Your data protection rights under the General Data Protection Regulation
Under the General Data Protection Regulation (GDPR), you have specific rights regarding your personal data. We are committed to respecting these rights and making them easily accessible to you.
Request a copy of all personal data we hold about you
Correct any inaccurate or incomplete personal data
Request deletion of your personal data ('Right to be Forgotten')
Limit how we process your personal data
Receive your data in a structured, machine-readable format
Object to processing of your personal data for specific purposes
Use this form to exercise your data protection rights
Processing necessary to fulfill your orders and provide services
Improving our services, fraud prevention, and business operations
Marketing communications and optional features (with your permission)
Compliance with tax, accounting, and other legal requirements
SSL encryption, secure servers, access controls, regular security audits
Staff training, data minimization, privacy by design principles
Data processing agreements with all service providers
Ongoing assessment of data protection practices and policies
When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place to protect your data.
We work with trusted service providers who are contractually bound to protect your data:
Stripe (Ireland), PayPal (Luxembourg) - EU-based processing
EU-based email providers with GDPR compliance
Google Analytics with IP anonymization and data retention limits
Data Type | Retention Period | Legal Basis | Deletion Process |
---|---|---|---|
Account Information | Active account + 3 years after closure | Contract performance | Automatic deletion |
Order History | 7 years from purchase date | Legal obligation (tax law) | Automatic deletion |
Marketing Data | Until consent withdrawal | Consent | Immediate upon request |
Website Analytics | 26 months (Google Analytics) | Legitimate interest | Automatic deletion |
Support Communications | 3 years from last contact | Legitimate interest | Manual review and deletion |
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we are committed to:
If we need to notify you about a data breach, our communication will include:
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection authority.
Garante per la protezione dei dati personali
Website: www.gpdp.it
Email: garante@gpdp.it
Phone: +39 06 69677 1
For EU-wide coordination
Website: edpb.europa.eu
Find your local authority on their website
Our Data Protection Officer is here to help
For formal written requests
We guarantee to respond to all GDPR requests within 30 days as required by law. For complex requests, we may extend this period by an additional 60 days with proper notification.