Privacy Policy
PRIVACY POLICY
Last updated: July 14, 2026
This Privacy Policy describes how personal data is collected, used, stored, and protected when users visit and use the website www.tototai.it (the “Website”), operated by Tototai S.r.l. as the Data Controller, in accordance with Regulation (EU) 2016/679 (“GDPR”), Italian Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018, and all applicable data protection laws.
1. Data Controller
Tototai S.r.l.
Registered Office: Piazza della Libertà 1, 33100 Udine (UD), Italy
Operational Office: Via San Marco 11/C, 35129 Padova (PD), Italy
VAT No.: IT03214430302
Email: info@tototaisrl.com
Website: www.tototai.it
For any request concerning the processing of personal data, you may contact the Data Controller using the email address provided above.
2. Categories of Personal Data Processed
While browsing or using the Website, the following categories of personal data may be collected.
Identification Data
- First and last name;
- Shipping and billing address;
- Company name (where applicable);
- Tax code and VAT number (where required).
Contact Data
- Email address;
- Telephone number.
Order Information
- Purchased products;
- Order history;
- Amounts paid;
- Shipping status;
- Customer support requests.
Payment Information
The Website does not store complete payment card details.
Payments are processed through external payment service providers, including:
- PayPal;
- Revolut Business.
Information relating to payment methods is processed exclusively by the respective providers in accordance with their own privacy policies.
Technical Data
During browsing, the following information may be collected automatically:
- IP address;
- Browser type;
- Operating system;
- Date and time of the visit;
- Pages visited;
- Device information;
- Log data.
Cookies
The Website uses technical, analytics, and, subject to the user’s consent, marketing cookies, as described in the Cookie Policy.
3. Purposes of Processing
Personal data is processed for the following purposes.
Performance of a Contract
To:
- register a user account;
- manage orders;
- process payments;
- ship products;
- provide customer support;
- manage returns and refunds;
- fulfill contractual obligations.
Legal basis: Performance of a contract or pre-contractual measures.
Compliance with Legal Obligations
To comply with tax, accounting, civil, and administrative obligations imposed by applicable law.
Legal basis: Legal obligation.
Handling User Requests
To respond to communications submitted via:
- the contact form;
- email;
- telephone.
Legal basis: Performance of pre-contractual measures or the legitimate interests of the Data Controller.
Statistical Analysis
To analyze website traffic and improve Website performance using Google Analytics 4, in accordance with the user’s consent preferences.
Legal basis: Consent, where required.
Marketing
Subject to the user’s consent, personal data may be used for:
- sending newsletters;
- commercial offers;
- promotions;
- advertising campaigns;
- informational communications.
Consent may be withdrawn at any time.
Security
To prevent fraud, unauthorized access, unlawful use, and to ensure the security of the Website.
Legal basis: Legitimate interest of the Data Controller.
4. Methods of Processing
Personal data is processed using electronic systems and, where necessary, paper-based records, while implementing appropriate technical and organizational measures to ensure its security, confidentiality, and integrity.
5. Provision of Personal Data
Providing the personal data required to place an order is mandatory.
Failure to provide such data may prevent:
- account registration;
- purchasing products;
- shipment of orders;
- customer support services.
Providing personal data for marketing purposes is optional.
6. Recipients of Personal Data
Personal data may be disclosed exclusively to parties involved in providing the requested services, including:
- couriers and shipping companies;
- tax and accounting consultants;
- banking institutions;
- PayPal;
- Revolut Business;
- IT service providers;
- hosting providers;
- Google Ireland Ltd.;
- competent public authorities where required by law.
These parties process personal data either as independent data controllers or as data processors, depending on the circumstances.
7. Transfers of Personal Data Outside the EEA
Some service providers may process personal data outside the European Economic Area (EEA).
Where this occurs, personal data is transferred in compliance with the GDPR through the safeguards provided by applicable law, including adequacy decisions adopted by the European Commission or Standard Contractual Clauses (SCCs), where required.
8. Data Retention
Personal data is retained only for the period necessary to achieve the purposes described above and, subsequently, for the period required by applicable law.
In particular:
- Order-related data: retained for up to 10 years for tax and accounting purposes;
- Customer support requests: retained for the time necessary to handle the request and, where appropriate, to protect the legal rights of the Data Controller;
- Marketing data: retained until consent is withdrawn or for the period permitted under applicable law;
- Browsing data: retained as described in the Cookie Policy.
9. Data Subject Rights
Users may exercise, at any time, the rights provided for under Articles 15–22 of the GDPR, including the right to:
- obtain confirmation as to whether personal data concerning them is being processed;
- access their personal data;
- request the rectification of inaccurate data;
- request the erasure of personal data where permitted by law;
- request restriction of processing;
- object to processing where applicable;
- receive their personal data in a structured, commonly used, and machine-readable format and request its portability, where applicable;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before such withdrawal.
Requests may be sent to:
Users also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
10. Data Security
Tototai S.r.l. implements appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, unauthorized access, alteration, disclosure, or misuse.
11. Children
The Website is not intended for individuals under the age of 18.
Should the Data Controller become aware that personal data relating to minors has been collected in violation of applicable law, such data will be deleted without undue delay.
12. Changes to this Privacy Policy
This Privacy Policy may be updated at any time to reflect legislative, regulatory, or organizational changes.
The updated version will be published on the Website together with the date of the latest revision.
13. Contact Information
For any questions regarding this Privacy Policy, please contact:
Tototai S.r.l.
Piazza della Libertà 1
33100 Udine (UD), Italy
Operational Office:
Via San Marco 11/C
35129 Padova (PD), Italy
Email: info@tototaisrl.com
Website: www.tototai.it
