PRIVACY POLICY

Introduction
Standard Scuderia Ferrari Club S.c.ar.l Privacy and data protection policy

By completing Member Registration you are joining your local “Scuderia Ferrari Club”, an official member and sub licensee of the Scuderia Ferrari Club S.c.ar.l., and will benefit from the privileges and services that come with membership. You are invited to read the following privacy policy, which outlines the purposes and means used for protection of your personal information in compliance with Regulation (EU) 2016/679.

Purpose and procedure for the processing of personal data

The personal data you have provided (“Data”) will be processed for the following purposes:
(a) to manage your registration in Scuderia Ferrari Club S.c.ar.l. (the “Club”);

(b) to allow you to take part to events and activities organized by the Club as well as to provide you with the services that are specially reserved for you following registration (“Service”);

(c) to allow the Club to perform satisfaction surveys (“Customer Satisfaction”) related to the quality of Club services according to the Club’s legitimate interest;

(d) subject to your explicit consent, sending commercial communications as well as sending advertising on the Club services, or performing market research (“Marketing”);

(e) subject to your express consent, analyzing your behavior, habits and propensity to consume, so as to enhance products and services provided by the Club as well as satisfy your expectations (“Profiling”);

(f) subject to your express consent, communicating Data to the companies controlled directly or indirectly by Ferrari N.V. and/or connected to Ferrari S.p.A. (“Ferrari Group Companies”) who will process such Data to send commercial communications as well as advertising of their products and services, or to perform market research (“Marketing Ferrari Group Companies”).

The Data may be processed in hardcopy, or by automated or electronic means including via mail or e-mail, telephone (e.g. automated phone calls, SMS, MMS), fax and any other means (e.g. web sites, mobile apps).

Consequences of failure to provide the data
Submitting Data is not mandatory; however, by not providing the Data marked as mandatory this would prevent the Company from providing the Service. On the other hand, by not providing the optional Data this will still allow you to access the Service. Recipients of the Data may process the Data using natural persons and/or legal entities, acting on behalf of the Club and under specific contractual obligations, based in EU Member States or in countries outside the EU. The Data may be communicated to third parties to comply with legal obligations, to execute Public Authority orders, or to exercise a right of Club before judicial authorities.

Data transfer outside of the EEA

Within its contractual relationship the Club may transfer the Data to countries outside of the European Economic Area (EEA), including to store in databases managed by entities acting on behalf of the Club. Database management and Data processing may only be carried out for purposes of processing and in accordance with applicable law. In the event that Data in transferred outside of the EEA then the Club will use appropriate measures in accordance with the standard rules adopted by the EU Commission to regulate the transfer of personal data outside of the EEA.

Controller and data protection officer

The Controller is Scuderia Ferrari Club S.c.ar.l., with registered office in via Abetone Inferiore 4, Maranello (MO), Italy. You can contact the Data Protection Officer at the email address privacy@scuderiaferrari.club

Data retention

The Data processed in order to provide the Service and Customer Satisfaction will be held by the Club for a period to be determined as necessary in order to complete the approved uses and Services. With regard to Data processed for the provision of the Service, the Club may continue to store such Data for as long as may be necessary to protect Club’s interests regarding potential liability relating to provision of Services. The Data processed for Marketing purposes will be kept by the Club from the time of consent until such consent is withdrawn. After consent is withdrawn, Data will no longer be used for such previously consented purposes, however such Data may still be retained by Club to manage any future claims and/or lawsuits. Data retention for Marketing purposes will be compliant with local laws and current regulations of the Data Protection Authority.

Your rights

You can exercise the following rights:

1. right to access means the right to obtain information from the Club as to if and how your Data are being processed and if applicable, reasonable access to such Data;

2. right to rectification and right to erasure means the right to rectification of any inaccurate and/or incomplete Data, as well as the erasure of Data for any legitimate reasons;

3. right to restriction of processing means the right to request suspension of any future processing for any legitimate reason;

4. right to data portability means the right to obtain Data in a format that is commonly used and readable, as well as the right to transfer of such Data to other controllers;

5. right to object means the right to object to the processing of Data when the request is legitimate, including if the Data are processed for marketing or profiling, as applicable;

6. right to lodge a complaint with a supervisory authority in case of unlawful processing of Data.

You can exercise the abovementioned rights by writing to Ferrari S.p.A., Via Abetone Inferiore N.4. Maranello (MO). Italy or to the email address privacy@scuderiaferrari.club.

SFC Silverstone specific policy, procedure, and protocol

SFC Silverstone is not a data controller we use the systems as provided under our licence agreement with Scuderia Ferrari Club S.c.a.r.l [ SFC ]
SFC Silverstone are a data processor only.
This involves a SFC managed email client and a SFC managed web portal to add members.

SFC Silverstone Specifc information

1. What data do we receive?

1.1 Full Name, Date of Birth, Postal Address, Email Address, Phone number

2. How do we receive data?
& How do we process the data we receive?

2.1 We receive physical paper forms completed with the minimum data we need to register the applicant as a member within the Ferrari Portal as specified in 1.1
2.1.1 Once received or as soon as is practically possible the applicants data is entered into the SFC portal.

  1. 2.1.2  Once this data has been entered the physical paper form is cross cut shredded
  2. 2.1.3  We do not keep or store paper copies of the form

2.2 We receive emails with the same membership data.

  1. 2.2.1  These are received via the SFC email account
  2. 2.2.2  Once received as soon as is practically possible the applicants data is entered into

the SFC portal.
2.2.3 Once this data has been entered the email is deleted.

3. How long do we keep the data?

3.1 We only log the members data whilst they are a member of the club, is their membership lapses, expires, or the member withdraws their membership their record is deleted from the SFC portal.

4. What do we do with peoples data?

4.1 We only use the data for the purposes of administering their membership to the club.
4.1.1 This is to allow us to send the membership pack, to inform members of club events and activities.

4.1.2 Each member receives a club handbook which details what data we have and how we manage this data.

  1. 4.1.3  Any member at any time can ask us to remove data and we will action accordingly.
  2. 4.1.4  We do not sell on or pass data to any third parties for any purpose.

4.2 We have a email database where we send emails only related to club activity, events, offers, and the Ferrari team activities in Formula one and GT racing series. 4.2.1 Any member at any time can ask us to remove their email address and unsubscribe from the mailing list and we will action accordingly.

5. Email Communication

  1. 5.1  See points 4.2 & 4.2.1 as above
  2. 5.2  We will never email a recipient who has not contacted us directly in the first

instance.
5.2.1 We do not as default add email addresses received to any mailing list
The only email mailing list is as mentioned in point 4.2 which is only for subscribed members where this is needed for the member to be informed of club business as outlined.

6. Website

6.1 The website does not track, gather cookies or any information regarding the person viewing the site.

6.2 The website has a very basic contact form which is linked to the official SFC email account so that general enquiries can be sent direct from the website.
6.2.1 These website contact form emails are treated as per section 5. on Email communication.

6.3 SFC Silverstone hold no responsibility for the third party websites linked from our site

7. Responsibility

7.1 The club has a board of management and a President.
It is the collective responsibility of the board that this policy is implemented and adhered to at all times where required it is reviewed, updated and these updates documented.

8. Review

8.1 Reviews to this policy will be made once per year or when information is bought to light that necessities review or change.