Contact

Contact Form

Legal information

Privacy Policy

Last updated: September 7, 2026

OVYÈ S.R.L., with registered office in Via dei Pellicciai, Blocco 1 Centergross, 40050 Funo di Argelato (BO), VAT and Tax Code IT03415721202, REA BO n. 517639, owner of the website accessible at the URL www.ovye.it, as well as any other domains, subdomains or addresses attributable to the same online store (hereinafter, the “Website”), informs users and customers (hereinafter, “Users” or “Data Subjects”) that personal data relating to browsing the Website, account creation and management, purchases, payments, returns and refunds, assistance requests and the use of other services will be processed in compliance with Regulation (EU) 2016/679 (“GDPR”), Legislative Decree 196/2003, as amended, and applicable legislation on personal data protection. This privacy policy is provided pursuant to Articles 13 and 14 of the GDPR and does not apply to third-party websites or services that may be reached via links, integrations or connections on the Website, for which their respective privacy policies apply.

1. DATA CONTROLLER

The data controller is OVYÈ S.R.L., with registered office in Via dei Pellicciai, Blocco 1 Centergross, 40050 Funo di Argelato (BO), VAT and Tax Code IT03415721202, REA BO n. 517639, (hereinafter, the “Controller”). For matters relating to personal data protection and for exercising the rights provided by the GDPR, the Controller can be contacted at the e-mail address support@ovye.it.

2. PURPOSES AND LEGAL BASES FOR DATA PROCESSING

a) To enable proper browsing and functioning of the Website. Technical and browsing data necessary for the functioning of the Website, session management, shopping cart, checkout, security, and strictly necessary preferences are processed for the execution of the services requested by the User pursuant to Article 6, para. 1, letter b), GDPR and, where applicable, based on the legitimate interest of the Controller to ensure the security, integrity, and correct functioning of the Website pursuant to Article 6, para. 1, letter f), GDPR.

b) To enable the use of customer account functionalities. The Website may provide Users with customer account functionalities supplied and technically managed through the Shopify platform, which allow, among other things, authentication, viewing order history, managing profile information and addresses, checking order status, and accessing any return functionalities or other reserved services. OVYÈ S.R.L. processes personal data related to the use of the customer account to make these functionalities available and manage the relationship with the User, pursuant to Article 6, para. 1, letter b), GDPR. The technical management of the account and related authentication systems is carried out through Shopify, as specified in the section dedicated to recipients and platform providers. The provision of necessary data is a requirement for using the related functionalities.

c) To manage the purchase procedure and execute sales contracts. Identification data, contact data, billing and shipping data, data relating to orders, products, returns, right of withdrawal, refunds, legal warranty, and related communications are processed to take pre-contractual measures at the request of the Data Subject and to conclude and execute the contract pursuant to Article 6, para. 1, letter b), GDPR, as well as to comply with legal obligations related to sales pursuant to Article 6, para. 1, letter c), GDPR.

d) To manage payments, collections, refunds, and related verifications. Transaction data is processed to receive and reconcile payments, arrange refunds, manage disputes, chargebacks, anti-fraud checks, and any other activity necessary for the execution of the purchase or return. The legal basis is Article 6, para. 1, letter b), GDPR and, for regulatory and accounting compliance, Article 6, para. 1, letter c), GDPR; fraud prevention and management activities may also be based on the legitimate interest of the Controller in transaction security pursuant to Article 6, para. 1, letter f), GDPR. Full payment instrument data, such as the full card number and related security codes, are acquired and processed by payment service providers according to their respective systems and are not directly stored by the Controller.

e) To manage requests, assistance, and customer service. Data communicated via e-mail, telephone, contact forms, messaging, or other assistance channels are processed to respond to User requests and manage pre-contractual, contractual, and post-sales activities. The legal basis is Article 6, para. 1, letter b), GDPR when the request concerns a contractual or pre-contractual relationship and, in other cases, the legitimate interest of the Controller in responding to received requests pursuant to Article 6, para. 1, letter f), GDPR.

f) To prevent abuse, fraud, and illicit use of the Website and transactions. The Controller may process data related to browsing, accounts, orders, and transactions to detect anomalies, attempted fraud, unauthorized use of payment instruments, abusive access, or violations of applicable conditions. Processing is based on the legitimate interest of the Controller in the security of the Website, transactions, and its assets pursuant to Article 6, para. 1, letter f), GDPR, and, where applicable, on compliance with legal obligations pursuant to Article 6, para. 1, letter c), GDPR.

g) To send newsletters and commercial communications. The e-mail address and any other data used for sending newsletters, promotional communications, and commercial initiatives are processed based on the consent of the Data Subject pursuant to Article 6, para. 1, letter a), GDPR, except in cases where the law allows communications relating to similar products or services without new consent. Consent is optional and can be revoked at any time via the link in the communications or by contacting the Controller.

h) To perform statistical analyses, measurement, and marketing activities using cookies or similar technologies. Processing carried out using cookies and other non-strictly necessary technologies, including non-anonymized analytics tools, campaign measurement, personalization, and advertising, are carried out with the User's prior consent pursuant to Article 6, para. 1, letter a), GDPR, where such consent is required. Detailed information, durations, and methods for managing preferences are described in the Website's Cookie Policy.

i) To comply with legal, tax, accounting, and administrative obligations. Data is processed to comply with obligations set forth by applicable law, including provisions on tax, accounting, consumer protection, product safety, and cooperation with authorities. The legal basis is Article 6, para. 1, letter c), GDPR.

j) To ascertain, exercise, or defend rights. Data may be processed to manage complaints, disputes, and litigation, recover debts, protect the Controller's rights, or defend against third-party claims, based on the legitimate interest of the Controller pursuant to Article 6, para. 1, letter f), GDPR.

3. TYPES AND SOURCES OF DATA PROCESSED

The Website is not intended for purchases by individuals under 18 years of age. The Controller does not intend to knowingly collect personal data of minors to allow them to make purchases on the Website.

3.1. Browsing and technical data

During normal browsing, IP addresses, device and session identifiers, browser and operating system data, connection information, URLs and visited pages, date and time of requests, technical events, security logs, and other data generated by interaction with the Website may be processed. Such data may be processed by the Controller, Shopify, and other technical providers involved to provide the service, ensure security and functionality, prevent abuse, and produce, where permitted, usage statistics.

3.2. Cookies and similar technologies

The Website uses cookies, pixels, tags, local storage, and similar technologies. Strictly necessary cookies are used for the functioning of the Website and its related functionalities; preference, statistical, and marketing technologies are used within the limits and according to the choices expressed by the User through the consent management system. For detailed information on individual tools, providers, purposes, durations, and methods of revoking or changing consent, please refer to the Cookie Policy available on the Website.

3.3. Account, order, and contractual relationship data

First name and surname, e-mail address, telephone number, credentials and information necessary for account management, shipping and billing addresses, any tax code or other tax data, purchased or returned products, amounts, discounts, shipping and delivery methods, order status, information relating to withdrawal, returns, exchanges, refunds, warranty, and after-sales assistance may be processed.

3.4. Payment and refund data

The Controller may receive transaction-related information, such as payment method used, amount, currency, authorization or payment status, transaction identifiers, partially masked payment instrument data, information necessary for refunds, disputes, or reconciliations. Full card data and confidential payment credentials are processed by payment service providers according to their respective policies and terms.

3.5. Third-party data

The User may provide third-party data, for example, when indicating a different recipient for delivery or purchasing a gift. Such data is processed solely to the extent necessary to fulfill the order and related activities. The User is invited to communicate third-party data only when authorized to do so. The Controller will provide the third party with the information required by Article 14 of the GDPR in the cases and times provided by applicable law.

3.6. Data from sources other than the Data Subject

Some data may be received from Shopify, Sugo S.n.c., payment service providers, banks, wallets, payment circuits, couriers, carriers, anti-fraud services, applications integrated into the Website or other providers involved in the execution of the order and requested services, limited to the information necessary for the purposes described in this privacy policy.

4. DATA PROCESSING METHODS

Processing is carried out using electronic, telematic and, where necessary, paper-based tools, through operations of collection, recording, organization, structuring, storage, consultation, processing, use, communication, comparison, limitation, erasure and destruction, in accordance with principles of lawfulness, fairness, transparency, data minimization and security, and with the adoption of appropriate technical and organizational measures pursuant to Article 32 GDPR.

The Controller may use automated security and anti-fraud systems to identify anomalous transactions or behaviors and to subject certain operations to further checks. As a rule, the Controller does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect the Data Subject. However, payment providers and other third parties may independently carry out automated checks according to their own policies and conditions, for example, to authorize or reject a transaction.

5. DATA RETENTION

Personal data is retained for the time necessary to achieve the purposes for which it is processed and, subsequently, for the periods required by applicable law or necessary for the protection of the Controller's rights. In particular:

– data relating to orders, contracts, payments, refunds and related administrative-accounting formalities are retained for the period necessary for the execution of the relationship and, where required by civil, tax or accounting law, up to ten years, without prejudice to further terms necessary in case of disputes or litigation;

– account-related data is retained until the account is deleted, subject to separate retention of data that must be kept for legal obligations, order fulfillment, abuse prevention or rights protection;

– data relating to assistance requests are retained for the time necessary to manage the request and, if connected to an order or a dispute, for the period applicable to the related relationship;

– data processed for newsletter and marketing purposes are retained until the Data Subject's consent is revoked or objection is raised, except for the minimum retention necessary to document the expressed choices;

– data collected through cookies and similar technologies are retained according to the times indicated in the Cookie Policy and consent settings;

– data processed to comply with legal obligations are retained for the period provided by the relevant legislation;

– data processed to ascertain, exercise or defend a right are retained for the time necessary to manage the related claim and, in any case, until the expiry of the applicable statute of limitations or the definition of any initiated proceedings.

6. DATA DISCLOSURE AND PARTIES INVOLVED IN PROCESSING

Personal data may be disclosed or made accessible, to the extent necessary for the purposes indicated above, to the parties described below.

6.1. Sugo S.n.c. di Federico Sacchi e Cristian Antolini

The Controller uses Sugo S.n.c. di Federico Sacchi e Cristian Antolini, with registered office in Crevalcore (BO), via Giacomo Matteotti 154, Tax Code and VAT number 03269341206, (hereinafter, also “Sugo”), for activities related to the operational management of the Website and e-commerce services, including, depending on the assigned task, order management, customer assistance, returns, refunds, technical and administrative support, and payment flow management. When operating on behalf of OVYÈ S.R.L., according to the latter's instructions and for purposes determined by the Controller, Sugo acts as a data processor pursuant to Article 28 GDPR. Sugo is also responsible for receiving and collecting, in the name and on behalf of the Controller, the amounts related to purchases made on the Website and, where applicable, for managing the related refund flows. Only if and to the extent that, in relation to specific further processing connected to bank relationships or payment accounts held by Sugo, the latter is required to process personal data to comply with legal obligations directly incumbent on it, manage its own relationships with banks or payment service providers, or protect its own rights, independently determining the purposes and essential means of processing, Sugo operates as an independent controller limited to these activities. This potential qualification does not extend to activities carried out exclusively on behalf of the Controller.

6.2. Shopify

The Website is built and hosted using the Shopify platform. Within the scope of the services provided to the Controller, Shopify generally processes customers' personal data as a data processor according to the applicable Data Processing Addendum. In relation to certain proprietary services aimed at consumers or advanced functionalities, including services that may require the activation of Shopify Network Intelligence, Shopify may also process certain data as an independent controller, according to its own terms and policies. More information on Shopify's data processing and related privacy options is available at https://www.shopify.com/it/legal/privacy and, where applicable, at https://privacy.shopify.com.

6.3. Payment providers, banks, and other recipients

Data may also be disclosed or made accessible to:

– payment service providers, digital wallets, card schemes, issuers, banks, and payment institutions, including PayPal, Shopify Payments, Klarna, or other entities available from time to time at checkout, who may process data as independent controllers for the purposes determined in their respective policies;

– couriers, carriers, freight forwarders, logistics operators, and pick-up points, to the extent necessary for delivery, collection, and management of any returns;

– IT, hosting, security, technical assistance, customer care, communications, email, analytics, marketing, returns management, and other application providers integrated into the Website, who act as data processors or, when the conditions are met, as independent controllers;

– accountants, consultants, lawyers, auditors, and other professionals, to the extent necessary for the performance of their respective duties;

– judicial, administrative, tax, public security authorities, or other public entities, when disclosure is required or mandated by law;

– personnel, collaborators and subjects authorised by the Controller, within the limits of their respective duties and instructions.

The updated list of data processors can be requested from the Controller at the addresses indicated in this policy.

7. TRANSFER OF DATA TO THIRD COUNTRIES

The use of Shopify and other technological, payment, analytics, marketing, or support providers may involve the processing or transfer of personal data outside the European Economic Area. Shopify International Limited, as the contractual entity of reference for merchants in the EMEA area, may use group companies and sub-processors established in different countries; Shopify also declares that it currently stores some data of European merchants and customers "at rest" in Europe, while continuing to carry out international transfers necessary for the provision of its services.

When data is transferred to countries that do not benefit from an adequacy decision by the European Commission, the transfer is carried out using appropriate safeguards in accordance with Articles 44 et seq. of the GDPR, such as, depending on the case, binding corporate rules (Binding Corporate Rules), standard contractual clauses approved by the European Commission and additional measures required by applicable law. For transfers carried out by Shopify, reference is also made to the relevant Data Processing Addendum and the information on international transfers published by Shopify. The other providers potentially involved apply the transfer mechanisms indicated in their respective policies and conditions.

8. DATA SUBJECT RIGHTS

In the cases and within the limits provided for by the GDPR, the Data Subject may exercise the following rights towards the Controller:

– obtain confirmation of the existence of processing and access to their personal data and the information provided for by Art. 15 GDPR;

– obtain the rectification of inaccurate data and the integration of incomplete data pursuant to Art. 16 GDPR;

– obtain the erasure of personal data in the cases provided for by Art. 17 GDPR;

– obtain the restriction of processing in the cases provided for by Art. 18 GDPR;

– receive, in the cases provided for by Art. 20 GDPR, the data provided to the Controller in a structured, commonly used and machine-readable format and transmit them to another controller;

– object, for reasons related to their particular situation, to processing based on legitimate interest pursuant to Art. 21 GDPR and object at any time to processing for direct marketing purposes;

– withdraw consent given at any time, without prejudice to the lawfulness of the processing carried out before the withdrawal;

– not be subject, in the cases provided for by Art. 22 GDPR, to decisions based solely on automated processing that produce legal effects or similarly significantly affect the person;

– lodge a complaint with the competent supervisory authority. In Italy, the Garante per la protezione dei dati personali can be reached via the website www.garanteprivacy.it.

Requests relating to processing carried out by OVYÈ S.R.L. can be sent to the Controller at support@ovye.it. For processing carried out by third parties as independent controllers, including Shopify in cases where it acts in such capacity, payment service providers and, limited to any specific activities indicated in point 6.1, Sugo, the Data Subject may exercise their rights directly towards the respective controller according to their respective policies.

9. CHANGES TO THE PRIVACY POLICY

The Controller reserves the right to modify or update this Privacy Policy to adapt it to regulatory, organizational, technical or service changes. The updated version will be published on the Website with an indication of the date of the last update. In the event of substantial changes requiring specific communication to Data Subjects, the Controller will adopt the information measures provided for by applicable law.

E-shop support

  • Product information.
  • Assistance with orders, payments, refunds and returns.
  • Technical support.

Fill out the form on this page, or contact us via:

Real-time assistance via Chat:
Click on the icon that appears on the website pages as you browse.
Or click HERE and wait a few moments; our Chat will open.

HOURS: Monday to Friday, 09:00 - 13:00 / 14:00 - 17:30 CET

Assistance via Email:

Write to: support@ovye.it
HOURS: Monday to Friday, 09:00 - 13:00 / 14:00 - 17:30 CET

Corporate & B2B

SHOWROOM FOR RETAILERS ONLY:

Ovyè S.r.l.

Blocco 1, Via dei Pellicciai
Centergross, 40050
Funo di Argelato
Bologna - Italy

Tel: +39 051 66.47.102
Fax: +39 051.66.46.001
E-Mail: info@ovye.it

Opening hours:
Monday to Friday, 8.30 am to 6.00 pm non-stop