PRIVACY POLICY

I - INFORMATION RELATING TO THE SITE'S PRIVACY POLICY

1. This section contains information relating to the management methods of www.laurabrioschi.com with reference to the processing of data of users of www.laurabrioschi.com and www.laurabrioschi.it.

2. This information is also valid for the purposes of article 13 of Regulation (EU) no. 2016/679, concerning the protection of individuals with regard to the processing of personal data as well as the free circulation of such data, for subjects who interact with www.laurabrioschi.com and can be reached at the address corresponding to the initial page:

www.laurabrioschi.com or www.laurabrioschi.it

3. The information is provided only for www.laurabrioschi.com and not for other websites that may be consulted by the user via links contained therein.

4. The purpose of this document is to provide information on the methods, timing and nature of the information that the data controllers must provide to users when connecting to the web pages of www.laurabrioschi.com, regardless of the purpose of the connection itself, according to Italian and European legislation.

5. The information may undergo changes due to the introduction of new regulations in this regard, the user is therefore invited to periodically check this page.

6. If the user is under the age of 14, pursuant to article 8, c.1 of regulation (EU) 2016/679, and of the Art. 2 - Quinquies of Legislative Decree 196/2003, as amended by Legislative Decree 181/18, will have to legitimize its consent through the authorization of the parents or guardians.

II - DATA PROCESSING

1 - Owner of the Data

1. The data controller is the natural or legal person, public authority, service or other body which, individually or together with others, determines the purposes

1/9

and the means of processing personal data. He also takes care of the security profiles.

2. With regard to this website, the data controller is: Laura Brioschi, and for any clarification or exercise of the user's rights, she can contact her at the following email address: lp.consulting.italia@gmail.com.

2 - Responsible for data processing

1. The data controller is the natural or legal person, public authority, service or other body which processes personal data on behalf of the data controller.

2. Pursuant to article 28 of regulation (EU) no. 2016/679, upon appointment of the data owner, the data controller of the site www.laurabrioschi.com is: Laura Brioschi.

3 - Place of data processing

1. The data processing generated by the use of www.laurabrioschi.com or www.laurabrioschi.it takes place in Italy.

2. If necessary, the data connected to the newsletter service can be processed by the data controller or subjects appointed by him for this purpose at the relevant office.

III - COOKIES

1 - Type of Cookies

1. The www.laurabrioschi.com site uses cookies to make the user's browsing experience easier and more intuitive: cookies are small strings of text used to memorize some information that may concern the user, his preferences or the Internet access device (computer, tablet or mobile phone) and are mainly used to adapt the functioning of the site to the user's expectations, offering a more personalized browsing experience and memorizing the choices made previously.

2. A cookie consists of a small set of data transferred to the user's browser from a web server and can only be read by the server that made the transfer. It is not executable code and does not transmit viruses.

2/9

3. Cookies do not record any personal information and any identifiable data will not be stored. If you wish, you can prevent the saving of some or all cookies. However, in this case the use of the site and the services offered could be compromised. To proceed without changing the options relating to cookies, simply continue browsing.

Below are the types of cookies that the site uses:

2 - Technical cookies

1. There are numerous technologies used to store information on the user's computer, which are then collected by the sites. Among these, the best known and most used is that of HTML cookies. They are used for navigation and to facilitate access and use of the site by the user. They are necessary for the transmission of communications on the electronic network or for the supplier to provide the service requested by the customer.

2. The settings to manage or disable cookies may vary depending on the internet browser used. In any case, the user can manage or request the general deactivation or cancellation of cookies by changing the settings of his internet browser. This deactivation can slow down or prevent access to some parts of the site.

3. The use of technical cookies allows safe and efficient use of the site.

4. The cookies that are inserted in the browser and retransmitted through Google Analytics or through the statistics service of bloggers or similar are technical only if used for site optimization purposes directly by the site owner, who will be able to collect information in aggregate form on the number of users and how they visit the site. Under these conditions, the same rules apply for analytics cookies, in terms of information and consent, as for technical cookies.

5. From the point of view of duration, temporary session cookies can be distinguished which are automatically deleted at the end of the browsing session and are used to identify the user and therefore avoid logging into each page visited and the permanent ones which remain active in the PC until upon expiration or cancellation by the user.

6. Session cookies may be installed in order to allow access and permanence in the reserved area of ​​the portal as an authenticated user.

7. They are not memorized permanently but exclusively for the duration of navigation until the browser is closed and disappear when the same is closed. Their use is strictly limited to the transmission of identifiers of

3/9

session consisting of random numbers generated by the server necessary to allow safe and efficient exploration of the site.

3 - Third party cookies

1. In relation to the origin, the cookies sent to the browser directly from the site you are visiting can be distinguished from those of third parties sent to your computer from other sites and not from the one you are visiting.

2. Permanent cookies are often third-party cookies.

3. Most third-party cookies consist of tracking cookies used to identify online behavior, understand interests and therefore customize advertising offers for users.

4. Analytical third-party cookies may be installed. They are sent from domains of the aforementioned third parties external to the site.

5. Third-party analytical cookies are used to detect information on user behavior on www.laurabrioschi.com. The survey takes place anonymously, in order to monitor performance and improve the usability of the site. Third-party profiling cookies are used to create user profiles, in order to propose advertising messages in line with the choices expressed by the users themselves.

6. The use of these cookies is governed by the rules set up by the third parties themselves, therefore, users are invited to read the privacy information and the indications for managing or disabling the cookies published on the relative web pages.

4 - Profiling cookies

1. Profiling cookies create user profiles and are used to send advertising messages in line with the preferences expressed by the user while surfing the net.

2. When these types of cookies are used, the user must give explicit consent.

3. Article 22 of Regulation (EU) 2016/679 and article 122 of the Data Protection Code will apply.

4/9

IV - DATA PROCESSED

1 - Data processing mode

1. Like all websites, this site also makes use of log files in which information collected in an automated manner is kept during user visits. The information collected could be the following:

- internet protocol (IP) address;
- type of browser and parameters of the device used to connect to the site; - name of the internet service provider (ISP);
- date and time of visit;
- web page of origin of the visitor (referral) and exit;
- possibly the number of clicks.

2. The aforementioned information is processed in an automated form and collected in an exclusively aggregated form in order to verify the correct functioning of the site, and for security reasons. This information will be treated on the basis of the legitimate interests of the owner.

3. For security purposes (spam filters, firewalls, virus detection), the automatically recorded data may possibly also include personal data such as the IP address, which could be used, in compliance with applicable laws, in order to block attempts to damage to the site itself or to cause damage to other users, or in any case harmful activities or activities constituting a crime. These data are never used for the identification or profiling of the user, but only for the purpose of protecting the site and its users, such information will be treated on the basis of the legitimate interests of the owner.

4. If the site allows the insertion of comments, or in the case of specific services requested by the user, including the possibility of sending the Curriculum Vitae for a possible working relationship, the site automatically detects and records some identification data of the user , including the email address. These data are intended to be voluntarily provided by the user at the time of requesting service provision. By inserting a comment or other information, the user expressly accepts the privacy information, and in particular agrees that the contents inserted are freely disclosed to third parties as well. The data received will be used exclusively for the provision of the requested service and only for the time necessary for the provision of the service.

5. The information that users of the site deem to make public through the services and tools made available to them, are provided by the user knowingly and voluntarily, exempting this site from any liability regarding any violations of the law. It is up to the user to verify

5/9

to have permission to enter personal data of third parties or content protected by national and international standards.

2 - Purpose of data processing

1. The data collected by the site during its operation are used for the purposes indicated above and for the following purposes:

Marcheting, newsletters, shipping, order information.

2. Data retention will be carried out for the period strictly necessary to achieve the aforementioned purpose and in any case not exceeding 3 years.

3. The data used for security purposes (blocking attempts to damage the site) are kept for the time strictly necessary to achieve the previously indicated purpose.

3 - Data provided by the user

1. As indicated above, the optional, explicit and voluntary sending of e-mails to the addresses indicated on this site involves the subsequent acquisition of the sender's address, necessary to respond to requests, as well as any other personal data included in the message.

2. Specific summary information will be progressively reported or displayed on the pages of the site set up for particular services on request.

4 - Support in configuring your browser

1. The user can also manage cookies through the settings of his browser. However, deleting cookies from your browser could remove the preferences you have set for the site.

2. For more information and support, you can also visit the specific help page of the web browser you are using:

- Internet Explorer: http://windows.microsoft.com/en-us/windows-vista/block-or-allow-cookies

- Firefox: https://support.mozilla.org/en-us/kb/enable-and-disable-cookies-website-preferences

6/9

-Safari: http://www.apple.com/legal/privacy/it/

- Chrome: https://support.google.com/accounts/answer/61416?hl=it - Opera: http://www.opera.com/help/tutorials/security/cookies/

5 - Social Network Plugins

1. This site also incorporates plugins and/or buttons for social networks, in order to allow easy sharing of content on your favorite social networks. These plugins are programmed so as not to set any cookies when accessing the page, to safeguard user privacy. Eventually cookies are set, if so provided by social networks, only when the user makes effective and voluntary use of the plugin. Keep in mind that if the user browses being logged into the social network then he has already consented to the use of cookies conveyed through this site when registering with the social network.

2. The collection and use of information obtained through the plugin are governed by the respective privacy policies of the social networks, to which please refer:

Facebook: https://www.facebook.com/help/cookies

Twitter: https://support.twitter.com/articles/20170519-uso-dei-cookie-e-di-altre-tecnologie -simili-da-parte-di-twitter

Google+: http://www.google.com/policies/technologies/cookies Pinterest: https://about.pinterest.com/it/privacy-policy AddThis: http://www.addthis.com/privacy/privacy- LinkedIn policy: https://www.linkedin.com/legal/cookie-policy

V. YOUR RIGHTS

1. The art. 13, ch. 2 of Regulation (EU) 2016/679 lists the user's rights.

2. The site www.laurabrioschi.com therefore intends to inform the user of the existence of the user's rights, based on the following articles of Regulation (EU) 2016/679:

7/9

a) On the basis of art. 15, of the right of the interested party to ask the owner for access to personal data, based on art. 16 the possibility of rectifying the data provided, based on art.18 the possibility of integrating or limiting the processing that concerns him, or to oppose, for legitimate reasons, their treatment based on art. 21, in addition to the right to data portability based on art. 20 Regulation (EU);

b) the right to request cancellation on the basis of article 17, transformation into anonymous form or blocking of data processed in violation of the law, including data whose retention is not necessary in relation to the purposes for which the data have been collected or subsequently processed.

c) the right to obtain certification that the operations of updating, rectification, integration of data, cancellation, blocking of data, transformation have been brought to the attention, also as regards their content, of those to whom the data have been communicated or disseminated, except in the case in which this fulfillment proves impossible or involves the use of means manifestly disproportionate to the protected right.

3. Requests can be addressed to the data controller, without formalities or, alternatively, using the model provided by the Guarantor for the Protection of Personal Data, or by sending an email to the address: lp.consulting.italia@gmail.com

4. If the treatment is based on the art. 6, paragraph 1, lett. a) – express consent to use – or on art. 9, paragraph 2 lett. a) – express consent to the use of genetic, biometric, health-related data revealing religious or philosophical beliefs or union membership, revealing racial or ethnic origin, political opinions – the user has the right to revoke the consent at any time without prejudice to the lawfulness of the treatment based on the consent given before the revocation.

5. Likewise, in the event of a violation of the law, the user has the right to lodge a complaint with the Guarantor for the Protection of Personal Data, as the authority responsible for monitoring data processing in the Italian State.

6. For a more in-depth examination of your rights, see articles 15-22 of Regulation (EU) 2016/679.

VI - DATA TRANSFER TO NON-EU COUNTRIES

1. This site may share some of the data collected with services located outside the European Union area. In particular with Google, Facebook and Microsoft (LinkedIn) through social plugins and the Google Analytics service. The

8/9

transfer is authorized and strictly regulated by article 45, paragraph 1 of Regulation (EU) 2016/679, for which no further consent is required. The companies mentioned above guarantee their adherence to the Privacy Shield.

2. Data will never be transferred to third countries that do not comply with the conditions set out in article 45 and following of the (EU) Regulation.

VII. SECURITY OF DATA PROVIDED

1. This site processes user data in a lawful and correct manner, adopting the appropriate security measures aimed at preventing unauthorized access, disclosure, modification or unauthorized destruction of data. The processing is carried out using IT and/or telematic tools, with organizational methods and with logic strictly related to the purposes indicated.

2. In addition to the owner, in some cases, categories of persons involved in the organization of the site (administrative, commercial, marketing, legal, system administrators) or external subjects (such as third party technical service providers, couriers) may have access to the data. postal services, hosting providers, IT companies, communication agencies).

VIII. CHANGES TO THIS DOCUMENT

1. This document, which constitutes the privacy policy of this site, is published at the address:

https://www.laurabrioschi.com/pages/request-personal-data

2. It may be subject to changes or updates. In the case of significant changes and updates, these will be reported with specific notifications to users.

3. Previous versions of the document will still be available on this page.

4. The document was updated on 01/03/2021 to comply with the relevant regulatory provisions, and in particular in compliance with Regulation (EU) 2016/679.

“In order to be able to offer you Klarna's payment methods, at checkout we may pass your personal data to Klarna in the form of contact details and order details, so that Klarna can assess your suitability for your payment methods and customize these payment methods. Your personal data transferred is treated in line with Klarna's privacy policy .

For USA user: https://laurabrioschi.it/pages/ccpa-opt-out