The Sister’s Lab S.r.l. attaches great importance to the protection of personal data and is committed to ensuring that all processing is carried out in accordance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity and confidentiality as set out in Regulation (EU) 2016/679 (“GDPR”) and applicable national legislation.
This Privacy Policy describes how the personal data of users who visit and use the website www.mettiunfiore.it is collected, used, stored and protected.
The website allows users to browse products, create an account, make online purchases, make payments, arrange delivery, request assistance, manage complaints, returns and withdrawals, subscribe to the newsletter and, for adults, purchase alcoholic beverages.
Use of the website involves the processing of certain data necessary for its operation, security and the provision of the requested services, as described in this Privacy Policy and in the Cookie Policy.
The Data Controller is:
To obtain information regarding data processing or to exercise your rights under the GDPR, please use the contact details provided above.
This Privacy Notice applies to the website www.mettiunfiore.it and to the processing carried out by The Sister’s Lab S.r.l. through its e-commerce functions, forms, account area, customer service and interactions with users and customers.
It does not apply to third-party websites that may be accessed via links. For such websites, the user must consult the privacy notices of the respective data controllers.
IT systems and software procedures automatically collect information whose transmission is implicit in the use of Internet protocols.
This information may constitute personal data and is used for operational purposes, security, the prevention of misuse, the establishment of liability and, where permitted, for visitor statistics.
When a user creates or uses an account, the following may be processed: first name, surname, email address, telephone number, securely stored login credentials, delivery and billing addresses, order history, preferences and data associated with the account.
Passwords are not stored in plain text.
To manage purchases, the following data may be processed: first name, surname, contact details, addresses, tax reference number, VAT number, products, quantities, prices, discounts, order number and date, delivery method, order status, communications, and tax and administrative data.
Electronic payments are normally handled by external service providers. The Data Controller may receive the payment method, amount, date and time, transaction ID and outcome, as well as data necessary for reconciliations, disputes and refunds.
Unless otherwise configured technically, the Data Controller does not collect or store the full card number, security code or login details for PayPal or other payment services.
In the event of a bank transfer or refund, the IBAN and any strictly necessary banking information may be processed.
For delivery purposes, the recipient’s name, address, telephone number, email address, delivery instructions, tracking code, delivery status, date and information on goods held in storage may be processed. Such data is disclosed to the designated carriers and logistics operators.
When the user contacts Customer Services or exercises their right of withdrawal, the following may be processed: name, contact details, order number, product concerned, content of the request, photographs, return details, date and time of the notification, outcome and information necessary for the refund.
The digital withdrawal function allows you to provide or confirm the data necessary to identify the contract and the electronic means to which the confirmation should be sent. The reason for withdrawal is not mandatory in cases provided for by law.
The sale of alcoholic beverages is restricted to adults. The following may be processed: a declaration of legal age, date of birth where requested, the outcome of the verification, and data strictly necessary derived from a document.
The Data Controller avoids collecting or storing full copies of the document where not necessary. The verification may also be carried out by the carrier upon delivery.
Sending emails or communications entails the collection of the sender’s details, the content, any attachments and other data provided voluntarily.
Users are advised not to transmit unnecessary data, in particular data falling within special categories as defined in Article 9 of the GDPR.
When subscribing to the newsletter, the following may be processed: name, email address, date, time and source of consent, preferences, subscription, unsubscription and, where applicable and permitted, interactions with the communications.
Subscription is optional and separate from any purchase.
The website may use technical, functional, analytical and marketing cookies, as well as similar technologies.
Non-essential tools are used only where the legal requirements are met and, where required, following the provision of explicit consent via the preference management platform.
Categories, purposes, providers, durations and management methods are described in the Cookie Policy and in the preferences panel.
The Data Controller may receive data from payment providers, carriers, e-commerce platforms, security providers, authentication services, social networks or parties making a purchase or arranging a delivery on behalf of the data subject.
The data is processed to the extent necessary for the purpose for which it was provided.
The data is processed for specific, explicit and legitimate purposes, in particular to:
Processing takes place only where there is a legal basis provided for under Article 6 of the GDPR.
Il trattamento avviene soltanto in presenza di una base giuridica prevista dall’articolo 6 GDPR.
| Purpose | Legal basis |
| Browsing, functionality and security | Legitimate interests of the Data Controller – Article 6(1)(f) of the GDPR |
| Accounts, orders, payments, deliveries, returns and withdrawal | Performance of the contract and pre-contractual measures – Article 6(1)(b) of the GDPR |
| Invoicing, tax obligations, consumer protection and requests from authorities | Legal obligation – Article 6(1)(c) of the GDPR |
| Customer support and communications | Pre-contractual measures, performance of the contract or legitimate interest, depending on the content |
| Age verification | Legal obligation and legitimate interest in preventing unlawful sales |
| Fraud prevention and protection of rights | Legitimate interest – Article 6(1)(f) of the GDPR |
| Newsletters and marketing | Consent – Article 6(1)(a) of the GDPR, except where permitted by law |
| Analytical cookies not classified as technical or marketing cookies | Consent, where required |
The provision of data necessary for registration, ordering, payment, delivery, invoicing, age verification, cancellation, returns and refunds is necessary to conclude or perform the contract or to comply with legal obligations.
Failure to provide such data may prevent registration, purchase, payment, delivery or the processing of the request.
The provision of data for newsletters and marketing purposes is optional. Failure to give consent does not affect your ability to make a purchase or receive assistance.
Data is processed using electronic means and, where necessary, on paper, with appropriate measures in place to ensure its confidentiality, integrity, availability, accuracy and protection against unauthorised access, loss, destruction or unlawful disclosure.
Processing is carried out by authorised staff and by external parties appointed as data processors in accordance with Article 28 of the GDPR where applicable.
The Data Controller does not make decisions based solely on automated processing that produce legal effects or effects of comparable significance, unless this is expressly indicated and permitted by law.
To the extent necessary, data may be disclosed to:
The recipients act as data processors, independent data controllers or authorised parties, depending on the specific role they perform.
An up-to-date list of data processors may be requested from the Data Controller. The data is not disclosed.
Certain technology, payment, newsletter, security, support or analytics providers may process data in countries outside the European Economic Area.
In such cases, the transfer takes place in accordance with Articles 44 et seq. of the GDPR, through adequacy decisions, Standard Contractual Clauses, binding corporate rules or other recognised safeguards.
The data subject may request information on the safeguards adopted by contacting the Data Controller.
Data is retained for a period no longer than that necessary for the purposes, taking into account legal obligations and limitation periods.
Category
| Category | Period or criterion |
| Account | Until a request for erasure or closure is made, except for data necessary for orders, legal obligations or the protection of rights. |
| Orders, payments and invoicing | Generally 10 years from registration or the end of the relationship, unless there is a dispute or further obligations. |
| Complaints, warranty, returns and withdrawal | For the time necessary to handle the matter and subsequently to document compliance and protect rights. |
| Verification of legal age | For the time necessary to verify and document compliance; copies of documents are deleted when no longer required. |
| Requests for information | For the time necessary to respond and subsequently depending on the nature of the request and the retention periods. |
| Newsletter e marketing | Until consent is withdrawn and, in any event, for a maximum period of 24 months from the last expression of interest, unless a different period is lawfully specified. |
| Proof of consent and withdrawal | For the period necessary to demonstrate the lawfulness of the processing and to safeguard your rights. |
| Browsing and security data | For the period necessary to demonstrate the lawfulness of the processing and to protect rights. |
| Cookie | In accordance with the durations specified in the Cookie Policy and in the preferences panel. |
At the end of the applicable periods, the data is deleted, anonymised or retained solely where necessary to comply with legal obligations or to safeguard a right.
In the cases provided for by the GDPR, the data subject may:
These rights are not absolute and may be restricted in the cases provided for by law, for example where retention is necessary to comply with legal obligations or to defend rights.
The exercise of these rights is free of charge, except in the case of manifestly unfounded or excessive requests within the meaning of Article 12 of the GDPR.
Data subjects who consider that the processing is contrary to the law may lodge a complaint with the Data Protection Authority or refer the matter to the competent judicial authority, in accordance with Articles 77 et seq. of the GDPR.
Requests may be sent to:
The request must contain the information necessary to identify the data subject and specify the right being exercised. In the event of reasonable doubts regarding identity, the Data Controller may request additional information strictly necessary for verification.
The Data Controller shall respond without undue delay and, as a rule, within one month, subject to any extensions permitted by the GDPR.
The Sister’s Lab S.r.l. implements technical and organisational measures appropriate to the risk in order to protect data against destruction, loss, alteration, disclosure, unauthorised access or unlawful processing.
These measures are reviewed and updated taking into account technological developments, the nature of the data and the risks involved.
This Policy may be updated in response to regulatory changes, measures taken by the authorities, technological developments, or changes to services, data processing activities or suppliers.
The updated version is published on this page with the date of the update. Where the changes are significant, the Data Controller may also communicate them via email, notices on the website or other appropriate means.
| Document | Privacy Policy – E-commerce website |
| Data Controller | The Sister’s Lab S.r.l. |
| Website | www.mettiunfiore.it |
| Version | 2.0 |
| Revision | 00 |
| Date of issue | 13 July 2026 |
| Next revision | In the event of regulatory, technological or service changes |