Privacy & Cookie Policy

Last updated: August 2026

1. Data Controller (Titolare del Trattamento)

The Data Controller responsible for the processing of personal data collected through studiomagla.com is Studio Magla (Email: [email protected]), operating in compliance with EU Regulation 2016/679 ("GDPR") and applicable national data protection laws.

2. Legal Basis for Processing

We process personal data based on the following legal grounds under Article 6 of the GDPR:

— Performance of a Contract (Art. 6.1.b): Processing necessary to fulfill sales orders, process payments, and manage shipping/deliveries.

— Legal Obligation (Art. 6.1.c): Processing required for statutory accounting, tax obligations, and legal compliance.

— Legitimate Interest (Art. 6.1.f): Processing necessary for maintaining website security, fraud prevention, and system stability.

— Consent (Art. 6.1.a): Consent provided for non-essential analytical cookies (e.g., Google Analytics).

3. Categories of Data Collected

Depending on your interaction with the site, we collect the following data:

— Purchase & Contact Data: Full name, billing address, shipping address, email address, phone number.

— Technical & Navigation Data: IP address (anonymized), browser type, operating system, referral URLs, device information, access timestamps.

— Payment Transaction Data: Tokenized payment confirmations. We do not store or process raw credit card details on our infrastructure.

4. Third-Party Data Processors & Transfers

Personal data is shared strictly with essential third-party service providers acting as Data Processors under Article 28 GDPR. International transfers outside the EEA are governed by Standard Contractual Clauses (SCCs) or the EU-U.S. Data Privacy Framework:

— Stripe Payments Europe, Ltd. / Stripe Inc.: Secure payment processing and fraud prevention. (U.S. transfers secured via EU-U.S. DPF / SCCs).

— Google Ireland Limited (Google Analytics 4): Anonymized web usage analytics. IP addresses are truncated prior to logging/storage.

— Sanity AS: Headless Content Management System infrastructure for site data operations.

— Cloudflare Inc.: Content Delivery Network (CDN) and Web Application Firewall (WAF) for DDoS protection and secure routing.

5. Data Retention Periods

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

— Order & Tax Data: Retained for 10 years to comply with statutory accounting and tax regulations.

— Analytics Data: Retained in Google Analytics for a maximum of 14 months before automated deletion.

— Customer Support Logs: Retained for 24 months from the last resolution of the inquiry.

6. Detailed Cookie Policy

Cookies are small text files stored locally on your device during website navigation:

— Technical & Essential Cookies: Strictly required for basic core functionality, security tokens, and cart status. These do not require user consent under EU ePrivacy Directive.

— Analytical Cookies (Google Analytics): Used to measure website traffic and aggregate usage patterns. IP anonymization is active. You can opt out at any time via your browser configuration or by installing the Google Analytics Opt-out Browser Add-on.

— Profiling Cookies: Studio Magla does not utilize behavioral tracking or ad-profiling cookies.

7. Data Subject Rights (Articles 15-22 GDPR)

Under the GDPR, you hold statutory rights regarding your personal information:

— Right of Access (Art. 15): Request confirmation and copy of your personal data processed.

— Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.

— Right to Erasure / "To be Forgotten" (Art. 17): Request deletion of personal data when no longer legally required.

— Right to Restriction (Art. 18) & Object (Art. 21): Limit or object to specific processing activities.

— Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format.

8. Complaints & Supervisory Authority

To exercise your rights or ask questions, email [email protected]. If you believe your data processing infringes GDPR regulations, you have the right to lodge a complaint with your local supervisory authority (in Italy: Garante per la protezione dei dati personali — www.garanteprivacy.it).

Cart