PRIVACY POLICY FOR THE USERS East Side Ltd, having
its registered office in Gzira (Malta), 84 Luqa Briffa Street, VAT No. MT23084935
(hereinafter, “Controller”), hereby
provides the privacy policy pursuant The Data Protection Act of 2001 (CAP
440) of the Laws of Malta ( hereinafter the Privacy
Code) and pursuant to art. 13 of the Regulation EU 2016/679 of the
European Parliament and of the Council of 27 April 2016 on the protection of
natural persons with regard to the processing of personal data and on the
free movement of such data (hereinafter, “Regulation”
and together with the Privacy Code “Applicable Law”)
in its capacity as data controller in relation to personal data of the users whose
data were regularly acquired by the Controller (hereinafter, the “User”). The Controller takes the outmost account to
the privacy rights and to the protection of its Users’ personal data. For any
information in relation to this privacy policy at any time whatsoever, the
Users may contact the Controller using the following modalities:
The Controller did not appoint a Data
Protection Officer (DPO), because the Controller is not subject to the
mandatory obligation to appoint it pursuant to art. 37 of the Regulation.
The Users’ personal data will be processed by
the Controller lawfully pursuant to art. 6 of the Regulation for the
following processing purposes: A. Because of the fact that Users gave their consent, to the
subject from which the Controller regularly acquired the personal data, for the communication
of their data to third parties for direct marketing purposes: the User’s personal data (name, surname, email
address, zip code, birthdate …) will be processed by the Controller for
marketing purposes (sending advertising material, direct sale, commercial
communication) or in order for the Controller to contact the relevant User by
means of mail, electronic mail, telephone (fixed, mobile, with automated
calling systems with and/or without human intervention) and/or SMS and/or MMS
for proposing to the User to purchase products and/or services offered by the
Controller and/or third parties companies, present offers, promotions and
commercial opportunities. B.
Accounting and
administrative purposes, meaning the performance of organizational, administrative,
financial and accounting activities, such as internal organizational
activities and activities aimed at fulfilling contractual and pre-contractual
obligations. C. Legal obligations, meaning to comply with obligations established by law
or European regulations.
Controller’s employees and/or workers
appointed to manage personal data may become aware of any Users’ personal
data. Such subjects, who are formally appointed by the Controller as persons
in charge for the processing, will process the relevant User’s data
exclusively for the purposes specified under this policy and in compliance
with the provisions of the Applicable Law. Furthermore, third parties which may process
personal data for the account of the Controller may become aware of any
Users’ personal data in their capacity as “external
data processor”, such as, including, but not limited to, providers
entrusted with the sending of marketing e-mails for the account of the
Controller, outsourcing or cloud computing services providers, professionals
and advisors. External data processors are as well: Sending Plateform:
Users have the right to obtain a list of the
data processor (if any) appointed by the Controller upon a specific request
to be made to the Controller following the modalities specified under the
following paragraph 4.
Users may exercise the rights granted to them
by the Applicable Law, contacting the Controller with the following
modalities:
Pursuant to the Applicable Law, the Controller
hereby informs that any Users has the right to obtain the indication of (i)
the source of the personal data; (ii) the purposes and methods of the
processing; (iii) the logic applied to the processing, if the latter is
carried out with the help of electronic means; (iv) the identification data
concerning data controller and data processors; (v) the entities or
categories of entity to whom or which the personal data may be communicated
and who or which may get to know said data in their capacity as designated
data processor(s) or person(s) in charge of the processing. Furthermore, data subjects have the right to
obtain: A.
Access, updating, rectification or, where interested therein, integration of the data;
Furthermore, Users have: A.
The right to withdraw the consent at any time, when the
processing is based on consent;
|