PRIVACY POLICY
1. Introduction
By means of this notice, C.T.F. S.r.l. describes how the personal data of users browsing the website are processed. The company regards the protection of personal data as a fundamental value and guarantees compliance with the principles of EU Regulation 2016/679 (GDPR), Italian Legislative Decree 196/2003 and the measures issued by the Italian Data Protection Authority.
This notice concerns exclusively the processing carried out by C.T.F. S.r.l. as Data Controller in relation to its institutional website, and does not cover processing carried out on behalf of customers (manufacture and sale of products, order management, support, etc.).
2. Data Controller
C.T.F. S.r.l.
Via Labriola, 147 – 59013 Montemurlo (PO), Italy
Tax code and VAT no.: 02064530971
Email: info@compagniatessile.it
Telephone: +39 0574 556280
Certified email (PEC): ctf.filati@legalmail.it
For information on data processing and to exercise the rights provided for by the GDPR, the Data Controller may be contacted using the details above.
3. Types of Data Processed
Browsing data: acquired automatically by the IT systems during normal browsing (IP address, device identifiers, browser information, operating system, date and time of access, pages visited, technical data).
Data provided voluntarily: collected through the forms on the website, for example when making a purchase or registering an account (first name, surname, billing and shipping address, email, telephone, order details, username, encrypted password).
Data from correspondence: sent spontaneously by the user via email or contact form (name, email, message), processed solely to reply to the request.
4. Purposes of Processing
The data are processed for:
Commercial communications are sent only with the user’s specific consent. Data are neither sold nor transferred to third parties for marketing purposes.
5. Legal Basis for Processing
The processing is based on:
Commercial communications are sent only with explicit consent.
6. Methods of Processing
Data are processed using electronic and paper-based tools according to criteria related to the purposes indicated. C.T.F. S.r.l. adopts appropriate technical and organisational measures (Arts. 24, 25, 32 GDPR) to prevent unauthorised processing, unlawful access, loss of data, alteration of information and breaches of security.
7. Nature of the Provision of Data
Providing data in the forms is optional. However, the data marked as required are essential in order to respond to the request or to process the order.
8. Data Recipients
Data are processed by authorised personnel of C.T.F. S.r.l. within the scope of their respective duties. They may be disclosed to:
9. Transfer of Data to Third Countries
Data are normally processed within the European Economic Area. Any transfers to third countries take place in compliance with Arts. 44-49 GDPR, adopting the safeguards provided for by European legislation.
10. Retention Period
Order data: retained for 10 years, for tax and accounting compliance purposes.
Contact form data: retained for 12 months from the handling of the request.
Browsing data: retained for the time strictly necessary to pursue the purposes of website security and functioning, subject to any further legal obligations.
11. Cookies
The website uses technical cookies and tracking tools governed by a specific Cookie Policy, available for information on the types, purposes and methods of consent/withdrawal.
12. Links to Third-Party Websites
C.T.F. S.r.l. exercises no control over processing carried out by third parties. Users are invited to consult the privacy policies of any linked third-party websites before using their services.
13. Rights of the Data Subject
Data subjects may exercise the rights provided for by Arts. 15-22 GDPR:
Requests may be sent to the Data Controller’s contact details indicated in point 2.
14. Complaint to the Supervisory Authority
If the data subject considers that the processing infringes the GDPR, they may lodge a complaint with the Italian Data Protection Authority ([www.garanteprivacy.it](https://www.garanteprivacy.it)) or bring proceedings before the competent judicial authority.
15. Updates to this Notice
This notice may be updated to reflect regulatory, organisational or technological changes, or following the introduction of new services. The updated version will be published together with the date of the last update.
Last updated: 3 August 2026