Last updated: August 2026
Bottega dei Regali is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This page outlines how we comply with GDPR requirements and explains your rights as a data subject.
Bottega dei Regali acts as the data controller for personal information collected through this website and our services.
Contact details:
Bottega dei Regali
Via delle Botteghe 42
20121 Milan, Italy
[email protected]
We process personal data under the following legal bases:
As a data subject, you have the following rights:
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information within 30 days of your request.
Right to Rectification
If you believe any personal data we hold is inaccurate or incomplete, you have the right to request correction. We will respond to such requests promptly.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purpose it was collected.
Right to Restriction
You can request that we limit how we use your data while a complaint is being resolved or to prevent deletion of data you believe we should retain.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing that significantly affect you. We do not currently use automated decision-making.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days. We may need to verify your identity before processing your request.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
We primarily store and process data within the European Economic Area. If we transfer data outside the EEA, we ensure appropriate safeguards are in place as required by GDPR.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. Retention periods vary based on the type of data and legal requirements.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection authority. In Italy, this is the Garante per la protezione dei dati personali.
We may update this GDPR information from time to time. We encourage you to review this page periodically for any changes.