Privacy Notice

Last updated: 25 July 2026

This Privacy Notice describes how Barbiconi S.r.l., as Data Controller, collects and processes the personal data of users who visit and use the website www.barbiconi.it, including when making online purchases.

This Privacy Notice is provided pursuant to Articles 12, 13 and 14 of Regulation (EU) 2016/679, hereinafter referred to as the “GDPR”, and the applicable Italian legislation on the protection of personal data.

1. Data Controller

The Data Controller is:

Barbiconi S.r.l.
Registered office: Via Santa Caterina da Siena 58/60, 00186 Rome, Italy
VAT number: 00873181002
Tax code: 00141150581
Email: info@barbiconi.it
Certified email address (PEC): barbiconi@pec.it
Telephone: +39 06 679 4985

For any request concerning the processing of personal data or the exercise of the rights provided for under the GDPR, data subjects may contact the Data Controller using the contact details set out above.

2. Categories of Personal Data Processed

The following categories of personal data may be processed through the website.

2.1 Browsing Data

The IT systems and software procedures used to operate the website acquire, during their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols.

Such data may include:

  • IP address;

  • type of browser and device used;

  • operating system;

  • date and time of access;

  • pages visited;

  • addresses of the requested resources;

  • technical information required for the operation and security of the website.

These data are used to ensure the proper operation of the website, protect the security of the systems, prevent misuse and obtain technical information regarding the use of the services.

2.2 Data Provided When Registering an Account

When a user creates an account on the website, the following data may be collected:

  • first name and surname;

  • email address;

  • password, stored in protected form;

  • billing and shipping address;

  • telephone number;

  • any information relating to organisations, institutions, parishes, dioceses, religious communities or other organisations;

  • tax code or VAT number, where required;

  • information relating to orders placed.

2.3 Data Provided When Placing an Order

The following data may be processed in order to manage an online purchase:

  • first name and surname;

  • shipping address;

  • billing address;

  • email address;

  • telephone number;

  • tax code or VAT number, where required;

  • products purchased;

  • sizes, measurements, customisations and preferences relating to the garments ordered;

  • payment amount and payment status;

  • shipping and delivery information;

  • any communications sent by the customer in connection with the order.

2.4 Payment Data

Card payments are managed through Nexi and PayPal.

Neither the website nor the Data Controller directly acquires or stores the full card number, security code or banking credentials used to make the payment.

The data required to process the payment are transmitted directly to the provider through secure connection systems. The Data Controller may receive information from the provider such as:

  • payment outcome;

  • amount paid;

  • transaction identifier;

  • date and time of the transaction;

  • any information required to manage refunds, disputes or anti-fraud checks.

The payment provider processes personal data in accordance with its own privacy notice, which users are invited to read before completing a payment.

2.5 Data Provided in Communications

When a user contacts the Data Controller by email, telephone, certified email, contact form or any other available channel, the following data may be processed:

  • identification and contact details;

  • content of the request;

  • any documents or images attached;

  • information required to provide assistance;

  • data relating to orders, payments, shipments, returns or complaints.

Users are invited not to provide personal data that are not necessary, particularly data belonging to special categories of personal data under Article 9 of the GDPR.

3. Purposes, Legal Bases and Nature of the Provision of Data

3.1 Website Browsing and Operation

Browsing data are processed in order to:

  • allow the website to be displayed and operate correctly;

  • maintain the shopping cart and account functions;

  • ensure the security of the website;

  • prevent unauthorised access, fraud and unlawful use;

  • diagnose and resolve technical issues.

The legal bases for the processing are the performance of measures requested by the user, the performance of a contract and the legitimate interest of the Data Controller in ensuring the security and proper operation of its systems.

The provision of technical data is necessary in order to use the website.

3.2 Account Creation and Management

Personal data are processed in order to:

  • create a personal account;

  • allow access to the restricted area;

  • store addresses and information useful for making purchases;

  • view order history;

  • manage the functions connected with the account.

The legal basis for the processing is the performance of pre-contractual measures taken at the user’s request and the performance of a contract.

The provision of data marked as mandatory is necessary in order to create and use an account.

3.3 Management of Orders and the Contract of Sale

Personal data are processed in order to:

  • receive and confirm orders;

  • verify product availability;

  • prepare and package products;

  • carry out any requested customisations;

  • manage payments;

  • issue tax documents;

  • arrange shipping and delivery;

  • provide updates concerning the order;

  • manage returns, replacements, refunds, complaints and warranties;

  • provide pre-contractual and after-sales assistance.

The legal basis for the processing is the performance of pre-contractual measures taken at the data subject’s request and the performance of the contract of sale.

The provision of the data required to place an order is mandatory. Without such data, it will not be possible to enter into or perform the contract.

3.4 Compliance with Legal, Tax and Accounting Obligations

Personal data may be processed in order to:

  • issue and retain invoices, receipts and accounting documents;

  • comply with tax and fiscal obligations;

  • respond to requests from the competent authorities;

  • comply with obligations imposed by laws, regulations or administrative measures.

The legal basis for the processing is compliance with a legal obligation to which the Data Controller is subject.

The provision of data required by law is mandatory.

3.5 Assistance and Management of Requests

Personal data are processed in order to:

  • respond to users’ requests;

  • provide information about products;

  • assist customers in choosing sizes, models or customisations;

  • manage requests concerning orders, payments, shipments, returns or refunds;

  • retain correspondence required to manage the relationship with the customer.

The legal basis for the processing is the performance of pre-contractual measures, the performance of a contract or the legitimate interest of the Data Controller in properly managing the requests received.

3.6 Fraud Prevention and Protection of Rights

Personal data may be processed in order to:

  • prevent fraudulent orders;

  • verify unusual transactions;

  • protect the website and users’ accounts;

  • establish, exercise or defend a legal claim in judicial or out-of-court proceedings;

  • manage disputes, unpaid amounts and unlawful conduct.

The legal basis for the processing is the legitimate interest of the Data Controller in ensuring the security of transactions and protecting its rights.

The processing is carried out in compliance with the fundamental rights and freedoms of data subjects.

4. Processing Methods

Personal data are processed using IT, electronic and, where necessary, paper-based tools.

The Data Controller adopts appropriate technical and organisational measures to protect personal data against:

  • loss;

  • destruction;

  • alteration;

  • unauthorised access;

  • unlawful disclosure;

  • misuse;

  • processing that is incompatible with the stated purposes.

Access to personal data is permitted exclusively to authorised personnel and to suppliers who require access in order to perform their activities.

5. Recipients of Personal Data

Personal data may be disclosed, to the extent necessary, to the following categories of recipients:

  • personnel and collaborators authorised by the Data Controller;

  • IT service providers;

  • hosting and server providers;

  • developers, technicians and maintenance providers for the PrestaShop website;

  • payment providers;

  • banks and credit institutions;

  • couriers, shipping companies and logistics operators;

  • suppliers responsible for preparing or customising products, where necessary;

  • tax, accounting, administrative and legal advisers;

  • insurance companies;

  • parties responsible for managing returns, refunds or debt recovery;

  • public authorities, supervisory bodies, law enforcement authorities and judicial authorities, where required by law.

Parties processing personal data on behalf of the Data Controller are appointed, where necessary, as Data Processors pursuant to Article 28 of the GDPR.

Personal data are not publicly disclosed.

6. Payment Providers

Card payments are managed by Nexi and PayPal.

Depending on the circumstances and the services provided, the payment provider may operate as an independent Data Controller or as a Data Processor.

Before using the payment service, users are invited to read the privacy notice provided by the relevant payment provider.

7. Shipping and Delivery

In order to deliver purchased products, the Data Controller discloses to the courier or shipping company only the data required for delivery, such as:

  • the recipient’s first name and surname;

  • delivery address;

  • telephone number;

  • email address, where necessary;

  • operational information relating to delivery.

The courier may contact the recipient to arrange or facilitate delivery.

The data are processed for the performance of the contract of sale.

Courier used: Bartolini.

8. Transfers of Personal Data Outside the European Economic Area

The Data Controller gives preference to suppliers that process personal data within the European Economic Area.

Where the use of a supplier involves the transfer of personal data to countries outside the European Economic Area, the transfer will be carried out in accordance with Articles 44 et seq. of the GDPR and on the basis of one of the safeguards provided for by applicable legislation, such as:

  • an adequacy decision adopted by the European Commission;

  • Standard Contractual Clauses;

  • Binding Corporate Rules;

  • another legally recognised transfer mechanism.

Data subjects may contact the Data Controller to obtain further information about any international transfers of personal data.

9. Retention Periods

Personal data are retained for the period necessary to fulfil the purposes for which they were collected.

In particular:

  • account data are retained until the user requests the deletion of the account, without prejudice to any data that must be retained in order to comply with legal obligations or protect the rights of the Data Controller;

  • data relating to orders and contracts are retained for the period necessary to perform the contract and, thereafter, for the applicable limitation period;

  • invoices, tax documents and accounting records are retained for the period required under tax and accounting legislation, normally ten years;

  • payment data are retained for the time necessary to manage the transaction, any refunds, disputes and legal obligations;

  • correspondence relating to customer support is retained for the time necessary to manage the request and, thereafter, for the period necessary to protect the rights of the Data Controller;

  • security logs are retained for a period proportionate to the purposes of security and prevention of misuse;

  • data required to manage disputes are retained until the dispute has been finally resolved and the applicable time limits for appeals have expired.

At the end of the applicable retention period, personal data are deleted, anonymised or retained exclusively where required by law.

10. Cookies and Tracking Technologies

The website uses technical cookies and other technologies required to:

  • enable browsing;

  • maintain the user’s active session;

  • manage the shopping cart;

  • store selected products;

  • allow access to the account;

  • ensure the security of the website;

  • complete the purchasing process.

The use of any analytical, advertising, profiling or third-party cookies is described in the website’s specific Cookie Policy.

Where required by law, such technologies are activated only after the user has provided consent through the cookie banner or the preference management panel.

11. Minors

The website and its online sales services are not specifically intended for persons under the age of 18.

Purchases must be made by adults or with the assistance and authorisation of a parent or a person exercising parental responsibility.

If the Data Controller becomes aware that a minor’s data have been collected without the necessary legal grounds, the Data Controller will delete such data to the extent permitted by law.

12. Automated Decision-Making

Unless otherwise stated in connection with specific services, the Data Controller does not make decisions based solely on automated processing that produce legal effects concerning the data subject or similarly significantly affect the data subject.

The tools used by payment providers may carry out automated checks for fraud-prevention purposes. Further information is available in the relevant provider’s privacy notice.

13. Rights of the Data Subject

Data subjects may exercise the rights provided for under Articles 15 to 22 of the GDPR and, in particular, may request:

  • confirmation as to whether or not personal data concerning them are being processed;

  • access to their personal data;

  • rectification of inaccurate personal data;

  • completion of incomplete personal data;

  • erasure of personal data, where the applicable requirements are met;

  • restriction of processing;

  • data portability, where applicable;

  • objection to processing based on legitimate interest;

  • withdrawal of consent, where the processing is based on consent;

  • information concerning the source of the personal data, the purposes of the processing, the recipients and the applicable retention periods;

  • not to be subject to a decision based solely on automated processing, where provided for by law.

The withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

To exercise their rights, data subjects may submit a request to:

Email: barbiconi@pec.it
Postal address: Barbiconi S.r.l. – Via Santa Caterina da Siena 58/60, 00186 Rome, Italy

The Data Controller may request the information necessary to verify the identity of the person making the request.

The request will be handled within the time limits established by the GDPR.

14. Right to Lodge a Complaint with the Supervisory Authority

Data subjects who believe that the processing of their personal data infringes applicable data protection legislation may lodge a complaint with:

Italian Data Protection Authority — Garante per la protezione dei dati personali
Piazza Venezia 11
00187 Rome, Italy
Website: www.garanteprivacy.it

This is without prejudice to the data subject’s right to seek a judicial remedy before the competent courts.

15. Links to Third-Party Websites and Services

The website may contain links to websites, services or platforms managed by third parties.

The Data Controller does not control how such third parties process personal data. Users are therefore invited to read the relevant privacy notices before using such services.

16. Changes to This Privacy Notice

The Data Controller may amend or update this Privacy Notice in order to reflect:

  • changes in applicable legislation;

  • measures adopted by the competent authorities;

  • changes to the services provided;

  • technical or organisational changes to the website;

  • the introduction or replacement of suppliers.

The updated version will be published on this page, together with the date of the latest update.

In the event of significant changes, the Data Controller may inform users through the website or by using the available contact details.

17. Contact Details

For information concerning the processing of personal data:

Barbiconi S.r.l.
Via Santa Caterina da Siena 58/60
00186 Rome, Italy
Email: info@barbiconi.it
Certified email address (PEC): barbiconi@pec.it
Telephone: +39 06 679 4985

Product added to wishlist
Product added to compare.

This website uses cookies

We use cookies to personalize content and ads, to provide social media features and to analyze our traffic.
We also share information about how you use our site with our partners who deal with web analytics, advertising
and social media, who may combine it with other information that you have provided to them or that they collected from your use of their services.