SUBSCRIBE TO MY LOVERS AND GET 15% DISCOUNT NOW!
DELIVERY IN 5 WORKING DAYS IN EUROPE
The Data Controller is Medspa Ltd, represented by its legal representative, with registered office at 17 Corso Sempione, Milan.
Tel. 081/19569101, email: privacy@medspa.it, certified email: medspa.srl@pec.it
The Data Protection Officer (DPO) can be contacted at the email address: dpo@medspa.it
Data and information are collected to allow the correct functioning and use of the Data Controller's website (operational data, statistical data, security information, etc.). Data collection occurs automatically upon opening the website pages.
Data will be stored for a maximum of 24 months.
Legal Basis: Data Controller's legitimate interest
Data collection occurs to process and complete product purchase transactions. Purchase operations through Medspa Ltd web pages are protected by suitable security systems (e.g., HTTPS protocol). Payment management services allow the Data Controller to process payments via credit card, bank transfer, or other methods (e.g., Paypal, Scalapay, Klarna, Doofinder, CDN systems, etc.). Payment data is acquired directly by the required payment service provider, without being processed by the Data Controller except for transaction outcomes. Some of these services may also involve scheduled message sending to the User, such as emails containing invoices or payment-related notifications. Users are advised to review the respective information on the service provider's web pages. Data provision is necessary to provide the requested service. Data will be stored for 10 years in compliance with regulations on document retention for tax and contractual purposes.
Legal Basis: Fulfillment of contractual obligations
Data collection aims to process contact or interaction requests that are spontaneously sent through forms on the website page (e.g., "Contact Us" section or "Chat with Us"). For request management, an application external to the website (e.g., Whatsapp) might be used, in which case, the data may be known to the application manager, who may process them as an independent data controller. Medspa Ltd will notify the use of external applications before data sharing. Data provision is optional. Data will be stored for the time necessary to manage the request.
Legal Basis: Exercise of contractual and pre-contractual activities at the data subject's request
Data is processed to request and manage appointments with our consultants. Only contact details are processed. Data provision is optional. Data will be stored for the time necessary to manage the request.
Legal Basis: Exercise of contractual and pre-contractual activities at the data subject's request.
Your data will be processed to manage your participation in contests and/or point collections organized by the Data Controller. Data provision is optional, but failure to provide data will result in the inability to participate in the aforementioned initiatives. Data will be stored for the time necessary to manage the event. Only data necessary to fulfill legal obligations will be retained for 10 years.
Legal Basis: Exercise of contractual and pre-contractual activities at the data subject's request and compliance with legal obligations (Adherence to Regulations)
Through the website, you can join the "Miamo Lovers" Community by creating a personal account. The Community is for commercial purposes; registration allows access to promotions, discounts, and personalized offers. The creation of a "Miamo Lovers" account is not mandatory but is an optional service offered by the Data Controller to manage the contractual relationship and improve the commercial experience with the Customer. Registration implies consent to the Data Controller's marketing activities, enabling access to offers dedicated to Community participants (see point no. 8). Data will be stored until the account deletion request. Subsequently, only data necessary to fulfill legal obligations will be retained.
Legal Basis: Fulfillment of contractual obligations (Adherence to Terms and Conditions) and consent
Data will be collected to perform a skin assessment via the dedicated webpage and provide a report on any identified issues and proposed solutions. During the test, special data (suitable for revealing the data subject's health status) may be collected to provide diagnosis and treatment (Art. 9, paragraph 2, letter h). Data provision is optional. Transmitting the final report involves sending commercial advice, requiring consent to the Data Controller's marketing activities as described in the "Marketing" section of this document. If the procedure concludes without a request for the final report, the data will be immediately deleted. If the procedure concludes with the final report, the data will be stored for months to provide periodic comparison to the User about the treatment status. Data deletion can be requested at any time as described in the "Data Subject Rights" section of this document.
Legal Basis: Exercise of pre-contractual activities at the data subject's request
The Data Controller may contact the Customer via email or telephone to collect information about the quality of the service provided. These processing activities aim to improve the products and services covered by the contract and tailor the offer to customer needs. Data provision is optional. Data will be stored for months and then archived in anonymous form for statistical and service quality control purposes.
Legal Basis: Data Controller's legitimate interest
Data is processed for the communication of commercial information (marketing). The Data Controller's marketing activities may include:
Data may be communicated to third parties for legal obligations.
Your data may also be communicated to companies that, on behalf of Medspa srl (Data Processors pursuant to Article 28 of the GDPR), perform activities such as IT system management, server hosting, cloud services, accounting, debt collection, credit rating, etc.
In pursuit of the above-mentioned purposes, data may also be communicated to third parties who may act as independent data controllers, such as banks responsible for payments, couriers, and carriers responsible for shipments and deliveries. The list of such third parties is available at the contact details provided under the Data Controller section.
The dissemination of personal data is not foreseen, unless expressly authorized by the data subject.
No automated processes are planned. All processes involve the assistance of an operator.
The website pages and related applications may share collected data with services located outside the European Union. The Data Controller verifies the existence of appropriate legal bases for data transfer outside the EU. Regarding data transfer resulting from Cookie activities, please refer to the Cookie Policy.
Pursuant to Articles 15-22 of the GDPR, data subject rights include: