PRIVACY POLICY
Last updated: 2 September 2026
Dasaby Design S.R.L. respects the privacy of visitors to this website and processes personal data in accordance with applicable data-protection law, including Regulation (EU) 2016/679 (“GDPR”).
1. Data Controller
The Data Controller is: Dasaby Design S.R.L.
Società a socio unico
Registered office: Via del Lauro 9, 20121 Milano (MI), Italy, c/o Lexia
P.IVA / C.F.: 14271110968
REA: MI-2770568
PEC: dasabydesign@legalmail.it
Privacy-related requests may be sent to the contact details above.
2. Personal Data We Process
When you visit or interact with this website, we may process limited categories of personal data.
Contact data. If you contact Dasaby through the website contact form, we may receive your name, email address and any information you choose to include in your message or attachments.
Technical and browsing data. The website and its technical providers may automatically process technical information needed to provide, secure and maintain the website. This may include IP address, browser and device information, request data, date and time of access, technical logs, diagnostic information and security-related information.
Security and anti-abuse information. The contact form may use Google reCAPTCHA or related anti-spam technology. Such technology may process technical information in order to identify automated, fraudulent or abusive activity.
Cookie-related information. Necessary cookies or similar technologies may be used for website operation, security, technical functionality and the recording of relevant technical choices. Further information is provided in our Cookie Policy.
Dasaby does not currently provide customer accounts, accept payments through this website or operate a newsletter through this website.
3. Purposes and Legal Bases
Personal data submitted through the contact form is processed in order to receive, manage and respond to enquiries. Where an enquiry relates to a potential commercial relationship, trade enquiry, collaboration, supply arrangement or other steps requested by the sender before entering into a contract, processing may be necessary to take pre-contractual measures at the request of the data subject.
For other enquiries, processing may be based on Dasaby's legitimate interest in receiving and responding to communications addressed to the company.
Technical data may be processed where necessary for Dasaby's legitimate interests in maintaining the security, availability, integrity and correct functioning of the website and preventing misuse.
Personal data may also be processed where necessary to comply with a legal obligation.
Where Dasaby introduces any technology in the future that legally requires consent, that technology will not be used without obtaining the required consent.
Article 6 GDPR provides, among other legal bases, processing necessary for pre-contractual measures requested by the data subject and processing necessary for legitimate interests, subject to the conditions laid down in the Regulation.
4. Providing Personal Data
Browsing the public areas of the website does not require you to submit personal information through a form.
If you decide to contact Dasaby, however, sufficient contact information must be provided for us to respond to you.
Please avoid submitting special-category or otherwise sensitive personal data unless it is genuinely necessary for your enquiry.
5. Recipients and Service Providers
Personal data may be accessible to authorised persons acting on behalf of Dasaby and to service providers used to operate and protect the website.
These may include:
GoDaddy, which provides website-building, hosting, form and related infrastructure services.
Google, where reCAPTCHA or similar Google security technology is used to protect the website against spam or abuse.
Technical, IT, security, professional or advisory providers where reasonably necessary.
Public authorities, courts or regulatory bodies where disclosure is required by applicable law.
Dasaby does not sell personal data.
6. Transfers Outside the European Economic Area
Some technology providers used by Dasaby operate internationally and may process information outside the European Economic Area. Where personal data is transferred internationally, such transfers will be subject to an appropriate mechanism recognised under applicable data-protection law, such as an adequacy decision, Standard Contractual Clauses or another legally recognised safeguard.
7. Retention
Contact-form enquiries will normally be retained only for the period reasonably necessary to respond to and manage the relevant enquiry and, as a general rule, for no longer than 12 months after the last meaningful correspondence, unless a longer period is necessary because:
- a commercial relationship remains active;
- the information is required to establish, exercise or defend legal claims; or retention is required by law.
- Technical and security information may be retained for the periods reasonably required by the relevant service provider and for the purposes of website security, technical operation and incident investigation.
- When personal data is no longer required, it will be deleted or anonymised where reasonably possible.
8. Your Rights
Subject to the conditions provided by the GDPR, individuals may have the right to request:
- access to their personal data;
- correction of inaccurate or incomplete data;
- deletion of personal data;
- restriction of processing;
- objection to processing based on legitimate interests;
- data portability where applicable;
- and withdrawal of consent at any time where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Requests may be addressed to:
Dasaby may request information reasonably necessary to verify the identity of the person making the request.
9. Right to Complain
You also have the right to lodge a complaint with a competent supervisory authority.
In Italy, the supervisory authority is: Garante per la Protezione dei Dati Personali
10. Automated Decision-Making
Dasaby does not currently use information collected through this website to make decisions based solely on automated processing that produce legal or similarly significant effects concerning individuals.
11. Children
This website is intended to present Dasaby, its products and collections to a general audience and is not specifically directed at children. Dasaby does not knowingly seek to collect personal information from children through this website.
12. External Websites and Marketplaces
This website may contain links to third-party websites, social-media platforms, marketplaces or retailers. When you follow such a link, the relevant third party may process your personal data independently and according to its own privacy practices. Dasaby is not responsible for the privacy practices of independent third-party websites.
13. Security
Dasaby takes reasonable technical and organisational measures designed to protect personal data against unauthorised access, disclosure, loss, alteration or misuse. No internet-based system, however, can provide an absolute guarantee of security.
14. Changes to this Privacy Policy
This Privacy Policy may be updated where the website, technologies used by Dasaby, legal requirements or our data-processing activities change. The current version will be published on this website together with the date of its most recent update.
© 2026 Dasaby Design S.R.L. · Società a socio unico · P.IVA/C.F. 14271110968 · REA MI-2770568 · Capitale sociale €1.000 i.v. · Sede legale: Via del Lauro 9, 20121 Milano (MI), c/o Lexia · PEC: dasabydesign@legalmail.it