Privacy Policy
Privacy Policy of www.giordano.photo
Last updated: September 2026 - Ref. Legislative Decree 196/2003
1. Data Controller
The Data Controller of personal data is:
Skyrover S.r.l.s.
Registered office: 5° Trav. Viale Italia, 4 – 70032 Bitonto (BA)
VAT / Tax ID: 08994720723
Email: skyroversrls@gmail.com
Certified Email (PEC): skyrover@pec.it
2. Types of data processed
The website collects, directly or through third parties, the following categories of personal data:
- identifying data (first name, last name);
- contact data (email, phone number);
- billing and shipping data (address, postal code, city, province, country);
- tax data (tax code, VAT number, company name, if provided);
- data related to orders and payments;
- browsing and website usage data;
- cookies and tracking tools, as indicated in the Cookie Policy.
Data may be provided voluntarily by the user or collected automatically during browsing.
3. Purposes of processing
Personal data are processed for the following purposes:
- management of orders, payments and shipments;
- creation and management of the user account;
- fulfilment of contractual, tax and legal obligations;
- customer support and handling of requests;
- sending informative communications related to orders;
- sending promotional communications and newsletters, with prior consent;
- statistical analysis and improvement of the user experience;
- website security and prevention of abuse or fraud.
4. Legal basis for processing
Data processing is based on one or more of the following legal bases:
- performance of a contract or of pre-contractual measures;
- fulfilment of legal obligations;
- explicit consent of the user;
- legitimate interest of the Data Controller (security, website management, direct marketing within the permitted limits).
5. Methods of processing
Data processing is carried out using IT and electronic tools, with security measures adequate to guarantee the confidentiality, integrity and availability of information, in compliance with Regulation (EU) 2016/679 (GDPR).
6. Communication and recipients of data
Personal data may be communicated to third parties acting as data processors or independent controllers, such as:
- e-commerce platform and hosting (Shopify);
- infrastructure and data storage services (Cloudflare);
- payment providers (e.g. PayPal, HeyLight);
- couriers and logistics operators;
- IT service providers and technical support;
- email marketing service providers, with prior consent.
7. Transfer of data outside the EU
Some service providers may process data in countries outside the European Union. In such cases, the transfer takes place in compliance with Articles 44 et seq. of the GDPR, through appropriate safeguards, such as adequacy decisions or standard contractual clauses.
8. Data retention
Personal data are retained for the time necessary to achieve the purposes for which they were collected and, in any case, in compliance with legal obligations. Data processed for marketing purposes are retained until consent is withdrawn.
9. User rights
The user may exercise at any time the rights provided for by Articles 15 et seq. of the GDPR, including:
- access to personal data;
- rectification or erasure;
- restriction of or objection to processing;
- data portability;
- withdrawal of consent;
- lodging a complaint with the Garante per la protezione dei dati personali (Italian Data Protection Authority).
Requests can be sent to: skyroversrls@gmail.com
10. Price reports
Product pages include a box ("Found a better price?") that allows users to report a cheaper offer found on another website, so that the Data Controller can assess whether to match it.
The following data are collected through this form:
- name, email address and, if the user chooses to provide it, phone number;
- the link to the reported offer and any notes written by the user;
- the product from which the report was sent, with the date and time of submission.
The user's IP address is not stored: only an encrypted fingerprint is recorded, from which the original address cannot be traced and which is used solely to prevent the automated submission of fake reports.
The legal basis for the processing is the performance of pre-contractual measures taken at the request of the data subject (Art. 6.1.b GDPR), since this is a response requested by the user; the IP address fingerprint is instead based on the legitimate interest of the Data Controller in protecting the form from abuse (Art. 6.1.f GDPR). The data collected through this box are not used for marketing purposes and are not disclosed to third parties.
Reports are kept for six months from submission, after which they are automatically deleted. They are stored with Cloudflare, Inc., acting as data processor, in a database bound to the jurisdiction of the European Union.
The rights listed in point 9 remain unaffected and can be exercised by writing to skyroversrls@gmail.com.
11. Cookies
The website uses technical cookies and, with prior consent, profiling and third-party cookies. For more information, please consult the dedicated Cookie Policy.
12. Changes to this policy
The Data Controller reserves the right to modify this Privacy Policy at any time. Changes will be published on this page with an indication of the update date.
