Privacy Policy

The purpose of this document is to inform the natural person (hereinafter “Data Subject”) regarding the processing of their personal data (hereinafter “Personal Data”) collected by the data controller, Tesma Special Fibres srl, with registered office at Via Di Prato 60, 59013 Montemurlo (PO), Tax ID/VAT Number 01569080979, e-mail address info@matecashmere.com, certified e-mail (PEC) address tesmaspecialfibres@legalmail.it, telephone 0558022386, (hereinafter “Controller”), through the website www.matecashmere.com (hereinafter “Application”).

Modifications and updates will be binding as soon as they are published on the Application. In case of non-acceptance of the changes made to the Privacy Policy, the Data Subject is required to cease using this Application and may request the Controller to delete their Personal Data.

  1. Categories of Personal Data processed

    The Controller processes the following types of Personal Data provided voluntarily by the Data Subject:

    • Contact data: first name, last name, address, e-mail, telephone, images, authentication credentials, any further information sent by the Data Subject, etc.
    • Tax and payment data: tax code, VAT number, credit card details, bank account details, etc.

    The Controller processes the following types of Personal Data collected in an automated manner:

    • Technical data: Personal Data produced by the devices, applications, tools, and protocols used, such as, for example, information on the device used, IP addresses, browser type, Internet Service Provider (ISP) type. Such Personal Data may leave traces that, particularly when combined with unique identifiers and other information received by servers, can be used to create profiles of natural persons
    • Navigation and Application usage data: such as, for example, pages visited, number of clicks, actions performed, duration of sessions, etc.
    • Data regarding the exact location of the Data Subject: for example, geolocation data that precisely identifies the location of the Data Subject, which can be collected via satellite network (e.g., GPS) and other means, collected subject to the Data Subject’s consent. The Data Subject may withdraw consent at any time.

    Failure by the Data Subject to provide Personal Data for which there is a legal or contractual obligation, or where they constitute a necessary requirement for the conclusion of the contract with the Controller, will result in the Controller being unable to establish or continue the relationship with the Data Subject.

    The Data Subject who communicates third-party Personal Data to the Controller is directly and exclusively responsible for their origin, collection, processing, communication, or dissemination.

  2. Cookies and similar technologies

    The Application uses cookies, web beacons, unique identifiers, and other similar technologies to collect Personal Data of the Data Subject on pages, links visited, and other actions performed when the Data Subject uses the Application. These are stored to be then transmitted on the Data Subject's next visit. You can view the full Cookie Policy at the following address: xxxx

  3. Legal basis and purposes of processing

    The processing of Personal Data is necessary:

    1. for the performance of the contract with the Data Subject and precisely:
      1. fulfillment of any obligation deriving from the pre-contractual or contractual relationship with the Data Subject
      2. support and contact with the Data Subject: to respond to the Data Subject’s requests
      3. payment management: to manage payments via credit card, bank transfer, or other instruments
    2. for a legal obligation and precisely:
      1. the fulfillment of any obligation provided for by current regulations, laws, and regulations, in particular, in tax and fiscal matters
    3. based on the legitimate interest of the Controller, for:
      1. management, optimization, and monitoring of the technical infrastructure: to identify and resolve any technical problems, to improve the performance of the Application, to manage and organize information in an IT system (e.g., servers, databases, etc.)
      2. security and anti-fraud: to ensure the security of the Controller’s assets, infrastructure, and networks
    4. based on the Data Subject’s consent, for:
      1. profiling the Data Subject for marketing purposes: to provide the Data Subject with information about the Controller’s products and/or services through automated processing aimed at collecting personal information with the purpose of predicting or evaluating their preferences or behavior
      2. retargeting and remarketing: to reach the Data Subject who has already visited or shown interest in the products and/or services offered by the Application with a personalized advertisement using their Personal Data. The Data Subject can opt-out by visiting the page of the Network Advertising Initiative
      3. marketing purposes for the Controller’s products and/or services: to send commercial and/or promotional information or materials, to carry out direct sales activities for the Controller’s products and/or services, or to conduct market research using automated and traditional methods

    Based on the Controller’s legitimate interest, the Application allows for interactions with external platforms or social networks, the processing of Personal Data for which is governed by their respective privacy policies, which you are requested to refer to. The interactions and information acquired by this Application are in any case subject to the privacy settings chosen by the Data Subject on those platforms or social networks. This information – in the absence of specific consent to processing for further purposes – is used solely for the purpose of enabling the use of the Application and providing the requested information and services.

    The Data Subject’s Personal Data may also be used by the Controller to defend itself in court before the competent judicial authorities.

  4. Processing methods and recipients of Personal Data

    The processing of Personal Data is carried out using paper and electronic tools with organizational methods and logics strictly related to the indicated purposes and through the adoption of adequate security measures.

    Personal Data is processed exclusively by:

    • persons authorized by the Data Controller who have committed to confidentiality or have an adequate legal obligation of confidentiality;
    • subjects who operate autonomously as distinct data controllers or subjects designated as data processors by the Controller in order to carry out all the processing activities necessary to pursue the purposes of this privacy policy (e.g., business partners, consultants, IT companies, service providers, hosting providers);
    • subjects or entities to whom it is mandatory to communicate Personal Data due to legal obligation or by order of the authorities.

    The subjects listed above are required to use appropriate safeguards to protect Personal Data and may access only those necessary to perform the tasks assigned to them.

    Personal Data will not be indiscriminately disseminated in any way.

  5. Location

    Personal Data will not be subject to any transfer outside the territory of the European Economic Area (EEA).

  6. Personal Data retention period

    Personal Data will be stored for the period of time necessary to fulfill the purposes for which they were collected, in particular:

    • for purposes related to the performance of the contract between the Controller and the Data Subject, they will be stored for the entire duration of the contractual relationship and, after its termination, for the ordinary limitation period of 10 years. In the event of judicial litigation, for the entire duration of the same, until the expiration of the terms of feasibility of appeal actions
    • for purposes related to the Controller’s legitimate interest, they will be stored until such interest is fulfilled
    • for the fulfillment of a legal obligation, by order of an authority, and for legal defense, they will be stored in compliance with the timeframes provided by said obligations, regulations, and in any case until the expiration of the limitation period provided by current laws
    • for purposes based on the Data Subject’s consent, they will be stored until the withdrawal of consent

    At the end of the retention period, all Personal Data will be deleted or stored in a form that does not allow for the identification of the Data Subject.

  7. Rights of the Data Subject

    Data Subjects may exercise certain rights with reference to the Personal Data processed by the Controller. In particular, the Data Subject has the right to:

    • be informed about the processing of their Personal Data
    • withdraw consent at any time
    • restrict the processing of their Personal Data
    • object to the processing of their Personal Data
    • access their Personal Data
    • verify and request the rectification of their Personal Data
    • obtain the restriction of the processing of their Personal Data
    • obtain the deletion of their Personal Data
    • transfer their Personal Data to another controller
    • lodge a complaint with the supervisory authority for the protection of their Personal Data and/or take legal action.

    To exercise their rights, Data Subjects may address a request to the following e-mail address: info@matecashmere.com. Requests will be taken over by the Controller immediately and processed as soon as possible, in any case within 30 days.

Last update: 24/10/2025