PRIVACY POLICY

INFORMATION ON THE PROCESSING OF PERSONAL DATA PURSUANT TO ART. 13 OF REGULATION (EU) 2016/679

Pursuant to Article 13 of Regulation (EU) 2016/679 ("GDPR"), this privacy policy is provided by PÉPÉ S.R.L. regarding the processing of personal data carried out through the website www.pepechildrenshoes.com (hereinafter, the "Site").


PÉPÉ S.R.L., in its capacity as Data Controller, provides users of the Site with information regarding the methods of collection, use, retention, communication, and protection of personal data processed in the context of browsing, registering a user account, purchasing products, subscribing to the newsletter, managing commercial relationships, and using online services.


The processing of personal data is carried out in compliance with the principles of lawfulness, fairness, transparency, purpose limitation, storage limitation, data minimization, accuracy, integrity, and confidentiality, as well as the principle of accountability under Article 5 of the GDPR.


This information policy does not apply to other websites that may be accessible via links on the Site provided by third parties, for which reference should be made to their respective privacy policies.

DATA CONTROLLER

The Data Controller of personal data is PÉPÉ S.R.L., with registered office at Viale dei Mille n. 51, 27029 Vigevano (PV), Italy, Tax Code and VAT No. 00283040186.


The Data Controller can be contacted at the following details:

TYPES OF PERSONAL DATA PROCESSED

1. Navigation Data

The computer systems and software procedures used to operate the Site acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.


These include, by way of example:

  • IP addresses;
  • URI (Uniform Resource Identifier) addresses of requested resources;
  • Date and time of the request;
  • Method used to submit the request to the server;
  • Numerical code indicating the status of the response given by the server;
  • Parameters relating to the user's operating system and IT environment;
  • Information regarding the device used for browsing.

Such data are processed exclusively to ensure the proper functioning of the Site, the security of computer systems, the prevention of unlawful use, and to ascertain responsibility in the event of cyberattacks or unlawful conduct.

2. Data Provided Voluntarily by the User

Users may voluntarily provide personal data by filling out forms on the Site, registering an account, sending contact or support requests, subscribing to the newsletter, and making online purchases.


The processed data may include:

  • First and last name;
  • Email address;
  • Phone number;
  • Billing and shipping address;
  • City, postal code, province/state, and country;
  • Date of birth, where requested;
  • Content of sent communications;
  • Data relating to orders placed;
  • Any additional information voluntarily provided by the user.

Such data are processed exclusively to manage received requests, account registration and administration, order execution, payments, shipping, returns, customer support, compliance with contractual and legal obligations, and, subject to the data subject's consent where required, sending informational and promotional communications.

3. Data Relating to Purchases and Commercial Transactions

In the event of product purchases through the Site, the Data Controller processes data necessary to manage the order, billing, payment, shipping, potential exercise of the right of withdrawal, returns, and post-sale support.


Payment details are processed directly by the payment service providers used by the Site in accordance with their respective privacy policies; the Data Controller does not acquire or store full payment card details.

4. Data Processed for Marketing Purposes

Subject to the data subject's consent, where required by applicable law, the Data Controller may process the email address and other contact details provided by the user to send newsletters, commercial communications, promotions, and information regarding products and services offered, as well as to perform marketing and remarketing activities using tools embedded in the Site.

PURPOSES AND LEGAL BASES OF PROCESSING

Personal data collected through the Site are processed for the following purposes:

a) Site Browsing and Usage

Navigation data are processed to ensure the proper functioning of the Site, maintain IT systems security, prevent illegal activity, and improve the user browsing experience.


Legal basis:
Art. 6(1)(f) GDPR – legitimate interest of the Data Controller to ensure the security and proper functioning of its IT systems.

b) Handling Inquiries and Customer Support

Data voluntarily provided via contact details on the Site, contact forms, or support tools are processed to answer requests, provide product information, and manage support, returns, and pre-contractual measures.


Legal basis:
Art. 6(1)(b) GDPR – execution of pre-contractual measures taken at the request of the data subject.

c) User Account Registration and Management

Personal data provided during registration are processed to enable account creation, access to restricted areas, viewing order history, and managing user preferences.


Legal basis:
Art. 6(1)(b) GDPR – performance of a contract or pre-contractual measures requested by the data subject.

d) Order Processing and Sales Management

Personal data are processed to handle purchases on the Site, execute sales contracts, process payments, manage billing and shipping, send order status updates, deliver post-sale support, handle returns or withdrawals, and execute logistics.


Legal basis:
Art. 6(1)(b) GDPR – performance of a contract to which the data subject is party.

e) Legal Compliance

Data may be processed to fulfill duties under applicable legal regulations, including administrative, tax, accounting, and document retention obligations.


Legal basis:
Art. 6(1)(c) GDPR – compliance with a legal obligation to which the Data Controller is subject.

f) Newsletters and Commercial Communications

Subject to user consent, the Data Controller may use contact details to send newsletters, promotional offers, and news about products sold on the Site. Additionally, for email addresses provided during a product sale, the Data Controller may send commercial communications for similar products without prior consent under Art. 130(4) of Italian Legislative Decree 196/2003 ("soft spam"), provided the data subject has not initially or subsequently opted out. Users can object to these communications at any time, free of charge, and easily.


Legal basis:
For standard newsletters and marketing, Art. 6(1)(a) GDPR – user consent. For soft spam email communications, Art. 130(4) of Italian Legislative Decree 196/2003, as an exception to consent rules for electronic communications.


Consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal. The right to object to soft spam communications remains unaffected at all times.

g) Protection of Rights

Data may be processed to establish, exercise, or defend the Data Controller's rights in judicial, administrative, or out-of-court settings.


Legal basis:
Art. 6(1)(f) GDPR – legitimate interest of the Data Controller in protecting its legal rights.

h) Cookie Management and Tracking Tools

Data collected via cookies and tracking tools are processed according to the Site's Cookie Policy, which details tool categories, purposes, and preference management options.


Legal basis:
For technical cookies, Art. 6(1)(f) GDPR. For analytical, profiling, and marketing cookies, Art. 6(1)(a) GDPR – user consent.

PROVISION AND PROCESSING METHODS OF PERSONAL DATA

Providing personal data is optional; however, failure to provide data marked as mandatory or necessary for account registration, order placement, shipping, service delivery, or support may prevent the Data Controller from fulfilling user requests or providing services.


Browsing data are collected automatically during site usage; their processing is mandatory to ensure technical operation and system security.


Data are processed by personnel authorized and instructed by the Data Controller under Art. 29 GDPR and Art. 2-quaterdecies of Italian Legislative Decree 196/2003, and may be handled by third parties supplying operational services for website management, e-commerce, payments, shipping, support, IT infrastructure, and marketing. These entities operate as Data Processors under Art. 28 GDPR or as independent Data Controllers.


Appropriate technical and organizational security measures are adopted pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk and protect data from unauthorized access, loss, destruction, disclosure, or misuse.


RETENTION AND DELETION OF DATA

Personal data are retained only as long as necessary to achieve the specific purposes for which they were collected, in accordance with the storage limitation principle of Art. 5 GDPR.


Specifically:

  • Browsing data: Retained strictly for the time necessary to ensure Site operation, security, and defense against cybercrime or legal claims.
  • Contact inquiries / Support data: Retained for the time needed to resolve the request, and no longer than 24 months from resolution.
  • Account data: Retained until account deletion is requested, or up to 24 months of inactivity, unless longer retention is required by law or for legal protection.
  • Order, transaction, billing, and tax records: Retained for the period required by law, typically 10 years following contract completion.
  • Marketing and newsletter data: Retained until consent is withdrawn, subject to periodic reviews, with automatic deletion or renewal after 24 months of inactivity.
  • Legal claims: Data may be retained longer if required to establish, exercise, or defend rights in court or out-of-court proceedings.

Upon expiration of the applicable retention period, data will be deleted, anonymized, or securely archived according to legal regulations and system backup schedules.

COMMUNICATION AND SHARING OF PERSONAL DATA

Personal data may be accessed by authorized internal personnel instructed pursuant to Art. 29 GDPR and Art. 2-quaterdecies of Italian Legislative Decree 196/2003 within the scope of their assigned duties.


Data may also be disclosed or made accessible to third-party providers servicing Site operations and commercial activities, including:

  • Hosting, cloud computing, and IT infrastructure providers;
  • E-commerce platform software providers;
  • Electronic payment service providers;
  • Couriers and shipping/delivery agencies;
  • Technical support and IT maintenance vendors;
  • Marketing, newsletter, and communication platform providers;
  • Administrative, tax, legal, or IT consultants and professionals;
  • Public authorities, entities, or bodies as required by law.

These recipients process data strictly within the limits necessary for their duties, acting as Data Processors (Art. 28 GDPR) or independent Data Controllers. Personal data are never disseminated to the public.


DATA TRANSFERS OUTSIDE THE EEA

Certain service providers used by the Data Controller may involve data transfers outside the European Economic Area (EEA).


In such cases, transfers occur in full compliance with Articles 44 et seq. of Regulation (EU) 2016/679, relying on European Commission Adequacy Decisions or appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission.

RIGHTS OF THE DATA SUBJECT

Data subjects may exercise their rights under Articles 15 to 22 of Regulation (EU) 2016/679 at any time, including the right to:

  • Access personal data and obtain confirmation of their existence or processing;
  • Request the rectification of inaccurate data or completion of incomplete data;
  • Request the erasure of personal data ("right to be forgotten") under Art. 17 GDPR;
  • Request restriction of processing under Art. 18 GDPR;
  • Receive personal data in a structured, commonly used, machine-readable format and transfer them to another controller (data portability) under Art. 20 GDPR;
  • Object to processing based on legitimate interest at any time, for reasons related to a specific personal situation;
  • Withdraw consent at any time without affecting the lawfulness of processing performed before withdrawal;
  • Not be subject to decisions based solely on automated processing under Art. 22 GDPR.

Requests to exercise rights can be sent to the Data Controller using the contact details provided in this document. The Data Controller will respond without undue delay and at the latest within one month, expandable under Art. 12 GDPR if necessary.


Il Titolare fornirà riscontro senza ingiustificato ritardo e, comunque, entro un mese dal ricevimento della richiesta, salvo proroga nei casi previsti dall'art. 12 del GDPR.


If a data subject believes their data are being processed in violation of applicable laws, they have the right to lodge a complaint with the Data Protection Authority (Garante per la protezione dei dati personali) pursuant to Art. 77 GDPR, or initiate legal proceedings.


Further details and rights request forms are available on the Italian Privacy Authority's official website www.garanteprivacy.it.

COOKIES

The Site uses cookies and tracking tools necessary for operation and, subject to user consent, for statistical, analytical, and marketing purposes. Detailed information regarding categories, retention periods, third parties, and consent management can be found in the Cookie Policy published on the Site.

CHANGES TO THIS PRIVACY POLICY

The Data Controller reserves the right to amend or update this policy at any time due to legal updates, regulatory decisions, technological changes, or modifications in data processing practices.


Updates will be published on the Site and take effect immediately upon publication. Users are encouraged to review this policy periodically.

Last updated: 23/09/2026

The Data Controller
PÉPÉ S.R.L.