Privacy Policy
In compliance with applicable privacy regulations, including Regulation (EU) No. 2016/679 (“GDPR”), this Privacy Policy describes how Dorsal S.r.l. (“Dorsal”, “us”, “our”, "company") collects your personal data, how it uses it, with whom it shares it, and your choices in this regard.
Index
-
Applicability of the Privacy Policy
-
Processor and DPO
-
Collection of Personal Data (Information provided, automatically collected, other sources)
-
Recipients of Your Personal Data
-
Your Data Choices and Consequences of Refusal
-
Your Rights and How to Exercise Them
-
Transfer of Personal Data Outside the EEA
-
Preservation of Data
-
Manner of Processing and Information Security
-
Modification of the Privacy Policy
- Link to Third Party Sites
1. APPLICABILITY OF THE PRIVACY DISCLOSURE
This Privacy Policy applies to personal data collected by Dorsal through websites owned and operated by Dorsal, (collectively, the "Websites").
2. DATA CONTROLLER AND DATA PROTECTION RESPONSIBILITY
The Data Controller is Dorsal S.r.l., with registered office in Via Madonna di Loreto, 31020 Corbanese (TV), Italy. Dorsal's Data Protection Officer can be contacted by e-mail at privacy@dorsal.it.
3. COLLECTION OF PERSONAL DATA
We collect personal data, which is information that identifies you or relates to you as an identifiable natural person.
(A) Information provided by you
If you choose to take advantage of certain services offered on our Websites, we will collect personal information provided by you. We collect personal data from you when:
- You submit an application. When you apply for employment with Dorsal, we collect your identifying information (name, e-mail address, physical address, and phone number) and your professional or work information (resume, cover letter, work experience, and education). This data is used to manage and evaluate your application for us as necessary to comply with the law. The legal basis for processing is the need to perform a contract or actions at your request, prior to entering into a contract (Art. 6(1)(b) GDPR). Dorsal also processes such personal data as part of its legitimate interest in facilitating and optimizing the selection process (Art. 6, par. 1, lett. f of the GDPR).
- You contact us. When you send Dorsal a question or request, or ask for other support, you will need to provide us with personal identifiers (name and email address) and any other information you choose to disclose in your correspondence. This data is used to respond to your questions or requests, troubleshoot problems where necessary, and resolve any issues you encounter with the Websites or the services offered on them. The legal basis for this processing è the’performance of our contract with you (Art. 6(1)(b) GDPR).
- You register as an owner. If you register as an owner of a Dorsal product, we will collect your personal identifiers (name, email address, age range, and physical address), information about your profession or occupation (employment activity), and business information (purchase identification number, vendor name and location, date of purchase). This personal data is used to process your registration as an owner of one or more Dorsal products. The legal basis for this processing is the performance of our contract with you (Art. 6, par. 1, lett. b of the GDPR).
- In the case of profiling activities.If you provide your consent, we may use the personal data described in this section to analyze your behavior, habits and propensity to consume in order to improve the products and services provided by Dorsal, to meet your expectations as well as, if you have also consented to receive direct and indirect marketing communications, to send you marketing communications that we think may be of interest to you. In doing so, Dorsal will analyze your preferences and interests using automated analysis techniques that provide the company with inferences about you, including profiling. The legal basis for such processing is your consent (Art. 6(1)(a) GDPR). You can revoke your consent at any time by clicking on the unsubscribe (unsubscribe) link provided within each e-mail. This link will redirect you to our consent management page where you can unsubscribe from our newsletters and marketing communications.
- You consent to receive direct and indirect marketing communications. If you provide your consent, we may also use your personal data (such as name, address, phone number, email) to send you marketing communications regarding products, services, events, new Dorsal collections or to conduct market research (so-called direct marketing). This data may be processed through paper support, through automatic or electronic means, including mail or e-mail, telephone (e.g., calls, SMS), fax and other means (e.g., websites, mobile apps). In doing so, Dorsal will analyze your preferences and interests using automated analysis techniques that provide Dorsal with inferences about you, including profiling. The legal basis for such processing is your consent (Art. 6(1)(a) GDPR). You can revoke your consent at any time by clicking on the unsubscribe (unsubscribe) link provided within each e-mail. This link will redirect you to our consent management and newsletters page where you can opt out of marketing communications.
- Personalized Audiences and Similar Audiences. If you provide your consentfor marketing activities, we may share your personal information (such as your first name, last name, email address, phone number) with social networking platforms including Meta, LinkedIn, Google Ads, YouTube, and other similar platforms ("Social Networks") to make our business more responsive to your interests and/or those of like-minded consumers. To do this, your personal information will be hashed and encrypted before Social Networks access it for the purpose of creating a "Custom Audience" (which consists of sending targeted promotional ads to Social Network users who are already our customers or potential customers). Regarding "Similar Audiences" (where targeted promotional ads are sent to users on the Social Networks who appear to have shared interests or demographics similar to our existing or potential customers) we only collect information provided by the Social Network according to their privacy policy when users click on ads displayed on the Social Networks; we do not have access to the identity of anyone in the "Similar Audience" unless they choose to click on such ads. The legal basis for such activities is your consent (Art. 6(1)(a) GDPR). You can revoke your consent at any time according to the modalities provided in sections 4 and 5 below and we will remove your personal data from our list of Custom Audiences. You can refer to the Social Networks to learn more about their privacy policies regarding the data and consents you may have provided to them.
- You subscribe to Dorsal newsletters. When you sign up for Dorsal newsletters, we collect your personal identifiers (email address) and preferences about the newsletters you wish to receive. This personal information is used to send you the newsletter(s) as requested. The legal basis for this processing is the performance of our contract with you (Art. 6(1)(b) GDPR). You can request to stop receiving newsletters at any time by clicking on the unsubscribe (unsubscribe) link provided within each email. This link will redirect you to our consent and newsletters management page where you can unsubscribe from newsletters.
Dorsal may also use the personal data it collects as described in this section to improve its products and services, to comply with the law, to efficiently maintain its business, and for other limited circumstances as described in the DESTINATORS OF YOUR PERSONAL DATA section. This is within our legitimate interest in the fulfillment of our contractual obligations, protection of legal rights and compliance with legal obligations. Dorsal may also anonymize or aggregate personal data for benchmarking purposes.
(B) Automatically collected information.
Cookies and tracking technologies
In addition to the personal information you provide to us directly, we may also collect information automatically as you use our Websites. This information includes the following information about’activity on the Internet or other electronic bed (with legs) and location information:
- Use Information. Include information related to your interaction with our Websites, such as which pages you visit, how often you access them, how long you spend on each page, what you click on while on the Websites, and the addresses of the Websites from which you came.
- Device Information.This includes some information about the device you use to access our Websites, such as browser type, browser language, hardware model, operating system, and your preferences.
- Location Information. Includes information about your location, which can be determined through your IP address.
To collect this information, we use cookies and other tracking technologies. A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device to remember information about you, such as language preference or login information. These cookies are set by us and are called first-party cookies. We also use third-party cookies – that is, cookies from a domain other than the website you are visiting – for our advertising and marketing initiatives.
To control the information collected about you using cookies and other technologies, please see our Cookie Policy. Specific third-party cookies on our Noteworthy Websites include:
Google Analytics 4. We use Google Analytics 4 to collect information regarding your use of the Websites to improve our Websites. To collect this information, Google Analytics 4 may set cookies on your browser or read cookies you already have. Google Analytics 4 may also receive information about you from applications you have downloaded that work with Google. We do not combine information collected through the use of Google Analytics 4 with identity information. Google's ability to use and share information collected by Google Analytics 4 regarding your visits to our Websites or another Google partner application è limited by the Google Analytics Terms of Service and Google Privacy Policy available here. To prevent your data from being used by Google Analytics 4, you can download the Google Analytics opt-out browser add-on that you can find here.
DoubleClick. We use Google's DoubleClick to serve ads based on a user's previous visit to our Websites. Each visitor on our Site receives a different cookie, and the information collected by the cookie is used to generate conversion statistics and allow us to see the total number of people who have clicked on our advertisements. The DoubleClick cookie is used by Google in advertisements placed on the Web sites of its partners, such as Web sites that participate in Google's certified advertising bed bases (with legs). DoubleClick enables Google and its partners to serve ads based on your visit to our Websites and other sites on the Internet. Please refer to Google's Privacy Policy for more information about how Google uses the information it collects. To turn off such sharing and targeted advertising by Google, access Google's advertising customization. You can also install the add-on for disabling DoubleClick.
Google Ads. We use Google Ads to provide you with advertisements and to track whether you have interacted with an ad we have placed elsewhere on the Internet. Google Ads stores a conversion tracking cookie on your device when you click on our advertisement. The information obtained through the cookie is used to generate statistics and allows us to see the total number of users who have clicked on our ads. We also use Google Ads to present users of our Websites with advertisements on the Internet and within Google's advertising bed base (with legs) based on their visits to our Websites. For more information please refer to Google's Privacy Policy available here. To disable such sharing and targeted advertising by Google, access Google's advertising customization Google.
Facebook Pixel/TikTok Pixel. We use the Facebook Pixel and the TikTok Pixel (jointly, the “Pixel”) to personalize our advertising and to deliver ads to you on your social media based on your browsing behavior. This allows us to track your behavior after you are redirected to our Websites by clicking on the Facebook and/or TikTok ad. Pixels send and store data to enable us to optimize campaigns, measure the effectiveness of Facebook and/or TikTok ads for statistical and market research purposes. The information collected via Pixels is stored and processed by Facebook and/or TikTok. Facebook and TikTok may link this information to your Facebook/TikTok account and also use it for their own promotional purposes in accordance Data Policy of Facebook and with the Privacy Policyof TikTok. Pixels also allow Facebook and TikTok and their partners to show you advertisements within and outside of Facebook and TikTok. To turn off this sharing and display of Facebook ads, visit your Advertisement Settings of Facebook, where you can delete and control the information that third parties share with Facebook on the page Insertions shown outside Facebook.To disable this sharing and the display of TikTok's advertisements, visit their Privacy Noticeand their TikTok Websites Cookie Policy. If you do not have a Facebook and/or TikTok account, you can disable Facebook and TikTok ads through the Digital Advertising Alliance here.
(C) Information collected through other sources.
Social media listening (“SML”). From time to time we may use SML tools to extract information (e.g., user comments regarding Dorsal, user name, etc.) from web sources (e.g., blogs, forums, etc.) and social media channels. This activity is based on our legitimate interest to find information about the visibility of our brand on social media channels, as well as to evaluate the impact of our web campaigns (Art. 6(1)(f) GDPR). For this purpose, we can only process publicly available information and derive statistical analysis from it.
Social networks. If you interact with us via social networking platforms including Instagram, Facebook, LinkedIn, YouTube and any other similar platforms (“Social Network”), when you fill out specific forms (e.g. request for information, etc.) and/or when you interact with our official pages/profiles on the Social Networks, we may receive from the Social Networks your personal data (e.g., e-mail, first name, last name, country of origin, address, house number, locality, zip code, city, phone number), your interactions on the Social Networks (e.g., posts you like, private messages you may send us, etc.). Depending on the settings you have chosen on your Social Network profile, we may be able to receive additional data such as your age, groups you are a member of, etc., which in some cases may lead us to identify you. We may process your data in order to respond to your posts, requests and questions, to perform statistical analysis and market research on users interacting with our pages and/or Websites as well as for marketing activities as described in section (A) if you give your consent. The legal basis for this processing is the performance of our contract with you (art. 6, par. 1, lett. b of the GDPR).
Please note that this section (C) refers only to the processing of data by Dorsal. We are not responsible in case of unauthorized disclosure of your information by third-party social media channels in violation of the options you have selected and/or the consents you have provided. Please refer to the websites of such third-party social media channels and social networks for more information about their privacy policies regarding the data and consents you may have provided to them.
4. RECIPIENTS OF YOUR PERSONAL DATA
General Disclosure
Dorsal may need to make personal data identified in this Privacy Policy available within Dorsal, with the authorized sales and after-sales bed base (with legs), with service providers, or with other third parties. Such instances include:
With our authorized sales and after-sales bed base (with legs). On the basis of specific contractual agreements, we share your personal data with our reseller bed base (with legs) who assist us in providing our products and services.
With service providers. We may share your personal data with our service providers who assist us in providing the Websites. The legal basis is our legitimate interest in providing the Websites efficiently. These service providers include communication providers, web hosting providers, IT support, our customer management platform, shipping providers, payment processing companies, marketing providers. We may also share your personal information with social networks for marketing purposes.
With third parties. We may have to disclose your personal information to third parties, such as legal advisors, law enforcement or government/regulatory bodies in order to protect our legal interests and other rights, protect us from fraud or other illegal activities, prevent harm, for risk management purposes, and to fulfill our legal obligations. The legal basis is compliance with the law, fulfillment of legal obligations and our legitimate interest in protecting the rights of others.
In the event of corporate reorganization. In the event that we undertake, or intend to undertake, a transaction that changes the structure of our business, such as a reorganization, merger, acquisition, sale, joint venture, divestiture, consolidation, transfer, change of control or other disposition of all or part of our business, assets or securities, we would share personal data with third parties, including the acquirer or target (and their agents and advisors) for the purpose of facilitating and completing the transaction. Personal data would also be shared with third parties in the event of bankruptcy or liquidation in the course of such proceedings.
With your consent. In addition to the reasons stated above, we may request your permission to share your personal data for a specific purpose. We will inform you and request your consent before you provide personal data or before personal data you have already provided is shared for that purpose. You can revoke your consent at any time.
5. YOUR CHOICES ABOUT THE DATA AND THE POSSIBLE CONSEQUENCES OF AN EVENTUAL REFUSAL TO PROVIDE YOUR DATA
Online Advertising. To opt out of interest-based advertising generally or to get more information about our service providers' use of this information, you can visit the Network Advertising Initiative or the Digital Advertising Alliance. For European users, visit the European Interactive Digital Advertising Alliance here.
Marketing emails and newsletters. You can opt out of receiving marketing e-mails and/or newlsetters from us by clicking on the “unsubscribe” link provided in each e-mail. Please note that we will continue to send the necessary notifications for the Websites or products or services you have requested.
Device Location Settings. You can prevent your mobile device from sharing your location data by changing permissions on your mobile device or desktop browser.
Providing your personal data is always optional. However, a refusal to provide any of the personal data, in whole or in part, necessary for the provision of a service may result in Dorsal being unable to allow the requested service to be provided.
If you choose not to provide your personal data for the additional marketing and profiling purposes or if you choose to revoke your consent afterwards, this will not affect the pursuit of the other purposes indicated above.
6. YOUR RIGHTS
Rights of data subjects established by the GDPR
You have the following rights in relation to your personal data:
- Right of Access. You have the right to ask Dorsal for copies of your personal data. This right has some exceptions, which means that you may not always receive all of the personal data we process.
- Right to Rectification.You have the right to ask Dorsal to rectify personal data that you believe is inaccurate. You also have the right to ask us to supplement information that you believe is incomplete.
- Right to erasure. You have the right to ask Dorsal to delete your personal information under certain circumstances.
- Right to restrict processing. You have the right to ask Dorsal to restrict the processing of your personal data under certain circumstances. Please see the section “YOUR CHOICES ABOUT YOUR DATA AND THE POSSIBLE CONSEQUENCES OF ANY REFUSAL TO PROVIDE YOUR DATA” to learn about additional ways in which you can limit the processing of your personal data.
- Right to object to processing. You have the right to object at any time, on grounds arising from your particular situation, to the processing of your personal data carried out on the basis of our legitimate interests. Please see the section “YOUR CHOICES ABOUT THE DATA AND THE POSSIBLE CONSEQUENCES OF ANY REFUSAL TO PROVIDE YOUR DATA” and our Cookie Policy to learn about additional ways in which you can object to the processing of your personal data. It remains your right to object at any time and free of charge to the processing of your personal data for direct marketing purposes, including profiling related to such activity.
- Right to data portability. You have the right to ask us to transfer the personal data you have provided to us from one organization to another, or to provide it to you in a structured, commonly used and readable format.
- Right to bring a complaint. You have the right to propose a complaint to a’supervisory authority.
In order to exercise your rights, you may address a written request to Dorsal S.r.l., Via Madonna di Loreto, 31020 Corbanese (TV), Italy, and/or telematically to privacy@dorsal.it. You also have the right to file a complaint with the Data Protection Authority (www.garanteprivacy.it).
7. TRANSFER OF PERSONAL DATA OUTSIDE THE EUROPEAN ECONOMIC AREA
For the provision of services, in particular for web traffic analysis using Google Analytics (GA4), Dorsal uses third-party service providers (such as Google) who may transfer personal data to countries outside the European Economic Area (EEA), in particular to the United States.
In the event of such a transfer, the Data Controller shall take the appropriate safeguards required by the GDPR, including:
-
Standard Contractual Clauses (SCCs): The implementation of contractual agreements based on the Standard Contractual Clauses adopted by the EU Commission.
-
Supplementary Measures: The implementation of additional technical and organizational measures necessary (such as pseudonymization or anonymization of data) to ensure that the level of protection of transferred data is equivalent to that guaranteed by the GDPR.
8. STORAGE
- Contractual relationships/product records/requests:
for the durability / lifespan of the relationship and up to 10 years from termination due to legal obligations/defense in court. - Candidations: [e.g., 12 months] from receipt, unless otherwise agreed.
- Marketing: 24 months from collection/last useful contact;
- Profiling: 12 months from collection;
- Cookie Policy: according to durability / lifespans indicated in the Cookie Policy;
- Hash Lists for Custom Audience: removal after match or upon your revocation.
9. MODALITÁ OF THE PROCESSING AND SECURITY OF INFORMATION
The processing of your personal data is carried out using computer and manual tools, with logics strictly related to the purposes of the processing indicated above and, in any case, in such a way as to ensure the protection, confidentiality and security of the data. To protect your personal data from unauthorized access, destruction, use, modification or disclosure, we have implemented technical, administrative and physical security measures. These security measures include encryption, access controls, and virus and malware protection. However, no security measures or mode of data transmission is 100% secure and we cannot guarantee the absolute security of the personal data we have collected from you.
10. MODIFICATION OF THIS PRIVACY POLICY
This Privacy Policy is subject to change. Any changes to the Privacy Policy will be posted on this page and will indicate the date they take effect. We encourage you to frequently check and review the Privacy Policy to become aware of any changes. If any changes are made that significantly affect your privacy rights, we will notify you by e-mail or by prominently posting on our Websites.
Last updated: April 1, 2025.
11. LINKS TO THIRD-PARTY WEBSITES
Third party websites accessible from this website are the responsibility of the third party. Dorsal disclaims any responsibility for requests and/or transmission of personal data to third-party websites.
12. Minors
The Site is not intended for minors under the age of 14. If you believe that a minor has provided us with data without parental consent, please contact us: we will arrange for deletion.
13. AUTOMATED DECISIONS AND PROFILING
We do not make decisions based solely on automated processing that produce legal effects or significantly affect the data subject (Art. 22 GDPR). Any profiling carried out serves to personalize communications and is only done with prior consent; you can revoke it at any time.