Privacy policy
Privacy Policy
This notice explains how S.P. International S.R.L. processes the personal data of users and customers of sphelmets.it under Regulation (EU) 2016/679 (“GDPR”), Italian Legislative Decree 196/2003 as amended, and applicable rules on electronic communications and tracking technologies.
1. Data controller
S.P. International S.R.L.
Via Giuseppe di Vittorio 33, 50145 Florence (FI), Italy
Tax code and VAT number: 04594180483
REA: FI-463940
Email: info@spinternational.it
Certified email (PEC): spinternationalsrl@cert.cna.it
2. Personal data we process
Depending on how you use the website, we may process:
- identification and contact data such as name, address, email and telephone number;
- data relating to orders, products purchased, deliveries, returns, refunds, customer support and warranties;
- customer-account data and related preferences;
- information needed for invoicing and tax obligations;
- technical and browsing information such as IP address, online identifiers, device, browser, logs and website interactions;
- newsletter, marketing, cookie and tracking preferences;
- the content of communications sent to customer service.
Full payment-card details are normally processed directly by payment providers and are not made available to S.P. International S.R.L. in full.
3. Purposes and legal bases
- Pre-contract enquiries, orders, payments, accounts, shipping, returns, refunds, support and warranties: steps taken before entering into a contract and performance of the contract.
- Tax, accounting, administrative and legal obligations: compliance with legal obligations.
- Security, fraud prevention, website protection, abuse management and defence of legal claims: legal obligations and/or the controller's legitimate interests, with due regard for data-subject rights.
- Newsletters and promotional communications: consent where required by law, except where applicable law permits communications concerning similar products or services with a right to object.
- Analytics, measurement, personalisation and non-essential tracking: consent where required.
4. How data is collected
Data may be provided directly by the user, generated through use of the website, or received from providers involved in delivering the service, such as the e-commerce platform, payment, logistics, support, analytics and security providers.
5. Providers and recipients
Data may be disclosed, to the extent necessary for their respective functions, to processors, independent controllers or authorised persons, including:
- Shopify, as e-commerce platform, technical infrastructure, customer-account and checkout provider;
- payment and financial-service providers, including Klarna when chosen by the customer;
- carriers, freight forwarders, logistics providers and shipping-management systems;
- email, customer-support, communications and IT providers;
- analytics, measurement and session-replay providers, including Lucky Orange if and to the extent the service is active and subject to consent where required;
- translation/localisation, consent-management and other technical providers that may be active on the website;
- accountants, legal advisers, insurers and public authorities where necessary or legally required.
The list of providers may change over time depending on the services actually used.
6. Klarna payments
If you choose a Klarna payment method, certain contact, order and transaction data may be sent to Klarna so that it can process the payment, assess eligibility for the selected method and perform the activities described in its own privacy notice. Klarna may act as an independent controller for those processing activities.
7. Cookies and other tracking technologies
The website uses cookies and similar technologies necessary for its operation and, subject to consent where required, analytics, measurement, personalisation or marketing tools.
Preferences can be managed through the cookie banner or consent-management panel available on the website. Non-essential tools are activated only in accordance with applicable law and the user's choices.
8. Transfers outside the EEA
Some providers may process data in countries outside the European Economic Area. In such cases, transfers are based on an adequacy decision by the European Commission or on other safeguards under Articles 44 and following of the GDPR, such as Standard Contractual Clauses, where applicable.
9. Retention periods
Data is retained for as long as necessary for the purposes for which it was collected and thereafter for periods required or permitted by law.
- Order, invoicing and accounting data may be retained for statutory tax and civil-law periods, normally up to 10 years.
- Support, return and warranty data is retained for the time needed to handle the request and any subsequent protection of legal rights.
- Marketing data is processed until consent is withdrawn or the user objects, subject to limited retention needed to document preferences.
- Data collected through cookies and tracking technologies is retained for the periods shown in the consent panel or in the relevant provider notices.
10. Your rights
Where provided by the GDPR, you may exercise rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, without affecting the lawfulness of processing carried out before withdrawal.
To exercise your rights, write to info@spinternational.it or to our certified email spinternationalsrl@cert.cna.it.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
11. Minors
The website and sales services are not specifically directed at minors. Purchases must be made by persons with the legal capacity required to enter into a valid contract or with the involvement of a parent or guardian.
12. Automated decision-making
As a rule, S.P. International S.R.L. does not make decisions based solely on automated processing that produce legal or similarly significant effects for the user. Certain payment providers, such as Klarna, may independently perform automated checks under their own notices.
13. Security
We use technical and organisational measures appropriate to the risk to protect personal data. No system can guarantee absolute security.
14. Changes to this policy
This policy may be updated following legal, organisational or technological changes. The version published on the website is the version applicable at the time it is consulted.