Privacy & Data Protection Policy
1. Data Controller Identification
This Privacy Policy applies to the processing of personal data by Depotlistripple Atelier & Architecture S.A. (hereinafter "Depotlistripple", "we", "us", or "our"), with registered legal headquarters at Via Monte Napoleone 14, 20121 Milano, Italy (Registration No. IT-MI-94820194). For all data protection and GDPR inquiries, our designated Data Protection Officer (DPO) can be contacted at: [email protected].
2. Regulatory Framework & Principles
Depotlistripple strictly adheres to European Union General Data Protection Regulation (EU) 2016/679 (GDPR), the Italian Privacy Code (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018), the Swiss Federal Act on Data Protection (FADP), and California Consumer Privacy Act (CCPA). We process all information in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
3. Categories of Personal Data Collected
We may collect and process the following classes of personal data depending on your interaction with our digital platforms and studio services:
- Identification & Contact Data: Full legal name, residential or commercial billing address, telephone number, email address, and entity affiliations submitted via inquiry forms or private consultation requests.
- Architectural Project Briefs: Cadastral details, geographic property coordinates, spatial program parameters, interior square meterage, architectural preferences, and budget indications disclosed during commissions.
- Technical & Browsing Telemetry: IP addresses, browser user-agent strings, referring URLs, screen resolution metrics, device identifiers, and session timestamps collected automatically via server access logs.
- Sample Kit & Delivery Information: Shipping recipient name, physical delivery address, customs identification numbers, and courier tracking updates for mineral and stone sample dispatches.
4. Legal Grounds for Processing (GDPR Art. 6)
We process personal data solely on the following lawful bases:
- Performance of a Contract (Art. 6(1)(b)): To execute architectural feasibility studies, design contracts, material supply agreements, or client consultations.
- Legitimate Interests (Art. 6(1)(f)): To maintain website security, prevent fraudulent consultation submissions, optimize mineral archive presentations, and protect intellectual property rights.
- Consent (Art. 6(1)(a)): For non-essential analytic cookies, subscription to our architectural monograph essays, or receipt of sample kits.
- Legal Obligations (Art. 6(1)(c)): To comply with Italian, Swiss, and European taxation, anti-money laundering (AML), and architectural statutory records requirements.
5. Third-Party Sub-Processors & Data Transfers
Depotlistripple does not sell, rent, or trade personal data to marketing brokers. Personal data is shared strictly on a need-to-know basis with vetted European sub-processors operating under GDPR Article 28 Data Processing Agreements (DPAs):
- High-security hosting and cloud infrastructure providers located within Frankfurt, Milan, and Zurich data centers (EU/EEA).
- Specialist fine-art couriers and stone transport logistics partners for sample delivery.
- Statutory Italian chartered accountants and legal advisors bound by professional secrecy.
6. Data Retention Schedule
Personal data is stored only for as long as necessary to fulfill the specific purposes for which it was gathered. Commission consultation inquiries that do not lead to architectural engagement are purged within 24 months. Formal client contractual archives, building specifications, and material warranty logs are retained for 10 years in compliance with Italian Civil Code Article 2220 architectural liability requirements.
7. Data Subject Rights (EU & Swiss Citizens)
Under GDPR Articles 15–22 and Swiss FADP, you maintain the following rights:
- Right of Access: Obtain confirmation as to whether your data is being processed and receive a copy of your personal data archive.
- Right to Rectification: Request correction of inaccurate or incomplete architectural records.
- Right to Erasure ("Right to be Forgotten"): Request immediate deletion of your data when retention is no longer legally mandated.
- Right to Restriction & Objection: Object to processing based on legitimate interests or request processing suspension.
- Right to Data Portability: Receive your provided data in a structured, machine-readable JSON/CSV format.
- Right to Lodge a Complaint: Lodge a formal grievance with the Italian Data Protection Authority (Garante per la protezione dei dati personali - www.garanteprivacy.it) or your local EU supervisory authority.
8. Security Architecture
We employ rigorous cryptographic and organizational safeguards, including TLS 1.3 encryption in transit, AES-256 encryption at rest, strict role-based access control (RBAC), multi-factor authentication for studio staff, and periodic vulnerability audits.
9. Amendments
We reserve the right to revise this Privacy Policy to reflect changes in regulatory directives or studio operations. Continued interaction with our website constitutes acknowledgement of the updated terms.