Privacy policy
Information notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
Last updated: 1 July 2026
AMMETTI S.R.L. (“AMMETTI”, “we”, “us” or “our”) manufactures and sells hair-care and cosmetic products, and operates the online store available at ammetti.com (the “Website” or the “Services”). We take the protection of your personal data seriously. This notice explains, in a transparent way, how we collect, use, disclose and retain your personal data when you visit, browse, register on, or make a purchase through the Website, or otherwise communicate with us, and the rights you may exercise under applicable data-protection law, in particular the GDPR and Italian Legislative Decree No. 196/2003 (the “Italian Privacy Code”).
Our Website is hosted on the Shopify platform, which enables us to provide the Services to you and processes certain personal data on our behalf and, in some cases, as an independent controller. This notice should be read together with our Cookie Policy, which describes the cookies and similar technologies used on the Website, and with our Terms of Service.
1. Data Controller
The data controller responsible for the processing of your personal data is:
AMMETTI S.R.L.
• Registered office: Viale Affori 19, 20161 Milan (MI), Italy
• VAT / Tax code (P.IVA): 14684450969
• E-mail: info@ammetti.com
Given the nature and scale of our processing activities, we are not required to appoint a Data Protection Officer (DPO) under Article 37 of the GDPR. For any question relating to this notice or to the processing of your personal data, you may contact us at info@ammetti.com.
2. Categories of personal data we process
Depending on how you interact with the Services, we may collect or process the following categories of personal data (Article 4(1) GDPR), including inferences drawn from them:
• Identification and contact data – first name, surname, billing and shipping address, telephone number, e-mail address, and, where applicable, date of birth.
• Account data – username, password, preferences and settings for the registered area of the Website.
• Order and transaction data – products viewed, added to cart or wishlist, purchased, returned, exchanged or cancelled, and your order history.
• Payment data – form of payment, payment-card and financial-account details, transaction details and payment confirmations (card data is processed by our payment providers; we do not store full card numbers).
• Communications – the content of your enquiries, customer-support messages, reviews and other communications with us.
• Technical and usage data – IP address, device, browser and operating-system information, unique identifiers, and information about how and when you interact with the Website (see also the Cookie Policy).
• Marketing data – your marketing preferences and consents and your interaction with our newsletters and campaigns.
3. Sources of personal data
• Directly from you – when you create an account, browse or use the Website, place an order or communicate with us.
• Automatically – from your device and through cookies and similar technologies when you use the Website.
• From Shopify and our service providers – where they collect or process personal data in order to provide the Services.
• From partners and other third parties – for example, marketing or advertising partners, where permitted by law.
4. Purposes of the processing, legal bases and retention periods
We process your personal data for the purposes and on the legal bases set out below. For each group of purposes we indicate the applicable retention period.
4.1 – Performance of a contract or pre-contractual measures (Article 6(1)(b) GDPR)
• Concluding and performing your purchase contract, including processing orders and payments, fulfilment, shipping, and handling returns and exchanges;
• Creating and managing your account in the restricted area of the Website;
• Handling your requests, enquiries and customer-service interactions.
Retention: for the duration of the relationship and for 10 years from the end of the contract or legal relationship (in line with the ordinary limitation period under Article 2946 of the Italian Civil Code), except where longer retention is required by a dispute or a specific legal provision. Account data is retained until you request deletion of the account; an account inactive for more than 10 years may be deleted on our initiative.
4.2 – Compliance with a legal obligation (Article 6(1)(c) GDPR)
• Fulfilling accounting, tax, invoicing and other obligations under applicable laws and regulations;
• Complying with consumer-protection obligations (e.g. Italian Legislative Decree No. 206/2005, the Consumer Code) and with requests from competent authorities.
Retention: generally 10 years (e.g. Article 2220 of the Italian Civil Code for accounting records), or the different period required by the applicable legal obligation.
4.3 – Legitimate interests of the controller (Article 6(1)(f) GDPR)
• Preventing, detecting and investigating fraud, and ensuring a secure payment and shopping experience;
• Monitoring the proper functioning and security of the Website and carrying out aggregated, statistical analysis of its use;
• Sending you, by e-mail, marketing communications about our own products that are similar to those you have already purchased (“soft opt-in”), and reminders about items left in your basket, subject to your right to object at any time;
• Establishing, exercising or defending legal claims.
Retention: for soft opt-in marketing, up to 24 months from your last purchase; abandoned-cart reminders, up to 48 hours from the cart being filled; security and fraud-prevention data, for the time needed to complete the related checks and administrative formalities and, in any event, no longer than necessary for the underlying purpose or to protect our rights.
4.4 – Consent of the data subject (Article 6(1)(a) GDPR)
• Sending newsletters, promotional material and invitations to events, including to individuals who are not existing customers;
• Marketing carried out through automated means (e.g. e-mail, SMS and instant-messaging systems) and non-automated means (e.g. operator calls);
• Profiling activities intended to analyse or predict your preferences and purchasing habits in order to send you offers tailored to your profile;
• Use of non-essential cookies and similar technologies, as described in the Cookie Policy.
Retention: up to 24 months from the date consent is given, or until you withdraw your consent, whichever is earlier. You may withdraw consent at any time, with effect for the future; processing carried out before withdrawal remains lawful.
5. Recipients and categories of recipients (Article 13(1)(e) GDPR)
In connection with the purposes above, your personal data may be disclosed to the following categories of recipients, who act either as data processors appointed under Article 28 of the GDPR or as independent controllers:
• Shopify – as the platform provider hosting the Website (see Section 6);
• Payment providers – Shopify Payments / Stripe / PayPal, for the secure processing of payments;
• Shipping and logistics providers – couriers and companies involved in packaging and dispatch;
• Marketing and communications providers – Klaviyo / Mailchimp, and advertising/analytics partners such as Google, Meta;
• IT and technical service providers – hosting, data storage, software management and IT consultancy;
• Professional advisers – accountants, lawyers and compliance consultants;
• Public authorities and bodies – within the scope of their institutional duties or in response to lawful requests.
We do not sell your personal data. An up-to-date list of recipients is available from us on request at the contact details in Section 1.
6. Relationship with Shopify
The Services are hosted by Shopify, which collects and processes personal data relating to your access to and use of the Website in order to provide and improve the Services. Information you submit will be transmitted to and shared with Shopify and with third parties that may be located outside your country of residence. To provide certain enhanced features, Shopify may also use data about your interactions with our store, other merchants and Shopify itself; in those circumstances Shopify acts as an independent controller. To learn more, please see the Shopify Consumer Privacy Policy and, where applicable, exercise your rights through the Shopify Privacy Portal.
7. Transfers of personal data outside the EEA (Article 13(1)(f) GDPR)
Some of our providers (including Shopify and certain marketing or analytics tools) may process personal data in countries outside the European Economic Area, including the United States. Where such transfers occur, we rely on an appropriate safeguard under Chapter V of the GDPR, namely: (i) an adequacy decision of the European Commission (Article 45 GDPR), including, where the recipient is certified, the EU–US Data Privacy Framework; or (ii) the European Commission’s Standard Contractual Clauses (Article 46 GDPR), together with any supplementary measures required. You may obtain a copy of the safeguards in place by contacting us at the details in Section 1. The list of countries recognised as adequate by the European Commission is available here.
8. Your rights
Subject to the conditions and exceptions provided by law, you have the right to exercise the following rights in relation to your personal data:
• Access (Art. 15) – to obtain confirmation of, and information about, the processing of your data and a copy of it;
• Rectification (Art. 16) – to have inaccurate or incomplete data corrected;
• Erasure / “right to be forgotten” (Art. 17);
• Restriction of processing (Art. 18);
• Data portability (Art. 20) – to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller;
• Objection (Art. 21) – including the right to object at any time to processing for direct-marketing purposes;
• Not to be subject to automated decision-making, including profiling, that produces legal or similarly significant effects (Art. 22);
• Withdrawal of consent – where processing is based on consent, at any time and without affecting the lawfulness of prior processing.
To exercise these rights, please contact us at info@ammetti.com. We may need to verify your identity before responding, and we will reply within the time limits set by applicable law. You will not be treated unfairly for exercising your rights.
9. Right to lodge a complaint
If you consider that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the supervisory authority of your habitual residence or place of work, without prejudice to any other administrative or judicial remedy.
10. Nature of the provision of data and consequences of failure to provide it
Providing data required to perform the contract or to comply with a legal obligation is necessary; without it, we cannot process your order or provide the requested Services. Providing data for marketing, profiling and other consent-based purposes is optional: refusing or withdrawing consent will not affect the provision of the products you purchase, but may prevent us from carrying out the specific activities for which consent was requested.
11. Automated decision-making and profiling
We do not use solely automated decision-making processes producing legal or similarly significant effects within the meaning of Article 22 of the GDPR. Should this change, we will inform you and, where required, obtain your consent.
12. Methods and security of processing
Personal data is processed by electronic and, where necessary, manual means, by staff authorised and instructed by the controller, using appropriate technical and organisational measures to ensure the confidentiality, integrity, availability and security of the data. During normal operation, the Website’s systems automatically acquire certain data whose transmission is inherent in the use of internet protocols (such as IP addresses, browser and operating-system type, and request times); this data is used to operate and secure the Website and to establish liability in the event of offences against it. Please note that no security measure can guarantee absolute security, and information transmitted over the internet may not be fully secure in transit.
13. Minors
The Services are not directed to children. In Italy, individuals under the age of 14 may not provide personal data or consent to processing in connection with information-society services without the authorisation of the holder of parental responsibility. We do not knowingly collect personal data from children below that age. If you believe a child has provided us with personal data, please contact us so that we can delete it.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. We will post the revised version on this page and update the “Last updated” date, providing notice as required by law. We encourage you to review this page periodically.
15. Contact
For any question about this Privacy Policy or our data-protection practices, or to exercise your rights, please contact:
AMMETTI S.R.L. – Viale Affori 19, 20161 Milan (MI), Italy
E-mail: info@ammetti.com
