• SCROLL TO EXPLORE THE MILLEFIORI UNIVERSE • SCROLL TO EXPLORE THE MILLEFIORI UNIVERSE

Cookie Policy

PRIVACY POLICY OF THE WEBSITE WWW.MILLEFIORIMILANO.COM

Notice on the processing of personal data pursuant to Art. 13 of Regulation (EU) 2016/679 (GDPR)

This Privacy Policy is intended to describe how the website www.millefiorimilano.com (hereinafter, the “Website”) is managed with regard to the processing of the personal data of users (hereinafter, the “Users” or “Data Subjects”) who consult it, register on it, or make online purchases.

This notice is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), Legislative Decree 196/2003 (as amended by Legislative Decree 101/2018) and the Guidelines of the Italian Data Protection Authority (Garante Privacy)

1. DATA CONTROLLER

The Data Controller for the personal data collected through this Website is:

Home Fragrance Italia S.r.l. Registered office: Via Del Commercio 28, 20881 Bernareggio (MB) VAT no.: 12886810154 E-mail: info@millefiorimilano.com Certified e-mail (PEC): millefiorisrl@legalmail.it Tel: +39 039 9220979

For any question relating to the processing of personal data, the User may contact the Controller at the contact details indicated above.

2. TYPES OF PERSONAL DATA PROCESSED

The Controller collects and processes, in connection with the different purposes described in point 3 below, the following categories of personal data:

  1. technical browsing data: IP addresses, device identifiers, URI/URL codes of the requested resources, time and duration of sessions, log data, parameters relating to the User's operating system and browser. Such data are automatically generated by the Website's computer systems and are not associated with identified users, except where necessary due to security events;

  2. registration and account data: first name, last name, e-mail address, login credentials. Passwords are stored exclusively by means of non-reversible cryptographic hashing algorithms;

  3. transaction and e-commerce data: shipping address, billing address, telephone number, purchase history and details of the products ordered (diffusers, refills, fragrances). Data relating to credit cards or other payment instruments are not collected or stored by the Controller: their processing is carried out directly by third-party payment gateways, in encrypted form compliant with PCI-DSS standards;

  4. data for marketing and profiling (only subject to consent): e-mail address for sending the newsletter; data relating to purchasing preferences, consumption habits and interactions with the Website, used for profiling purposes, subject to obtaining specific and separate consent.

3. PURPOSES OF PROCESSING, LEGAL BASES AND RETENTION PERIODS

For each processing purpose, the legal basis and the related retention period are indicated, in accordance with Articles 5, 6 and 13 of the GDPR.

A) Technical browsing and IT security

Description: ensure the correct functioning of the Website, ensure the stability of the technological infrastructure, detect and manage any cyberattacks (e.g. DDoS), prevent fraudulent activities and monitor system security.

Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR) in protecting its digital infrastructure and ensuring the continuity of the service offered to Users.

Retention period: browsing data are processed for the time strictly necessary for the functioning of the Website and session management. Technical data and security logs are retained for the time necessary to detect, analyze and manage anomalous events or security incidents, and in any case for no longer than 90 days, unless specific requests from the Judicial Authority or another competent Authority require longer retention for the purposes of investigating and preventing crimes. 

B) Account registration, order fulfillment and after-sales support

Description: management of the user profile, the cart, online purchases, the shipping of products, customer care services and after-sales support.

Legal basis: performance of a contract to which the data subject is party, or performance of pre-contractual measures taken at the data subject's request (Art. 6(1)(b) GDPR).

Retention period: data relating to commercial transactions are retained for 10 years from the date of the transaction, in compliance with the accounting record-keeping obligations set out in Art. 2220 of the Italian Civil Code. Account profile data not strictly necessary for tax or accounting purposes are retained for the time necessary to manage the contractual relationship and deleted at the request of the data subject, without prejudice to cases of mandatory statutory retention.

C) Compliance with legal obligations

Description: compliance with tax, customs, accounting and anti-money laundering regulations and with orders or requests from the competent Authorities (e.g. Revenue Agency, Judicial Authority, Financial Police).

Legal basis: compliance with a legal obligation to which the Controller is subject (Art. 6(1)(c) GDPR).

Retention period: data are retained for the periods required by applicable law. As an indication: 10 years for tax and accounting documentation (Arts. 2214 and 2220 of the Italian Civil Code; Art. 43 of Presidential Decree 600/1973); further specific time limits may apply in relation to other sector-specific regulations. 

D) Direct marketing via newsletter

Description: sending promotional communications, product updates, discounts and commercial news about the Millefiori Milano Brand by e-mail.

Legal basis: free, specific, informed and unambiguous consent of the data subject (Art. 6(1)(a) GDPR), given by means of a positive action and a checkbox that is not pre-ticked at the time of registration for the service.

Retention period: data are retained until consent is withdrawn by the User (opt-out), and in any case for no longer than 24 months from the last active interaction with the communications sent (opening, click). After this period, the Controller will check whether the User's interest persists or will proceed with deletion.

Right of withdrawal: consent may be withdrawn at any time, as easily as it was given, by means of the “unsubscribe” link present in every newsletter e-mail or by writing to: info@millefiorimilano.com. Withdrawal does not affect the lawfulness of processing carried out prior to it. 

E) Profiling and personalization of commercial communications

Description: analysis of purchasing preferences, consumption habits and interactions with the Website (e.g. products viewed, fragrances purchased, order frequency) in order to create individual and group profiles and send the data subject personalized commercial communications and offers that are more relevant to their interests.

This activity constitutes profiling within the meaning of Art. 4(4) GDPR. It does not result in automated decision-making with legal effects on the data subject (Art. 22 GDPR), but affects the personalization of the commercial communications received. 

Legal basis: specific, free and optional consent of the data subject (Art. 6(1)(a) GDPR), separate from the consent given for the general newsletter and given by means of a dedicated checkbox that is not pre-ticked. Failure to give consent for this purpose does not prevent registration for the newsletter referred to in point D). 

Retention period:

Data relating to the details of purchases and interactions used for analysis and profiling: 12 months from collection.

Contact data used to send personalized commercial communications: 24 months from the date consent was given.

Upon expiry of these periods, or in the event of withdrawal of consent, the data will be irreversibly deleted or permanently anonymized, in accordance with the technical deletion and backup procedures.

4. NATURE OF THE PROVISION OF DATA AND CONSEQUENCES OF REFUSAL

Pursuant to Art. 13(2)(e) of the GDPR, the nature of the provision of data by the User is specified in relation to the different purposes of the processing;

browsing and security purposes (Point 3.A): the provision of browsing data is implicit and necessary for consulting the Website. Without such data, browsing and the correct functioning of the web services would not be possible;


account registration and order fulfillment purposes (Point 3.B): the provision of the data required for account registration and to complete a purchase (e.g. personal details, shipping address, contact details) is a necessary requirement for entering into the contract. Failure to provide such data will make it impossible to create a personal account and to process and ship orders;

compliance with legal obligations purposes (Point 3.C): the processing of data for this purpose derives from a legal obligation and, therefore, the provision is mandatory;

Direct Marketing purposes (Newsletter) (Point 3.D): the provision of data (e-mail address) for this purpose is entirely optional. Refusal to give consent has no consequence on the possibility of browsing the website, registering or making purchases; it will only result in the impossibility of receiving our promotional communications and general newsletters.

Profiling purposes (Point 3.E): the provision of data for this purpose is entirely optional and separate from consent to general marketing. Refusal to give consent to profiling does not in any way affect the use of the other services (browsing, purchases, receipt of the general newsletter, if requested), but will solely result in the Controller being unable to send personalized offers and commercial communications based on your interests

5. RECIPIENTS OF PERSONAL DATA

Users' personal data are not disclosed to an indeterminate number of parties. They may be shared, solely for the pursuit of the purposes described in this notice, with the following categories of recipients:

Internal personnel of the Controller expressly authorized and instructed (IT, marketing, sales, logistics and administration departments);

Data Processors appointed pursuant to Art. 28 GDPR, including: hosting and cloud computing service providers, e-commerce platforms (e.g. Shopify/Magento), marketing and newsletter management agencies, application service providers;

Logistics companies and couriers responsible for the shipping and delivery of products;

Credit institutions and payment service companies (limited to the data necessary for managing transactions);

Legal, tax and corporate advisors of the Controller, within the limits of their respective services;

Judicial, administrative or supervisory authorities, in the cases provided for by applicable law.

The updated list of Data Processors is available at the Controller's registered office and may be requested by writing to info@millefiorimilano.com.

6. TRANSFER OF DATA TO COUNTRIES OUTSIDE THE EEA

Users' personal data are, as a rule, processed within the European Economic Area (EEA).

Should it become necessary, for technical or organizational reasons, to transfer data to countries outside the EEA, the Controller ensures that such transfer will take place solely in compliance with Articles 44 et seq. GDPR, and in particular:

to countries covered by an Adequacy Decision of the European Commission (including the EU-US Data Privacy Framework for transfers to the United States); or

by entering into the Standard Contractual Clauses (SCC) adopted by the European Commission with Implementing Decision 2021/914 of 4 June 2021, supplemented, where necessary, by additional technical and organizational measures to protect data in transit.

7. RIGHTS OF THE DATA SUBJECT

The applicable law grants the data subject specific rights listed in Articles 15 to 22 of the GDPR. In particular, the data subject has the right to ask the Controller for:

confirmation as to whether or not processing of their personal data is being carried out and, if so, to obtain access to it (Art. 15 – right of access);

rectification of inaccurate data or completion of incomplete data (Art. 16 – right to rectification);

erasure of the data where one of the grounds provided for applies (Art. 17 – right to erasure, “right to be forgotten”);

restriction of processing in the cases provided for (Art. 18 – right to restriction of processing);

to receive the data provided in a structured, commonly used and machine-readable format, and to transmit it to another controller, where the processing is based on consent or on a contract and is carried out by automated means (Art. 20 – right to data portability);

to object at any time to processing based on the legitimate interest of the Controller (Art. 21 – right to object);

to withdraw at any time any consent given, without prejudice to the lawfulness of consent-based processing carried out prior to the withdrawal.

Requests concerning the exercise of the above rights may be addressed to the Controller at the contact details indicated in the last paragraph, without any particular formality, including by means of the form for the exercise of data subjects' rights.

The data subject may also lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (Art. 77 GDPR), or bring proceedings before the competent courts pursuant to Art. 79 GDPR. The data subject may also withdraw any consent given as easily as it was given, by written communication sent via certified e-mail (PEC) or registered letter with return receipt to the contact details indicated in the last paragraph.

The Italian Data Protection Authority (Garante per la protezione dei dati personali) is located at Piazza Venezia n. 11, 00187 Rome – switchboard tel. (+39) 06.696771 – e-mail garante@gpdp.it – PEC protocollo@pec.gpdp.it – website www.garanteprivacy.it.

8. UPDATES TO THIS NOTICE

The Controller reserves the right to amend this notice in order to adapt it to legislative reforms, measures and guidelines of the supervisory Authorities, or to developments in the Website's technological infrastructure. Substantial changes will be communicated to Users in the most appropriate way (e.g. banner on the Website, e-mail communication). The updated version will always be available on the Website, indicating the relevant revision date.

Last updated: 30 June 2026