Privacy policy
This Privacy Policy explains how Valentino Di Rosa (hereinafter “Valentino Di Rosa”, “we”, “us”, or “Controller”), with registered office in Switzerland, processes personal data in accordance with the Swiss Federal Act on Data Protection (nLPD 2023) and related regulations.
Using the website vdrfragrance.com implies acceptance of the processing described here.
INTRODUCTION
Valentino Di Rosa is committed to protecting the privacy of visitors and users of the Site. We process personal data in accordance with the principles of proportionality, transparency, good faith, purpose limitation, data minimization, integrity and confidentiality required by the nLPD.
All personal data you provide or that we collect while you use the Site will be processed for the purposes described in this Policy and protected with appropriate technical and organisational measures.
DEFINITIONS
Personal data: Any information relating to an identified or identifiable natural person.
Sensitive personal data (particularly worthy of protection): Data concerning health, political, religious or philosophical opinions, biometric data identifying a person, private life details, etc.
Processing: Any operation performed on personal data (collection, storage, use, transmission, deletion, etc.).
Profiling: Automated processing intended to evaluate certain personal aspects (preferences, behaviour, interests).
Types of Data Processed
Contact Data
We may process contact information such as:
First and last name
Postal address
Email address
Telephone/mobile number
Data submitted in site forms or registrations
Identifiers used by advertising services (e.g., Google Ads)
Data Collected During Navigation
When you browse the Site we automatically collect technical information, including:
IP address and domain names used to connect to the Site
Requested page URIs
Date and time of request
Request method to the server
Response status code (success, error)
File size of responses and other parameters related to the operating system and IT environment
These data are used to ensure proper functioning of the Site, produce anonymous statistics, detect anomalies, and for security / anti-fraud purposes. Such data are retained for the time strictly necessary for these purposes.
Data Voluntarily Provided by the User
If you provide personal data of third parties (e.g., in an order or contact form), you confirm you have the right to share those data and assume responsibility. Valentino Di Rosa is not liable for disputes arising from unlawful sharing of third-party personal data.
COOKIES
The Site uses cookies and similar technologies for authentication, session management, storing preferences, analytics, and — with consent — profiling and advertising. A separate Cookie Policy describes cookie usage in detail.
Legal Bases (nLPD)
While the Swiss LPD does not follow the GDPR’s formal legal bases, processing on the Site is carried out according to principles of lawfulness, proportionality and transparency and is justified by:
the consent of the user (when required, for marketing and non-essential cookies),
the performance of a contract (orders, payments, shipping),
the legitimate interest of the Controller (security, fraud prevention, internal analytics),
legal obligations in specific cases (e.g., requests by competent authorities).
Purposes of Processing
We process personal data for the following purposes:
operate and maintain the Site;
respond to contact requests and provide customer support;
manage orders, payments and shipments;
send newsletters and marketing communications (only with consent);
perform statistical analyses and improve the Site;
prevent and detect fraud or abuse;
provide targeted advertising where consent is given.
THIRD-PARTY SERVICES AND DATA RECIPIENTS
We use third-party services, including but not limited to: Google (Analytics, Fonts, YouTube), Meta (Facebook, Instagram), TikTok, Mailgun (newsletter), hosting providers (Google Cloud or similar), anti-spam services (reCAPTCHA), payment gateways, and live chat providers. These third parties process data according to their own policies.
Personal data may be shared with:
technical and hosting providers;
payment and shipping service providers;
consultants and service providers acting on our behalf;
competent Swiss authorities when required by law.
We do not sell personal data to third parties for unrelated purposes.
Cross-border Data Transfers
Some processors (e.g., Google, Meta, Mailgun) may store or process data outside Switzerland (for example, in the United States). Transfers are made only to countries that provide adequate protection as recognised by the Swiss Confederation, or under contractual safeguards, or with your explicit consent.
DATA RETENTION
We retain personal data no longer than necessary for the purposes for which they were collected:
Contractual / transactional data: retained in accordance with Swiss commercial and tax law (up to 10 years when required).
Newsletter data: retained until you withdraw consent.
Technical logs: retained for the period necessary for security and troubleshooting (generally limited months).
Profiling data: retained according to your consent and applicable retention terms.
After the retention period, data are securely deleted or irreversibly anonymised.
PROFILING
We may use profiling techniques to personalise content and advertising. Profiling is performed only with your consent and is never used for automated decisions producing legal effects.
Security Measures
We adopt appropriate technical and organisational measures to protect personal data, including encryption, access controls, firewalls, backups, and logging. Access to personal data is limited to authorised personnel.
Your Rights (nLPD)
Under the Swiss nLPD you have the right to:
request access to personal data we hold about you;
request rectification or completion;
request deletion (subject to legal retention obligations);
request restriction of processing;
object to processing;
withdraw consent at any time (without affecting processing carried out before withdrawal);
request data portability where technically possible;
lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC / IFDP).
To exercise your rights or for any information, contact: go4vale@gmail.com
USE OF DATA FOR LEGAL REQUESTS
We may disclose information to courts, law enforcement, or other public authorities in Switzerland when required by law.
LOG FILES
We log events and system activity for security, troubleshooting, and maintenance purposes. Logs are used for diagnostics, to identify misuse and security incidents.
Do Not Track
The Site does not currently respond to “Do Not Track” browser signals. Please consult the privacy notices of third-party services for their support of such signals.
Changes to This Policy
We may update this Privacy Policy at any time. The updated policy will be posted on the Site and will indicate the date of the last revision. Continued use of the Site after publication of changes implies acceptance.
Contact
For questions and to exercise your rights: care@vdrfragrance.com