This Privacy Policy describes how Arte del Tempo S.r.l, registered at Via Gramsci 25, 43036 Fidenza (PR), VAT/Tax No. 02873970343 (hereinafter "Controller" or "we"), collects, uses and protects the personal data of users who visit our website and purchase our products, in accordance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended.
1. Data Controller
The Data Controller is Arte del Tempo S.r.l, with registered office at Via Gramsci 25, 43036 Fidenza (PR), VAT/Tax No. 02873970343. For any matter relating to the processing of your personal data you may contact us at rrubiniorologi+privacy@gmail.com or by post at the address above.
2. Data we collect
We collect the following categories of personal data:
2.1 Data provided directly by you
- First name, last name and email address for account creation and communications
- Phone number (optional, for customer support and order notifications)
- Shipping and billing address for order fulfilment
- Payment information: processed securely via Stripe Inc. — we do not store card data on our systems
- Trade-In service data: description and photos of the watch you wish to sell, availability for appointments
- Communications and notes entered during the purchase or contact process
2.2 Automatically collected data
- IP address, browser type, operating system and pages visited (for analytics and security purposes)
- Browsing data and preferences via cookies (see section 7)
3. Purpose and legal basis of processing
We process your personal data for the following purposes:
- Contract performance (Art. 6(1)(b) GDPR): order management, payment processing, shipping and after-sales support
- Contract performance: handling Trade-In requests and scheduling appointments
- Legal obligation (Art. 6(1)(c) GDPR): retention of invoices and tax/accounting compliance
- Legitimate interest (Art. 6(1)(f) GDPR): fraud prevention, site security, service improvement and aggregated data analysis
- Consent (Art. 6(1)(a) GDPR): sending marketing communications and newsletters (only with your explicit consent, which may be withdrawn at any time)
4. Data sharing
We never sell or transfer your personal data to third parties. We share only strictly necessary data with:
- Stripe Inc. (payment processing): payment data is transmitted directly to Stripe in encrypted form
- Couriers and shipping companies (e.g. GLS, Ferrari Corriere, FedEx): name, shipping address and phone for order delivery
- Cloud and hosting service providers (for secure data storage)
- Accountants and legal advisors (for tax and legal compliance, bound by confidentiality)
- Public authorities and law enforcement: only when required by law or by order of the authority
5. International data transfers
Some of our service providers (e.g. Stripe, cloud providers) may process data outside the European Economic Area (EEA). In such cases we ensure that transfers comply with the GDPR, through EU Standard Contractual Clauses or other adequacy mechanisms provided by law.
6. Data retention
We retain your data for the following periods:
- Order and billing data: 10 years from the date of the order (mandatory under Italian tax law)
- Account data: for the duration of the relationship and 2 years after account closure
- Marketing/newsletter data: until consent is withdrawn
- Navigation data and security logs: 12 months
- Data relating to incomplete Trade-In requests: 6 months from the request
7. Cookies and tracking technologies
The site currently uses only technical/essential cookies, which are necessary for the correct functioning of the site (e.g. shopping cart, authentication session). These cookies do not require your consent as they are essential to the provision of the service. We do not use analytical, profiling or third-party marketing cookies. Should we introduce additional types of cookies in the future, this Policy will be updated and your consent will be requested where required by law.
You can manage cookie preferences through your browser settings.
8. Data security
We adopt appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, alteration or disclosure. The site uses encrypted connections (HTTPS/TLS). Payment data is never stored on our servers: the payment process takes place entirely on Stripe's secure platform, which is PCI DSS certified.
9. Your rights
Under Arts. 15–22 GDPR, you have the right to:
- Access (Art. 15): obtain confirmation whether we are processing your data and receive a copy
- Rectification (Art. 16): correct inaccurate or incomplete data
- Erasure / right to be forgotten (Art. 17): request deletion of your data, except where legal retention obligations apply
- Restriction of processing (Art. 18): in certain circumstances, request suspension of processing
- Data portability (Art. 20): receive your data in a structured, machine-readable format
- Objection (Art. 21): object to processing based on legitimate interest or for direct marketing purposes
- Withdrawal of consent: withdraw consent at any time without affecting the lawfulness of prior processing
To exercise your rights write to rrubiniorologi+privacy@gmail.com. We will respond within 30 days of receiving your request.
Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali), Piazza Venezia 11 — 00187 Rome, website: www.garanteprivacy.it, if you believe that the processing of your data violates the GDPR.
10. Contact
For any questions regarding this Privacy Policy, to exercise your rights, or for any other data protection matter, please contact us:
- Email: rrubiniorologi+privacy@gmail.com
- Postal address: Arte del Tempo S.r.l, Via Gramsci 25, 43036 Fidenza (PR)
We reserve the right to update this Policy. Any material changes will be communicated via a notice on the site or by email. The date of the last modification is shown at the top of the page.