Privacy Policy

Last updated: 4 August 2026

 

Discretion is a fundamental principle of our Maison. HEIS treats your personal data with the same rigour applied to the creation of our products. We collect and analyse data exclusively to refine your experience, process your transactions securely, and understand our own performance.

We do not sell or rent your personal information. We do not share it with external advertising networks, third-party data brokers, or shared merchant databases for cross-site retargeting. We consider privacy a fundamental right of modern luxury, not a concession.

This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction through our platform, including all related content, features, tools, products and services (the "Services"), or when you otherwise communicate with us. The Services are operated in conjunction with our technical partner, Shopify, in compliance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003, as amended.

Please read this Privacy Policy carefully. By accessing the Services you acknowledge that you have read and understood it. Where our Terms of Service conflict with this Privacy Policy, this Privacy Policy prevails in respect of the collection, processing and disclosure of personal information.

 

1. Data Controller

The entity determining the processing of your data is:

The legal entity governing these transactions is HEIS MILANO di Filipe Abrahao, with registered office in Piazza della Repubblica 19, 20124 Milan (MI), Italy, VAT: 05620550284, REA: MI-2785988, PEC: heismilano@pec.it. Privacy matters: privacy@heismilano.com. Corporate Legal Office: legal@heismilano.com

We have assessed our processing activities and, as of the date above, we are not required to appoint a Data Protection Officer under Article 37 GDPR. Should this change, we will update this Policy and publish the relevant contact details.

 

2. Personal Information We Collect

By "personal information" we mean information that identifies or can reasonably be linked to you. It does not include data collected anonymously or effectively de-identified. Depending on how you interact with the Services and where you reside, we may process the following categories:

Identity and contact details. Name, billing address, shipping address, telephone number, email address.

Financial information. Transaction details, form of payment, payment confirmation, and financial account references. HEIS does not store your credit card information. Payment data is captured and processed directly by encrypted gateways under Shopify Payments and its authorised processors.

Account information. Username, password (stored in hashed form), preferences and settings.

Transaction information. Items viewed, added to cart or wishlist, purchased, returned, exchanged or cancelled, and your transaction history.

Communications with us. The content of your enquiries, customer care correspondence, and returns or after-sales requests.

Device and technical information. Device type, browser, network connection, IP address and unique identifiers.

Usage information. How and when you navigate and interact with the Services.

System logs. For operation, maintenance and security purposes, the Services record technical interaction data, including IP address, timestamp and server response. These logs are retained for the period necessary to the purpose and are not used to profile you.

Consent records. Your cookie and marketing choices, with timestamp, scope and version of the notice, retained as evidence of lawful processing for the periods set out in Section 9.

Providing identity, contact, shipping and payment data is necessary to conclude and perform a purchase. Without it we cannot process your order. All other information, including marketing consent, analytics consent and account preferences, is provided freely, and refusal has no consequence on your ability to browse or purchase.

We do not knowingly collect special categories of data under Article 9 GDPR. Please do not include such information in your communications with us.

Business contacts and candidates. Where you contact us in a professional capacity, or submit an application, we process the identity, contact and professional information you provide. Business enquiries are processed on the basis of our legitimate interest in evaluating commercial opportunities and are retained for 24 months from the last contact. Applications are processed on the basis of your consent, retained for 12 months, and deleted thereafter unless you ask us to retain them for a longer period. We do not process special categories of data in either context, and we ask you not to include such information.

 

3. Sources of Personal Information

We collect personal information directly from you, when you create an account, place an order, or contact us. We collect it automatically through the Services, from your device and through cookies and similar technologies, subject to your prior consent where required. We also receive it from our service providers, when they process personal information on our behalf, and from our partners, such as logistics operators confirming a delivery event.

 

4. How We Use Your Personal Information

Provide, tailor and improve the Services. To perform our contract with you: process payments, fulfil and dispatch orders, manage returns and exchanges, create and administer your account, remember your preferences, notify you about your order status, and provide a coherent shopping experience.

Client care and relationship. To respond to your enquiries, provide after-sales assistance, and maintain our commercial relationship.

Marketing and communications. To send you brand updates, editorial content and invitations by email or post, where you have consented or as otherwise permitted by applicable law, and to measure the effectiveness of those communications, for example whether a message has been opened. This measurement is internal. It does not enable advertising cookies and involves no disclosure to retargeting networks.

Analytics. Where you consent, to understand in aggregate how the Services are used and to refine their design and performance.

Security and fraud prevention. To authenticate accounts, secure the payment and shopping environment, and detect, investigate or act upon possible fraudulent, unlawful or malicious activity. If you register an account, you remain responsible for the confidentiality of your credentials. We recommend you do not share them.

Legal reasons. To comply with applicable law, respond to valid legal process, exercise or defend legal claims, and enforce or investigate potential violations of our terms.

 

5. Legal Bases for Processing

Where the GDPR applies, we process personal information on four legal bases. Each purpose corresponds to one of them.

Performance of a contract, Art. 6(1)(b), covers order processing, delivery and account management. Without this information we cannot conclude or perform the sale.

Consent, Art. 6(1)(a) and Art. 122 of Italian Legislative Decree 196/2003, covers analytics cookies, marketing communications and non-essential technologies. Nothing in this category operates before you have granted it.

Legal obligation, Art. 6(1)(c), covers tax records, accounting and statutory consumer obligations. These duties are imposed on us by law and do not depend on our discretion.

Legitimate interests, Art. 6(1)(f), cover platform security, fraud prevention, protection of our rights and service improvement.

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interest does not override your rights and freedoms. You may object to such processing at any time, as set out in Section 10, and you may request further information on that assessment.

Where we rely on consent, you may withdraw it at any time. Withdrawal is as straightforward as granting it, and does not affect the lawfulness of processing carried out beforehand.

 

6. Disclosure of Personal Information

HEIS operates with strict data discipline. We disclose personal information only where necessary for legitimate operational purposes, and only to recipients bound by contractual confidentiality and security obligations:

To processors performing essential services on our behalf: e-commerce infrastructure, secure payment processing, order fulfilment, shipping and logistics, cloud storage, transactional and marketing email delivery, and analytics.

Where you direct or request it, such as transmitting your address to a courier.

In connection with a corporate transaction such as a merger, acquisition, reorganisation or transfer of assets, in which case we will notify you as required by law.

To comply with legal obligations, respond to lawful requests from public authorities, and protect the Services, our rights and the safety of others.

Our principal processors and recipients are:

Shopify International Ltd. (Ireland), for the e-commerce platform, hosting and payment facilitation.

Google Ireland Ltd., for analytics, activated only where you have consented.

Logistics and shipping partners, for the delivery of your order.

We do not sell, rent, or otherwise make your personal information available to advertising networks, data brokers, or shared merchant databases for cross-site targeted advertising.

 

7. Relationship with Shopify

The Services are hosted by Shopify, which provides the technical infrastructure enabling the Maison to operate securely. Information you submit is transmitted to and stored by Shopify in order to process your orders and deliver the Services. Shopify acts as our processor under Article 28 GDPR and processes your personal information strictly to facilitate your direct relationship with HEIS. Further detail is available in the Shopify Consumer Privacy Policy.

 

8. Cookies and Similar Technologies

We use strictly necessary technologies to operate the Services and, subject to your prior consent, analytics technologies to measure performance. No non-essential cookie or similar technology is placed on your device before you provide consent through our cookie banner. Refusing consent has no consequence on your ability to browse or purchase.

You may change or withdraw your choices at any time via the Data Preferences link in the website footer. Full details, including the identity and duration of each technology, are set out in our Cookie Policy.

 

9. Retention Periods

We retain personal information only for as long as necessary for the purposes described, and thereafter only where evidentiary or statutory reasons require it.

Order, invoicing and transactional data is retained for ten years from the transaction, as required by Italian tax and accounting law.

Account data is retained for the life of the account, and for twenty-four months thereafter.

Client care correspondence is retained for twenty-four months from the last contact. The same period applies to business enquiries.

Marketing consent records and communication data are retained until consent is withdrawn, and for a further twenty-four months as evidence of that consent.

Cookie consent records are renewed every twelve months. Each record is retained for twenty-four months as evidence.

Analytics data collected through Google Analytics 4 is retained for fourteen months.

System logs are retained for twelve months.

Applications are retained for twelve months, unless a longer retention is requested.

Data relating to a dispute or legal claim is retained until final resolution and expiry of the applicable limitation period.

At the end of the applicable period, data is deleted or irreversibly anonymised.

 

10. Your Rights

Under the GDPR you retain control over your personal data. Subject to the conditions and exceptions provided by law, you may exercise the rights set out below.

The right of access allows you to obtain confirmation of processing and a copy of your personal information.

The right of rectification allows you to have inaccurate or incomplete data corrected.

The right of erasure allows you to request deletion, where no overriding legal obligation requires retention.

The right of restriction allows you to request that we limit our processing in defined circumstances.

The right of portability allows you to receive your data in a structured, machine-readable format, or to have it transmitted to another controller.

The right to object applies to processing based on legitimate interests, and at any time to processing for direct marketing purposes.

Consent, where it is the basis of processing, may be withdrawn at any time, without affecting the lawfulness of prior processing.

Two further points concern how we operate.

We take no decisions producing legal effects on you, or similarly significantly affecting you, based solely on automated processing. Nor do we carry out profiling in that sense.

Promotional communications may be discontinued at any time, through the link in each email or by writing to us. Service messages relating to your account or your orders may still be sent.

To exercise your rights, or to seek clarification on our privacy practices, write to privacy@heismilano.com, or to our Corporate Legal Office at legal@heismilano.com.

We may need to verify your identity before acting on your request, as permitted or required by law. You may appoint an authorised representative, subject to proof of authorisation. We will respond within one month, extendable by two further months for complex requests, in accordance with Article 12 GDPR. Exercising your rights is free of charge, and will never result in less favourable treatment.

To learn more about how Shopify processes personal information and the rights available to you, visit privacy.shopify.com.

 

11. Complaints

If you have concerns about how we process your personal information, please contact us first at privacy@heismilano.com. Should our response not satisfy you, you have the right to lodge a complaint with a supervisory authority:

Italy: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, garanteprivacy.it

Other EEA countries: you may lodge a complaint with the supervisory authority of your habitual residence or place of work. The list is published by the European Data Protection Board.

You also retain the right to seek a judicial remedy before the competent courts.

 

12. International Transfers

Your personal information is primarily processed within the European Economic Area. Certain of our processors, including sub-processors engaged by Shopify and Google, may access or process data from outside the EEA, principally the United States.

Where we transfer personal information outside the European Economic Area, we rely on recognised transfer mechanisms: an adequacy decision covering the destination country, the EU-U.S. Data Privacy Framework where the recipient is certified (European Commission adequacy decision of 10 July 2023), the European Commission's Standard Contractual Clauses, and supplementary technical and organisational safeguards where our assessment identifies the need. A copy of the relevant safeguards, and the current list of recipients located outside the EEA, may be requested at privacy@heismilano.com.

 

13. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS), access control on a need-to-know basis, and payment processing through PCI-DSS certified providers. Please be aware that no security measure is impenetrable and information transmitted over the internet cannot be guaranteed absolutely secure. We recommend you do not use unsecured channels to send us sensitive or confidential information.

Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and inform you without undue delay where the law so requires.

 

14. Minors

The Services are not directed to minors and we do not knowingly collect personal information from persons below the age of majority in their jurisdiction. Purchases require legal capacity to contract. If you are a parent or guardian and believe a minor has provided us with personal information, contact us at privacy@heismilano.com and we will delete it.

 

15. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or for operational, legal or regulatory reasons. The revised version will be published on this website with an updated "Last updated" date. Where changes are material, in particular where they affect the purposes of processing or the recipients of your data, we will provide notice in advance and, where required, request renewed consent.

 

16. Contact

For any question regarding our privacy practices, or to exercise your rights:

Privacy matters: privacy@heismilano.com - Corporate Legal Office: legal@heismilano.com - Client Services: clientservices@heismilano.com

For the purposes of applicable data protection law, HEIS MILANO di Filipe Abrahao is the data controller of your personal information.