Privacy policy
Last updated: 15 May 2026
This Privacy Policy is issued pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree no. 196 of 30 June 2003, as amended by Italian Legislative Decree no. 101 of 10 August 2018 (the "Italian Privacy Code"). It describes how personal data of users who interact with the website solkai.it (the "Website") and the related services are processed.
1. Data controller
The data controller is EmmePi S.r.l. (the "Controller" or "we"), with registered office at Via Magenta 77, 20017 Rho (MI), Italy, VAT number IT 14405370967, email info@solkai.it, phone +39 349 310 6547.
2. Data Protection Officer (DPO)
The Controller is not required to appoint a Data Protection Officer under Article 37 of the GDPR. Any request relating to personal data may be addressed to info@solkai.it, with subject line "Privacy GDPR".
3. Categories of personal data processed
Depending on how the user interacts with the Website, the Controller may process the following categories of personal data:
- Identification and contact data: first name, last name, postal address (billing and shipping), phone number, email address.
- Customer account data: login credentials, preferences, order history, wishlist.
- Order data: purchased items, amounts, order date, delivery method, order notes.
- Payment data: credit card number, expiry date and security code are neither collected nor stored by the Controller; they are processed directly by the payment service providers (Shopify Payments, Stripe, PayPal and other authorised operators). We only receive transaction confirmation and minimum information (e.g. last four digits of the card) for accounting and customer-service purposes.
- Communication data: content of emails, WhatsApp messages and other communications sent to customer service.
- Browsing data: IP address, browser and device type, operating system, pages visited, time on page, referrer, session parameters, cookie identifiers.
- Marketing and profiling data (subject to consent): purchasing preferences, inferred interests, email opens and clicks, automated segmentation.
Special categories of personal data within the meaning of Article 9 of the GDPR (e.g. health data, sexual orientation, religious beliefs) are not processed. Users are therefore asked not to include such information in contact forms or communications.
4. Purposes of processing and legal bases
| Purpose | Legal basis | Retention period |
|---|---|---|
| Order management: conclusion of the sale contract, order processing, shipping, returns, refunds and after-sales support. | Article 6(1)(b) GDPR (performance of a contract or pre-contractual measures). | For the duration of the contractual relationship and for 10 years thereafter pursuant to Articles 2214 and 2220 of the Italian Civil Code (retention of accounting records). |
| Tax, accounting and administrative obligations. | Article 6(1)(c) GDPR (compliance with a legal obligation). | 10 years from the close of the financial year (Italian Presidential Decree no. 600/1973 and Articles 2214 and 2220 of the Italian Civil Code). |
| Creation and management of the customer account. | Article 6(1)(b) GDPR (registration contract). | Until deletion of the account or, in the absence of activity, 36 months from the last log-in. |
| Customer service and management of enquiries, complaints and data-subject rights requests. | Article 6(1)(b) and (f) GDPR (legitimate interest in providing adequate customer service). | 24 months from the closure of the request; 10 years for formal complaints. |
| Sending direct marketing communications by email regarding products, news, events and promotional initiatives of the Controller (newsletter). | Article 6(1)(a) GDPR (free and specific consent). For customers who have already purchased similar products, the so-called "soft spam" provision under Article 130(4) of the Italian Privacy Code applies (legitimate interest), subject to the right to object. | Until withdrawal of consent or objection; in any case no longer than 24 months from the last meaningful interaction, subject to renewal. |
| Profiling of purchase habits and automated segmentation for tailored marketing. | Article 6(1)(a) GDPR (specific separate consent). | 12 months from collection or from the last interaction, subject to renewal of consent. |
| Aggregate statistical analysis of traffic and improvement of the Website (aggregate analytics cookies). | Article 6(1)(f) GDPR (legitimate interest) for fully aggregated analytics; Article 6(1)(a) GDPR (consent) for analytics with non-anonymised identifiers. | See the Cookie Policy for details. |
| Fraud prevention, Website security, protection of information systems and risk management. | Article 6(1)(f) GDPR (legitimate interest in preventing fraud and abuse). | 12 months, unless a longer retention is necessary because of an ongoing investigation. |
| Establishment, exercise or defence of legal claims. | Articles 6(1)(f) and 9(2)(f) GDPR. | For the time strictly necessary to protect the right, even beyond ordinary limitation periods. |
5. Mandatory or optional nature of the data
Providing identification, contact and payment data is necessary in order to fulfil the order and to comply with legal obligations. Failure to provide such data makes it impossible to enter into the contract. Providing data for marketing and profiling purposes is optional: the absence of consent does not affect the possibility of purchasing on the Website.
6. Method of processing
Personal data are processed by electronic and organisational means that are appropriate to ensure their security, confidentiality, integrity and availability, in accordance with Articles 25 and 32 of the GDPR. Security measures include, by way of example, encryption in transit (TLS), access controls, multi-factor authentication for corporate users, access logging, environment segregation, regular backups and pseudonymisation where technically feasible.
7. Categories of recipients
Personal data may be disclosed to the following recipients, acting either as processors (Article 28 GDPR) or as independent controllers, only for the purposes set out above:
7.1 E-commerce platform and payments
- Shopify International Limited (Ireland) and Shopify Inc. (Canada) for the e-commerce platform, hosting, technological infrastructure, checkout and related analytics features. Privacy notice: shopify.com/legal/privacy.
- Payment providers (Shopify Payments, Stripe, PayPal and other authorised operators): they process payment data independently in accordance with their respective privacy policies.
- Couriers and logistics operators (such as DHL, BRT, UPS, GLS, Poste Italiane) for the delivery of products and the handling of returns.
7.2 Email marketing and CRM
- Klaviyo Inc. (incorporated in Delaware, USA, with operational seat in Boston, MA) for management of the marketing database, sending of newsletters and transactional communications, segmentation, behavioural profiling of subscribers and recognition of subscribers during purchase sessions. Processing for marketing purposes takes place only on the basis of consent as described in section 4 above. Privacy notice: klaviyo.com/legal/privacy-notice.
7.3 Statistical analytics and user-experience tools
- Google Ireland Limited (Dublin, Ireland) for the Google Analytics 4 service (statistical analysis of traffic, campaign attribution, conversion measurement) and Google Search Console (monitoring of indexing and organic search queries). Google Search Console does not install cookies on the visitor's device: it processes only aggregated data on Website indexing and does not identify individual users. Google Analytics operates on the basis of consent, as set out in the Cookie Policy. Privacy notice: policies.google.com/privacy.
- Microsoft Ireland Operations Limited (Dublin, Ireland) for the Microsoft Clarity service, used for anonymised session recording, generation of heatmaps, analysis of user behaviour and detection of anomalies in the user experience. The service masks the content of sensitive input fields by default. Privacy notice: privacy.microsoft.com.
7.4 Advertising and conversion-tracking tools
- Meta Platforms Ireland Limited (Dublin, Ireland) for the Meta Pixel and Conversion API services for Facebook and Instagram, used to measure conversions, optimise advertising campaigns, build custom audiences and run retargeting activities. Processing takes place on the basis of explicit consent. Privacy notice: facebook.com/privacy/policy.
- TikTok Information Technologies UK Limited (London, United Kingdom) and TikTok Technology Limited (Dublin, Ireland) for the TikTok Pixel service and Events API, used to measure conversions, optimise advertising campaigns on the TikTok platform, build custom audiences and run retargeting activities. Processing takes place on the basis of explicit consent. Privacy notice: tiktok.com/legal/page/eea/privacy-policy/en.
- Google Ireland Limited for Google Ads and Google Tag Manager, used to track conversions from Google advertising campaigns, run retargeting on Google Display Network and YouTube, and automate bidding. Processing takes place on the basis of explicit consent.
7.5 Other recipients
- Professionals, consultants and service providers (tax advisors, lawyers, fiscal consultants, audit firms, marketing agencies) for legal compliance, performance of the contractual relationship and management of litigation.
- Public authorities where required by law, judicial order or request from supervisory bodies.
Personal data are neither disseminated nor sold to third parties. An updated list of the processors may be requested by writing to info@solkai.it.
8. Transfers of personal data outside the EU
Some of the recipients listed in section 7 also process personal data outside the European Economic Area (EEA). In particular:
- Shopify Inc. – Canada (country subject to an adequacy decision pursuant to Article 45 GDPR – Decision 2002/2/EC);
- Klaviyo Inc. – United States of America;
- Google LLC – United States of America (even though the front-line provider is Google Ireland Limited, the infrastructure may involve transfers to the USA);
- Microsoft Corporation – United States of America (even though the front-line provider is Microsoft Ireland Operations Limited);
- Meta Platforms, Inc. – United States of America (parent company of Meta Platforms Ireland Limited);
- TikTok Inc. – United States of America, and other ByteDance group infrastructure, including data centres in Ireland and Norway ("Project Clover").
For transfers to the United States, the Controller ensures that the transfer takes place on the basis of appropriate safeguards under Chapter V of the GDPR, in particular:
- EU-U.S. Data Privacy Framework (European Commission adequacy decision of 10 July 2023) for self-certified US providers (Google LLC, Microsoft Corporation, Meta Platforms Inc., Klaviyo Inc.);
- Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914, supplemented by additional technical and organisational measures (encryption in transit and at rest, pseudonymisation, access control, periodic audits) where the Data Privacy Framework does not apply or where a further level of protection is required, in particular for transfers to TikTok Inc. and to ByteDance group companies.
A copy of the safeguards in place may be requested free of charge at info@solkai.it.
9. Automated decision-making
The Controller does not carry out fully automated decision-making that produces legal effects on the data subject or significantly affects them within the meaning of Article 22 of the GDPR, save for the marketing segmentation and profiling activities described in section 4, which are based on consent. The data subject may withdraw consent at any time or request human intervention.
10. Rights of the data subject
At any time the data subject may exercise the rights granted by Articles 15 to 22 of the GDPR:
- Right of access (Article 15): obtain confirmation of the processing and a copy of personal data.
- Right to rectification (Article 16): obtain correction of inaccurate data or completion of incomplete data.
- Right to erasure (Article 17, "right to be forgotten"): obtain deletion of personal data in the cases set out by law.
- Right to restriction (Article 18): request suspension of processing in specific circumstances.
- Right to data portability (Article 20): receive personal data in a structured, commonly used and machine-readable format and have such data transmitted to another controller.
- Right to object (Article 21): object to processing based on legitimate interest or for direct marketing, including profiling.
- Right not to be subject to automated decisions (Article 22), as set out above.
- Right to withdraw consent at any time, without prejudice to the lawfulness of processing based on consent before its withdrawal.
The rights may be exercised free of charge by writing to info@solkai.it. The Controller will reply within 30 days of receipt, extendable by a further 60 days where the request is particularly complex (the data subject will be informed of any extension). The Controller may request the information necessary to verify the identity of the requester.
11. Complaint to the supervisory authority
The data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it, Piazza Venezia 11, 00187 Rome, Italy), or with the supervisory authority of the EU Member State of residence, work or place of alleged infringement, under Article 77 of the GDPR. Other administrative or judicial remedies remain available (Article 79 GDPR).
12. Minors
The products and services offered through the Website are not directed at children under 16 years of age. The Controller does not knowingly collect personal data of children under 16. Should it become aware of any such data collected without the consent of the holder of parental responsibility, it will be promptly deleted. Parents or guardians who believe that a minor has provided personal data are invited to contact info@solkai.it.
13. Cookies and similar technologies
The Website uses cookies and similar technologies. Further information is set out in the Cookie Policy, which forms an integral part of this Privacy Policy.
14. Changes to this Policy
This Privacy Policy may be updated from time to time, including as a result of regulatory changes, technological developments or changes in the Controller's activity. Changes take effect when published on the Website. Users are encouraged to review this page periodically; the last-updated date is set out at the beginning of the document. Material changes will be specifically notified, where possible, also by email to subscribers.