Skip to content

Privacy Policy

Last updated: 17 July 2026

This Privacy Policy explains how Poiesis S.r.l. collects and processes the personal data of visitors to www.poiesisfirenze.com and of individuals who contact us or request an appointment. It is provided pursuant to Regulation (EU) 2016/679 (the “GDPR”) and Italian Legislative Decree No. 196/2003 as amended (the “Privacy Code”).


1. Data Controller

POIESIS S.R.L.

Registered office

Via Sacco e Vanzetti 21, 50012 Bagno a Ripoli (FI), Italy

Atelier

Via Romana 77R, 50125 Florence (FI), Italy

VAT / Tax code

07518540484

Email

poiesisfirenze@gmail.com

Telephone

+39 328 468 2550

Poiesis S.r.l. (the “Controller”, “we”, “us”) determines the purposes and means of the processing described below. No Data Protection Officer (DPO) has been appointed, as appointment is not mandatory under Article 37 GDPR for our activity.

2. What Data We Collect

Data you provide to us

When you complete the appointment request form on our Contact page, or when you write to us by email, you may provide:

  • Identification and contact details: first name, last name, email address, telephone/mobile number, country;
  • Information about your request: the type of garment you are interested in (jacket, suit, coat, other), your preferred appointment time and any additional notes you choose to include;
  • Any further personal data you voluntarily include in free-text fields or in email correspondence.
Data collected automatically

When you browse the website, our systems and those of our providers may record technical data such as your IP address, browser type and settings, device information, pages viewed, and date and time of access. This data is processed in log form and, where applicable, through cookies and similar technologies (see Section 8).

3. Purposes and Legal Bases of Processing

We process your personal data for the following purposes, each supported by a legal basis under Article 6 GDPR:

  • To respond to your enquiries and manage appointment requests — legal basis: the performance of pre-contractual measures taken at your request (Art. 6(1)(b)) and, for information you provide voluntarily, your consent (Art. 6(1)(a)).
  • To provide our bespoke tailoring services and manage the client relationship — legal basis: performance of a contract (Art. 6(1)(b)).
  • To comply with legal obligations, including accounting, tax and invoicing requirements — legal basis: compliance with a legal obligation (Art. 6(1)(c)).
  • To ensure the security, integrity and proper functioning of the website — legal basis: our legitimate interest in protecting our systems (Art. 6(1)(f)).

Providing the data marked as required in the contact form is necessary to process your request; without it we cannot respond to you or arrange an appointment. Providing any additional information is optional.

4. How We Share Your Data

Your personal data may be made accessible to:

  • Personnel of Poiesis S.r.l. authorised to process data in connection with the purposes above;
  • External service providers acting as data processors under Article 28 GDPR, including our website hosting provider, and Google (Google Ireland Ltd. / Google LLC) for email services (Gmail) and for the interactive map embedded on the Contact page (Google Maps);
  • Professionals and consultants (e.g. accountants) and public authorities, where required to fulfil legal obligations.

We do not sell your personal data, and we do not disclose it for third parties’ independent marketing purposes.

5. Transfers Outside the EU/EEA

Some of our providers, in particular Google, may process data on servers located outside the European Economic Area, including in the United States. Where this occurs, transfers are safeguarded by appropriate measures under Chapter V GDPR, such as the European Commission’s Standard Contractual Clauses and, where applicable, the certification of the recipient under the EU–US Data Privacy Framework.

6. Data Retention

We keep your personal data only for as long as necessary for the purposes for which it was collected:

  • Enquiry and appointment-request data, where no client relationship follows, is retained for the time needed to handle the request and for up to 24 months thereafter;
  • Data relating to clients and orders is retained for the duration of the relationship and, for accounting and tax purposes, for the periods required by law (generally up to 10 years, pursuant to Article 2220 of the Italian Civil Code);
  • Technical and log data is retained for the limited period necessary for security and diagnostic purposes.

7. Your Rights

Under Articles 15 to 22 GDPR, and to the extent applicable, you have the right to:

  • Access your personal data and obtain a copy of it;
  • Request rectification of inaccurate or incomplete data;
  • Request erasure of your data (“right to be forgotten”);
  • Request restriction of processing;
  • Object to processing carried out on the basis of legitimate interest;
  • Receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller (data portability);
  • Withdraw any consent you have given at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

To exercise these rights, please write to poiesisfirenze@gmail.com. We will respond without undue delay and in any event within the time limits set by the GDPR.

You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), or with the supervisory authority of your country of residence.

8. Cookies

Our website uses technical cookies that are necessary for its proper functioning and do not require your consent. Pages that embed third-party content — in particular the Google Maps map on the Contact page — may cause those third parties to set cookies and to receive your IP address; such non-essential cookies are only activated with your prior consent, where required. For full details of the cookies used and to manage your preferences, please refer to our Cookie Policy or the consent tool available on the website.

9. Children

Our website and services are directed to adults. We do not knowingly collect personal data from children under the age of 16. If you believe a minor has provided us with personal data, please contact us so that we can delete it.

10. Social Media

Our website links to our profiles on Instagram and Facebook. When you interact with those platforms, your data is processed by the respective providers in accordance with their own privacy policies, over which we have no control.

11. Security

We adopt appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure, in accordance with Article 32 GDPR.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our processing activities or in applicable law. The current version is always available on this page, with the date of the latest revision indicated at the top.ed spam detection service.