Privacy policy
Pursuant to Articles 13-14 of Regulation (EU) 2016/679 (GDPR) · Last updated: 9 September 2026
1. Data controller
The data controller is Gioielleria La Rosa dal 1835 S.r.l.s., with registered office at Via Carnazza 75/M, 95030 Tremestieri Etneo (CT), VAT No. 06010360870, represented by its legal representative Ancylla de Fátima Menezes da Silva. For any request concerning the processing of data, please write to larosagioielli@gmail.com.
2. What data we process
- Identification and contact data: first name, surname, email, telephone number, shipping and billing address, provided during registration, purchase or contact.
- Order and payment data: products purchased, amounts and data required for payment. Card details are processed directly by payment providers (Shopify Payments/Stripe, PayPal) and are not stored in full by the Data Controller.
- Browsing data and cookies: IP address, device and pages visited, collected through cookies and similar technologies (see Cookie Policy).
- Communications: content of requests sent through the contact form, email or social media channels.
3. Purposes and legal bases
| Purpose | Legal basis (Article 6 GDPR) |
|---|---|
| Management of orders, payments, shipping, returns and support | Performance of a contract, Article 6(1)(b) |
| Tax, accounting and legal obligations (invoicing, warranties) | Legal obligation, Article 6(1)(c) |
| Sending newsletters and promotional communications | Consent, Article 6(1)(a) (withdrawable at any time) |
| Website security, fraud prevention and service improvement | Legitimate interest, Article 6(1)(f) |
Providing the data marked as required is mandatory for fulfilling the order; refusal prevents completion of the purchase. Providing data for marketing purposes is optional.
4. Recipients of data
Data may be disclosed, solely for the purposes stated above, to parties acting as data processors under Article 28 GDPR:
- Shopify International Ltd / Shopify Inc., e-commerce platform and store hosting;
- Shopify Payments / Stripe and PayPal, payment processing;
- couriers and logistics providers, shipping and delivery of orders;
- email/marketing service providers, the tax adviser/accountant and IT providers;
- public authorities, where required by law.
Data is neither publicly disclosed nor sold to third parties.
5. Transfers outside the EU
Some providers (particularly Shopify) may also process data in countries outside the EU (United States, Canada). Such transfers take place on the basis of appropriate safeguards pursuant to Articles 44 et seq. GDPR (European Commission Standard Contractual Clauses and/or participation in the EU-US Data Privacy Framework).
6. Retention period
- Order and invoicing data: 10 years from the conclusion of the contract (civil and tax obligations).
- Customer account data: until deletion is requested.
- Data for marketing purposes: until consent is withdrawn.
- Cookies: according to the periods stated in the Cookie Policy.
7. Rights of the data subject
As a data subject, under Articles 15-22 GDPR you have the right to obtain access to your data, its rectification or erasure, restriction of processing and data portability, to object to processing and to withdraw consent at any time (without affecting the lawfulness of prior processing). To exercise these rights, write to larosagioielli@gmail.com. You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
8. Minors
The Services are not intended for anyone under 18 and we do not knowingly collect data from minors. Any data concerning minors that is identified will be deleted.
9. Changes
The Data Controller reserves the right to update this policy; the current version is always published on this page with its update date.