Privacy Policy

PRIVACY POLICY

pursuant to Art. 13 of EU Regulation 2016/679 (GDPR)

MADAME T SRL Version 1.0 — May 2026


1. Data Controller

The controller of your personal data is:

MADAME T SRL Via Adua 11, 24040 Stezzano (BG) — Italy VAT No.: 04920820166 Email: info@madamet.it PEC: amministrazione@pec.madamet.it

Hereinafter referred to as the "Controller" or "MADAME T".


2. Personal Data Processed and Purposes

2.1 Website Browsing

When you browse www.madamet.it, technical data necessary for the operation of computer systems is collected automatically (IP address, browser type, operating system, pages visited, access time). This data is processed only to the extent strictly necessary for the Site's operation and is retained for the shortest time required.

Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR) in the security and proper functioning of the Site.

2.2 Order Management and Sales Contract

When you make a purchase, we collect the data necessary to fulfil the contract: name, surname, email address, delivery and billing address, telephone number, payment information (processed directly by payment providers, not by MADAME T).

Purposes: order processing, shipping, after-sales support, returns management, fulfilment of legal obligations (fiscal and accounting).

Legal basis:

  • Performance of the contract (Art. 6(1)(b) GDPR)
  • Compliance with legal obligations (Art. 6(1)(c) GDPR)

Retention: 10 years from the end of the contractual relationship, in compliance with fiscal and accounting obligations.

2.3 Customer Support

When you contact us by email, we collect the data necessary to handle your request (name, email, content of the request).

Legal basis: performance of the contract or legitimate interest (Art. 6(1)(b) and (f) GDPR).

Retention: for the time necessary to handle the request and, where connected to an order, for the duration of the contractual relationship.

2.4 Marketing and Newsletter

If you have given your explicit consent, we use your email address to send you commercial communications (newsletters, promotions, new collections).

Legal basis: consent of the data subject (Art. 6(1)(a) GDPR).

You may withdraw consent at any time by clicking the "Unsubscribe" link at the bottom of any email or by writing to info@madamet.it. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Retention: until consent is withdrawn or, in any event, no longer than 24 months from the last interaction.

2.5 Cookies and Tracking Technologies

For information on cookies and tracking technologies (Google Analytics 4, Meta Pixel, TikTok Pixel, Omnisend), please refer to the Cookie Policy available on the Site.


3. Recipients of Data

Personal data may be shared with the following categories of parties, appointed as processors under Art. 28 GDPR, or acting as independent controllers:

Payment providers

  • PayPal (Europe) S.à r.l. et Cie, S.C.A. — Luxembourg — for PayPal payment processing
  • Scalapay Italy S.r.l. — for the Scalapay instalment payment service
  • Klarna Bank AB (publ) — Sweden — for the Klarna deferred payment service
  • Shopify International Limited — Ireland — for e-commerce platform management and card payment processing

Shipping providers

The courier appointed for delivery receives the data necessary for shipping (name, surname, address, telephone number).

Marketing and analytics tools

  • Google Ireland Limited — Ireland — for Google Analytics 4 (statistical analysis of Site visits). Privacy policy: https://policies.google.com/privacy
  • Meta Platforms Ireland Limited — Ireland — for Meta Pixel (analysis and advertising via Facebook and Instagram). Privacy policy: https://www.facebook.com/privacy/explanation
  • TikTok Information Technologies UK Limited — United Kingdom — for TikTok Pixel (analysis and advertising on TikTok). Privacy policy: https://www.tiktok.com/legal/privacy-policy
  • Rocket Science Group LLC (Omnisend) — USA — for email and SMS campaign management. Transfer to the USA is made in accordance with the adequate safeguards under Chapter V GDPR (Standard Contractual Clauses). Privacy policy: https://www.omnisend.com/privacy/

Competent authorities

Data may be shared with tax, judicial or public security authorities where required by law.

MADAME T does not sell, assign or transfer personal data to third parties for their own purposes.


4. Transfers Outside the European Union

Some providers listed in section 3 (in particular Omnisend/Rocket Science Group LLC) transfer personal data to the United States. Such transfers are made in compliance with the adequate safeguards provided by the GDPR (Arts. 44 to 49), in particular by means of the Standard Contractual Clauses adopted by the European Commission. You may request a copy of these safeguards by writing to info@madamet.it.


5. Data Subject Rights

Under Arts. 15 to 22 of the GDPR, you have the right to:

  • Access (Art. 15): obtain confirmation that your data is being processed and receive a copy
  • Rectification (Art. 16): request correction of inaccurate or incomplete data
  • Erasure (Art. 17, "right to be forgotten"): request deletion of your data where no legal retention obligation exists
  • Restriction of processing (Art. 18): request restriction of processing in specific circumstances
  • Portability (Art. 20): receive your data in a structured, machine-readable format, where processing is based on consent or contract and carried out by automated means
  • Objection (Art. 21): object to processing based on legitimate interest, including direct marketing
  • Withdrawal of consent: withdraw consent at any time without affecting the lawfulness of prior processing
  • Lodge a complaint (Art. 77): file a complaint with the Italian Data Protection Authority (www.garanteprivacy.it)

To exercise your rights, write to: info@madamet.it

MADAME T responds to requests within 30 days of receipt (Art. 12 GDPR), with the possibility of a further 60-day extension in complex cases, communicated within the initial deadline.


6. Data Security

MADAME T adopts appropriate technical and organisational measures to protect personal data from unauthorised access, loss, destruction or disclosure, in accordance with Art. 32 GDPR. Payment transactions are encrypted using the SSL/TLS protocol.


7. Automated Decision-Making

MADAME T does not carry out automated profiling with significant legal effects on data subjects under Art. 22 GDPR.


8. Changes to this Policy

This Policy may be updated to reflect regulatory changes or new processing activities. The updated version will be published on the Site with a revision date. In the event of material changes, MADAME T may also notify Customers by email.


9. Contact

For any questions about the processing of your personal data:

MADAME T SRL Email: info@madamet.it PEC: amministrazione@pec.madamet.it


Last updated: May 2026