Last updated: 9 September 2026
This notice explains how personal data is processed when users visit strassoutlet.com, create an account, place an order, request support or use other website services, in accordance with Regulation (EU) 2016/679 (the "GDPR") and applicable Italian law.
1. Data controller
The data controller is Punto GT Crystal di Salvatore Puglisi, Viale Mario Rapisardi 199, 95123 Catania (CT), Italy, VAT number 03650250875.
For questions about personal data or to exercise your rights, email info@strassoutlet.com or call +39 351 52 41 692.
2. Personal data we process
- Browsing and technical data: IP address, request date and time, pages visited, referring URL, device or browser identifiers, technical logs, error and security information.
- Identity and contact data: first and last name, email address, telephone number, postal address and account credentials.
- Purchase and delivery data: products ordered, amounts, payment method and status, selected carrier, delivery address, order history, returns and refunds.
- Billing data: company or business name, address, VAT number, Italian tax code, certified email address and SDI recipient code, where required.
- Payment data: information required to manage the transaction and its outcome. Full card details are processed directly by the payment provider and are not stored by StrassOutlet.
- Communications: requests and attachments sent by email, contact form, telephone, WhatsApp or chat.
- Preferences and content: newsletter subscription, cookie consent, stated preferences, reviews and ratings.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Enable browsing and manage the account, shopping cart and essential preferences. | Performance of a contract or pre-contractual measures; legitimate interest in providing a secure service. |
| Manage orders, payments, deliveries, support, returns, refunds and purchase-related communications. | Performance of a contract or measures requested by the data subject. |
| Issue and retain tax and accounting documents, comply with legal duties and respond to authorities. | Compliance with a legal obligation. |
| Prevent fraud, abuse and unauthorised access and protect systems, customers and the controller's rights. | Legitimate interest and, where applicable, compliance with law. |
| Respond to enquiries and support requests not directly related to an order. | Pre-contractual measures requested by the user or legitimate interest in handling requests. |
| Send newsletters, promotions and commercial communications. | Consent, which may be withdrawn at any time. |
| Measure website use, improve performance and content, personalise advertising or measure its effectiveness through non-essential technologies. | Consent given through the cookie settings, where required. |
| Collect, moderate and publish product reviews. | Performance of the requested service and legitimate interest in informing users and protecting content authenticity. |
| Establish, exercise or defend legal claims. | Legitimate interest of the controller. |
4. Required and optional information
Information marked as required is needed to create an account, enter into and perform a contract, deliver an order or comply with tax obligations. If it is not provided, the relevant service or order may not be completed. Information used for newsletters, analytics, personalisation and marketing is optional; refusing consent does not prevent purchases.
5. Processing methods and security
Data is processed by electronic means and, where necessary, on paper in accordance with the principles of lawfulness, fairness, transparency, data minimisation and storage limitation. Technical and organisational safeguards proportionate to the risk are used, including access controls, protected communications, backups and monitoring. No system can guarantee absolute security.
6. Recipients
Personal data may be accessed by authorised personnel and by suppliers acting, as appropriate, as processors or independent controllers, only as necessary. Recipient categories include:
- hosting, maintenance, security, e-commerce platform and IT service providers;
- payment providers, banks and fraud prevention services;
- carriers, logistics operators and collection points;
- accountants, advisers, insurers and appointed professionals;
- email, newsletter, customer support, chat and communication providers;
- analytics and advertising providers, within the preferences expressed by the user;
- public authorities, supervisory bodies and recipients required by law.
Data is not made public unless the user chooses to publish content, such as a review.
7. Transfers outside the EEA
Some technology providers may process data outside the European Economic Area. Where this occurs, transfers rely on a European Commission adequacy decision, including the EU-US Data Privacy Framework where applicable, or on standard contractual clauses and any supplementary safeguards required by Articles 44 and following of the GDPR. Information about the applicable safeguards may be requested from the controller.
8. Retention
Data is retained for as long as necessary for the purpose for which it was collected and thereafter for periods required by law or necessary to protect legal rights. In particular:
- account data: until deletion is requested or after a prolonged period of inactivity, without prejudice to data that must be retained by law;
- orders, invoices and administrative records: generally 10 years, subject to longer periods connected with disputes or specific duties;
- support requests: for the time needed to handle the request and generally no longer than 24 months after closure, unless a dispute arises;
- newsletter data: until consent is withdrawn, with minimum information retained where necessary to evidence the withdrawal or prevent further messages;
- reviews: while published and until removal is requested, unless retention is necessary to protect legal rights;
- technical and security logs: for the strictly necessary period, normally no more than 30 days, unless a security incident or legal obligation requires longer retention;
- proof of cookie preferences: 6 months; individual cookie lifetimes are listed in the Cookie Policy.
9. Cookies and similar technologies
The website uses cookies and similar technologies. Strictly necessary cookies are used without consent to operate and secure the website. Non-essential functional, analytics and advertising technologies are used only in accordance with the user's preferences where consent is required. See the Cookie Policy for providers, lifetimes and instructions for changing your choices.
10. Marketing communications
Promotional communications are sent only where there is a valid legal basis. Consent may be withdrawn at any time through the link in an email or by contacting the controller. Service messages required to manage an account or order are not marketing and may be sent without promotional consent.
11. Automated decision-making
No decisions based solely on automated processing are made that produce legal effects or similarly significantly affect users. Advertising profiling through cookies, if enabled, takes place only with consent and does not produce such effects.
12. Your rights
Where the GDPR applies, you may request access, rectification, erasure, restriction of processing and data portability, and object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Requests may be sent to info@strassoutlet.com. The controller may request information necessary to verify the applicant's identity. You may also lodge a complaint with the Italian Data Protection Authority or the competent supervisory authority in your Member State.
13. Children
The website and online sales services are not directed at children who cannot validly enter into a contract. If the controller becomes aware that a child's data has been collected without a lawful basis, it will be deleted.
14. Third-party websites and services
The website may link to third-party services, including payment providers, carriers, WhatsApp and social media. Their processing is governed by their own privacy notices and is outside the controller's control.
15. Updates
This notice may be updated to reflect legal, organisational or technical changes. The latest version is published on this page with its revision date. Where required, material changes will be communicated by additional means.





















































