Privacy Policy of shop.blacklotus.eu
Website: shop.blacklotus.eu 路 Policy version: v2 路 Last update: 2026-07-22T16:09:04+00:00 路 Effective date: 2026-05-29
This policy is generated from the website profile, configured services and legal fields maintained in Lean Cookie Consent. The website owner must review it before publication and keep it aligned with the real forms, plugins, tags, providers, jurisdictions and retention rules used on the website.
Owner and Data Controller
Types of Data collected
This website may process Data provided directly by users, Data generated while browsing, technical identifiers needed for security and consent storage, and Data received through configured third-party services. The exact categories depend on the forms, embeds, analytics tools, marketing pixels, checkout providers, chat tools and other integrations actually enabled by the website owner.
Common categories of Personal Data
Contact details, account or form information, billing or commercial information where relevant, technical identifiers, browser and device information, approximate location derived from network data, interaction data, cookie identifiers and consent preferences.
Usage Data
Usage Data may include IP-derived information, browser type and version, operating system, referring pages, visited pages, time of request, time spent on pages, interaction events, diagnostic data and other technical information transmitted by the browser or device.
Some Data is required to provide the requested service or secure the website. Other Data is optional and is processed only when the user chooses to provide it or gives the required consent. If mandatory Data is not provided, some functions may not be available.
Users who provide Data about other people must have a valid reason to do so and should avoid sending excessive or irrelevant information.
How processing is organized
Methods of processing
The Owner should process Data with measures proportionate to the nature of the website and the services used: access limitation, secure accounts, provider review, minimization, retention control and documented instructions for people who can access Data. Processing should remain connected to the purposes described in this policy.
Persons authorized to process Data
In addition to the Owner, Data may be accessible to persons involved with the operation of this website such as administration, sales, marketing, legal, system administration or external parties appointed as processors where required.
Place
Data is processed at the Owner operating offices (Viale Papiniano 42 20123 Milano), on the infrastructure used for this website and by the providers configured by the Owner. Provider location may affect international transfer analysis.
Purposes of processing and legal basis
Providing and securing the website, responding to requests, complying with legal obligations, measuring performance, improving content, managing marketing activities where consent is given, and keeping evidence of consent choices.
Legal basis under GDPR
Consent, performance of a contract or pre-contractual measures, compliance with legal obligations, legitimate interests, vital interests, or tasks carried out in the public interest depending on the processing activity. Technical operations normally rely on necessity to provide the service, legal obligations or legitimate interests where appropriate. Optional analytics, advertising, remarketing, social embeds and similar trackers should run only after consent where required by applicable law.
Service-level processing matrix
Purpose, legal basis and retention details derived from the configured services. The website owner should verify each row against the real implementation and provider agreements.
| Service | Purpose | Legal basis | Retention | Consent status |
|---|---|---|---|---|
| Google Analytics 4 Google LLC | Measures website traffic, events and aggregated usage statistics. | Consent where required by ePrivacy/GDPR; legitimate interests only for privacy-friendly analytics where locally appropriate. | Up to 2 years. The owner should verify provider-side retention and any account-level retention settings. | Loaded only after analytics consent unless configured as strictly necessary and privacy-friendly. |
| Google Tag Manager Google LLC | Loads and manages tags configured by the website owner. | Consent where required by ePrivacy/GDPR; legitimate interests only for privacy-friendly analytics where locally appropriate. | Depends on configured tags. The owner should verify provider-side retention and any account-level retention settings. | Loaded only after analytics consent unless configured as strictly necessary and privacy-friendly. |
| Google Maps Google LLC | Displays interactive maps and may process location and interaction data. | Consent for advertising, remarketing, social embeds, tracking pixels and similar optional technologies. | Session to 6 months. The owner should verify provider-side retention and any account-level retention settings. | Loaded only after marketing consent. |
| YouTube Embed Google LLC | Displays embedded video content and may collect interaction data. | Consent for advertising, remarketing, social embeds, tracking pixels and similar optional technologies. | Session to 2 years. The owner should verify provider-side retention and any account-level retention settings. | Loaded only after marketing consent. |
| Trustpilot Widget Trustpilot A/S | Displays customer reviews or trust badges and may process interaction, device and referral data. | Consent for advertising, remarketing, social embeds, tracking pixels and similar optional technologies. | Session to 1 year. The owner should verify provider-side retention and any account-level retention settings. | Loaded only after marketing consent. |
| Cloudflare Cloudflare, Inc. | Provides CDN, security, bot mitigation, caching and network protection services. | Contract necessity, legal obligation or legitimate interests for security, fraud prevention, checkout and core service delivery. | Session to 30 minutes. The owner should verify provider-side retention and any account-level retention settings. | Always active when strictly necessary. |
| Google Fonts Google LLC | Loads web fonts used by the site interface; when loaded from Google servers it can expose technical request data such as IP address and user agent. | Contract necessity, legal obligation or legitimate interests for security, fraud prevention, checkout and core service delivery. | Request-level technical data. The owner should verify provider-side retention and any account-level retention settings. | Always active when strictly necessary. |
| Google reCAPTCHA Google LLC | Protects forms against spam and abuse by analyzing technical signals. | Contract necessity, legal obligation or legitimate interests for security, fraud prevention, checkout and core service delivery. | Session to 6 months. The owner should verify provider-side retention and any account-level retention settings. | Always active when strictly necessary. |
Cookies and tracking technologies
This website uses cookies or similar technologies to keep the website working, remember consent choices and, only when enabled by the visitor, measure traffic or support marketing activities. The Cookie Policy linked from this document lists the configured categories and services. Optional categories can be managed from the cookie banner or preference control.
Technical cookies
Required for core site features and security. Always active.
Status: always active because they are required for core site functionality and security.
Analytics cookies
Help measure traffic and improve content.
Status: used only when the visitor gives analytics consent.
Marketing cookies
Allow advertising, pixels and campaign measurement scripts.
Status: used only when the visitor gives marketing consent.
Services configured for this website
The services below come from the site profile. They should match the real scripts, tags, embeds, forms and checkout tools active on the website.
| Service | Provider | Category | Purpose | Cookies | Duration | Privacy |
|---|---|---|---|---|---|---|
| Google Analytics 4 | Google LLC | analytics | Measures website traffic, events and aggregated usage statistics. | _ga, _ga_*, _gid | Up to 2 years | Provider policy |
| Google Tag Manager | Google LLC | analytics | Loads and manages tags configured by the website owner. | Depends on configured tags | Depends on configured tags | Provider policy |
| Google Maps | Google LLC | marketing | Displays interactive maps and may process location and interaction data. | NID, 1P_JAR and related Google cookies | Session to 6 months | Provider policy |
| YouTube Embed | Google LLC | marketing | Displays embedded video content and may collect interaction data. | VISITOR_INFO1_LIVE, YSC, PREF | Session to 2 years | Provider policy |
| Trustpilot Widget | Trustpilot A/S | marketing | Displays customer reviews or trust badges and may process interaction, device and referral data. | Trustpilot widget/session identifiers | Session to 1 year | Provider policy |
| Cloudflare | Cloudflare, Inc. | technical | Provides CDN, security, bot mitigation, caching and network protection services. | __cf_bm, cf_clearance, _cfuvid | Session to 30 minutes | Provider policy |
| Google Fonts | Google LLC | technical | Loads web fonts used by the site interface; when loaded from Google servers it can expose technical request data such as IP address and user agent. | Usually none | Request-level technical data | Provider policy |
| Google reCAPTCHA | Google LLC | technical | Protects forms against spam and abuse by analyzing technical signals. | _GRECAPTCHA, NID | Session to 6 months | Provider policy |
Third-party services and processors
Hosting providers, analytics services, tag managers, embedded content providers, payment processors, CRM systems, email delivery services, advertising networks, security tools and support platforms used by the website owner. The website owner should ensure appropriate data processing agreements are in place where required.
International data transfers
Where data is transferred internationally, the owner should rely on adequacy decisions, Standard Contractual Clauses, binding corporate rules, explicit consent, contractual necessity or another valid transfer mechanism.
Retention time
Personal Data is retained only for as long as required by the purposes for which it was collected, unless a longer retention period is required by law, accounting obligations, dispute management or security needs. Consent choices for this website are configured to expire after 180 days unless changed by the visitor earlier.
Retention criteria
Retention should be based on purpose, legal basis, limitation periods, security needs and provider settings. When Data is no longer needed, it should be deleted, anonymized or aggregated. The Owner should verify that configured providers follow compatible retention rules.
Privacy rights
Users may exercise privacy rights regarding their Data, to the extent permitted by applicable law.
Rights available to Users
Depending on the applicable law, Users may withdraw consent, object to processing, access their Data, request correction, request deletion, request restriction, receive Data in a structured format, request portability where technically feasible and lodge a complaint with the competent supervisory authority.
Details about the right to object to processing
Where Personal Data is processed for public interest, official authority or legitimate interests, Users may object by providing grounds related to their particular situation. Where Data is processed for direct marketing purposes, Users can object at any time, free of charge and without providing any justification.
How to exercise rights
Users can exercise their rights by contacting the privacy contact listed in this policy. The owner may need to verify the requester identity before acting on the request.
Additional regional disclosures
Applicable jurisdictions configured by the owner: European Union / EEA, United Kingdom, Switzerland, United States privacy laws where applicable, Brazil LGPD where applicable
European Union, EEA, United Kingdom and Switzerland
Users in these regions may benefit from rights under GDPR, UK GDPR, Swiss FADP and related ePrivacy rules. Optional non-essential cookies and similar trackers should generally be based on consent unless another valid rule applies.
California and United States privacy laws
Where laws such as CCPA/CPRA or other state privacy laws apply, users may have rights to know, access, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and non-discrimination for exercising privacy rights. The website owner should disclose whether Personal Data is sold or shared and provide required opt-out mechanisms where applicable.
Sale or sharing disclosure
The owner should disclose whether Personal Data is sold or shared for cross-context behavioral advertising and provide required opt-out mechanisms where applicable.
Brazil LGPD and other jurisdictions
Where LGPD or similar privacy laws apply, users may have rights to confirmation of processing, access, correction, anonymization, blocking, deletion, portability and information about sharing. The website owner should adapt this document to the jurisdictions where it operates or targets users.
System logs and security
For operation, fraud prevention, diagnostics and security, the website and connected services may process technical logs such as timestamps, browser information, consent choices, policy version, banner version, request metadata and pseudonymized network identifiers.
Sensitive data
The website does not intentionally collect special categories of Personal Data unless clearly disclosed by the owner and supported by a valid legal basis.
Children privacy
This website is not intended to knowingly collect Personal Data from children below the configured minimum age: 16, unless a lower age is allowed by applicable local law. If the owner becomes aware that such Data has been collected without appropriate authorization, it should be deleted or otherwise handled according to applicable law.
Automated decision-making
Unless specifically disclosed by the owner, the website does not use Personal Data for solely automated decisions that produce legal or similarly significant effects.
Additional information about Data collection and processing
Legal action
The User Personal Data may be used by the Owner for legal purposes in court or in the stages leading to possible legal action arising from improper use of this website or related Services. The User acknowledges that the Owner may be required to reveal Personal Data upon request of public authorities.
Additional information about User Personal Data
In addition to the information contained in this privacy policy, this website may provide Users with contextual information concerning specific Services or the collection and processing of Personal Data upon request.
System logs and maintenance
For operation and maintenance purposes, this website and connected services may collect files that record interaction with the website, such as system logs, or use other Personal Data such as IP-derived technical identifiers for this purpose.
Information not contained in this policy
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time using the contact information provided in this document.
Changes to this policy
The website owner may update this policy when services, legal requirements or data processing activities change. When consent-relevant sections change, visitors may be asked to renew their consent.
Consent evidence
Lean Cookie Consent stores consent evidence with selected categories, policy version, banner version, domain, timestamp and pseudonymized technical identifiers where supported. This helps the Owner demonstrate which notice and banner were active when a choice was saved.
Definitions and legal references
Personal Data or Data
Any information that directly, indirectly, or in connection with other information allows for the identification or identifiability of a natural person.
Usage Data
Information collected automatically through this website or third-party services, including IP-derived information, browser and operating system details, request time, page path, interaction data and technical parameters about the User device.
User and Data Subject
The individual using this website who, unless otherwise specified, is the natural person to whom the Personal Data refers.
Data Processor
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
Data Controller or Owner
The natural or legal person, public authority, agency or other body which determines the purposes and means of the processing of Personal Data. Unless otherwise specified, the Data Controller is the Owner listed in this policy.
Service and this website
The Service is the website, application, content or functionality provided by the Owner through the configured domain: shop.blacklotus.eu.