Last update: 13/07/2026
This privacy policy describes how AndRed.it di Savarin Andrea processes the personal data of users who browse and purchase through the XTec.it ecommerce website.
This privacy policy is provided pursuant to Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree no. 196 of 30 June 2003 (“Personal Data Protection Code”), as amended and supplemented.
1. Data Controller
The Data Controller is:
AndRed.it di Savarin Andrea
Registered office: via Aldo Moro, 11, 23826 Mandello del Lario (LC), Italy
VAT No.: 04270450135
Email: [email protected]
2. Types of personal data processed
Through the XTec.it website, the following categories of personal data may be processed:
- Identification and contact data: first name, last name, email address, telephone number, billing address and shipping address.
- Order-related data: products purchased, quantities, amounts, order status, delivery information, support requests, returns and refunds.
- Tax and administrative data: tax code, VAT number, invoicing details, where provided or required.
- Payment data: information relating to the payment method used, transaction outcome and technical payment identifiers. XTec.it does not store full payment card details.
- Technical browsing data: IP address, device identifiers, browser data, operating system, technical logs, pages visited, access date and time.
- Data collected through cookies and similar technologies: consent preferences, analytics data, measurement data, advertising and remarketing data, as described in the Cookie Policy.
- Data contained in communications: information voluntarily submitted through contact forms, emails, support requests, reviews or other communications.
3. Purposes of processing and legal bases
Personal data is processed for the following purposes:
| Purpose | Legal basis |
|---|---|
| Website browsing management and technical operation of the website | Legitimate interest of the Data Controller and technical necessity of the service |
| Creation and management of the customer account | Performance of pre-contractual or contractual measures |
| Management of orders, payments, shipments, deliveries, returns and after-sales support | Performance of the contract |
| Tax, accounting, administrative and legal obligations | Legal obligation |
| Response to information, support or contact requests | Performance of pre-contractual or contractual measures or legitimate interest |
| Website security, fraud prevention, abuse prevention, unauthorised access prevention and protection against harmful activities | Legitimate interest of the Data Controller |
| Statistical analysis and website performance measurement | Consent, where required |
| Marketing, remarketing, personalised advertising and conversion measurement | Consent, where required |
| Sending commercial or promotional communications | Consent or, where permitted, legitimate interest for communications relating to similar products or services |
4. Provision of data
Providing the data necessary for order management, payment, shipping, invoicing and support is required to conclude and perform the sales contract.
Failure to provide such data may prevent registration, purchase, delivery of products or handling of support requests.
Providing data for marketing, non-technical analytics, remarketing or personalised advertising purposes is optional and is based on consent, where required.
5. Recipients of personal data
Personal data may be disclosed or made accessible, within the limits necessary, to the following categories of recipients:
- hosting, technical maintenance, IT security and infrastructure management service providers;
- ecommerce platforms, management systems, CRM systems, customer support systems and technical tools connected to the operation of the website;
- payment providers and financial services, including Stripe, PayPal, Satispay or other payment methods shown during checkout;
- couriers, shipping companies, warehouses, distributors, suppliers and logistics partners involved in preparing, shipping, delivering, returning or providing assistance for products;
- tax, accounting, legal, administrative consultants and other appointed professionals;
- public authorities, bodies, supervisory authorities or authorised entities, where required by law;
- analytics, marketing and advertising tools: if activated with consent, measurement, remarketing and advertising tools provided by third parties may be used, including Google, Meta/Facebook, TikTok, Pinterest or other similar services listed in the Cookie Policy and in the consent management panel.
Where necessary, parties processing data on behalf of the Data Controller are appointed as Data Processors pursuant to Article 28 GDPR.
6. Transfers of data outside the European Economic Area
Some technical, analytics, marketing, payment or infrastructure service providers may process personal data outside the European Economic Area.
In such cases, the transfer takes place in compliance with the safeguards provided by the GDPR, such as adequacy decisions, standard contractual clauses approved by the European Commission, supplementary measures or other instruments provided by the applicable law.
7. Retention periods
- Contact and support requests: for the time necessary to handle the request and for a subsequent period proportionate to any protection, verification or documentation needs.
- Orders, invoicing and legal/tax obligations: for the periods required by the applicable law, generally up to 10 years for accounting and tax documentation where required.
- Customer account: until the account deletion request, except for data that must be retained for legal, tax, contractual or Data Controller protection purposes.
- Marketing, newsletters, remarketing and personalised advertising: until consent is withdrawn or deletion is requested, without prejudice to the technical need to retain proof of consent or withdrawal.
- Privacy preferences and consents: for the time necessary to demonstrate the choice made and correctly manage the user’s preferences.
- Technical and security logs: for a limited period proportionate to security, abuse prevention, debugging and technical website management needs.
- Cookies and similar technologies: according to the durations indicated in the Cookie Policy and in the consent management panel.
8. Data subject rights
The user may exercise, where applicable under the GDPR, the following rights:
- right of access to personal data;
- right to rectify inaccurate or incomplete data;
- right to erasure of data;
- right to restriction of processing;
- right to object to processing;
- right to data portability;
- right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before withdrawal;
- right to lodge a complaint with the competent data protection authority.
To exercise these rights, the user may write to: [email protected].
9. Cookies and tracking technologies
XTec.it uses cookies and similar technologies for technical, functional, statistical, measurement, marketing and advertising purposes, according to the preferences expressed by the user through the consent management banner.
Some cookies are necessary for the proper operation of the website, cart, checkout, payments, security and privacy preferences. Other cookies or tracking tools are used only with prior consent, where required.
For detailed information on the cookies used, their purposes, retention periods and how to manage or withdraw consent, please refer to the Cookie Policy.
10. Payments and security
Payments made through XTec.it are handled through specialised providers and secure payment systems. XTec.it does not store full payment card details.
Payment providers may process personal data as independent data controllers or processors, according to their respective privacy policies and the rules applicable to the service selected by the customer.
11. Minors
XTec.it is not intended for users under the age of 18. Purchases must be made by adults or by persons authorised under the applicable law.
12. Data security
The Data Controller adopts appropriate technical and organisational measures to protect personal data against unauthorised access, loss, disclosure, alteration or destruction.
The measures adopted include, where applicable, infrastructure protection, secure connections, access controls, monitoring systems, security tools and operational procedures for the technical management of the website.
13. Changes to this Privacy Policy
The Data Controller may update this Privacy Policy to reflect regulatory, technical, organisational or service-related changes.
The updated version will be published on XTec.it with the last update date.