Privacy policy

PRIVACY POLICY

This policy describes how Saturnino69 S.r.l. processes the personal data of those who visit the website www.saturninoeyewear.com, create a customer account, make purchases, or subscribe to the newsletter, in accordance with Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree No. 196 of June 30, 2003, as amended by Italian Legislative Decree No. 101 of August 10, 2018 (“Privacy Code”). For data collected through cookies and other tracking tools, please refer to the Site's Cookie Policy.

1. Data Controller

The Data Controller is Saturnino69 S.r.l., with registered office at Via Maurizio Gonzaga 5, 20123 Milan, Tax Code and VAT No. IT08573630962 (the “Data Controller”).

For any matter relating to the processing of personal data and for the exercise of the rights described in Section 9, the Data Subject may contact the Data Controller:

·        by email at privacy@saturninoeyewear.com;

·        by mail, to the address of the registered office indicated above;

·        by phone, at +39 02.78622340.

The Data Controller has not appointed a Data Protection Officer (DPO).

2. Categories of personal data processed

Depending on the methods of interaction with the Site, the Data Controller processes the following categories of data:

·        Identifying and contact data: first name, last name, email address, telephone number, shipping address, and billing address.

·        Tax data: tax code or VAT number and any additional data necessary for issuing the invoice, where required.

·        Order data: products purchased, amounts, order date and status, returns, refunds, exercise of the right of withdrawal, and warranty support requests.

·        Payment data: payment method used, outcome and identifier of the transaction, card network and last digits of the card. The Data Controller does not collect or store the complete payment card details, which are processed directly by the payment service providers.

·        Account data: email address used for login, saved addresses, and order history. Access to the account is via a one-time code sent to the user's email address; there is no provision for creating a password.

·        Newsletter data: email address, date, time, and method of giving and withdrawing consent

·        Data relating to promotional communications to customers: email address provided at the time of purchase, products purchased, date and method of any objection.

·        Content of communications: data contained in requests sent to the Data Controller by email, telephone, or through the contact channels on the Site.

·        Browsing data: IP address, type of device and browser, operating system, date and time of access, pages visited, and other technical parameters acquired by the IT systems during the normal operation of the Site.

The Data Controller does not request or process special categories of personal data. The Data Subject is asked not to include such data in communications sent to the Data Controller.

3. Data sources

The data are collected directly from the data subject at the time of registration, purchase, subscription to the newsletter or submission of a request, as well as automatically while browsing the Site.

Some data are also received from third parties:

·        from payment service providers (Shopify Payments, PayPal, Klarna): transaction outcome and information on the fraud risk associated with the order;

·        from the Shopify platform: fraud risk indicators relating to the order;

·        from Shopify, if the Shop Pay service is used: identification, contact, shipping and billing data necessary to fulfill the order.

4. Purposes, legal bases, and nature of the data provision

Purposes

Legal basis

Nature of the data provision

a) Creation and management of the customer account.

Performance of a contract to which the Data Subject is a party (Article 6, paragraph 1, letter b) of the GDPR).

Optional. Failure to provide data prevents the creation of an account but not the purchase without registration.

b) Conclusion and execution of the sales contract: management of the order, payment, shipping, returns, the right of withdrawal, and the legal guarantee of conformity; sending of service communications relating to the order.

Performance of a contract or pre-contractual measures taken at the request of the data subject (Article 6, paragraph 1, letter b) of the GDPR).

Required. Failure to provide data prevents the conclusion and execution of the contract.

c) Compliance with legal obligations, particularly in tax and accounting matters, and with measures imposed by authorities.

Legal obligation (Article 6, paragraph 1, letter c) of the GDPR).

Required. Failure to provide data prevents the conclusion of the contract.

d) Responding to requests for information and assistance.

Performance of a contract or pre-contractual measures (Article 6, paragraph 1, letter b) of the GDPR); in other cases, the Data Controller's legitimate interest in responding to requests received (Article 6, paragraph 1, letter f) of the GDPR).

Optional. Failure to provide data prevents the request from being fulfilled.

e) Fraud prevention and security of the Site and payments.

The Data Controller's legitimate interest in preventing payment fraud and unlawful use of the Website and in ensuring the security of IT systems (Article 6, par. 1, letter f) of the GDPR; Recitals 47 and 49).

Processing related to the purchase. The Data Subject may object pursuant to Article 21 of the GDPR (para. 9).

f) Sending the newsletter and promotional communications by email relating to the Data Controller's products.

Consent of the Data Subject (Article 6, paragraph 1, point a) of the GDPR; Article 130, paragraphs 1 and 2, of the Privacy Code).

Optional. Failure to provide consent does not affect the purchase. Consent may be withdrawn at any time.

f-bis) Sending promotional emails to customers who have made a purchase, concerning Data Controller products similar to those purchased, to the email address provided at the time of purchase.

The Data Controller's legitimate interest in promoting products similar to those purchased to its customers (Article 6, par. 1, letter f) of the GDPR; Recital 47; Article 130, paragraph 4, of the Privacy Code).

The email address is required for the purchase (point b). The Data Subject may object to the sending of promotional communications at the time of purchase, by using the appropriate option at checkout, and on the occasion of each communication, without any prejudice to the purchase.

g) Establishment, exercise or defense of a right in judicial or extrajudicial proceedings.

Legitimate interest of the Data Controller in protecting its rights (Article 6, par. 1, letter f) of the GDPR).

—

 

Subscription to the newsletter is optional, and the purchase of products is not contingent upon it. Promotional communications are sent to those who have given their consent or, in the absence of consent, to customers who have not objected; each communication contains a link to withdraw consent or to object.

5. Processing methods and automated decision-making processes

The data are processed using electronic tools, in compliance with the principles set out in Article 5 of the GDPR and with appropriate technical and organizational measures to ensure a level of security commensurate with the risk. Only personnel authorized and instructed by the Data Controller have access to the processing.

The Data Controller does not engage in profiling activities and does not make decisions based solely on automated processing that produce legal effects concerning the data subject or that similarly significantly affect them. Orders flagged by the platform as being at risk of fraud are reviewed by the Data Controller's staff before any cancellation.

6. Recipients of the data

For the purposes indicated in paragraph 4, the data may be disclosed to the following categories of recipients:

Data Processors

·        Shopify International Limited (Ireland), provider of the e-commerce platform, the related hosting services, and the service for sending newsletters and promotional communications (Shopify Email);

·        providers of IT services, technical support and logistics services;

·        consultants and professionals in the accounting, tax, and legal fields, who act as Data Processors or as independent Data Controllers depending on the activity performed.

Independent Data Controllers

·        Payment service providers: providers that carry out transactions through Shopify Payments; PayPal (Europe) S.à r.l. et Cie, S.C.A.; Klarna Bank AB, which, if a deferred payment is chosen, may carry out creditworthiness checks. Each provider processes the data according to its own policy;

·        Shopify, limited to the Shop Pay service, if the data subject chooses to use it: data relating to the Shop Pay account are processed by Shopify in accordance with its own privacy policy;

·        Couriers and freight forwarders responsible for delivery;

·        tax authorities, customs authorities, judicial authorities and other public authorities, in the cases provided for by law.

The updated list of data processors is available upon request at privacy@saturninoeyewear.com. Personal data are not disclosed.

7. Transfer of data to third countries

Some processing operations involve the transfer of personal data outside the European Economic Area (EEA), with the following safeguards:

·        Shopify platform: The data are processed by Shopify International Limited (Ireland) and transferred to the parent company Shopify Inc. (Canada) on the basis of the European Commission's adequacy decision concerning Canada (Decision 2002/2/EC). Further transfers to Shopify sub-processors established in third countries, including the United States, take place on the basis of the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.

·        Shipments to the United Kingdom: The data necessary for delivery and customs formalities are communicated on the basis of the European Commission's adequacy decision concerning the United Kingdom, renewed on December 19, 2025.

·        Shipments to other third countries: The transfer of data necessary for delivery and customs formalities is necessary for the performance of the contract concluded with the data subject.

Payment service providers operating as independent data controllers manage any transfers in accordance with their respective policies.

8. Retention period

Data category / purpose

Retention period

Account data (par. 4, letter a)

Until the request to delete the account or, in the event of inactivity, for 24 months from the last login. This is without prejudice to the terms established for order-related data.

Data relating to orders and accounting and tax documentation (par. 4, letters b and c)

10 years from the date of the last entry (Article 2220 of the Italian Civil Code).

Requests for information and assistance not related to an order (par. 4, letter d)

24 months from the closure of the request.

Data processed for fraud prevention (par. 4, letter e)

For the time necessary to verify the order; in the event of confirmed fraud or a dispute, until the dispute is resolved.

Newsletter (par. 4, letter f)

Until consent is withdrawn.

Promotional communications to customers (par. 4, letter f-bis)

Until the data subject objects and, in any case, no later than 24 months from the last purchase. This is without prejudice to the time limits established for order-related data.

Protection of rights in judicial or extrajudicial proceedings (par. 4, letter g)

For the duration of the dispute and until the expiration of the appeal periods.

Browsing data

As indicated in the Cookie Policy.

 

Once the indicated time limits have elapsed, the data are deleted or irreversibly anonymized.

9. Rights of the Data Subject

The data subject may exercise the following rights at any time, within the limits and under the conditions provided for in Articles 15 et seq. of the GDPR:

·        access to personal data and information on their processing;

·        rectification of inaccurate data and completion of incomplete data;

·        erasure of data;

·        restriction of processing;

·        portability of the data provided to the Data Controller, for processing based on contract or consent and carried out by automated means;

·        withdrawal of consent at any time, without prejudice to the lawfulness of the processing based on the consent given prior to the withdrawal.

Right to object

The data subject has the right to object at any time to processing based on the Data Controller's legitimate interest.

The Data Subject also has the right to object at any time, without the need to provide a reason, to the processing of data for direct marketing purposes, including promotional communications sent to customers who have made a purchase (Paragraph 4, letter f-bis). This right may be exercised at the time of purchase, by using the specific option available at checkout, as well as by using the unsubscribe link included in each promotional communication or by writing to privacy@saturninoeyewear.com. Following the objection, the data will no longer be processed for this purpose.

The Data Controller shall respond without undue delay and, in any case, within one month of receiving the request. If there are reasonable doubts about the identity of the Data Subject, the Data Controller may request the information necessary to confirm it.

10. Complaints and appeals

Data subjects who believe that the processing of their data violates the GDPR have the right to lodge a complaint with the Italian Data Protection Authority, without prejudice to their right to appeal to the judicial authorities.

11. Minors

Subscription to the newsletter is reserved for those who are at least 14 years of age. If the Data Controller becomes aware of data collected for this purpose relating to children under the age of 14 without the consent of the person exercising parental responsibility, the Data Controller shall delete such data.

12. Changes to the Privacy Policy

The Data Controller may amend this policy, including as a result of regulatory or organizational changes. Substantial changes will be brought to the attention of data subjects in an appropriate manner.