UPDATE OF THE PRIVACY POLICY

INFORMATION MADE PURSUANT TO ART. 13-14 OF GDPR 2016/679 (GENERAL DATA PROTECTION REGULATION) and Legislative Decree 101/2018

Dear Interested,

the protection of personal data is an absolute priority. For this reason, En Beautè Parrucchieri di Domenico Floriello has adequate security measures in place in order to preserve its confidentiality, integrity and availability.

We inform you that, given the important innovations introduced starting from 25 May 2018 by the European Union Regulation no. 679/2016, also known as GDPR, En Beautè Parrucchieri di Domenico Floriello has updated the information on the processing of your personal data, which we recommend you read carefully.

We are at your disposal for any further information.

This information explains how En Beautè Parrucchieri di Domenico Floriello undertakes to protect and safeguard the privacy of the users of its site http://www.acconciaturenbeaute.it to protect the information collected.

The purpose of this document is to provide you with the information you need so that you can express, if you deem it appropriate, an explicit and informed consent to the treatments carried out.

In general, any information or personal data provided through this site is treated according to the principles, in their internationally recognized meaning, of lawfulness, correctness, transparency, purpose and conservation limitation, data minimization, accuracy, integrity and confidentiality.

Due to changes in the applicable legislation, we inform you that this page can often undergo changes and therefore we invite you to visit it regularly to be informed correctly.

We inform you that the lack of consent and the lack of approval of what is expressed in this statement entails the need for you to immediately stop using this site and the services connected to it. It follows that by continuing to use this site and our services, you consent to the use of your data by us as specified below in this Notice.

The information is divided into the following points:

1. Data Controller and Data Protection Officer

2.Data object of the treatment

2.1. Data provided voluntarily by the interested party

2.2. Navigation data

3. Cookies

4.Legal basis and mandatory or optional nature of the processing

5. Purpose of the processing

6. Recipients of personal data

7. Methods of treatment

8.Transfer of personal data

9.Conservation of personal data

10. Rights of the interested party

11. Modifications

12.Definitions

1. Data Controller and Data Protection Officer.

The Data Controller is En Beautè Parrucchieri di Domenico Floriello - PI 01972560740, responsible towards you for the legitimate and correct use of your personal data. The Data Controller is Domenico Floriello

2.Data object of the Treatment.

The personal data processed through the site are as follows:

1. Name, contact details and other personal data

On some pages of the site you may be asked to enter information such as the user's name, company name, telephone number, address, email address. and other elements of personal identification.

2. Navigation data.

The computer systems and so ſt ware procedures used to operate the site acquire by default some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified interested parties, but which by their very nature could, through processing and association with data held by third parties, allow users to be identified. This category includes IP addresses, domain names of computers used by users who connect to the site, addresses in URI notation, the time of the request, the method used to submit the request to the server, the size of the file obtained. in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the IT environment of the interested party. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the Site,

3. Cookies.

Information relating to the use of cookies is available at: http://www.acconciaturenbeaute.it [address uri page cookies]

4.Legal basis and mandatory or optional nature of the processing. The legal bases used by En Beautè Parrucchieri di Domenico Floriello to process personal data, according to the purposes indicated in the following Article 4, are as follows:

1.Product supply / fulfillment of contractual obligations. The processing for this purpose is necessary for the execution of the contract signed between En Beautè Parrucchieri di Domenico Floriello and the user and, therefore, to be able to provide the contractually agreed services. The provision of personal data for this purpose is not mandatory, but failing that, it will not be possible to provide the service requested by the user

2.Legitimate prevailing interest of the owner: the processing is necessary to carry out checks and assessments on the results and progress of the contractual relationship, as well as on the risks connected to it (such as: truthfulness of the data provided, solvency also during the relationship and correct use of product and services).

3. Legal obligations: processing for this purpose is necessary so that En Beautè Parrucchieri di Domenico Floriello can fulfill any legal obligations. The personal data provided to En Beautè Parrucchieri di Domenico Floriello are treated according to the applicable legislation, which could entail their conservation and communication to the competent Authorities.

4. Promotional communications to its customers: the processing for this purpose is based on the legitimate interest of En Beautè Parrucchieri di Domenico Floriello in transmitting marketing communications regarding the integration of products purchased by customers or the promotion of similar products. The user can at any time and free of charge, stop receiving these communications by writing to paoloranieri.commercialista@pec.it in the person of Mr. Domenico Floriello

5. Purpose of the treatment. User data is used for the following purposes:

1. Supply of products / fulfillment of contractual obligations: for purposes relating to the execution of the obligations provided for by the General Contract Conditions

subjects are appointed as Data Processors and a complete list of Data Processors can be requested by contacting the email address: paoloranieri.commercialista@pec.it

8.Transfer of personal data. For purposes related to the execution of the contract, some data may be disclosed to recipients located outside the EU Economic Area. The owner Domenico Floriello ensures that the processing of personal data by these recipients takes place in compliance with the applicable legislation, and that there are adequate guarantees such as Standard Contractual Clauses approved by the European Commission or similar. More information is available at En Beautè Parrucchieri di Domenico Floriello by writing to the following address paoloranieri.commercialista@pec.it

9.Conservation of personal data. The personal data processed for the purpose of “Provision of

Service / Contractual fulfillments "are kept for the time strictly necessary to pursue the aforementioned purpose. These personal data are processed to provide
products / services, therefore they are kept for the time necessary in order to protect the interests of En Beautè Parrucchieri di Domenico Floriello from possible responsibilities relating to the supply. Personal data processed for marketing purposes are kept by En Beautè Parrucchieri di Domenico Floriello until the consent given by the user is revoked. If the user revokes the consent, En Beautè Parrucchieri di Domenico Floriello ceases to use the data for such purposes, but keeps the data for the time necessary to protect the interests of En Beautè Parrucchieri di Domenico Floriello from possible liabilities based on such treatments. The personal data processed for the purpose of sending promotional offers to customers will be kept by En Beautè Parrucchieri di Domenico Floriello until the interested party objects to the processing by writing to paoloranieri.commercialista@pec.it

Personal data processed for the purpose of "Fulfillment of legal obligations" will be kept by En Beautè Parrucchieri di Domenico Floriello for the period provided for by specific legal obligations or by applicable legislation. Personal data processed for the purpose of preventing abuse and fraud are kept by En Beautè Parrucchieri di Domenico Floriello for the time strictly necessary for the aforementioned purpose.

10.User Rights. The user has the right to ask En Beautè Parrucchieri di Domenico Floriello at any time:

1. Access to personal data, (and / or a copy of such personal data), as well as further information on the treatments in progress on them (Article 15 of EU Regulation no. 2016/679)

2. The rectification or updating of personal data (Article 16 of EU regulation no. 2016/679)

3. The deletion of personal data from the databases of En Beautè Parrucchieri di Domenico Floriello (Article 17 of EU Regulation no. 2016/679)

4. The limitation of the processing of personal data by En Beautè Parrucchieri di Domenico Floriello art. 18 EU Regulation no. 2016/679);

5. Data portability, that is to obtain in a structured format, commonly used and readable by an automatic device, a copy of your personal data provided or to request its transmission to another Data Controller (Article 20 of EU Regulation no. 2016/679 )

6. Opposition to the processing of personal data (Article 21 of EU Regulation no. 2016/679)

7. The revocation of one's consent to the processing without prejudice to the lawfulness of the treatment based on consent acquired before the revocation (Article 7, paragraph 3 of the EU Regulation

n. 2016/679).

En Beautè Parrucchieri di Domenico Floriello will provide the interested party with information relating to one or more of the actions taken as per the previous list without unjustified delay and, in any case, at the latest within one month of the request itself. This deadline can be extended

2. Legitimate overriding interest of the owner: for checks and assessments on the results and progress of the relationship, as well as on the risks connected to it (such as: truthfulness of the data provided, solvency even during the relationship), to compile statistics, anonymously , on the services rendered and on access to the sites and commercial information and on participation in trade fairs, events, seminars and any other initiative aimed at promoting the products of En Beautè Parrucchieri di Domenico Floriello to prevent or identify any abuse in the use of the site or any fraudulent activity; to improve the quality of the services rendered, by sending questionnaires, feedback on participation in events.

3. Legal obligations to which the data controller is subject: for compliance with the law and / or provisions of public bodies, which require En Beautè Parrucchieri di Domenico Floriello to collect and / or further process certain types of personal data .

4. Sending promotional offers to their customers or who have previously given their consent. It is understood that in relation to this purpose, the user can deny the treatment at any time and free of charge. In this case the user will not be able to use the services connected to the treatment itself.

6. Recipients of personal data. The personal data of the interested party may be intended for the subjects indicated below ("Recipients"):

1. Subjects who typically act as data processors, that is: natural persons, companies or professional firms that provide assistance and consultancy to En Beautè Parrucchieri di Domenico Floriello in accounting, administrative, legal, tax, financial and debt recovery matters in relation to the provision of the Services, the mailing of advertising material or contractual communications, companies that organize training events, providers of services for web meetings and web training seminars; a complete list of all the managers can be requested by contacting the email address: paoloranieri.commercialista@pec.it

2. Subjects providing e-mail services (platforms for sending e-mails), also delegated to manage requests for cancellation sent by users for the purposes of processing.

3.Subjects delegated to carry out technical maintenance activities (including maintenance of network equipment and electronic communication networks);

4.Persons authorized by En Beautè Parrucchieri di Domenico Floriello to process personal data necessary to carry out activities strictly related to the supply of products towards such persons operates a legal obligation of confidentiality;

5.Factoring companies, credit institutions, debt collection companies, credit insurance companies.

6. Professional Orders or Training Bodies accredited with these Orders;

7. Subjects, bodies or competent authorities to whom it is mandatory to communicate personal data to comply with legal obligations, prevent abuse or fraud.

7. Methods of treatment. The processing of personal data is carried out by means of the following operations: collection, registration, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, cancellation and destruction of data. In compliance with European regulations and national data protection laws, En Beautè Parrucchieri di Domenico Floriello has put in place speci fi c procedures aimed at preventing both unauthorized access to data and their improper or illegal use. It has also put in place specific procedures to prevent the destruction or even accidental loss of the data. Only duly authorized and trained personnel can access the data while carrying out their work and for the sole purpose of carrying out their duties. The subjects are appointed as Data Processors and a complete list of the Managers can be requested by contacting the email address: paoloranieri.commercialista@pec.it

8.Transfer of personal data. For purposes related to the execution of the contract, some data may be disclosed to recipients located outside the EU Economic Area. The owner Domenico Floriello ensures that the processing of personal data by these recipients takes place in compliance with the applicable legislation, and that there are adequate guarantees such as Standard Contractual Clauses approved by the European Commission or similar. More information is available at En Beautè Parrucchieri di Domenico Floriello by writing to the following address paoloranieri.commercialista@pec.it

9.Conservation of personal data. The personal data processed for the purpose of “Provision of

Service / Contractual fulfillments "are kept for the time strictly necessary to pursue the aforementioned purpose. These personal data are processed to provide
products / services, therefore they are kept for the time necessary in order to protect the interests of En Beautè Parrucchieri di Domenico Floriello from possible responsibilities relating to the supply. Personal data processed for marketing purposes are kept by En Beautè Parrucchieri di Domenico Floriello until the consent given by the user is revoked. If the user revokes the consent, En Beautè Parrucchieri di Domenico Floriello ceases to use the data for such purposes, but keeps the data for the time necessary to protect the interests of En Beautè Parrucchieri di Domenico Floriello from possible liabilities based on such treatments. The personal data processed for the purpose of sending promotional offers to customers will be kept by En Beautè Parrucchieri di Domenico Floriello until the interested party objects to the processing by writing to paoloranieri.commercialista@pec.it

Personal data processed for the purpose of "Fulfillment of legal obligations" will be kept by En Beautè Parrucchieri di Domenico Floriello for the period provided for by specific legal obligations or by applicable legislation. Personal data processed for the purpose of preventing abuse and fraud are kept by En Beautè Parrucchieri di Domenico Floriello for the time strictly necessary for the aforementioned purpose.

10.User Rights. The user has the right to ask En Beautè Parrucchieri di Domenico Floriello at any time:

1. Access to personal data, (and / or a copy of such personal data), as well as further information on the treatments in progress on them (Article 15 of EU Regulation no. 2016/679)

2. The rectification or updating of personal data (Article 16 of EU regulation no. 2016/679)

3. The deletion of personal data from the databases of En Beautè Parrucchieri di Domenico Floriello (Article 17 of EU Regulation no. 2016/679)

4. The limitation of the processing of personal data by En Beautè Parrucchieri di Domenico Floriello art. 18 EU Regulation no. 2016/679);

5. Data portability, that is to obtain in a structured format, commonly used and readable by an automatic device, a copy of your personal data provided or to request its transmission to another Data Controller (Article 20 of EU Regulation no. 2016/679 )

6. Opposition to the processing of personal data (Article 21 of EU Regulation no. 2016/679)

7. The revocation of one's consent to the processing without prejudice to the lawfulness of the treatment based on consent acquired before the revocation (Article 7, paragraph 3 of the EU Regulation

n. 2016/679).

En Beautè Parrucchieri di Domenico Floriello will provide the interested party with information relating to one or more of the actions taken as per the previous list without unjustified delay and, in any case, at the latest within one month of the request itself. This term can be extended by two months, taking into account the complexity and number of requests, informing the user of the necessary extension with a specific informative letter within one month of receipt of the request. The interested party also has the right to lodge a complaint with the competent Supervisory Authority (for Italy, Privacy Guarantor, http://www.garanteprivacy.it), if he considers that the processing of his personal data is contrary to the legislation in force. . The exercise of the rights referred to in this article may be exercised by the interested party at the following email address: paoloranieri.commercialista@pec.it

11. Modifications. This Information is effective from May 21, 2018. En Beautè Parrucchieri di Domenico Floriello reserves the right to modify or update it also due to any regulatory or practice changes coming from the National Control Authority or from the European Protection Committee. some data.

12. Definitions

1. Personal Data: any information concerning an identified or identifiable natural person (interested); the natural person who can be identified, directly or indirectly, is considered to be identifiable, with particular reference to an identi fi cation such as a name, an identification number, location data, an online identi fi cation or one or more characteristic elements of his / her physical identity, physiological, genetic, psychic, economic, cultural or social;

2. Processing: any operation or set of operations, carried out with or without the aid of automated processes and applied to personal data or sets of personal data, such as the collection, registration, organization, structuring, storage, 'adaptation or modification, extraction, consultation, use, communication by transmission, distribution or any other form of making available, comparison or interconnection, limitation, cancellation or destruction;

3. Data Controller: the natural or legal person, public authority, service or other body which, individually or together with others, determines the purposes and means of the processing of personal data; when the purposes and means of such processing are determined by the law of the Union or of the Member States, the data controller or the specific criteria applicable to its designation may be established by the law of the Union or of the Member States;

4. Data Processor: the natural or legal person, public authority, service or other body that processes personal data on behalf of the data controller;

5. Recipient: the natural or legal person, public authority, service or other body that receives communication of personal data, whether it is a third party or not. However, public authorities which may receive disclosure of personal data in the context of a specific investigation in accordance with Union or Member State law are not considered to be recipients; the processing of such data by said public authorities complies with the applicable data protection rules according to the purposes of the processing;

6. Third: the natural or legal person, public authority, service or other body other than the data subject, the data controller, the data processor and the persons authorized to process personal data under direct authority of the owner or manager;

7.Consent of the interested party: any manifestation of free, specific, informed and unequivocal will of the interested party, with which the same expresses his / her consent, by unequivocal positive declaration or action, that the personal data concerning him / her are subject to processing ;

8. Personal Data Breach: the security breach that accidentally or unlawfully involves the destruction, loss, modification, unauthorized disclosure or access to personal data transmitted, stored or otherwise processed;

9.Binding Corporate Rules: the personal data protection policies applied by a data controller or data processor established in the territory of a Member State to the transfer or complex of transfers of personal data to a data controller or controller in one or more third countries, in the context of an entrepreneurial group or group of companies carrying out a common economic activity;

10. Supervisory Authority: the independent public authority established by a Member State pursuant to Article 51;

11.Control Authority Concerned: a supervisory authority involved in the processing of personal data because

a. the Data Controller or the Data Processor is established in the territory of the Member State of this Supervisory Authority;

b. data subjects residing in the Member State of the supervisory authority are or are likely to be substantially affected by the processing;

c. a complaint has been lodged with this supervisory authority.

12.Cross-border processing:

a. processing of personal data that takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State;

b. processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union, but which affects or is likely to substantially affect data subjects in more than one Member State.