GDPR

1. Legal Basis

This data protection policy is drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and current legislation on data protection in Italy.

It governs how personal data processed through the website is collected, processed, stored, and protected.

Data processing takes place in compliance with the principles of lawfulness, fairness, transparency, purpose limitation, and data minimization.

2. Data Controller

The data controller is the shop management unit, responsible for the technical and organizational administration of the information provided by users when using the digital services offered through the website.

Data processing takes place exclusively for purposes related to order management, communication with users, and the proper functioning of the services.

3. Types of Data Collected

During the use of the website, the following categories of personal data may be collected:

Contact data: e-mail address, phone number (optional), shipping or billing address
Order and transaction data: products purchased, amounts, payment method used
Technical and usage data: IP address, browser type, date and time of access, preferences, cookies

Data can be provided directly by the user or collected through technical tools necessary for the proper functioning of the website.

4. Purposes and Legal Bases of Processing

Personal data are processed for the following purposes:

execution of purchase contracts and order management
fulfillment of legal and administrative obligations
protection of the legitimate interests of shop management, including service improvement and prevention of improper use
ensuring the security and proper technical functioning of the website

Processing is based on contract execution, legal obligations, legitimate interests, or the explicit consent of the user.

The user may withdraw any consent given at any time, without affecting the lawfulness of the processing carried out before the withdrawal.

5. Data Retention and Security

Personal data are stored exclusively for the time necessary to achieve the purposes indicated above.

For administrative and legal reasons, order-related data may be retained for up to 10 years.
Data processed on the basis of consent are retained until withdrawal of consent.

Appropriate technical and organizational measures are adopted to prevent unauthorized access, loss, disclosure, or alteration of data.

Information is stored on servers protected by security protocols and SSL encryption systems.

6. User Rights

Pursuant to articles 15 to 22 of the GDPR, the user has the right to:

· obtain information about processed personal data

· request data rectification or update

· request data erasure

· obtain processing restriction

· request data portability

· object to processing for legitimate reasons

· withdraw consent at any time

· lodge a complaint with the competent supervisory authority in Italy

Requests concerning the exercise of these rights can be sent by e-mail to customer service.

7. Policy Update

This data protection policy may be updated periodically to reflect regulatory changes or technical adjustments.

Changes come into effect upon their publication on the website. Users are advised to consult this policy regularly.

8. Contacts

For any questions regarding this data protection policy, please contact us via:

E-mail: info@arredamentimazzini.it

Phone: +39 051 361894

Address: Via dell'Arcoveggio 56, 40129 Bologna Bologna, Italy

Hours: Monday to Friday, 9:00 AM – 6:00 PM (CET)

Service Area: Italy