Last updated: 5 August 2026

Privacy notice

Fashion From Italy™ — version dated 5 August 2026. This notice covers the website, sourcing requests, communications, quotations, possible purchases and shipments, support and compliance checks.

1. Controller

The controller is MBC Consulting & Services S.r.l., Piazza IV Novembre, 4, 20124 Milan, Italy, VAT and Tax ID 12798050964, operator of Fashion From Italy™.

Contacts: info@mbcconsulting.net; PEC mbccs@pec.cloud; +39 388 1062165. No DPO contact is stated unless formally appointed.

2. Scope

This notice applies to the site, request forms, communications, product assessment and search, quotations, purchases and shipments, support, compliance checks and relationships with private and professional clients. Cookie information reflects the tools actually installed.

3. Data categories

CategoryExamples
Identity and contactName, surname, email, telephone, Telegram, WhatsApp, language, time zone, company and role.
RequestPhotos, screenshots, links, descriptions, brand, model, SKU, size, colour, material, collection, condition, quantity, alternatives, budget and urgency.
Delivery and operationResidence, delivery location, recipient, end-user, purpose, currency, order, invoice, shipment and support.
PaymentStatus, amount, currency and transaction reference. Full card data is handled by the payment provider and is not stored by the site.
ComplianceData needed for sanctions, export, customs, fraud, recipient and end-user checks; identity documents only when necessary and proportionate.
CommunicationsMessages, clarifications, preferences, quotations, disputes and support history.
TechnicalIP, date and time, logs, browser, device, security events and identifiers according to preferences.
Third partiesRecipient, end-user or company contact data supplied by the requester.

4. Unrequested data and uploads

The service does not request health, biometric, political, religious, sexual-orientation or trade-union data. Do not include them. Product images should not contain unnecessary faces, documents, addresses or conversations. Excessive data may be removed, masked or deleted.

5. Purposes and legal bases

PurposeLegal basis
Assess and manage a request; contact, search and prepare a proposalPre-contractual steps and contract — Art. 6(1)(b) GDPR.
Purchase, invoice, payment, shipment, returns and supportContract and legal obligations — Art. 6(1)(b) and (c).
Sanctions, exports, customs, fraud, recipient and end-user checksLegal obligations and legitimate interest in preventing unlawful or risky operations — Art. 6(1)(c) and (f).
Security and abuse preventionLegitimate interest — Art. 6(1)(f).
Legal claims and disputesLegitimate interest and, where applicable, legal obligation.
MarketingConsent — Art. 6(1)(a), optional and withdrawable.
Non-essential analyticsConsent unless the tool is strictly technical under applicable law.

6. Processing and AI

Authorised staff process data electronically and, where needed, manually. AI may assist extraction, classification, translation, comparison, clarification and anomaly flags. Acceptance, compliance, purchase, payment and shipping decisions remain under human control. No solely automated decision with legal or similarly significant effects is planned under Article 22 GDPR.

7. Recipients

Data may be shared as necessary with hosting, cloud, database, backup, security, maintenance, CRM, email and support providers; messaging services; payment providers and banks; sellers and professionals consulted for availability; carriers, insurers and customs operators; screening and verification providers; professional advisers and competent authorities. Article 28 processor agreements are used where applicable; some recipients act as independent controllers.

8. International transfers

Global providers and the international service may involve transfers outside the EEA. Before launch, actual providers and transfers must be identified. Transfers will rely on adequacy decisions, Standard Contractual Clauses, other Article 46 safeguards or a limited lawful derogation.

9. Other people’s data

Anyone supplying another person’s data must be authorised and provide essential privacy information. Where required, the company will provide information directly under Article 14 GDPR.

10. Retention

CategoryPeriod / criterion
Unsent draftsUp to 30 days unless stored only locally.
Rejected, not found or non-contract requestsNormally 24 months after closure.
Requests with purchase or contractContract, accounting and tax data for 10 years or another legal period, longer in a dispute.
Product photos and mediaNormally no more than 24 months after closure unless needed as evidence, for a dispute, authenticity or an authorised case study.
Compliance dataFor the legally required or demonstrably necessary period; normally up to 10 years for completed operations unless records specify otherwise.
Technical and security logsNormally up to 6 months, longer for incidents or legal duties.
MarketingUntil withdrawal or 24 months after the last meaningful interaction, retaining minimal suppression evidence.
Cookies and preferencesAccording to the cookie policy and actual durations.

11. Required and optional data

Mandatory fields are needed to assess the request or manage the relationship. Missing data may prevent search, quotation, purchase, payment or delivery. Marketing and non-essential tools are always optional.

12. Rights

Where Articles 15–22 GDPR apply, you may request access, correction, deletion, restriction, portability, objection, direct-marketing objection and consent withdrawal. Contact info@mbcconsulting.net or mbccs@pec.cloud. Identity verification may be requested.

13. Complaint

A complaint may be lodged with the Italian Data Protection Authority or the competent supervisory authority in the Member State of residence, work or alleged infringement.

14. Minors

The service is for adults and professional operators. Autonomous requests from minors are not knowingly collected. Unnecessary minor data will be removed or handled through an authorised adult.

15. Security

Risk-appropriate measures include access controls, encryption, backups, logging, upload protection, incident response and provider selection. No system can guarantee zero risk.

16. Updates

This notice may change when the service, providers or law change. The version and date will be published; material changes affecting ongoing processing will be communicated appropriately.