COOKIE POLICY

<p>Last updated May 2021.</p>
<p>Welcome to our website Miscusi.com (the “<strong>Website</strong>”).</p>
<p>This privacy notice regarding the processing of personal data ("<strong>notice</strong>") applies to the processing of your personal data by Miscusi S.r.l. (“<strong>Miscusi</strong>” or the “<strong>Controller</strong>”) through our Website pursuant to Regulation (EU) 2016/679 - General Data Protection Regulation ("<strong>GDPR</strong>"), Legislative Decree No. 196/2003 (as subsequently amended), the relevant decisions and guidelines of national and European data protection authorities, as well as applicable national and European legislation (jointly, the "<strong>Applicable Law</strong>").</p>
<p>Some services offered by us may be subject to specific notices; in such cases, we will provide you, from time to time, with all relevant information.</p>
<p>&nbsp;</p>
<ol>
<li><strong>The data controller&nbsp;</strong></li>
</ol>
<p>The data controller is Miscusi S.r.l., with registered office at Piazza Castello 26, 20121 Milan (MI), Italy, VAT No. IT09677510969. For any request relating to the processing of your personal data, you may contact us by sending an e-mail to [email protected] or by sending written correspondence to our registered office.</p>
<p><strong>&nbsp;</strong></p>
<ol start="2">
<li><strong>Categories of data processed, purposes of the processing, legal bases&nbsp;</strong></li>
</ol>
<p>We will process your personal data, both by manual and automated means, for the following purposes and under the following conditions.</p>
<p>&nbsp;</p>
<div class="table-wrapper"><table width="633">
<tbody>
<tr>
<td width="245">
<p><strong>Purpose</strong></p>
</td>
<td width="151">
<p><strong>Legal basis</strong></p>
</td>
<td width="236">
<p><strong>Categories of data processed</strong></p>
</td>
</tr>
<tr>
<td width="245">
<p>(i)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To enable you to use the Website.</p>
</td>
<td width="151">
<p>Performance of pre-contractual measures taken at the data subject’s request and performance of a contract to which the data subject is party (Art. 6(1)(b) GDPR).</p>
</td>
<td width="236">
<p>Details of the web browser used and the IP address and any additional browsing-related data.</p>
</td>
</tr>
<tr>
<td width="245">
<p>(ii)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To enable you to purchase our products offered on the Website, as well as to use our services (<em>e.g. pre-order and pickup, </em>book a table, <em>e-commerce</em>).</p>
</td>
<td width="151">
<p>Performance of pre-contractual measures taken at the data subject’s request and performance of a contract to which the data subject is party (Art. 6(1)(b) GDPR).</p>
</td>
<td width="236">
<p>Identification and contact data collected in relation to the requested service (<em>e.g.</em> shipping address, billing address and payment data).</p>
</td>
</tr>
<tr>
<td width="245">
<p>(iii)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To enable you to book our premises for an event / <em>team building</em> activity on our Website.</p>
</td>
<td width="151">
<p>Performance of pre-contractual measures taken at the data subject’s request and performance of a contract to which the data subject is party (Art. 6(1)(b) GDPR).</p>
</td>
<td width="236">
<p>Identification and contact data, as well as any additional information voluntarily provided.</p>
</td>
</tr>
<tr>
<td width="245">
<p>(iv)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To assess your CV in the event of an application.</p>
</td>
<td width="151">
<p>Performance of pre-contractual measures taken at the data subject’s request and performance of a contract to which the data subject is party (Art. 6(1)(b) GDPR).</p>
</td>
<td width="236">
<p>Identification and contact data and the content of the documentation you choose to share with us.</p>
<p>We ask that you do not send us special categories of personal data.</p>
</td>
</tr>
<tr>
<td width="245">
<p>(v)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To process and respond to any requests submitted by you through the contact channels indicated on the Website (<em>i.e.</em> <em>customer service</em>).</p>
<p>&nbsp;</p>
</td>
<td width="151">
<p>Performance of pre-contractual measures taken at the data subject’s request and performance of a contract to which the data subject is party (Art. 6(1)(b) GDPR).</p>
</td>
<td width="236">
<p>The personal data collected through our Website, for example, the data directly provided by you or that we collect when you send us an e-mail to request information (<em>e.g</em>. first name and surname, subject of the request, e-mail address and telephone number), details of the web browser used and the IP address.</p>
</td>
</tr>
<tr>
<td width="245">
<p>(vi)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To comply with legal obligations and respond to requests from competent authorities.</p>
</td>
<td width="151">
<p>Compliance with a legal obligation to which we are subject (Art. 6(1)(c) GDPR).</p>
</td>
<td width="236">
<p>Any information that may be required by law or to respond to requests received from the competent public authority.</p>
</td>
</tr>
<tr>
<td width="245">
<p>(vii)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To protect our rights and those of our employees and collaborators, in judicial and extrajudicial proceedings.</p>
</td>
<td width="151">
<p>&nbsp;</p>
<p>Pursuit of our legitimate interest or that of a third party (Art. 6(1)(f) GDPR).</p>
<p>&nbsp;</p>
</td>
<td width="236">
<p>Any information necessary to ensure the fulfilment of this purpose.</p>
</td>
</tr>
<tr>
<td width="245">
<p>(viii)&nbsp;&nbsp;&nbsp;&nbsp; To carry out extraordinary transactions involving the Controller (including mergers, acquisitions, transfers, corporate reorganisations, corporate restructurings), to the extent strictly necessary for pursuing this purpose and on the basis of the Controller’s legitimate interest following an appropriate balancing with the rights and fundamental freedoms of data subjects.</p>
</td>
<td width="151">
<p>&nbsp;</p>
<p>Pursuit of our legitimate interest or that of a third party (Art. 6(1)(f) GDPR).</p>
<p>&nbsp;</p>
</td>
<td width="236">
<p>Only the information necessary to ensure the fulfilment of this purpose.</p>
</td>
</tr>
<tr>
<td width="245">
<p>(ix)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To send you commercial communications limited to our products and/or services similar to those you have purchased (so-called <em>soft spam</em>) by e-mail.</p>
</td>
<td width="151">
<p>Pursuit of our legitimate interest or that of a third party (Art. 6(1)(f) GDPR).</p>
<p>&nbsp;</p>
</td>
<td width="236">
<p>E-mail address provided when creating the <em>account</em>.</p>
</td>
</tr>
<tr>
<td width="245">
<p>(x)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To send you information and marketing communications, newsletters and/or market research about our products and/or the products of our commercial partners, such as promotions, through automated tools (<em>e.g. </em>e-mail, SMS, telephone, WhatsApp) and through traditional means (<em>e.g. </em>postal mail), without however sharing your data with third parties. Such communications will be sent to you by e-mail, unless you have also provided other contact details and consented to receive such communications through those channels.</p>
</td>
<td width="151">
<p>Consent of the data subject (Art. 6(1)(a) GDPR).</p>
</td>
<td width="236">
<p>The identification and contact data you have provided (i.e. first name, surname, e-mail address and any other contact details if provided).</p>
</td>
</tr>
<tr>
<td width="245">
<p>(xi)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To carry out data analysis and processing activities to improve our products/our service, also in order to send you only content that is relevant to you (e.g. informing you of the opening of one of our new restaurants in the city where you have already booked with us, provided that you have given your consent under point (x)).&nbsp;</p>
</td>
<td width="151">
<p>Pursuit of our legitimate interest or that of a third party (Art. 6(1)(f) GDPR).&nbsp;</p>
</td>
<td width="236">
<p>The data you provide when using the Website and the services offered through it.</p>
</td>
</tr>
</tbody>
</table></div>
<p>&nbsp;</p>
<p>To find out how we process your data through the use of cookies, please consult our Cookie Policy.</p>
<p><strong>&nbsp;</strong></p>
<ol start="3">
<li><strong>Nature of the provision of data</strong></li>
</ol>
<p>The personal data collected for the purposes referred to in numbers (i)-(vi) of Section 2 above will be processed as necessary to perform a contract to which you are a party and/or pre-contractual measures adopted at your request, as well as to comply with a legal obligation to which Miscusi is subject. You are free to provide us with your data or not, but in the absence of the requested data we will not be able to allow you to use the Website, its features or respond to your requests.</p>
<p>&nbsp;</p>
<p>The personal data collected for the purposes referred to in numbers (vii)-(ix) of Section 2 above will be processed on the basis of the legitimate interest of Miscusi or third parties. The right to object, including in relation to so-called <em>soft spam</em> communications, may be exercised by contacting us using the contact details indicated in this notice and/or, with specific reference to marketing communications, by clicking the appropriate “unsubscribe” link at the bottom of each communication or by sending an e-mail to the contact address indicated in this notice. Exercising the right to object may affect your ability to continue using the Website or its features. For more information on the legitimate interests pursued and the related balancing assessments carried out by us, you may contact us using the contact details indicated in this notice.</p>
<p>&nbsp;</p>
<p>The data collected for the purpose referred to in number (x) of Section 2 above will be processed only with your free, specific, informed and unambiguous consent. The provision of your personal data for this purpose is not necessary for the use of the Website and its features; however, failure to provide it will prevent you from receiving communications on commercial initiatives (including possibly profiled ones) from Miscusi relating to its own products and/or those of our commercial partners. Any consent given may be withdrawn at any time, without affecting the lawfulness of processing based on consent before its withdrawal. Consent may be withdrawn by clicking the appropriate “unsubscribe” link at the bottom of each communication or by sending an e-mail to the contact address indicated in this notice. Any refusal to give consent, or subsequent withdrawal of it, will only result in the impossibility of receiving marketing communications (including possibly profiled ones) from us, while it will not prevent you from continuing to use the Website and its features.</p>
<p>&nbsp;</p>
<ol start="4">
<li><strong>Data retention&nbsp;</strong></li>
</ol>
<p>Your personal data will be processed for the time strictly necessary to achieve the purposes for which it is collected and will be retained for different periods depending on the purpose pursued. At the end of the indicated retention period, the personal data will be deleted or anonymised. In particular, your personal data, processed for the purposes referred to in Section 2 above, are retained in compliance with the terms and criteria specified below:</p>
<ul>
<li>Purposes (i), (ii), (iii), (vi), (vii) and (viii): personal data collected for these purposes will be retained for the time strictly necessary to pursue such purposes, unless it is necessary to retain them longer in order to comply with a legal obligation, an order of an Authority, or to defend one of our rights.</li>
<li>Purpose (iv): personal data collected following receipt of the CV will be retained for eighteen months from receipt.</li>
<li>Purpose (v): data collected to satisfy your requests will be retained until your request has been fulfilled, unless it is necessary to retain them longer in order to comply with a legal obligation, an order of an Authority, or to defend one of our rights.</li>
<li>Purposes (ix)-(xi): regardless of the existence of an active account, personal data will be processed for sending marketing communications, newsletters and/or market research, also for <em>soft spam</em> purposes, as well as for improving our products/our service, until you decide to withdraw the consent given and/or exercise the right to object, without prejudice to the fact that, after one year from your last access or interaction with our services, your data will in any case be deleted or anonymised, and that, after one year from their collection, the data used for improving our products/our service will in any case be deleted.</li>
<li>Purpose (xi): personal data processed for profiling purposes will be retained for a period not exceeding [1 (one) year] from collection, after which they will be deleted or anonymised.</li>
</ul>
<p>More detailed information about retention periods is available upon request, by contacting us using the contact details indicated in this notice.</p>
<p>&nbsp;</p>
<ol start="5">
<li><strong>Transfer of data outside the European Economic Area</strong></li>
</ol>
<p>Where necessary for pursuing the purposes indicated in Section 2 above, your personal data may be transferred outside the European Economic Area (“EEA”). Some of the third parties listed in the following section “Who processes the data” may in fact be based in countries outside the EEA.</p>
<p>Whenever your personal data are transferred outside the EEA and, in particular, to States that do not benefit from an adequacy decision of the European Commission, we will adopt one of the safeguards provided for this purpose by the Applicable Law, for example by entering into the standard contractual clauses adopted by the European Commission, keeping them updated, and we will adopt any further technical, organisational and/or contractual measures suitable to ensure a level of protection of your personal data that is adequate and, in any case, essentially equivalent to that guaranteed within the EEA.</p>
<p>The list of countries outside the EEA to which we may transfer your personal data is available upon request, by contacting us using the contact details indicated in this notice.</p>
<p>&nbsp;</p>
<ol start="6">
<li><strong>Who processes the data</strong></li>
</ol>
<p>Your personal data will be processed by Miscusi personnel specifically instructed and authorised to process them.</p>
<p>In addition, to the extent necessary for pursuing the purposes referred to in Section 2 above, your personal data may be transmitted to the following categories of subjects:</p>
<ul>
<li>companies providing services connected and/or instrumental to the services offered by Miscusi (<em>e.g.</em> companies operating in the fields of marketing, data processing and <em>advertising</em>, including <em>social networking</em> sites, companies providing IT and telematic services, storage services, couriers and/or other administrative, accounting or legal services to Miscusi);</li>
<li>consultants, lawyers, accountants of the Controller or of another party involved in a corporate transaction or for the protection of rights, as well as the party involved as potential and/or actual transferee, purchaser, etc., if your personal data must be communicated in order to assess and/or complete the corporate transaction and/or if a third party takes over as new data controller, as well as where it becomes necessary, in the interest of the Controller, to involve consultants for other business needs;</li>
<li>independent authorities, law enforcement bodies or judicial and administrative authorities for their institutional purposes within the limits established by law, as well as for the detection and prosecution of crimes, prevention and protection from threats to public security, to enable Miscusi to establish, exercise or defend a right in court, as well as for other reasons related to the protection of the rights and freedoms of others.</li>
</ul>
<p>With reference to the personal data communicated to them, the subjects indicated may act, depending on the case, as data processors, on the basis of a specific data processing agreement with Miscusi, or as independent controllers, on the basis of their own privacy notice (in which case the communication of personal data will be limited to what is necessary to achieve the purposes of processing referred to in Section 2 above, and will take place on the basis of the same legal bases referred to in Section 2).</p>
<p>You may request from us at any time a detailed and updated list of such subjects and their privacy roles.</p>
<p>Your data may also be collected by third parties when you accept third-party cookies. Please consult our Cookie Policy for further information.</p>
<p>&nbsp;</p>
<ol start="7">
<li><strong>Your rights </strong></li>
</ol>
<p>To the extent that they are applicable to the processing described in this notice, you may exercise the rights referred to in Articles 15 et seq. of the GDPR. In particular, you may at any time ask us to access, rectify and erase your personal data, as well as restrict their processing. You may also object to processing based on our legitimate interest and/or exercise the right to data portability concerning your personal data. Finally, you may at any time withdraw any consent given to us.</p>
<p>Should you consider that the processing of your personal data violates the principles laid down by the Applicable Law, you may lodge a complaint with the judicial authority or with the supervisory authority for the protection of personal data in the Member State where you habitually reside, work or where the alleged infringement occurred. The competent authority in Italy is the Data Protection Authority (“Garante”). More information on how to lodge complaints is available on the Garante’s website at http://www.garanteprivacy.it.</p>
<p>For any request relating to the processing of your personal data, you may contact us by sending an e-mail to [email protected] or by sending written correspondence to our registered office.</p>
<p>&nbsp;</p>
<ol start="8">
<li><strong>Changes to this notice</strong></li>
</ol>
<p><strong>&nbsp;</strong>The development of our services may result in changes to the characteristics of the processing of your personal data described herein. Consequently, this privacy notice may be amended and supplemented over time, including where necessary due to new regulatory interventions. We therefore invite you to periodically check this page to verify whether anything has changed: where possible, we will seek to inform you promptly about the amendments made and their consequences.</p>
<p>The updated version of the privacy notice will, in any case, be published on this page, indicating the date of its latest update.</p>