Last updated: 2026-01-27
This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
The data controller responsible for your personal data is:
[Company Name]We use cookies to provide essential website functionality and, with your consent, to analyze website usage. See Section 4 for details.
We process your personal data based on the following legal grounds:
| Purpose | Legal Basis | Data Categories |
|---|---|---|
| Order Processing | Contract Performance (Art. 6(1)(b) GDPR) |
Name, email, addresses, order details |
| Account Management | Contract Performance (Art. 6(1)(b) GDPR) |
Account information, login credentials |
| Security & Fraud Prevention | Legitimate Interest (Art. 6(1)(f) GDPR) |
IP address, access logs, user agent |
| Operational Logging | Legitimate Interest (Art. 6(1)(f) GDPR) |
User actions (login, cart, checkout) for system monitoring and debugging |
| Analytics & Improvement | Consent (Art. 6(1)(a) GDPR) |
Browsing behavior, product views, searches |
| Legal Compliance | Legal Obligation (Art. 6(1)(c) GDPR) |
Invoice data, tax records |
For processing based on legitimate interest, we have conducted a balancing test to ensure our interests do not override your fundamental rights. Our legitimate interests include: ensuring website security, preventing fraud, maintaining system stability, and improving our services. You have the right to object to this processing (see Section 7).
We retain your personal data only for as long as necessary for the purposes described in this policy:
| Data Type | Retention Period | Motivazione |
|---|---|---|
| Account Data | Until account deletion | Service provision |
| Order History | 10 years | Legal requirement (tax/accounting) |
| Invoices | 10 years | Legal requirement (Italian law) |
| Access Logs (IP, requests) | 30 days | Security, fraud prevention |
| Application Logs | 30 days | System monitoring, debugging |
| Analytics Events | 180 days (configurable) | Website improvement |
| Visitor Sessions | 90 days | Analytics |
| Admin Audit Logs | 365 days | Security, compliance |
After the retention period expires, data is automatically deleted through our scheduled cleanup processes.
We do not sell your personal data. We may share your data with:
We may disclose your data when required by law, court order, or to protect our legal rights.
Your data is primarily stored within the European Economic Area (EEA). If any data is transferred outside the EEA, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses).
As a data subject, you have the following rights:
You can request a copy of all personal data we hold about you.
You can request correction of inaccurate or incomplete data.
You can request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
You can request your data in a machine-readable format.
You can object to processing based on legitimate interest.
You can withdraw consent at any time (e.g., analytics cookies).
To exercise any of these rights, please:
We will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection authority.
We implement appropriate technical and organizational measures to protect your data:
We may update this Privacy Policy from time to time. When we make significant changes, we will:
If you have any questions about this Privacy Policy or our data practices, please contact us:
Data Protection ContactFor complaints, you may also contact the Italian Data Protection Authority (Garante per la protezione dei dati personali) at www.garanteprivacy.it.