CMO S.P.A is committed to protecting our customer privacy and takes its responsibility regarding the security of customer information very seriously. We will be clear and transparent about the information we are collecting and what we will do with that information.

This Privacy Policy explains how information about you is collected, used and disclosed, and sets out the following:

Data Controller

CMO S.P.A, (referred to as “we”, “us”, “our” or “CMO S.P.A” in this policy) is the “data controller” of all personal information that is collected and used about CMO S.P.A customers for the purposes of EU-wide GPDR. CMO S.P.A is registered in Italy, with VAT number 02637320967 and registered offices at Via die mille, 1 - 20811 Cesano Maderno (MB) - Italy.

What personal data we collect

Personal data means any information relating to you which allows us to identify you, such as your name, contact details, reference number, payment details and information about your access to our website.

We may collect personal data from you when you purchase our products and services (either directly or indirectly through our trusted third-party partners), create an CMO S.P.A account, use our tutorials, use our website and / or App and other websites accessible through our website and / or App, receive our newsletters, participate in a survey or competition, or when you contact us.

Specifically, we may collect the following categories of information:

  1. Name, home address, e-mail address, telephone number, passport or other recognized personal ID card numbers and details, VAT numbers, credit/debit card or other payment details.
  2. Purchase history, including information related to your purchases of our products and services.
  3. Information you provide about your preferences in your CMO S.P.A account.
  4. Information about your purchases of our trusted partners’ products and services.
  5. Information about your participation in our webinars.
  6. Information about your use of our tutorials and website and/or App.
  7. The communications you exchange with us or direct to us via letters, emails, chat service, forum, calls, and social media.
  8. Location, including real-time geographic location of your computer or device through GPS, Bluetooth, and your IP Address, along with crowd-sourced Wi-Fi hotspot and cell tower locations, if you use location-based features and turn on the Location Services settings on your device and computer

We may also obtain information from other sources and combine that with information we collect through our Services. We may receive updated information about you, such as an updated billing address, from the financial institution or ecommerce platforms issuing your credit card or in connection with our billing for the Services.

What do we use your personal data for, why and for how long

Your data may be used for the following purposes:

  1. Providing products and services you request: we use the information you give us to perform the services you have asked for.
  2. Credit or other payment card verification/screening: we use your payment information for accounting, billing and audit purposes and to detect and/or prevent any fraudulent activities
  3. Administrative or legal purposes: we use your data for statistical and marketing analysis, systems testing, customer surveys, maintenance and development, or in order to deal with a dispute or claim. Note that we may perform data profiling based on the data we collect from you for statistical and marketing analysis purposes. Any profiling activity will be carried out with your prior consent only and by making best endeavors to ensure that all data it is based on is accurate. By providing any personal data you explicitly agree that we may use it to perform profiling activities in accordance with this Privacy Policy.
  4. Administrative, crime prevention/detection: we may pass your information to government authorities or enforcement bodies for compliance with legal requirements.
  5. Customer Services communications: we use your data to manage our relationship with you as our customer and to improve our services and enhance your experience with us.
  6. Provide tailored services: we use your data to provide information we believe is of interest to you, prior to, during, and after your purchase our products and services to personalize the services we offer to you, such as special offers.
  7. Marketing: from time to time we will contact you with information regarding product promotions, tutorials, and ancillary products via e-communications. You will have the choice to opt in or opt out of receiving such communications by indicating your choice at our web and/or App at the purchasing stage. You will also be given the opportunity on every e-communication that we send you to indicate that you no longer wish to receive our direct marketing material.

We will only process your personal data where we have a legal basis to do so. The legal basis will depend on the reasons we have collected and need to use your personal data for.

In most cases we will need to process your personal data so we can provide you the products and/or services you´ve requested.

We may also process your personal data for one or more of the following:

Only children aged 16 or over can provide their own consent. For children under this age, consent of the children’s’ parents or legal guardians is required.

We will not retain your data for longer than is necessary to fulfil the purpose it is being processed for. To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the purposes for which we process it and whether we can achieve those purposes through other means.

We must also consider periods for which we might need to retain personal data in order to meet our legal obligations (e.g. in relation to tax) or to deal with complaints, queries and to protect our legal rights in the event of a claim being made. For retention of information on your CMO S.P.A account, please see the below section about my CMO S.P.A

When we no longer need your personal data, we will securely delete or destroy it. We will also consider if and how we can minimize over time the personal data that we use, and if we can anonymize your personal data so that it can no longer be associated with you or identify you, in which case we may use that information without further notice to you.

Security of your personal data

We follow strict security procedures in the storage and disclosure of your personal data, and to protect it against accidental loss, destruction or damage. The data you provide to us is protected using SSL (Secure Socket Layer) technology. SSL is the industry standard method of encrypting personal information and credit card details so that they can be securely transferred over the Internet.

All payment details are transmitted over SSL across dedicated network infrastructure and stored in compliance with Payment Card Industry Data Security Standards (PCI DSS) Level 1 certified (Payment Card Industry Data Security Standard). PCI DSS is the most important security standard for the card payment industry and includes a set of comprehensive requirements for security management, policies, procedures, network architecture, software design and other critical protective measures.

We also have a variety of other security standards we comply with: ISAE 3402 and SSAE 16, Safe Harbor US-EU/EEA and Switzerland, 3-D Secure vendor/client protection, VeriSign certificate for secure SSL (Secure Socket Layer) orders, BBB Accreditation.

We may disclose your information to trusted third parties for the purposes set out in this Privacy Policy. We require all third parties to have appropriate technical and operational security measures in place to protect your personal data, in line with Spanish and EU law on data protection rules.

International Data Transfer

CMO S.P.A operates businesses in multiple jurisdictions, some of which are not located in the European Economic Area (EEA), such as Lithuania and USA. While countries outside the EEA do not always have strong data protection laws, we require all services providers to process your information in a secure manner and n accordance with Spanish and EU law on data protection. We utilize standard means under EU law to legitimize data transfers outside the EEA.

Sharing your personal data

Your personal data shall not be shared except:

Your personal data may be shared with other companies within the CMO S.P.A Group.

We may also share your personal data with the following third parties for the purposes described in this Privacy Policy:

  1. Government authorities, law enforcement bodies, and regulators for compliance with legal requirements.
  2. Trusted service providers we are using to run our business such as consultants, vendors, call centers providing assistance to our customers, cloud storage services, cloud service and e-mail marketing service providers assisting our marketing team with running customer surveys and providing targeted marketing campaigns.
  3. Ecommerce platforms, credit and debit card companies which facilitate your payments to us, and anti-fraud screening, which may need information about your method of payment and products and services acquisitions to process payment or ensure the security of your payment transaction.
  4. Legal and other professional advisers, law courts and law enforcement bodies in all countries we operate in in order to enforce our legal rights in relation to our contract with you.
  5. Social media: You may be able to access third party social media services through our website or App or before coming to our website or App. When you are registered with your social service account, we will obtain the personal information you choose to share with us through these social media services pursuant to their privacy settings in order to improve and personalize your use of our website or App. We may also use social media plugins on our website or App. As a result, your information will be shared with your social media provider and possibly presented on your social media profile to be shared with others in your network. Please refer to the privacy policy of these third-party social media providers to find out more about these practices.

Your data protection rights

Under certain circumstances, by law you have the right to:

  1. Request information about whether we hold personal information about you, and, if so, what that information is and why we are holding/using it.
  2. Request access access to your personal information (commonly known as a "data subject access request"). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
  3. Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
  4. Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
  5. Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
  6. Object to automated decision-making including profiling, that is not to be subject of any automated decision-making by us using your personal information or profiling of you.
  7. Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
  8. Request transfer of your personal information in an electronic and structured form to you or to another party (commonly known as a right to “data portability”). This enables you to take your data from us in an electronically useable format and to be able to transfer your data to another party in an electronically useable format.
  9. Withdraw consent. In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.

If you want to exercise any of these rights, then please contact our DPO in the following email:

You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.

Versione italiana Italian Version

Informativa Privacy

Informativa ai sensi dell'art. 13 del Regolamento dell'Unione Europea 2016/679 (GDPR)


Il Titolare del trattamento dei Dati è CMO S.P.A con sede legale in Via die mille, 1 - 20811 Cesano Maderno (MB) - Italia, email: che garantisce il rispetto della disciplina in materia di protezione dei dati personali fornendo le seguenti informazioni circa il trattamento dei dati comunicati o comunque raccolti.


I Dati forniti dall'utente tramite form sono raccolti, trattati e conservati per le seguenti finalità:
a) adempiere agli obblighi legali e fiscali cui è soggetto il Titolare;
b) nell'ambito dell'esecuzione dei contratti di cui il Cliente è parte o per l'adozione di misure precontrattuali adottate su richiesta dello stesso;
c) nell'eventualità che sia necessario accertare, esercitare o difendere un diritto in sede giudiziaria, per il perseguimento del legittimo interesse che il Titolare ha ravvisato sussistere sulla base del bilanciamento degli interessi effettuato;
d) per l'invio di comunicazioni commerciali su prodotti e servizi analoghi a quelli già acquistati;
e) in presenza di specifico consenso, per l'invio di comunicazioni commerciali su prodotti e servizi, corsi di formazione, webinar, promozioni speciali o di chiamate telefoniche con operatore.
f) per l'analisi statistica dell'utilizzo del sito web priva di informazioni personali.
g) nel caso di invio di curriculum vitae, esclusivamente per finalità di selezione.

Il trattamento dei Dati per la finalità sub a) e b) non richiede il consenso del Cliente in quanto è necessario per adempiere ad obblighi legali o per l'esecuzione dei contratti di cui il Cliente è parte o per l'adozione di misure precontrattuali adottate su richiesta dello stesso, ai sensi dell'art. 6, c. 1, lett. b) c) del GDPR. Il trattamento dei Dati per le finalità sub c) non richiede il consenso del Cliente in quanto è necessario per il perseguimento del legittimo interesse del Titolare, ai sensi dell'art. 6, c. 1, lett. f) del GDPR. Il trattamento dei Dati per la finalità sub d) non richiede il consenso del Cliente, ai sensi dell'art. 130, comma 4, del Codice.

Per il sub f) vengono raccolti alcuni dati generici la cui trasmissione è implicita nell'uso dei protocolli Internet. Questi dati (ad esempio nomi di dominio, indirizzi IP, sistema operativo utilizzato, tipo di dispositivo, di browser utilizzato) non sono accompagnati da alcuna informazione personale aggiuntiva e vengono utilizzati per ricavare informazioni statistiche anonime sull'uso del sito o per accertare responsabilità in caso di ipotetici reati informatici.
La base giuridica che legittima il trattamento di tali dati è la necessità di rendere utilizzabili le funzionalità del sito a seguito dell'accesso dell'utente.


Il conferimento dei Dati per le finalità sub a) e b) costituisce, rispettivamente, un obbligo legale e contrattuale. Il conferimento dei Dati per le finalità sub c), invece, è facoltativo ma necessario per il perseguimento dei legittimi interessi del Titolare indicati sopra. In tutti questi casi, il mancato conferimento dei Dati comporterà l'impossibilità per il Titolare di instaurare o proseguire nei rapporti commerciali con il Cliente.
Il conferimento dei Dati per la finalità sub e) è facoltativo e il loro mancato conferimento o il mancato consenso al loro trattamento comporterà l'impossibilità per i Titolari di svolgere le attività funzionali a raggiungere la finalità in questione.


I Dati potranno essere resi accessibili, portati a conoscenza di o comunicati ai seguenti soggetti, i quali potranno essere nominati dal Titolare, a seconda dei casi, quali responsabili o incaricati:
- società del gruppo di cui fa parte il Titolare (controllanti, controllate, collegate), dipendenti o collaboratori a qualsivoglia titolo del Titolare o di società del gruppo di cui fa parte il Titolare;
- soggetti pubblici o privati, persone fisiche o giuridiche, di cui il Titolare si avvalga per lo svolgimento delle attività strumentali al perseguimento della finalità di cui sopra o a cui il Titolare sia tenuto a comunicare i Dati, in forza di obblighi legali o contrattuali.


I Dati saranno conservati per un periodo di tempo massimo pari al periodo di prescrizione dei diritti azionabili dai o nei confronti del Titolare, come di volta in volta applicabile.


Agli interessati sono riconosciuti i diritti di cui agli artt. da 15 a 20 del GDPR. A titolo esemplificativo, ciascun interessato potrà dunque:
a) ottenere la conferma che sia o meno in corso un trattamento di dati personali che lo riguardano;
b) qualora un trattamento sia in corso, ottenere l'accesso ai dati personali e alle informazioni relative al trattamento nonché richiedere una copia dei dati personali;
c) ottenere la rettifica dei dati personali inesatti e l'integrazione dei dati personali incompleti;
d) ottenere, qualora sussista una delle condizioni previste dall'art. 17 del GDPR, la cancellazione dei dati personali che lo riguardano;
e) ottenere, nei casi previsti dall'art. 18 del GDPR, la limitazione del trattamento;
f) ricevere i dati personali che lo riguardano in un formato strutturato, di uso comune e leggibile da dispositivo automatico e richiedere la loro trasmissione ad un altro titolare, se tecnicamente fattibile.


Ciascun interessato ha il diritto di opporsi in qualsiasi momento al trattamento dei suoi dati personali effettuato per il perseguimento di un legittimo interesse dei Titolari. In caso di opposizione, i suoi dati personali non saranno più oggetto di trattamento, sempre che non sussistano motivi legittimi per procedere al trattamento che prevalgono sugli interessi, sui diritti e sulle libertà dell'interessato oppure per l'accertamento, l'esercizio o la difesa di un diritto in sede giudiziaria. Nel caso in cui sia richiesto il consenso per il trattamento dei dati personali, ciascun interessato potrà, altresì, revocare in qualsiasi momento il consenso già prestato, senza pregiudicare la liceità del trattamento basata sul consenso prestato prima della revoca. Il consenso può essere revocato, scrivendo una email all'indirizzo

Copyright © CMO Group - Cookies Policy - Privacy Policy - powered by 3dee