conditions envisaged by the Regulation;
- portability of personal data;
- the right to object to the processing of personal data.
Moreover, users are entitled to lodge claims with the Supervisory Authority for the Protection of Personal Data.
All requests to exercise your rights shall be sent to the Data Controller at privacy@beretta.com
- Third party websites and services
Whilst using the Community it is more than likely users may come across links to third-party websites and services. This privacy Information Notice does not apply to any processing of personal data carried out by third parties. Beretta has no control over and is not liable for the processing of personal data that may be carried out by third parties through their websites and/or services. For further information on the processing operations carried out by third-parties, please read the privacy policy issued by the same.
- Corporate aspects
In the event where Beretta should be subject to any acquisition or merger with another company, should transfer some or all of its assets to a third party, or in the event of bankruptcy or dissolution of corporate business, the personal data in its possession may be transferred to an acquiring undertaking or a third party, also in relation to or in connection with the prior due diligence envisaged for such business transactions, subject to the limits and guarantees set forth by the applicable laws in force. In any case, Users shall be promptly informed of any such corporate events so that they can decide whether or not to eliminate their profile or continue to use the My Beretta Services.
Last update: [12/10/2022]
We are constantly striving to improve the level of protection of your personal data and respect for the privacy of users, which means that we may amend, supplement or update this privacy Information Notice from time to time. We shall notify users when any changes are made to the privacy Information Notice via a Community pop-up and, in any case, users can access the Information Notice in the privacy section of the Community or visit the https://www.beretta.com website to ensure that you are always up to date with all processing developments and our compliance with applicable legislation on the protection of personal data.
1 For the purposes of this information notice “personal data” means any information concerning an identified or identifiable natural person (art. 4 no. 1 GDPR).
2 For the purposes of this Information Notice, “User” means any subject who has registered and created a personal account to access the My Beretta Community.
3 For the purposes of this Information Notice, “My Beretta Community” means the web area that allows Beretta customers and product enthusiasts who can access specific exclusive and dedicated services.
4 For the purposes of this Information Notice, the term “Data Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data (art. 4 no. 7 GDPR).
5 For the purposes of this Information Notice, the term “Beretta E-Store” means the e-commerce website of Fabbrica d’Armi Pietro Beretta S.p.A., which can be accessed at the following link……
6 For the purposes of this Information Notice, the term “Data Processor” means the natural or legal person, public authority, agency or other body which who process Personal Data on behalf of the Data Controller (art. 4 (8) of the GDPR).