Privacy Policy

Privacy Policy

Privacy notice pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”)
Last update: June 13, 2026

1. Data Controller

The Data Controller is Cognetta Abbigliamento S.r.l.s., with registered office at Corso Umberto I, no. 30, 89832 Dasà (VV), Italy, VAT number 03841570793.

For any request concerning the processing of personal data, please contact:

info@sartoriacognetta.com

2. Personal Data Processed

Through the contact form, we may collect personal data voluntarily provided by the user, including:

  • first and last name;

  • company or brand;

  • email address;

  • telephone number, where requested or provided;

  • project information and the content of the message.

Users are asked not to include special categories of personal data in the form, such as health data, religious beliefs, political opinions or other sensitive information that is not necessary for the request.

The IT systems and technical service providers used to operate the website may also process certain technical data necessary for the provision and security of the service, such as the IP address, device and browser type, date and time of the request, and information contained in technical logs.

3. Purposes and Legal Bases of Processing

Personal data is processed for the following purposes:

a. Managing requests and assessing potential collaborations

To respond to requests for information or quotations, review the information received, assess the feasibility of the project and follow up on the contact requested by the data subject.

The legal basis is the performance of pre-contractual measures taken at the request of the data subject, pursuant to Article 6(1)(b) of the GDPR.

b. Ensuring the operation and security of the website

To ensure the proper operation of the website and prevent abuse, unauthorized access attempts and technical issues.

The legal basis is the Controller’s legitimate interest in securely managing its IT systems, pursuant to Article 6(1)(f) of the GDPR.

c. Complying with legal obligations

Personal data may be processed where necessary to comply with legal or administrative obligations or requests from the competent authorities.

The legal basis is compliance with a legal obligation, pursuant to Article 6(1)(c) of the GDPR.

Personal data collected through the form will not be used to send newsletters or recurring promotional communications without a separate legal basis and, where required, the data subject’s specific consent.

4. Provision of Personal Data

The provision of the data marked as mandatory in the form is necessary to allow the Controller to receive and manage the request.

Failure to provide such data may make it impossible to submit the form or receive a response.

Any data marked as optional may be omitted without preventing the submission of the request.

5. Processing Methods and Retention Periods

Personal data is processed mainly by electronic means and using appropriate technical and organizational measures to protect it against unauthorized access, loss, alteration or unlawful disclosure.

Personal data relating to contact requests is retained for the time necessary to manage the request and any subsequent business developments and, in any event, for no longer than 24 months from the last contact, unless:

  • a contractual relationship is established;

  • retention is necessary to comply with legal obligations;

  • retention is necessary to establish, exercise or defend the Controller’s rights.

Where a contractual relationship is established, personal data will be retained for the periods required under the applicable administrative, tax and accounting regulations.

Any technical logs are retained for the period strictly necessary for the operation and security of the service, in accordance with the configurations and terms of the service providers used.

6. Authorized Persons and Recipients of Personal Data

Personal data may be processed by the Controller’s duly authorized and instructed employees and collaborators.

Personal data may also be processed by technical service providers necessary for the operation of the website and the management of communications, including:

  • Framer B.V., as the provider of the website platform, hosting and technical features;

  • Aruba S.p.A., as the provider of the domain and email service.

These parties process personal data according to their respective roles and, where applicable, as data processors pursuant to Article 28 of the GDPR.

Personal data may also be disclosed to professional advisers or public authorities where necessary to comply with legal obligations or protect the Controller’s rights.

Personal data is not publicly disclosed, sold or transferred to third parties for their own promotional purposes.

7. Transfers of Personal Data Outside the European Economic Area

Certain technical service providers, particularly Framer B.V. through its subprocessors, may process personal data in countries located outside the European Economic Area.

Where the recipient country is not covered by an adequacy decision of the European Commission, the transfer is carried out using safeguards recognized under the GDPR, such as the Standard Contractual Clauses approved by the European Commission, together with any applicable supplementary measures.

Further information regarding the safeguards adopted may be requested from the Controller by writing to info@sartoriacognetta.com.

8. Rights of the Data Subject

Where provided for under the GDPR, the data subject may exercise the following rights:

  • obtain confirmation as to whether or not their personal data is being processed;

  • access their personal data;

  • request its rectification or updating;

  • request its erasure;

  • request the restriction of processing;

  • object to processing based on legitimate interests;

  • receive their personal data in a portable format, where applicable;

  • withdraw any consent previously given, without affecting the lawfulness of processing carried out before its withdrawal.

Requests may be sent to:

info@sartoriacognetta.com

The data subject also has the right to lodge a complaint with the Italian Data Protection Authority or another competent supervisory authority.

9. Automated Decision-Making

Personal data collected through the website is not subject to solely automated decision-making, including profiling, that produces legal effects concerning the data subject or similarly significantly affects them.

10. Analytics Tools and Technical Browsing Data

The website uses the analytics tool integrated into the Framer platform to obtain aggregated statistics regarding the number of visits, pages viewed and main traffic sources.

According to the information provided by Framer, this tool does not use cookies or generate persistent identifiers. Technical data is processed for the purpose of producing aggregated statistics regarding the use of the website.

The Controller uses this information to understand how the website performs and to improve its content, performance and browsing experience.

As of the date on which this Privacy Policy was last updated, the website does not use advertising or profiling tools or external cookie-based analytics services.

Should external services using cookies or other non-essential tracking technologies be introduced in the future, this Privacy Policy will be updated and, where required by applicable law, such technologies will only be activated after obtaining the user’s consent.

11. Changes to This Privacy Policy

The Controller may update this Privacy Policy to reflect legal, technical or organizational changes.

The updated version will be published on this page together with the date on which it was last updated.

1. Data Controller

The Data Controller is Cognetta Abbigliamento S.r.l.s., with registered office at Corso Umberto I, no. 30, 89832 Dasà (VV), Italy, VAT number 03841570793.

For any request concerning the processing of personal data, please contact:

info@sartoriacognetta.com

2. Personal Data Processed

Through the contact form, we may collect personal data voluntarily provided by the user, including:

  • first and last name;

  • company or brand;

  • email address;

  • telephone number, where requested or provided;

  • project information and the content of the message.

Users are asked not to include special categories of personal data in the form, such as health data, religious beliefs, political opinions or other sensitive information that is not necessary for the request.

The IT systems and technical service providers used to operate the website may also process certain technical data necessary for the provision and security of the service, such as the IP address, device and browser type, date and time of the request, and information contained in technical logs.

3. Purposes and Legal Bases of Processing

Personal data is processed for the following purposes:

a. Managing requests and assessing potential collaborations

To respond to requests for information or quotations, review the information received, assess the feasibility of the project and follow up on the contact requested by the data subject.

The legal basis is the performance of pre-contractual measures taken at the request of the data subject, pursuant to Article 6(1)(b) of the GDPR.

b. Ensuring the operation and security of the website

To ensure the proper operation of the website and prevent abuse, unauthorized access attempts and technical issues.

The legal basis is the Controller’s legitimate interest in securely managing its IT systems, pursuant to Article 6(1)(f) of the GDPR.

c. Complying with legal obligations

Personal data may be processed where necessary to comply with legal or administrative obligations or requests from the competent authorities.

The legal basis is compliance with a legal obligation, pursuant to Article 6(1)(c) of the GDPR.

Personal data collected through the form will not be used to send newsletters or recurring promotional communications without a separate legal basis and, where required, the data subject’s specific consent.

4. Provision of Personal Data

The provision of the data marked as mandatory in the form is necessary to allow the Controller to receive and manage the request.

Failure to provide such data may make it impossible to submit the form or receive a response.

Any data marked as optional may be omitted without preventing the submission of the request.

5. Processing Methods and Retention Periods

Personal data is processed mainly by electronic means and using appropriate technical and organizational measures to protect it against unauthorized access, loss, alteration or unlawful disclosure.

Personal data relating to contact requests is retained for the time necessary to manage the request and any subsequent business developments and, in any event, for no longer than 24 months from the last contact, unless:

  • a contractual relationship is established;

  • retention is necessary to comply with legal obligations;

  • retention is necessary to establish, exercise or defend the Controller’s rights.

Where a contractual relationship is established, personal data will be retained for the periods required under the applicable administrative, tax and accounting regulations.

Any technical logs are retained for the period strictly necessary for the operation and security of the service, in accordance with the configurations and terms of the service providers used.

6. Authorized Persons and Recipients of Personal Data

Personal data may be processed by the Controller’s duly authorized and instructed employees and collaborators.

Personal data may also be processed by technical service providers necessary for the operation of the website and the management of communications, including:

  • Framer B.V., as the provider of the website platform, hosting and technical features;

  • Aruba S.p.A., as the provider of the domain and email service.

These parties process personal data according to their respective roles and, where applicable, as data processors pursuant to Article 28 of the GDPR.

Personal data may also be disclosed to professional advisers or public authorities where necessary to comply with legal obligations or protect the Controller’s rights.

Personal data is not publicly disclosed, sold or transferred to third parties for their own promotional purposes.

7. Transfers of Personal Data Outside the European Economic Area

Certain technical service providers, particularly Framer B.V. through its subprocessors, may process personal data in countries located outside the European Economic Area.

Where the recipient country is not covered by an adequacy decision of the European Commission, the transfer is carried out using safeguards recognized under the GDPR, such as the Standard Contractual Clauses approved by the European Commission, together with any applicable supplementary measures.

Further information regarding the safeguards adopted may be requested from the Controller by writing to info@sartoriacognetta.com.

8. Rights of the Data Subject

Where provided for under the GDPR, the data subject may exercise the following rights:

  • obtain confirmation as to whether or not their personal data is being processed;

  • access their personal data;

  • request its rectification or updating;

  • request its erasure;

  • request the restriction of processing;

  • object to processing based on legitimate interests;

  • receive their personal data in a portable format, where applicable;

  • withdraw any consent previously given, without affecting the lawfulness of processing carried out before its withdrawal.

Requests may be sent to:

info@sartoriacognetta.com

The data subject also has the right to lodge a complaint with the Italian Data Protection Authority or another competent supervisory authority.

9. Automated Decision-Making

Personal data collected through the website is not subject to solely automated decision-making, including profiling, that produces legal effects concerning the data subject or similarly significantly affects them.

10. Analytics Tools and Technical Browsing Data

The website uses the analytics tool integrated into the Framer platform to obtain aggregated statistics regarding the number of visits, pages viewed and main traffic sources.

According to the information provided by Framer, this tool does not use cookies or generate persistent identifiers. Technical data is processed for the purpose of producing aggregated statistics regarding the use of the website.

The Controller uses this information to understand how the website performs and to improve its content, performance and browsing experience.

As of the date on which this Privacy Policy was last updated, the website does not use advertising or profiling tools or external cookie-based analytics services.

Should external services using cookies or other non-essential tracking technologies be introduced in the future, this Privacy Policy will be updated and, where required by applicable law, such technologies will only be activated after obtaining the user’s consent.

11. Changes to This Privacy Policy

The Controller may update this Privacy Policy to reflect legal, technical or organizational changes.

The updated version will be published on this page together with the date on which it was last updated.

1. Data Controller

The Data Controller is Cognetta Abbigliamento S.r.l.s., with registered office at Corso Umberto I, no. 30, 89832 Dasà (VV), Italy, VAT number 03841570793.

For any request concerning the processing of personal data, please contact:

info@sartoriacognetta.com

2. Personal Data Processed

Through the contact form, we may collect personal data voluntarily provided by the user, including:

  • first and last name;

  • company or brand;

  • email address;

  • telephone number, where requested or provided;

  • project information and the content of the message.

Users are asked not to include special categories of personal data in the form, such as health data, religious beliefs, political opinions or other sensitive information that is not necessary for the request.

The IT systems and technical service providers used to operate the website may also process certain technical data necessary for the provision and security of the service, such as the IP address, device and browser type, date and time of the request, and information contained in technical logs.

3. Purposes and Legal Bases of Processing

Personal data is processed for the following purposes:

a. Managing requests and assessing potential collaborations

To respond to requests for information or quotations, review the information received, assess the feasibility of the project and follow up on the contact requested by the data subject.

The legal basis is the performance of pre-contractual measures taken at the request of the data subject, pursuant to Article 6(1)(b) of the GDPR.

b. Ensuring the operation and security of the website

To ensure the proper operation of the website and prevent abuse, unauthorized access attempts and technical issues.

The legal basis is the Controller’s legitimate interest in securely managing its IT systems, pursuant to Article 6(1)(f) of the GDPR.

c. Complying with legal obligations

Personal data may be processed where necessary to comply with legal or administrative obligations or requests from the competent authorities.

The legal basis is compliance with a legal obligation, pursuant to Article 6(1)(c) of the GDPR.

Personal data collected through the form will not be used to send newsletters or recurring promotional communications without a separate legal basis and, where required, the data subject’s specific consent.

4. Provision of Personal Data

The provision of the data marked as mandatory in the form is necessary to allow the Controller to receive and manage the request.

Failure to provide such data may make it impossible to submit the form or receive a response.

Any data marked as optional may be omitted without preventing the submission of the request.

5. Processing Methods and Retention Periods

Personal data is processed mainly by electronic means and using appropriate technical and organizational measures to protect it against unauthorized access, loss, alteration or unlawful disclosure.

Personal data relating to contact requests is retained for the time necessary to manage the request and any subsequent business developments and, in any event, for no longer than 24 months from the last contact, unless:

  • a contractual relationship is established;

  • retention is necessary to comply with legal obligations;

  • retention is necessary to establish, exercise or defend the Controller’s rights.

Where a contractual relationship is established, personal data will be retained for the periods required under the applicable administrative, tax and accounting regulations.

Any technical logs are retained for the period strictly necessary for the operation and security of the service, in accordance with the configurations and terms of the service providers used.

6. Authorized Persons and Recipients of Personal Data

Personal data may be processed by the Controller’s duly authorized and instructed employees and collaborators.

Personal data may also be processed by technical service providers necessary for the operation of the website and the management of communications, including:

  • Framer B.V., as the provider of the website platform, hosting and technical features;

  • Aruba S.p.A., as the provider of the domain and email service.

These parties process personal data according to their respective roles and, where applicable, as data processors pursuant to Article 28 of the GDPR.

Personal data may also be disclosed to professional advisers or public authorities where necessary to comply with legal obligations or protect the Controller’s rights.

Personal data is not publicly disclosed, sold or transferred to third parties for their own promotional purposes.

7. Transfers of Personal Data Outside the European Economic Area

Certain technical service providers, particularly Framer B.V. through its subprocessors, may process personal data in countries located outside the European Economic Area.

Where the recipient country is not covered by an adequacy decision of the European Commission, the transfer is carried out using safeguards recognized under the GDPR, such as the Standard Contractual Clauses approved by the European Commission, together with any applicable supplementary measures.

Further information regarding the safeguards adopted may be requested from the Controller by writing to info@sartoriacognetta.com.

8. Rights of the Data Subject

Where provided for under the GDPR, the data subject may exercise the following rights:

  • obtain confirmation as to whether or not their personal data is being processed;

  • access their personal data;

  • request its rectification or updating;

  • request its erasure;

  • request the restriction of processing;

  • object to processing based on legitimate interests;

  • receive their personal data in a portable format, where applicable;

  • withdraw any consent previously given, without affecting the lawfulness of processing carried out before its withdrawal.

Requests may be sent to:

info@sartoriacognetta.com

The data subject also has the right to lodge a complaint with the Italian Data Protection Authority or another competent supervisory authority.

9. Automated Decision-Making

Personal data collected through the website is not subject to solely automated decision-making, including profiling, that produces legal effects concerning the data subject or similarly significantly affects them.

10. Analytics Tools and Technical Browsing Data

The website uses the analytics tool integrated into the Framer platform to obtain aggregated statistics regarding the number of visits, pages viewed and main traffic sources.

According to the information provided by Framer, this tool does not use cookies or generate persistent identifiers. Technical data is processed for the purpose of producing aggregated statistics regarding the use of the website.

The Controller uses this information to understand how the website performs and to improve its content, performance and browsing experience.

As of the date on which this Privacy Policy was last updated, the website does not use advertising or profiling tools or external cookie-based analytics services.

Should external services using cookies or other non-essential tracking technologies be introduced in the future, this Privacy Policy will be updated and, where required by applicable law, such technologies will only be activated after obtaining the user’s consent.

11. Changes to This Privacy Policy

The Controller may update this Privacy Policy to reflect legal, technical or organizational changes.

The updated version will be published on this page together with the date on which it was last updated.