Privacy policy

PRIVACY POLICY

pursuant to Articles 13 and 14 of EU Regulation 2016/679

Website notoriousbrand.it

Last updated: June 3, 2026

This Privacy Policy is provided pursuant to Articles 13 and 14 of EU Regulation 2016/679 (“GDPR”) and describes how the personal data of users who access, browse, and purchase products through the website https://notoriousbrand.it/ (hereinafter also “Site” or “Platform”) is processed.

The Data Controller is:

NOTORIOUS DI A.G.S.

VAT Number: 05778780287

Registered office: Via G. Mazzini, 53, 35030 Rubano, PD, Italy

Contact e-mail: help@notoriousbrand.it

The Controller informs that users’ personal data will be processed using manual, electronic, IT, and telematic tools, following logic strictly related to the purposes indicated in this policy and, in any case, in a manner that ensures the security, confidentiality, integrity, and availability of personal data.

1. Nature of the Data Processed

1.1 Identification and Contact Data

Browsing the Site, registering an account, sending requests via contact forms, and purchasing products may involve the processing of data suitable for directly or indirectly identifying a natural person.

By way of example, the Controller may process: first and last name; e-mail address; telephone number; shipping address; billing address; city, postal code, province, country; tax code and/or VAT number, where necessary for tax or invoicing purposes; data relating to orders placed; data relating to returns, refunds, complaints, and customer service; any data voluntarily entered by the user in communications sent to the Controller.

The Site does not require users to provide data belonging to the special categories referred to in Article 9 GDPR, such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, or data concerning health, sex life, or sexual orientation.

Should the user voluntarily disclose such data through messages, requests, or communications sent to the Controller, the Controller may delete it, where not necessary, or process it solely to the extent indispensable to handle the user’s request and in compliance with applicable law.

1.2 Browsing Data

The computer systems and software procedures used to operate the Site acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.

This category includes, by way of example: IP addresses; domain names of the devices used by users; URI/URL addresses of the requested resources; time of the request; method used to submit the request to the server; size of the file obtained in response; numerical code indicating the status of the server’s response; parameters relating to the user’s operating system, browser, and IT environment.

This data is used to enable browsing on the Site, to derive anonymous statistical information on its use, to verify its proper functioning, and to ascertain any liability in the event of hypothetical computer crimes or abusive use.

1.3 Cookies and Tracking Tools

The Site may use cookies and technical, analytical, functional, advertising, and/or marketing tracking tools.

For more information on the types of cookies used, their purposes, and how to manage or withdraw consent, users are invited to consult the specific Cookie Policy available on the Site.

1.4 Data Voluntarily Provided via Contact Forms or E-mail Communications

The optional, explicit, and voluntary sending of messages to the e-mail addresses indicated on the Site, as well as the completion of any contact forms, involves the acquisition of the data provided by the user, including the sender’s e-mail address and any other personal data entered in the communication.

This data is processed exclusively to respond to user requests, provide assistance, manage commercial or pre-contractual communications, and follow up on any requested activities.

Data Relating to Registration and Product Purchases

To allow users to register, place orders, purchase products, receive shipments, request assistance, and manage any returns or refunds, the Controller may process: first and last name; e-mail address; telephone number; shipping address; billing address; data relating to the purchased product; order number; purchase history; payment information; data necessary to manage delivery; data necessary to manage returns, replacements, and refunds; any communications exchanged with customer service.

Payment data is generally not processed in full by the Controller, but by the payment service providers used on the Site, which operate according to their respective privacy policies and security measures.

2. Purposes of Processing

Users’ personal data may be processed for the following purposes.

2.1 Browsing and Operation of the Site

Browsing data is processed to enable access to the Site, ensure its proper functioning, improve IT security, prevent abuse, and derive statistical information on the use of the Platform.

2.2 Managing User Requests

Data provided via e-mail, contact forms, chat, support channels, or other communication tools is processed to respond to user requests, provide information on products, and manage complaints, support requests, and questions relating to orders, shipments, returns, and refunds.

2.3 Account Registration

Where the Site allows the creation of a personal account, the user’s data will be processed to enable registration, access to the personal account area, profile management, order history viewing, and use of related features.

2.4 Order Management and Sale of Products

The user’s personal data is processed to enable the purchase of products available on the Site, order confirmation, payment management, shipment preparation, sending communications relating to the purchase, delivery of products, and management of any related obligations.

2.5 Shipping, Delivery, and Logistics Model, Including Outside the EU

The Controller processes user data to manage the shipping and delivery of purchased products.

The user acknowledges that the Controller may also operate through an online sales logistics model involving direct shipment from suppliers, logistics partners, or warehouses located outside the European Union, including China.

For this reason, the data strictly necessary for shipment, such as first and last name, delivery address, telephone number, e-mail, order information, and data necessary for delivery, may be disclosed to suppliers, logistics partners, couriers, postal operators, customs authorities, or other parties involved in the order fulfillment chain.

Where this involves a transfer of personal data to countries outside the European Economic Area, the transfer will take place in compliance with Articles 44 et seq. GDPR, by means of adequate safeguards, such as European Commission adequacy decisions, Standard Contractual Clauses, or other instruments provided for by applicable law.

2.6 Managing Returns, Refunds, Complaints, and After-Sales Support

The user’s personal data may be processed to handle requests for withdrawal, return, product exchange, refund, complaint, legal warranty claims, delivery disputes, or other after-sales support requests.

In such cases, the Controller may also process photographs of the product, packaging, shipping labels, proof of delivery, return shipment receipts, and any other information necessary to verify the user’s request.

2.7 Tax, Accounting, and Administrative Obligations

The user’s personal data may be processed to comply with obligations under tax, accounting, administrative, and civil law regulations, including the management of documentation relating to orders, payments, invoices, refunds, and obligations connected to online sales.

2.8 Newsletter and Commercial Communications

Where the user gives their consent, personal data may be processed to send newsletters, promotional communications, commercial offers, product updates, marketing campaigns, discounts, promotions, and brand initiatives.

Communications may be sent via e-mail, SMS, messaging systems, or other digital tools, within the limits of the consent given by the user.

The user may withdraw consent at any time, using the unsubscribe link in the communications received or by writing to the Controller.

2.9 Marketing, Remarketing, and Personalized Advertising

Subject to the user’s consent, the Controller may use cookies, pixels, tags, and other tracking tools for marketing, remarketing, advertising campaign measurement, and personalized ad delivery purposes, including through third-party platforms such as, by way of example, Meta, Google, TikTok, Shopify, or other advertising and analytics service providers.

The user may manage their preferences through the cookie banner or the tools made available by the Site and by individual third-party providers.

2.10 Protection of the Controller’s Rights

Personal data may be processed to establish, exercise, or defend a right of the Controller in judicial or extrajudicial proceedings, as well as to prevent fraud, abuse, unlawful use of the Site, payment disputes, chargebacks, or violations of the Terms and Conditions.

3. Legal Bases for Processing

The processing of personal data is based on the following legal grounds.

3.1 Performance of a Contract or Pre-Contractual Measures

The processing of data relating to orders, payments, shipping, delivery, account registration, returns, refunds, and customer service is necessary to perform the sales contract or pre-contractual measures requested by the user.

3.2 Compliance with Legal Obligations

The processing of personal data may be necessary to comply with tax, accounting, administrative, civil, customs, or other obligations provided for by applicable law.

3.3 Consent of the Data Subject

Processing for purposes of newsletters, direct marketing, promotional communications, advertising profiling, remarketing, and the use of non-technical cookies is based on the data subject’s consent, where required by applicable law.

Consent is freely given, specific, informed, and revocable at any time.

Legitimate Interest of the Controller

The Controller may process personal data on the basis of its own legitimate interest where processing is necessary to: ensure the security of the Site; prevent fraud or abusive use; manage disputes, complaints, or claims; establish, exercise, or defend a right; improve the services offered, within the limits permitted by law; and send communications relating to products or services similar to those already purchased, where permitted by law and unless the user objects.

4. Methods of Processing

Personal data is processed using manual, electronic, IT, and telematic tools, following logic strictly connected to the purposes indicated in this policy.

The Controller adopts appropriate technical and organizational measures to protect personal data from loss, unauthorized access, unlawful use, disclosure, alteration, or unauthorized destruction.

Data will be processed exclusively by persons authorized by the Controller or by third parties providing services necessary for the management of the Site, orders, payments, shipments, marketing, and customer service.

5. Categories of Data Recipients

The user’s personal data may be disclosed to the following categories of parties: staff, collaborators, and persons authorized by the Controller; IT service providers; hosting providers; e-commerce platforms; cloud service providers; payment service providers; banks and financial intermediaries; couriers, freight forwarders, logistics and postal operators; suppliers, warehouses, and logistics partners located abroad as well; tax advisors, accountants, legal counsel, and other professionals; companies providing customer care services; e-mail marketing and newsletter platforms; advertising and analytics platforms; public, administrative, tax, customs, or judicial authorities, in cases provided for by law.

The updated list of any Data Processors appointed pursuant to Article 28 GDPR is available from the Controller and may be requested by writing to the e-mail address indicated in this policy.

Personal data will not be disclosed to undetermined recipients.

6. Payment Providers

To manage payments made through the Site, the Controller may use third-party providers, such as, by way of example, Shopify Payments, PayPal, Stripe, credit cards, Apple Pay, Google Pay, Shop Pay, or other payment systems available at checkout.

These parties may process the user’s personal data as independent data controllers or, depending on the case, as data processors, in accordance with their respective privacy policies.

The Controller does not retain the user’s payment card data in full, as this is managed by payment providers in accordance with industry-standard security practices.

7. Couriers, Freight Forwarders, Suppliers, and Logistics Partners

To fulfill orders and deliver purchased products, the Controller may disclose the user’s personal data to couriers, freight forwarders, logistics operators, postal operators, suppliers, warehouses, and business partners.

Given the logistics model used, some products may be shipped directly from suppliers or warehouses located outside the European Union, including China.

In such cases, the data necessary for shipping and delivery may be transferred to the foreign parties involved in the logistics chain, to the extent strictly necessary to perform the sales contract and deliver the product to the user.

8. Place of Processing

Personal data is processed at the Controller’s registered office, at the servers and technical infrastructure used to operate the Site, and at the premises of the technical, commercial, and logistics suppliers and partners involved in the processing.

Data may also be stored and processed through cloud services, e-commerce platforms, payment systems, marketing tools, and logistics services located in Italy, the European Union, or non-EU countries, in compliance with applicable law.

9. Transfer of Data to Non-EU Countries

The use of e-commerce platforms, payment tools, cloud services, marketing tools, international couriers, logistics providers, and partners located abroad may involve the transfer of personal data outside the European Economic Area.

In particular, due to the sales and shipping model used by the Controller, the data necessary for order fulfillment and product delivery may be disclosed to suppliers, warehouses, or logistics partners located in China or other non-EU countries.

Transfers of data outside the EU take place in compliance with Articles 44 et seq. GDPR and, where necessary, on the basis of adequate safeguard instruments, such as: European Commission adequacy decisions; Standard Contractual Clauses approved by the European Commission; supplementary technical, organizational, and contractual measures, where necessary; derogations provided for by Article 49 GDPR, in cases where the transfer is necessary for the performance of the contract concluded between the user and the Controller or for the performance of pre-contractual measures taken at the user’s request.

10. Data Retention

Personal data will be retained for the time strictly necessary to achieve the purposes for which it was collected.

After the retention period has elapsed, the data will be deleted, anonymized, or aggregated in a manner that prevents identification of the data subject.

11. Mandatory or Optional Nature of Data Provision

The provision of browsing data is necessary to allow access to and operation of the Site.

The provision of data necessary for registration, purchase, payment, shipping, delivery, and the management of returns or refunds is necessary to conclude and perform the sales contract.

Any refusal to provide such data may result in the inability to register, place orders, receive purchased products, obtain assistance, or make use of the requested services.

The provision of data for marketing purposes, newsletters, advertising profiling, and non-technical cookies is optional. Failure to consent does not affect the ability to browse the Site or purchase products, except for the inability to receive promotional communications or personalized content.

12. Rights of the Data Subject

The user, as a data subject, may exercise the rights provided for under Articles 12-22 GDPR at any time.

In particular, the user has the right to:

  • obtain confirmation as to whether or not personal data concerning them is being processed;
  • access their personal data;
  • obtain rectification of inaccurate data;
  • obtain completion of incomplete data;
  • obtain erasure of data in cases provided for by law;
  • obtain restriction of processing;
  • receive data in a structured, commonly used, and machine-readable format;
  • object to processing in cases provided for by law;
  • withdraw consent given, without affecting the lawfulness of consent-based processing carried out before the withdrawal;
  • not be subject to a decision based solely on automated processing, including profiling, which produces legal effects or significantly affects the person.

To exercise their rights, the user may contact the Controller by writing to:

help@notoriousbrand.it

The Controller undertakes to respond to requests within the timeframes provided for by applicable law.

13. Complaint to the Data Protection Authority

Should the user believe that the processing of their personal data is carried out in violation of applicable law, they have the right to lodge a complaint with the Data Protection Authority (Garante per la protezione dei dati personali).

The user retains the right to bring the matter before the competent judicial authority.

14. Security of Personal Data

The Controller adopts technical and organizational measures appropriate to the risk, in order to protect the personal data processed from unauthorized access, loss, destruction, disclosure, alteration, or unlawful processing.

These measures include, where applicable, authentication systems, security protocols, access restrictions, backups, software updates, IT security tools, and internal procedures for managing personal data.

Despite the adoption of adequate security measures, no IT system can be considered completely immune from risk. Users are therefore encouraged to use secure credentials, refrain from sharing their access details, and promptly report any unauthorized use of their account.

16. Changes to This Policy

The Controller reserves the right to modify, update, or supplement this Privacy Policy at any time, including in response to regulatory changes, technical updates, changes to the services offered, or changes to the organizational and logistics model.

Changes will be published on the Site and will take effect from the time of publication.

Users are invited to regularly check this page for any updates.

17. Contacts

For any request relating to the processing of personal data, the exercise of privacy rights, or this Policy, users may contact the Controller at the following details:

E-mail: help@notoriousbrand.it

Registered office: Via G. Mazzini, 53, 35030 Rubano, PD, Italy