Privacy policy

Last updated: June 2026

1. Who We Are

This website, fernandlems.com (“the Site”), is operated by Fernanda Lemos, an individual based in Genoa, Italy (“we”, “us”, or “our”). We are the data controller responsible for your personal data.

If you have any questions about this policy or how we handle your data, you can contact us at fernandlems@gmail.com.

2. What Data We Collect

When you place an order or interact with the site, we may collect the following personal data:

  • Identity data: first name, last name;
  • Contact data: email address, phone number;
  • Delivery data: shipping address, billing address;
  • Transaction data: details of products purchased and payment amounts; and
  • Technical data: IP address, browser type, device information, pages visited (collected automatically by WordPress/WooCommerce).

We do not collect payment card details directly. All card payments are processed securely by Stripe, which is subject to its own privacy policy. Apple Pay and Google Pay transactions are similarly processed by their respective providers.

3. How We Use Your Data

We use your personal data for the following purposes:

PurposeLegal Basis
Processing and fulfilling your orderPerformance of a contract (Art. 6(1)(b) GDPR)
Sending order confirmations and shipping updatesPerformance of a contract (Art. 6(1)(b) GDPR)
Responding to enquiries and customer serviceLegitimate interest (Art. 6(1)(f) GDPR)
Complying with legal obligations (e.g. record-keeping)Legal obligation (Art. 6(1)(c) GDPR)
Sending newsletters (only if you opt in)Consent (Art. 6(1)(a) GDPR)

We do not sell your personal data to third parties. We do not use your data for automated profiling or decision-making.

4. Who We Share Your Data With

We share your data only where necessary, with the following categories of recipients:

  • Stripe: payment processing (see stripe.com/privacy);
  • Apple / Google: payment processing via Apple Pay/Google Pay;
  • Packlink PRO/BRT/Poste Italiane/UPS: shipping and delivery fulfilment;
  • Hostinger: website hosting (servers located within the EU); and
  • WooCommerce / Automattic: e-commerce platform.

All third-party processors are contractually required to handle your data securely and in compliance with GDPR.

5. How Long We Keep Your Data

We retain your personal data for as long as necessary to fulfil the purposes described in this policy:

  • Order data: kept for 10 years to comply with Italian fiscal record-keeping obligations;
  • Email newsletter subscriptions: until you unsubscribe; and
  • Customer service communications: up to 2 years after the last interaction.

6. Cookies

The Site uses cookies that are strictly necessary for the functioning of the shop (e.g., your shopping cart, session management) and for secure payment processing (Stripe). We do not use analytics or advertising cookies.

For full details, please see our Cookie Policy.

7. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access: you can request a copy of the data we hold about you;
  • Right to rectification: you can ask us to correct inaccurate data;
  • Right to erasure: you can ask us to delete your data, subject to legal retention obligations;
  • Right to restriction: you can ask us to limit how we use your data;
  • Right to data portability: you can request your data in a structured, machine-readable format;
  • Right to object: you can object to processing based on legitimate interest; and
  • Right to withdraw consent: where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, contact us at fernandlems@gmail.com.

You also have the right to lodge a complaint with the Italian data protection authority: Garante per la protezione dei dati personaliwww.garanteprivacy.it

8. Data Security

We take reasonable technical and organisational measures to protect your personal data against accidental loss, unauthorised access, or disclosure. Our website is hosted on Hostinger and uses HTTPS encryption.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be published on this page with an updated date. We encourage you to review this page periodically.

Shopping Basket