Welcome to the world of Kaleido

Shop Kaleido

Contact Us

Shop Kaleido

Email:

shoponline.kaleido@gmail.com

 

Everything you need to live in style

PRIVACY POLICY


instagram
whatsapp

Follow Us

Copyright 2026 | Kaleido

Information on the Processing of Personal Data. Effective as of January 21, 2026

 

INTRODUCTION

 

This information notice takes into account the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (GDPR) and the Italian Privacy Code (Legislative Decree No. 196 of June 30, 2003). The document has also been drafted in accordance with the Guidelines of the Italian Data Protection Authority (in particular the Anti-Spam Guidelines issued by the Italian Data Protection Authority on July 4, 2013).

 

Data Controller: Alonzi Luana, IT03199490602, registered with the Chamber of Commerce of Frosinone and Latina, REA No. FR - 311490, VAT number IT03199490602, email: info@shopkaleido.com (hereinafter referred to as the Supplier).

 

Website to which this privacy policy refers: www.shopkaleido.com (Site).

 

The Data Controller has not appointed a DPO (Data Protection Officer). Therefore, you can send any inquiries directly to the Data Controller.

 

GENERAL INFORMATION

 

This document describes how the Data Controller processes your personal data provided on the Site.

 

The main types of processing of your personal data are described below. Specifically, the legal basis for processing is explained, whether providing personal data is mandatory, and the consequences of failure to provide it. To better describe your rights, where necessary, we have specified whether and when a specific processing of personal data is not carried out. On the Site, you have the option of entering the personal data of third parties. In this case, you guarantee that you have obtained the consent of these parties to enter this personal data. Therefore, you undertake to indemnify and hold the Data Controller harmless from any liability.

 

Website Registration

 

The information and data requested during registration will be used to allow you to access the reserved area of ​​the Website and to use the online services offered by the Data Controller to registered users. The legal basis for the processing is the Data Controller's need to implement pre-contractual measures taken at the request of the data subject. Providing data is optional. However, your refusal to provide such data will make it impossible to register on the Website.

 

Purchases on the Website

 

Your personal data will be processed to allow you to make purchases on the Website. In the event of an online purchase order, to allow the conclusion of the purchase contract and the correct execution of related transactions (and, where necessary under applicable legislation, to fulfill tax obligations). This processing of personal data also includes the possibility of sending communications (e.g., tracking, order information, and requests to leave a review) via automated tools such as email and/or text message and/or WhatsApp. The legal basis for processing is the Data Controller's obligation to perform the contract with the data subject or to comply with legal obligations. Regardless of the above (and therefore your consent), the Data Controller may process your data for so-called "soft spam" purposes, governed by Article 130 of the Italian Privacy Code. This means that, limited to the email address you provide in the context of a purchase through the Site, the Data Controller will process the email address to enable direct marketing of similar products/services, unless you object to such processing in accordance with the methods set forth in this policy. The legal basis for processing is the Data Controller's legitimate interest in sending this type of communication. This legitimate interest can be considered equivalent to the data subject's interest in receiving "soft spam" communications. The Data Controller may send emails to remind you to complete a purchase. The legal basis for this processing is the Data Controller's legitimate interest in sending this type of communication. Through the "follow on shop" option, the Data Controller may also process your personal data to send updates by email and/or telephone (depending on the options available on the Site from time to time) on the status of your orders, shipments, and/or supplies. The legal basis for this processing is the Data Controller's legitimate interest in sending this type of communication. This interest is equal to your interest in receiving this type of update. Providing your personal data for this purpose is optional. However, if you do not provide your personal data, the Data Controller will not be able to send you this type of communication. The Data Controller does not offer products or services. The Data Controller does not offer products or services prohibited to minors under 18. Therefore, no specific age verification system is implemented, as there are no content subject to legal restrictions.

 

Responding to Your Requests

 

Your data will be processed to respond to your requests for information. Providing it is optional, but refusal will make it impossible for the Data Controller to respond to your questions. The legal basis for the processing is the Data Controller's legitimate interest in responding to your requests. This legitimate interest is equivalent to the user's interest in receiving a response to communications sent to the Data Controller. The Data Controller may process your personal data for the purpose of managing support tickets. The legal basis for the processing is the Data Controller's legitimate interest in responding to your request. This interest is equivalent to the data subject's interest in receiving a response. Personal data will be retained for this purpose until the ticket is processed.

 

General Marketing

 

With your prior consent, the Data Controller may process the personal data you provide to send you advertising materials and/or newsletters relating to its own or third-party products. The legal basis for this processing is your consent. Providing personal data for this purpose is purely optional. Failure to consent to data processing for marketing purposes will prevent you from receiving advertising materials relating to the Data Controller's and/or third-party products/services, as well as preventing the Data Controller from conducting market research, including those aimed at assessing user satisfaction, and from sending you newsletters. These communications will be sent to the email address you provided on the Website.

 

Profiling

 

With your prior consent, the Data Controller may process your personal data for profiling purposes, i.e., to analyze your consumer choices by identifying the type and frequency of your purchases, in order to send you advertising material and/or newsletters relating to its own or third-party products of specific interest to you. The legal basis for this processing is your consent. Providing your data for this purpose is purely optional. Failure to consent to the processing of your personal data for profiling purposes will make it impossible for the Data Controller to develop your commercial profile by identifying your choices and purchasing habits, and to send you advertising material relating to the Data Controller's and/or third-party products of specific interest to you. These communications will be sent to the email address you provided on the Site.

 

Data Transfer

 

The Data Controller does not share your personal data with third parties.

 

Geolocation

 

The Site does not implement tools to geolocate your IP address.

 

Resume

 

It is not possible to submit resumes via the Site. Therefore, your data will not be processed for these purposes.

 

Appointment Booking

 

There are no third-party systems for booking appointments with the Data Controller on the Site. Therefore, your data will not be processed for this purpose. In any case, you may always contact the Data Controller using the contact details provided above.

 

Photographs and Videos

 

The Data Controller does not request the publication of photographs and/or videos of you. Therefore, your data will not be processed for these purposes.

 

Web Scraping

 

The use of any automated process or system to access, acquire, copy, or monitor any portion of our website, including, but not limited to, web scraping, crawling, or spidering, is expressly prohibited. The Data Controller reserves the right to take all necessary measures, including legal action, to prevent and prosecute any unauthorized scraping activity. By using the Site, you or any third party agree not to: (i) use automated systems, such as bots, scrapers, or spiders, to access or interact with the Site; (ii) collect content, data, or other information from the Site without express written permission; (iii) distribute, display, publish, or otherwise use content acquired through scraping techniques without consent. Any violation of this clause will be considered a material breach of the Site's Terms of Use and will result in the adoption of appropriate measures, including possible suspension of access to the Site and legal action to protect the Data Controller's interests.

 

Disclosure of Personal Data

 

As part of its ordinary activities, the Data Controller may disclose your personal data to certain categories of parties. Article 2 lists the parties to whom the Data Controller discloses your personal data. To facilitate the protection of your rights, Article 2 may specify in certain cases when your data will not be disclosed to third parties.

Disclosure of personal data to third parties is different from disclosure (regulated in the previous paragraph). In disclosure, the third party to whom the data is disclosed may use it only for the specific purposes described in the relationship with the Data Controller. In disclosure, however, the third party becomes the independent Data Controller of the personal data. Furthermore, your consent is always required to disclose your personal data to third parties.

Notwithstanding the foregoing, it is understood that the Data Controller may still use your personal data to properly fulfill the obligations set forth in applicable laws.

 

SPECIFIC PRIVACY NOTICE

 

Article 1 Processing Methods

 

1.1 Your personal data will be processed primarily using electronic or automated means, using methods and tools that ensure the security and confidentiality of your personal data.

 

1.2 The information acquired and the processing methods will be relevant and not excessive in relation to the type of services provided. Your data will also be managed and protected in secure IT environments appropriate to the circumstances.

 

1.3 The Site does not process "specially-identified data." Specially-identified data are data that may reveal racial or ethnic origin, religious, philosophical, or other beliefs, political opinions, membership of political parties, trade unions, associations, or organizations of a religious, philosophical, political, or trade union nature, health, or sexual orientation.

 

1.4 The Site does not process judicial data.

 

 

Article 2 Communication of Personal Data

 

The Data Controller may communicate your personal data to certain categories of entities. The entities to whom the Data Controller reserves the right to communicate your data are listed below:

 

- The Data Controller may disclose your personal data to all entities (including public authorities) that have access to personal data pursuant to regulatory or administrative provisions.


- Your personal data may also be disclosed to all public and/or private entities, natural and/or legal persons (legal, administrative, and tax consultancy firms, judicial offices, Chambers of Commerce, Labor Chambers and Offices, etc.), if disclosure is necessary or functional to the proper fulfillment of legal obligations.


- The Data Controller does not employ employees and/or collaborators of any kind. Therefore, your personal data will not be disclosed to these categories of entities.


- The Data Controller does not employ companies, consultants, or professionals responsible for the installation, maintenance, updating, and, in general, management of the Data Controller's hardware and software. Therefore, your data will not be disclosed to these categories of entities.


- To send its communications, the Data Controller uses external companies tasked with sending this type of communication (CRM platforms). Your personal data (particularly your email address) may therefore be shared with these companies.
 

- The Data Controller does not use external companies to provide customer care services.
 

- The Data Controller uses banks and companies that manage national and international payment circuits for online payments for products and services purchased through the Site.
The buyer's personal data may be shared with post offices, couriers, or shipping agents responsible for delivering the Products purchased through the Site.

 

- The Data Controller reserves the right to modify the above list based on its ordinary operations. Therefore, you are invited to regularly access this policy to check to which parties the Data Controller shares your personal data.

 

 

Article 3 Retention of Personal Data

 

3.1 This article describes how long the Data Controller reserves the right to retain your personal data.

For marketing purposes, personal data will be retained until you withdraw your consent. For inactive users, personal data will be deleted one year after the last email you viewed has been sent.
For the purpose of fulfilling the sales contract, data will be retained for 10 years from the date of receipt of the purchase order. This is to allow the Data Controller to exercise its right of defense and to demonstrate that the contract has been properly performed.
As required by Article 2220 of the Italian Civil Code, invoices, as well as all accounting records in general, are retained for a minimum period of ten years from the date of registration, so that they can be presented in the event of an audit.
You can delete your account through the Website (or by making a request to the Data Controller). In this case, all stored personal data will be deleted and will not be retained by the Data Controller for any purpose.
If you have activated the option to be updated on orders, shipments, and/or supplies, your personal data will be retained for this purpose exclusively for the time necessary to perform this service.
For "profiled" marketing purposes, unless consent is withdrawn first, the data will be retained for 12 months from the date of provision. After consent is withdrawn or at the end of the 12-month period, the personal data will be deleted and no longer used for this purpose.
For the use, publication, and reproduction of photographs and/or videos of you, the data will be retained for the time necessary to carry out the informational and promotional purposes related to the Data Controller's activities.
If age verification measures are implemented, the personal data will be processed exclusively for the time necessary to carry out the verification and will not be retained beyond that purpose.
Your personal data will be retained only for the time necessary to ensure the correct provision of the services offered through the Site.

 

3.2 Without prejudice to the provisions of Article 3.1, the Data Controller may retain your personal data for the time required by specific regulations, as amended from time to time.

 

Article 4 Transfer of Personal Data

 

4.1 The Data Controller is based in a country that provides an adequate level of security from a regulatory perspective. If your personal data is transferred to a non-EU country for which the European Commission has expressed an adequacy rating, the transfer is deemed to be secure from a regulatory perspective. This Article 4.1 indicates the countries to which your personal data may be transferred and where the European Commission has expressed an adequacy rating.

 

- We therefore encourage you to regularly access this Article to verify whether your personal data is being transferred to a country with these characteristics.

 

4.2 Without prejudice to the provisions of Article 4.1, your data may also be transferred to non-EU countries for which the European Commission has not issued an adequacy judgment. You are therefore invited to regularly review this Article 4.2 to determine which of these countries your data may be transferred.

 

4.3 In this Article, the Data Controller indicates the countries to which it specifically directs its activities. This circumstance may imply the application of the legislation of the relevant country, together with that governing the relationship with the user as indicated in the Introduction.

 

- At the user's request, the Data Controller will apply any more favorable legislation provided by the user's national legislation to the processing of personal data.

 

Article 5. Rights of the Data Subject

 

The Data Controller informs you that you have the right to:

 

- ask the Data Controller for access to your personal data and to rectify or erase it, limit its processing, or object to its processing, as well as the right to data portability.

 

- Withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

 

- Lodge a complaint with a supervisory authority.

 

The above rights may be exercised by submitting a request informally to the contact details indicated in the Introduction.

 

Article 6. Amendments and Miscellaneous

 

The Data Controller reserves the right to make changes to this policy at any time, providing appropriate publicity to Site users and ensuring adequate and comparable protection of personal data. To review any changes, you are invited to consult this policy regularly. In the event of substantial changes to this privacy policy, the Data Controller may also notify you via email.