Last updated: 5 August 2026
Privacy notice
Fashion From Italy™ — version dated 5 August 2026. This notice covers the website, sourcing requests, communications, quotations, possible purchases and shipments, support and compliance checks.
1. Controller
The controller is MBC Consulting & Services S.r.l., Piazza IV Novembre, 4, 20124 Milan, Italy, VAT and Tax ID 12798050964, operator of Fashion From Italy™.
Contacts: info@mbcconsulting.net; PEC mbccs@pec.cloud; +39 388 1062165. No DPO contact is stated unless formally appointed.
2. Scope
This notice applies to the site, request forms, communications, product assessment and search, quotations, purchases and shipments, support, compliance checks and relationships with private and professional clients. Cookie information reflects the tools actually installed.
3. Data categories
| Category | Examples |
|---|---|
| Identity and contact | Name, surname, email, telephone, Telegram, WhatsApp, language, time zone, company and role. |
| Request | Photos, screenshots, links, descriptions, brand, model, SKU, size, colour, material, collection, condition, quantity, alternatives, budget and urgency. |
| Delivery and operation | Residence, delivery location, recipient, end-user, purpose, currency, order, invoice, shipment and support. |
| Payment | Status, amount, currency and transaction reference. Full card data is handled by the payment provider and is not stored by the site. |
| Compliance | Data needed for sanctions, export, customs, fraud, recipient and end-user checks; identity documents only when necessary and proportionate. |
| Communications | Messages, clarifications, preferences, quotations, disputes and support history. |
| Technical | IP, date and time, logs, browser, device, security events and identifiers according to preferences. |
| Third parties | Recipient, end-user or company contact data supplied by the requester. |
4. Unrequested data and uploads
The service does not request health, biometric, political, religious, sexual-orientation or trade-union data. Do not include them. Product images should not contain unnecessary faces, documents, addresses or conversations. Excessive data may be removed, masked or deleted.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Assess and manage a request; contact, search and prepare a proposal | Pre-contractual steps and contract — Art. 6(1)(b) GDPR. |
| Purchase, invoice, payment, shipment, returns and support | Contract and legal obligations — Art. 6(1)(b) and (c). |
| Sanctions, exports, customs, fraud, recipient and end-user checks | Legal obligations and legitimate interest in preventing unlawful or risky operations — Art. 6(1)(c) and (f). |
| Security and abuse prevention | Legitimate interest — Art. 6(1)(f). |
| Legal claims and disputes | Legitimate interest and, where applicable, legal obligation. |
| Marketing | Consent — Art. 6(1)(a), optional and withdrawable. |
| Non-essential analytics | Consent unless the tool is strictly technical under applicable law. |
6. Processing and AI
Authorised staff process data electronically and, where needed, manually. AI may assist extraction, classification, translation, comparison, clarification and anomaly flags. Acceptance, compliance, purchase, payment and shipping decisions remain under human control. No solely automated decision with legal or similarly significant effects is planned under Article 22 GDPR.
7. Recipients
Data may be shared as necessary with hosting, cloud, database, backup, security, maintenance, CRM, email and support providers; messaging services; payment providers and banks; sellers and professionals consulted for availability; carriers, insurers and customs operators; screening and verification providers; professional advisers and competent authorities. Article 28 processor agreements are used where applicable; some recipients act as independent controllers.
8. International transfers
Global providers and the international service may involve transfers outside the EEA. Before launch, actual providers and transfers must be identified. Transfers will rely on adequacy decisions, Standard Contractual Clauses, other Article 46 safeguards or a limited lawful derogation.
9. Other people’s data
Anyone supplying another person’s data must be authorised and provide essential privacy information. Where required, the company will provide information directly under Article 14 GDPR.
10. Retention
| Category | Period / criterion |
|---|---|
| Unsent drafts | Up to 30 days unless stored only locally. |
| Rejected, not found or non-contract requests | Normally 24 months after closure. |
| Requests with purchase or contract | Contract, accounting and tax data for 10 years or another legal period, longer in a dispute. |
| Product photos and media | Normally no more than 24 months after closure unless needed as evidence, for a dispute, authenticity or an authorised case study. |
| Compliance data | For the legally required or demonstrably necessary period; normally up to 10 years for completed operations unless records specify otherwise. |
| Technical and security logs | Normally up to 6 months, longer for incidents or legal duties. |
| Marketing | Until withdrawal or 24 months after the last meaningful interaction, retaining minimal suppression evidence. |
| Cookies and preferences | According to the cookie policy and actual durations. |
11. Required and optional data
Mandatory fields are needed to assess the request or manage the relationship. Missing data may prevent search, quotation, purchase, payment or delivery. Marketing and non-essential tools are always optional.
12. Rights
Where Articles 15–22 GDPR apply, you may request access, correction, deletion, restriction, portability, objection, direct-marketing objection and consent withdrawal. Contact info@mbcconsulting.net or mbccs@pec.cloud. Identity verification may be requested.
13. Complaint
A complaint may be lodged with the Italian Data Protection Authority or the competent supervisory authority in the Member State of residence, work or alleged infringement.
14. Minors
The service is for adults and professional operators. Autonomous requests from minors are not knowingly collected. Unnecessary minor data will be removed or handled through an authorised adult.
15. Security
Risk-appropriate measures include access controls, encryption, backups, logging, upload protection, incident response and provider selection. No system can guarantee zero risk.
16. Updates
This notice may change when the service, providers or law change. The version and date will be published; material changes affecting ongoing processing will be communicated appropriately.