INFORMATION REGARDING THE PROCESSING OF PERSONAL DATA (PRIVACY) Based on Legislative Decree 196/2003 "Code regarding the protection of personal data" and EU Regulation 2016/679

With reference to the provisions of Legislative Decree 196/2003 "Code regarding the protection of personal data", and of the EU Regulation 2016/679, in particular with regard to articles 12 and 13, we inform you that your personal data will be processed in accordance with current legislation.

H2O srl
based in Rome, Viale Luigi Schiavonetti 270 is constantly committed to adopting technical and organizational solutions aimed at guaranteeing high standards of lawfulness, security and protection in the processing of personal data: the requirements of the General Data Protection Regulation of the European Union are implemented (hereinafter in the text "GDPR" acronym for General Data Protection Regulation) and other legal provisions, including, in particular, those of the Code regarding the protection of personal data (hereinafter "Privacy Code" or "Code") .

1. Who is the data controller? H2O srl based in Rome, Viale Luigi Schiavonetti 270 (hereinafter in the text "H2O" or "we"), is the owner of the processing of your personal data in accordance with the GDPR and the Code.

2. What data are processed by us? Personal data means any type of information relating to an identified or identifiable natural person (hereinafter "Data").
Data provided by you: all the data that you have provided to request the purchase and sale of a good and / or the provision of a service; the Data could be, by way of example: your name and surname, your contact details (including address, telephone number and e-mail address), profession, date and place of birth, tax code. The provision of such information, if required by the contract or essential for its execution, is a necessary requirement for the conclusion of the Contract; failure to communicate such data may make it impossible to conclude the Contract and / or provide by H2O related services and products.
H2O does not acquire and does not process categories of personal data, such as information revealing your racial origin, your political opinions, your religious or philosophical beliefs.

3. On what legal bases and on what rules will we process your data? Personal data means any type of information relating to an identified or identifiable natural person (hereinafter "Data"). We will only process your Data where permitted by applicable legal provisions. Specifically, we will process your data on the basis of articles. 6 and 9 GDPR and on the basis of consent pursuant to art. 7 GDPR, as well as in compliance with the corresponding rules of the Code:

Consent art. 6 (1) paragraph 1 (a), art. 7 GDPR): we will process certain Data only in the presence of your preliminary, free and express consent. You have the right to revoke the consent given at any time with effect for the future.
Execution of a contract: in order to conclude and execute the requested contract it is necessary to have access and process certain data.
Compliance with a legal obligation art. 6 (1) paragraph 1 (c) GDPR): in order to ensure compliance with these requirements, we must process certain data.

4. For what purposes are your data processed? Your data will be processed by us only and exclusively for the purposes permitted by the data protection legislation such as: a) purposes previously approved by you; b) processing of data in order to execute the Contract; c) execution of pre-contractual measures at your request; d) fulfillment of the legal obligations to which we are subject; e) safeguarding our legitimate interests or the legitimate interests of third parties, unless your interests prevail over them; f) ascertainment, exercise or defense of a right or legal claim; g) for reasons of significant public interest; h) marketing and advertising, in particular direct marketing activities.

Among other things, we will process your data for the specific purposes as indicated below by way of example:
- for purposes related to the Contract: especially to execute the Contract entered into with you;

- contact you in relation to the Contract and for the management of the same;

- Customer service: in order to offer you a valid customer service, we will regularly process your data, in order, for example, to give you comprehensive advice.

- management of requests for legal guarantees, product compliance, assistance, requests for withdrawal, management and termination of the Contract;

Processing of your data subject to consent: in the following cases we will process your data only and only if you have given your express consent for:
the) Market research, possibly based on profiling activities: we conduct market research regarding the interests of our customers in order to offer them interesting and targeted offers. This includes, for example, customer satisfaction studies with our services. As part of our market research activities, we exclusively process - whenever possible - anonymised and aggregated data. For these activities, however, we may also process your personal data.
ii) Advertising and marketing: if you have previously given your consent to this effect, we will process your data to inform you of any offer that may interest you and we will contact you using the communication channels expressly authorized by you. The promotional and marketing activities (including participation in competitions and prize operations) in question can be carried out by telephone, sending SMS, email: obviously you can object to the processing for these purposes at any time.
In addition to the above, H2O may process your data to comply with legal obligations and, therefore, for compliance with any rule or provision of law that we intend and must comply with or for data security for measures that are essential to ensure the security of your data. and company data from external attacks and / or in order to prevent external attacks. Again to comply with legal obligations imposed on us and / or in order to prevent fraud or in the event of a dispute. Lastly, for mandatory fiscal, accounting and administrative purposes, always in compliance and in compliance with current regulations.
In some cases, certain features of the site and / or the H2O application and / or certain promotions and / or operations may be limited for individuals with an age below that indicated on the H2O site and / or established by current regulations ; in such cases, additional express consent may be required to use certain services and / or features.
Finally, H2O may process your data to safeguard the legitimate interests of H2O itself, except in the event that your interests prevail. This is done with sales controls to improve the services rendered and in an aggregate and anonymous form without indicating your identity or for studies aimed at improving the products and services rendered as well as our procedures.

5. For what period will we process your data? As expressly provided for by art. 5, co. 1, lett. e) of the GDPR, we will keep your data only for the time necessary to process them for the purposes for which they are processed. If we process the Data for multiple purposes, they will be automatically deleted or saved in a format that does not allow us to reach any direct conclusions in relation to your identity, as soon as the last specific purpose has been fulfilled. In order for all your data to be deleted or made anonymous in line with the principle of data minimization and in accordance with art. 5, co. 1, lett. e) of the GDPR.

Indicatively, your data will be kept for the following periods: - fiscal / administrative obligations: 10 years; - regulatory obligations regarding product warranty: 28 months; - contractual obligations regarding additional after-sales services: from 36 to 78 months depending on the service chosen. At any time you can cancel your account on the e-commerce site www.h2owaterstore.it and the relative data released during the registration and purchase of H2O products. www.acquaallaspina.it

How is your data protected? H2O will process your personal data on the basis of the security obligations relating to data processing pursuant to art. 32 GDPR. In order to guarantee an adequate level of data protection aimed at limiting the risk of using the same in an improper or illicit way, technical and organizational measures have been implemented that comply with internationally recognized IT standards, these measures are constantly subject to verification. .

Your rights. According to the GDPR and other applicable provisions on data protection, you have specific and unlimited rights.
As an interested party, he has in particular the following rights under the GDPR, against H2O:
- Right of access (Article 15 GDPR): you may at any time request that you be provided with information on your data stored by us. This information refers, among other things, to the categories of data processed by us, the purposes of the processing, the origin of the Data if we did not obtain it directly from you, as well as the recipients to whom we may have transferred your data. , where applicable. You can receive a free copy of your data which are the subject of the contract.
- Right of rectification (Article 16 GDPR): may request a rectification of your data. We will take appropriate measures aimed at ensuring that your data stored and processed by us on an ongoing basis, are kept correct, complete, updated and relevant, based on the most recent information provided to us.
- Right of cancellation (Article 17 GDPR): may request the cancellation of your data, provided that the relative conditions provided by law exist. For example, this could occur based on art. 17 of the GDPR:
• - if the Data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
• - if you revoke the consent on which the data processing is based, and there is no other legal basis for the processing;
• - if you object to the processing of your data and there are no overriding legitimate reasons to proceed with the processing, or if you object to the processing of data for direct marketing purposes;
• - if the Data have been processed unlawfully; unless the processing is necessary: - for the fulfillment of a legal obligation that requires the processing of your data; in particular as regards the retention periods of documents provided for by law; - to ascertain, exercise or defend a legal right or claim.
- Right to limitation of treatment (Article 18 GDPR): you can obtain a limitation of the processing of your data if these are not exact or if they are no longer necessary;
- Right to data portability (Article 20 GDPR): You are entitled to receive one copy of your data, previously provided directly to H2O, and if expressly requested by you, we undertake to transfer the same - where this is technically possible - to another data controller indicated by you;
- Right to object (Article 21 GDPR): You may object at any time, for reasons connected with your particular situation, to the processing of your data, pursuant to art. 6, paragraph 1, letters e) or f) of the GDPR, or if the personal data are processed for direct marketing purposes. In this case, we will no longer process your data. This last condition does not apply if we can demonstrate the existence of compelling legitimate reasons that justify the processing and that prevail over your interests, or if we need your data to ascertain, exercise or defend a right in court.
- Right to withdraw consent at any time (Article 13 of the GDPR) if the treatment is based on consent - without prejudice to the lawfulness of the treatment based on the consent given before the revocation, by sending the related request to the contacts listed below or through the technical methods possibly made available by H2O.
H2O will try to manage all requests within a reasonable period and, approximately, within 30 days, unless an extension is motivated and communicated.
- Complaint: You always have the right to make a report and lodge a complaint with a competent data protection authority, pursuant to art. 77 of the GDPR.

In any case, you will find every broader reference in terms of current legislation on the website of our Guarantor for the protection of personal data at the internet address www.garanteprivacy.it and the complete text of the GDPR can be consulted by accessing the following website:
http://eur-lex.europa.eu/legal-content/IT/TXT/?uri=uriserv:OJ.L_.2016.119.01.0001.01.ITA&toc=OJ:L:2016:119:TOC

The data controller is H2O srl, in the person of the Legal Representative, who can be contacted at the following address Viale Luigi Schiavonetti 270, 00173 Rome.

For all requests for information and to exercise your rights, you can contact H2O srl:
- by post to H2O srl, in Viale Luigi Schiavonetti 270, 00173 Rome;
- by telephone at 06 5010699;
- by email at info@h2o.it;