Privacy Policy
Controller
The controller is Mair Mair Srl, represented by CEO Monika Moser Mair. Email: [email protected]. Tel.: +39 0472 765386.
No data protection officer has been appointed.
Scope and technical platform
This privacy policy applies to our online shop. The storefront is based on Next.js. Product, cart, customer, order and checkout functions are processed through MedusaJS; editorial content and legal texts are provided through Payload.
Purposes, categories of data and legal bases
Shop, orders and customer account: We process identification, contact, contract, payment, communication and logistics data to take pre-contractual steps, perform the contract and comply with legal obligations. The legal bases are Article 6(1)(b) and (c) GDPR.
Customer service and communication: If you contact us by form or email, we process the contact details and message content provided, timestamps and, where applicable, the related case history. The legal bases are Article 6(1)(b) or (f) GDPR.
Payments: If you select Stripe or PayPal, the data required for payment processing, checks and fraud prevention is transferred to the selected payment service. The payment services largely act as independent controllers under their own privacy notices. The legal bases are Article 6(1)(b) and (c) GDPR and, for fraud prevention, Article 6(1)(f) GDPR.
Shipping and logistics: For delivery, we transfer your name, address, contact details and parcel information to the carrier used, in particular DHL, UPS, DPD or TNT. Omest GmbH in Bolzano supports fulfilment. The legal basis is Article 6(1)(b) GDPR.
Technical operation and security: When you access the online shop, technically necessary connection and log data is processed, in particular your IP address, time of access, requested page and browser and device information. This is used to provide a secure, stable and error-free service. The legal basis is Article 6(1)(f) GDPR.
Newsletter: We use Brevo to send the newsletter. We process the email address, consent status and, if enabled, opening and click data. The legal basis is Article 6(1)(a) GDPR. Consent can be withdrawn at any time with effect for the future.
Web analytics and advertising: If you have given your consent, we use Google Analytics 4 and Google Ads functions to measure reach, analyse use of our services and measure or optimise our advertising. Depending on the settings enabled, Google Signals and personalised advertising functions may also be used. The legal basis is Article 6(1)(a) GDPR.
Cookies and consent management
We use our own consent management system. You can decide which optional services may be activated. In particular, the selected categories, time of the decision, consent version used and a pseudonymous identifier are stored as evidence of consent. Statistics and marketing services are only activated after the corresponding consent has been given. Consent can be withdrawn or changed at any time through the cookie settings.
Technically necessary cookies and similar storage mechanisms are used for purposes including sign-in, the shopping cart, language, market, security and storage of your consent choices.
Social media profiles
Our pages may link to public profiles on social networks. The terms and privacy notices of the relevant platform only apply when you visit it; the respective provider independently processes data generated on that platform.
Recipients and categories of recipients
Depending on how the shop is used, recipients may include payment services, carriers and fulfilment providers, IT and hosting providers, Brevo for the newsletter and Google for analytics and advertising services. Data is only disclosed where necessary for the relevant purpose or where consent has been given.
Transfers to third countries
Where individual service providers transfer data to countries outside the European Economic Area, in particular the United States, this is carried out in accordance with Articles 44 et seq. GDPR, for example on the basis of an adequacy decision or appropriate safeguards such as standard contractual clauses.
Retention periods
We retain personal data only for as long as required for the relevant purpose or by statutory retention obligations. Commercial and tax records may generally be retained for up to ten years. Server access logs are generally deleted or anonymised after seven days, and support and contact requests after no more than twelve months. Newsletter data is retained until consent is withdrawn.
Your rights
Subject to the statutory requirements, you have rights of access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent at any time with effect for the future.
You may lodge a complaint with the Italian Garante per la protezione dei dati personali at www.garanteprivacy.it or with the data protection supervisory authority responsible for your place of residence.
Minors and automated decisions
Our services are not directed at minors. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
Security
We use appropriate technical and organisational measures to protect personal data. Data transmitted between your browser and our online shop is encrypted using TLS/HTTPS.
Changes
We update this privacy policy when required by legal, technical or organisational changes.