Privacy policy

Personal data processing

This Privacy Policy contains information regulating the processing of personal data of users (hereinafter referred to as the "User") who access and use the following websites, owned by Milor S.p.A., or by companies controlled by it, in particular:

www.bronzallure.it
www.bronzallure.com
www.bronzallure.eu
www.etruscagioielli.com
www.albertm.it
www.duomilor.it
www.milor.com
www.galleria-milano.com
www.elledilinda.com

each individually identified as "the Site") for its consultation and for the purchase of products on sale. ("Products").

Milor S.p.A. ("The Data Controller") is registered with the Company Register of the Milan Chamber of Commerce, Tax Code / VAT no. 04362490155; its registered office is in Via dei Gracchi, 35 20146 Milan, email: privacy@milor.com.

This Privacy Policy is to be considered an integral and substantial part of the Terms of Use of each site and the cookie policy.

The information contained in the Privacy Policy is extended in accordance with article 13 of Legislative Decree 30 June 2003 no. 196 and subsequent amendments - (the "Privacy Code") and article 13 of EU Regulation 2016/679 ("GDPR") to all Users who access and use the Site and/or purchase Products on the Site. This Policy refers solely to the use of the Site and to no other third-party site, even if referred to in any way within the Site.

Any changes will take effect immediately and will apply only to Users who use the Site after the date of such change. Consequently, we invite you to refer to it whenever you visit our Site to review its latest version available on the Site.

Version of 10 May 2018

Purpose of data processing

The data entered by the User upon registration to the Website or the Website newsletter and when placing each order will be used for purposes strictly inherent to the purpose indicated at the time of data collection and/or for the purposes indicated in this Privacy Policy. More precisely, for sending the newsletter and/or for fulfilling the order request and all related services, such as payment and delivery.

The User's personal data may also be used by the Data Controller and third parties authorized by them to comply with any accounting and tax obligations related to the purchase of Products and to complete all activities strictly linked and preparatory to managing the Website-Customer relationship.

Specifically: carrying out operations related to our commercial relationship, i.e., concerning your subscription to the Services (in particular, verifying the authenticity of your email), Orders, deliveries, invoices, accounting, follow-up of the "customer relationship" with a Member, and conducting satisfaction surveys, managing complaints and after-sales service, refunds, specific commercial gestures, returning Orders, exercising your right of withdrawal, managing unpaid debts and disputes.

If the User has given consent, such personal data may be used for other purposes related to the sale of products on the Website:
1. sending promotions, offers, and suggestions on Products for sale;
2. checking User satisfaction;
3. sending promotional and/or advertising information relating to other activities of the Website and its Partners;
4. conducting market research and post-sales analysis.
5. proposing commercial offers close to your geographical location, particularly within the scope of offers that may include the "Store pickup" service;
6. managing your comments on the Website and/or on internet pages published by us and hosted on our Social Network websites.

Treatment mode

All user data collected will be processed exclusively and with due diligence by individuals specifically appointed to this task and properly trained on the subject. The purposes of processing are those for which the data were collected, primarily with electronic and IT tools.

The data will be stored on computer and paper media, as well as on any other medium deemed suitable and compliant with the security measures imposed by applicable regulations. The data are stored in such a way as to make it possible to identify the User for the minimum time necessary to achieve the objectives for which they were collected and then processed, and, in any case, always in compliance with legal requirements.

Any damages caused by causes not directly attributable to the Data Controller, such as inaccessibility of the Site, or viruses, corrupted files, interruption of internet or telephone network connections, or other causes similar to the cases listed above, are not attributable to the Data Controller.

Furthermore, the User is required to diligently and responsibly keep all personal information strictly linked to the Site, such as login credentials, any order and shipping codes, or other data. Any theft or improper use of this data, and the consequences arising from these events are the sole responsibility of the User.

Nature of data acquisition

The personal data requested by the Controller during website navigation may be mandatory or optional. The User's failure to consent to provide mandatory data will result in the non-fulfillment of the purpose for which they were requested. The completion of optional data, on the other hand, is entirely at the discretion of the User, who can choose whether or not to provide them. In this case, refusal does not entail any consequences for the execution of the purposes indicated at the time of the request.

The User is also responsible for constantly updating this data, so as to allow the Controller to effectively and efficiently provide all services without incurring delays, errors, or additional costs resulting from the failure to update such data.

In particular, the Controller collects the Data that you voluntarily declare via a collection form on the Website, including socio-professional information (for example, your profile, your surname, traditional first name, names, gender, date of birth, godfather and/or delivery address, profession).

When placing an Order, our banking providers also collect and process Personal Data relating to your payment methods (credit card number, credit card expiry date, visual cryptogram - data that will not be stored, etc.). For our part, we may process the partial number of your credit card consisting of the first six (6) digits and the last four (4) digits and the expiry date of your credit card as transmitted to us by your bank. Therefore, this payment identifier does not allow for bank transactions to be carried out.

We also collect information relating to the transaction carried out (transaction number, purchase details, etc.), or relating to the payment of invoices issued from or through the Website (payment method, discounts granted, receipts, balances and non-payments, or relating to subscribed credits, amount and duration, etc.).

The Controller processes Data related to the monitoring of the commercial relationship with you: product and/or service purchased, quantity, amount, frequency, delivery and/or billing address(es), telephone number, security code, and any other relevant delivery information (tracking number, shipment location, etc.) purchase and service history, product returns, correspondence and/or telephone exchanges between you and our after-sales service, etc.

Data communication

The communication of the User's personal data to third parties is subject to compliance with the legal limits imposed and the purposes declared and provided for in point 1. The third parties involved fall into the following categories:

1. those responsible for warehousing, packaging, shipping, delivery and return of products;
2. those appointed by the Data Controller for the administrative, contractual, accounting and legal management of the Website's activities;
3. credit and insurance institutions and the company/companies appointed to manage payments, including electronic payments;
4. those appointed to manage and maintain the Website and all its functions;
5. any other parties to whom the Data Controller has granted access to the data, always in compliance with legal or regulatory provisions.
6. associated, related companies, and offices associated with our Company.

Finally, the User's personal data may be used for contests and/or prize draws, for sending advertising and promotional material relating to the Website and the Data Controller's Partners, only with the User's explicit and voluntary consent.

Consent to processing

In cases where data processing requires the User's explicit and voluntary consent, it will be collected specifically with an explanation of the individual purposes pursued. It is specified that Article 6 of the GDPR provides for cases where data processing does not require the User's express authorization, such as for the fulfillment of legal or contractual obligations assumed towards the User.

Data Subject Rights

The User has the right to request at any time confirmation of the existence of personal data concerning them, in accordance with articles 12 et seq. of the GDPR.

In particular, in accordance with the Personal Data Regulation, you benefit from the following Specific Rights:

a. access (Article 15 of the GDPR),
b. rectification (Article 16 of the GDPR),
c. erasure (Article 17 of the GDPR),
d. restriction of processing (Article 18 of the GDPR),
e. data portability (Article 20 of the GDPR),
f. objection (Articles 21 and 22 of the GDPR),
g. post-mortem directives (Law No. 78-17 of 6 January 1978 on information technology, files, and freedoms);

Access rights

You have the right to obtain from the Data Controller confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data and the following information:

1. the purposes of the processing;
2. the categories of personal data concerned;
3. the recipients or categories of recipient to whom the personal data have been or will be disclosed;
4. where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
5. the existence of the right to request from the Controller rectification or erasure of personal data or restriction of processing of your personal data or to object to such processing;
6. where the personal data are not collected from you, any available information as to their source;
7. where personal data are transferred to a third country or to an international organisation, you have the right to be informed of the appropriate safeguards relating to the transfer.

Rectification rights

You have the right to obtain from the Data Controller, as soon as possible, the rectification of inaccurate data concerning you. You also have the right to request that incomplete data be completed, even if a supplementary declaration needs to be provided.

Right to erasure

You have the right to obtain from the Controller the erasure, as soon as possible, of data concerning you when for one of the following reasons:

a. the data are no longer necessary in relation to the purposes for which they were collected or otherwise processed by the Controller,
b. you have withdrawn your consent to the processing of these data and there is no other legal basis for the processing;
c. you exercise your right to object under the conditions set out below
d. there is no compelling legitimate reason for the processing;
e. the data have been unlawfully processed;
f. the data must be erased to comply with a legal obligation;
g. the data have been provided by a child.

Rights to restriction

You have the option to obtain from the Data Controller the restriction of the processing of your data in application of one of the following reasons:

a. the Data Controller verifies the accuracy of the data following your dispute of the accuracy of the data.
b. the processing is unlawful and you oppose the erasure of the data, demanding instead the restriction of their use;
c. the Data Controller no longer needs the data for the purpose of their processing, but they are still necessary for the establishment, exercise, and/or defense of legal claims;
d. you have objected to the processing under the conditions set out below, and the Data Controller verifies whether the legitimate grounds pursued override the grounds you have stated.

Right to data portability

You have the right to receive from the Controller the data concerning you in a structured, commonly used and machine-readable format when:

1. Data processing is based on consent and/or a contract, and
2. Processing is carried out using automated procedures.

When you exercise your right to portability, you have the right to have the data transmitted directly from the Controller to a data processor you designate, where technically feasible.

Right to object

You have the right to object at any time, on grounds relating to your particular situation, to processing of data concerning you based on the legitimate interest of the Controller. In such a case, the Controller shall no longer process the data, unless it demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defense of legal claims.

Where data are processed for direct marketing purposes, you have the right to object at any time to processing of these data.

Finally, the User has the right to object, in whole or in part, on legitimate grounds, to the processing of personal data concerning him or her, even if pertinent to the purpose of the collection, and to the processing of personal data concerning him or her for the purpose of sending advertising materials or direct sales or for carrying out market research or commercial communication.

To exercise these rights, the User may contact the following addresses: Tony S.r.l. - Via Carducci 32, 2012 Milano - email: privacy@milor.it 

Data controller

The data controller of the personal data of Users who use the Website is Milor S.p.A. - Via dei Gracchi 35, 20146 Milan. To exercise their rights and for any further information regarding data processing, the User can contact the Data Controller at the following addresses: Milor S.p.A. - Via dei Gracchi 35, 20146 Milan - email: privacy@milor.it.

Data retention period

Your Personal Data is kept active for a period of three (3) years from your last activity on the Site or on an electronic communication medium (specifically an email message) or, after this period, your profile is considered "inactive" and will be automatically deactivated. You are therefore responsible for creating a new one for any new Orders.

Your Personal Data in connection with an Order is kept for a period of three (3) years from an Order. It remains accessible to you and us, particularly after the creation of your account, to allow you and us to have a complete history of your Orders. We can delete them at any time upon your simple request.

However, at the end of the aforementioned periods, and where applicable, from your deletion request, your Personal Data may be subject to intermediate archiving to fulfill our legal, accounting, and tax obligations.

Social networks

The Website is present on Social Networks. For more information on the protection of your Data when browsing these Social Networks, please consult their respective privacy policies.

To allow us to facilitate your registration or connection to our Website, you may have the option to authenticate on our Website through a Social Network. Simply click on the dedicated button to automatically pre-fill your Website registration form based on the information you have already provided to the Social Network. On our part, and as the recipient, we may collect information when you browse our Social Network pages or use their authentication features.

Protection of minors

Unless specifically stated otherwise, the Website's services are intended for a general audience. We recognize a special obligation to protect personal information obtained from young children. Therefore, for children under the age of 16 to register for any service, we require the child to provide the email address, or other contact information, of a parent or guardian who will be contacted by the Data Controller in order to inform them, confirm, modify, or refuse their child's registration. The Data Controller reserves the right to request written proof of parental or guardian authorization at any time. Until the parent or guardian responds to the Data Controller's email in accordance with the Data Controller's instructions, the child's use of the services may be limited.

Cookie policy

Cookie

A "cookie" is a connection marker that designates a text file which can be stored, according to your choices, in a dedicated space on your device's hard drive when you visit the Website. A cookie file allows its issuer to identify the device on which it is stored, for the duration of the cookie's validity or storage period, and should therefore be considered as Personal Data.

When you connect to our Website, we may, based on your choices, install various cookies on your device that allow your device's browser to be recognized during the validity period of the cookie in question.

No personal user data is acquired by the Website in this regard. Cookies are not used for the transmission of personal information, nor are so-called persistent cookies of any kind used, or systems for tracking users.

The use of so-called session cookies (which are not persistently stored on the user's computer and disappear when the browser is closed) is strictly limited to the transmission of session identifiers (consisting of random numbers generated by the server) necessary to allow secure and efficient exploration of the site. The so-called session cookies used on this site avoid the use of other IT techniques potentially prejudicial to the confidentiality of users' navigation and do not allow the acquisition of personal identifying user data.

Third-party cookies

The use of third-party cookies (temporary and permanent) by the site is anonymous only and solely aimed at allowing the owner to use web analysis services provided by third parties. These cookies allow information about the pages visited on the site to be collected and recorded anonymously, but do not allow the visitor to be identified, and are in no way combined with other information. These data are used exclusively to track and examine user site usage, compile statistics based on anonymously collected information and by using aggregated data.

 

In particular, users are informed that the web analysis service that issues cookies used by the owner is 'Google Analytics', described below. Google Analytics is a web analysis service provided by Google, Inc. ('Google') that uses 'cookies', which are stored on the user's computer to enable the visited website to analyse how users use it. The information generated by the cookie about the user's use of the visited website (including the IP address) will be transmitted to Google and stored on Google's servers in the United States. Google will use this information for the purpose of tracking and examining the user's use of the website, compiling reports on website activity for site operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law or where such third parties process the aforementioned information on Google's behalf. Google will not associate the user's IP addresses with any other data held by Google. The user can, at any time, refuse the use of cookies by selecting the appropriate setting on their browser.

 

By using this Site, the User consents to the processing of their data by Google for the methods and purposes indicated above. To consult the privacy policy of the company Google, relating to the Google Analytics service, please visit the website http://www.google.com/intl/en/analytics/privacyoverview.html.

Code of ethics

Guiding principles

The Code of Ethics represents an organization's identity card; it expresses the guidelines for conduct that should inspire the behavior of its members and is the main means of disseminating ethical culture within the company. The spread of the Code of Ethics has increased in recent years, also by virtue of specific legal provisions that, especially at an international level, have led companies and other organizations to adopt it.

Due to the globalization of markets, there is an ever-increasing need worldwide to introduce and explicitly state ethical and social rules in economic models that allow profit and value creation objectives to coexist with respect for the demands and interests of those involved in business activities, not only in national and international relations but also within corporate environments (either because the expectations and interests, however legitimate, of the various stakeholders - Shareholders, Employees, Suppliers, Customers, Commercial Partners, etc. – may conflict with each other, or because in some cases there is a risk that actual behaviors do not correspond at all to the proclaimed principles).

In the Italian landscape, the importance of having a tool such as the Code of Ethics is emphasized, among other things, by the provision for specific liability of entities consequent to the commission of crimes pursuant to Legislative Decree no. 231 of 8 June 2001.
In this context, the companies belonging to the Milor group (the "Group") have always committed themselves to applying rigorous principles observed in the performance of various activities and have always been characterized by the seriousness, reliability, and professionalism of the work of their Management, their Employees, and Collaborators, thus acquiring over the years a consolidated reputation appreciated also at an international level.

In order to pursue continuous improvement objectives, Milor has deemed it appropriate to adopt and issue this Code of Ethical Conduct, which explicitly states the corporate principles and values it has pursued over the years, highlighting rules of conduct whose observance - by all those who, for any reason, operate in the name and on behalf of the Group's companies - is fundamental for maintaining and improving the regular functioning, the reliability of business processes, and the image of the Group itself.

All operations and behaviors of all recipients of this Code of Ethics must refer to these principles and rules, both in internal professional relationships and in relations with parties external to the Group.

The Group's Mission

The Group recognizes the importance of ethical and social responsibility in conducting its business and corporate activities and is committed to respecting the legitimate interests of Shareholders, Directors, Employees, Collaborators, Customers, Suppliers, and Business Partners.

The Group companies are therefore committed to:

— maintaining consistency with the policies always adopted regarding fairness, transparency, trust, and cooperation in conducting business;
— maintaining an active role in the market, economic development, and technological progress of the sectors in which it operates;
— pursuing solid and sustainable value from an economic, financial, and social perspective, built on customer trust, employee motivation, and a responsible and constructive relationship with the local community;
— continuously improving the quality of products and services offered to customers, increasing customer satisfaction through effective and fair market competition, in full and absolute compliance with the laws and regulations in force in the countries where it operates;
— sensitizing and involving Suppliers in a proactive role, particularly concerning compliance with laws and regulations in the supply of goods and services and transparency and contributes, among other things, to spontaneous compliance by every Employee and Collaborator.
— promoting the personal and professional development of its Collaborators and motivating them to a sense of belonging and the pursuit of continuous improvement in efficiency and effectiveness in order to increase satisfaction and corporate and personal well-being.

At the same time, it requires all Employees belonging to the Group companies and all those who cooperate in the exercise of business activities to comply with company rules and the provisions established in this Code of Ethics.

The achievement of these objectives can only occur through the constant and active participation of all subjects involved in the business activities of the Group companies and their full awareness that these goals must be achieved in compliance with those reference values and rules of conduct that, through this Code of Ethics, are made explicit.

The rules contained in this Code of Ethics and the principles of conduct for conducting business and in interpersonal relationships must not, therefore, appear "obvious" to the recipient of this document, but rather as a tool for reflection on the values referred to: a personal adherence to these values contributes, among other things, to spontaneous compliance by every Employee and Collaborator.

Recipients and scope of the code

The reference values and rules of conduct set out in the Code of Ethics are binding for all Group companies, their Directors, Employees, and third parties who operate in the interest of the Group in any capacity; these include Agents, Technical Assistance providers, Suppliers, Distributors, developers, Consultants, and Collaborators in general (hereinafter “Collaborators”). In particular, Directors are required to be guided by these values and rules of conduct when setting the objectives of the companies within the Group, proposing investments and implementing projects, as well as in any decision or action related to company management.

Employees with management qualifications, when concretely implementing the management activities of the Group companies, must be guided by the same values and rules of conduct both within the Group, thus strengthening cohesion and the spirit of mutual collaboration, and towards third parties who come into contact with the Group itself.

All Employees are required to adhere, in the performance of their duties and responsibilities, to the principles and rules of conduct contained in the Code of Ethics, to company procedures, regulations, and policies.

All Employees are also called upon to demand compliance with the principles and rules contained in this Code of Ethics from independent third-party Collaborators who, in any capacity, operate in the interest of the Group. They undertake to inform Collaborators of the content of this Code of Ethics and instruct them to comply with the rules contained therein.

The Group's Collaborators are required to adapt their behavior to the provisions of the Code, company procedures, and regulations.

Reference values

Compliance with Laws and Regulations
The Group companies recognize compliance with the laws and regulations in force in all the countries in which they operate as a fundamental principle. Directors, Employees, and Collaborators who, in various capacities, are involved in the Group's business activities, are therefore required to carry out their activities in a context of maximum transparency and in absolute compliance with the laws and regulations in force in the place and at the time in which they operate. They therefore undertake to have the best possible knowledge of the applicable regulations relating to their activity and of the responsibilities arising from their violation. In no case can the pursuit of the Group's interest justify actions that do not comply with laws and regulations.

Integrity
Moral integrity is a constant duty for all those who work in the name of and/or on behalf of the Group companies. All recipients of this Code of Ethics are required to pursue objectives with honesty, fairness, and responsibility and to maintain conduct based on respect for rules, laws, and professional ethics.

Transparency and completeness of information
The Group companies promote transparency in communications, formal agreements, and the criteria underlying the behaviors followed in order to allow autonomous and informed choices by the involved parties. All recipients of this Code of Ethics are required to respect the principles of truthfulness, correctness, completeness, accuracy, and transparency of information and to communicate the Group's image clearly and diligently in all its internal and external relationships.

Value of the person
The Group companies promote respect for the physical, moral, and cultural integrity of the person; they guarantee working conditions that respect individual dignity and safe working environments. All recipients of this Code of Ethics are called upon to promote listening and dialogue as levers for improvement and continuous stimulus for the search for proposed solutions, not only in relations with customers but also in relations with their Collaborators and colleagues, respecting the professionalism and competence of each.

Equity and equal opportunities
The Group companies undertake to avoid any discrimination in personal conduct and to respect differences in gender, age, race, religion, political or trade union affiliation, language, or disability. All recipients of this Code of Ethics are called upon to operate taking into account the concrete circumstances; not engaging in discriminatory and opportunistic behavior but rather contributing to bringing out the potential of each individual.

Fairness
In conducting any activity, situations must be avoided where the parties involved in transactions are, or may even appear to be, in a conflict of interest.

Relationships with supervisory bodies
Relationships with supervisory bodies are inspired by principles of transparency, completeness, truthfulness, and correctness of information.
Information that, according to current regulations, must be communicated to the supervisory bodies cannot be withheld or distorted.

Confidentiality
Milor ensures the confidentiality of the information in its possession and refrains from seeking confidential data, except in the case of express and informed authorization in accordance with current legal provisions. Group employees are obliged not to use confidential information for purposes not related to the exercise of their job duties.

Freedom of the market
Milor conducts its activities in compliance with the principles of competition and freedom of the market and, consistently with the management autonomy of individual subsidiaries, aligns the Group's activities with these principles.

Rules of Conduct

Milor's Code of Ethics is addressed to all Group companies, their Directors, Employees and Collaborators, regardless of specific organizational, production and/or commercial realities, and sets forth rules of conduct which all recipients are called upon to observe. Directors, Executives, Employees and Collaborators who have contractual relationships with the Group, for whatever reason, are required to observe and ensure the observance of these principles within the scope of their functions and responsibilities, as well as to collaborate in the preparation of adequate procedures designed to safeguard the interests of the Group.

Human Resources Management

In accordance with the values stated above, the Group recognizes human resources as an indispensable element for successfully competing in the market and achieving corporate objectives, as well as the importance of establishing relationships with them based on loyalty and mutual trust.

Group companies must ensure that the selection, classification, and career paths of company personnel, as well as the choice of Employees and Collaborators in various capacities, are based exclusively, without any discrimination, on objective considerations of the professional and personal characteristics necessary for the work to be performed and on the abilities demonstrated in its fulfillment. Group companies must reject any discriminatory behavior regarding access to employment, assignment of qualifications and duties, career progression, or assignment of roles.

Selection and management of resources
In light of the above, company policies for the selection, remuneration, and training of Employees and Collaborators must be based on criteria of professionalism, seriousness, competence, and merit. In particular, the responsible functions must ensure that:

- acquired resources correspond to the profiles actually necessary for company needs, avoiding favoritism and concessions of any kind, respecting equal opportunities and without any discrimination based on the private sphere and opinions of candidates;
- fair and consistent treatment of Employees and Collaborators is maintained, preventing abuses and discrimination based on sex, race, religion, political and trade union affiliation, language, age or disability;
- equal treatment and equal opportunities are guaranteed in the assignment of roles or tasks, considering mobility to different work positions as an element to promote professional growth.

Professional development and training of resources
The Group companies are committed to contributing to the training and professional growth of their Employees and Collaborators by periodically offering them opportunities for mutual knowledge and information on their respective work experiences, as well as other training interventions, in order to promote their development and enable them to develop their professional competence within the Group.

For this reason, Managers and Function Heads are called upon to pay the utmost attention to valuing and enhancing the professionalism of their colleagues and Collaborators by creating the conditions for the development of their abilities and the realization of their potential. In particular, the responsible functions must ensure that:

- the necessary conditions are maintained to develop the skills, abilities, and talent of each individual in compliance with company equal opportunities policies;
- systems for evaluating behaviors, competencies, knowledge, and potential are maintained according to criteria of transparency and meritocracy;
- the possibility of expressing one's individuality at work is recognized, valuing the diversity and specificity of each person as an essential contribution to the Group's growth;
- conditions are maintained that enable each person to best interpret their role, promoting constant improvement in their level of competence and developing the ability to work in a team to contribute to the achievement of company objectives;
- training that also considers individual needs is proposed, evaluated, and developed in the definition of training paths.

Work environment
All Employees and Collaborators must be treated in strict compliance with the principles set forth in this Code of Ethics and within a climate that maximizes communication and cooperation, among themselves and with superiors and subordinates, with a common and shared objective of growth and consolidation of the spirit of belonging to the Group. In particular, company management, executives, employees, and collaborators who work in various capacities on behalf of and/or in the name of the Group's companies must:

- base their interpersonal and professional relationships on criteria and behaviors of fairness, loyalty, and mutual respect;
- promote and support respect for the personality of each colleague and Collaborator as a fundamental element for the development of a work environment permeated by mutual trust and the contribution of each individual;
- commit to creating a work environment that guarantees, to all those who interact with the Group's companies in any capacity, conditions that respect personal dignity and in which individual characteristics cannot give rise to discrimination or conditioning;
- aim to create a work environment that is always stimulating and rewarding and that, therefore, favors the development of everyone's potential.

Financial, administrative, and accounting management

The most rigorous accounting transparency for each company within the Group is, at all times and under all circumstances, a priority requirement for the Group itself. The procurement and disbursement of financial resources, as well as their administration and control, must always comply with the Group's approval and authorization procedures.

Directors, Employees, Collaborators, and all those who have any dealings with the Group must maintain strictly correct, transparent, and collaborative conduct in compliance with legal norms and company procedures in all activities aimed at preparing financial statements and other corporate communications. In particular, the following is mandatory:

- everyone is required to strictly observe established procedures and provide maximum cooperation to ensure that management events are presented correctly and promptly in the company's accounting records;
- everyone, within their respective competencies and functions, must adhere to the most rigorous principles of transparency, correctness, and truthfulness in the preparation of accounting documents and data, as well as every record pertaining to administration;
- in the case of economic-asset items based on valuations, the related recording must clearly illustrate, in the relevant documentation, the criteria that guided the determination of the asset's value;
- the documentation supporting every accounting transaction must be adequate, truthful, clear, and complete; it must be kept on file in such a way as to allow, at all times, control over the characteristics of the transaction, its reasons, and the precise identification of who, at different stages, authorized, carried out, recorded, and verified the transaction itself; competencies must be clearly defined and known within the organization;
- the related accounting record must clearly, completely, and truthfully reflect what is described in the supporting documentation;
- the supporting documentation must be easily retrievable and archived according to appropriate criteria that allow for easy consultation by both internal entities and external entities authorized for control.

Receiving stolen goods and money laundering

Accuracy of financial flows
Any operation that could lead to even the slightest possibility of the Company being involved in cases of receiving stolen goods, money laundering, or using assets or money of illicit origin is strictly prohibited. Financial flows must be managed by ensuring complete traceability of operations, maintaining adequate documentation, and always within the limits of the responsibilities assigned to each individual. To this end, it is necessary to comply with the following principles regarding the documentation and retention of records:
- all payments and other transfers made by or on behalf of the Company must be accurately and fully recorded in the company's accounting systems;
-. all payments must be made only to the entities and for the activities contractually formalized and/or resolved by the Company.

The Company implements the necessary controls to verify the authenticity of cash collected and used within the scope of company activities. Recipients are required to exercise the utmost diligence and attention in handling cash to ensure that no counterfeit money is collected or spent. The Company is committed to ensuring that the gold used for the production of its jewellery items does not come from geographical areas of the world involved in armed conflicts generated by economic interests for the control of precious metal extraction. Furthermore, it confirms its commitment to the responsible sourcing of gold.

To this end, our commitment is to ensure compliance with the Dodd Frank Act and to purchase gold only from banks, metal exchanges or refineries that are included in the LBMA Good Delivery List or that are certified by the RJC (Responsible Jewellery Council) organization.

Privacy Policy

In compliance with current legislation, the Group companies undertake to guarantee the protection of privacy regarding information related to the private sphere and the opinions of each of their Employees and those who interact with the Group. Employees and Collaborators acting in the name or on behalf of the Group companies are required to process personal data in full compliance with current privacy protection legislation, according to the directives given to them. In particular, it is mandatory to:

- acquire and process only the data necessary and directly related to their functions;
- respect the confidential and private nature of the information;
- acquire and process data for specific, explicit and legitimate purposes;
- acquire and process relevant, accurate, complete and non-excessive data with respect to the purposes for which they were collected and subsequently processed, ensuring their proper updating;
- store said data in such a way as to prevent unauthorized third parties from accessing them;
- communicate and disclose data only within the scope of established procedures or with the prior authorization of the responsible managers;
- store data in a form that allows the identification of the data subject for a period not exceeding that necessary for the purposes for which they were collected and subsequently processed.

Management, Employees or Collaborators appointed to process personal data must adopt all suitable measures to avoid the risks of destruction or loss, even accidental, of the aforementioned data, unauthorized access to them or processing not permitted or not compliant with the purposes of collection; these measures are identified and periodically updated within the Group companies.

Protection of safety

The Group's companies aim to maintain the highest levels of hygiene and safety and to guarantee the necessary prevention measures against accidents and illnesses in the workplace. Everyone must contribute to maintaining a healthy and safe work environment and ensure the safety of their colleagues and Collaborators of various capacities.


Every corporate function must do everything possible to always have full knowledge, for its area of responsibility, of the Group's rights and obligations derived from legal norms, contracts, or relationships with Public Administration, and must not engage in any conduct that could harm the Group's interests in any way.

All Employees and Collaborators working for or on behalf of the Group's companies are strictly forbidden from disclosing to third parties information not publicly known regarding projects, acquisitions, mergers, commercial strategies, and more generally, information concerning the Group's companies of which they have become aware or whose dissemination could, in any case, prejudice the Group's interests.

Each individual is responsible for safeguarding, preserving, and defending the Group's assets and resources entrusted to them in the course of their activities and has the obligation to use them appropriately and in compliance with regulations, preventing any improper use.

Protection of company assets

To protect the integrity of the company's assets, it is specifically forbidden, except in cases permitted by law, to:

- return contributions in any form or release members from the obligation to make them;
- distribute profits not actually earned or legally allocated to reserves, or to reserves not distributable by law; purchase or subscribe shares or
company quotas;
- carry out reductions of share capital, mergers, or demergers in violation of the rules protecting creditors; fictitiously increase or subscribe to share capital; satisfy, in the event of liquidation, the claims of members to the detriment of company creditors.

Relations with public administration

This context includes all relationships, pertaining to the Group's companies' activities, maintained with public officials or public service representatives operating on behalf of the Public Administration or national and foreign legislative bodies, EU institutions, and public organizations of any foreign state.

Relationships with governments and public institutions are reserved for corporate functions authorized to establish and manage such relationships based on service orders and prevailing procedures. These relationships must be undertaken and managed in absolute and strict compliance with current laws and regulations, the rules and principles set forth in the Code of Ethics, and relevant internal procedures.

Attention and care must be exercised in relationships with the aforementioned subjects, particularly in areas related to: tenders, contracts, authorizations, licenses, concessions, requests and/or management and use of publicly sourced funding (national or EU) however denominated, order management, relationships with supervisory authorities or other independent authorities, social security institutions, tax collection agencies, civil, criminal or administrative proceedings. Attention and care must also be exercised in those sectors which, although not implying direct relationships aimed at concluding business with the Public Administration, are considered in support of business activities such as the management of financial flows and the management and security of IT data.

The operations referred to above and the related management of financial resources must be undertaken in due observance of laws, the principles of the Code of Ethics, and in full compliance with internal procedures. In particular, it is expressly forbidden to:

- accept, give or promise, neither directly nor indirectly, nor through an intermediary, money, gifts, goods, services, benefits or favors to public officials - or to persons related to them by kinship or affinity - in order to promote and favor one's own interests or the interests of the Group's companies, or even to compensate or repay for an act of their office, or to obtain the execution of an act
contrary to the duties of their office;
- receive, offer or promise gifts or other forms of presents to public officials or to persons related to them by kinship or affinity – when such gifts, considering their value, exceed normal commercial and courtesy practices or in any case fall outside what is provided
by internal company protocols;
- hire personnel, assign agency, consultancy or other types of assignments, if the hiring or assignment is – or may appear – aimed at an exchange of favors with subjects belonging, or previously belonging, to the Public
Administration;
acknowledge compensation in favor of external Collaborators that is not adequately justified by the type of assignment to be carried out and by local practices;
- submit untrue declarations or other documentation to public bodies in order to influence the independence of judgment;
- submit untrue declarations or other documentation to national or EU public bodies in order to obtain public disbursements, contributions or subsidized financing;
- allocate sums received from national or EU public bodies as disbursements, contributions or financing for purposes other than those for which they were intended;
- alter the functioning of an IT or telecommunication system or manipulate the data contained therein in order to obtain an unfair profit causing damage to the Public Administration.

In dealings with the Public Administration, it is always necessary to act in compliance with the law, with the express prohibition of engaging in conduct which, in order to bring advantages to the Group, would constitute criminal offenses.

Supplier and customer relations

Supplier Relationships
The Directors, Employees and Collaborators of the Group's companies are required to ensure equal opportunities in the selection of Suppliers, taking into account their compatibility and adequacy with the size and needs of the Group. In particular, the appointed functions, when selecting independent third parties such as consultants, agents, suppliers of goods and services, must ensure that:

- they are selected based on objective evaluations and parameters (such as quality, convenience, price, capability and efficiency, etc.) aimed at protecting the commercial and industrial interests of the Group and, in any case, at creating greater value for it;
- they are selected according to criteria of reliability and integrity, also in consideration of the need to comply with the reference values, the rules of conduct contained in the Code of Ethics and internal procedures, using written form and in compliance with the Group's hierarchical structure;
- the Group's policies are communicated to them and specific contractual clauses regarding compliance with this Code of Ethics are provided for.
The appointed functions must also ensure that there is continuous awareness and involvement of Suppliers in a proactive role and a responsible attitude, particularly with regard to transparency, communication, compliance with laws and regulations, and that fosters awareness of the social and ethical risks and opportunities arising from their activities.

Customer Relationships
In relationships with Customers, whether public or private, the Directors, Employees and Collaborators of the Group's companies are required to:

- develop and maintain favourable and lasting relationships with them, based on maximum efficiency, collaboration and courtesy;
- operate within the framework of current legislation and demand its punctual compliance;
- ensure that the declarations and attestations made to them are precise and truthful;
- respect commitments and obligations undertaken towards them;
- provide accurate, complete, truthful and timely information to enable the Customer to make informed decisions.

In business relationships with Suppliers and Customers, company policies must be respected, basing relationships on maximum fairness, especially in the management and conclusion of contracts, avoiding conflicts of interest, even potential ones.

Without prejudice to the provisions of the paragraph "Relations with the Public Administration", in business relationships with Suppliers and Customers, donations, gifts, acts of courtesy or hospitality are prohibited (both directly and indirectly) unless they are of such a nature as not to compromise the image of the Group and not to be interpreted as aimed at obtaining preferential treatment that is not determined by legitimate market rules. In any case, any gifts, acts of courtesy and hospitality that do not fall within normal custom must be adequately documented and communicated to one's manager so that they can evaluate their appropriateness. The Employee or Collaborator who receives gifts or preferential treatment from Suppliers or Customers that go beyond ordinary courtesy must immediately inform their hierarchical superior; after appropriate checks with the competent management, the companies will, through the appointed functions, inform the author of the gift, present, etc., about the Group's policy on the matter.

Compliance with competition law

The Group companies are committed to ensuring maximum competitiveness in the market and, therefore, their commercial policy must be based on compliance with competition regulations, both in the national market and internationally.



All recipients of this Code of Ethics must always stay updated on the regulations in force and consult their direct supervisor before concluding any agreement or understanding that could have effects of presumed unlawful competition.

Prevention of conflicts of interest

Company management, employees, and collaborators acting on behalf of the Group's companies are required to operate in a manner that avoids situations conflicting with the Group's interests. By way of example, but not limited to, the following constitute conflicts of interest:

- using one's functional position to pursue interests that conflict with those of colleagues within the company;
- using information acquired during work activities for one's own benefit or that of third parties, or in any case in conflict with the Group's interests;
- an employee's participation – overt or covert – in the activities of suppliers, customers, or competitors;
- performing work activities of any kind for customers, suppliers, competitors, and/or third parties, in conflict with the Group's interests. In particular, for employees, the acceptance of any professional assignment offered by third parties must be evaluated in advance with their direct superior and with the Human Resources Director of Milor S.p.A. in order to assess the absence of any incompatibilities or prejudicial situations.

Everyone has a duty to promptly report to the relevant management any situation that could be considered, even potentially, prejudicial to the rights and interests of the Group, so that the management can proceed, equally promptly, with the necessary protective actions.

Relations with regulatory bodies

Relationships with bodies responsible for legally assigned control or auditing activities, and relationships with auditing firms, must be based on the utmost fairness, transparency, and cooperation, in full compliance with current laws and regulations.

In particular, auditors, both internal and external, must have free access to data, documents, and information necessary for carrying out their activities. It is expressly forbidden to prevent or hinder the performance of control or auditing activities legally assigned to shareholders, other corporate bodies, or the auditing firm.

The same obligations extend to relationships with the Supervisory Body which, within the scope of the responsibilities provided for by the respective Organization and Management Models voluntarily prepared by the Group companies pursuant to Legislative Decree No. 231 of 8 June 2001, "Regulation of the administrative liability of legal persons, companies and associations, even those without legal liability, pursuant to Article 11 of Law No. 300 of 29 September 2000," is tasked with overseeing compliance with existing preventive and control systems, as well as their actual adequacy, particularly in those areas where potential crime-risks connected to the activities carried out are identified (Ref. Code of Ethics and Organizational Models pursuant to Legislative Decree 231/2001).

Code of ethics and organizational models (pursuant to Legislative Decree 231/2001)

As part of the internal control systems of the Group's companies, this Code of Ethics is an integral part of the Organization and Management Models pursuant to Legislative Decree No. 231/2001 voluntarily adopted by them. In compliance with their full autonomy and their respective commercial and/or production specificities, the Group companies that adopt Organization and Management Models in adherence to the principles expressed by Legislative Decree 231/2001 and subsequent amendments and/or additions, are required to carry out risk assessment activities in order to identify the areas in which crimes can be committed and to establish prevention and control systems based on the provisions of the decree itself.

Supervisory body

The Group companies appoint their own Supervisory Body (OdV), which has autonomous powers of initiative and control, with the task of:

— overseeing the functioning and observance of the Code of Ethics and company procedures, particularly in those areas where crime risks under Legislative Decree 231/2001, potentially related to the activities carried out, are identified – to this end, it is free to access all company information sources, inspect documents, and consult data;
— receiving and/or reporting any violations of the Code of Ethics;
— proposing any updates to the Code of Ethics and internal protocols to align them with laws;
— verifying, controlling, and evaluating cases of violation of the rules established by the Code of Ethics and reporting them to the relevant functions for the application of appropriate disciplinary measures in compliance with laws, regulations, and national collective bargaining agreements (CCNLs).

Reports to the supervisory body

Group companies are required to establish appropriate communication channels through which anyone who becomes aware of any conduct within Group companies that is contrary to the principles and rules of conduct expressed in this Code can report it freely, directly and confidentially to their direct superior and to the Supervisory Body, if appointed.

The information acquired by the Supervisory Body and the designated functions, for the purposes of due investigations, must be treated in such a way as to guarantee:
- the confidentiality and anonymity of the whistleblower,
- the protection of the whistleblower against any form of retaliation, penalty, discrimination, without prejudice to legal obligations and the protection of the rights of the Group companies or persons wrongly and/or maliciously accused.

Code violation and sanitizing system

Compliance with the principles and rules of the Code of Ethics must be considered an essential part of the contractual obligations of Employees. Violations of the rules of the Code of Ethics may constitute a breach of the main obligations of the employment relationship or a disciplinary offense, with all legal consequences, including with regard to the continuation of the employment relationship, and may lead to compensation for damages arising therefrom.



Compliance with the Code of Ethics must be considered an essential part of the contractual obligations assumed by non-subordinate Collaborators and/or individuals having business relations with the Group. Violations of the rules of the Code of Ethics may constitute a breach of contractual obligations, with all legal consequences, including with regard to the termination of the contract and/or assignment, and may lead to compensation for damages arising therefrom. For violations by members of the Board of Directors and Statutory Auditors, all legal provisions apply with the consequent remedies and sanctions.



The Group companies undertake to provide and impose, consistently, impartially and uniformly, sanctions proportionate to the respective violations of the Code and in compliance with the current provisions on the regulation of employment relationships.

Dissemination of the Code of Ethics

The Group's companies undertake to disseminate the Code of Ethics among its recipients, to promote and give ample space, within their internal communication, to issues related to ethics/behavioural conduct and the prevention of irregularities. All recipients of this Code of Ethics are therefore required to be aware of its content, to observe and ensure that the principles and rules of conduct expressed therein are observed.