Prada S.p.A., with registered office in Milan (Italy), the operating holding company of the Prada Group and site manager of www.prada.com (the “Website”), together with its subsidiary, Prada Taiwan Limited Taiwan branch, with its registered branch office in Taiwan, the Prada Group’s entity directly operating the selling of products offered on the Website with shipping in Taiwan (Prada S.p.A. and Prada Taiwan Limited Taiwan branch are referred together as “PRADA”) recognise the importance of maintaining the confidentiality, integrity and security of your personal data (hereinafter, “Personal Data”), and hereby inform you that any Personal Data which you provide to PRADA through our Website, as well as any Personal Data which you may provide to a Prada Group store, including through its subsidiaries and/or affiliates (collectively the “Prada Group”), will be processed in compliance with current applicable laws on privacy and with any specific local regulations applicable from time to time, including the Personal Information Protection Act 2010 in Taiwan (“PDPA”) and the European General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), together with the principles and general rules of conduct contained in the Code of Ethics adopted by the Prada Group.
1. Type and source of data
During their normal operation, the computer systems and software procedures used to operate our Website collect certain personal data (log files). The transmission of such data is inherent to the use of internet communication protocols. This information is not collected in order to be associated to specific data subjects. However, due to its nature, this information can allow users to be identified by means of their processing and integration with data held by third parties. Such information includes the IP addresses or domain names of the computers you use to visit our Website, URIs (Uniform Resource Identifiers) of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical status code of the server reply (successful, error, etc.) and other parameters concerning the user's operating system and computer environment. This data is used with the sole purpose of obtaining anonymous statistical information on the use of our Website and to guarantee its correct operation.
Personal Data voluntarily provided by the data subject
PRADA collects, processes and uses the Personal Data that you directly and voluntarily provide through our Website when (i) you place online orders, (ii) register to our Website and/or (iii) you use other functionalities available on the Website (for example, to subscribe to our newsletter, to send a request to our Customer Service, to book an appointment in store, to connect or interact with us through social networks, etc). PRADA may also collect, process and use the Personal Data that you may provide by filling in and signing our customer card (“Customer Card”) at a Prada Group’s store.
If you decide to register to the Website through the social login function, please be informed that PRADA will have access to the Personal Data of your social account (for example, your email address and your public profile) in accordance with the privacy settings of the applicable social media platform. For more information, please refer to the related privacy statements on the applicable social media platform; PRADA does not oversee or control such social media services or user profiles on these platforms and does not establish privacy settings or rules regarding how Personal Data is used on such platforms.
The items of Personal Data collected may include personally identifiable information (title, first and last name, location, date of birth), contact and billing details (delivery and billing addresses, postal address, email address, telephone ), details of purchases and/or other information regarding you that you may decide to provide during interactions with our Client Service or with sales staff.
Furthermore, when you voluntarily send an e-mail through our Website and/or to the addresses indicated in our Website, we collect your e-mail address, as well as any additional Personal Data contained in your message, so that we can reply to any request.
If you call our Client Service team or our Client Service team contacts you with the details you have provided to us, please note that calls may be recorded for quality assurance and record-keeping purposes.
In addition, we may also obtain information about you as a result of authentication or identity checks (for example, you will be asked to present your identity document when you pick up your purchase in-store). PRADA uses this information to identify you as a customer, to process your order, to deliver products and services, to process payments.
Your credit card data (including credit card numbers and other payment information) are provided to our payment services providers who process payment details further. PRADA does not store or maintain your credit card data or use it directly.
Personal Data of minors
You must be at least 16 years old (or older depending on your country or state of residence – 20 years old in Taiwan) in order to provide us with Personal Data and at least 20 years old to purchase products from our Website.
PRADA protects the Personal Data of minors in accordance with the relevant national laws and regulations.
If PRADA discovers that it has collected Personal Data about a minor, it will de-activate the minor’s account and try to delete the data as soon as possible.
2. Purpose and legal bases of the processing
Your Personal Data may be processed and used for the following purposes:
- (a) to respond to all your requests and to manage your relationship with PRADA;
- (b) to fulfil your online purchase orders and perform all management activities connected with it (including administrative management of the contract, delivery of goods, payment processing, management of any claims and litigation, and fraud prevention), and to comply with any applicable legal or regulatory obligations;
- (c) to send by email the newsletters and other marketing communication regarding Prada Group’s products, services, initiatives and events as a result of your subscription to the service.
Furthermore, if you agree to register to the Prada Group customer database (as a result of your registration to the Website, or your signing the Customer Card at a Prada Group store), your Personal Data will be managed by the holding company PRADA S.p.A., and shared with all Prada Group stores globally, and may be processed and used, together with the details of your purchases online and/or in stores, for the following purposes:
- (d) to confirm your identity as a registered Prada Group customer and, consequently, to provide a customized customer care service and post-sales assistance and allow you to access exclusive services and benefits reserved for registered members (e.g.: preservation of the purchase order history, faster online checkout, simplified procedures for product repair and warranty, commercial discounts, pre-sale and other promotional events, etc.);
- (e) profiling: to perform individual or group studies, surveys, statistical analyses and/or market research with regards to your preferences for Prada and the other brands, products and services of the Prada Group, so that a personalised service can be offered and cultural and recreational activities may be promoted based on customers’ interests;
- (f) marketing: to contact you and/or send you (by post, telephone, e-mail and any other form of electronic communication or digital means including social network platforms and other instant messaging applications) information and promotions, including commercial information, newsletters, advertising, catalogues and invitations to events concerning Prada and the other brands, products and services of the Prada Group.
The Personal Data processing referred to in subsections (a), (c) and (d) is necessary to provide the service requested by the data subject. The processing referred to subsection (b) is necessary to execute the contract with the data subject or the related pre-contractual measures and to fulfill the connected legal obligations of an administrative and fiscal nature. Further, the data processing referred to in subsections (e) and (f) is based on the prior consent of the data subject.
3. Nature of the provision of personal data
The provision of your Personal Data is optional.
However, if you wish to make a purchase order for products offered on our Website, register to the Prada Group Customers database, receive information on Prada Group’s products and services, and/or use any other services offered on the website, you need to fill in all mandatory fields of the relevant forms, otherwise PRADA cannot proceed with the contractual services requested.
The provision of your Personal Data for the purposes of profiling and marketing indicated at letters (e) and (f) of section 2 above is subject to your prior express consent. If you withhold your consent, we may not be able to proceed with the indicated purposes, including the ability to offer you a personalised service, inform you of any initiatives that may interest you and/or send you any other commercial information on products, initiatives and events of the Prada Group.
You may withdraw or modify your consent to the processing of your Personal Data by us at any time, by sending an e-mail to firstname.lastname@example.org, or by using the “unsubscribe” link included in all of our commercial electronic communications, and/or by using any other appropriate procedures which may be made available to you by PRADA (e.g. by logging into your online account).
4. Processing Methods
Your Personal Data will be processed by suitable electronic or automated means and computerised tools, or manually and on hard copy, exclusively for the purposes for which they have been collected and guaranteeing the security and confidentiality of any processed information through the adoption of appropriate measures to prevent the alteration, cancellation, destruction, unauthorized access or processing or actions not in accordance with the purpose of collection. Your Personal Data will be processed only by the Prada Group’s internal staff duly committed to confidentiality and duly authorised to do so under their respective job duties.
5. Transfer and disclosure of data
Whenever necessary and/or instrumental to the above purposes, your Personal Data may be processed on behalf of PRADA by other entities engaged by PRADA in the correct and regular pursuit of the described purposes, including:
- Prada Group companies and franchisees that operate Prada Group stores;
- Third party service providers, consultants and firms providing advisory and/or consulting activities, or performing related services that are instrumental to data processing on behalf of PRADA (e.g. service providers, carriers, IT technicians or any other suppliers appointed by PRADA to carry out and/or manage any promotional campaigns for PRADA’s products and services, etc.).
These third parties will act on behalf of PRADA as data processor and are under a contractual obligation of confidentiality of the personal information.
As PRADA is part of an international network and uses global services your Personal Data may be transferred abroad, even temporarily, in accordance with applicable legislation, including to locations outside Taiwan (R.O.C.) and the European Union (click here to see the jurisdictions in which the Prada Group and its service providers operate), by adopting all appropriate security measures and safeguards to ensure an appropriate level of data protection and security.
Your Personal Data will not be used for third-party advertising purposes or for the promotion of products, services or initiatives by entities other than the Prada Group, nor shall they be disclosed to unknown persons under any circumstances.
Communication of data to the other PRADA Group companies
Please also note that if you register on the Prada Group customer database for the purposes referred to in sections 2, letters (d)-(f), your Personal Data will be automatically visible to, and shared with, all Prada Group stores globally to provide you with the same level of service around the world. PRADA will take all appropriate and suitable security and confidentiality measures as required by applicable legislation to ensure an adequate standard of data protection, as well as in compliance with article 49, paragraph 1 letter b) of the GDPR, as the data transfer is necessary for the implementation of pre-contractual and contractual measures adopted at the data subject’s request.
6. Retention period
Your personal data will be processed and stored for: (a) as long as required to carry out the for purposes which the Personal Data were collected, (b) in accordance with the storage periods provided for by the applicable laws, or (c) until you revoke your consent to the processing/storage of your Personal Data, if applicable. After the conclusion of such period(s) and where there is no legal or business purpose for retaining your Personal Data, it will be automatically and permanently erased or made anonymous.
In particular, regarding the data processing of registered members into Prada Group customer database:
- Personal Data collected for the purposes of customer management to offer personalized services and advantages reserved for registered members, are kept for a period of 7 years from the date of your last interaction with the Prada Group; and
- Purchase details are kept for a period of 7 years from the date of purchase.
7. Data controllers and contacts
For the purpose referred in section 2 letters (a) and (b), the Data Controller is:
Prada Taiwan Limited, Taiwan branch
12/F., No. 44, Sec.2, Jhongshan N. Rd., Jhongshan District, Taipei City 104, Taiwan (R.O.C.)
For the other purposes referred to in section 2 letters (c) to (f), the Data Controller is:
Via Antonio Fogazzaro 28, Milan (Italy)
Group Data Protection Officer
8. Your rights
Please note that you may exercise the rights under the applicable privacy laws, including the PDPA and the GDPR, at any time by contacting the Data Controller at the addresses indicated in the previous paragraph.
In particular, you may also exercise your rights under Article 3 of the PDPA, including (1) inquiry and request for a review of your Personal Data; (2) request to make duplications of your Personal Data; (3) request to supplement or correct your Personal Data; (4) request to discontinue collection, processing or use of your Personal Data; and (5) request to delete your Personal Data.
Under the GDPR, you have the right to request information as to whether your Personal Data is being processed and as to the characteristics of the processing, the right to rectification and erasure of your Personal Data, to limitation of the data processing and/or the right to object to the processing, to request the transmission of your Personal Data to another controller, and/or to lodge a complaint with the competent supervisory authority including the Italian Garante per la protezione dei dati personali (www.garanteprivacy.it) or take legal action if you believe there is non-compliance with the provisions of the applicable laws.
You also have the right to withdraw your consent for the processing and use of your Personal Data by PRADA at any time, without charge. The withdrawal of your consent will not affect the lawfulness of processing based on your consent before its withdrawal.
Last updated: November, 17th 2020