Skip to content

Privacy Policy

This Privacy Policy describes how Cartiere Paolo Pigna S.p.A. collects and processes Personal Data relating to Users who visit and use pigna.it, including the e-commerce services available through the website.

Data Controller

The Data Controller is Cartiere Paolo Pigna S.p.A., with registered office at Via Paolo Pigna 2, 24022 Alzano Lombardo (BG), Italy.
Tel. +39 035 519111.

For information concerning the processing of Personal Data by the Data Controller, and to exercise data subject rights under Articles 15–22 of Regulation (EU) 2016/679 (“GDPR”), Users may contact privacy@pigna.it.

Data Protection Officer (DPO)

The Data Controller has appointed a Data Protection Officer (“DPO”) pursuant to Article 37 GDPR. The DPO may be contacted at dpo@pigna.it.

Types of Personal Data processed

Personal Data processed through this website, directly or through third parties, may include:

  • identification data, such as first name and last name;
  • contact data, such as email address and telephone number;
  • residential, billing and/or shipping address;
  • customer account data, where an account is created;
  • data relating to products viewed, selected, added to cart, ordered or purchased;
  • order, payment, refund and transaction data;
  • shipping and delivery data;
  • data contained in support requests or communications sent to the Data Controller;
  • data required for administrative, accounting, tax and legal obligations;
  • preferences relating to commercial communications and marketing;
  • Usage Data, IP address, technical information about the device and browser;
  • Trackers and cookies;
  • data relating to interactions with the website, advertising campaigns and communications received, including, where applicable, clicks, scrolling, page views, interactions with interface elements and session statistics.

Further details on the specific categories of Personal Data processed through individual third-party services are provided in the “Details on the processing of Personal Data” section.

Personal Data may be freely provided by the User or, in the case of Usage Data and Trackers, collected automatically when using the website.

Where certain Data are required to enter into or perform a contract, comply with a legal obligation or provide a service requested by the User, failure to provide such Data may make it impossible to complete a purchase or provide the requested service.

Methods of processing

The Data Controller implements appropriate technical and organisational measures designed to prevent unauthorised access, disclosure, alteration or destruction of Personal Data.

Processing is carried out using IT and telematic tools, according to procedures and logic strictly related to the purposes described in this Privacy Policy.

In addition to the Data Controller, Personal Data may be accessed by internal personnel involved in the organisation and management of the website and commercial activities, such as administrative, sales, marketing, customer service, system administration and other authorised personnel.

External parties may also process Personal Data when carrying out specific activities, including providers of the e-commerce platform and related technology services, payment service providers, logistics operators, couriers, marketing and analytics providers, hosting providers, cybersecurity providers, consultants and other parties appointed, where necessary, as Data Processors pursuant to Article 28 GDPR.

An updated list of Data Processors may be requested from the Data Controller.

Place of processing and international transfers

Personal Data are processed at the Data Controller’s operating offices and at the locations where the parties involved in the processing activities described in this Privacy Policy are established.

Some providers used to operate the website and related services may involve the transfer or processing of Personal Data in countries outside the European Economic Area.

Where such transfers occur, they are carried out in accordance with Articles 44 et seq. GDPR and on the basis of safeguards provided by applicable law, such as adequacy decisions, Standard Contractual Clauses or other recognised transfer mechanisms.

For further information on transfers connected with individual services, Users may refer to the “Details on the processing of Personal Data” section or contact the Data Controller.

Purposes of processing

1. Website browsing, operation, content delivery and security

Technical and Usage Data may be processed to enable the proper operation of the website, deliver content, optimise performance, protect the infrastructure, prevent fraudulent or automated use and ensure service availability.

Data processed: IP address, Usage Data, technical information about the device and browser, logs, Trackers and security-related data.

Legal basis: the Data Controller’s legitimate interest in website security and proper operation, Article 6(1)(f) GDPR; where processing is necessary to provide a service requested by the User, Article 6(1)(b) GDPR.

Retention: for the period strictly necessary to ensure website operation, security and protection and, where necessary, to establish, exercise or defend legal claims.

2. Customer account registration and management

Where the website allows Users to create a personal account, the Data provided are processed to enable registration, authenticate the User, manage the profile and provide access to customer-only features.

Data processed: first name, last name, email address, credentials and any other data associated with the account.

Legal basis: performance of a contract or steps taken at the User’s request prior to entering into a contract, Article 6(1)(b) GDPR.

Retention: for the duration of the account and thereafter for the period required to comply with legal obligations or protect the Data Controller’s rights.

3. Cart, checkout and order management

User Data are processed to enable products to be added to the cart, manage checkout, receive and confirm orders, verify product availability and properly perform the sales contract.

Data processed: identification and contact data, purchased products, quantities, amounts, order data, billing and shipping address and any other information required to complete the purchase.

Legal basis: performance of a contract and steps taken at the User’s request prior to entering into a contract, Article 6(1)(b) GDPR.

Retention: for the period necessary to fulfil the order and thereafter for the periods required by applicable civil, tax and accounting law and for the protection of the Data Controller’s rights.

4. Payment management

Data required for a transaction are processed to receive, verify and manage payment for an order, as well as refunds, reversals or disputes. Depending on the payment method selected, certain Data may be collected directly by the relevant payment service provider.

Depending on the payment methods actually enabled at checkout, the website may offer services and payment networks such as PayPal, Apple Pay, Google Pay, Visa, Mastercard and American Express.

The Data Controller may receive information regarding the outcome, status or identifier of a transaction without necessarily having access to the complete details of the payment instrument used.

Data processed: order data, amount, transaction identifiers and data required by the selected payment method.

Legal basis: performance of a contract, Article 6(1)(b) GDPR; where applicable, compliance with a legal obligation, Article 6(1)(c) GDPR.

Retention: for the period required to manage the transaction and any legal, accounting or dispute-related obligations.

5. Shipping and delivery

User Data are processed and disclosed to parties involved in preparing, handling and delivering purchased products.

Data processed: first name, last name, shipping address, contact details, order data and other information required for delivery.

Legal basis: performance of a contract, Article 6(1)(b) GDPR.

Retention: for the period required to complete delivery and thereafter where necessary to handle complaints, disputes or legal obligations.

6. Returns, refunds, complaints and after-sales support

Personal Data may be processed to manage returns, withdrawal rights, replacements, refunds, complaints, warranties and support requests after a purchase.

Data processed: identification and contact data, information relating to the order and purchased product, contents of requests and any documents provided.

Legal basis: performance of a contract and compliance with legal obligations, Article 6(1)(b) and (c) GDPR.

Retention: for the period required to handle the request and thereafter for the applicable periods needed to protect the parties’ rights.

7. Order and service-related communications

The Data Controller may send communications strictly necessary for managing the User account, order, payment, shipping, return or other services requested by the User. Such communications are functional or transactional and are separate from marketing communications.

Data processed: name, email address, contact details and data relating to the relevant order or service.

Legal basis: performance of a contract or provision of a service requested by the User, Article 6(1)(b) GDPR.

Retention: according to the period connected with the provision of the service and any applicable legal obligations.

8. Administrative, accounting, tax and legal obligations

The Data Controller processes Personal Data as required to comply with applicable administrative, accounting, tax, commercial and consumer protection laws.

Data processed: identification data, order and transaction data, billing data and any further information required to comply with legal obligations.

Legal basis: compliance with a legal obligation, Article 6(1)(c) GDPR.

Retention: for the periods required by applicable law.

9. Fraud, bot and abuse prevention and protection of rights

Personal Data may be processed to identify unusual transactions, attempted fraud, automated traffic, abuse or unlawful use of the website and, where necessary, to establish, exercise or defend the Data Controller’s rights.

Data processed: account, order and transaction data, IP address, logs, technical identifiers and security-related data.

Legal basis: the Data Controller’s legitimate interest in fraud prevention, security and protection of its rights, Article 6(1)(f) GDPR; where applicable, compliance with a legal obligation, Article 6(1)(c) GDPR.

Retention: for the period necessary to prevent or manage fraud or protect the relevant right.

10. Contacting the User and managing requests

When a User contacts the Data Controller through forms, email or other channels available on the website, the Data provided are used to respond to requests, provide information and manage pre-contractual or support requests.

Data processed: first name, last name, email address, telephone number and contents of the request.

Legal basis: steps taken at the User’s request prior to entering into a contract, Article 6(1)(b) GDPR, or the Data Controller’s legitimate interest in responding to requests received, Article 6(1)(f) GDPR, depending on the nature of the request.

Retention: for the period necessary to manage the request and thereafter where required to protect legal rights.

11. Newsletters, promotional forms and marketing communications through Klaviyo

With the User’s consent, the Data Controller may use the User’s email address and other relevant Data to send newsletters, promotional communications, information about products, initiatives, offers and Pigna commercial activities. Klaviyo is currently used for these activities, including the related contact collection forms.

Data processed: email address, name, marketing preferences and data entered into forms.

Legal basis: User consent, Article 6(1)(a) GDPR.

Retention: until consent is withdrawn or the right to object is exercised, without prejudice to Data required to document consent or its withdrawal.

12. Analytics, performance measurement and user experience improvement

Subject to consent where required by applicable law, the website may use analytics and interaction-analysis tools to understand how Users use the website, measure performance and improve content, interface and services. Such tools may include Shopify Analytics, Google Analytics 4 and Microsoft Clarity.

Data processed: Usage Data, Trackers, technical information, page views, interactions, clicks, scrolling and session statistics.

Legal basis: User consent, Article 6(1)(a) GDPR, where required by applicable law.

Retention: according to the periods stated for the individual services and within the limits of the User’s expressed preferences.

13. Tag management and technical conversion measurement

The website may use tools to centrally manage tags and scripts and to enable proper technical measurement of conversions, such as Google Tag Manager and Google Conversion Linker. The use of such tools is ancillary to the processing carried out by the services activated through them.

Data processed: Usage Data, technical identifiers and Trackers, depending on the tags and services activated.

Legal basis: the legal basis depends on the purpose of the service activated through the tag; for analytics, advertising or profiling services subject to consent, processing is based on User consent, Article 6(1)(a) GDPR.

Retention: according to the periods provided for the individual services activated.

14. Advertising, remarketing and conversion measurement

With the User’s consent, the website may use advertising tools to measure campaign effectiveness, attribute conversions, create audience segments and display relevant advertising. Such services may include Google Ads, Meta Events Manager and Meta Pixel.

Data processed: Usage Data, Trackers, online identifiers, interactions with the website, conversion and campaign-related data.

Legal basis: User consent, Article 6(1)(a) GDPR.

Retention: according to the periods stated for the individual services and within the limits of the User’s expressed preferences.

15. Personalisation and automation of marketing communications

Subject to consent where required, the Data Controller may use information relating to purchases, browsing and interactions with communications to segment recipients, personalise content and activate automated flows through Klaviyo.

Data processed: identification and contact data, purchase data, interactions with the website and communications, preferences and Trackers.

Legal basis: User consent, Article 6(1)(a) GDPR.

Retention: until consent is withdrawn or for the periods provided by the service in relation to the relevant purpose.

Details on the processing of Personal Data

Information relating to the individual services and providers used by the website, the categories of Data processed, the specific purposes and any international transfers is set out below and kept updated also through Iubenda.

Privacy Policy

Cookie Policy

This website uses Cookies and other Trackers. For further information on the categories of Trackers used, their purposes and how Users may express or modify their preferences, please refer to the Cookie Policy.

Legal basis of processing

PurposeLegal basis
Website browsing, operation and securityLegitimate interest / performance of the requested service
Customer account registration and managementPerformance of a contract or pre-contractual steps
Cart, checkout and order managementPerformance of a contract or pre-contractual steps
Payment managementPerformance of a contract / legal obligation
Shipping and deliveryPerformance of a contract
Returns, refunds, complaints and after-sales supportPerformance of a contract / legal obligation
Order and service-related communicationsPerformance of a contract
Administrative, accounting, tax and legal obligationsLegal obligation
Fraud, bot and abuse prevention and protection of rightsLegitimate interest / legal obligation where applicable
Contact requestsPre-contractual steps / legitimate interest
Newsletters and marketing communicationsConsent
Analytics and user experience analysisConsent, where required
Tag management and technical measurementDepends on the purpose of the activated service; consent for analytics/advertising where required
Advertising, remarketing and conversion measurementConsent
Marketing personalisation and automationConsent

The legal bases above refer to Article 6(1) GDPR.

Additional information on retention

Personal Data are retained for the period required to achieve the purposes for which they were collected. A longer period may apply where necessary to comply with legal obligations or to establish, exercise or defend legal claims.

  • Data processed for the performance of a contract are retained for the period required to fully perform the contract and thereafter for the periods required by applicable law.
  • Data relating to purchases, orders, billing and transactions may be retained for the period required by civil, accounting and tax obligations.
  • Data processed on the basis of consent are retained until consent is withdrawn, without prejudice to any period required to document consent previously given.
  • Data processed on the basis of legitimate interest are retained for the period necessary to pursue such interest, taking into account the rights and freedoms of the data subject.
  • Data required to handle disputes or protect legal rights may be retained until the relevant dispute has been resolved and for any additional period provided by applicable law.

At the end of the applicable retention period, Personal Data will be deleted or anonymised unless another legal basis permits further retention.

Recipients and categories of parties to whom Data may be disclosed

Personal Data may be disclosed, to the extent strictly necessary, to the following categories of recipients:

  • providers of the e-commerce platform and related technology services;
  • payment service providers and payment networks;
  • parties involved in order preparation, logistics and delivery;
  • IT support, hosting, content delivery and cybersecurity providers;
  • analytics, advertising, marketing automation and communications providers;
  • administrative, tax, accounting and legal advisers;
  • public authorities and other parties where disclosure is required by law.

Depending on the circumstances, such parties act as Data Processors, independent Data Controllers or persons authorised to process Personal Data.

User rights under the GDPR

Within the limits provided by applicable law, Users have the right to:

  • withdraw consent at any time;
  • object to the processing of their Data;
  • obtain access to their Personal Data;
  • request rectification or updating;
  • obtain restriction of processing;
  • obtain erasure of Personal Data where provided by law;
  • receive their Data in a structured format and, where applicable, obtain portability to another controller;
  • lodge a complaint with the competent supervisory authority;
  • seek judicial remedy.

Users may also request information concerning the safeguards used for any transfers of Personal Data outside the European Economic Area.

Right to object

Where Personal Data are processed on the basis of the Data Controller’s legitimate interest, Users have the right to object to such processing on grounds relating to their particular situation, in the cases and within the limits provided by Article 21 GDPR.

Where Personal Data are processed for direct marketing purposes, Users may object at any time, free of charge and without providing reasons.

How to exercise User rights

Requests are free of charge where provided by applicable law and will be handled within the time limits established by the GDPR.

Legal defence

User Personal Data may be used by the Data Controller in legal proceedings or in the preparatory stages thereof to protect its rights or defend against misuse of the website or related services.

The Data Controller may also be required to disclose Personal Data to competent authorities where required by law.

System logs and maintenance

For purposes related to operation, maintenance and security, the website and third-party services used by it may collect system logs, i.e. files recording interactions with IT systems and which may contain Personal Data such as IP addresses, technical information about the device, date and time of requests and security-event information.

Changes to this Privacy Policy

The Data Controller reserves the right to amend this Privacy Policy at any time, including as a result of changes in applicable law, changes to the services offered or the introduction of new tools and providers.

Where a change affects processing based on consent, the Data Controller will request renewed consent where required.

Iubenda hosts part of the content relating to details of the services used and processes only the Personal Data necessary to provide the relevant service.

Last updated: 22 September 2026