Privacy Policy

Last Updated: December 11, 2025

1. Data Controller

The Data Controller is BEAUTY DEF S.R.L., registered office at Viale Montello 7, 20154 Milan (MI), Italy, VAT ID 08968280969.
For any clarification, contact us at: [email protected].

2. Types of Data Collected

We collect various types of personal data:
- Navigation data: IP addresses, access times, and other technical parameters.
- Voluntarily provided data: name, email, phone, shipping address (for purchases or inquiries).
- Cookies: see our Cookie Policy details.

3. Purpose and Legal Basis of Processing

Your data is processed for the following purposes:
- Service execution: to manage orders, requests, and customer support (Legal basis: Contract performance).
- Legal obligations: invoicing, accounting (Legal basis: Legal obligation).
- Marketing (optional): sending newsletters and promotions, only with your explicit consent (Legal basis: Consent).

4. Processing Methods and Place

Processing is carried out using IT and/or telematic tools, with organizational methods strictly related to the indicated purposes. Data is processed at the Controller's operating offices and in any other places where the parties involved in the processing are located (within the EU).

5. Retention Period

Data is processed and stored for the time required by the purposes for which it was collected.
- Data for contractual purposes is retained for 10 years (tax obligations).
- Data for marketing purposes is retained until consent is revoked.

6. User Rights (Arts. 15-22 GDPR)

As a data subject, you have the right to:
- Request access to your personal data.
- Obtain rectification or erasure of data (Right to be forgotten).
- Restrict processing concerning you.
- Object to processing.
- Request data portability.
- Withdraw consent at any time.

To exercise these rights, write to [email protected].

7. Complaint to Supervisory Authority

You have the right to lodge a complaint with a supervisory authority (In Italy: Garante per la protezione dei dati personali, www.garanteprivacy.it) if you believe the processing violates the GDPR.