Privacy Policy

Last updated: June 2026. This policy describes how Davide Cristofaro Limited processes the personal data of users of www.davidecristofaro.com, in accordance with Regulation (EU) 2016/679 (GDPR).

1. Data Controller

The Data Controller is Davide Cristofaro Limited, a company incorporated under English law (No. 09685798), with registered office at Unit 5, 399-405 Oxford Street, Mayfair, London, W1C 2BU, United Kingdom. For any request regarding your personal data, you can write to customercare@davidecristofaro.com.

2. What personal data we collect

Depending on how you use the site, we may process the following categories of data:

  • Contact and account data: first name, last name, email, password (encrypted) and, where applicable, phone number.
  • Optional profile data: the day and month of your birthday, if you choose to add them to your account to receive our wishes. We never collect the year of birth, and you can remove this from your profile at any time.
  • Order and billing data: shipping and billing address, products purchased and data needed to issue the invoice (including, if provided, tax code or VAT number).
  • Payment data: handled directly by the payment providers; we do not store full card numbers.
  • Communications: the content of the requests you send us (support, commissions, contact).
  • Browsing data and cookies: technical information collected through cookies and similar technologies (see the Cookie Policy).

3. Purposes and legal bases of processing

  • Performance of the contract (Art. 6.1.b GDPR): managing your account, orders, shipping, returns and support.
  • Legal obligations (Art. 6.1.c GDPR): issuing and retaining invoices, tax and customs compliance.
  • Consent (Art. 6.1.a GDPR): non-essential cookies and, if you subscribe, sending the newsletter. If you add the day and month of your birthday to your profile, we use them only to send you our wishes with a small thought reserved for you.
  • Legitimate interest (Art. 6.1.f GDPR): site security, fraud prevention, service improvement and post-purchase service communications (such as care advice for the piece you purchased).

4. Cookies and tracking technologies

The site uses necessary technical cookies and, subject to your consent, functionality, experience, measurement and marketing cookies. Details, management and withdrawal of consent are described in our Cookie Policy.

5. Data recipients and providers

To provide our services we rely on providers that process data on our behalf, as data processors, including:

  • Hosting and cloud infrastructure, CDN and media storage (e.g. Cloudflare).
  • Transactional email (e.g. Zoho).
  • Payment providers (e.g. Stripe, PayPal and the associated networks), which act as independent controllers for payment data.
  • Couriers and shipping carriers for order delivery.
  • Advisors, accountants and tax service providers for legal compliance.

Data is not disclosed or sold to third parties for marketing purposes without your consent.

6. Transfers of data outside the European Union

The Controller is based in the United Kingdom, which is subject to an adequacy decision by the European Commission. Some providers may process data outside the European Economic Area: in such cases the transfer is safeguarded by adequacy decisions or by Standard Contractual Clauses approved by the European Commission.

7. Retention period

  • Order and billing data: retained for the period required by tax and accounting obligations (generally 10 years).
  • Account data: until you request its deletion.
  • Cookie consent records: 24 months (see point 10).
  • Support communications: for the time needed to handle the request and subsequent obligations.

8. Your rights

As a data subject, you have the right to:

  • access your personal data and obtain a copy;
  • request its rectification or update;
  • request its erasure (“right to be forgotten”);
  • request the restriction of, or object to, processing;
  • receive your data in a portable format;
  • withdraw your consent at any time, without affecting processing already carried out;
  • lodge a complaint with the supervisory authority (in Italy, the Garante per la protezione dei dati personali).

9. How to exercise your rights

You can exercise your rights at any time by writing to customercare@davidecristofaro.com. We will respond within the timeframes set by applicable law.

10. Consent records

To demonstrate that we have validly obtained your cookie consent (Art. 7 GDPR), we keep a record of your choices: a consent identifier, the categories accepted, the date and time, the version of the notice, the language, the browser used and the IP address in encrypted form (never in clear text). This data is kept for 24 months and used solely as proof of consent.

11. Data security

We adopt appropriate technical and organisational measures to protect personal data against unauthorised access, loss or disclosure, including encryption of credentials, secure connections and restricted access to data.

12. Changes to this policy

We may update this policy to reflect regulatory or service changes. The updated version will always be available on this page, indicating the date of the last update.

13. The withdrawal register

13.1. What data we process: when you withdraw from the Site we record the name you confirm in the statement, the order number, the order email address (where we send the receipt), the items you are withdrawing from, the reason if you choose to give one (it is optional and may be left blank), the exact date and time of the statement, a hashed form of your IP address and the technical details of your browser. The IP address is never stored in clear text; the hash is still pseudonymised personal data, because we could link it back to you, and we treat it as such.

13.2. Why we process it and on what basis: receiving your statement and sending you the receipt is a legal obligation (Art. 6.1.c GDPR, Art. 54-bis of the Italian Consumer Code). The refund is performance of the contract (Art. 6.1.b GDPR). Keeping the record after the refund rests instead on our legitimate interest in establishing, exercising or defending legal claims (Art. 6.1.f and Art. 17.3.e GDPR). We do not ask for your consent: asking for consent to do something the law requires would not be fair to you.

13.3. How long we keep it: ten years from the date of the statement, matching the ordinary limitation period under Italian law (Art. 2946 of the Civil Code). Once that term expires, an automated routine irreversibly erases the name, email, reason, outcome note, IP hash and browser details: only the items, the dates and the outcome remain, and they can no longer be traced back to you. If you ask for erasure earlier, the identifying data in your profile are removed straight away while the withdrawal record is kept as evidence, with the email replaced by a non-personal identifier, until the term expires (Art. 17.3 GDPR). The related order and invoice are kept for ten years under tax law, as stated in point 7.

13.4. Who sees this data: the Controller and the customer care staff handling the case. The IP hash and the browser details do not even appear in the list of cases that customer care works from: they serve only as proof of where the statement came from.

13.5. Your rights: they remain the ones listed in point 8 and are exercised as described in point 9. In particular, you may object at any time to processing based on legitimate interest, explaining your situation: unless we have overriding grounds to keep the record, we will anonymise it before the term expires.

13.6. The receipt in our sent-mail archive: besides reaching your inbox, the receipt is also kept as a copy in our internal archive of sent messages. That copy is not touched by the automatic erasure described in point 13.3: it is kept for the same period as the order it relates to, as stated in point 7.