Privacy Policy & Cookies

**Information on the processing of personal data of customers and business partners**

Article 13 of EU Regulation 2016/679 of 27/04/2016

Pursuant to Article 13 of EU Regulation 2016/679 of 27/04/2016, hereinafter referred to as GDPR

(General Data Protection Regulation), Mambo srl, headquartered at Viale Cassala 32, 20143 Milan

(MI), as the data controller of personal data, informs you of the following:

**Data Controller and Processor**

The Data Controller is Mambo SRL, VAT number 12079730961, headquartered at Viale Cassala

32, 20143 Milan (MI).

**Collected Data**

Automatically collected navigation data from the site: access and navigation data

Whenever users access the site, the IT systems and software procedures responsible for its

operation acquire, during their normal operation, access and navigation data (for example:

information on the browser used by the user, pages visited, date, time, and duration of each visit,

as well as other parameters related to the user’s operating system and IT environment – the

“Navigation Data”).

Data provided by users to contact the Data Controller: personal data, contact details, and other

personal information voluntarily provided

Within the mambogroup.com, via phone at +347 4440781, to request information or clarifications

regarding Mambo’s services.

**Cookies**

The site uses IT techniques for the direct acquisition of personal identification data consisting of

“code strings”: the “cookies”. For all information on the cookies active on the site and the related

personal data processing, please refer to the sheet dedicated to the management and processing

of cookies.

**Purpose of Data Processing**

The personal data you provide will be used exclusively for the following purposes:

– Monitoring the correct functioning of the site, anonymously and in aggregate form, for statistical

purposes related to understanding how the site is used by users, to improve accessibility and

increase its attractiveness, as well as to detect any technical problems as soon as possible.

– Compliance with obligations imposed by law, regulations, applicable legislation, and other

provisions issued by authorities vested with the law and supervisory and control bodies. The

processing of personal data for the above purposes does not require your explicit consent (Article

6 letters b) and e) of the GDPR).

– The personal data, contact details, and other personal data voluntarily provided by users when

contacting the Data Controller will be used solely to respond to users’ various requests and

possibly provide a quote for the requested services. These uses are based on the fact that users

themselves contact the Data Controller to obtain information about Mambo services. Thus, the

Data Controller cannot respond to such requests without using this data.

– Conduct marketing and promotion activities for the controller’s products and services,

commercial communications, both automated and non-automated (e.g., SMS, fax, MMS, email,

etc.) or traditional (by phone, mail). Development of studies and market research.The processing of personal data for the above purposes requires your explicit consent (Article 7 of

the GDPR). This consent covers both the automated and traditional communication methods

described above. You will always have the right to freely and freely object, in whole or in part, to

the processing of your data for such purposes, for example, excluding automated contact

methods and expressing your wish to receive commercial and promotional communications solely

through traditional contact methods.

**Mandatory or Optional Nature of Providing Data and Consequences of Not Providing Personal

Data**

The data required for the purposes mentioned in paragraphs 1 and 2 above must be provided to

comply with legal obligations and/or to conclude and execute the contractual relationship and

provide the requested services. Therefore, any refusal, even partial, to provide such data would

make it impossible for the Supplier to establish and manage the relationship itself and provide the

requested service.

The provision of personal data necessary for the purposes mentioned in paragraphs 3 and 4

above is optional, so any refusal to provide such data would make it impossible to carry out the

activities described therein.

**Methods of Data Processing**

The processing of personal data is carried out through the operations indicated in Article 13 of

Law no. 196/2003. 4 no. 2) GDPR, for the above purposes, both on paper and electronically, using

electronic or automated tools, in compliance with current legislation, particularly in terms of

privacy and security and respecting the principles of fairness, legality, and transparency and

protection of customer rights.

The processing is carried out directly by the controller’s organization, its managers, and/or

agents.

**Communication and Dissemination**

Your personal data may be communicated, within the limits strictly relevant to the obligations,

tasks, and purposes mentioned above and in compliance with current legislation, to the following

categories of subjects:

– Subjects to whom such communication must be made to fulfill or enforce compliance with

specific obligations provided by laws, regulations, and/or community regulations.

– Companies belonging to the controller’s Group or controlled, controlled or connected

companies pursuant to Art. 2359 of the Civil Code, which perform the function of data controller

or for administrative and accounting purposes (purposes connected with the performance of

internal, administrative, financial, and accounting activities, particularly functional to the fulfillment

of contractual and pre-contractual obligations).

– External individuals and/or legal entities providing instrumental services to the Data Controller’s

activities for the purposes referred to in paragraph 1 above (suppliers, consultants, companies,

entities, institutions, professional firms). These subjects will act as data controllers.

Personal data will not be disseminated in any way.

**Personal Data Retention Period**

Data will be processed both on paper and electronically, via systems that ensure protection,

security, and confidentiality.

The Data Controller has also adopted specific and adequate logical, legal, organizational, and

technical security measures to prevent data loss, unlawful or unauthorized use, and unauthorized

access.

Data will not be kept for longer than necessary. Specifically:- Navigation Data – which does not allow for user identification – does not persist for more than 1

week and is immediately deleted after aggregation (except for any need to ascertain crimes by the

competent Judicial Authority);

– Personal data, contact details, and other voluntarily transmitted personal data necessary to

respond to users’ requests are kept for up to 1 year after receiving the request and, in the case of

establishing a contractual supply relationship, are also kept until the contract is executed and, in

any case, for 10 years.

Data will be kept for a longer time if necessary to comply with legal obligations or to ensure

judicial protection of the controller’s rights, always respecting the maximum terms allowed by law.

**Data Transfer**

Personal data is stored on servers located within the European Union. In any case, it is

understood that the Data Controller, if necessary, will have the right to move the servers outside

the European Union. In this case, the Data Controller ensures that the non-EU data transfer will

take place following the applicable legal provisions, subject to the stipulation of the standard

contractual clauses provided by the European Commission.

**Rights of the Data Subject**

As a data subject, you have the rights referred to in Art. 15 GDPR, specifically the rights to:

– Obtain confirmation of the existence or not of personal data concerning you, even if not yet

registered, and their communication in an intelligible form.

– Obtain the indication: a) of the origin of the personal data; b) of the purposes and methods of

processing; c) of the logic applied in case of processing carried out with the aid of electronic

instruments; d) of the identification details of the data controller, the managers, and the

representative designated pursuant to Art. 7 of Legislative Decree no. 196/2003. 5, paragraph 2 of

the Privacy Code and Art. 5, paragraph 2 of the Privacy Code and Art. 3, paragraph 1, GDPR; e)

of the subjects or categories of subjects to whom personal data may be communicated or who

may become aware of it as a designated representative in the territory of the State, managers, or

agents.

– Obtain: a) the update, correction, or, when interested, the integration of data; b) the deletion,

transformation into anonymous form, or blocking of data processed in violation of the law,

including those whose retention is not necessary for the purposes for which the data were

collected or subsequently processed; c) the attestation that the operations referred to in letters a)

and b) have been brought to the knowledge, also as regards their content, of those to whom the

data have been communicated, except where such fulfillment proves impossible or involves a use

of means manifestly disproportionate to the right protected.

– Object, in whole or in part: a) for legitimate reasons to the processing of personal data

concerning you, even if pertinent to the purpose of the collection; b) to the processing of personal

data concerning you for the purpose of sending advertising material or direct sales or for carrying

out market research or commercial communication, through automated call systems without the

intervention of an operator via email and/or traditional marketing methods by phone and/or paper

mail. It is specified that the data subject’s right to object, as described in the previous point b), for

direct marketing purposes with automated methods, extends to traditional ones and that, in any

case, the possibility remains for the data subject to exercise the right to object even only partially.

Therefore, the data subject can decide to receive only communications through traditional

methods or only automated communications or neither of the two types of communication.

If applicable, you also have the rights referred to in Articles 16-21 GDPR (Right of Rectification,

Right to be Forgotten, Right to Restriction of Processing, Right to Data Portability, Right of

Opposition), as well as the right to lodge a complaint with the Supervisory Authority.

To exercise the rights referred to in Art. 15 of the GDPR or for questions or information regarding

the processing of your data and the security measures adopted, you can in any case submit your

request to the following address:Mambo Srl

– Viale Cassala 32, 20143 Milan (MI), Italy

Phone: +347 4440781

Email: finance@mambogroup.com

**Cookie Policy**

**Effective Date: August 7, 2019**

This cookie policy describes how we use cookies and similar technologies to provide,

personalize, evaluate, improve, promote, and protect our services. If you have any comments or

questions about this cookie policy, do not hesitate to contact us at finance@mambogroup.com

**What are cookies?**

Cookies are small pieces of text sent to your browser when you visit a site. They serve various

functions, such as allowing us to remember certain information you provide while navigating

between the pages of the services.

**What types of cookies do we use?**

We use cookies on the website for the following purposes:

– **Authentication, personalization, security, and other functional cookies:** Cookies help us verify

your account and device and determine when you are logged in, making it easier for you to

access the services and provide appropriate experiences and features. We also use cookies to

prevent fraudulent use of login credentials and to remember choices you have made about the

services, such as your language preference.

– **Performance and analysis:** Cookies help us analyze how the services are accessed and used

and enable us to track the performance of the services. For example, we use cookies to

determine if you have viewed a page or opened an email. This helps us provide you with

information you find interesting.

– **Third-party cookies:** Third-party services may use cookies to help you access their services

from our services. The use of cookies by third parties is governed by the third party’s policy that

sets the cookie. The main types of third-party cookies we use are:

– **Advertising cookies:** These cookies allow the site to create an anonymous profile of users

based on their browsing experience on this site and others. This allows us to provide users with

targeted advertising based on their interests rather than generic advertising. Here is a list of

advertising cookies (includes a link to more information about these cookies and instructions on

how to manage user consent):

– Google

– Doubleclick

– **Retargeting cookies:** These cookies allow third parties to send advertisements to users

who have previously visited the site. Here is a list of targeted cookies:

– Criteo

– Facebook Custom Audience

– **Social media cookies:** These cookies are necessary to share content on social networks.

Here is a list of social media cookies:

– Instagram

– Facebook

– Twitter

– YouTube

– **Analytical cookies:** These cookies are collected by third parties, individually or aggregated,

to collect information on the number of users and how they visit the website, such as information

on which pages or sections are most viewed. Here is a list of analytical cookies (includes a link to

pages with more information about these cookies and instructions on how to manage user

consent):- Google Analytics

– Hotjar

– GA audience

**Denying consent**

The site uses cookies that do not allow any control over the user’s device and do not install

programs on the user’s device. You can set your browser not to accept cookies, but this may limit

the ability to use the services. Users can manage cookie preferences through the web browser

settings.

**How we identify the device**

We use device identifiers on our website to track, analyze, and improve the performance of the

services and our advertisements.

**Third-party tags**

We use and manage third-party tags on the website. Third-party tags can take the form of pixels

or tracking fragments. We use pixels to know how you interact with site pages and emails, and

this information helps us and our advertising partners provide you with a more personalized

experience. We use Google Tag Manager to manage the use of third-party tags. This can cause

other tags to be triggered, which may, in turn, collect data and set cookies in certain

circumstances. Google Tag Manager does not store this data.

**Updates to this cookie policy**

When we make changes, we will update the “effective date” at the top of the cookie policy and

post it on our sites. We invite you to periodically check this cookie policy for any changes since

your last visit.

**How to contact us**

If you have any questions, comments, or complaints about this privacy policy or our privacy

practices, or if you want to exercise your rights and choices, please email us at

finance@mambogroup.com, or write to us at the address below:

Mambo Srl – Viale Casssala 32, 20143 Milan (MI), Italy.