This Privacy Policy describes how Eataly Toronto Holding and Eataly Net Usa LLC (referred to in the "Data Controllers" section below, jointly in this Privacy Policy as "Eataly") as independent Data Controllers, collect and process the personal data of users or customers through their websites, in particular www.eataly.ca ("Sites" or "Site"), physical stores, or more generally every time that express reference is made to this Privacy Policy. By using our Site(s), or otherwise providing us with personal data where we reference this Privacy Policy, you consent to the terms of this Privacy Policy, and the collection, use and disclosures of personal data described in it. If you do not agree with any terms of this Privacy Policy, please do not use our Sites or submit any personal data to us. This Privacy Policy includes the following sections. You should read the entire policy; however, you may use the links below to be directed to the information you are seeking:

 

1. What Is Personal Data?

2. This Privacy Policy May Change

3. Purposes Of Using And Processing And Legal Basis

4. Categories Of Personal Data Processed By Eataly

5. Cookies

6. Data Recipients Or Categories Of Recipients

7. Transfer Of Data To Other Countries

8. Data Retention Period

9. Security

10. Rights Of The Data Subject

11. Data Controller

12. Children

13. Third Party Links

14. How To Contact Us

 

1. WHAT IS PERSONAL DATA?

The term “personal data” means any information concerning an identified or identifiable individual person. For example, personal data includes the name, an identification number, location data, or an online identifier of an individual.

2. THIS PRIVACY POLICY MAY CHANGE

Eataly may amend, supplement or periodically update this information, also in consideration of possible regulatory changes which are applicable or provisions from the competent authorities for the Protection of Personal Data. The changes and substantial updates to the Privacy Policy will be applied and brought to the attention of the interested parties as soon as they are adopted by updating the link to the Privacy Policy in the Site footer and by emailing the registered users. In case of changes that significantly affect the rights of the registered user, the communication will be made with reasonable notice.

3. PURPOSES OF USING AND PROCESSING AND LEGAL BASIS

We use and process personal data for the following purposes. a) If you enter a contract with us, for example, by making a purchase or registering for our Sites, we process your personal data based on contractual need in order to: - manage orders and perform related activities (ex: sales and after-sales customer assistance, communications with the customers on the status of their orders, responses to their information requests, management of payments, etc.); - managing user accounts when registered with the Site in order to use the related services; - allow access to specific and additional services requested from time to time by the user (e.g. registration to courses held at Eataly stores); - manage product shipments and create waybills; - follow and respond to specific user requests (e.g. consider a candidate submitted through the "Work With Us" section or otherwise). b) Based on the consent expressed by the user, for example, we may ask you to provide us with personal data, in order to carry out market research, as well as to contact the user and send commercial communications and promotional offers, in addition to sending the Newsletter described below, with regard to products, services and/or events of Eataly, through SMS, telephone, paper mail or other means, including through a prior analysis of consumer behavior aimed at customizing the commercial messages we send you, including directly, and on our Sites and third party websites. After making a purchase on the Site, the user will receive our Newsletter regarding similar products or services offered on the Sites (specifically, the Online Store newsletter on www.eataly.ca. The user has a right to unsubscribe from the Newsletter right away (i) by using the appropriate link at the end of each email, (ii) changing his/her preferences in the "My account" section on the Sites, or (iii) by using the contact details indicated below in the section "Rights of the data subject". The user can also modify or expand their preferences at any time by using the appropriate "Newsletter" drop-down menu on www.eataly.ca or in the "My account" section on www.eataly.ca, expressing his/her consent to be contacted regarding offers on specific services or products of interest. In any case, the user may exercise his right to object to such processing in the manner indicated above. The foregoing also applies to the sending of the Newsletter following the provision of data in Eataly's physical stores, at events or in any case following a purchase. c) Based on the legitimate interest of Eataly, and your consent to this Privacy Policy, specifically: - for the analysis and improvement of its services; - for statistical and/or research and development activities, also by analyzing data deriving from the use of services and products or consumer behavior; - in order to defend their rights in the course of legal, court, administrative or extrajudicial proceedings, and in disputes arising in connection with the services offered; - in the case of business transactions, such as a merger, sale of a business unit, acquisitions, etc., or if any such transaction is proposed. d) Based on the need to fulfill the legal obligations to which Eataly is subject. The provision of data for the purposes referred to in paragraph (a) above is mandatory, as it is necessary to process the sale and delivery of products and services purchased, or for registration at the sites. Refusal to provide personal data for processing makes it impossible to perform the services required for the purchase of goods and services on the Sites. As explained in “Cookies” and “Rights of the Data Subject below, you have the right to withdraw consent to certain other processing of your personal data, including withdrawing consent to online tracking and advertising, or receiving our marketing emails.

4. CATEGORIES OF PERSONAL DATA PROCESSED BY EATALY

Below is a description of the categories of personal data we deal with: - Personal data supplied directly by you as the data subject: this includes all personal data entered on the Site (to proceed with online purchases or to register), or in any case provided to Eataly in any manner (e.g. in the context of promotional activities in Eataly stores, or on the occasion of participation in one of our courses, etc.). Examples of data provided directly by you as a data subject are: name; address and telephone number; credit card data (processed only for the time necessary for your purchase, or for what is necessary in the case of periodic payments and, if the person concerned has not withdrawn your consent to such processing by changing your settings in "My account", section "Payment Methods", saved for subsequent purchases). More generally, all the data provided to allow the execution of a purchase order, the carrying out of research of products on the Sites, the compilation and use of the profile on the Sites, the facilitation of the delivery of products with the communication data relating to numbers or contact addresses (e.g. telephone, email, addresses), participation in courses, etc. If the user submits an application through the "Work with us" section, or otherwise, the information concerning the CV and the relevant position will be collected, and may be used for evaluating you for employment with us, and if you are accepted, to establish and manage the employment relationship. - The data provided by third parties constitute all the personal data Eataly collects from other sources (postal service companies, couriers, data entry companies, etc.) to perform its services. Examples of data provided by third parties are the data related to updates or corrections received during delivery by couriers, transport partners or third parties, the data on web pages visited that we may receive from other commercial operators with whom Eataly collaborates for certain initiatives, the names of the recipients of the orders, if different from the buyer. Please note that if you provide us with the personal data of another individual, you must have their permission to do so. - Data collected automatically: these are browsing data and/or data collected using so-called "cookies" or other technologies such as tracking scripts and tracking pixels. During their normal operation, the computer systems and software procedures used to operate this Site acquire certain data whose transmission is implicit in the use of internet communication protocols. This information is not collected with the aim of linking it to identified users, although, by its nature, it might enable user identification through processing and linking with data held by third parties. This category of data includes IP addresses or domain names of computers used by persons who connect to the site, the URI (Uniform Resource Identifier) of requested resources, the time of request, the method used to submit the request to the server, the size of the file received in reply, the numerical code indicating the status of the reply provided by the server (successful, error, etc.) and other parameters regarding the user's operating system and computer environment.

5. COOKIES

A cookie is a small file sent by a website and stored on the user's browser when they use an Internet site. Cookies can be stored only for the time you use a particular site (cookies session) or for a longer period of time and independent from the session (persistent cookies). Cookies work in conjunction with the website content and normally have the function of improving the usability and browsing experience on the web (technical cookies). Some types of cookies also allow you to know the contents displayed, the choices selected and any use of the site by the user. This functionality may also allow us to offer more useful and relevant advertising to every single user (profiling cookies), both on our Sites, and on other websites. A website can use self-developed cookies (first-party cookies) or cookies developed by third-party companies (third-party cookies). In addition to allowing an easy use of the Sites, Eataly may use cookies for various purposes, including: (i) identifying the user when logging in; (ii) storing the products saved in the cart for purchase; (iii) avoiding fraudulent use of accounts or payments; (iv) performing user profiling and then providing information on the products of interest to you, or other personalized contents or offers, both on our Sites, and other websites; (v) providing promotions, content, advertising, related to the user and his/her preferences and to remember these preferences; (vi) carrying out market research; (vii) improving the Sites, the offer of Eataly products, and their marketing, etc. In particular, Eataly may use: a) TECHNICAL COOKIES: These are cookies necessary for browsing as they allow correct use of the Site and its full functionality. They include cookies which enable the creation of a personalized account, logging in, displaying content in the chosen language at every access, recognizing the user is connecting from (and remembering this setting for future access) and order management. These cookies are strictly necessary for Site operation and their deactivation might impair browsing experience and outcome. In particular, we may use technical cookies for the following purposes: - for the management of dynamic web pages, for the geographical identification of users, and for the management of last access data; - to guarantee the correct functioning of the web pages; - for the functioning of the forms (e.g. course registration form); - for the management of data relating to the amounts and products of the orders b) ANALYTICAL COOKIES: used to collect information on the number of users and how they visit and use the site. For example: - Google Analytics: the site uses the Google Analytics tool to collect information, in aggregate form, on the number of users and how they visit the Site. This tool uses third-party technical cookies for its operation. Information on the processing of information and privacy by Google is available at the following link: http://www.google.com/analytics/learn/privacy.html. Information on the cookies used by Google Analytics, collection and use of this data are available at the following link: https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage#gajs. The following link also contains information to deny consent to the use of third-party cookies by Google Analytics: http://tools.google.com/dlpage/gaoptout c) THIRD PARTY PROFILING COOKIES FOR MARKETING/RETARGETING: these are cookies of third-party companies that allow the collection of information on the user for subsequent communication of more specific and/or personalized promotional material. They include cookies for inserting banner advertisements on the Site, or on other websites, relating to third party companies or products chosen or viewed by the user, or similar or like products. These cookies can be deactivated without preventing proper navigation on the Sites, however their deactivation involves the receipt of promotional messages that may not be relevant to the user. For more information on profiling cookies currently installed in the user's terminal, review the third party privacy information and change the preferences expressed, including to opt-out, users can consult the page http://www.youronlinechoices.com/it. Disabling cookies. The user can always decide to block, delete, disable cookies or other similar technologies through the settings of their browser or device. There are many different browsers: each different browser (and in some cases even each different version of the same browser) has its own procedure for deleting cookies. Cookie preferences must be set separately for each browser used, as the features and options offered may vary. It is therefore advisable to visit the support pages of your browser for more information. Furthermore, the user can modify the settings related to Eataly cookies, including their activation and deactivation, by accessing the dedicated section in the Sites' footer, under "Cookie Settings". Their complete deactivation may preclude many features, or the proper browsing or viewing of the Site or other web pages. Acceptance and waiver of cookies. At the time of the user's first access to the Sites and, in any case, until a choice is expressed, the user will be asked to provide his consent to the use of third-party analytical cookies and profiling cookies. In particular, consent can be provided by continuing to use the Site without changing your settings.

6. DATA RECIPIENTS OR CATEGORIES OF RECIPIENTS

The data may be processed by third parties, carefully selected in terms of reliability and competence, who, as data processors, act in the name and on behalf of Eataly on the basis of contractual agreements and specific instructions. This is necessary or appropriate in order to carry out activities, including instrumental or ancillary, related to the purposes of data processing indicated in this Privacy Policy, the main one of which consists in the supply of goods or services requested by the interested party (e.g.: data entry companies, companies that manage marketing and newsletters, etc.). Furthermore, the personal data of the users can be communicated between the Eataly Group companies, primarily but not exclusively to Eataly Distribuzione S.r.l., Eataly USA LLC., Eataly Net S.r.l., Eataly Net USA LLC, Eataly Toronto LP, Eataly Toronto Limited for the purposes indicated in this Privacy Policy. For example, if the user purchases a course or service on the Site, his data will be processed by the company relevant to the request. Likewise, if the user submits his application for an open position at a specific Eataly store, the data will be processed by the data controller of the position in question. In any other case, except as required by applicable law, personal data are not transferred and/or disclosed to third parties without prior express consent.

7. TRANSFER OF DATA TO OTHER COUNTRIES

The servers that make the Site available are located in Montreal and in Europe. Our hosting provider is based in the United States. This provider acts only on Eataly instructions and implements technical measures necessary on an ongoing basis to help keep your personal information secure. We may transfer personal data outside of Canada, including to the United States and Europe. As a result, this information may be subject to access requests from governments, courts, or law enforcement in those jurisdictions according to laws in those jurisdictions. By providing us with personal data, you expressly agree to such international transfers. If personal data are transferred to countries outside Canada the transfers will take place in compliance with the provisions established by applicable laws in order to help ensure an adequate level of protection.

8. DATA RETENTION PERIOD

Eataly may store the personal data only for as long as is reasonably necessary taking into consideration the purposes for which we have collected it, such as our need to answer queries or resolve problems, provide improved and new services, comply with legal requirements under applicable law(s) or in the event of disputes and extraordinary claims that reasonably require the retention of personal data. This means that Eataly may retain your personal data for a reasonable period after you stop using Eataly services or stop using the Site. As soon as the personal data are no longer necessary for the purposes for which they were collected, Eataly will delete them, unless the law requires further storage, or the user has consented to the processing for a longer time, or when they are archived. In particular, following the deactivation of the account or, for unregistered users, of the completion of the order, Eataly will retain the personal data that are necessary to: - fulfill the requests of the authorities within their competence; - defend or assert any existing or potential claim; - handle any complaint regarding contracts or orders concluded. Regarding the data entered in the "Work with us" section, when submitting a job application online or by other means, if the application is not successful, such data will be stored in the system of the relevant Eataly branch for a maximum of 12 months, in order to allow us to evaluate the candidate for other positions. The user can oppose to this processing at any time by submitting a request to the contacts indicated in the section "Rights of the data subject".

9. SECURITY

We use technical, contractual, physical, and administrative security measures to help protect the personal data in our possession. Only staff members or our representatives or service providers needing access to personal data to carry out the purposes described in this Privacy Policy, and such other purposes as permitted or required by applicable law, are provided access to such information and we limit their access to that needed for the purpose(s) they are carrying out. Personal data we collect is managed from our offices at New York, USA, Canada and Milan, Europe. Please note that no security measures can provide absolute protection. We cannot ensure or warrant the security of any information you provide to us.

10. RIGHTS OF THE DATA SUBJECT

You have the right to request access your personal data and to obtain confirmation of the existence or otherwise of your personal data, even if not yet registered, and to their request it be corrected if you believe it is not accurate. Each user has the right to object, in whole or in part, to the processing of personal data concerning him/her. The requests referred to in the previous point should be addressed to the data controller's contacts indicated in the "Data Controller" section below. The requests must be addressed to the relevant controller for the relevant activities. If you have doubts or if you want more information about the relevant data controller, contact the Customer Care. To help protect against fraudulent requests for access to your personal data, we ask you for information to allow us to confirm that the person making the request is you or is authorized to access your information before granting access. For example, we may require you to verify your identity before you access your personal data.

11. DATA CONTROLLER AND HOW TO CONTACT US

The Controllers of the data processing, depending on the activity performed/service provided, are: - Eataly Net USA LLC, with registered office in 43 W23rd St., New York, NY, United States with regard to (i) the processing activities on the Sites (e.g. operation of the Site, cookies, e-commerce, purchase of products and services from the Eataly virtual store), as well as (ii) the newsletters relating to the Eataly virtual store and, if authorized by the user for each relevant instance, other marketing activities concerning the Site. You may contact Mr. Emanuele Varva, Head of Ecommerce, at e.varva@eataly.it. -Eataly Toronto Holding, registered office in 55 Bloor St West, Toronto, ON, Canada, with regard to (i) the processing activities in the stores in Canada, including in relation to the courses and events held there, as well as (ii) the newsletter relating to such stores or, if authorized for each relevant instance by the user, other marketing activities, and (iii) the processing linked to the evaluation of candidates applying for positions with Eataly Toronto Holding; You may contact Mr. Nico Dagnino, Store Director of Eataly Toronto at nico.dagnino@eataly.com - Other companies of the Eataly Group, relevant to the stores managed by them.

12. CHILDREN

Our services are not intended for children. Despite this, if you are the parent or legal guardian of a child under 13 who has provided us with personal data themselves, you may ask to review or delete this information.

13. THIRD PARTY LINKS

Our Sites may contain links to websites owned by third parties. These other websites may have their own privacy policies and terms and conditions that are not governed by this Privacy Policy. We are not responsible for the privacy practices or the content of any website(s) owned and operated by third parties. Other websites may collect and treat information collected differently, so we encourage you to carefully read and review the privacy policy for each website you visit. Any links from this site to other websites, or references to products, services or publications other than those of Eataly, do not imply the endorsement or approval of such websites, products, services or publications by Eataly.

14. HOW TO CONTACT US

If you have doubts or if you want more information about the relevant data controller, or for any matters regarding the processing of your personal data and the exercise of your rights deriving from applicable laws, you can contact us in the following ways: by e-mail to: ciaotoronto@eataly.com by telephone at +1 437-374-0250 from 9.00 am. to 10 pm EST time. by mail to the attention of Legal Department at 55 Bloor St West, Toronto, ON, Canada