PRIVACY POLICY
Welcome to the e-commerce site of Collectable Station (shop.collectablestation.com)!
With this Privacy Policy, Collectable Station informs you about the purposes and methods of processing your
personal data, and your rights as a data subject pursuant to Regulation (EU) 2016/679 ("GDPR") and how you can
exercise them.
1. Data Controller
The data controller is Collectable Station S.r.l., with registered office in Via Nicola Coviello 20, Rome 00165, in the
person of the legal representative pro tempore. You can contact the Data Controller for any question relating to the
processing of your personal data and to exercise your rights as a data subject, as described in paragraph 7 below, by
writing to: info@collectablestation.com.
2. Categories of personal information
In order to allow you to browse the Site and use the different services and features, the Data Controller processesthe following categories of personal information:
o personal information, such as name, surname, address, telephone number, e-mail; o profile image; o data relating to purchases and sales made through the Site; o reviews received as buyer and/or seller; o data contained in requests made through the Site. |
To access the Reserved Area of the Site, you can use the social login offered by Facebook and Google. In such cases,
when you register, the Data Controller will collect from Facebook or Google, depending on the option you choose,
the personal data necessary for the creation of your account.
In addition, the computer systems and software procedures responsible for the operation of this website acquire, in
the course of their normal operation, some personal data whose transmission is implicit in the use of internal
communication protocols, such as the IP addresses or domain names of the computers used by users connecting to
the site, the Uniform Resource Identifier (URI) notation of the requested resources, the time of the request, the
method used in submitting the request to the server, the size of the file obtained in response, the numeric code
indicating the status of the response given by the server (good end, error, etc.) and other parameters related to the
operating system and the computer environment of the user.
The Data Controller does not install cookies except for the technical cookies necessary for the operation of the Site.
3. Purpose of processing
This point 3 contains a description of the processing purposes pursued by the Data Controller depending on the
service requested from time to time.
3.1 Registration and creation of user profile
Your personal data will be processed by the Data Controller to complete your request for registration on the Site and
for the creation of your profile, necessary to access the services offered to registered users.
The process of registration and creation of the reserved area may take place through the social plugins offered by
Facebook and Google, which, under the conditions established by these, will communicate to the Data Controller the
data necessary for the creation of your profile.
Failure to provide the requested data will make it impossible for the Data Controller to continue with the creation of
your profile and, consequently, the impossibility of using the services of the Site connected to the profile-user.
However, at the time of registration, you will be offered the possibility of freely some personal data not necessary
for the creation of your profile that you may decide not to communicate to us.
The legal basis for registration on the Site is the need to execute your request, in compliance with Article 6,
paragraph 1, letter b), GDPR.
3.2 Registered User Services and purchase and sale of goods through the Site
Through the Site, by accessing the Reserved Area, you can buy and/or sell collectables, verify your feedback, add
feedback for third-party buyers and sellers and start grading operations.
The provision of the requested data is necessary to offer you the requested service; therefore, failure to provide the
requested data will make it impossible for the Data Controller to offer you the services requested from time to time.
The legal basis for the processing of your personal data for the purpose of managing the purchase and sale process
through the Site and to provide the additional services related to the Reserved Area is the need to execute the
contract signed with the Data Controller, in compliance with Article 6, paragraph 1, letter b), GDPR.
3.3 Requests made through the Site
Personal data relating to requests made through the Site or the e-mail addresses available on it will be processed by
the Data Controller to meet such requests. Therefore, the Data Controller will process all personal data
communicated by you and in any case necessary for the management of the request itself. To this end, we
encourage you not to disclose personal data not strictly necessary to manage and fulfill your request.
The legal basis of the processing is the need to execute your request, in compliance with Article 6, paragraph 1,
letter b), GDPR.
3.4 Regulatory requirements
For the purposes of managing the Site and the services offered through it, the Data Controller may also process
personal data for the fulfilment of any regulatory obligations provided for by national or Community laws and/or
regulations on the same.
In this case, the legal basis of the processing is the need to comply with a legal obligation, in compliance with Article
6, paragraph 1, letter c), GDPR.
3.5 Management of the Site
Personal data will also be processed by the Data Controller to manage the Site, to carry out anonymous statistical
analysis on the use of the site to check its correct functioning and/ or to ascertain responsibility in case of
hypothetical computer crimes against the Site. In any case, these data are processed anonymously and are deleted
immediately after processing.
The legal basis of the processing is the legitimate interest of the Data Controller to ensure the correct use of the Site
and to prevent any possible cybercrime, in compliance with article 6, paragraph 1, letter f), GDPR.
Your personal data will be made immediately anonymous and in any case deleted at the end of your browsing
session. However, if information offences are found, your personal data will be stored for the time necessary to
manage the dispute.
4. Consequences of a refusal to provide personal data
The provision of your personal data is optional and does not affect the possibility of browsing the Site.
However, the provision of certain personal data is necessary for registration on the Site and to use the various
services accessible through the Reserved Area of your profile. Therefore, failure to provide such data, will make it
impossible for the Data Controller to offer the specific service requested.
5. Communication of your personal data
Your personal data may be disclosed to third parties that the Data Controller uses for the pursuit of the purposes
described above. In any case, Collectable Station has provided these third parties with specific instructions for the
processing of your data and has appointed the same data processors pursuant to Article 28 of the GDPR.
In particular, your personal data will be processed by third parties belonging to the following categories:
a) entities that support the Owner for the management and maintenance of the Site;
b) persons providing legal and/or tax advice.
In addition, your personal data may be transferred, if necessary to perform your requests or to comply with specific
legal obligations imposed on Collectable Station to third parties who will act as independent owners, such as public
authorities, entities that carry out grading activities or counterparties to the purchase and sale service.
The personal data processed by the Data Controller will not be transferred outside the European Union or
disseminated. However, please note that reviews regarding your seller and/or buyer profile will be publicly available
on the Site.
The complete and updated list of subjects to which your personal data may be disclosed can be requested by
contacting the Data Controller.
6. Storage of personal data
Personal data related to your profile and related to the various services will be kept for a maximum of 10 years from
the decision to cancel the account, in accordance with the limitation period provided by the Italian Civil Code, and
only retained for any purpose of defending a right in court or out of court.
7. Your rights and how to exercise them
In relation to the processing described in this Policy, as a data subject you may, under the conditions provided for bythe law on the protection of personal data, exercise the following rights:
o right of access - obtain confirmation that personal data, information relating to such processing and a copy of the personal data processed are being processed or not; o right of rectification - to obtain the rectification of inaccurate personal data and/or the integration of incomplete personal data; o right to erasure (right to be forgotten) - to certain conditions, obtain the erasure of personal data concerning you; o right to restriction of processing - subject to certain conditions, obtain the limitation of the processing of your personal data; o the right to data portability - to receive, in a structured, commonly used and machine-readable format, your personal data and the right to transmit it (or obtain it to be transmitted) to another data controller; o right to object - object, at any time, to the processing of personal data based on the legitimate interest of the Data Controller, unless there are legitimate reasons to continue the processing that outweigh the interests, the rights and freedoms of the data subject or for the establishment, exercise or defence of a right in court; o the right to withdraw consent; o submit a complaint to the Italian Data Protection Authority, Piazza Venezia 11, 00187 - Rome, also by writing to: protocollo@gpdp.it. |
The above rights may be exercised, against the Data Controller, by contacting the references indicated in point 1
above.
Collectable Station undertakes to provide you with feedback free of charge and without delay and at the latest
within one month of receipt of your request. However, in the case of manifestly unfounded or excessive requests,
also for their repetitiveness, the Holder may charge a reasonable fee in the light of the administrative costs incurred
or deny the satisfaction of the request. In addition, Collectable Station may request additional information necessary
to confirm your identity.