Data Collection for Account Services
Personal data is collected for account creation, loyalty programs, and user interactions.
🌐 www.lafeltrinelli.it
Limits data use, explains security measures, but lacks detail on biometrics and location data.
Clearly references GDPR, outlines legal bases, and details user rights.
Provides user rights but includes broad data sharing with partners.
Structured but legalistic; some plain language used.
The document provided is not a standard privacy policy text but appears to be the HTML source code of a webpage, likely for an e-commerce site (LaFeltrinelli). The privacy policy section is embedded within this code. Analyzing the privacy policy content reveals several problematic aspects.
The privacy policy states that Feltrinelli S.p.A. and LaFeltrinelli Internet Bookshop S.r.l. are joint data controllers (Contitolari) as of January 1, 2020, but notes that data for users registered before this date continues to be processed solely by Feltrinelli. This creates a fragmented governance structure where user rights may differ based on registration date, complicating compliance and user understanding.
The policy mentions the use of Google's Advanced Conversions, which involves sharing hashed user data (like email) with Google for ad measurement and personalization based on legitimate interest. The reliance on legitimate interest for sharing personal data for advertising purposes is a significant legal basis that requires a robust assessment, which is not demonstrated to the user, and may not align with user expectations of privacy.
A chatbot service collects user data including geolocation (if enabled by the user). While the legal basis is contract execution, the collection of geolocation for a customer service chatbot may be perceived as excessive or not strictly necessary for the service's core function.
For WhatsApp services, the policy states that minors under 18 should not provide data without parental consent, but it places the responsibility on the user to declare their age. This is a weak age verification mechanism that may not effectively protect minors' data, potentially violating provisions like those in the GDPR concerning children's data.
The policy lists "Soft Spam" as a purpose, using the legal basis of legitimate interest to send promotional emails for similar products/services to those previously purchased. While this may be permitted under Italian law (Art. 130(4) of the Privacy Code), it conflicts with the high standard for legitimate interest under the GDPR. Users have a right to object, but pre-checked consent or opt-out mechanisms for direct marketing are generally not considered compliant with the GDPR's standard for affirmative consent.
Data retention periods are extensive. For core contractual services (A, C, D, E), data is kept for 10 years after the contractual relationship ends. For marketing and profiling (F, G, H), data is kept for up to 36 months from the last purchase or until consent is withdrawn. A 10-year post-contract retention period is exceptionally long and may not be justified as necessary or proportionate for the stated purposes, raising compliance issues with the GDPR's storage limitation principle.
The policy mentions an "Accordo di Contitolarità" (Joint Controller Agreement) and a separate trilateral agreement with Rakuten Kobo Inc. for e-book services. While required by Article 26 GDPR, the policy only states that the "essential content" can be requested. This lacks transparency, as the key details of how responsibilities are allocated and how users can exercise their rights against each controller are not immediately accessible within the policy itself.
For profiling (purpose G), the policy states it involves automated analysis of user habits and preferences to send personalized commercial offers. While consent is the basis, the policy does not provide meaningful information about the logic involved, the significance of the processing, or its consequences for the user, as arguably required by Articles 13(2)(f) and 15(1)(h) GDPR for automated decision-making/profiling.
The policy states that data may be communicated to partners in a wide range of sectors (publishing, cinema, music, banking, insurance, etc.) for their own marketing purposes (purpose H), based on user consent. The categories of partners are very broad and non-specific, which may not constitute valid, informed consent as the user cannot reasonably foresee the specific future recipients.
While security measures like TLS and not storing full credit card details are mentioned, the policy
Personal data is collected for account creation, loyalty programs, and user interactions.
Marketing communications and profiling require explicit, revocable user consent.
Data may be shared with group companies and partners for commercial communications.
Data is retained for up to 10 years post-contract or 36 months for marketing.
Users have rights to access, correct, delete, and port their personal data.
Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.
Add Termzy AI to the Browser - It's Free