Privacy Policy Wifi Guest

Guest WiFi Privacy Notice

We at Emilio Pucci S.r.l. respect your privacy. This privacy notice (“Privacy Notice”) explains who we are and how we collect, use, and share the personal information we receive from you in connection with our services (“Services”). If you have any questions, please do not hesitate to contact us as indicated in the “How to contact us” section at the end of this Privacy Notice.

This Privacy Notice and the Terms of Use (together, the “Terms”) apply to access to and use of the guest Wi-Fi services at all of our locations.

This Privacy Notice does not cover information collected by us through other means, for example through our websites, sales and marketing activities, or otherwise in the course of our business operations.

Emilio Pucci S.r.l. is the Data Controller of your personal data. Emilio Pucci S.r.l. is a company registered in Italy.

What data we collect and how it is collected

The information we may collect about you generally falls into the following categories:

Information we collect automatically

Location data: When you bring your device (with Wi-Fi and/or Bluetooth enabled) into one of our locations, the technology we use to provide the service detects the following: the presence of your device, its signal strength, its manufacturer (Apple, Samsung, etc.), geographic location, and a unique identifier known as a MAC (Media Access Control) address. This combination of numbers and letters identifies a specific device to surrounding Wi-Fi or Bluetooth networks. Since the MAC address does not reveal the real-world identity of the device owner, such identity information is never collected. This technology promptly anonymizes and de-personalizes any MAC address it collects. General visit information is collected when your mobile device moves across different locations using the above technology.

Activity information: When you use our service, additional information may also be automatically collected from your mobile device. In some countries, including countries in the European Economic Area (“EEA”), this information may be considered personal data under applicable data protection laws. We refer to this information as “Activity Information.” This information does not reveal your specific identity but may include information about the specific mobile device you are using to access the service, such as unique device identifiers known as MAC addresses, device type and model, operating system, browser type and language, your browser Internet Protocol address, connection start and stop timestamps, amount of traffic, hotspot connected from, and type of disconnection reason. It may also include broad geographic location data (e.g., country- or city-level location). Cookies and other tracking technologies may be used to collect some of this Activity Information, as further explained in the section titled “Cookies and similar tracking technologies.”

Information you provide voluntarily

Registration information: When you use guest Wi-Fi services at one of our locations, registration may sometimes be required. The “Registration Information” you may provide includes, for example, your full name, phone number, email address, or demographic information (e.g., date of birth, gender, geographic area, and preferences).

You understand and agree that by providing us with Registration Information, you authorize us to:

  • store and access your personal data;
  • link your personal data to the MAC address and your location, as provided by your mobile device;
  • use the Registration Information in other ways consistent with the terms and conditions set forth herein; and
  • only with your specific and express consent, use the Registration Information for marketing and profiling activities.

Information we collect from third-party sources

If you access the Wi-Fi network through a third-party service, such as Facebook Login or Google OpenID, we may access the information described in the third-party service’s authorization request, such as your name, email address, gender, age, and home ZIP/postal code. Please review your privacy settings with these third-party services to ensure you are sharing only the information you wish to share.

How we use your information

Registration information and activity information:
Once you have registered for our services, we use the information provided to grant you access to the network and to operate the service.

General access information:
General access information is used to help us generate aggregated statistics and reports to improve our Services for a variety of purposes, such as:

  • Improving customer service;

  • Improving the operation of our facilities;

  • Setting staffing levels; and

  • Other business and operational purposes, such as financial and product planning and execution.

We do not combine Registration Information and Activity Information with the general visit information previously collected from your mobile device.

Other uses

We also use your information to:

  • Help us internally manage and maintain our Services (e.g., troubleshooting, testing our security systems, etc.);

  • Improve and further develop the Services (e.g., creating new features or functions, refining the user experience, improving technical performance, etc.);

  • Provide you with notices related to your use of the Service (such as account notifications and legal notices).

Optional additional uses:

With your consent, which is optional, we process your data for marketing purposes, commercial or promotional communications, direct sales, market research, and in-store sales support worldwide, via email (newsletters), telephone, SMS, chat, instant messaging, social networks, and traditional mail, including sending invitations to events. You may at any time indicate your preferred contact methods and object to receiving promotional communications through all or only some of these methods.

With your consent, which is optional, we also collect information about your preferences, habits, and interactions with us in order to create group and individual profiles (profiling) and send personalized communications. Personalized communications may be sent via email (newsletters), telephone, SMS, MMS, chat, instant messaging, social networks, and traditional mail. You may at any time indicate your preferred contact methods and object to receiving personalized communications through all or only some of these methods. Consent for the above marketing and profiling purposes is optional, and refusal will have no consequences.

Cookies and similar technologies

We may use cookies and similar tracking technologies (collectively, “cookies”) to collect and use Activity Information about you (including for interest-based advertising). For more information about the types of cookies we use, why we use them, and how you can control cookies, please see the Service Provider’s Cookie Policy available at the following link:
https://cloud4wi.zendesk.com/hc/en-us/articles/200537906-Splash-Pages-Cookies-Policy

With whom we share your information

Except as described in this Privacy Notice, we will not share your personal information with third parties without your consent, except in the following circumstances:

Service providers: We may share personal information with third-party service providers (e.g., data storage and processing facilities) that host our servers and databases and provide other services to us. We limit the personal information shared with these service providers to what is necessary for them to perform their functions and require them to maintain appropriate technical and organizational measures to ensure adequate protection and confidentiality of such personal information. In any case, we ensure that these service providers process personal data in compliance with European data protection law to guarantee a high level of data protection, even if personal data are transferred to a country for which no EU Commission adequacy decision has been adopted.

To protect our interests: We may also share personal information and other information if we believe it is legally required or in our interest to protect our property or other legal rights (including, but not limited to, enforcement of agreements) or the rights or property of others, or otherwise to help protect the safety or security of the Services or other guest Wi-Fi users.

Exercise of data subject rights

You may contact us or the Data Protection Officer at any time to exercise the rights provided under Articles 15 et seq. of the GDPR, where applicable, such as obtaining confirmation of whether or not your data exist, verifying their content, origin, and accuracy, requesting their completion, updating, rectification, erasure, anonymization, data portability, restriction of processing, or objecting to processing for legitimate reasons, including objection to marketing activities. You also have the right to withdraw your consent at any time using the contact details provided in the “How to contact us” section below, as well as to lodge a complaint with the Supervisory Authority (the Italian Data Protection Authority).

Opt-out of mobile location analytics

Our Service Provider adheres to the Mobile Location Analytics Code of Conduct. As provided in the code, you may choose not to associate information about your presence at a location with a device’s MAC address (i.e., general visit information as defined in this Privacy Notice) at:
https://smart-places.org/.
If you opt out, we will use your device’s MAC address only to maintain the opt-out status of the device.

How long we retain your information

We retain your information for as long as you are a user of the guest Wi-Fi services. We also retain this information for 12 months after you are no longer a user or until it is no longer necessary for the purposes for which it was collected. Where such information is subject to a legally mandated data retention period exceeding the above period, we will store the data for the duration specified by the applicable legal provisions. In such cases, the data will be retained in a restricted form, and further processing will be permitted solely for the establishment, exercise, or defense of legal claims, protection of another person’s rights, or reasons of significant public interest. After this period, your personal data will be irreversibly destroyed.

If you have provided consent for the processing of personal data for marketing and profiling purposes, such data will be retained for a period of 7 years, after which it will be automatically deleted or permanently and irreversibly anonymized.

Where we store your information

As of the date of this Privacy Notice, we store information on the servers of our Service Provider in Ireland.

We may transfer your data from your country to other countries in connection with data processing, fulfillment of your requests, and service management. If we collect your data in the EU, your data will not be transferred to a country or territory outside the EU.

We use third-party providers who may process your personal data on our behalf. We have assessed the compliance and security measures implemented by all our providers and have entered into data processing and data transfer agreements (where applicable) with them that are compliant with the GDPR.

How we protect your personal information

We use appropriate administrative, organizational, technical, and physical safeguards to protect the personal information we collect and process about you. The measures we use are designed to provide a level of security appropriate to the risk of processing your personal information and to ensure that your data are safe, secure, and accessible only to you and to those you have authorized to access them. Specific measures include the use of Secure Socket Layer protection (as visible in your web browser). We also adopt measures such as firewalls and authentication to safeguard your information and prevent unauthorized access.

Mobile location analytics information is securely transferred and then hashed before being stored on virtual hosting infrastructure. Hashed data cannot be decoded by third parties to reveal a device’s MAC address.

However, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so you should take care when deciding what information to send to us in this way.

Third-party websites

Guest Wi-Fi services may, from time to time, contain links to and from third-party websites. If you follow a link to any of these websites, please note that these websites and any services accessible from them have their own privacy policies, and we do not accept any responsibility or liability for those policies or for any personal information that may be collected through those websites or services. Please review those policies before submitting personal data to such websites or using them.

Children’s privacy notice

We do not knowingly collect information from individuals under the age of 16 unless we first obtain authorization from the child’s parent or legal guardian. However, if despite our best efforts we learn that we have collected information from a child under the age of 16 on our Platform, we will delete such information as quickly as possible.

If you become aware that your child has provided us with personal information without your consent, please contact us using the contact details provided in the “How to contact us” section below.

Recourse, enforcement, and liability

We are committed to ensuring that our privacy practices comply with the Principles and this Policy. We encourage you to direct any questions, concerns, or complaints regarding the collection and use of your personal information to our Data Protection Officer (contact details provided below). We will investigate and work promptly to resolve any complaints or disputes in accordance with the Principles and this Policy.

Updates to this policy

We may update this Privacy Notice from time to time. This Privacy Notice applies to information collected while it is in effect. If we make changes to this policy that materially affect your rights or obligations under it, we will make reasonable efforts to inform you of the change. Use of the Platform after the effective date of the changes constitutes acceptance of the revised terms. We reserve the right to apply the revised terms to information already collected, subject to applicable legal requirements. We encourage you to review this Privacy Notice regularly to check for updates.

How to contact us

If you have any questions or comments about this policy, you may contact us using the following details:

EMILIO PUCCI S.r.l.,
registered office in Milan, Via Fieno 3, 20123

Email: client.experience@pucci.com

Data Protection Officer:
domiciled at the Data Controller’s premises, available at the following email address: dpo@pucci.com