VTO Privacy Policy

Welcome to Virtual Mirror

Luxottica uses an augmented reality application on your device to show you the right fit and look of the frames you select. Any information gathered will be stored on your device and will not be shared nor stored by Luxottica.

FOR USERS IN THE EUROPEAN UNION (“EU”)

Under the General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, or “GDPR”), individuals in the EU are afforded specific rights with respect to their “Personal Data” as defined under the GDPR. For the purposes of this Policy, Luxottica Group S.p.A (“Luxottica,” “we,” “our,” or “us”), with a registered office in Piazzale Luigi Cadorna, 3, 20123 Milan, Italy, operates as a data controller.

We have appointed a Data Protection Officer that can be contacted at the email address: dpo@luxottica.com.

This Policy describes how the websites that link to this Policy (collectively “Sites”), as well as the Face Scanning App (“FSA”), or our in-store Face-Scanning Kiosk (“Kiosk”) and certain other technological services aimed at providing you with a customized experience (e.g. Frame Advisor, Size Advisor) as described below (collectively, the “Platforms”) collect, use, and generally process data about you.

It is understood that the Virtual Mirror ("VM") experience is excluded from the abovementioned Platforms. The experience does not involve any processing of personal and/or special data (including biometric data), as it takes place exclusively on the user's device in real-time mode. Therefore, to participate in the VM experience, consent to processing is not required and any information uploaded to the user's personal device will not be shared with Luxottica.

  • WHAT KIND OF PERSONAL DATA DO WE USE AND WHERE IS IT COLLECTED FROM?
  • We process your Personal Data, which is collected directly from you, whether you access the Platform through one of our websites, the mobile application, or an in-store kiosk. The Personal Data you provide is outlined in the categories of personal data listed below:

    • Personal Data provided during the Platform experience (first and last name, email address, phone number, face shape, face dimensions, and other information directly provided by you);
    • Your image that is provided when you take part on the virtual technology features of our Platforms;
    • Data derived from your image or from your Biometric Data (face shape, eye color, hair, skin tone);
    • Hereinafter, point a), b), c) will be referred to as “Personal Data”

    • “Biometric data” means anything that relates to the measurement of your physical features and characteristics (in particular, your face measurement, starting from your interpupillary distance);

    Hereinafter, Personal Data and Biometric Data will be jointly referred to as “Data”.

  • FOR WHAT PURPOSES AND WHY DO WE USE YOUR PERSONAL DATA?
  • We process your Personal Data for the following purposes, based on the following legal basis:

    • The Platforms allow you to use an online service capable of simulating lenses and eyeglasses onto photos. Your image will be uploaded and then, based on the characteristics of your facial shape, the Platforms will provide you recommendations with your image results (the “virtual technology feature”). Such data processing activities are performed to provide you with the products and services required (including any registration of such Personal Data within your online account if you require us to do so). The legal basis for the data processing aforementioned is the execution of a contract pursuant to art. 6 par. 1 lett b). If you do not want your Personal Data to be processed for such purposes, it will not be possible for us to provide the required products and services.
    • To provide you with the services required, we could process your Biometric Data, derived from the scanning of your face through one of our Platforms. Such Platforms will detect your interpupillary distance and consequently derive from it the other facial measurements. Any collection of biometric identifiers and biometric information is for the sole purpose of providing you with the frame suggestions (Suggestions) based on your facial features, assisting you in viewing how certain eyeglasses may look on your face. We will not disclose or disseminate any biometric information to any entity, other than those contracted parties that assist us in providing this service to you. Biometric data can be processed by us only with your prior explicit consent pursuant to Article 9 par. 2 lett. a) of the GDPR. However, if you do not grant your explicit consent to the processing of your biometric data for this purpose, you will not be able to use the virtual technology feature and you will only be able to access the recommendations based on the answers you provided us with.
    • Except for Biometric Data. We process, with your prior consent, your Personal Data, for the following marketing purposes: (i) to send you the image and the product recommendations via email; (ii) to send commercial and promotional communications and periodical updates through the communication channels you provided us with related to our products, services, Platforms, initiatives, and events.
    • We will process your Personal Data to: (i) exercise or defend legal claims in court proceedings or in an administrative or out-of-court procedures relating to the rights of Luxottica, of its group companies and/or of their representatives, shareholders, officers and directors; (ii) enable the technical management of the Website and its operational functions, including solving any technical problems, to perform tests, updates and upgrades that cannot be performed through non-personal data; (iii) prevent or identify fraudulent activities or misuses of the Website or against the Luxottica group and/or the users of the Website; (iv) complete a potential merger, sale of assets, transfer of all or a material part of its business, or financing transaction by disclosing and transferring the Personal Data to the third party or parties involved in the transaction as part of the transaction; (v) conduct, surveys and market researches relating to Luxottica’s products and services by post, telephone or e-mail; (vi) anonymize Personal Data in order to perform statistical analysis.
  • WHAT MODALITIES DO WE USE TO PROCESS YOUR DATA?
  • The processing of your Data is carried out electronically and manually, and only within the limits necessary to pursue the purposes outlined above. All Data provided by users is kept on secure servers, adopting adequate security measures to protect Data from non-authorized access, to maintain the accuracy of Data and guarantee their proper use.

  • TO WHOM IS YOUR DATA COMMUNICATED AND WHERE ARE YOUR DATA TRANSFERRED?
  • Your Data will be accessed by our service providers (hosting and infrastructure service providers, etc). Each service provider will act as a data processor, by virtue of a specific agreement in place per Article 28 of the GDPR. We will process your Personal Data in countries outside the European Union, when necessary to provide you with the services mentioned above and will ensure that the data transfer complies with Article 48 of the GDPR.

  • HOW LONG IS YOUR PERSONAL DATA RETAINED BY US?
  • We retain your Data for the time strictly necessary to achieve the purposes for which they was collected and further processed, including any retention period required under applicable laws, including GDPR.

    With specific regard to the Biometric Data, they will be deleted within 24 hours from the time of the collection. However, in case you ask us to save your experience, suggestions and/or the image in your account, we will retain your Biometric Data for six months from the last access or until you delete your take or the online account.

    Please understand that when you request your image via email through the virtual technology feature, and you did not previously asked us to save that image into your profile, we will only temporarily store your image to provide your chosen service.

    For marketing and profiling purposes, Personal Data will be processed for seven years from the last purchase and/or from the last contract with you (e.g. subscription to a prize competition, participation to an event, opening of a newsletter), notwithstanding the right to withdraw the consent provided or object to the processing at any time.

  • HOW CAN YOU EXERCISE YOUR PRIVACY RIGHTS?
  • You can exercise any of the following rights, subject to verification of your identity, by submitting a request on https://privacy.luxottica.com

    • Access: You may request a copy of the Personal Data our Platform databases currently contain.
    • Automated Processing & Decision-Making: You may request that we stop using your Personal Data for automated processing, such as profiling. When such restrictions are not possible, we will advise you accordingly. You can then choose to exercise any other rights under this Policy, including withdrawing your consent to the processing of your Personal Data.
    • Correction or Rectification: You may request to correct what Personal Data our Platform databases currently contain. We may not accommodate a request to change Personal Data if we believe the change would violate any law or legal requirement or cause the information to be incorrect. Where applicable, we will ensure such changes are shared with trusted third parties.
    • Restrict Processing: When applicable, you may restrict the processing of your Personal Data. When such restrictions are not possible, we will advise you accordingly. You can then choose to exercise any other rights under this Policy, including withdrawing your consent to the processing of your Personal Data. Where applicable, we will ensure such changes are shared with trusted third parties.
    • Object to Processing: When applicable, you have the right to object to the processing of your Personal Data. When such objections are not possible, we will advise you accordingly. You can then choose to exercise any other rights under this Policy, to include withdrawing your consent to the processing of your Personal Data. Where applicable, we will ensure such changes are shared with trusted third parties.
    • Portability: Upon request and when possible, we can provide you with copies of your Personal Data. When such a request cannot be honoured, we will advise you accordingly. You can then choose to exercise any other rights under this Policy, including withdrawing your consent. Where applicable, we will ensure such changes are shared with any trusted third parties.
    • Withdraw Consent: At any time, you may withdraw your consent to our processing of your Personal Data through the Platforms. Upon receipt of such a withdrawal of consent, we will confirm receipt and proceed to stop processing your Personal Data. Where applicable, we will ensure such changes are shared with trusted third parties.
    • Erasure: If you should wish to cease use of our Platforms and have your Personal Data deleted from our Platforms, then you may submit a request. Upon receipt of such a request for erasure, we will confirm receipt and will confirm once your Personal Data has been deleted. Where applicable, we will ensure such changes are shared with trusted third parties.
  • HOW CAN YOU CONTACT LUXOTTICA?
  • The Data Controller of your Personal Data is Luxottica Group S.p.A., with a registered office in Piazzale Luigi Cadorna, 3, 20123 Milan, Italy.

    Should you have questions or comments on this Policy, or any data processing carried out by Luxottica, you may contact Luxottica at dpo@luxottica.com.

Visitor ID: