Via Umbria 33, 57017 Collesalvetti (LI) - Italy

Ufficio Commerciale

Via Monte Napoleone 8, 20121 Milano (MI) - Italy

Privacy Policy

Privacy Policy

INFORMATION ON THE PROCESSING OF PERSONAL DATA pursuant to Article 13 of EU Regulation 2016/679, General Data Protection Regulation (‘GDPR’) and Italian Legislative Decree no. 196/2003, Code on the protection of personal data (‘Privacy Code ’)

This information is provided for the site (hereinafter “the site”) and other services connected to it, which provide for interaction with the user.  

This information does not concern other sites, pages or online services accessible through hyperlinks that may be published on the site but refer to resources outside the domain

To whom the information is addressed

The information is intended for all those who interact with the web pages of the site, both those who use the site without registering, and those who, at the end of a specific procedure, register on the site and use the online services provided through it. 

This information is provided pursuant to Article 13 GDPR and the Privacy Code, limited to the provisions applicable compatibly with the GDPR, as well as in accordance with Recommendation no. 2/2001 that the European Authorities for the Protection of Personal Data, gathered in the Group established by Article 29 of Directive no. 95/46/EC, adopted on 17 May 2001 to identify some minimum requirements for the collection of personal data online, and subsequent amendments and additions.

Data controller

Following consultation of this site, data relating to identified or identifiable persons may be processed.

Il titolare del tThe data controller is


Registered Office and Operational Headquarters 

Via Umbria 33 57017 

Stagno, Collesalvetti (LI) Italia 

VAT 01979890496


Mail :

Code: M5UXCR1

Data protection officer

The Data Controller has appointed a Data Protection Officer (DPO) to whom it is possible to turn to exercise all the rights provided for by Articles 15 to 21 of the GDPR.

to turn to exercise all the rights provided for by Articles 15 to 21 of the GDPR. 

The Data Protection Officer (DPO) can be reached at the following email address:

External data protection officers

Additional external data protection officers – for data collected for the aforementioned purposes – have been identified as the following external entities duly authorised to process for the needs of technological maintenance of the site and production of the data connected to it: 

Uplink Web Agency Srl

Via Aurelia 929
57016 – Fraz. Castiglioncello – Rosignano (LI)
VAT 01350780498

Legal basis for data processing

IN&OUT HEALTHY SRL, the data controller of the data collected through its website, processes personal data both manually and electronically, in a strictly confidential manner and for the period of time necessary to provide the requested services.

In accordance with the relevant European legislation, IN&OUT HEALTHY SRL adheres to strict security procedures in the processing of personal data, in order to prevent improper use of it, deriving from any unauthorised access.

Type of data processed

DaPersonal data and identifying data

Personal data and identifying data

Common personal data means any information relating to a natural person, identified or identifiable, even indirectly, by reference to any other information.

Identification data refers to the set of personal data that allow the direct identification of the data subject (such as, for example, first name, surname, email address, address, telephone number, etc.).

Please note that through the website and the use of the related features and/or adherence to the services provided therein, the following can be collected and processed for the purposes indicated in the dedicated paragraph: 

•     common and identifying personal data, such as first name, surname, email address or other contact details, date of birth; 

•     data on the order and the purchase process.

For the purposes indicated in this information, IN&OUT HEALTHY SRL does not collect or process personal data attributable to the user that the GDPR qualifies as “sensitive categories” (such as, by way of example, data suitable for revealing racial and ethnic origin, religious, philosophical or other beliefs, political opinions, membership of associations or organisations of a religious, philosophical or trade union nature, as well as personal data suitable for revealing the state of health) or data relating to criminal convictions and crimes. 

Navigation data

The computer systems and software procedures used to operate this site acquire some personal data during their normal operation, the transmission of which is implicit in the use of internet communication protocols.

This category of data includes IP addresses or domain names of the computers and terminals used by users, the URI/URL (Uniform Resource Identifier/Locator) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the user’s operating system and IT environment.

This data, which is necessary for the use of web services, is also processed in order to:

  • obtain statistical information on the use of services (most visited pages, number of visitors by time or day, geographical areas of origin, number of clicks, etc.);
  • check the correct functioning of the services offered.

Data provided voluntarily by the user

The optional, explicit and voluntary sending of emails to the addresses indicated on this site involves the subsequent acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data entered. 

The data collected will not be disclosed to third parties, except as required by law.

Specific information is published on the pages of the site prepared for the provision of certain services.


Please refer to the specific cookie policy.


Purpose of processing


The processing of personal data is based on the existence of a contractual or legal obligation or, as the case may be and as better specified in the following paragraph, on the existence of a legitimate interest of IN&OUT HEALTHY SRL or on the consent of the user, optional and revocable at any time, and is aimed exclusively at achieving the following purposes: 

A. Fulfilment of contractual obligations (Article 6 letter b) GDPR) – to ensure registration on the site and the correct provision of the services requested on the site and, therefore, to fulfil in a correct and timely manner all the obligations deriving from the respective pre-contractual and contractual relationships established. 

B. The administrative and accounting purposes connected and in any case deriving from the contract concluded with the user are expressly included, also with regard to the possible transmission by email of commercial invoices by IN&OUT HEALTHY SRL.

C. It also includes in this context, the assistance/chat service and, therefore, the processing of the user’s personal data for the management and sending of responses to requests for assistance in relation to one or more of the services available on the site. 

D. It also includes the receipt of communications referring to Skin4Passion for which IN&OUT HEALTHY SRL is held harmless and indemnified from any damage, compensation obligation and/or sanction deriving from and/or in any way related to the receipt by the user, or third parties entered by the user, of said communications.

Provision of data and consequences in the event of non-provision

The provision of data for the purposes referred to in point A) (fulfilment of contractual obligations) of the preceding paragraph is merely optional.

However, since such processing is necessary to allow registration on the site and the provision by IN&OUT HEALTHY SRL of the eCommerce service, the non-provision, partial or incorrect provision of the data in question will make it impossible, depending on the case, to use the services provided and, in general, to proceed with the contractual relationship established or being established and/or to fulfil the obligations as provided for by the contract or by the applicable law or, again, to fulfil specific requests.

Communication and dissemination of data


The user’s data may be communicated to the following categories of people (“recipients”): 

a) to all those entities (including Public Authorities) that have access to personal data by virtue of regulatory or administrative provisions; 

b) to banking institutions and companies that manage national or international payment channels through which online payments are made for products purchased through the Platform; 

c) to all those entities, public and/or private, natural and/or legal persons (Judicial Offices, Chambers of Commerce, Chambers and Labour Offices, etc.), if the communication is necessary or functional for the correct fulfilment of the contractual obligations assumed, as well as of the obligations deriving from the law. 

The data concerning the user will not be disseminated, except in anonymous and aggregated form, for statistical or research purposes. 

Conservazione dei dati personali

I dati personali che riguardano l’utente saranno conservati per il solo tempo necessario a garantire la corretta prestazione dei servizi offerti da IN&OUT HEALTHY SRL e, in particolare, secondo quanto di seguito precisato: 

  • i dati dell’utente saranno trattati e conservati per tutta la durata del rapporto contrattuale e, successivamente, per il tempo massimo previsto dalle disposizioni di legge applicabili in materia di prescrizione dei diritti e/o decadenza dell’azione e, in generale, per l’esercizio/difesa dei diritti di IN&OUT HEALTHY SRL nelle vertenze promosse da pubbliche autorità, soggetti /enti pubblici e soggetti privati.

Diritti degli interessati

Gli interessati hanno diritto di chiedere al Titolare di esercitare i seguenti diritti.

Diritto di accesso

Gli interessati potranno richiedere di ottenere la conferma in merito all’esistenza o meno di un trattamento sui dati personali e, in caso positivo, di accedere a tali dati e ad informazioni specifiche sul trattamento, quali, a titolo esemplificativo, le finalità, le categorie di dati oggetto di trattamento, l’esistenza degli altri diritti di seguito indicati. Potranno, inoltre, chiedere una copia dei dati. 

Diritto di rettifica

Gli interessati hanno il diritto di chiedere ed ottenere rettifica dei dati personali che li riguardano e/o l’integrazione dei dati personali incompleti. 

Diritto di cancellazione

Gli interessati potranno ottenere la cancellazione dei dati, senza ingiustificato ritardo, se (i) tali dati non sono più necessari per le finalità per cui sono stati raccolti, (ii) si oppone al trattamento dei suoi dati (come di seguito indicato) e non sussiste altro motivo legittimo prevalente per il trattamento, (iii) i dati sono trattati illecitamente, (iv) i dati devono essere cancellati in forza di un obbligo di legge.

Invitiamo a considerare che tale diritto non si applica se il trattamento dei dati è necessario, tra l’altro: 

– per l’adempimento di un obbligo di legge; 

– per l’accertamento, l’esercizio o la difesa in giudizio di un diritto. 

Diritto di limitazione

Gli interessati hanno diritto di ottenere la limitazione del trattamento in caso di: 

– contestazione dell’esattezza dei dati personali che li riguardano entro il termine necessario al titolare per verificare l’esattezza di questi dati; 

– trattamento illecito e richiesta da parte dell’interessato della limitazione d’uso in luogo della relativa cancellazione; 

– necessità da parte dell’interessato dei dati per l’accertamento, l’esercizio o la difesa di un diritto in sede giudiziaria; 

– opposizione da parte dell’intestato al trattamento, come di seguito indicato, in attesa di verifica di prevalenza di motivi legittimi da parte del titolare. 

Diritto di opposizione

Gli interessati hanno il diritto di opporsi in qualsiasi momento al trattamento basato su un legittimo interesse del titolare, salva la dimostrazione da parte di quest’ultimo di motivi legittimi cogenti per procedere al trattamento che prevalgano sugli interessi, diritti e libertà fondamentali dell’interessato oppure per l’accertamento, l’esercizio o la difesa di un diritto in sede giudiziaria. 

Diritto di Reclamo

Gli interessati che ritengono che il trattamento dei dati personali a loro riferiti effettuato attraverso questo sito avvenga in violazione di quanto previsto dal Regolamento hanno il diritto di proporre reclamo al Garante, come previsto dall’art. 77 del Regolamento stesso, o di adire le opportune sedi giudiziarie (art. 79 del Regolamento).

Inoltre, l’interessato ha il diritto di proporre reclamo all’Autorità di Controllo. 

I diritti di cui sopra potranno essere esercitati con richiesta rivolta senza formalità al Titolare. La richiesta potrà essere inviata al Titolare tramite lettera o posta elettronica ai seguenti indirizzi: 


Via Umbria 33 57017 

Stagno, Collesalvetti (LI) Italia 

P.IVA e CF 01979890496


Mail :

Privacy Policy aggiornata al 30 marzo 2022

Start typing and press Enter to search

Shopping Cart

No products in the cart.

error: Content is protected !!
This site is registered on as a development site.