PRIVACY NOTICE PURSUANT TO ARTICLE 13 OF EU REGULATION 2016/679 BY ARENA S.P.A., Società Benefit
1. Introduction
For Arena, your privacy and the security of your personal data are important. We treat your data with the utmost care, adopting the necessary technical and organizational measures to ensure its full security in accordance with European Regulation 2016/679 (hereinafter "GDPR") and the applicable national regulations. The personal data collected during your interaction with our website will be processed manually or by electronic or automated, IT, or telematics means. As we use cookies, we invite you to review the relevant policy for further details regarding this matter. You can do so by accessing the following link: https://www.arenasport.com/en_uk/cookie-policy
2. Definitions
The following definitions are used in this document.
Personal Data: Any information relating to an identified or identifiable natural person, which, alone or in combination with other data or by using information technology techniques, can identify a person. Examples of personal data include name, address, identification document number, email address, and telephone number.
Processing: Any operation, automated or not, performed on personal data, such as collection, recording, storage, consultation, use, or deletion.
Data Controller: The legal entity that determines the purposes and means of processing personal data.
Data Processor: The natural or legal person who processes personal data on behalf of the Data Controller.
Data Subject: The identified or identifiable natural person to whom the personal data relates.
3. Identity and Contact Details of the Data Controller and Data Protection Officer (DPO)
The processing of your personal data is carried out by Arena S.p.A., Società Benefit, (hereinafter "Arena"), with its registered office at Tolentino (MC), Italy, C.da Cisterna 84/85, acting as the Data Controller.
For any questions and/or requests regarding the processing of your personal data, you can contact us at the following details:
Arena S.p.A.
Contrada Cisterna, 84/85, 62029, Tolentino (Macerata, Italy)
Phone: +39 0733 956 200
Email: privacy@arenasport.com
Arena also employs an external Data Protection Officer (DPO), a lawyer specialized in privacy protection, who provides the necessary consultancy to ensure compliance with the law and monitors Arena's activities in this area to ensure our reliability. If preferred, you can also contact the DPO via email at: dpo@arenasport.com.
4. Types of Data and Purposes of Processing
The personal data that Arena processes are those you provide when making a purchase or interacting with our online services. Your personal data, once collected, will be processed for the following purposes:
Purpose | Legal basis | |
---|---|---|
A | To allow you to register on the website www.arenasport.com | Contractual necessity, no explicit consent required. |
B | To fulfill obligations set by national and/or European laws and regulations or requirements by Authorities and Supervisory Bodies | Legal obligation, consent not required. |
C | To ensure the proper functioning of our web pages and content | Legitimate interest of the Data Controller, no explicit consent required. |
D | To carry out direct promotional activities, such as sending newsletters to the email address you provided upon registration | Consent required. Exception: communications regarding similar products/services to those already purchased/subscribed to are based on the legitimate interest of the Data Controller. |
E | To assess your experience with our online services, products, and offerings | Consent required. |
The provision of your data for purposes A), B), and C) is mandatory. If you do not provide your data, we will not be able to ensure the proper functioning of the site and/or the usability of the services offered. Providing data for purposes D) and E) is optional. If you do not provide this data, it will not affect the proper functioning of the site or the full usability of the services offered.
5. Categories of Recipients of Personal Data
Your personal data is processed by Arena’s personnel, specifically authorized in accordance with Article 4, paragraph 10 of the GDPR, under Arena's instructions. It may happen that third parties process your data on our behalf. These third parties are carefully selected to ensure compliance with GDPR standards. These parties are appointed as Data Processors under Article 28 of the GDPR and are required to carry out their activities under Arena's instructions and supervision.
These parties may include: financial operators, internet providers, IT service companies, couriers, marketing agencies, market research and data processing companies, companies handling online sales operations. A specific and updated list of these parties is available at Arena's headquarters and can be consulted upon request.
Data may also be transmitted to third parties in the event of mergers, acquisitions, company transfers, or other corporate operations, as well as to anyone entitled to receive communications under legal or regulatory provisions. For the purposes outlined above, your data may also be shared with other companies within the Arena Group, which will process the data in accordance with applicable laws.
Your data may also be transmitted to law enforcement authorities or judicial/administrative bodies for the detection and prosecution of crimes, prevention, and safeguarding public security, or to enable Arena to exercise or protect a legal right before the competent authorities, or for other reasons related to the protection of the rights and freedoms of others.
6. Data Transfers Outside the EU
Generally, your data will not be transferred outside the European Union or to countries that are not considered adequate in terms of EU data protection standards. If this happens, the transfer will be carried out in compliance with EU regulations and based on agreements containing the so-called "Standard Contractual Clauses" issued by the European Commission or otherwise in accordance with the latest provisions from the Data Protection Authority.
7. Data Retention
Your data will be stored for the shortest period possible, depending on the type of processing and the specific purposes of processing. In particular:
- Data collected during your registration on our site will be stored for a maximum of five years.
- Data collected for other services offered by Arena will be stored until the service ends, and in any case, for no longer than five years.
- Data provided for customer service requests will be stored for no more than five years.
- Data provided for commercial communications, opinion surveys, and market research will be stored for two years from your last interaction. After this period, we may ask you to renew it. If not, the data will be deleted or irreversibly anonymized.
8. Data Subject Rights
In accordance with the GDPR, you have the right to:
- Access (Article 15 GDPR): You have the right to request whether your data is being processed, the type of processing, and a copy of your data.
- Rectification (Article 16 GDPR): You have the right to request the correction of incomplete or inaccurate data.
- Erasure (Article 17 GDPR): In cases provided by law, you can request the deletion of your personal data.
- Restriction (Article 18 GDPR): You have the right to request the restriction of the processing of your personal data in case of unlawful processing or if the data you provided is inaccurate.
- Portability (Article 20 GDPR): You have the right to transfer your data to another controller if the processing is based on consent and is automated.
- Objection (Article 21 GDPR): You have the right to object to the processing of your personal data for direct marketing or other specific cases mentioned in your request.
- Complaint (Article 77 GDPR): You have the right to file a complaint with the Data Protection Authority if you believe Arena has violated your privacy rights.
- Withdrawal of Consent (Article 7 GDPR): You have the right to withdraw consent at any time by contacting Arena using the details provided in paragraph 3. For more information, you can request a full copy of the GDPR articles mentioned above by contacting Arena via email.
9. Security Measures
Arena adopts appropriate and preventive security measures to safeguard the confidentiality, integrity, completeness, and availability of your personal data. Our websites use encryption systems for information both on the login page and in other sections where you can provide, view, or modify your personal data. Arena is not responsible for the processing of false data or data submitted fraudulently.
10. Changes to this Notice
The constant evolution of our services may lead to changes in the characteristics of the processing of your personal data, which we will inform you of as promptly as possible. We therefore invite you to periodically review the contents of this notice, which will always be published on our website with the date of the last update.
Last Update: January 15, 2025