Privacy policy


PRIVACY POLICY

pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR)

1. Data Controller

The Data Controller responsible for the processing of personal data is:

SAVIN MILANO di Elisabetta Savin
Registered office: Via Lazzaretto 16, 20124 Milan (MI), Italy
VAT No.: 13905250968
REA: MI – 2751212
Email: info@savinmilano.com

The Data Controller determines the purposes and means of the processing of personal data.

2. Types of Personal Data Processed

The Data Controller processes the following categories of personal data:

2.1 Browsing Data

The IT systems and software procedures used to operate the website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.

Such data may include, by way of example:

  • IP addresses or domain names of the devices used by users;

  • URI addresses of the requested resources;

  • time of the request;

  • method used to submit the request to the server;

  • size of the file received in response;

  • numerical code indicating the status of the server response;

  • parameters relating to the user's operating system and IT environment.

This data is not collected for the purpose of being associated with identified data subjects; however, by its nature, it may allow users to be identified through processing and association with data held by third parties.

2.2 Data Voluntarily Provided by the User

The Data Controller processes personal data voluntarily provided by the user, for example through:

  • contact forms;

  • newsletter subscriptions;

  • account creation;

  • online purchasing procedures;

  • communications via email or other channels.

Such data may include:

  • first and last name;

  • email address;

  • telephone number;

  • shipping and billing address;

  • payment details (processed by external providers);

  • any additional information voluntarily provided by the user.

3. Purposes of Processing and Legal Bases

Personal data is processed for the following purposes:

a) Website Management and Security

  • enabling website navigation;

  • ensuring website security;

  • preventing fraud or misuse.

Legal basis: legitimate interests of the Data Controller (Article 6(1)(f) GDPR).

b) Order Management and Contractual Relationships

  • processing and fulfilling orders;

  • managing payments;

  • shipping products;

  • providing customer support;

  • managing returns and complaints.

Legal basis: performance of a contract (Article 6(1)(b) GDPR).

c) Compliance with Legal and Tax Obligations

  • accounting obligations;

  • tax obligations;

  • compliance with applicable legal requirements.

Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR).

d) Marketing and Newsletter Activities

  • sending promotional communications;

  • providing updates regarding collections, events and brand initiatives.

Legal basis: explicit consent of the data subject (Article 6(1)(a) GDPR).

Consent may be withdrawn at any time.

e) Statistical Analysis

  • anonymous or aggregated analysis of website usage;

  • improvement of services and user experience.

Legal basis: consent (for non-anonymised analytics cookies) or legitimate interest (for anonymised cookies).

4. Methods of Processing

Personal data is processed using IT and electronic tools, as well as in paper format, in compliance with the principles of lawfulness, fairness, transparency, data minimisation and security.

Appropriate technical and organisational measures are adopted to ensure a level of security appropriate to the relevant risk.

5. Data Retention

Personal data is retained only for the period strictly necessary to achieve the purposes for which it was collected, and in particular:

  • contractual and tax data: 10 years;

  • marketing data: until consent is withdrawn;

  • browsing data: as specified in the Cookie Policy.

6. Disclosure of Personal Data

Personal data may be disclosed to:

  • IT and hosting service providers;

  • payment service providers;

  • couriers and logistics companies;

  • legal, tax and accounting advisers;

  • public authorities, where required by law.

Such parties may act as Data Processors or independent Data Controllers, as applicable.

7. Transfers of Personal Data Outside the EU

Where personal data is transferred to countries outside the European Union, such transfers will be carried out in compliance with Articles 44 et seq. of the GDPR, including through adequacy decisions or Standard Contractual Clauses.

8. Rights of the Data Subject

The data subject may exercise, at any time, the rights provided for under Articles 15–22 of the GDPR, including:

  • right of access;

  • right to rectification;

  • right to erasure;

  • right to restriction of processing;

  • right to data portability;

  • right to object;

  • right to withdraw consent.

The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).

9. Amendments to this Privacy Policy

The Data Controller reserves the right to amend this Privacy Policy at any time. Any amendments will be published on the website.

COOKIE POLICY

pursuant to the provisions of the Italian Data Protection Authority and the GDPR

1. What Are Cookies?

Cookies are small text files that websites visited by users send to their devices, where they are stored and subsequently transmitted back to the same websites upon the user's next visit.

2. Types of Cookies Used

2.1 Technical Cookies

These cookies are necessary for the proper functioning of the website and do not require the user's consent.

2.2 Analytics Cookies

These cookies are used to collect statistical information regarding the use of the website.

They may be:

  • anonymised (consent is not required);

  • non-anonymised (consent is required).

2.3 Profiling Cookies

These cookies are used to create profiles relating to users and to send advertising messages consistent with the preferences expressed by users while browsing the website.

Explicit consent is required.

3. Third-Party Cookies

The website may use third-party cookies, including those relating to:

  • traffic analysis services;

  • social media platforms;

  • marketing and remarketing tools.

The information collected through such services is governed by the privacy policies of the respective third parties.

4. Consent Management

Upon first accessing the website, users may:

  • accept all cookies;

  • reject non-essential cookies;

  • customise their preferences.

Consent may be modified or withdrawn at any time.

5. Disabling Cookies Through Browser Settings

Users may also manage or disable cookies through their browser settings.

6. Updates to the Cookie Policy

This Cookie Policy may be amended from time to time. Users are therefore encouraged to review it periodically.

I kept the substance unchanged while using standard English GDPR terminology rather than translating the Italian legal expressions too literally.nter your text here...