Privacy Policy
Welcome to Vista Point Shop
The e-commerce site vistapointshop.com is owned by Vista Point srls. This privacy policy outlines how our organization uses the personal data it collects from its users, during the use of the site and in relation to our online sales services, in compliance with the European Union General Data Protection Regulation (GDPR).
Data Controller:
The data controller of your personal data is VISTAPOINT srls, Via Padova 79/81, Catania, P.IVA/Cod.Fiscale 05634140874. The controller is hereinafter also referred to as “Vista Point” or “we.”
We invite you to carefully read our privacy and cookie policy. For further details, questions, or inquiries regarding the processing of your personal data, feel free to contact us at any time using the email address info@vistapointottica.com.
Types of Data Collected
While browsing the site vistapointottica.com, we may collect the following types of data:
Aggregated data to understand how users interact with and use the site: analytics of your browsing path, the pages you visit, and how you interact with individual pages.
Personal identification data (e.g., first name, last name, email address, and phone number).
Your email address and consent to receive communications when you sign up for our newsletter.
Personal data you provide when contacting our customer service.
Residential or domicile address, phone number, if you place online orders, or if you complete your user profile, even if the online order is not completed.
Data indicated in the prescription for glasses if you request prescription lenses or those provided for the purchase of contact lenses.
How Data is Collected
By accessing our services or registering on vistapointshop.com, you directly provide us with the personal data that we collect and process. We collect and process your data when:
You browse, use, or view the pages of our site, accepting cookies from your browser.
You send us a request or an order proposal via the site or email.
You sign up for our newsletter by entering your email address and accepting the terms of service.
You voluntarily complete an online survey or send us a review or opinion, even by email.
Vista Point may also receive your personal data indirectly from the following third parties:
PayPal, if you use the Express Checkout service.
How We Use the Data We Collect:
Your personal data is processed by us, in compliance with applicable laws regarding personal data protection, for the following purposes:
To execute the purchase contract for products or services offered on vistapointshop.com.
To manage the requests and inquiries you send to our Customer Service.
To provide you with additional services such as subscribing to our newsletter for periodic offers or other initiatives we believe may be of interest to you.
How and Where We Store the Data
Vista Point takes every reasonable security measure and good organizational practice to protect your personal data and prevent accidental or fraudulent deletion, modification, total or partial loss of data, unauthorized access, or forwarding. We regularly verify the effectiveness of our technical and organizational measures to ensure continuous improvement in data security.
Our employees are required to respect strict confidentiality obligations, are informed about data protection practices, and receive regular updates on training and legal changes related to personal data protection.
Legality of Processing and Legal Basis:
The processing is lawful based on one or more of the following grounds: it is necessary to provide you with a service that you have expressly requested; to execute the purchase contract for goods or services, in case your order proposal is accepted or in case of reservation of a good or service; to comply with legal obligations, regulations, or European legislation, including accounting and tax obligations.
Vista Point may share your personal data with third-party companies or third-party software, in order to provide services such as delivering purchased products or making additional services and features available, or for statistical surveys and analysis with aggregated data, useful to understand how users use the site, improve our offering, and our services. Our service providers may include:
Financial institutions
Companies specializing in fraud detection and prevention
Third-party companies providing technological services
Third-party companies providing logistics, transportation, and delivery services
Third-party companies providing customer support services
Third-party companies providing marketing and advertising services
Location of Processing:
We process your data at our operational offices, our offices, and our logistics locations, through external data processors we have appointed and via external data processing platforms.
In some cases, our service providers may be located in countries outside the European Union. In these cases, the transfer of your personal data to such countries is carried out in compliance with the safeguards provided by law.
The services offered by our providers enable essential functions of our site, such as user registration management, review and comment management, user database management, e-commerce services, payment processing, session analytics tools, etc. Some of these services operate through servers located in different geographic areas. Please refer to the section regarding Personal Data Processing details for each service:
Hostinger Inc. - Acts as a data processor for various types of personal data on behalf of the Controller, as specified in the service’s privacy policy, which you can consult here.
PayPal Inc. - Manages services that enable online payments. It collects and manages various types of data according to the service's privacy policy, which you can consult here.
Duration of Processing:
The personal data you provide may be stored by us for as long as necessary to achieve the purposes stated in our General Conditions and, in any case, until a possible request for data deletion, such as when you request the deletion of your account.
Personal data collected with your consent for storage and processing, to execute a purchase order proposal or to fulfill a service you requested, is kept in compliance with civil and tax regulations, solely to fulfill legal requirements.
Once the retention period expires, the data is completely deleted or rendered anonymous in an irreversible manner.
Your Rights
Vista Point is committed to ensuring that you have full rights under Articles 16, 17, 18, and 19 of Regulation (EU) 2016/679 (GDPR), regarding rectification, deletion, and limitation of processing. You have the right to obtain confirmation of whether or not personal data processing is ongoing and to access your personal data for portability. You have the right to request:
Access to data being processed
Receiving your data in a structured, commonly used, and machine-readable format
Rectification and correction of inaccurate or incomplete data you have entered by mistake
Deletion of your personal data if the data is no longer needed, or for withdrawal of consent, or to comply with a legal obligation
Limitation of processing, under certain circumstances
In case of rectification or deletion of personal data or limitation of processing, you will receive a notification within one month of the date of your request. If you wish to exercise any of the rights described above, we invite you to contact us using the email address info@vistapointottica.com.
Changes to Our Privacy Policy
Vista Point regularly reviews its privacy policy, publishing changes and updates on this page. We recommend visiting it from time to time.
How to Contact Us
For further details, questions, or inquiries about the processing of your personal data, we invite you to contact our Customer Service at any time using the email address info@vistapointottica.com.
How to Contact the Competent Authorities
To contact your national competent authority regarding personal data protection, it may be useful to refer to the list of members of the European Data Protection Board, an independent European body that contributes to the consistent application of data protection rules throughout the European Union and promotes cooperation between EU data protection authorities.
Last update: December 19, 2024