top of page


Dear Customer,

pursuant to the GDPR of 2016/679 (General Data Protection Regulation), we inform you that the personal data you provide or in any case acquired upon signing the Loyalty Card“HeavenCard”/ mailing listwill be processed in compliance with current legislation and the principles of correctness, lawfulness, transparency and protection of confidentiality provided by it.


The Data Controller is Heaven Srl, PI IT05215670281 with headquarters in Cittadella, via Guglielmo Marconi, 17, in the person of its legal representative who, within the scope of its prerogatives, may avail itself of the collaboration of specifically identified managers or agents.


The data will be processed with the aid of electronic and/or paper instruments, according to logic strictly related to the purposes indicated above and in any case by adopting suitable procedures and measures to protect their security and confidentiality.


The data processing will be aimed at carrying out the activities listed below:

  1. issue of the Loyalty Card and management of activities that cannot be carried out anonymously and are necessary to allow subscribers to use and recognize discounts and promotions, offer and send prizes, participate in collecting points and access other ancillary services that can be used with the Card;

  2. performance, subject to your express written consent, of direct marketing activities, such as the sending - by e-mail - of advertising material and communications with informative and/or promotional content in relation to products or services provided and/or promoted by the Data Controller or from its business partners, including free gifts and discounts;

  3. carrying out, subject to your express written consent, individual or aggregate profiling activities and market research within the company aimed, for example, at the analysis of consumption habits and choices, at the elaboration of statistics on the same or at the evaluation the degree of satisfaction with the products and services offered.



For the purposes referred to in point 1 of the previous point, the provision of data is optional, but constitutes a necessary and indispensable condition for the issue of the Loyalty Card: failure to provide it therefore makes it impossible for the applicant to obtain the Card itself. For the purposes referred to in points 2. and 3. of the previous point, the provision of data is optional and any refusal to provide such data and to give the relative consent will make it impossible for the Data Controller to follow up on the activities of direct marketing and profiling indicated therein, but does not affect the possibility for the applicant to obtain the issue of the Loyalty Card and to access the benefits connected to it.


The data processing will be carried out by personnel directly employed by the Data Controller and/or by natural or legal persons specifically identified by the Data Controller as data processors or persons in charge of processing. The data provided will in no case be disclosed or communicated to third parties, with the exception of subjects whose right to access the data is recognized by provisions of the law or by orders of the authorities as well as subjects, including external and/or foreign, of which the Data Controller uses to carry out instrumental and/or ancillary activities for the management of the Loyalty Card and for the provision of the services and benefits connected to it, including the suppliers of software solutions, web applications and storage services also provided through Cloud Computing systems and used for this purpose. It should be noted that, pursuant to art. 4, paragraph 1, lett. d), of Legislative Decree no. 196/2003, personal data suitable for revealing racial and ethnic origin, religious, philosophical or other beliefs, political opinions, membership of parties, trade unions, associations or organizations of a religious, philosophical, political or union, as well as personal data suitable for revealing the state of health and sex life and those relating to health, are sensitive data. Such data, voluntarily provided by you, will not be processed without your express written consent and prior authorization from the Guarantor for the protection of personal data.


The subjects to whom the personal data refer may at any time exercise the rights granted to them vis-à-vis the Data Controller pursuant to the GDPR of 2016/679. In particular they will be able to:

  1. have confirmation of the existence or not of personal data concerning them, even if not yet registered, and have it communicated in an intelligible form;

  2. obtain the indication of the origin of the personal data, of the purposes and methods of the treatment; of the logic applied in case of treatment carried out with the aid of electronic instruments; of the identification details of the owner, of the managers and of the designated representative pursuant to the GDPR of 2016/679; of the subjects or categories of subjects to whom the personal data may be communicated or who can learn about them as designated representative in the territory of the State, managers or agents;

  3. obtain the updating, rectification or integration of data;

  4. obtain the cancellation, transformation into anonymous form or blocking of data processed unlawfully, including data whose retention is unnecessary for the purposes for which the data were collected or subsequently processed;

  5. have certification that the aforementioned operations have been brought to the attention of those to whom the data have been communicated or disseminated, except in the case in which this fulfillment proves impossible or involves the use of means manifestly disproportionate to the protected right;

  6. object, in whole or in part, for legitimate reasons, to the processing of personal data concerning them, even if pertinent to the purpose of the collection, and to the processing of personal data concerning them for the purpose of sending advertising material or direct sales or for carrying out market research or commercial communication.

To exercise these rights, the interested party may directly contact the Data Controller by telephone or by sending an email to

bottom of page