Last updated: January 2025
The Data Controller is Gaucheando — P.IVA IT03051070427 — Via Martiri della Resistenza 58, 60125 Ancona AN, Italia. For privacy-related requests: [email protected]
Full name, email, phone, shipping address, order history. Payment data is processed by Nexi S.p.A. (PCI-DSS certified) — we do not store card details. Navigation data (IP, browser type) is collected via strictly necessary cookies only.
Gaucheando does not collect or process special categories of personal data as defined by Art. 9 GDPR (health data, racial or ethnic origin, religious beliefs, biometric data, genetic data, political opinions, sexual orientation). If a customer voluntarily provides dietary preferences (e.g. allergies) in order notes, this information is used solely to fulfil the order and is not retained beyond the order lifecycle.
• Contract execution (Art. 6.1.b GDPR): order processing, shipping, returns, refunds. • Legal obligation (Art. 6.1.c GDPR): fiscal/accounting record retention for 10 years under Italian tax law. • Legitimate interest (Art. 6.1.f GDPR): fraud prevention, system security, legal defence. • Consent (Art. 6.1.a GDPR): marketing communications, if explicitly opted in.
Fiscal records: 10 years. Account/order data: until account deletion plus 6 months. Navigation data: 12 months. Support emails: 2 years from closure.
Data processors (Art. 28 GDPR): Sendcloud B.V. (shipping), Nexi S.p.A. (payments), Cloudinary Ltd. (images), shipping carriers (DHL, GLS, BRT, Poste Italiane), Oracle Cloud Infrastructure (hosting). No data is transferred outside the EEA without adequate safeguards (adequacy decisions or Standard Contractual Clauses).
Where service providers process data outside the EU/EEA, we ensure transfers are covered by an EU adequacy decision (Art. 45 GDPR) or Standard Contractual Clauses (Art. 46.2.c GDPR). Details available at [email protected].
Gaucheando does not make decisions based solely on automated processing that produce legal or similarly significant effects. No user profiling for advertising or credit assessment is performed.
We implement appropriate technical and organisational measures (Art. 32 GDPR): HTTPS/TLS encryption, Argon2id password hashing, HttpOnly Secure authentication cookies, access controls, encrypted backups. In the event of a data breach posing risk to individuals, we will notify the Italian DPA within 72 hours (Art. 33 GDPR) and affected individuals where required (Art. 34 GDPR).
This site is intended for users aged 16 and over. We do not knowingly collect data from children under 16. Contact [email protected] if you believe a minor has provided personal data.
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), withdrawal of consent (Art. 7). Contact: [email protected] — response within 30 days. You may lodge a complaint with the Italian Data Protection Authority: www.garanteprivacy.it
See our Cookie Policy for full details.
We may update this policy periodically. The date above reflects the latest version. Significant changes will be communicated to registered users by email.