Legal

Privacy Notice

Last updated: 15 May 2026

Ars Aures values the privacy of the people who visit the arsaures.com site and who contact us for information, showroom listenings, purchases or support. This notice explains what data we collect, why and how we process it, pursuant to Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended (Italian Privacy Code).

1. Data Controller

The Data Controller, pursuant to Art. 4 No. 7 GDPR, is:

ARS AURES S.r.l.
Registered office: SS 115 km 68 s.n.
VAT / Tax Code: 02832390815
REA registration: TP-200052
Email: privacy@arsaures.com

For any request relating to the processing of personal data you may write to privacy@arsaures.com.

2. Categories of data collected

We process the following categories of personal data:

  • Identification and contact data voluntarily provided by filling in the website forms (information request, showroom listening booking, newsletter subscription, dealer application): first name, last name, email, telephone, city, country, optional company name and role.
  • Browsing data automatically collected by the systems that operate the site: IP address, browser type and version, operating system, pages visited, date and time of requests, referrer URL. Such data is used in aggregated and anonymous form for statistical and security purposes.
  • Cookie data and similar technologies: see the "Cookies" section and the dedicated Cookie Policy.
  • Contents of communications you send us via email or through the website forms.

We do not intentionally collect data belonging to special categories pursuant to Art. 9 GDPR (racial or ethnic origin, political opinions, religious beliefs, health data, genetic or biometric data).

3. Purposes and legal bases of processing

Your personal data is processed exclusively for the following purposes:

a) Responding to requests and managing the contractual relationship

Reply to product information requests, organise showroom listenings or private demos, manage orders, sales contracts and after-sales support, provide technical assistance, comply with related legal obligations (tax, accounting, warranty).

Legal basis: performance of a contract or pre-contractual measures at your request (Art. 6.1.b GDPR); compliance with legal obligations (Art. 6.1.c GDPR).
Provision of data: required; refusal makes it impossible to follow up on the request.

b) Selection and management of the dealer and distributor network

Evaluate applications from commercial operators interested in distributing Ars Aures products and manage contractual relationships with active partners.

Legal basis: performance of a contract or pre-contractual measures (Art. 6.1.b GDPR); legitimate interest of the Controller in developing and maintaining its commercial network (Art. 6.1.f GDPR).

c) Sending marketing communications and newsletter

Send the newsletter, communicate new products, events, fairs, previews and promotional material via email and — if requested — postal mail.

Legal basis: your free, specific consent, revocable at any time (Art. 6.1.a GDPR; Art. 130 D.Lgs. 196/2003).
Provision of data: optional; refusal does not affect access to the site or the management of contact requests.

d) Statistical analysis and site improvement

Analyse site use in aggregated form to improve its content, performance and usability.

Legal basis: legitimate interest of the Controller in maintaining and improving its site (Art. 6.1.f GDPR). When third-party statistical cookies are used, the legal basis is your consent expressed through the cookie banner.

e) Site security and fraud prevention

Ensure the IT security of the site, prevent improper use, abuse, cyber attacks and fraud attempts.

Legal basis: legitimate interest of the Controller and users in the security of systems and data (Art. 6.1.f GDPR); compliance with legal obligations (Art. 6.1.c GDPR).

f) Legal defence

Ascertain, exercise or defend a right in court or out of court.

Legal basis: legitimate interest of the Controller (Art. 6.1.f GDPR).

4. Processing methods

Data is processed by electronic means and — limited to the activities that require it — on paper. Data is stored on servers located in the European Economic Area, managed directly by the Controller or by cloud service providers appointed as Data Processors pursuant to Art. 28 GDPR.

Processing takes place through procedures suitable to protect data confidentiality and prevent unauthorised access, loss, destruction or disclosure. Technical and organisational measures appropriate to the risk are adopted, including:

  • HTTPS/TLS transmission encryption;
  • role-based access controls and authentication;
  • credential protection with robustness policies;
  • periodic backups;
  • system access logging;
  • training and confidentiality commitments of authorised personnel.

Payment data (e.g. card number) is not stored on our systems: the transaction is handled directly by the payment service provider (gateway / authorised payment institution), in compliance with PCI-DSS standards and GDPR.

5. Categories of recipients

Your data may be communicated, for the purposes indicated in point 3, to the following categories of subjects:

  • authorised staff of the Controller (sales, administration, marketing, technical support, IT), duly instructed and bound to confidentiality;
  • network of authorised dealers and distributors, when your request requires forwarding to a local partner (e.g. listening at a showroom other than ours or local technical support);
  • external suppliers who carry out technical, organisational and operational activities on our behalf, appointed as Data Processors pursuant to Art. 28 GDPR: hosting and cloud providers, transactional email service providers, CMS and CRM software, IT maintainers, marketing agencies, shipping and logistics agencies, legal, tax and administrative consultants;
  • public authorities, supervisory bodies, judicial authority, where required by law or by an order of the competent authority.

The updated list of Data Processors may be requested by writing to privacy@arsaures.com.

Your data is not disclosed nor sold to third parties for their own independent marketing purposes.

6. Transfer of data outside the European Union

Data is mainly processed within the European Economic Area. Should some providers (for example email marketing or analytics services) entail the transfer of data outside the EEA, we guarantee that the transfer takes place under adequate safeguards pursuant to Art. 44 et seq. GDPR, in particular:

  • European Commission adequacy decision relating to the country of destination, or
  • Standard Contractual Clauses approved by the European Commission, supplemented by any additional measures, or
  • other safeguards provided by the GDPR.

You may request a copy of the safeguards applied by writing to privacy@arsaures.com.

7. Retention period

Data is retained for the time strictly necessary for the purposes for which it was collected and, in particular:

  • Contact data collected for response to information requests (purpose 3a): up to 24 months from the last useful contact, unless the request evolves into a contractual relationship.
  • Data relating to sales and service contracts (purpose 3a): for the entire duration of the relationship and for 10 years thereafter, in compliance with civil and tax obligations (Arts. 2220 Italian Civil Code and 22 D.P.R. 600/1973).
  • Application data of non-selected dealers (purpose 3b): up to 24 months from the application.
  • Marketing and newsletter data (purpose 3c): until withdrawal of consent or, in the absence of interactions, for 24 months from the last opening/interaction, after which the position is anonymised or deleted.
  • Browsing and security logs (purposes 3d–3e): typically up to 12 months, unless longer retention is needed for investigating cybercrime or legal defence.
  • Cookie data: according to the times indicated in the Cookie Policy.

At the end of the indicated periods, the data is irreversibly deleted or anonymised, except for retention for the time necessary for the legal defence of a right of the Controller.

8. Cookies

The site uses technical cookies necessary for proper operation and, with your consent, first or third-party analytical and profiling cookies. Consent is collected through the banner that appears on the first visit and can be revoked at any time via the "Manage cookies" link in the footer. For details on purposes, providers and retention times, see the Cookie Policy.

9. Data subject rights

At any time you may exercise the rights provided for by Articles 15-22 GDPR towards the Controller:

  • right of access (Art. 15): to obtain confirmation as to whether or not your personal data is being processed and, if so, to receive a copy of the data and information required by law;
  • right of rectification (Art. 16): to have inaccurate data corrected or incomplete data supplemented;
  • right to erasure or "right to be forgotten" (Art. 17): to obtain the deletion of data in the cases provided for;
  • right to restriction of processing (Art. 18);
  • right to data portability (Art. 20): to receive in a structured, commonly used and machine-readable format the data concerning you provided to the Controller, and to transmit it to another controller;
  • right to object (Art. 21), in particular to processing for direct marketing purposes, at any time and without the need for justification;
  • right not to be subject to a decision based solely on automated processing producing significant legal effects (Art. 22). The Controller does not carry out automated profiling activities producing such effects;
  • right to withdraw consent (Art. 7.3 GDPR) at any time, without affecting the lawfulness of processing based on consent given before withdrawal;
  • right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or with another competent supervisory authority in the Member State of residence, work or alleged infringement.

For erasure (Art. 17) and data copy/portability (Arts. 15 and 20) requests, a self-service form is available at the My data page: enter your email, choose the type of request, and receive a confirmation link valid for 24 hours. The request is executed immediately after confirmation and you receive a summary email.

For other rights (rectification, restriction, objection, complaint) or for cases that require manual identity verification, write to privacy@arsaures.com attaching a copy of an identity document. The Controller responds within one month of the request, extendable by a further two months taking into account complexity (Art. 12 GDPR). The exercise of rights is free of charge, except in the cases provided for by law.

To object to newsletter delivery only, simply click the "unsubscribe" link in each message.

10. Children's data

The site is not directed at children under 18 and we do not knowingly collect personal data of children. Should we become aware of the involuntary collection of a child's data, we will arrange for its deletion as quickly as possible. Parents and guardians who believe a child has provided us with personal data are invited to write to privacy@arsaures.com.

11. Links to third-party sites

The site may contain links to third-party websites (social networks, commercial partners, dealers, suppliers). The Controller is not responsible for the processing practices of such sites, which are governed by their own independent notices. You are invited to read the respective privacy policies before providing data.

12. Changes to this notice

The Controller reserves the right to modify or update this notice to reflect regulatory, organisational or technological changes. The updated version will be published on this page with the date of last update indicated. You are therefore invited to consult it periodically.

For any clarification or to exercise rights under the GDPR write to privacy@arsaures.com.