Privacy Policy
Privacy Policy
Last updated: 31 July 2026
This Privacy Policy describes how the personal data of users who:
-
visit the website www.prologo.it;
-
create an account;
-
make a purchase;
-
request information or assistance;
-
exercise their right of withdrawal;
-
request a return, refund or warranty assistance;
-
register a Prologo product;
-
subscribe to the newsletter;
-
interact with the services and forms available on the website;
is collected, used, stored and disclosed.
This Privacy Policy is provided pursuant to Regulation (EU) 2016/679, hereinafter the “GDPR”, Italian Legislative Decree No. 196/2003, as subsequently amended, and any other applicable personal data protection laws.
1. Data Controllers
The role of each Data Controller depends on the service used and the purpose for which the personal data is collected.
1.1 Lunar Sport S.r.l.
LUNAR SPORT S.R.L.
Registered office: Via Gianfranco Miglio 2, 21045 Gazzada Schianno (VA), Italy
VAT number and Tax Code: 03030530129
Economic and Administrative Register No.: VA-315003
Telephone: +39 0332 816961
E-mail: ecommerce@prologotouch.com
Certified e-mail address, PEC: lunarsport@pec.lunarsport.com
Lunar Sport S.r.l. acts as Data Controller for processing activities relating to:
-
technical and operational management of the e-commerce platform;
-
website browsing and security;
-
creation and management of customer accounts;
-
shopping cart and checkout management;
-
conclusion and performance of orders;
-
payments and fraud prevention;
-
invoicing and tax compliance;
-
dispatch and delivery;
-
order cancellations;
-
the right of withdrawal;
-
returns and refunds;
-
complaints;
-
the legal guarantee of conformity;
-
after-sales assistance;
-
protection and enforcement of the Seller’s rights;
-
commercial communications sent by Lunar Sport, where permitted by law or authorised by the data subject.
1.2 VELO EUROPE S.r.l.
VELO EUROPE S.R.L.
Registered office: Via Francesco Petrarca 4, 20123 Milan, Italy
Operating office: Via Piemonte 1/C, 20874 Busnago (MB), Italy
VAT number and Tax Code: 04955290962
Economic and Administrative Register No.: MI-2090481
E-mail: info@prologotouch.com
Telephone: +39 039 682 3507
VELO EUROPE S.r.l. acts as an independent Data Controller for processing activities relating to:
-
technical enquiries concerning Prologo products;
-
commercial enquiries concerning the brand;
-
product registration;
-
any commercial warranty offered by the manufacturer;
-
brand initiatives, events, competitions and campaigns;
-
newsletters and promotional communications concerning the Prologo brand, where the relevant form or consent identifies VELO EUROPE as the Data Controller;
-
management of relationships with athletes, teams, retailers and business partners;
-
analysis and development of Prologo products and services, within the limits permitted by law.
Where a request submitted to Lunar Sport exclusively concerns the technical characteristics, registration or commercial warranty of a product, the necessary personal data may be transferred to VELO EUROPE, which will process it as an independent Data Controller in order to respond to the request.
Similarly, VELO EUROPE may transfer to Lunar Sport a request concerning an order, payment, delivery, return, refund or legal guarantee, so that it may be handled by the Seller.
Where a specific service is accompanied by a separate privacy notice, that notice will supplement this Privacy Policy or, in the event of any conflict, prevail over it.
2. Categories of personal data processed
Depending on the service used, the following categories of personal data may be processed.
2.1 Identification and contact details
-
first name and surname;
-
postal address;
-
billing address;
-
delivery address;
-
e-mail address;
-
telephone number;
-
country and language;
-
company name, where applicable;
-
VAT number and Tax Code;
-
electronic invoicing recipient code or certified e-mail address;
-
company representative’s details.
2.2 Account data
-
login credentials;
-
account identifier;
-
order history;
-
products saved or added to the shopping cart;
-
language and geographical preferences;
-
privacy consents and preferences;
-
communications associated with the account.
Passwords are managed through technical systems that do not normally allow the Data Controller’s staff to view them in plain text.
2.3 Order and transaction data
-
products purchased;
-
quantities;
-
prices;
-
discounts;
-
currency;
-
date and time of the order;
-
order number;
-
delivery method;
-
order status;
-
invoice information;
-
information concerning returns, refunds and disputes;
-
payment transaction references.
Lunar Sport does not normally retain complete payment card details where such information is processed directly by the payment service provider.
2.4 Payment and fraud-prevention data
The following information may be processed:
-
payment outcome;
-
transaction identifier;
-
amount and currency;
-
final digits or type of payment instrument, where available;
-
IP address;
-
device information;
-
risk indicators;
-
inconsistencies between billing, payment and delivery information;
-
information received from payment service providers and fraud-prevention services.
2.5 Dispatch and delivery data
-
recipient’s name;
-
delivery address;
-
telephone number and e-mail address;
-
tracking number;
-
shipment status;
-
proof of delivery;
-
any delivery instructions;
-
information concerning failed delivery, storage, refusal or damage.
2.6 Return, withdrawal and warranty data
-
order number;
-
product concerned;
-
reason for the return or request;
-
withdrawal notice;
-
photographs and videos of the product;
-
description of the defect;
-
serial number, asset tag or product code;
-
proof of purchase;
-
return shipment information;
-
outcome of technical inspections;
-
information concerning repair, replacement or refund.
2.7 Data provided in communications
When a user contacts Lunar Sport or VELO EUROPE, the following information may be processed:
-
content of the e-mail or message;
-
attachments;
-
data entered in forms;
-
records of requests and responses;
-
any technical information required to handle the request.
Users are requested not to include unnecessary special categories of personal data in forms or communications, such as information concerning health, ethnic origin, political opinions, religious beliefs, trade union membership, biometric data or information concerning their sex life.
2.8 Browsing and technical data
IT systems may automatically collect:
-
IP address;
-
date and time of access;
-
pages visited;
-
products viewed or searched for;
-
activities carried out in the shopping cart;
-
referring URL;
-
technical identifiers;
-
browser type;
-
operating system;
-
device type;
-
language;
-
approximate country;
-
error information;
-
data relating to website security and interactions.
2.9 Marketing data
-
e-mail address;
-
commercial preferences;
-
consents;
-
date, time and method by which consent was obtained;
-
opening of and interaction with communications, where permitted;
-
previous purchases;
-
products viewed;
-
interests and commercial segments;
-
objections, withdrawals of consent and unsubscribe requests.
2.10 Product registration data
-
identification and contact details;
-
registered product;
-
serial number or asset tag;
-
date and place of purchase;
-
retailer;
-
proof of purchase;
-
information required to manage the commercial warranty.
3. Sources of personal data
Personal data may be collected:
-
directly from the data subject;
-
while browsing the website;
-
when creating an account;
-
during checkout;
-
through the returns portal;
-
through contact or registration forms;
-
by e-mail or telephone;
-
from payment service providers;
-
from carriers and logistics operators;
-
from fraud-prevention services;
-
from Shopify and applications connected to the online store;
-
from VELO EUROPE or Lunar Sport, where a request must be transferred to the other company;
-
from authorised retailers, where necessary for registration, assistance or warranty purposes;
-
from social media platforms, exclusively where the data subject voluntarily interacts with the relevant profiles or services.
4. Purposes and legal bases of processing
4.1 Website browsing and operation
Technical data is processed to:
-
display the website correctly;
-
maintain the user session;
-
manage language, country, currency and shopping cart;
-
provide access to the account;
-
ensure that checkout operates correctly;
-
identify and correct errors.
The legal basis is the performance of measures requested by the user, performance of the contract and the Data Controller’s legitimate interest in ensuring that the website operates correctly.
4.2 Security and prevention of abuse and fraud
Personal data is processed to:
-
protect accounts and transactions;
-
prevent unauthorised access;
-
combat spam, bots and abusive automated activity;
-
investigate suspicious transactions;
-
prevent fraud;
-
protect the website, customers and Data Controllers.
The legal basis is the legitimate interest in security, fraud prevention and protection of the assets of the companies and their users.
4.3 Account creation and management
Personal data is processed to:
-
create the account;
-
authenticate the user;
-
display orders and associated information;
-
simplify subsequent purchases;
-
manage preferences and requests.
The legal basis is the performance of pre-contractual or contractual measures requested by the user.
4.4 Order management
Personal data is processed to:
-
receive and verify the order;
-
conclude the contract;
-
process payment;
-
prepare and dispatch the products;
-
send confirmations and updates;
-
manage delivery;
-
provide assistance.
The legal basis is the performance of the contract and pre-contractual measures requested by the data subject.
4.5 Payments
The necessary personal data is disclosed to the payment service provider selected by the customer.
The legal basis is the performance of the contract.
Payment service providers may process certain personal data as independent Data Controllers in order to comply with legal obligations, prevent fraud, carry out checks and manage disputes. In such cases, their respective privacy policies also apply.
4.6 Invoicing and administrative obligations
Personal data is processed for:
-
issuing invoices and tax documents;
-
accounting;
-
tax compliance;
-
administrative checks;
-
communications to competent authorities.
The legal basis is compliance with legal obligations.
4.7 Dispatch and delivery
Personal data is processed and disclosed to carriers in order to:
-
arrange dispatch;
-
deliver the parcel;
-
provide tracking information;
-
manage storage and delivery problems;
-
manage damage or loss.
The legal basis is the performance of the contract.
4.8 Withdrawal, returns, refunds and legal guarantee
Personal data is processed to:
-
receive and document withdrawal notices;
-
manage the return;
-
inspect the products;
-
issue the refund;
-
manage complaints and lack of conformity;
-
repair or replace products;
-
comply with obligations under the Italian Consumer Code.
The legal basis is the performance of the contract and compliance with legal obligations.
4.9 Assistance and contact requests
Personal data is processed in order to respond to:
-
pre-contractual enquiries;
-
questions concerning orders;
-
technical enquiries;
-
commercial enquiries;
-
complaints;
-
after-sales requests.
The legal basis is the performance of pre-contractual or contractual measures or the legitimate interest in providing assistance and correctly managing relationships with users.
4.10 Product registration and commercial warranty
Personal data is processed by VELO EUROPE to:
-
register the product;
-
verify proof of purchase;
-
manage any commercial warranty;
-
communicate technical or safety information;
-
contact the owner in the event of a product recall;
-
provide product assistance.
The legal basis is performance of the requested service, performance of any applicable commercial warranty, compliance with legal obligations and the legitimate interest in product safety.
Registration is not required in order to benefit from the legal guarantee provided by the Seller.
4.11 Newsletters and consent-based marketing
Where consent is requested, personal data may be used to send:
-
newsletters;
-
product news;
-
promotions;
-
event invitations;
-
surveys;
-
brand initiatives;
-
personalised content.
The legal basis is the data subject’s consent.
Consent is optional and may be withdrawn at any time by using the unsubscribe link contained in communications or by contacting the relevant Data Controller.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
4.12 Communications concerning similar products — soft spam
Lunar Sport may use the e-mail address provided in connection with a completed sale to promote its own products or services that are similar to those already purchased, within the limits permitted by Italian law.
The data subject may object free of charge:
-
when the data is collected;
-
in every communication received;
-
by contacting Lunar Sport.
Following an objection, the e-mail address will no longer be used for this purpose.
4.13 Profiling and personalisation
With the data subject’s consent, data relating to browsing, purchases, preferences and interactions may be analysed to:
-
understand interests and habits;
-
create audience segments;
-
personalise content and promotions;
-
measure the effectiveness of campaigns;
-
display more relevant communications.
The legal basis is consent.
Refusal to provide consent does not prevent the user from using the website or making purchases.
4.14 Statistical analysis and service improvement
Personal data may be used in aggregated or, where possible, anonymous form to:
-
analyse website performance;
-
improve browsing;
-
assess interest in products and content;
-
improve product ranges and services.
Where analysis involves cookies or tracking tools that are not strictly necessary, processing is carried out only after consent has been obtained.
4.15 Dispute management and protection of rights
Personal data may be processed to:
-
prevent and manage disputes;
-
recover debts;
-
respond to requests from public authorities;
-
protect the rights of the Data Controllers;
-
bring or defend judicial or administrative proceedings.
The legal basis is the legitimate interest in protecting legal rights and, where applicable, compliance with legal obligations.
5. Mandatory or optional provision of personal data
Providing personal data required to:
-
create an account;
-
conclude an order;
-
process payment;
-
issue an invoice;
-
dispatch products;
-
manage withdrawal;
-
issue a refund;
-
provide warranty assistance;
is necessary in order to provide the requested service.
Failure to provide the required data may make it impossible to create the account, conclude or perform the order or manage the request.
Providing personal data for marketing, newsletter and profiling purposes is optional. Refusal to provide consent does not prevent the user from browsing the website, making purchases or receiving assistance.
6. Processing methods and security
Personal data is processed using electronic systems and, where necessary, paper records.
The Data Controllers adopt technical and organisational measures appropriate to the relevant risks, aimed at:
-
preventing unauthorised access;
-
protecting the confidentiality, integrity and availability of personal data;
-
preventing loss, destruction or alteration;
-
restricting access to authorised personnel;
-
ensuring backup and recovery procedures;
-
managing any personal data breaches;
-
periodically reviewing security measures.
However, no IT system can guarantee absolute security.
7. Recipients of personal data
Personal data may be disclosed, to the extent necessary, to the following categories of recipients:
-
authorised staff of Lunar Sport and VELO EUROPE;
-
e-commerce platform and IT infrastructure providers;
-
Shopify and its providers and sub-processors;
-
developers, website maintenance providers and Shopify application providers;
-
payment service providers, banks and financial institutions;
-
fraud-prevention service providers;
-
carriers, freight forwarders, couriers and logistics operators;
-
return-management and customer-service providers;
-
e-mail, newsletter and CRM service providers;
-
statistical, advertising and marketing service providers, subject to consent where required;
-
security and anti-bot service providers;
-
legal, tax, accounting and insurance advisers;
-
debt collection companies;
-
manufacturers, technicians or service centres involved in warranty claims;
-
public authorities, law enforcement agencies and judicial authorities, where required by law.
Service providers that process personal data on behalf of a Data Controller are appointed as Data Processors pursuant to Article 28 GDPR, where applicable.
Certain entities, including payment providers, banks, carriers, public authorities and providers of their own independent services, may act as independent Data Controllers.
An updated list of Data Processors may be requested from the relevant Data Controller.
8. Shopify platform
The website uses the Shopify e-commerce platform.
Shopify processes personal data in order to provide:
-
hosting and infrastructure;
-
online store management;
-
accounts;
-
the shopping cart;
-
checkout;
-
order management;
-
security;
-
technical support;
-
services connected to the platform.
For users located in the European Economic Area, personal data is initially processed through Shopify’s European entity. Shopify may use affiliated companies and sub-processors located outside the European Economic Area.
When Shopify processes personal data on behalf of the merchant, it normally acts as a Data Processor. For certain services of its own, including Shop or Shop Pay, Shopify may also process personal data as an independent Data Controller in accordance with its own privacy policy.
9. Anti-bot protection through hCaptcha
The website uses hCaptcha to verify that certain operations, including submitting forms or accessing protected functions, are carried out by a human being and not by abusive automated systems.
The service may analyse information including:
-
IP address;
-
device and browser type;
-
duration of the visit;
-
movements and interactions with the page;
-
technical data required to assess the risk of abuse.
The purpose is to protect the website against spam, fraud, attacks and unlawful automated use.
The legal basis is the legitimate interest in website security and, where the check is necessary to provide a requested service, the performance of pre-contractual or contractual measures.
The service provider may process personal data in the United States and other countries in accordance with the safeguards required under applicable law.
10. International transfers
Certain service providers may process personal data outside the European Economic Area.
Depending on the circumstances, transfers are carried out on the basis of:
-
adequacy decisions adopted by the European Commission;
-
Standard Contractual Clauses approved by the European Commission;
-
the Data Privacy Framework, where applicable;
-
Binding Corporate Rules;
-
other safeguards provided for under Articles 44 et seq. GDPR;
-
derogations permitted by law in specific circumstances.
Shopify may transfer personal data from its European entity to affiliated companies, including its Canadian parent company, and to international sub-processors.
The data subject may request information concerning the safeguards used by contacting the relevant Data Controller.
11. Cookies and tracking technologies
The website uses cookies and similar technologies.
Strictly necessary technical cookies may be used without consent in order to:
-
enable browsing;
-
maintain the session;
-
manage the shopping cart and checkout;
-
store language, country and currency preferences;
-
ensure security and authentication.
Analytics cookies that cannot be treated as technical cookies, as well as profiling, marketing and advertising cookies, are used only after consent has been obtained, where required.
Users may:
-
accept all cookies;
-
reject non-essential cookies;
-
choose individual categories;
-
change or withdraw their preferences through the “Cookie Settings” function.
For detailed information concerning cookies, providers, purposes and duration, users are invited to consult the website’s Cookie Policy.
12. Retention periods
Personal data is retained for the period necessary for the purposes for which it was collected and, thereafter, for the periods required or permitted by law.
Unless particular circumstances require otherwise, the following retention periods apply.
Browsing and security data
Technical and security logs are normally retained for a maximum of six months.
They may be retained for longer where necessary to:
-
investigate incidents;
-
prevent fraud;
-
respond to requests from public authorities;
-
protect legal rights in judicial proceedings.
Customer account
Account data is retained until a deletion request is received or, where the account is not used, for a maximum of 24 months from the last significant activity.
Data concerning orders, invoices and legal obligations will continue to be retained for the applicable periods even after the account has been closed.
Shopping cart
Data concerning a shopping cart that is not converted into an order is retained for the period technically necessary to provide the function and normally for no longer than 30 days, unless it is linked to an account or a different period is required for security or service-management purposes.
Orders, invoices and payments
Administrative, accounting, tax and contractual data is retained for at least 10 years from the relevant registration or conclusion of the relationship, without prejudice to longer periods required in connection with audits, disputes or proceedings.
Deliveries
Delivery data is retained together with order data for the period necessary to comply with contractual and tax obligations and to protect legal rights, normally for up to 10 years.
Withdrawal, returns, refunds, complaints and legal guarantee
Personal data is retained for the period necessary to manage the relevant case and subsequently for a maximum of 10 years from its closure, unless disputes or legal obligations require a longer retention period.
Information and assistance requests
Requests that do not result in a contractual relationship are normally retained for a maximum of 24 months from closure of the request.
Product registration and commercial warranty
Personal data is retained for the duration of the service or commercial warranty and, thereafter, for the period necessary to protect legal rights, normally for up to 10 years from closure of the relevant case.
Marketing and newsletters
Personal data processed for sending newsletters and promotional communications on the basis of consent is retained until:
-
the data subject withdraws consent;
-
the data subject objects to processing;
-
the newsletter service or the relevant promotional purpose is discontinued;
-
the data is no longer necessary, relevant or up to date in relation to the purpose for which it was collected.
The Data Controller periodically verifies whether the conditions justifying the processing continue to apply and deletes or anonymises data that is no longer necessary.
Withdrawal of consent or an objection will result in the discontinuation of the use of personal data for promotional purposes.
Information strictly necessary to document consent previously given, its withdrawal or an objection may be retained separately for the period necessary to comply with legal obligations, demonstrate compliance with applicable law and protect the Data Controller’s rights. Such information will not be used to send further promotional communications.
Profiling
Personal data processed for profiling purposes on the basis of consent is retained until consent is withdrawn and, in all cases, only for as long as it remains necessary, relevant and appropriate in relation to the stated analysis and personalisation purposes.
The Data Controller periodically verifies:
-
whether the data is up to date;
-
whether the information remains relevant to the user’s interests;
-
whether the profiling purpose continues to exist;
-
whether it remains necessary to retain the data in an identifiable form.
Data that is no longer necessary or representative is deleted, anonymised or excluded from profiling processes.
Withdrawal of consent will result in the discontinuation of profiling activities based on that consent, without affecting the lawfulness of processing carried out before withdrawal.
Communications concerning similar products — soft spam
The e-mail address used for communications concerning products or services similar to those already purchased is retained and used until:
-
the data subject objects to processing;
-
the commercial relationship or promotional purpose ends;
-
the e-mail address is no longer valid;
-
the data is no longer necessary or relevant to the purpose.
The data subject may object free of charge and at any time by using the link contained in each communication or by contacting Lunar Sport S.r.l.
Following an objection, the e-mail address will no longer be used for promotional purposes. It may be retained on a suppression list, limited to the information required to respect the objection and prevent further unwanted communications.
Cookies
The duration of cookies and tracking technologies is indicated in the Cookie Policy and the preference management panel.
At the end of the applicable retention periods, personal data is deleted, anonymised or retained exclusively where necessary to comply with legal obligations or protect legal rights.
13. Commercial communications and right to object
The data subject may withdraw consent or object to marketing at any time by:
-
using the unsubscribe link contained in e-mails;
-
changing account preferences, where available;
-
contacting the relevant Data Controller.
No justification is required in order to object to direct marketing, and exercising this right is free of charge.
Following an objection, personal data will no longer be used for direct marketing purposes but may be retained on a suppression list in order to prevent further unwanted communications.
14. Automated decision-making and profiling
The website may use automated systems to:
-
identify unusual activities;
-
assign risk indicators;
-
prevent fraud;
-
segment users and personalise content and communications, subject to consent in the cases described in this Privacy Policy.
Unless otherwise stated in a specific notice, Lunar Sport and VELO EUROPE do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject.
Orders flagged by fraud-prevention systems may be subject to human review.
Payment service providers may independently decide whether to authorise transactions in accordance with their own terms and privacy policies.
15. Children’s data
The website and its sales services are not specifically intended for children.
Users under the age of 18 should use the services with the involvement of a parent or person exercising parental responsibility.
In Italy, where an information society service is offered directly to a child and the processing is based on consent, a child who is at least 14 years old may independently provide consent within the limits permitted by law.
For children under the age of 14, consent must be given or authorised by a person exercising parental responsibility.
Where it is established that a child’s personal data has been collected in breach of applicable law, the data will be deleted or processed in accordance with the instructions of the person exercising parental responsibility.
16. Third-party links and services
The website may contain links to:
-
social networks;
-
maps;
-
videos;
-
partner websites;
-
payment service providers;
-
Shopify services;
-
other external services.
When a user accesses an external service, the relevant provider may collect personal data as an independent Data Controller.
This Privacy Policy does not govern processing carried out independently by third-party websites and services. Users are invited to consult the relevant privacy policies.
17. Rights of the data subject
Where applicable, the data subject may exercise the following rights:
-
obtain confirmation as to whether personal data is being processed;
-
access their personal data;
-
obtain rectification of inaccurate data;
-
complete incomplete data;
-
obtain erasure;
-
obtain restriction of processing;
-
receive personal data in a structured, commonly used and machine-readable format;
-
transmit personal data to another Data Controller, where technically feasible;
-
object to processing based on legitimate interests;
-
object at any time to direct marketing;
-
withdraw consent;
-
not be subject, in the cases provided for by law, to a decision based solely on automated processing;
-
lodge a complaint with a supervisory authority.
The right to erasure is not absolute. Certain personal data may be retained where necessary to:
-
comply with legal obligations;
-
perform a contract;
-
establish, exercise or defend legal claims;
-
manage a dispute;
-
ensure the security of the service.
18. How to exercise data protection rights
For processing relating to the e-commerce platform, orders, payments, deliveries, returns, refunds and the legal guarantee, data subjects may contact:
LUNAR SPORT S.R.L.
E-mail: ecommerce@prologotouch.com
Certified e-mail address, PEC: lunarsport@pec.lunarsport.com
Address: Via Gianfranco Miglio 2, 21045 Gazzada Schianno (VA), Italy
For processing relating to technical requests, product registration, commercial warranties, newsletters and brand initiatives, data subjects may contact:
VELO EUROPE S.R.L.
E-mail: info@prologotouch.com
Address: Via Francesco Petrarca 4, 20123 Milan, Italy
The request must contain sufficient information to identify the data subject and understand the right being exercised.
Where necessary to protect personal data, the Data Controller may request additional information in order to verify the identity of the applicant.
The Data Controller will normally respond within one month. This period may be extended in the circumstances provided for under the GDPR, in which case the data subject will be informed of the reasons for the delay.
Exercising data protection rights is free of charge, except where requests are manifestly unfounded or excessive.
19. Complaints to a supervisory authority
The data subject has the right to lodge a complaint with:
The Italian Data Protection Authority — Garante per la protezione dei dati personali
or with the competent supervisory authority in the European country in which the data subject resides or works, or where the alleged infringement took place.
The right to bring proceedings before the competent courts remains unaffected.
20. Amendments to this Privacy Policy
This Privacy Policy may be updated as a result of:
-
changes in applicable law;
-
changes to the services;
-
the introduction or removal of service providers;
-
changes to the purposes or methods of processing;
-
technical and organisational developments.
The updated version will be published on the website together with the date of the latest update.
Where amendments substantially affect data subjects’ rights or processing based on consent, a specific notice may be provided or new consent may be requested.