Privacy Policy Margot Milano

PRIVACY POLICY

Processing of personal data carried out during browsing and purchases on the website https://margotmilano.com/

Last updated: February 20, 2026

1. Data controller

The Data Controller is:

MARGOT SRL

Registered office: Salita San Pietro 4, 25036 Palazzolo sull'Oglio (BS), Italy

Tax Code/VAT No.: 03274070980

PEC: margot10@legalmail.it

Email: info@margotmilano.com

Telephone: +39 339 271 7610

DPO (Data Protection Officer): not appointed.

2. Categories of data processed

Depending on the use of the Site and the services, the following may be processed:

  • Browsing and technical data: IP address, device identifiers, browser/OS information, pages visited, date/time, security events, technical logs.
  • Account data (if registered): name, surname, email, password (in encrypted/hashed form), addresses, preferences.
  • Purchase and order data: products, amounts, shipping/billing address, contact information, notes, order status, returns/refunds.
  • Support data: content of requests, email, telephone number (if provided), any attachments (e.g. photos for warranty purposes).
  • Marketing data: consent, preferences, newsletter subscription; any email interaction data (e.g., opening/clicking) if the service used records it.
  • Data from cookies and similar technologies: as described in the Cookie Policy and managed via the banner and cookie settings.

3. Data provision

  • Providing data for purchases , payments , shipments , returns , guarantees and accounting/tax compliance is necessary: ​​without it, it will not be possible to complete or manage the order.
  • Providing data for newsletters , marketing , and cookie-based remarketing is optional: failure to provide it or provide consent does not prevent the purchase and use of the essential features of the Site.

4. Purpose of processing and legal bases

A) Operation of the Site, technical management and security

  • allow navigation and use of features;
  • ensure security, prevent abuse, fraud, unauthorized access;
  • log management, diagnostics, and service continuity.

    Legal basis: legitimate interest (Article 6.1.f GDPR) and/or technical necessity.

B) Account registration and management

  • account creation and management;
  • order history and preferences.

    Legal basis: execution of pre-contractual measures/contract (Article 6.1.b GDPR).

C) Online sales, order management, payments, shipments, returns and guarantees

  • process orders, deliveries, manage returns/refunds;
  • after-sales assistance and warranty;
  • accounting and tax obligations;
  • prevention and management of fraud/misuse.

    Legal basis: contract (Article 6.1.b), legal obligation (Article 6.1.c), legitimate interest (Article 6.1.f) for anti-fraud/security purposes.

Payment information: Payment data (e.g., card details) are processed by the respective payment providers; the Cardholder does not store complete card details, except for information required for administrative purposes (e.g., transaction outcome and ID).

D) Contacts and customer care

  • respond to requests for information/assistance/complaints;
  • management of pre- and post-sales communications.

    Legal basis: art. 6.1.b and/or art. 6.1.f GDPR.

E) Newsletter and promotional communications (consent)

  • sending newsletters, commercial and promotional communications;
  • marketing initiatives relating to the Data Controller's products/services.

    Legal basis: consent (Article 6(1)(a) GDPR).

    Revocation: at any time via the unsubscribe link in the emails or by contacting the Data Controller.

F) Promotional communications to customers (soft spam)

If you have purchased on the Site and provided us with your email address when making your purchase , we may send you promotional communications via email relating to products similar to those already purchased.

You can opt out at any time, easily and free of charge, by using the "unsubscribe" link in every email or by contacting us.

If you opt out, you will no longer receive this type of communication.

Legal basis: legitimate interest of the Data Controller and applicable law.

G) Statistics and remarketing/advertising through cookies and similar technologies

  • measuring visits and performance of the Site;
  • campaign and conversion measurement;
  • remarketing and personalized advertising activities.

    Legal basis: Consent via cookie banner (Article 6.1.a GDPR) for non-technical cookies/tools; consent is not required for essential technical cookies.

5. Profiling and automated decisions

With consent to marketing/remarketing cookies, "marketing" profiling activities based on online identifiers and interactions (e.g., visits to pages, events, purchases) may be carried out to:

  • show more relevant ads on third-party platforms;
  • limit repetitions and measure the effectiveness of campaigns;
  • create audience segments (e.g. remarketing and “lookalike” audiences).

No exclusively automated decisions are made that produce legal effects or significantly similar impacts on the user.

Consent can be modified/revoked at any time via your cookie settings. Revoking consent to marketing cookies will deactivate cookie-based remarketing activities for the future.

6. Data recipients (categories and main suppliers)

The data may be processed by:

  • authorized personnel of the Owner;
  • IT providers and e-commerce platform (e.g. Shopify ) for hosting, order management and online store functions;
  • couriers and logistics (e.g. GLS ) for delivery;
  • payment providers (e.g. Stripe , PayPal ) for transaction management;
  • marketing/analytics/advertising providers (e.g. Google and Meta ) only according to your cookie preferences and active configurations;
  • email/newsletter providers used by the Data Controller to send and manage communications;
  • consultants (legal, tax, accounting) and competent authorities when necessary.

Where required, these entities act as Data Processors (Article 28 GDPR). In other cases, they may act as independent Data Controllers (e.g., some payment providers and/or advertising platforms, depending on their roles and configurations). An updated list of Data Processors can be requested from the Data Controller.

7. Data transfers to non-EU/EEA countries

The use of providers and platforms (particularly cloud services, analytics, and advertising) may involve data transfers to countries outside the EU/EEA. In such cases, the Data Controller adopts adequate safeguards, such as Standard Contractual Clauses and additional measures where necessary, to ensure a level of protection compliant with the law.

8. Processing methods and security measures

Processing is carried out using IT and electronic means, in compliance with the principles of lawfulness, fairness, and transparency. Appropriate technical and organizational measures (access controls, data minimization, backups, security logs, account protection) are adopted to protect confidentiality and integrity.

9. Storage times

The data is stored for different periods based on the purposes:

  • Orders, invoices, accounting and legal compliance: 10 years .
  • Order management, returns, warranties, and after-sales support: for the time necessary for processing and, if related to accounting/tax documentation, according to the terms above; any procedures or disputes may require retention periods consistent with legal requirements and the defense of rights.
  • Account: until deleted/closed; in the event of inactivity for 24 months , the account may be deleted/anonymized in accordance with legal obligations and protection of rights.
  • “Contact us” requests and customer care not related to orders: until the request is fulfilled and for a subsequent period of up to 12 months , barring disputes.
  • Newsletters with consent: until consent is revoked; otherwise, data will be deleted/anonymized 24 months after the last significant interaction, unless proof of consent is required and rights are protected.
  • Soft spam (customers): until you opt out and in any case for a maximum of 24 months from the last purchase, unless otherwise documented.
  • Technical and security logs: up to 12 months , unless otherwise required for investigation or defense.

10. Rights of the interested party

The user can exercise the rights provided for in Articles 15–22 of the GDPR: access, rectification, erasure, restriction, objection (including to processing based on legitimate interest and marketing), data portability, and withdrawal of consent (without affecting the lawfulness of prior processing).

To exercise your rights: contact the Data Controller at the contact details indicated in point 1.

11. Complaint

The user has the right to lodge a complaint with the Guarantor for the protection of personal data .

12. Minors

The Site and its services are not intended for minors. If the Data Controller detects the unintentional collection of data relating to minors, it will delete it.