Privacy policy
Privacy Policy
Last updated: July 2026
Notice on the processing of personal data pursuant to Regulation (EU) 2016/679 (GDPR) and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
1. Data Controller
L&Y S.r.l.s.
Registered office: Via Torino 118/A14, 10036 Settimo Torinese (TO)
VAT number: 13345320017 — REA: TO-1356798
Share capital: €9,900.00 fully paid-up
PEC: [email protected]
Contact: [email protected]
This notice applies exclusively to the B2B business relationships established through the website www.leysettimo.com.
2. Categories of Data Processed
2.1 Data provided during B2B registration
- Company name and legal form
- Italian VAT number and/or EU VAT number (verified through VIES)
- Tax code
- PEC and/or SDI code for electronic invoicing
- Company contact person details: first name, last name, role
- Business e-mail and phone number
- Registered office address and shipping addresses
- Type of business activity
2.2 Automatically collected data
- IP address and technical browser/device data
- Pages visited, session duration, navigation paths
- Behavioral data (clicks, e-commerce events: product views, cart, purchase) via GTM/GA4
- Technical data for bot detection (hCaptcha, Cloudflare)
2.3 Order and transaction data
Billing data (VAT number, PEC, SDI), items ordered, quantities, amounts, payment method, transaction history.
3. Purposes and Legal Bases
- B2B registration, verification of the VAT number and preliminary checks for account activation — performance of pre-contractual measures taken at the request of the data subject (Art. 6(1)(b) GDPR)
- Order fulfillment, electronic invoicing, tax compliance — legal obligation (Art. 6(1)(c) GDPR)
- Marketing communications and catalog updates — consent (Art. 6(1)(a) GDPR), revocable at any time
- Aggregated statistical analysis for service improvement (GA4) — legitimate interest (Art. 6(1)(f) GDPR)
- Platform security, fraud prevention, bot detection — legitimate interest (Art. 6(1)(f) GDPR)
- Anti-fraud checks and tax data verification — legitimate interest (Art. 6(1)(f) GDPR)
4. Automated Decision-Making and VAT Number Verification
During registration, the Site performs automatic checks on the tax data provided:
- Italian operators: formal validity check of the Italian VAT number (checksum), performed automatically at the time of registration.
- EU operators: automatic verification of the VAT number through the VIES (VAT Information Exchange System) of the European Commission.
In the event of unavailability of the VIES system, a negative verification outcome, or the presence of anomalies, the registration is not automatically approved but is referred to manual review by L&Y S.r.l.s., normally within 24 hours.
The automatic checks described above do not constitute decisions based solely on automated processing within the meaning of Art. 22 GDPR: human intervention is in any case provided for before the registration produces definitive effects on the Customer's account.
5. Platforms and Services Used
Listed below are only the third-party services currently active that involve the processing of personal data of visitors or customers. Services operating exclusively on the backend without access to visitors' personal data are not included.
5.1 Shopify Inc. — E-commerce Platform
Location: Canada (a country deemed adequate pursuant to Art. 45 GDPR). Shopify processes data for sessions, authentication, orders, checkout, and payments. For any transfers to infrastructure in the USA, Shopify adopts safeguards pursuant to Art. 46 GDPR.
Shopify activates hCaptcha by default (provider: Intuition Machines Inc., USA) on the registration, login, and password recovery forms. hCaptcha is used exclusively for security purposes and to prevent automated access. It may analyze the user's interaction patterns to distinguish human visitors from bots, with no commercial purpose. Legal basis: legitimate interest in security.
Shopify’s Privacy Policy: shopify.com/legal/privacy
5.2 Cloudflare Inc. — CDN, Security, and DDoS Protection
Location: USA. Operates as a reverse proxy between visitors and servers, processing IP addresses and HTTP headers for security and performance optimization. The data is not used for commercial profiling. Transfers to the USA take place on the basis of safeguards pursuant to Art. 46 GDPR. Legal basis: legitimate interest.
Privacy Policy: cloudflare.com/privacypolicy/
5.3 Google Tag Manager (GTM) and Google Analytics 4 (GA4)
Google LLC, USA. Transfers to the USA take place on the basis of safeguards pursuant to Arts. 45 and 46 GDPR. GTM coordinates the loading of tags via Consent Mode v2: in the absence of consent, no identifying cookies are placed and the tags operate exclusively in aggregated and anonymous mode.
GA4 collects: pages visited, session duration, e-commerce events, traffic source. The service configuration is oriented towards minimizing personal data and complying with applicable law. Legal basis: consent for analytics cookies.
GA4 opt-out: tools.google.com/dlpage/gaoptout
The Site also uses Google Search Console to monitor performance in organic search results: this tool does not collect personal data of individual visitors, but provides aggregated data at the site level. Google’s Privacy Policy: policies.google.com/privacy
5.4 Google Ads
Google LLC, USA. Google Ads is implemented via Google Tag Manager and is activated exclusively upon the user's explicit consent via the cookie banner (Consent Mode v2 active: in the absence of consent no identifying cookies are placed). It allows measurement of advertising campaign conversions and remarketing activities towards users who have visited the Site. Legal basis: consent (Art. 6(1)(a) GDPR).
5.5 WhatsApp Contact Widget
The Site integrates a direct contact button via WhatsApp (Meta Platforms Ireland Ltd., Ireland — EU). Before clicking, no personal data is transmitted to the Site through this element. Communications initiated via WhatsApp are subject to the Privacy Policy of Meta Platforms Ireland. Legal basis: processing takes place at the voluntary request of the data subject who decides to initiate communication with L&Y S.r.l.s. (Art. 6(1)(b) GDPR, where applicable, or Art. 6(1)(f) GDPR for managing inquiries).
5.6 Wishlist Feature
The Site integrates an in-house developed wishlist feature that allows the authenticated B2B Customer to save preferred products. The data (product codes associated with the Customer's account) is stored in the store's system and is not shared with third parties for commercial profiling, except as strictly necessary for the platform's operation. Legal basis: performance of the contract / legitimate interest.
5.7 Shopify Messaging and Shopify Flow — Email Communications
The Site uses Shopify Messaging and Shopify Flow for two categories of email communications:
- Transactional communications (order confirmations, shipping updates): legal basis — performance of the contract (Art. 6(1)(b) GDPR)
- Marketing communications via Flow automations (new arrivals emails, abandoned cart/checkout recovery): legal basis — consent (Art. 6(1)(a) GDPR), revocable at any time via the unsubscribe link present in every e-mail
Data processed: e-mail address, order data, behavior on the Site (only for cart recovery).
5.8 Cookie Consent Management System
The Site uses a native tool integrated into the platform for collecting and managing cookie consent. The system records the preferences expressed by the user and coordinates the activation or blocking of tags via Consent Mode v2. Legal basis: legal obligation (Art. 122 of Legislative Decree 196/2003 and the 2021 Guidelines of the Italian Data Protection Authority).
5.9 Payment Gateway
Payment data is processed directly by the payment service provider used at checkout (e.g., Shopify Payments). L&Y S.r.l.s. does not store nor have access to credit or debit card data.
5.10 Contact Form (Contact Page)
The Site has a Contact page containing a contact form. The data entered (name, company name, e-mail, message text) is processed by L&Y S.r.l.s. exclusively to respond to the request received. Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR). The data is not disclosed to third parties for commercial purposes and is retained for the time necessary to manage the request and, in any case, no longer than 24 months.
6. Recipients of the Data
Personal data may be disclosed to the following categories of recipients, to the extent strictly necessary for their respective purposes:
- Carriers and shippers: delivery data (recipient name, address, phone) is communicated to the couriers responsible for shipping the orders
- Professional consultants: accountants and legal consultants, within the scope of their engagements and bound by confidentiality obligations
- Competent authorities: at the request of public authorities in cases provided for by law
- Technical service providers: the entities listed in Section 5, where applicable, acting as data processors pursuant to Art. 28 GDPR
The data is not sold or transferred to third parties for marketing purposes.
7. Transfers Outside the EU
Some providers listed in Section 5 are based outside the European Economic Area. Transfers of data to third countries take place exclusively on the basis of appropriate safeguards pursuant to Arts. 45 and 46 GDPR, including:
- Adequacy decisions adopted by the European Commission (Art. 45 GDPR), where applicable
- Adherence to the EU-US Data Privacy Framework (Art. 45 GDPR), where the provider is certified
- Standard Contractual Clauses adopted by the European Commission (Art. 46 GDPR)
For specific information on the safeguards adopted by each provider, you may contact the Controller at [email protected].
8. Data Retention
- Tax and accounting data (invoices, billing data, accounting records): 10 years, in compliance with legal obligations
- Order-related data: for the duration of the business relationship and, subsequently, for the period necessary to fulfill applicable tax and legal obligations
- Data processed on the basis of consent (marketing communications): until consent is withdrawn
- Technical data and logs (navigation, security, bot detection): for the time necessary for security and statistical purposes and in compliance with the configurations and retention periods provided by the services used
- Contact form data: no longer than 24 months from receipt of the request
9. Rights of the Data Subject (Arts. 15–22 GDPR)
The data subject has the right to: access their own data (Art. 15), request rectification (Art. 16), obtain erasure subject to legal obligations (Art. 17), restrict processing (Art. 18), exercise the right to data portability (Art. 20), object to processing based on legitimate interest (Art. 21), withdraw consent at any time without prejudice to processing carried out prior to withdrawal.
Requests may be sent to: [email protected]. L&Y S.r.l.s. reserves the right to verify the identity of the requester before acting on requests, in order to ensure the protection of personal data. A response is provided within 30 days of receipt of the complete request (extendable by a further 60 days in cases of complexity).
The data subject has the right to lodge a complaint with the competent supervisory authority. For data subjects in Italy: the Italian Data Protection Authority (garanteprivacy.it). For data subjects in other EU member states: the supervisory authority of their own country.
10. Updates
This Privacy Policy may be amended due to regulatory, organizational, or technical changes. The version published on the Site fully replaces previous versions and takes effect from the date of publication. Where required by applicable law or deemed appropriate, L&Y S.r.l.s. may inform registered users by e-mail or other appropriate channels. The version in force is always available at www.leysettimo.com. The date of last update indicates the version currently in force