Privacy & Data Protection Policy

1. Data Controller Identification

This Privacy Policy applies to the processing of personal data by Depotlistripple Atelier & Architecture S.A. (hereinafter "Depotlistripple", "we", "us", or "our"), with registered legal headquarters at Via Monte Napoleone 14, 20121 Milano, Italy (Registration No. IT-MI-94820194). For all data protection and GDPR inquiries, our designated Data Protection Officer (DPO) can be contacted at: [email protected].

2. Regulatory Framework & Principles

Depotlistripple strictly adheres to European Union General Data Protection Regulation (EU) 2016/679 (GDPR), the Italian Privacy Code (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018), the Swiss Federal Act on Data Protection (FADP), and California Consumer Privacy Act (CCPA). We process all information in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.

3. Categories of Personal Data Collected

We may collect and process the following classes of personal data depending on your interaction with our digital platforms and studio services:

4. Legal Grounds for Processing (GDPR Art. 6)

We process personal data solely on the following lawful bases:

5. Third-Party Sub-Processors & Data Transfers

Depotlistripple does not sell, rent, or trade personal data to marketing brokers. Personal data is shared strictly on a need-to-know basis with vetted European sub-processors operating under GDPR Article 28 Data Processing Agreements (DPAs):

6. Data Retention Schedule

Personal data is stored only for as long as necessary to fulfill the specific purposes for which it was gathered. Commission consultation inquiries that do not lead to architectural engagement are purged within 24 months. Formal client contractual archives, building specifications, and material warranty logs are retained for 10 years in compliance with Italian Civil Code Article 2220 architectural liability requirements.

7. Data Subject Rights (EU & Swiss Citizens)

Under GDPR Articles 15–22 and Swiss FADP, you maintain the following rights:

8. Security Architecture

We employ rigorous cryptographic and organizational safeguards, including TLS 1.3 encryption in transit, AES-256 encryption at rest, strict role-based access control (RBAC), multi-factor authentication for studio staff, and periodic vulnerability audits.

9. Amendments

We reserve the right to revise this Privacy Policy to reflect changes in regulatory directives or studio operations. Continued interaction with our website constitutes acknowledgement of the updated terms.