This is a courtesy translation. In case of any discrepancy, the Italian version prevails.
This notice describes how the personal data of users who visit the shoprfid.it website is processed, in accordance with EU Regulation 2016/679 (General Data Protection Regulation, GDPR) and applicable Italian law.
1. Data controller
The data controller is Deyob srl, with registered and operational office at Viale Dell'Industria 77, 36015 Schio (VI), Italy, VAT no. 03954470245.
Email: [email protected] — Tel: +39 0445 1716784
2. Types of data collected
The personal data collected by this website includes:
- Browsing data: IP address, browser type, pages visited, time of access.
- Contact data: name, email, phone number and company, when provided through the contact form, newsletter sign-up, quote requests or orders.
- Payment data: handled directly by Stripe and PayPal. We do not store credit card data on our servers.
- Purchase data: order history, shipping and billing addresses.
3. Purposes of processing
Data is processed for the following purposes:
- Managing orders, shipping and invoicing (legal basis: performance of a contract);
- Responding to contact and quote requests (legal basis: legitimate interest);
- Sending newsletters and marketing communications (legal basis: consent);
- Complying with legal, accounting and tax obligations (legal basis: legal obligation);
- Improving the website through anonymous statistical analysis (legal basis: legitimate interest).
4. How data is processed
Data is processed using computer and/or online tools, within the scope of the purposes stated above. Appropriate security measures are in place to prevent unauthorised access, loss or destruction of data.
5. Disclosure of data
Data may be disclosed to third parties appointed as data processors, such as:
- Stripe (payment processing)
- PayPal (payment processing)
- Brevo (transactional emails and newsletters)
- Neon.tech (database hosting)
- Vercel (website hosting)
- Couriers (for shipping orders)
- Tax and business advisers (for statutory obligations)
Data is not sold to third parties for their own commercial purposes.
6. Transfers of data outside the EU
Some providers (e.g. Stripe, Vercel) may transfer data to countries outside the EU. In that case, the transfer is based on standard contractual clauses approved by the European Commission or on other legal bases that comply with the GDPR.
7. Data retention
Data is kept only for as long as strictly necessary to fulfil the purposes stated above, and in any case:
- Order and invoicing data: 10 years (required by law)
- Newsletter data: until consent is withdrawn (unsubscribing takes effect immediately)
- Contact data: up to 24 months if you do not become a customer
8. Your rights as a data subject
Under the GDPR, you have the right to:
- Access your personal data;
- Request its rectification or erasure;
- Restrict or object to its processing;
- Receive your data in a structured format (data portability);
- Withdraw your consent at any time;
- Lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it).
To exercise your rights, write to [email protected].
9. Changes to this privacy policy
This notice may be updated from time to time. Material changes will be communicated by email to registered users.