Privacy Policy

La Feltrinelli's Privacy Policy Overview

🌐 www.lafeltrinelli.it

La Feltrinelli is an Italian bookshop chain and e-commerce platform operated by Feltrinelli S.p.A. and LaFeltrinelli Internet Bookshop S.r.l., offering books, music, movies, and cultural products.
AI-Powered Analysis
Last analyzed March 29, 2026 15:05
View Original Privacy Policy
74
Moderate Score

Overall Rating: 74/100

Based on analysis of data protection, legal compliance, transparency, and fairness

75

User Data Protection

Limits data use, explains security measures, but lacks detail on biometrics and location data.

85

Legal Compliance

Clearly references GDPR, outlines legal bases, and details user rights.

65

Balance & Fairness

Provides user rights but includes broad data sharing with partners.

70

Transparency & Readability

Structured but legalistic; some plain language used.

AI Summary

The document provided is not a standard privacy policy text but appears to be the HTML source code of a webpage, likely for an e-commerce site (LaFeltrinelli). The privacy policy section is embedded within this code. Analyzing the privacy policy content reveals several problematic aspects.

The privacy policy states that Feltrinelli S.p.A. and LaFeltrinelli Internet Bookshop S.r.l. are joint data controllers (Contitolari) as of January 1, 2020, but notes that data for users registered before this date continues to be processed solely by Feltrinelli. This creates a fragmented governance structure where user rights may differ based on registration date, complicating compliance and user understanding.

The policy mentions the use of Google's Advanced Conversions, which involves sharing hashed user data (like email) with Google for ad measurement and personalization based on legitimate interest. The reliance on legitimate interest for sharing personal data for advertising purposes is a significant legal basis that requires a robust assessment, which is not demonstrated to the user, and may not align with user expectations of privacy.

A chatbot service collects user data including geolocation (if enabled by the user). While the legal basis is contract execution, the collection of geolocation for a customer service chatbot may be perceived as excessive or not strictly necessary for the service's core function.

For WhatsApp services, the policy states that minors under 18 should not provide data without parental consent, but it places the responsibility on the user to declare their age. This is a weak age verification mechanism that may not effectively protect minors' data, potentially violating provisions like those in the GDPR concerning children's data.

The policy lists "Soft Spam" as a purpose, using the legal basis of legitimate interest to send promotional emails for similar products/services to those previously purchased. While this may be permitted under Italian law (Art. 130(4) of the Privacy Code), it conflicts with the high standard for legitimate interest under the GDPR. Users have a right to object, but pre-checked consent or opt-out mechanisms for direct marketing are generally not considered compliant with the GDPR's standard for affirmative consent.

Data retention periods are extensive. For core contractual services (A, C, D, E), data is kept for 10 years after the contractual relationship ends. For marketing and profiling (F, G, H), data is kept for up to 36 months from the last purchase or until consent is withdrawn. A 10-year post-contract retention period is exceptionally long and may not be justified as necessary or proportionate for the stated purposes, raising compliance issues with the GDPR's storage limitation principle.

The policy mentions an "Accordo di Contitolarità" (Joint Controller Agreement) and a separate trilateral agreement with Rakuten Kobo Inc. for e-book services. While required by Article 26 GDPR, the policy only states that the "essential content" can be requested. This lacks transparency, as the key details of how responsibilities are allocated and how users can exercise their rights against each controller are not immediately accessible within the policy itself.

For profiling (purpose G), the policy states it involves automated analysis of user habits and preferences to send personalized commercial offers. While consent is the basis, the policy does not provide meaningful information about the logic involved, the significance of the processing, or its consequences for the user, as arguably required by Articles 13(2)(f) and 15(1)(h) GDPR for automated decision-making/profiling.

The policy states that data may be communicated to partners in a wide range of sectors (publishing, cinema, music, banking, insurance, etc.) for their own marketing purposes (purpose H), based on user consent. The categories of partners are very broad and non-specific, which may not constitute valid, informed consent as the user cannot reasonably foresee the specific future recipients.

While security measures like TLS and not storing full credit card details are mentioned, the policy

📋 Key Clauses Analyzed

Data Collection for Account Services

Personal data is collected for account creation, loyalty programs, and user interactions.

Marketing and Profiling Consent

Marketing communications and profiling require explicit, revocable user consent.

Data Sharing with Third Parties

Data may be shared with group companies and partners for commercial communications.

Data Retention Periods

Data is retained for up to 10 years post-contract or 36 months for marketing.

User Rights and Access

Users have rights to access, correct, delete, and port their personal data.

❓ Questions About This Privacy Policy

✨ AI Enhanced Answers
Generating AI response
Feltrinelli S.p.A. and LaFeltrinelli Internet Bookshop S.r.l. are joint data controllers (Contitolari) as of January 1, 2020. However, data for users registered before this date continues to be processed solely by Feltrinelli, creating a fragmented governance structure where user rights may differ based on registration date. This complicates both compliance and user understanding of who is responsible for their data.
Generating AI response
The policy mentions the use of Google's Advanced Conversions, which involves sharing hashed user data such as email with Google for ad measurement and personalization. This processing relies on the legal basis of legitimate interest, which is a significant basis requiring a robust assessment that is not demonstrated to the user. This reliance may not align with user expectations of privacy.
Generating AI response
The chatbot service collects user data including geolocation if enabled by the user, with the legal basis being contract execution. However, the collection of geolocation for a customer service chatbot may be perceived as excessive or not strictly necessary for the service's core function.
For WhatsApp services, the policy states that minors under 18 should not provide data without parental consent, but it places the responsibility on the user to declare their age. This is a weak age verification mechanism that may not effectively protect minors' data, potentially violating provisions like those in the GDPR concerning children's data.
For core contractual services (A, C, D, E), data is kept for 10 years after the contractual relationship ends, which is exceptionally long and may not be justified as necessary or proportionate under the GDPR's storage limitation principle. For marketing and profiling (F, G, H), data is kept for up to 36 months from the last purchase or until consent is withdrawn.

Never blindly click "agree" again

Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.

Add Termzy AI to the Browser - It's Free
🎉

Thank You for Using Termzy AI!

You're getting the full experience with complete policy analysis, all clauses unlocked, and unlimited FAQ access.