Last updated: 14 August 2026.
1. Data Controller
Personal data collected through this website is processed by LODGE MILANO SL (VAT / Tax ID B26818765), a Spanish limited company registered at the Madrid Commercial Registry (section 8, sheet M-874724, entry 1, dated 23/02/2026), with registered office at Paseo de la Castellana 194, 28046 Madrid, Spain. Sole director and sole shareholder: Joris Tsaratody Ferron. Contact: info@lodgemilanoandco.com.
LODGE MILANO SL has not appointed a Data Protection Officer, as none of the cases in Article 37 GDPR apply.
2. Applicable Law
Because we are established in the European Union, all processing is governed by the General Data Protection Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD), the ePrivacy Directive as implemented in Spain (Law 34/2002, LSSI-CE), and the consumer information duties of Directive 2011/83/EU. For visitors from California, applicable CCPA/CPRA rights are described in Section 9.
3. Categories of Personal Data
- Identification data: full name.
- Contact data: postal address, email, phone number.
- Transaction data: order details, invoice information, amounts, payment references. Full card numbers are not stored on our systems; they are processed directly by our payment processor (see Section 6).
- Communications: content of messages you send via the contact form or email.
- Technical data: IP address, device type, browser, timestamps — strictly for site operation, security and fraud prevention.
- Marketing data (only with consent): preferences, past purchases and profile used to tailor communications.
We do not process special categories of data (Article 9 GDPR). The site is not directed at children under 14; if such data is inadvertently collected, it will be deleted.
4. Purposes and Legal Basis
- Order fulfilment (Article 6.1.b GDPR — performance of contract): checkout, payment processing, shipping, invoicing, warranty and returns management.
- Customer communication (Article 6.1.b GDPR): order confirmations, shipping notifications, incident handling, response to enquiries.
- Legal compliance (Article 6.1.c GDPR): tax, accounting and commerce law obligations.
- Fraud prevention and site security (Article 6.1.f GDPR — legitimate interest).
- Marketing communications (Article 6.1.a GDPR — explicit consent), only when a separate opt-in is provided.
5. Data Retention
- Enquiries with no order: up to 12 months from last communication.
- Order and customer data: for the duration of the commercial relationship and, thereafter, for the periods required by Spanish accounting and tax law (up to 6 years under the Spanish Code of Commerce).
- Marketing data: until you withdraw consent.
- Technical and security logs: up to 12 months.
6. Recipients and Data Processors
We do not sell personal data. The following processors act on our behalf under Article 28 GDPR agreements:
| Processor | Service | Location | Safeguard |
|---|---|---|---|
| Hostinger International Ltd | Web hosting, database, outgoing form email | Cyprus (EU) | No international transfer |
| Elavon Financial Services DAC (via Frisbii) | Payment processing, 3-D Secure authentication, fraud prevention | Ireland (EU) | No international transfer |
| Automattic Inc. (WooCommerce Payments infrastructure) | Payment orchestration inside WooCommerce | USA | EU–US Data Privacy Framework and Standard Contractual Clauses |
| Shipping carrier assigned per shipment | Delivery of the physical order to the address provided | EU / carrier-dependent | Occasional processor for delivery |
| Public authorities (Spanish Tax Agency, Social Security) | When required by law | Spain (EU) | Legal obligation |
7. International Transfers
Most of our processors are established in the European Union. Where WooCommerce Payments infrastructure or third-party services occasionally involve access from the United States, we rely on the EU–US Data Privacy Framework adequacy decision (Commission Decision C(2023) 4745 of 10 July 2023) and, where applicable, on the Standard Contractual Clauses approved by the European Commission (Decision 2021/914). Certified organisations are listed at dataprivacyframework.gov. Copies of the safeguards in place are available on written request to info@lodgemilanoandco.com.
8. Your Rights under GDPR
- Access, rectification, erasure and restriction of processing.
- Objection to processing based on legitimate interest and to direct marketing.
- Data portability.
- Withdrawal of consent at any time, without effect on the lawfulness of prior processing.
- The right not to be subject to solely automated decisions with legal effect (LODGE MILANO SL does not carry out such processing).
To exercise these rights, write to info@lodgemilanoandco.com including a copy of an official ID. We will respond within one month. If you consider that the processing does not comply with the GDPR, you may lodge a complaint with the Spanish Data Protection Agency — aepd.es.
9. California Consumer Rights (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request access and deletion, to correct inaccurate information, and to opt out of the sale or sharing of personal information. LODGE MILANO SL does not sell or share personal information for cross-context behavioural advertising. To exercise your rights, contact info@lodgemilanoandco.com. We do not discriminate against consumers who exercise their CCPA/CPRA rights.
10. Security
We apply technical and organisational measures appropriate to the risk (Article 32 GDPR), including TLS encryption in transit, restricted authenticated access to the administration panel, and periodic backups.
11. Cookies
The use of cookies and similar technologies is described in the Cookie Policy.
12. Changes to this Policy
We may update this Privacy Policy to reflect legal or technical changes. Material changes will be announced on this page with the updated date.