Legal area
Privacy Policy
This Privacy Policy provides users of alanui.it (the “Site”) with the most complete and clear information on the processing of their personal data through the Site pursuant to the General Data Protection Regulation (GDPR) (EU 2016/679) and the Italian Privacy Code (Legislative Decree 196/2003). In accordance with legal obligations, this Privacy Policy also states:
- the nature of the personal data processed (as defined below);
- the purposes and methods of processing personal data;
- the identity and contact details of the data controller(s);
- any third parties involved in the processing activities;
- the personal data retention period;
- the security measures adopted to protect personal data;
- users’ privacy rights.
This Privacy Policy applies exclusively to the Site and does not concern any websites or platforms to which the Site may link. Users under the age of 16 (sixteen) are not authorised to give consent to the processing of personal data without parental authorisation.
DATA CONTROLLER
Pursuant to the GDPR, the data controller is the entity that determines the purposes and means of processing personal data. The data controller for the data relating to the Site’s activities is:
- ALANUI S.r.l. – Via Torquato Tasso 1, 20123 Milan, Italy (the “Controller”).
ALANUI S.r.l. has not appointed a Data Protection Officer. For any privacy-related request, users may contact ALANUI S.r.l. at: info@alanui.it.
PERSONAL DATA. PURPOSES OF PROCESSING.
“Personal data” means any information relating to users of the Site that personally identifies them, either alone or in combination with other information. Personal data is collected automatically by the Site or received through multiple sources: forms, chat, e-mail, apps, devices, social media and other means. The Site processes personal data in various forms for the following purposes:
BROWSING DATA
The Site collects non-sensitive browsing data using automatic tools in order to enable and improve user browsing (for example, IP address, date/time of the visit and its duration, any referring URL, pages visited on the Site, device used and other information). The processing of this information enables users to access the Site and fully use its features and services. Browsing data may also be used to verify the proper functioning of the Site. From time to time, browsing data is processed in anonymous form for statistical purposes. Browsing data is unlikely to allow the identification of the data subject. However, by its nature, browsing data may allow users to be identified if associated with other information. The browsing data described above is retained only temporarily in accordance with applicable law. The legal basis for the processing of personal data in this case is the Controller’s legitimate interest pursuant to Article 6, paragraph 1, letter f), of the GDPR.
ORDERS
At checkout, the Site requires users to provide personal data for the essential purpose of processing purchase orders and fulfilling contractual obligations (for example, name and surname, e-mail address, shipping address, etc.). Such personal data is also essential so that Customer Service can assist customers with requests and any related needs, before or after the sale (for example, in relation to the order delivery status or product returns). Personal data relating to orders will be retained for the time necessary to fulfil contractual obligations and applicable tax and accounting obligations. The Site may also verify the payment instruments used by customers to purchase on the Site (for example, credit or debit cards, etc.) mainly for the purpose of preventing fraudulent activities or pursuant to applicable anti-money laundering law. Since payment verification is entirely entrusted to third-party payment service providers, the Controller does not process or retain any financial information belonging to customers. Failure to provide the personal data requested at checkout will prevent users from completing an order on the Site. The legal basis for the processing of personal data in this case is Article 6, paragraph 1, letter b), of the GDPR (performance of a contract to which the data subject is party).
SOFT SPAM
On the basis of its legitimate interest in improving the relationship with customers, ALANUI S.r.l., as owner of the Site brand, will send customers e-mail communications with product suggestions, discounts, feedback requests or other updates. Customers are always free to unsubscribe from such e-mail communications (for example, by clicking the “unsubscribe” link at the bottom of each e-mail). The legal basis for the processing of personal data in this case is legitimate interest pursuant to Article 6, paragraph 1, letter f), of the GDPR.
REGISTRATION ON THE SITE
When users choose to register a personal account on the Site, they are required to provide personal data (for example, name, surname, date of birth, gender, e-mail address, residential or domicile address, telephone number, etc.). The Site clearly indicates which personal data is mandatory (or not) to create an account on the Site. Users must provide true and accurate personal data at the time of registration and are invited to keep their personal data updated (in case of changes) by accessing their personal account to make all relevant changes. Users who choose to enable or access their Site account through social media should be aware that, when they connect their Site account to a social media account, the Site collects certain personal data that the user has already provided to that social media (for example, the e-mail address and public profile on Facebook). The Controller does not supervise or control such social media services or users’ profiles on such services and does not establish privacy settings or rules relating to the use of personal data on such services. Users are strongly encouraged to read all policies and notices relating to the applicable social media services to learn more about how they process personal data. The legal basis for the processing of personal data in this case is the Controller’s obligation to perform an agreement (Article 6, paragraph 1, letter b), of the GDPR).
NEWSLETTERS AND MARKETING COMMUNICATIONS
On the Site, users may choose to receive newsletters and commercial communications. ALANUI always collects users’ explicit, free and unequivocal consent before sending them newsletters and marketing communications or, more generally, before undertaking electronic marketing initiatives dedicated to them. In such cases, users may be required to provide personal data in addition to their e-mail address (for example, gender, country of residence, etc.) for the purpose of personalising newsletters and marketing communications according to the user’s profile. Users may always easily withdraw their consent to receive newsletters and commercial communications in the following ways:
- through their account settings;
- by clicking the “unsubscribe” link in any such e-mail;
- by contacting our Customer Service.
The legal basis for the processing of personal data in this case is the data subject’s consent to the processing of their personal data.
PROFILING
Subject to the user’s explicit consent, newsletters and marketing communications may be personalised according to the user’s “profile”, on the basis of the personal data that ALANUI S.r.l. collects or receives regarding the relevant user. With reference to Site customers, it is in the legitimate interest of ALANUI S.r.l., as owner of the brand, to process personal data in order to offer more interesting products, improve the Site and personalise the products offered on the Site. The main purpose of profiling is to offer products, services and initiatives that are more in line with the tastes, purchasing habits and interests of users and customers. Personal data may also be used for remarketing, retargeting or profiling purposes, including through third parties (for example, social networks, etc.). Neither the Site nor the Controller will ever carry out profiling activities relating to minors. The legal basis for the processing of personal data in this case is the data subject’s consent to the processing of their personal data (Article 6, paragraph 1, letter a), of the GDPR).
LEGAL DEFENCE
Personal data may be processed for the purposes of establishing, exercising or defending the Controller’s rights, including in judicial and extrajudicial proceedings. Such processing is based on the Controller’s legitimate interest, considered overriding because it corresponds to a constitutionally protected right and is generally recognised as prevailing over the interests of the data subject. The provision of personal data for this purpose is necessary to enable the Controller to defend its rights.
COOKIES
Information relating to the cookies used on the Site is available in the COOKIE POLICY page.
SHARING AND TRANSFER OF PERSONAL DATA
The Controller may transfer customers’ personal data to primary third-party providers, acting as “data processors” (the “Processors”), for the purpose of carrying out commercial operations necessary to fulfil its contractual obligations (for example, delivery of ordered goods, payments, etc.). The Controller will make every reasonable effort to ensure that all Processors apply industry best practices to protect personal data and do not use personal data for purposes other than those agreed with the Controller. By way of example, the Controller may share personal data with the following categories of Processors:
- couriers and postal operators;
- order fulfilment centres and warehouses;
- advertising, digital, marketing and social media agencies;
- IT service providers;
- customer care service providers;
- payment service providers.
In such cases, the sharing of personal data with Processors is necessary so that the Controller can fulfil its contractual obligations and, moreover, improve the Site’s products and services. Users may request an updated list of the Processors involved in the processing of personal data relevant to the Site’s activities by writing an e-mail to: info@alanui.it. The Controller always reserves the right to disclose personal data relating to users where required by law (for example, in response to requests from authorities), and where necessary to protect the rights of the Controller or its affiliates or third parties. Furthermore, personal data may be disclosed to other companies belonging to the same corporate group as the Controller, or to third parties in the event of corporate reorganisation transactions, in full compliance with applicable law. In all other cases, the sharing of personal data will be subject to the user’s prior and explicit consent, unless the processing is permitted on the basis of another legal basis. The Controller will not transfer any personal data outside the European Economic Area (EEA), unless the user has explicitly authorised such transfer or the transfer of personal data outside the EEA is permitted by the GDPR on the basis of another legal basis.
METHODS OF PROCESSING AND SECURITY MEASURES
Users’ personal data is processed by the Controller using IT, automated and electronic tools and, in limited cases, paper media. In accordance with the GDPR, specific security measures have been implemented to prevent data loss, unlawful or improper use and unauthorised access. Only authorised employees of the Controller and authorised employees of third-party providers, acting as Processors on behalf of the Controller, have access to personal data relating to the Site’s activities. Data processing agreements are in force with the Processors in order to ensure that they always meet the level of security required by the GDPR when processing personal data relating to the Site’s activities. Although the Site adopts primary security measures to prevent the loss, destruction or dissemination of personal data, it cannot at the same time exclude the security risks naturally connected with the transmission of data online. The user accepts the inherent risks arising from the provision of personal data via the Internet and will not hold the Site liable for any security breaches, unless such breach is due to the Site’s negligence or wilful misconduct.
RETENTION OF PERSONAL DATA
The Controller will retain personal data for the time necessary to provide users and customers with the requested services, to comply with legal or tax obligations or for the minimum period required by law. The Site will promptly delete or anonymise personal data that is no longer necessary or that no longer needs to be retained under the law. Without prejudice to the right to be forgotten within the limits established by applicable law, where the retention of personal data is no longer permitted/required by law, the maximum retention period for personal data is indicated below for each type of activity:
| Activity | Data processed | Legal basis | Retention period |
| Browsing data | IP address, device data, browsing data | Controller’s legitimate interest in enabling the functioning of the Site, ensuring security and improving the user experience (Art. 6(1)(f) GDPR) | Retained for the time strictly necessary; in aggregated/anonymous form for statistical purposes |
| Orders | Identification data, contact details, purchase data | Performance of a contract to which the user is party or performance of pre-contractual measures taken at the user’s request pursuant to Art. 6(1)(b) GDPR | 10 years from the last purchase or the period required by local law |
| Soft spam | Identification data, contact details, purchase data | Legitimate interest (Art. 6(1)(f) GDPR) | 24 months from the acquisition of the personal data |
| Registration on the Site | Identification data, contact details, account data | Performance of a contract to which the user is party or performance of pre-contractual measures taken at the user’s request pursuant to Art. 6(1)(b) GDPR | 10 years from account cancellation or from termination of the contractual relationship with the user |
| Newsletters and marketing communications | Identification data, contact details, purchase data, browsing data, profiling data | User’s consent through acceptance click (Art. 6(1)(a) GDPR) | 24 months from the acquisition of the personal data |
| Profiling | Identification data, contact details, purchase data, browsing data | User’s consent through acceptance click (Art. 6(1)(a) GDPR) | 24 months from the acquisition of the personal data |
| Legal defence | Identification data, contact details, purchase data, browsing data | Controller’s legitimate interest in legal defence (Art. 6(1)(f) GDPR) | In accordance with the provisions on limitation periods with reference to contractual/non-contractual offences |
LINKS TO THIRD-PARTY WEBSITES OR PLATFORMS
The Site may contain banners, advertisements and other links to third-party websites or platforms. The Controller cannot control or be held responsible for the conduct of such third-party websites or platforms with reference to privacy legislation. Users are invited to read the relevant privacy policies to verify how such parties collect and process personal data.
USERS’ RIGHTS
Users (as data subjects) have the right to receive confirmation as to whether the Controller holds personal data concerning them. In this case, pursuant to the GDPR, users also have the right to:
- be informed about the collection and use of their personal data;
- access their personal data free of charge;
- obtain the rectification of inaccurate personal data or the completion of incomplete personal data;
- obtain the erasure of personal data (“right to be forgotten”);
- obtain, under certain conditions, the restriction or suppression of their personal data;
- obtain and reuse their personal data for personal purposes across different services when the processing is based on a contract or on consent and is carried out by automated means (“right to data portability”);
- object, under certain conditions, to the processing of their personal data;
- object at any time to the use of personal data for “profiling” or “automated decision-making” purposes;
- lodge complaints relating to the collection and processing of personal data with the competent supervisory authority;
- withdraw consent to the processing of personal data at any time, where required and given, without prejudice to the lawfulness of processing based on consent before its withdrawal;
- lodge a complaint with the competent Italian supervisory authority: Garante per la protezione dei dati personali, Piazza Venezia n. 11, 00187 Rome (RM), Italy.
Users may contact the Site for any request and to exercise their privacy rights at the following e-mail address: info@alanui.it.
CHANGES TO THIS PRIVACY POLICY
Any future changes to this Privacy Policy will be published on the Site and, where appropriate, communicated to users by e-mail. Users are invited to read this Privacy Policy frequently to check for any updates or changes.
Last updated: 14 July 2026