Go to content

Cart

Your cart is empty

Privacy Policy

Privacy Policy of www.guja.it

Welcome to the privacy policy of www.guja.it. This policy will help you understand what data we collect, why we collect it, and what your rights are regarding it.

Last updated: June 27, 2025

Data Controller

Guja s.r.l. - Via San Giovanni sul Muro, 13 - 20121 - Milan - Italy

Data Controller's email address: ecommerce@guja.it

Type of Data we collect

Among the Personal Data collected by this Website, independently or through third parties, are:

  • Tracking Tools
  • Usage Data
  • email
  • payment information
  • number of Users
  • session statistics
  • name
  • surname
  • purchase history
  • point of sale data
  • device information

Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or through specific informational texts displayed before the collection of the Data itself.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Website.
Unless otherwise specified, all Data requested by this Website is mandatory. If the User refuses to provide it, it may be impossible for this Website to provide the Service. In cases where this Website indicates some Data as optional, Users are free to refrain from providing such Data, without this having any consequence on the availability of the Service or its operation.
Users who have doubts about which Data is mandatory are encouraged to contact the Owner.
The possible use of Cookies - or other tracking tools - by this Website or by the owners of third-party services used by this Website aims to provide the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy.

The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this Website.

Methods and place of processing of the collected Data

Processing methods

The Owner adopts appropriate security measures aimed at preventing unauthorized access, disclosure, modification, or destruction of Personal Data.
The processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In addition to the Owner, in some cases, other subjects involved in the organization of this Website (administrative, commercial, marketing, legal staff, system administrators) or external subjects (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) may have access to the Data, also appointed, if necessary, as Data Processors by the Owner. The updated list of Processors can always be requested from the Data Controller.

Location

The Data is processed at the Owner's operational offices and in any other location where the parties involved in the processing are located. For more information, contact the Owner.
The User's Personal Data may be transferred to a country different from the one in which the User is located. For more information on the place of processing, the User can refer to the section regarding details on the processing of Personal Data.

Retention period

Unless otherwise specified in this document, Personal Data is processed and stored for the time required by the purpose for which it was collected and may be kept for a longer period due to any legal obligations or based on the consent of the Users.

Purpose of Data Processing

User Data is collected to allow the Owner to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect their rights and interests (or those of Users or third parties), identify any malicious or fraudulent activities, as well as for the following purposes:

  • Access to accounts on third-party services
  • Payment management
  • Statistics
  • Contact management and sending messages
  • Platform and hosting services
  • Hosting and backend infrastructure
  • Optimization and traffic distribution
  • Interaction with social networks and external platforms
  • Contact the User
  • Tag management

Facebook permissions requested by this Website

This Website may request some Facebook permissions that allow it to perform actions with the User's Facebook account and collect information, including Personal Data, from it. This service allows this Website to connect with the User's account on the social network Facebook, provided by Facebook Inc.
For more information on the following permissions, refer to the Facebook permissions documentation and the Facebook privacy policy.

The requested permissions are the following:

Basic information

The basic information of the User registered on Facebook normally includes the following Data: id, name, image, gender, and localization language and, in some cases, Facebook "Friends." If the User has made additional Data publicly available, these will also be accessible.

Usage Data

Email

Provides access to the User's primary email address.

device information

Tracking Tools

Tracking Tool means any technology - e.g. Cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting - that allows tracking Users, for example by collecting or saving information on the User's device.

Details on the processing of Personal Data

Access to accounts on third-party services

 

These types of services allow this Website to retrieve Data from your accounts on third-party services and perform actions with them.
These services are not activated automatically but require the User's explicit authorization.

 

Meta Platforms, Inc.Facebook account accessCompany:Meta Platforms, Inc.Location of processing:United StatesPermissions requested:Usage data +3

This service allows this Website to connect with the User's account on the social network Facebook, provided by Meta Platforms, Inc.

Permissions requested:
  • Usage Data
  • Email
  • device information
  • Tracking Tools
Legal basis for processing:
Service provided by:
Conditions for data transfer:
Data retention period:
Category of personal information collected under the CCPA
  • identifiers
  • information related to internet activities or other networks

Contact the User

 

Mailing list or newsletterPersonal Data processed:Usage data +2

By registering to the mailing list or newsletter, the User's email address is automatically added to a contact list to which email messages containing information, including commercial and promotional content, related to this Website may be sent. The User's email address may also be added to this list as a result of registration on this Website or after making a purchase.

Personal Data processed:
  • Usage Data
  • email
  • Tracking Tools
Legal basis for processing:
Service provided by:
    Conditions for data transfer:
    Data retention period:
    Category of personal information collected under the CCPA
    • identifiers
    • information related to internet activities or other networks
    Contact formPersonal Data processed:Usage data +1

    By filling out the contact form with their data, the User authorizes this Website to use such data to respond to requests (such as quotes and any other requests).

    Personal Data processed:
    • Usage Data
    • email
    Legal basis for processing:
    Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • identifiers
      • information related to internet activities or other networks

      Contact management and sending messages

       

      This type of service allows managing a database of email contacts, phone contacts, or contacts of any other type, used to communicate with the User.
      These services may also allow the collection of data related to the date and time the messages are viewed by the User, as well as the User's interaction with them, such as information on clicks on links included in the messages.

       

      Klaviyo Inc.KlaviyoCompany:Klaviyo Inc.Processing location:United StatesPersonal Data processed:purchase history +3

      Klaviyo is an address management and email message sending service provided by Klaviyo Inc.

      To use the service provided by Klaviyo, the Data Controller generally shares information regarding Users (who make purchases), such as contact details and purchase history. For more information about the scope of such sharing, check the instructions below the heading “Personal Data processed.”

      Personal Data processed:
      • purchase history
      • Usage Data
      • email
      • Tracking Tools
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • identifiers
      • business information
      • information related to internet activities or other networks
      Trustpilot A/STrustpilot Automatic Feedback ServiceCompany:Trustpilot A/SProcessing location:DenmarkPersonal Data processed:Usage data +2

      The Trustpilot Automatic Feedback Service is a message sending service provided by Trustpilot A/S that automates the sending of product or service review requests via email based on certain actions performed by Users on this Website.

      Personal Data processed:
      • Usage Data
      • email
      • Tracking Tools
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • identifiers
      • information related to internet activities or other networks

      Payment management

       

      Unless otherwise specified, this Website processes all payments by credit card, bank transfer, or other means through external payment service providers. In general, and unless otherwise indicated, Users are asked to provide payment details and personal information directly to such payment service providers.
      This Website is not involved in the collection and processing of such information: it will instead only receive a notification from the payment service provider in question about the completed payment.

       

      American Express CompanyAmerican ExpressCompany:American Express CompanyProcessing location:United StatesPersonal Data processed:Usage data +3

      American Express is a payment service provided by American Express Company, which allows the User to make online payments.

      Personal Data processed:
      • Usage Data
      • email
      • payment information
      • Tracking Tools
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • identifiers
      • business information
      • information related to internet activities or other networks
      Google LLCGoogle PayCompany:Google LLCProcessing location:United StatesPersonal Data processed:surname +5

      Google Pay is a payment service provided by Google LLC, which allows the User to make online payments using their Google credentials.

      Personal Data processed:
      • surname
      • Usage Data
      • email
      • payment information
      • name
      • Tracking Tools
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • identifiers
      • business information
      • information related to internet activities or other networks
      Mastercard Inc.MastercardCompany:Mastercard Inc.Processing location:United StatesPersonal Data processed:Usage data +3

      Mastercard is a payment service provided by Mastercard Inc, which allows the User to make online payments.

      Personal Data processed:
      • Usage Data
      • email
      • payment information
      • Tracking Tools
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • identifiers
      • business information
      • information related to internet activities or other networks
      PaypalPayPalCompany:PaypalProcessing location:See Paypal privacy policyPersonal Data processed:Usage data +3

      PayPal is a payment service provided by PayPal Inc., which allows the User to make online payments.

      Personal Data processed:
      • Usage Data
      • email
      • payment information
      • Tracking Tools
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • identifiers
      • business information
      • information related to internet activities or other networks
      Shopify Inc.Shop PayCompany:Shopify Inc.Processing location:CanadaPersonal Data processed:Usage data +3

      Shop Pay is a payment management and product purchase procedure service provided by Shopify Inc. that allows Users to make online payments on this Website.

      Personal Data processed:
      • Usage Data
      • point of sale data
      • payment information
      • Tracking Tools
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • business information
      • information related to internet activities or other networks
      Visa Inc.VisaCompany:Visa Inc.Processing location:United StatesPersonal Data processed:Usage data +3

      Visa is a payment service provided by Visa Inc, which allows the User to make online payments.

      Personal Data processed:
      • Usage Data
      • email
      • payment information
      • Tracking Tools
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • identifiers
      • business information
      • information related to internet activities or other networks

      Tag management

       

      This type of service allows the Owner to centrally manage the tags or scripts needed on this Website. As a result, User Data may be processed by these services, with the possibility that they are stored.

       

      Google LLCGoogle Tag ManagerCompany:Google LLCProcessing location:United StatesPersonal Data processed:Usage data +1

      Google Tag Manager is a tag management service provided by Google LLC.

      To learn about Google's use of Data, see their partner policy and their Commercial Data page.

      Personal Data processed:
      • Usage Data
      • Tracking Tools
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • information related to internet activities or other networks

      Hosting and backend infrastructure

       

      This type of service is intended to host Data and files that allow this Website to function and be distributed or to provide a ready-to-use infrastructure to perform specific functions or parts of this Website.

      Some of the services listed below, if present, may operate on geographically distributed servers, making it difficult to determine the actual location where the Personal Data is stored.

       

      Amazon Web Services, Inc.Amazon S3Company:Amazon Web Services, Inc.Processing location:United StatesPersonal Data processed:Usage data

      Amazon S3 is a cloud storage service provided by Amazon Web Services, Inc.

      Personal Data processed:
      • Usage Data
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • information related to internet activities or other networks
      Amazon Web Services, Inc.Amazon Web Services (AWS)Company:Amazon Web Services, Inc.Processing location:United StatesPersonal Data processed:various types of Data as specified by the service's privacy policy

      Amazon Web Services (AWS) is a hosting and backend service provided by Amazon Web Services, Inc.

      Personal Data processed:
      • various types of Data as specified by the service's privacy policy
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • identifiers

      Interaction with social networks and external platforms

       

      This type of service allows interactions with social networks, or with other external platforms, directly from the pages of this Website.
      Interactions and information acquired from this Website are in any case subject to the User's privacy settings related to each social network.
      This type of service may still collect traffic data for the pages where the service is installed, even when Users do not use it.
      It is recommended to log out of the respective services to ensure that data processed on this Website is not linked back to the User's profile.

       

      Meta Platforms, Inc.Facebook Like button and social widgetsCompany:Meta Platforms, Inc.Processing location:United StatesPersonal Data processed:Usage Data +1

      The “Like” button and Facebook social widgets are interaction services with the Facebook social network, provided by Meta Platforms, Inc.

      Personal Data processed:
      • Usage Data
      • Tracking Tools
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • information related to internet activities or other networks

      Optimization and traffic distribution

       

      This type of service allows this Website to distribute its content through servers located across the territory and to optimize its performance.
      The Personal Data processed depends on the characteristics and implementation method of these services, which by their nature filter communications between this Website and the User's browser.
      Given the distributed nature of this system, it is difficult to determine the locations where the contents are transferred, which may contain the User's Personal Data.

       

      Cloudflare, Inc.CloudflareCompany:Cloudflare, Inc.Location of processing:United StatesPersonal Data processed:Tracking Tools +1

      Cloudflare is a traffic optimization and distribution service provided by Cloudflare Inc. The integration methods of Cloudflare involve filtering all traffic of this Website, that is, communications between this Website and the User's browser, also allowing the collection of statistical data on it.

      Personal Data processed:
      • Tracking Tools
      • various types of Data as specified by the service's privacy policy
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • identifiers
      • information related to internet activities or other networks

      Platform and hosting services

       

      These services aim to host and operate key components of this Website, making it possible to deliver this Website from a single platform. These platforms provide the Owner with a wide range of tools such as analytics tools, user registration management, comment and database management, e-commerce, payment processing, etc. The use of such tools involves the collection and processing of Personal Data.
      Some of these services operate through servers located in different geographical locations, making it difficult to determine the exact place where the Personal Data is stored.

       

      Shopify Inc.ShopifyCompany:Shopify Inc.Location of processing:CanadaPersonal Data processed:Usage Data +2

      Shopify is a platform provided by Shopify Inc. that allows the Controller to develop, operate, and host an e-commerce website. This service may place trackers on the User's device. For more updated and complete information, consult the official documentation of the service.

      Personal Data processed:
      • Usage Data
      • device information
      • Tracking Tools
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • information related to internet activities or other networks

      Statistics

       

      The services contained in this section allow the Data Controller to monitor and analyze traffic data and are used to track User behavior.

       

      Google LLCGoogle Analytics 4Company:Google LLCProcessing location:United StatesPersonal Data processed:Usage data +3

      Google Analytics is a statistics service provided by Google LLC (“Google”). Google uses the Personal Data collected to track and examine the use of this Website, compile reports, and share them with other services developed by Google. Google may use Personal Data to contextualize and personalize ads in its advertising network. In Google Analytics 4, IP addresses are used at the time of collection and then deleted before data is recorded in any data center or server. To learn more, you can consult the official Google documentation.

      To learn about Google's use of Data, see their partner policy and their Commercial Data page.

      Personal Data processed:
      • Usage Data
      • number of Users
      • session statistics
      • Tracking Tools
      Legal basis for processing:
      Service provided by:
      Conditions for data transfer:
      Data retention period:
      Category of personal information collected under the CCPA
      • information related to internet activities or other networks

      Information on how to disable interest-based advertising

      In addition to any opt-out function provided by any of the services listed in this document, Users can read more about how to disable interest-based advertising in the dedicated section of the Cookie Policy.

      Further information on the processing of Personal Data

      Sale of goods and services online

      The Personal Data collected are used for providing services to the User or for the sale of products, including payment and possible delivery. The Personal Data collected to complete the payment may be those related to the credit card, the bank account used for the transfer, or other payment instruments provided. The payment data collected by this Website depend on the payment system used.

      This Website uses Tracking Tools. To learn more, Users can consult the Cookie Policy.

      Further information for users in the European Union

      Legal basis of the processing

      The Data Controller processes Personal Data relating to the User if one of the following conditions exists:

      • the User has given consent for one or more specific purposes.
      • the processing is necessary for the performance of a contract with the User and/or the implementation of pre-contractual measures;
      • the processing is necessary to comply with a legal obligation to which the Data Controller is subject;
      • the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
      • the processing is necessary for the pursuit of the legitimate interest of the Data Controller or third parties.
      It is always possible to request the Data Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on law, provided by a contract, or necessary to conclude a contract.

       

      Further information on the retention period

      Unless otherwise specified in this document, Personal Data is processed and stored for the time required by the purpose for which it was collected and may be kept for a longer period due to any legal obligations or based on the consent of the Users.

      Therefore:

      • Personal Data collected for purposes related to the execution of a contract between the Controller and the User will be retained until the execution of that contract is completed.
      • Personal Data collected for purposes related to the legitimate interest of the Controller will be retained until that interest is satisfied. The User can obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.

       

      When processing is based on the User's consent, the Controller may retain Personal Data longer until such consent is revoked. Furthermore, the Controller may be required to retain Personal Data for a longer period to comply with a legal obligation or an order from an authority.

      At the end of the retention period, Personal Data will be deleted. Therefore, upon expiration of this term, the rights of access, deletion, rectification, and data portability can no longer be exercised.

      User rights under the General Data Protection Regulation (GDPR)

      Users can exercise certain rights with reference to the Data processed by the Controller.

      In particular, within the limits provided by law, the User has the right to:

      • withdraw consent at any time. The User can withdraw consent to the processing of their previously given Personal Data.
      • object to the processing of their Data. The User can object to the processing of their Data when it is based on a legal ground other than consent.
      • access their own Data. The User has the right to obtain information about the Data processed by the Controller, on certain aspects of the processing, and to receive a copy of the processed Data.
      • verify and request rectification. The User can verify the accuracy of their Data and request its update or correction.
      • obtain the restriction of processing. The User can request the restriction of the processing of their Data. In such case, the Controller will not process the Data for any purpose other than their storage.
      • obtain the deletion or removal of their Personal Data. The User can request the deletion of their Data by the Controller.
      • receive their own Data or have it transferred to another controller. The User has the right to receive their own Data in a structured format, commonly used and readable by an automatic device and, where technically feasible, to obtain its transfer without obstacles to another controller.
      • file a complaint. The User may file a complaint with the competent data protection supervisory authority or take legal action.

      Users have the right to obtain information about the legal basis for the transfer of Data abroad, including to any international organization governed by international law or established by two or more countries, such as the UN, as well as about the security measures adopted by the Data Controller to protect their Data.

      Details on the right to object

      When Personal Data is processed in the public interest, in the exercise of public powers vested in the Data Controller, or to pursue a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.

      Users are informed that, if their Data is processed for direct marketing purposes, they may object to the processing at any time, free of charge and without providing any reason. If Users object to processing for direct marketing purposes, Personal Data will no longer be processed for such purposes. To find out if the Data Controller processes Data for direct marketing purposes, Users can refer to the respective sections of this document.

      How to exercise rights

      Any requests to exercise User rights can be addressed to the Data Controller through the contact details provided in this document. The request is free of charge and the Data Controller will respond as soon as possible, in any case within one month, providing the User with all information required by law. Any corrections, deletions, or restrictions of processing will be communicated by the Data Controller to each recipient, if any, to whom the Personal Data have been transmitted, unless this proves impossible or involves a disproportionate effort. The Data Controller will inform the User of such recipients upon request.

      Additional information for users in Switzerland

      This section applies to Users in Switzerland and, for such Users, replaces any other potentially conflicting or divergent information contained in the privacy policy.

      Further details regarding the categories of Data processed, the purposes of processing, the categories of recipients of personal data, if any, the retention period, and other information about Personal Data can be found in the section titled "Detailed information on the processing of Personal Data" within this document.

      Users' rights under the Federal Act on Data Protection

      Users may exercise certain rights related to their data within the limits of the law, including the following:

      • right of access to Personal Data;
      • the right to object to the processing of your Personal Data (which also allows Users to request the restriction of the processing of Personal Data, the deletion or destruction of Personal Data, the prohibition of disclosure of Personal Data to third parties);
      • right to receive your Personal Data and transfer it to another data controller (data portability);
      • right to request the correction of incorrect Personal Data.

      How to exercise these rights

      Any requests to exercise User rights may be addressed to the Data Controller through the contact details provided in this document. Such requests are free of charge and the Data Controller will respond as soon as possible, providing Users with the information required by law.

      Additional information for Users in Brazil

      This section of the document supplements and completes the information contained in the rest of the privacy policy and is provided by the entity that manages this Website and, if applicable, by its parent company and its subsidiaries and affiliates (for the purposes of this section collectively referred to as "we", "our" or "us").
      This section applies to all Users in Brazil (such Users are hereinafter simply referred to as “you”, “your”, "you" or "your"), pursuant to the "Lei Geral de Proteção de Dados" and, for such Users, it prevails over any other information that may be divergent or conflicting contained in this privacy policy.
      In this part of the document, the term “personal information” is used as defined by the LGPD.

      Legal bases under which we process your personal information

      We process your personal information exclusively if one of the legal bases for such processing exists. The legal bases are as follows:

      • your consent to the processing activities in question;
      • compliance with legal obligations that we are required to fulfill;
      • the enforcement of rules dictated by laws or regulations or by contracts, agreements or other similar legal instruments;
      • studies conducted by research entities, preferably carried out on anonymized personal information;
      • the execution of a contract and related pre-contractual obligations, if you are a party to such contract;
      • the exercise of our rights in court, in administrative procedures or in arbitrations;
      • the defense or physical safety of you or a third party;
      • health protection - in the context of procedures implemented by entities or professionals in the healthcare sector;
      • our legitimate interest, provided that your fundamental rights and freedoms do not prevail over such interests; and
      • credit protection.

       

      To learn more about the legal bases, you can contact us at any time using the contact details provided in this document.

      Categories of personal information processed

      To know which categories of personal information are processed, you can refer to the section “Details on the Processing of Personal Data” in this document.

      Why we process your personal information

      To know why we process your personal information, refer to the sections “Details on the Processing of Personal Data” and “Purpose of the Processing of Collected Data” in this document.

      Your privacy rights in Brazil, how to submit a request and how it will be handled by us

      Your privacy rights in Brazil

      You have the right to:

      • obtain confirmation of the existence of processing activities concerning your personal information;
      • access your personal information;
      • obtain the correction of your incomplete, inaccurate, or outdated personal information;
      • obtain anonymization, blocking, or deletion of unnecessary or excessive personal information, or of information processed in violation of the provisions of the LGPD;
      • obtain information about the possibility to give or refuse your consent and the related consequences;
      • obtain information about third parties with whom we share your personal information;
      • obtain, upon your explicit request, the portability of your personal information (except anonymized information) to other product or service providers, provided that our trade and industrial secrets are safeguarded;
      • obtain the deletion of personal information processed if the processing was based on your consent, unless one or more exceptions provided by article 16 LGPD apply;
      • withdraw your consent at any time;
      • file a complaint regarding your personal information with the ANPD (National Data Protection Authority) or a consumer protection agency;
      • object to processing activities in cases where such processing is not carried out in accordance with legal provisions;
      • request clear and adequate information regarding the criteria and procedures used within automated decision-making processes; and
      • request the review of decisions that harm your interests, made exclusively based on automated decision-making processes of your personal information. These include decisions to outline your personal, professional, consumer, or creditor profile, or other aspects of your personality.

       

      You will never be discriminated against, nor will you suffer any unfavorable treatment as a result of exercising your rights.

      How to submit a request

      You can submit an explicit request to exercise your rights free of charge, at any time, using the contact details provided in this document or through your legal representative.

      How and within what time frame we will handle your request

      We will do our best to respond to your request as soon as possible.
      In any case, if it is impossible for us to do so, we will ensure to communicate to you the factual or legal reasons that prevent us from immediately satisfying or following up on your request. If your personal information is not processed by us, if we are able to do so, we will indicate the natural or legal person to whom you should address your requests.

      In the event that you decide to submit a request for access or a request for confirmation of the existence of processing of personal information, please make sure to specify whether you prefer to receive your personal information in electronic or paper format.
      You must also let us know if you want an immediate response, in which case you will receive a simplified reply, or if you require a complete information notice.
      In the latter case, we will respond within 15 days from the moment of your request, providing you with all information regarding the origin of your personal information, confirmation or denial of the existence of personal information concerning you, all criteria used for processing, and the purposes of such processing, while safeguarding our trade and industrial secrets.

      In the event that you decide to submit a request for rectification, deletion, anonymization, or blocking of personal information, we will ensure to immediately inform the other parties with whom we have shared your personal information so that they can in turn fulfill your request - except in cases where such communication is impossible or excessively burdensome for us.

      Transfer of personal information outside Brazil in cases permitted by law

      We may transfer your personal information outside Brazilian territory in the following cases:

      • when the transfer is necessary for international legal cooperation between intelligence services, investigative and criminal procedure bodies, as provided by instruments made available by international law;
      • when the transfer is necessary to protect the life or physical safety of you or third parties;
      • when the transfer is authorized by the ANPD;
      • when the transfer results from an obligation assumed in the context of an international cooperation agreement;
      • when the transfer is necessary for the exercise of public order or for the performance of a public service;
      • when the transfer is necessary for compliance with a legal obligation, the execution of a contract and related pre-contractual obligations, or the normal exercise of rights in judicial, administrative or arbitration proceedings.

       

      Further information for Users in the United States

      This part of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the business running this Website and, if the case may be, its parent, subsidiaries and affiliates (for the purposes of this section referred to collectively as “we”, “us”, “our”).
      The information contained in this section applies to all Users (Users are referred to below, simply as “you”, “your”, “yours”), who are residents in the following states: California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota and Montana.
      For such Users, this information supersedes any other possibly divergent or conflicting provisions contained in the privacy policy.
      This part of the document uses the term Personal Information (and Sensitive Personal Information).

      Notice at collection

      The following Notice at collection provides you with timely notice about the categories of Personal Information collected or disclosed in the past 12 months so that you can exercise meaningful control over our use of that Information.
      While such categorization of Personal Information is mainly based on California privacy laws, it can also be helpful for anyone who is not a California resident to get a general idea of what types of Personal Information are collected.

      Identifiers

      Personal Data processed: Email; Tracking tools; Usage data; Device information + 5

      Personal Information collected or disclosed:

      • Email
      • Tracking Tools
      • Usage Data
      • device information
      • email
      • name
      • surname
      • purchase history
      • various types of Data as specified by the service's privacy policy

      Sensitive Personal Information collected or disclosed payment information

      Purposes:

      • Access to accounts on third-party services
      • Payment management
      • Payment management
      • Contact management and sending messages
      • Payment management
      • Payment management
      • Further information on Personal Data
      • Payment management
      • Optimization and traffic distribution
      • Contact management and sending messages
      • Hosting and backend infrastructure
      • Contact the User
      • Contact the User

      Retention period: for the time necessary to fulfill the purpose

      Sold or Shared: No

      Targeted Advertising: No

      Third-parties: Meta Platforms, Inc., American Express Company, Google LLC, Klaviyo Inc., Mastercard Inc., Paypal, Visa Inc., Cloudflare, Inc., Trustpilot A/S, Amazon Web Services, Inc.

      Internet or other electronic network activity information

      Personal Data processed: Email; Tracking tools; Usage data; Device information + 8

      Personal Information collected or disclosed:

      • Email
      • Tracking Tools
      • Usage Data
      • device information
      • email
      • number of Users
      • session statistics
      • name
      • surname
      • purchase history
      • point of sale data
      • various types of Data as specified by the service's privacy policy

      Sensitive Personal Information collected or disclosed payment information

      Purposes:

      • Access to accounts on third-party services
      • Payment management
      • Statistics
      • Payment management
      • Contact management and sending messages
      • Payment management
      • Payment management
      • Payment management
      • Platform and hosting services
      • Payment management
      • Hosting and backend infrastructure
      • Optimization and traffic distribution
      • Contact management and sending messages
      • Interaction with social networks and external platforms
      • Contact the User
      • Contact the User
      • Tag management

      Retention period: for the time necessary to fulfill the purpose

      Sold or Shared: No

      Targeted Advertising: No

      Third-parties: Meta Platforms, Inc., American Express Company, Google LLC, Klaviyo Inc., Mastercard Inc., Paypal, Shopify Inc., Visa Inc., Amazon Web Services, Inc., Cloudflare, Inc., Trustpilot A/S

      Commercial information

      Personal Data processed: Tracking tools; Usage data; Email; Name + 3

      Personal Information collected or disclosed:

      • Tracking Tools
      • Usage Data
      • email
      • name
      • surname
      • purchase history
      • point of sale data

      Sensitive Personal Information collected or disclosed payment information

      Purposes:

      • Payment management
      • Payment management
      • Contact management and sending messages
      • Payment management
      • Payment management
      • Payment management
      • Payment management

      Retention period: for the time necessary to fulfill the purpose

      Sold or Shared: No

      Targeted Advertising: No

      Third-parties: American Express Company, Google LLC, Klaviyo Inc., Mastercard Inc., Paypal, Shopify Inc., Visa Inc.

      ℹ️ You can read the definitions of these concepts inside the “Definitions and legal references section” of the privacy policy.

      To know more about your rights to limit the use of your sensitive personal information (“Limit the Use of My Sensitive Personal Information”) you can refer to the “Your privacy rights under US state laws” section of our privacy policy.

      For more details on the collection of Personal Information, please read the section “Detailed information on the processing of Personal Data” of our privacy policy.

      We won’t process your Information for unexpected purposes, or for purposes that are not reasonably necessary to and compatible with the purposes originally disclosed, without your consent.

      What are the sources of the Personal Information we collect?

      We collect the above-mentioned categories of Personal Information, either directly or indirectly, from you when you use this Website.

      For example, you directly provide your Personal Information when you submit requests via any forms on this Website. You also provide Personal Information indirectly when you navigate this Website, as Personal Information about you is automatically observed and collected.

      Finally, we may collect your Personal Information from third parties that work with us in connection with the Service or with the functioning of this Website and features thereof.

      Your privacy rights under US state laws

      You may exercise certain rights regarding your Personal Information. In particular, to the extent permitted by applicable law, you have:

      • the right to access Personal Information: the right to know. You have the right to request that we confirm whether or not we are processing your Personal Information. You also have the right to access such Personal Information;
      • the right to correct inaccurate Personal Information. You have the right to request that we correct any inaccurate Personal Information we maintain about you;
      • the right to request the deletion of your Personal Information. You have the right to request that we delete any of your Personal Information;
      • the right to obtain a copy of your Personal Information. We will provide your Personal Information in a portable and usable format that allows you to transfer data easily to another entity – provided that this is technically feasible;
      • the right to opt out from the Sale of your Personal Information; We will not discriminate against you for exercising your privacy rights.
      • the right to non-discrimination.

      Additional rights for Users residing in California

      In addition to the rights listed above common to all Users in the United States, as a User residing in California, you have

      • The right to opt out of the Sharing of your Personal Information for cross-context behavioral advertising;
      • The right to request to limit our use or disclosure of your Sensitive Personal Information to only that which is necessary to perform the services or provide the goods, as is reasonably expected by an average consumer. Please note that certain exceptions outlined in the law may apply, such as, when the collection and processing of Sensitive Personal Information is necessary to verify or maintain the quality or safety of our service.

      Additional rights for Users residing in Virginia, Colorado, Connecticut, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota and Montana

      In addition to the rights listed above common to all Users in the United States, as a User residing in Virginia, Colorado, Connecticut, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota and Montana you have

      • The right to opt out of the processing of your personal information for Targeted Advertising or profiling in furtherance of decisions that produce legal or similarly significant effects concerning you;
      • The right to freely give, deny or withdraw your consent for the processing of your Sensitive Personal Information. Please note that certain exceptions outlined in the law may apply, such as, but not limited to, when the collection and processing of Sensitive Personal Information is necessary for the provision of a product or service specifically requested by the consumer.

      In Minnesota Users also have the right to obtain a list of the specific third parties to which the controller has disclosed the consumer’s personal data

      * Note that in some states like Minnesota you have the following specific rights connected to profiling:

      • The right to question the results of the profiling;
      • The right to be informed of the reason that the profiling resulted in the decision; if feasible
      • The right to be informed of what actions the consumer might have taken to secure a different decision and the actions that the consumer might take to secure a different decision in the future;
      • The right to review personal data used in the profiling;
      • If inaccurate, the right to have the data corrected and the profiling decision reevaluated based on the corrected data;

      Additional rights for users residing in Utah and Iowa

      In addition to the rights listed above common to all Users in the United States, as a User residing in Utah and Iowa, you have

      • The right to opt out of the processing of your Personal Information for Targeted Advertising;
      • The right to opt out of the processing of your Sensitive Personal Information. Please note that certain exceptions outlined in the law may apply, such as, but not limited to, when the collection and processing of Sensitive Personal Information is necessary for the provision of a product or service specifically requested by the consumer.

      How to exercise your privacy rights under US state laws

      To exercise the rights described above, you need to submit your request to us by contacting us via the contact details provided in this document.

      For us to respond to your request, we must know who you are. We will not respond to any request if we are unable to verify your identity and therefore confirm the Personal Information in our possession relates to you. You are not required to create an account with us to submit your request. We will use any Personal Information collected from you in connection with the verification of your request solely for verification and shall not further disclose the Personal Information, retain it longer than necessary for purposes of verification, or use it for unrelated purposes.

      If you are an adult, you can make a request on behalf of a child under your parental authority.

      How to exercise your rights to opt out

      In addition to what is stated above, to exercise your right to opt-out of Sale or Sharing and Targeted Advertising you can also use the privacy choices link provided on this Website.

      If you want to submit requests to opt out of Sale or Sharing and Targeted Advertising activities via a user-enabled global privacy control, such as for example the Global Privacy Control (“GPC”), you are free to do so and we will abide by such request in a frictionless manner.

      How and when we are expected to handle your request

      We will respond to your request without undue delay, but in all cases within the timeframe required by applicable law. Should we need more time, we will explain to you the reasons why, and how much more time we need.

      Should we deny your request, we will explain to you the reasons behind our denial (where envisaged by applicable law you may then contact the relevant authority to submit a complaint).

      We do not charge a fee to process or respond to your request unless such request is manifestly unfounded or excessive and in all other cases where it is permitted by the applicable law. In such cases, we may charge a reasonable fee or refuse to act on the request. In either case, we will communicate our choices and explain the reasons behind them.

      Further information on processing

      Legal defense

      The User's Personal Data may be used by the Data Controller in legal proceedings or in the preparatory stages of its possible initiation to defend against abuses in the use of this Website or the related Services by the User.
      The User declares to be aware that the Data Controller may be obliged to disclose the Data by order of public authorities.

      Specific notices

      At the User's request, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

      System logs and maintenance

      For operational and maintenance needs, this Website and any third-party services it uses may collect system logs, that is files that record interactions and may also contain Personal Data, such as the User's IP address.

      Information not contained in this policy

      Further information regarding the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

      Changes to this privacy policy

      The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Website as well as, where technically and legally feasible, sending a notification to Users through one of the contact details it holds. Please therefore check this page frequently, referring to the last modification date indicated at the bottom.

      If the changes affect processing whose legal basis is consent, the Data Controller will collect the User's consent again, if necessary.

      Definitions and legal references

      Personal Data (or Data) / Personal Information (or Information)

      Personal data means any information that, directly or indirectly, also in connection with any other information, including a personal identification number, identifies or makes identifiable a natural person.

      Sensitive Personal Information

      Sensitive Personal Information means all Personal Information that is not publicly available and that reveals information considered sensitive under the applicable privacy laws.

      Usage Data

      These are the information collected automatically through this Website (also from third-party applications integrated into this Website), including: IP addresses or domain names of the computers used by the User connecting to this Website, addresses in URI (Uniform Resource Identifier) notation, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response from the server (success, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, various temporal details of the visit (for example, the time spent on each page), and details related to the itinerary followed within the Application, with particular reference to the sequence of pages viewed, parameters related to the User's operating system and IT environment.

      User

      The individual who uses this Website who, unless otherwise specified, coincides with the Data Subject.

      Data Subject

      The natural person to whom the Personal Data refers.

      Data Processor (or Processor)

      The natural person, legal entity, public administration, and any other entity that processes personal data on behalf of the Data Controller, as described in this privacy policy.

      Data Controller (or Owner)

      The natural or legal person, public authority, service, or other body which, alone or jointly with others, determines the purposes and means of processing personal data and the tools adopted, including security measures related to the operation and use of this Website. The Data Controller, unless otherwise specified, is the owner of this Website.

      This Website (or this Application)

      The hardware or software tool through which Users' Personal Data are collected and processed.

      Service

      The Service provided by this Website as defined in the relevant terms (if any) on this site/application.

      Sale

      Sale means any exchange of Personal Information by the Owner to a third party, for money or other valuable consideration, as defined by applicable U.S. state privacy law. Please note that exchanging Personal Information with a service provider under a written contract that meets the requirements set by applicable law does not constitute a Sale of your Personal Information.

      Sharing

      Sharing means any sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating, orally, in writing, electronically, or by other means, a consumer's Personal Information by the company to a third party for cross-context behavioral advertising, whether for money or other valuable consideration, including transactions between a company and a third party related to cross-context behavioral advertising on behalf of a company where no money is exchanged, as defined by California privacy laws. Please note that exchanging Personal Information with a service provider under a written contract that meets the requirements set by California privacy laws does not constitute sharing the user's Personal Information.

      Targeted Advertising

      Targeted Advertising means displaying advertisements to a consumer for whom the ad is selected based on Personal Information obtained from that consumer's activities over time and on non-affiliated websites or online applications to predict the preferences or interests of that consumer, as defined by applicable U.S. state privacy law.

      European Union (or EU)

      Unless otherwise specified, any reference to the European Union contained in this document is intended to extend to all current member states of the European Union and the European Economic Area.

      Cookie

      Cookies are Tracking Tools consisting of small pieces of data stored within the User's browser.

      Tracking Tool

      Tracking Tool means any technology - e.g. Cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting - that allows tracking Users, for example by collecting or saving information on the User's device.


      Legal references

      This privacy policy is drafted based on multiple legislative frameworks.

      Unless otherwise specified, this privacy policy applies exclusively to this Website.

      How can we help?

      In case of problems

      Although we strive to create a positive user experience, we know that problems can occasionally occur between us and our users.
      In that case, do not hesitate to contact us.

      Contact us

      Footer

      www.guja.it

      Guja s.r.l. - Via San Giovanni sul Muro, 13 - 20121 - Milan - Italy

      Data Controller's email address: ecommerce@guja.it