PRIVACY POLICY

Purpose of This Document

This Privacy Policy is intended to inform natural persons (hereinafter referred to as the ‘Data Subject’) regarding the processing of their personal data (‘Personal Data’) by Luxury Distribution S.R.L., with registered office at Viale Fratelli Rosselli 24, 22100 Como, Italy, Tax Code/VAT No. 04040630131, email: [email protected] (hereinafter referred to as the ‘Data Controller’), through the website https://luxury-distribution.com (the ‘Application’).

Updates and Acceptance

Modifications to this Privacy Policy will take effect upon publication on the Application. In the event of non-acceptance of such updates, the Data Subject must discontinue use of the Application and may request deletion of their Personal Data by contacting the Data Controller.

Categories of Personal Data Processed

The Data Controller may process the following categories of Personal Data provided voluntarily by the Data Subject:

– Contact Data: first name, last name, address, email address, phone number, profile picture, authentication credentials, and any additional information voluntarily provided.
– Fiscal and Payment Data: tax code, VAT number, credit card details, bank account information.

Automatically collected data includes:

– Usage Data: e.g., pages visited, number of clicks, actions performed, session duration.

If the Data Subject fails to provide Personal Data that is legally or contractually required, or essential to entering into a contract with the Data Controller, such a contract cannot be concluded or continued.

The Data Subject assumes full responsibility for Personal Data relating to third parties, ensuring its lawful acquisition and disclosure.

Legal Basis and Purposes of Processing

Personal Data is processed for the following purposes:

1. Performance of a Contract:
– Fulfilment of contractual or pre-contractual obligations
– Registration and authentication (including via external platforms)
– Responding to user inquiries
– Payment processing through various payment methods
2. Legal Obligations:
– Compliance with applicable laws and regulations, particularly in fiscal and tax matters
3. Legitimate Interests of the Data Controller:
– Direct marketing of similar products/services via email to existing clients
– Monitoring, optimizing, and securing the technical infrastructure
– Anti-fraud measures
– Anonymous statistical analysis to improve services

4. Consent-Based Activities:

– Marketing communications via automated and traditional methods
– Profiling to personalize marketing content based on preferences and behavior
– Retargeting/remarketing campaigns (with opt-out options available via the Network Advertising Initiative)

5. Use of Social Media or Third-Party Platforms:

Interactions with third-party platforms are governed by their own privacy policies and subject to the user’s settings on those platforms.

Processing Methods and Data Access

Personal Data is processed exclusively by:

  1. Personnel authorized by the Data Controller who are bound by confidentiality obligations.
  2. Independent third-party data controllers or data processors (e.g., consultants, service providers, IT and hosting companies). 
  3. Legal authorities or regulatory bodies, when required by law.

These parties are contractually obligated to use appropriate security measures and may only access data essential for their duties.

Personal Data is never shared indiscriminately or publicly.

Third-Party Sharing 

We share data with:
Payment processors (Stripe, PayPal) to enforce fee disputes.
Logistics partners (DHL) for delivery verification.
Legal authorities if required to investigate fraud
Banks for payment disputes

Location of Data Processing

Personal Data is stored and processed within the European Economic Area (EEA). No cross-border data transfers are conducted. 

Retention Period

We retain personal data for 3 years after account closure to comply with legal obligations and prevent fraud. Upon expiry of retention periods, Personal Data will be securely deleted or anonymized.

Rights of the Data Subject

The Data Subject has the right to:
  1. Be informed about the use of their Personal Data
  2. Withdraw consent at any time
  3. Restrict or object to data processing
  4. Access, correct, or delete their Personal Data
  5. Request data portability to another controller
  6. File a complaint with a data protection authority or pursue legal action
To exercise these rights, the Data Subject may send a request to [email protected]. Requests will be addressed promptly, and always within 30 days.