Privacy Policy (GDPR)
Data Controller
DSGN® S.R.L.
Share Capital: €10,000 fully paid
VAT No.: IT 04683470407
Registered Office: Via XX Settembre 37, 47030 San Mauro Pascoli (FC), Italy
REA FO-432368 | SDI Code: M5UXCR1
Email: hello@dsgn.cc
Data Protection Officer (DPO)
The Data Controller has not appointed a Data Protection Officer, as it is not required pursuant to Article 37 of Regulation (EU) 2016/679. Users may contact the Data Controller directly for any privacy-related request.
Definitions
GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
Personal Data (or Data): Any information that, directly or indirectly, even in connection with any other information, including a personal identification number, allows the identification or identifiability of a natural person. By way of example and not limitation: name, surname, address, telephone number, email address, IP address.
User: The individual using this Website who, unless otherwise specified, coincides with the Data Subject.
Data Processor (or Processor): The natural or legal person, public authority or any other body which processes personal data on behalf of the Data Controller, as described in this Privacy Policy.
Website or Site: https://www.dsgngroup.it
Services: The services provided by this Website.
European Union: Unless otherwise specified, any reference to the European Union includes all current Member States of the European Union and the European Economic Area (EEA).
Cookies: Small portions of data stored within the User’s device and collected during navigation.
DSGN® S.R.L., in its capacity as Data Controller, informs Users pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the methods and purposes of processing Personal Data.
1. Scope of Processing
The Data Controller processes common Personal Data (Article 6 GDPR) voluntarily provided by the User when:
- registering on the Controller’s websites;
- filling in contact forms or newsletter subscription forms;
- submitting requests for information or support;
- browsing the Website;
- placing orders and requesting shipment of purchased items;
- accessing restricted areas or user accounts.
Complete details on each type of data collected are provided in the relevant sections of this Privacy Policy or through specific information notices displayed prior to data collection.
2. Purposes of Processing and Legal Basis
Personal Data are processed for the following purposes:
A) Without the User’s explicit consent (Article 6(1)(b), (c), (f) GDPR)
- To allow the User to access and use the Services;
- To take pre-contractual steps at the User’s request and to perform contractual obligations;
- To process contact or information requests;
- To comply with legal obligations, regulations, EU law or orders from authorities;
- To exercise the Data Controller’s rights, including the management of disputes during the data retention period.
B) Only with the User’s specific and explicit consent (Article 6(1)(a) GDPR)
- To send emails, newsletters, commercial communications and promotional material;
- To carry out commercial profiling activities;
- To manage access to WooCommerce accounts;
- To manage access to restricted areas for file and document exchange;
- To process orders, payments and shipments.
3. Services and Processing Tools
During its activities, the Data Controller processes Personal Data using the following services:
Contact Management and Messaging
These services manage databases of email or other contact details used to communicate with Users and may collect interaction data (e.g. message opening, link clicks).
**Mailchimp – The Rocket Science Group LLC
Collected Data: name, surname, email address
Place of Processing: United States
Data transfers are carried out on the basis of Standard Contractual Clauses approved by the European Commission and, where applicable, the EU–US Data Privacy Framework.
Interaction with Social Networks
These services enable interaction with social networks directly from this Website. Data collected are subject to the User’s privacy settings on each platform.
Facebook Like Button and Social Widgets (Meta Platforms, Inc.)
Collected Data: Cookies, Usage Data
Place of Processing: United States
Anti-Spam Protection
Akismet – Automattic Inc.
Collected Data: Various types of data as specified in the service’s privacy policy
Place of Processing: United States
Statistics and Analytics
**Google Analytics (GA4) – Google LLC / Google Ireland Limited
Collected Data: Cookies, Usage Data
Purpose: Monitoring and analyzing traffic and user behavior
IP anonymization is enabled. Data collection is activated only upon User consent through a consent management platform (CMP). Data retention is configured in accordance with GDPR principles.
Place of Processing: European Union and United States, based on Standard Contractual Clauses and/or adequacy decisions.
4. Consequences of Refusal to Provide Data
Failure to provide data required for service-related purposes will make it impossible for the Data Controller to provide the requested Services. Refusal to consent to optional purposes will not affect access to basic Services.
Users are responsible for any Personal Data of third parties shared through the Website and guarantee they have the right to communicate such data.
5. Processing Methods and Data Access
Data are processed using electronic and IT tools, with organizational and logical measures strictly related to the stated purposes.
Access to data may be granted to authorized internal personnel and to external parties (e.g. hosting providers, IT companies, couriers, marketing agencies) appointed as Data Processors when necessary.
The updated list of Data Processors can be requested at: hello@dsgn.cc
6. Data Retention Period
Personal Data are retained for the time strictly necessary to achieve the purposes for which they were collected:
- Contract-related data: for the duration of the contract and as required by applicable laws;
- Legitimate interest data: until the interest is fulfilled;
- Consent-based data: until consent is withdrawn;
- Legal obligations: as required by law or authority orders.
After the retention period expires, Personal Data will be deleted.
7. Data Security
The Data Controller adopts appropriate technical and organizational measures pursuant to Article 32 GDPR, including SSL/HTTPS encrypted transmission protocols, to protect Personal Data against loss, misuse or unauthorized access.
8. Data Transfers Outside the EU
Personal Data are primarily processed within the European Union. Where data transfers outside the EU or EEA are necessary, such transfers are carried out in compliance with Articles 44–49 GDPR, based on:
- adequacy decisions adopted by the European Commission;
- Standard Contractual Clauses (SCCs);
- the EU–US Data Privacy Framework, where applicable.
Appropriate technical and organizational measures are adopted to ensure an adequate level of protection.
9. Profiling
The Data Controller may process usage data to create or update User profiles for statistical and marketing purposes, aimed at improving services and communications.
Profiling activities do not produce legal effects or similarly significant effects on Users pursuant to Article 22 GDPR. Users may object to profiling at any time by contacting the Data Controller.
10. User Rights
Users have the right to:
- withdraw consent at any time;
- object to processing;
- access their data;
- request rectification or updating;
- request restriction of processing;
- request erasure of data;
- receive their data in a structured, commonly used and machine-readable format and request data portability;
- lodge a complaint with the competent supervisory authority, in particular the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
11. Exercise of Rights
Users may exercise their rights by:
- sending a registered letter to: DSGN® S.R.L., Via XX Settembre 37, 47030 San Mauro Pascoli (FC), Italy;
- sending an email to: hello@dsgn.cc
12. Minors
This Website and its Services are not intended for individuals under 18 years of age. The Data Controller does not knowingly collect Personal Data relating to minors.
13. Changes to this Privacy Policy
The Data Controller reserves the right to modify this Privacy Policy at any time. Material changes will be communicated to Users where technically and legally feasible, including through the Website or direct contact for registered Users.
Last updated: 12th December 2025
