This Privacy Policy is provided by BRUFIT SRL, with registered office at Corso Canale 14, 12051 Alba (CN), Italy, as Data Controller of the personal data collected via the website (the “Site”), pursuant to Regulation (EU) 2016/679 (the “GDPR”) and the applicable national legislation on personal data protection.
Data processed and purposes
Depending on how the Site is used, BRUFIT may process:
-
Browsing data (e.g. IP addresses, logs, information on device and browser) to enable the technical functioning of the Site, ensure security and obtain anonymous statistics on usage.
-
Data voluntarily provided by the user (name, surname, contact details, shipping and billing address, order details) to:
-
manage orders, payments and delivery of products;
-
respond to contact and support requests;
-
comply with accounting, tax and legal obligations.
-
-
Data for marketing purposes (e.g. e-mail address for newsletters and promotional messages) only with the explicit consent of the data subject, which may be withdrawn at any time.
Legal basis of processing
Depending on the case, data are processed on the basis of:
-
performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR);
-
compliance with legal obligations (Art. 6(1)(c) GDPR);
-
the legitimate interests of the Controller (Art. 6(1)(f) GDPR), such as IT security, prevention of abuse and protection of rights in legal proceedings;
-
the consent of the data subject (Art. 6(1)(a) GDPR) for marketing activities and, where required, for certain types of cookies or profiling tools.
Recipients of data
Personal data may be disclosed to:
-
IT and technical service providers;
-
couriers and logistics operators;
-
consultants and professionals (e.g. accountants, lawyers);
-
payment institutions and financial intermediaries.
These parties generally act as Processors on the basis of specific agreements defining their obligations and security measures.
Transfers to third countries
Where, for the use of specific services (e.g. analytics tools, newsletter platforms, cloud services), personal data are transferred outside the EU/EEA, such transfers will take place in compliance with the GDPR, using appropriate safeguards (e.g. adequacy decisions, Standard Contractual Clauses).
Data retention
Order-related data are stored for the time necessary to perform the contract and fulfil legal obligations (e.g. tax and accounting).
Data processed for marketing purposes are retained until consent is withdrawn or erasure is requested by the data subject, without prejudice to any further retention period required to protect the Controller’s rights in legal proceedings.
Rights of the data subject
At any time, the data subject may exercise the rights provided for by Articles 15–22 GDPR, including:
-
the right of access to personal data;
-
the right to rectification and updating;
-
the right to erasure (“right to be forgotten”), where applicable;
-
the right to restriction of processing;
-
the right to data portability;
-
the right to object to processing on grounds relating to their particular situation and, at any time, to processing for direct marketing purposes.
To exercise these rights, the data subject may contact BRUFIT using the contact details provided on the Site or by writing to the registered office address.
Cookies and tracking tools
The Site may use technical cookies, analytics cookies and, with consent, profiling cookies or third-party cookies (e.g. web analytics tools, remarketing, social media integrations).
Further details on the types of cookies used, their purposes and how to manage preferences are set out in a dedicated Cookie Policy available on the Site. Users can always configure their browser to accept or refuse cookies, it being understood that disabling certain cookies may limit some functionalities of the Site.