“PRIVACY POLICY”
WWW.STEELES.IT

Privacy Policy

(Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679)

“DATA CONTROLLER”, DATA PROCESSORS AND CONTROLLERS

As regards personal data protection, browsing of this website entails the user access to information that qualifies as personal data. The Data Controller for this purpose
is Incoservice SRL, Tax Number 02444000133 in the person of its legal representative, with registered office at Via Alessandro Manzoni, 3 – 22060
Cucciago (CO).
Within Incoservice SRL’s data processing journey, all personal data collected are processed by employees working as “Data Processors”, who follow
specific instructions, or by appointed subjects – including third parties outside the organisation – who function as Data Processors.

PLACE OF DATA PROCESSING

The processing involved with the web services of the www.steeles.it website is carried out at the Cucciago (CO) headquarters, or at the below mentioned premises,
by the Data Processors and the Data Controller, and it is performed only by technical staff of the Department in charge, or by other
appointees in charge of occasional maintenance operations. No data deriving from the web service is communicated or disclosed (Article 90 of the GDPR). The personal data provided by users
who request dispatch of informative material are used only to perform the service or provision requested and are communicated to third parties only if this
is to this necessary end (Article 3 of the GDPR).

PRIVACY POLICY FOR WEBSITE VISITORS

This Privacy Policy describes the management mode of this site, in reference to the processing of personal data of users / visitors who consult it.

This informational notice is provided under Article 3 of the GDPR to those who visit the Steeles.it website and interact with web services corresponding

with the [https://www .steeles.it] page.

The [https://www .steeles.it] website is owned and managed by Incoservice SRL, who guarantees its compliance with the current legislation in terms of personal data protection (GDPR).

MEANING OF PERSONAL DATA AND PERSONAL DATA PROCESSING

Personal data processing refers to any operation or series of operations – carried out with or without electronic means – related to the collection,

recording, organisation,

conservation, consultation, elaboration, modification, selection, extraction, comparison, use, interconnection, freezing, communication, disclosure,

deletion and destruction of data, even if not recorded in a database.

TYPES OF PERSONAL DATA AND PURPOSE OF TREATMENT

1) Browsing data related to platform use

During the normal course of operation, information systems and software procedures used to operate this website acquire some personal data whose transmission

is implicit in the Internet communication protocols.

It concerns information that is not collected to be associated with specific individuals, but by their own very nature could, through the processing and association

with data held by third parties, allow users to be identified.

All our activities are based on stringent ethical principles and we are committed to protecting the privacy of all visitors of our website. For this reason, the way we collect

and store data is closely related to the modes of use of our website and its related services.

2) Data voluntarily provided by users / visitors

If the user / visitor connecting to this website sends his/her personal data with the intention of obtaining a particular service, or to request any other information,

this act permits Incoservice SRL to acquire said information from the address of the sender and any other personal data which in turn will be used exclusively to respond to the request.

Personal data provided by users / visitors will be provided to third parties only where such disclosure is necessary to fulfil the user / visitor

requests.

3) Cookies

Different technologies can be in use on our website in order to improve it and make it more user friendly, effective and safe. Such technologies allow us, or third parties operating

on our behalf, to automatically detect data. Cookies are examples of such technological solutions. Cookies are not used for the transmission of information of personal nature,

neither the use of so- called persistent cookies of any type, or rather users’ tracing systems. Using the so-called session cookies (which are not persistently

stored on the user’s computer and disappear when the browser is closed) is strictly limited to the transmission of session identifiers (consisting of random numbers

generated by the server) necessary for allowing a safe and efficient site exploration.

The session cookies used on this website avoid the need to use other data processing techniques which could potentially reduce the confidentiality of the users’ navigation of the website

and would not permit the acquisition of identifying personal information regarding the user.

You may decide which of these cookies to enable at any point, either through the related selection menu on the website’s Home page, or through the banners

you will find on each page, redirecting you to our Cookie Policy.

A detailed description of all cookies in use can also be found in the dedicated section, including their function, their purpose and their natural expiration date.

4) Data provided by you

In addition to the automatically detected data, we also process data provided by you.

These include, but are not limited to: your contact information, including company name and VAT ID, or name, surname and tax number in the case of individuals, address (which needs to be provided

on the invoice, as well as delivery address for shipping of goods), your e-mail address, website and date of birth, your telephone number, or mobile number in the case of individuals, in the instance

that we need to reach you with any questions or requests for information related to your order; other information needed to process your order: such as

information related to the products you ordered, information on your bank account, IBAN and SWIFT code, whether you contacted customer service, information related

to these communications.

All these data were provided by you. All these data were provided by you. This information will be used for the purposes outlined in this Policy. You have the right to withdraw

our personal data at any time, or to prevent their processing. (see the “Subject’s Rights” Section).

USE OF DATA COLLECTED: PURPOSE OF DATA PROCESSING

We will use your personal data for purposes related to your purchases on Steeles.it: for instance, to communicate the status of our purchases and/or deliveries. We might use your

ata to assess your credit standing, by using third-party information.

If you have provided personal data, for instance in relation to a sales promotion or an event, we might send you additional e- mails or other messages related to the service you have

requested.

If you have contacted our customer service, we will use your personal data (including your contact and call history) in order to more easily fulfil

your requests and provide the best possible service.

If you have shared your personal data while purchasing a product, we will inform you of similar products and services.

You can unsubscribe at any moment, free of charge and with immediate effect, from our mailing list by simply sending an e-mail (see the “Subject’s Rights”

Section), or from our Newsletter by using the related button included at the bottom of our e- mails.

Subject to your explicit permission, we might contact you through your provided information (via e-mail, text, telephone or other electronic means) for marketing and advertising

purposes on behalf of Incoservice SRL, owner of the Steeles brand.

This might include product information, e- commerce activities, special offers and/or promotional initiatives.

In order to provide information that might be of interest to you, we will analyse, use and combine any data collected during your interaction with Steeles.it, such as your purchases,

your product reviews and ratings, your history of calls to customer service, the Newsletter links your clicked on / opened, the types of newsletters

you requested.

Your personal data will be processed for the following purposes:

1. fulfilment of legal obligations, compliance with regulations and Community legislation;

2. performance of the contract or, before such performance, to fulfil your specific requests in relation to the sale of marketed goods

sold by Steeles.it;

3. client management and management of any purchase orders and related administrative activities, with related processing, in compliance with current legislation,

invoicing, electronic invoicing and shipping procedures;

4. establishment of appropriate protective measures against credit risk, including activities

aimed at assessing client credit rating and solvency, prior to entering

into a contractual relationship. Incoservice SRL might ascertain whether the bank / post information provided is correct; 5. 5. All activities related to the carrying out of market studies related to the carrying out of market studies

and research, to direct sales activities – even those carried out by phone – to the sharing of commercial information, as well as to the sharing of marketing / informational materials,

carried out in “traditional” ways (e.g., snail mail and/or operator calls).

The subject can at any time oppose to the processing by sending a request to the following dedicated e-mail address: info@steeles.it;

6. management of administrative disputes (contractual defaults, formal notices, transactions, debt collection, arbitrations, litigation).

PERSONAL DATA PROCESSING: MANDATORY AND OPTIONAL CONSENT

Personal data processing must be free, informed, expressed in a specific form and documented in writing, even by checking the checkboxes in

the related fields of this website.

The subject is free to provide his/her personal data each time they are requested. Their partial, inexact or non- conferment could make it impossible to supply the services

that you have requested (Article 7 of the GDPR).

Personal data processing is required for all related and aforementioned processes and/or those needed to fulfil legal

obligations and community law, to fulfil obligations that arise from a contract of which the subject is one of the parties or to fulfil specific contractual requirements – prior to the contract’s resolution (Purpose: items 1-2-3-4-6).

Consent to the processing of personal data for the purposes set out in item 5 is optional and can be withdrawn at any time in line with the procedures set out in the

“Subject’s Rights” Section of this Policy. The subject’s failure to adhere to item 5 will result in our inability to send marketing materials

and carry out promotional activities.

You can withdraw your previously provided consent to receiving marketing communications at any time in the following ways:

By sending a request to info@steeles.it, or by clicking on the relevant “Unsubscribe” field in the Newsletter section.

DATA PROCESSING AND DATA RETENTION MODES

Personal data are processed with paper, IT and online authorised tools, including profiling (Article 22 of the GDPR); profiling can be carried out through personal or

identifying data (e.g. biodata), or aggregated data derived from individual personal data. This in accordance with guarantees of confidentiality and safety measures

set out by the current legislation, with reasoning strictly relating to the purposes of the processing.

Specific safety measures are set out in order to prevent loss of data, illicit or incorrect uses and unauthorised access.

The data retention period is related to the purposes of the processing in progress. Incoservice SRL will not retain personal information for longer than necessary

to fulfil the purposes for which such information was processed, including the safety of our processing in accordance with our regulatory or legal obligations

(e.g. control, accounting and legal retention terms), dispute management and establishing, practising or defending legal claims in the countries where

we do business.

DISCLOSURE OF INFORMATION

One of our main principles is the commitment to treating your data safely and as confidential. We will never sell your data to third parties. Your data can only be disclosed

to third parties in accordance with the current legislation and only if allowed in accordance with the law.

We may use service providers and Data Processors working on behalf of Incoservice SRL. They provide hosting

and maintenance, analytics, e-mail messaging, shipping, payment management, credit check, address check services and much more. These third parties

have access to any personal data they might require to carry out their specific services. Service providers and Data Processors have a contractual obligation

to treat such information as strictly confidential.

You may request a full list of such Data Processors by sending an e-mail to info@steeles.it. The list of such Processors will be shared via e-mail

in an Excel or compatible format.

CATEGORIES OF PERSONS WHO MAY BECOME AWARE OF YOUR PERSONAL DATA

In addition to Incoservice SRL employees, some data processing procedures might be carried out by third parties, including companies to whom Incoservice SRL

entrusts or might entrust activities that are functional to website browsing. These same companies will act as independent Appointed Subjects, or as Data Managers.

In this case, the Data Controller will provide sufficient operational instructions for Data Processors, specifically in relation to safety measures, in order to ensure

data confidentiality, integrity and safety.

The user’s data might also be disclosed to the relevant regulatory or administrative authorities, or to any public bodies that are entitled to request them, in the cases provided for by the law.

For the fulfilment of the aforementioned purposes, Incoservice SRL may communicate the Subject’s personal data to

non-EU third parties with whom they entertain business, in Italy and abroad, and allow them to process such data. Incoservice SRL shall only provide them with the information that is necessary to carry out the requested services by taking

all necessary steps in order to protect your personal data (Article 44 of the GDPR).

ersonal data may be accessed by Incoservice SRL employees, freelancers, occasional workers, consultants, who were

nominated / designated as Data Processors or Data Controllers.

Accounting or invoicing staff; staff responsible for the marketing or goods / services;

the aforementioned data may be transferred and disclosed to the following categories of

subjects: companies operating in the transport industry, for the shipping of purchased goods or the collection or returns and defective goods, our suppliers of materials, Poste Italiane

and other mail companies, banks and credit institutes, credit recovery firms, legal firms, insurance companies, professional firms and/or companies

and/or associations of enterprises and entrepreneurs providing us with specific accounting and/or tax services, pension services, etc.;

SUBJECT’S RIGHTS

Incoservice SRL reminds the Subject that, as an identified and/or identifiable individual,

in accordance with Article 15, 16, 17, 18, 19, 20, 21 of the GDPR they may at any point obtain confirmation of the existence of their data and their availability in intelligible form, their provenance and content,

the logic involved in the data processing, verify the data integrity, request updating, rectification or integration of the data. In accordance with the aforementioned Articles, the Subject

has the right to request the cancellation, the transformation into an anonymous form or the block of processed data treated in violation of the law, and to oppose in any case, for legitimate reasons, to its treatment.

For any data processing related to direct marketing (either “traditional” or “automated”), you may always withdraw your consent and exercise your right to opt out.

In the absence of any indication to the contrary, such opt out option will refer both to traditional and automated communications. In order to exercise the aforementioned rights, you may send

an e- mail to the dedicated info@steeles.it address.

You have the right to be informed at any time about the personal data stored about you, their origin and recipients as well as the purpose for which they

are being stored. You may obtain information on the stored personal data by contacting us at info@steeles.it. The individuals whom

personal data refer to are always entitled to receive confirmation of the existence or non-existence of the data, information on the content and origin, to verify the correctness of the data or request data integration,

update or correction.

Right of reply

You have the right to request to correct, supplement, update, delete or block the personal data stored about you. Within two weeks of receiving

your request, we will communicate whether and how we will fulfil your request. If for any reason we are not able to fulfil

such request, we will ensure you are aware of our reasoning (Article 12 and 16 of the GDPR).

Right to oppose and unsubscribe

You have the right to request the cancellation, the transformation into an anonymous form or the block of processed data treated in violation of the law, and to oppose in any case, for legitimate reasons,

to its treatment (Article 21 of the GDPR). Any e-mails sent by Incoservice SRL and containing newsletters or marketing messages,

provide an option to unsubscribe. If you would like to no longer

receive our e-mails, you can simply send an e-mail to info@steeles.it with the subject “Unsubscribe” from the subscribed e-mail and we will no longer send you marketing

and commercial communications (Article 17 of the GDPR).

DATA INTEGRITY AND SAFETY

Appropriate technical and organisational measures are implemented to protect your personal data against unauthorised or unlawful access, disclosure, dissemination, alteration, or destruction or accidental loss,

in particular where the processing involves the transmission over a network, or any other unlawful processing and misuse.

CONTACTING US

The Data Controller, in the person of his/her legal representative, is:

Incoservice SRL, Tax Number 02444000133, with registered address at Via Alessandro Manzoni, 3 – 22060 Cucciago (CO) – Telephone No. 031 782243 – e-mail: amministrazione@incoservice.org.

By contacting the Data Controller or administration directly, you may access an updated version of this document and an updated list

of the Data Processors.

CHANGES TO THIS POLICY

Incoservice SRL is committed to adhering to the fundamental principles of data protection and considers personal data protection as a natural duty. herefore, we frequently review

our codes of conduct with regard to personal data protection, to ensure they are free of errors, include all necessary

information and are in compliance with relevant legislation.

This Personal Data Protection Policy might over time undergo changes in order to ensure it is current with progress and new opportunities presented by the

Internet and that it is compliant with current regulations.

Without your prior explicit consent, we will never enforce provisions limiting your rights as outlined in this Policy. Relevant changes to this Policy

will be published on our website, and we will simultaneously publish the updated version of the Personal Data Protection Policy.

Winter Sales
-20%