Who is responsible for your data
The data controller for the personal data described in this policy is TODO_LEGAL_ENTITY_NAME, trading as ANTRO, a company registered in Belgium under enterprise number TODO_COMPANY_NUMBER, with its registered office at TODO_REGISTERED_STREET_ADDRESS, Brussels, Belgium.
For any question about this policy or about how we handle your data, write to us at info@giorgioantro.com. We are not required to appoint a Data Protection Officer and have not done so.
What data we collect
We collect only what we need to sell you a garment and get it to you:
- Identity and contact data — your name and email address.
- Delivery data — the shipping address you give us at checkout.
- Order data — the items you bought, the amount paid, and the status of your order.
- Technical data— your IP address and basic request metadata, recorded transiently in our host’s server logs.
We never see or store your card details.Payment card data is captured directly by Stripe in a payment form hosted by Stripe and transmitted to Stripe’s systems. It does not pass through, and is never stored on, our servers or our database.
Why we process it, and on what legal basis
The GDPR requires us to have a lawful basis for every purpose for which we use your data. Ours are:
- Fulfilling your order and delivering your goods
- Name, email, shipping address, order historyPerformance of a contract (GDPR Art. 6(1)(b))
- Preventing fraudulent and abusive transactions
- Payment metadata, IP addressLegitimate interests (GDPR Art. 6(1)(f))
- Keeping accounting and tax records
- Invoice and transaction recordsLegal obligation (GDPR Art. 6(1)(c))
- Responding to enquiries sent through our contact form
- Name, email, message contentLegitimate interests (GDPR Art. 6(1)(f))
- Sending marketing emails about new releases
- Name, emailConsent (GDPR Art. 6(1)(a)), withdrawable at any time
We do not send marketing email unless you have asked us to. Where we rely on your consent, you may withdraw it at any time — by using the unsubscribe link in any marketing email, or by emailing us — without affecting the lawfulness of processing carried out before you withdrew it.
Who we share it with
We do not sell your personal data, and we do not share it for anyone else’s marketing. We rely on the following service providers, who process data on our instructions under a data processing agreement:
- Stripe
- Payment processing and fraud prevention.Data handled: Name, email, billing address, payment card details. Stripe may process data outside the EEA under the EU Standard Contractual Clauses.
- Supabase
- Order database.Data handled: Name, email, shipping address, order contents and status. Order data is stored in an EU-hosted database region.
- Resend
- Transactional email (order confirmations, replies to enquiries).Data handled: Name, email, order summary. Resend may process data outside the EEA under the EU Standard Contractual Clauses.
- Vercel
- Website hosting and delivery.Data handled: IP address and request metadata in transient server logs. Vercel may process data outside the EEA under the EU Standard Contractual Clauses.
INTERNATIONAL TRANSFERS
Some of these providers are established outside the European Economic Area, or use infrastructure outside it. Where personal data is transferred out of the EEA, that transfer is covered by the European Commission’s Standard Contractual Clauses, or by an adequacy decision, together with supplementary technical measures such as encryption in transit and at rest. You may request a copy of the safeguards that apply by writing to us.
We may also disclose data where we are legally obliged to — for example to tax authorities, or in response to a valid order from a court or public authority.
How long we keep it
- Order and invoice records — retained for 7 years from the end of the financial year in which the order was placed, because Belgian accounting and tax law requires it.
- Contact form correspondence — retained for as long as needed to resolve your enquiry, and then for up to 12 months in case you follow up.
- Marketing contact details — retained until you withdraw consent or unsubscribe.
- Server logs — retained transiently by our host and rotated out automatically.
When a retention period ends, we delete the data or irreversibly anonymise it so that it can no longer be linked to you.
Your rights
Under the GDPR (Articles 15 to 21) you have the following rights in relation to your personal data:
- Access — Obtain confirmation of whether we process your personal data, and receive a copy of it.
- Rectification — Have inaccurate personal data corrected and incomplete data completed.
- Erasure — Have your personal data deleted, except where we are legally required to retain it.
- Restriction of processing — Require us to limit how we use your data while a dispute about its accuracy or lawfulness is resolved.
- Data portability — Receive the data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller.
- Objection — Object at any time to processing based on our legitimate interests, and to any processing for direct marketing.
HOW TO EXERCISE THEM
Email info@giorgioantro.com stating which right you wish to exercise. We will respond within one month of receiving your request. That period may be extended by a further two months where a request is complex, in which case we will tell you within the first month and explain why. Exercising your rights is free of charge; we may charge a reasonable fee only if a request is manifestly unfounded or excessive. We may ask you for information to confirm your identity before we act.
RIGHT TO LODGE A COMPLAINT
If you believe we have handled your data unlawfully, you may lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels, Belgium — www.gegevensbeschermingsautoriteit.be. You may also complain to the supervisory authority of the EU member state where you live or work. We would appreciate the chance to address your concern first.
Security and changes to this policy
All traffic to this site is encrypted with TLS. Access to the order database is restricted to server-side credentials that are never exposed to your browser, and row-level security is enabled on it.
We may update this policy as the business changes. When we do, we will revise the “last updated” date above; if a change materially affects your rights, we will take reasonable steps to notify you directly.