PRIVACY POLICY

Prada S.p.A., with its registered office in Milan (Italy), the operating holding company of the Prada Group (define below) and site manager of www.prada.com together with its subsidiary Prada Germany GmbH, with registered office in München (Germany), the company directly operates the selling of products offered on www.prada.com/de/ (the “Website”) (Prada S.p.A. and Prada Germany GmbH are referred together as “PRADA”, “we” or “us”), are committed to protecting the confidentiality, integrity and security of your personal information (“Personal Data”), and hereby inform you that any Personal Data which you provide to PRADA through the Website, as well as any Personal Data which you may provide us by phone or in stores operated by PRADA and its subsidiaries and/or affiliates (collectively the “Prada Group”), will be processed in compliance with the European General Data Protection Regulation (Regulation (EU) 2016/679 – “GDPR”) and any local regulations on data protection applicable from time to time, together with the principles and general rules of conduct contained in the Code of Ethics adopted by the Prada Group.

1. Type and source of data

Browsing data
During their normal operation, the computer systems and software procedures used to operate our Website collect certain personal data (log files). The transmission of such data is inherent to the use of internet communication protocols. This information is not collected in order to be associated with specific data subjects. However, due to its nature, this information can allow users to be identified by means of its processing and integration with data held by third parties. Such information includes the IP addresses or domain names of the device you use to visit our Website, URIs (Uniform Resource Identifiers) of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical status code of the server reply (successful, error, etc.) and other parameters concerning the user's operating system and computer environment. This data is used with the sole purpose of obtaining anonymous statistical information on the use of our Website and to guarantee its correct operation.

Cookies
Our Website uses cookies to ensure its efficient functioning and to improve our services. Cookies are small text files that are sent to the terminal you use to access to the Internet (usually to your browser) by the websites you visit. Cookies are stored in your computer to be recognized by those websites on your subsequent visits. For more information on cookies, on the types of cookies used on our Website, on how to disable them and on how you can revoke your consent or manage your preferences, see our cookie policy.

Personal Data voluntarily provided by the data subject
We collect and process the Personal Data that you directly and voluntarily provide through our Website when (i) you place online orders; (ii) register to our Website by creating your online account; and/or (iii) you use other functionalities available on the Website (for example: to subscribe to our newsletter service, to send a request to our Client Service, to book an appointment in store, to connect or interact with us through social networks, etc).
PRADA may also collect and process the Personal Data that you provide at a Prada Group store when you purchase our products or use our services or choice to register into the Prada Group customer database by filling in and signing our customer card (“Customer Card”), as well as during your interactions with our Client Service or our sale staff.
If you decide to register to the Website through the social login function, please be informed that we will have access to the Personal Data of your social account (for example, your email address and your public profile) in accordance with the privacy settings of the applicable social media platform. For more information, please refer to the related privacy statements on the applicable social media platform. We do not oversee or control such social media services or user profiles on these platforms and do not establish privacy settings or rules regarding how Personal Data is used on such platforms.
The items of Personal Data collected may include personally identifiable information (title, first and last name, location and date of birth), contact, shipping and billing details (postal address, email, telephone), details of purchases, payment information and/or any other information regarding you that you may decide to provide us during the interactions with our Client Service or our sale staff.
We may also obtain information about you as a result of authentication or identity checks (for example, you will be asked to present your identity document when you pick up your purchase in-store).
Furthermore, when you voluntarily send us an e-mail through our Website and/or to the addresses indicated in our Website, we collect your e-mail address so that we can reply to any request, as well as any additional Personal Data contained in your message.

Personal Data of minors
You must be at least 16 years old (or older depending on your country or state of residence) in order to provide us with Personal Data and at least 18 years old to purchase products from our Website.
If we have actual acknowledge that a minor has provided, through the Website or otherwise, their Personal Data without a verifiable parental consent, we will de-activate the minor’s account and take all reasonable measures to delete or make anonymous the minor’s Personal Data from our systems.

2. Purposes and legal bases of the processing

Your Personal Data may be processed and used for the following purposes:

(a) to respond to all your requests and to manage your relationship with PRADA;
(b) to fulfil your purchase orders and perform all management activities connected with it (including administrative management of the contract, delivery of goods, payment processing and fraud prevention, invoicing, handle returns and refunds, management of any claims and litigation) and to comply with any applicable legal or regulatory obligations.
(c) to send by email the newsletters and other marketing communication regarding “Prada” and other Prada Group’s products, services, initiatives and events as a result of your subscription to the service.

Furthermore, if you are a registered customer (e.g. as a result of your online account registration or your subscription of the Customer Card), your Personal Data may be processed together with the details of your purchases online and/or in stores, for the following purposes:

(d) to confirm your identity as a registered Prada Group customer and, consequently, to provide a customized customer care service and post-sales assistance and allow you to access exclusive services and benefits reserved for registered members (e.g. preservation of your purchase order history, faster online checkout, simplified procedures for product repair and warranty, commercial discounts, pre-sale and other promotional events, etc.);
(e) profiling: to perform individual or group studies, surveys, statistical analysis and/or market research with regards to your preferences for “Prada” and the other brands, products and services of the Prada Group, so that a personalised service can be offered and cultural and recreational activities may be promoted based on customer’s interests;
(f) marketing: to contact you and/or send you (by post, telephone, e-mail and any other form of electronic communication or digital means including social network platforms and other instant messaging applications) information and promotions, including commercial information, newsletters, advertising, catalogues and invitations to events concerning “Prada” and the other brands, products and services of the Prada Group.

The Personal Data processing referred to in subsections (a), (c) and (d) is necessary to provide the service requested by the data subject. The processing referred to subsection (b) is necessary to execute the contract with the data subject or the related pre-contractual measures and to fulfill the connected legal obligations of an administrative and fiscal nature. Further, the data processing referred to in subsections (e) and (f) is based on the prior consent of the data subject. If you do not consent, you may still make your purchase orders and use our services.

3. Nature of the provision of personal data

The provision of your Personal Data is optional.
However, if you wish to purchase products offered on our Website, create an online account and register to the Prada Group customer database, receive information on Prada Group’s products and/or use any of our other services offered online and offline, you need to fill in all mandatory fields of the relevant forms, otherwise we cannot proceed with the contractual services requested.
The provision of your Personal Data for the purposes of profiling and marketing, indicated in section 2 above letters (e) and (f), is subject to your express prior consent. If you withhold your consent, we may not be able to proceed with the indicated purposes, including the ability to offer you personalised services, inform you of any initiatives that may interest you and/or send you any other commercial information on products, initiatives and events of the Prada Group.

You may withdraw your consent to the processing of your Personal Data at any time, by writing to the Data Controller at the contact addresses indicated in section 8, or by using the “unsubscribe” link included in all of our commercial electronic communications, and/or by using any other procedures which we may make available to you (e.g. by logging into your online account), as appropriate.

4. Processing Methods

Your Personal Data will be processed by suitable electronic or automated means and computerized tools, or manually and on hard copy, exclusively for the purposes for which the data have been collected and guaranteeing the security and confidentiality of any processed information through the adoption of appropriate measures to prevent the alteration, cancellation, destruction, unauthorized access or not allowed processing or actions not in accordance with the purpose of collection.
Your Personal Data will be processed by the PRADA internal staff committed to the confidentiality and duly authorised to do so under their respective job duties.

5. Transfer and disclosure of data

Whenever necessary and/or instrumental to the abovementioned purposes, PRADA may delegate the processing of your Personal Data to other Prada group companies or outside service providers (e.g. software and system technology service providers, risk control service provider, payment service providers, couriers, etc.), who will act on behalf of PRADA as data processors with a contractual obligation of confidentiality of the personal information. The service providers will not use any Personal Data beyond the scope of the work outsourced and will retain data only to the extent necessary for the execution of the outsourcing agreement.
As PRADA is part of an international network your Personal Data may be transferred abroad, even temporarily, in accordance with applicable legislation, including to countries outside the European Union where PRADA pursues its interests, by adopting all appropriate security measures and safeguards to ensure an adequate level of data protection and security.
Your Personal Data will not be used for third-party advertising purposes or for the promotion of products, services or initiatives by entities other than the Prada Group, nor shall they be disclosed to unknown persons under any circumstances.

Data communication within the Prada Group
Please also note that if you elect to register on the Prada Group customers database for the purposes referred to in sections 2, letters (d)-(f), your Personal Data will be automatically visible to, and shared with, all Prada Group stores globally (also in countries not belonging to the European Union) to provide you with the same level of service around the world. PRADA will take all appropriate and suitable security and confidentiality measures as required by applicable legislation to ensure an adequate standard of data protection, as well as in compliance with article 49, paragraph 1 letter b) of the GDPR, where the data transfer is necessary for the implementation of pre-contractual and contractual measures adopted at the data subject’s request.

6. Retention period

Your Personal Data will be processed and stored for: (i) as long as required to carry out the purposes for which the data were collected, (ii) in accordance with the storage periods provided for by the applicable laws, or (iii) until you revoke your consent to the processing, if applicable.  After the conclusion of such period(s), and where there is no legal or business purposes for retaining your Personal Data, it will be automatically and permanently erased or made anonymous.
In particular, regarding the data processing of registered customers:

- Personal Data collected for the purposes of customer management to offer personalized services and advantages reserved for registered members, are kept for a period of 7 years from the date of your last interaction with the Prada Group; and
- Purchase details are kept for a period of 7 years from the date of purchase.

7. Your rights

Please note that you may exercise the rights under the applicable privacy laws (and in particular under the articles 15 to 21 of the GDPR), including the right to request information as to whether your Personal Data is being processed and as to the characteristics of the processing, the right to rectification and erasure of your Personal Data, the right to limitation of the data processing, to object to their processing, to request the transmission of your Personal Data to another controller, and/or the right to lodge a complaint with the competent supervisory authority, including the Italian Garante per la protezione dei dati personali (www.garanteprivacy.it) or take legal action if you believe there is noncompliance with the provision of the applicable laws.
You also have the right to withdraw your consent for the processing of your Personal Data at any time, without charge. The withdrawal of your consent will not affect the lawfulness of processing based on your consent before its withdrawal.

8. Data controllers and contacts

For the purposes referred to in section 2 letters (a) and (b) the Data Controller is:

Prada Germany GmbH
Residenzstrasse 10, 80333 München (Germany)

For the other purposes referred to in section 2 letters (c) to (f) the Data Controller is:

Prada S.p.A.
Via Antonio Fogazzaro 28, Milan (Italy)

Group Data Protection Officer
E-mail: privacy@prada.com.

If you have any request regarding your Personal Data, have any inquiries regarding this Privacy Policy or you would like to exercise your rights, please contact (free on charge) the Data Controller or the Group Data Protection Officer by writing to the addresses/email address listed above.
We reserve the right to amend this Privacy Policy at any time. The Privacy Policy currently in force is the one published on the Website.

Last updated: March 03rd, 2022