Privacy policy

This Privacy Policy explains how Valentino Di Rosa (hereinafter “Valentino Di Rosa”, “we”, “us”, or “Controller”), with registered office in Switzerland, processes personal data in accordance with the Swiss Federal Act on Data Protection (nLPD 2023) and related regulations.

Using the website vdrfragrance.com implies acceptance of the processing described here.

INTRODUCTION

Valentino Di Rosa is committed to protecting the privacy of visitors and users of the Site. We process personal data in accordance with the principles of proportionality, transparency, good faith, purpose limitation, data minimization, integrity and confidentiality required by the nLPD.

All personal data you provide or that we collect while you use the Site will be processed for the purposes described in this Policy and protected with appropriate technical and organisational measures.

DEFINITIONS

Personal data: Any information relating to an identified or identifiable natural person.

Sensitive personal data (particularly worthy of protection): Data concerning health, political, religious or philosophical opinions, biometric data identifying a person, private life details, etc.

Processing: Any operation performed on personal data (collection, storage, use, transmission, deletion, etc.).

Profiling: Automated processing intended to evaluate certain personal aspects (preferences, behaviour, interests).

Types of Data Processed

Contact Data

We may process contact information such as:

First and last name

Postal address

Email address

Telephone/mobile number

Data submitted in site forms or registrations

Identifiers used by advertising services (e.g., Google Ads)

Data Collected During Navigation

When you browse the Site we automatically collect technical information, including:

IP address and domain names used to connect to the Site

Requested page URIs

Date and time of request

Request method to the server

Response status code (success, error)

File size of responses and other parameters related to the operating system and IT environment

These data are used to ensure proper functioning of the Site, produce anonymous statistics, detect anomalies, and for security / anti-fraud purposes. Such data are retained for the time strictly necessary for these purposes.

Data Voluntarily Provided by the User

If you provide personal data of third parties (e.g., in an order or contact form), you confirm you have the right to share those data and assume responsibility. Valentino Di Rosa is not liable for disputes arising from unlawful sharing of third-party personal data.

COOKIES

The Site uses cookies and similar technologies for authentication, session management, storing preferences, analytics, and — with consent — profiling and advertising. A separate Cookie Policy describes cookie usage in detail.

Legal Bases (nLPD)

While the Swiss LPD does not follow the GDPR’s formal legal bases, processing on the Site is carried out according to principles of lawfulness, proportionality and transparency and is justified by:

the consent of the user (when required, for marketing and non-essential cookies),

the performance of a contract (orders, payments, shipping),

the legitimate interest of the Controller (security, fraud prevention, internal analytics),

legal obligations in specific cases (e.g., requests by competent authorities).

Purposes of Processing

We process personal data for the following purposes:

operate and maintain the Site;

respond to contact requests and provide customer support;

manage orders, payments and shipments;

send newsletters and marketing communications (only with consent);

perform statistical analyses and improve the Site;

prevent and detect fraud or abuse;

provide targeted advertising where consent is given.

THIRD-PARTY SERVICES AND DATA RECIPIENTS

We use third-party services, including but not limited to: Google (Analytics, Fonts, YouTube), Meta (Facebook, Instagram), TikTok, Mailgun (newsletter), hosting providers (Google Cloud or similar), anti-spam services (reCAPTCHA), payment gateways, and live chat providers. These third parties process data according to their own policies.

Personal data may be shared with:

technical and hosting providers;

payment and shipping service providers;

consultants and service providers acting on our behalf;

competent Swiss authorities when required by law.

We do not sell personal data to third parties for unrelated purposes.

Cross-border Data Transfers

Some processors (e.g., Google, Meta, Mailgun) may store or process data outside Switzerland (for example, in the United States). Transfers are made only to countries that provide adequate protection as recognised by the Swiss Confederation, or under contractual safeguards, or with your explicit consent.

DATA RETENTION

We retain personal data no longer than necessary for the purposes for which they were collected:

Contractual / transactional data: retained in accordance with Swiss commercial and tax law (up to 10 years when required).

Newsletter data: retained until you withdraw consent.

Technical logs: retained for the period necessary for security and troubleshooting (generally limited months).

Profiling data: retained according to your consent and applicable retention terms.

After the retention period, data are securely deleted or irreversibly anonymised.

PROFILING

We may use profiling techniques to personalise content and advertising. Profiling is performed only with your consent and is never used for automated decisions producing legal effects.

Security Measures

We adopt appropriate technical and organisational measures to protect personal data, including encryption, access controls, firewalls, backups, and logging. Access to personal data is limited to authorised personnel.

Your Rights (nLPD)

Under the Swiss nLPD you have the right to:

request access to personal data we hold about you;

request rectification or completion;

request deletion (subject to legal retention obligations);

request restriction of processing;

object to processing;

withdraw consent at any time (without affecting processing carried out before withdrawal);

request data portability where technically possible;

lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC / IFDP).

To exercise your rights or for any information, contact: go4vale@gmail.com

USE OF DATA FOR LEGAL REQUESTS

We may disclose information to courts, law enforcement, or other public authorities in Switzerland when required by law.

LOG FILES

We log events and system activity for security, troubleshooting, and maintenance purposes. Logs are used for diagnostics, to identify misuse and security incidents.

Do Not Track

The Site does not currently respond to “Do Not Track” browser signals. Please consult the privacy notices of third-party services for their support of such signals.

Changes to This Policy

We may update this Privacy Policy at any time. The updated policy will be posted on the Site and will indicate the date of the last revision. Continued use of the Site after publication of changes implies acceptance.

Contact

For questions and to exercise your rights: care@vdrfragrance.com