Privacy policy
Personal Data Processing Notice
1. Data Controller
Sesterzi 2 S.r.l.
Registered Office: Via Carlo Maria Maggi 6, 20154 Milano (Italy)
VAT No.: IT13834080965
PEC: sesterzi2@pec.it
Business Email: info@laterego.it
Privacy Contact: via the site chat (indicating the order number as a reference).
Note: LaterEgo does not use public email addresses for privacy management, in order to guarantee the security and traceability of requests through the dedicated support platform.
2. Purchase Method: Guest Checkout
LaterEgo operates a simplified sales model that does not provide for the creation of registered user accounts (there are no usernames or passwords). All purchases are made in "Guest" mode through the secure Shopify platform.
The data provided during checkout is collected exclusively for the purpose of fulfilling the specific order and for the resulting legal obligations.
As there are no user accounts, the order number (received by email at the time of purchase) is the customer's sole identifier. For any communication with customer support or to exercise your privacy rights via the site chat, you must provide this number. You will never be asked for any password or other sensitive access credentials.
3. Categories of Data Collected
| Category | Specific data | Source | Mandatory |
|---|---|---|---|
| Identification and contact data | Name, surname, shipping address, email (for order confirmation and updates), phone number (optional) | Provided by the customer at checkout | Required for order fulfilment |
| Payment data | Card / account data (managed exclusively by Shopify Payments / Stripe / PayPal — LaterEgo does NOT store or access full card data) | Secure payment gateway | Required for payment |
| Personal images |
Photos uploaded by the customer. They may portray faces or natural persons (potentially biometric data
under Art. 9 GDPR). Images are not shared with external suppliers. The raw material provider has no access to the images or to any other personal data of the data subjects. |
Uploaded by the customer through the site | Required for the customised product |
| Navigation data | IP address, browser, operating system, pages visited, session duration, technical and analytics cookies | Shopify and analytics systems | Automatic |
| Order and chat data | Purchase history, order number, content of communications via the site chat | Generated by use of the service | Automatic |
| Mailing list data | Email, name (optional), communication preferences | Voluntary opt-in form | Optional |
4. Purposes and Legal Bases of Processing
| Purpose | Legal basis (GDPR) | Retention period |
|---|---|---|
| Order fulfilment (production, shipping, billing) | Art. 6.1.b — Performance of the contract | 10 years (tax obligation, Presidential Decree 633/1972) |
| Order updates by email | Art. 6.1.b — Performance of the contract | Duration of the relationship + 2 years |
| Creation of the 3D rendering from the face/image | Art. 6.1.a + Art. 9.2.a — Explicit consent | Only during processing — image retained for warranty purposes |
| Retention of the image for warranty management and post-production disputes | Art. 9.2.f + Art. 6.1.f — Establishment/defence of a legal claim + Legitimate interest | 2 years from delivery (or until an open dispute is resolved) |
| Management of customer support via chat | Art. 6.1.b + Art. 6.1.f — Contract + Legitimate interest | 2 years from ticket closure |
| Sending newsletters and promotional communications (mailing list) | Art. 6.1.a — Consent | Until consent is revoked |
| Tax and accounting obligations | Art. 6.1.c — Legal obligation | 10 years (Presidential Decree 633/1972) |
| Legal defence | Art. 6.1.f + Art. 9.2.f | Until the limitation period expires (max 10 years) |
5. Special Treatment: Personal Images
⚠️ SPECIAL CATEGORY OF DATA — ART. 9 GDPR
The personal images uploaded may contain biometric data. Processing is subject to enhanced protection and requires your explicit consent before any processing.
The uploaded images are retained in our system, linked to the order number, for 2 years from delivery. This allows us to verify the correspondence between the approved product and the one received in the event of a dispute. Once this period has elapsed without open controversies, the images are deleted automatically. In the event of an ongoing dispute, retention is extended until final resolution.
Given the specific nature of our service ("Turn Your Photo into a 3D Brick Statue"), the processing of personal images is central. Such images may contain biometric data and require enhanced protection.
Post-production retention of the image responds to a legitimate interest of both the Controller and the data subject: the image constitutes the contractual proof of what was approved by the customer and produced by LaterEgo. In the absence of this evidentiary element, it would be impossible to verify the merits of any claims relating to the quality or correspondence of the product. Processing at this stage does not require the original consent to be maintained, as it is based on the distinct legal bases of Art. 9.2.f and Art. 6.1.f GDPR.
Image Lifecycle and Legal Bases
Legal basis: Art. 9.2.f (defence of a legal claim) + Art. 6.1.f (legitimate interest).
Additional Security Guarantees
- Images are NEVER shared with third parties.
- Images are NEVER transmitted to raw material suppliers or production partners — processing is handled internally by LaterEgo.
- Images are NEVER used to train public artificial intelligence algorithms.
- Images are NEVER used for marketing or advertising purposes without further specific consent.
- Access is restricted exclusively to authorised technical staff.
Consent Revocation
Revocation of consent to the processing of the image is possible before production begins. Once production has started, revocation of the consent relating to the production stage is not possible without cancelling the order (the product is made to measure under Art. 59 letter c of Legislative Decree 206/2005). However, post-production retention for warranty and dispute purposes is not based on consent but on Art. 9.2.f GDPR; therefore, revocation of consent does not affect the lawfulness of this retention, which is necessary for defensive purposes.
6. Mailing List Opt-in
Subscription to our newsletter is optional and occurs only through explicit consent (Art. 6.1.a GDPR) by means of a non-pre-selected checkbox or a dedicated form.
Purpose: Sending promotional communications, special offers and product news.
Data processed: Email address and, optionally, name.
Manager: The newsletter service is operated through a specialised email marketing platform,
acting as Data Processor under Art. 28 GDPR. The specific name of the platform is available on request via
the site chat. In the event of an extra-EU transfer, the Standard Contractual Clauses (SCCs) under EU
Decision 2021/914 are adopted.
Revocation: You may revoke consent at any time by clicking the "Unsubscribe" link at the
foot of every email, or by contacting support via chat. Revocation is immediate.
Not subscribing to the mailing list does not in any way affect the possibility of making purchases on the site.
7. Data Processors (Sub-processors)
To deliver the service, LaterEgo relies on selected third-party providers that act as Data Processors or independent Controllers.
| Sub-processor | Service | Country | GDPR safeguards |
|---|---|---|---|
| Shopify Inc. | E-commerce platform, hosting | USA / EU | Standard Contractual Clauses (SCCs) |
| Stripe Inc. | Payment processor | USA | SCCs + PCI-DSS Certification |
| PayPal Holdings Inc. | Payment processor | USA | SCCs + Binding Corporate Rules |
| Email Marketing Platform | Mailing list management, sending newsletters and commercial communications to subscribers | EU/USA country (with SCCs safeguards if extra-EU) | Standard Contractual Clauses (SCCs) where applicable — complete list of processors available on request via chat |
8. Extra-EU Transfers
Some of our providers (e.g. Shopify, Stripe, PayPal) are based in or process data in the United States of America. The transfer of data to such countries occurs exclusively on the basis of the Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914/EU), which guarantee an adequate level of protection of personal data even outside the European Economic Area.
Shopify and the other providers contractually commit to complying with the GDPR through specific Data Processing Agreements (DPA).
9. Retention Periods
| Data category | Retention period | Basis/Reason |
|---|---|---|
| Identification data | 10 years from conclusion of the contract | Tax obligation (Presidential Decree 633/1972) |
| Contact email (order) | 2 years from delivery | Warranty management and post-sales support |
| Payment data | Not retained by LaterEgo | Managed entirely by the Gateways |
| Uploaded images | 2 years from the delivery date | Legal guarantee for goods (Art. 130 Italian Consumer Code) + Defence of disputes (Art. 9.2.f GDPR) |
| Images with an open dispute | Until final resolution + 30 days | Need for evidence to handle the claim |
| Navigation data | 13 months (analytics) / Session (technical) | Legitimate interest / Cookie consent |
| Support chat | 2 years from closure | Legitimate interest (defence of disputes) |
| Mailing list data | Until deletion / consent revocation | Consent (Art. 6.1.a) |
| Tax data (invoices) | 10 years | Legal obligation (Presidential Decree 633/1972) |
10. Data Subject Rights (Art. 15-22 GDPR)
As a data subject, you have the right to exercise the following rights at any time:
You can exercise your rights by contacting us via the site chat. For your security, you will be asked to provide the order number as proof of your identity (as this is a guest checkout system without a password). We will respond within 30 days.
11. Cookies and Tracking Technologies
This document does not detail the specific use of cookies. For complete information, please consult the separate Cookie Policy available on our site.
Please note that the Shopify platform uses technical cookies necessary for the operation of the cart, the checkout and browsing security. Analytics or marketing cookies may be activated only with your prior consent via the cookie banner.
12. Minors
It is strictly forbidden to upload images depicting minors under 18 without the prior written consent of the parent or legal guardian. LaterEgo is not responsible for uploads made in violation of this provision.
The service is intended for an adult audience. Should we detect the unauthorised upload of images of minors, we reserve the right to suspend the order and request immediate proof of parental consent, or to proceed with the deletion of the data.
13. Amendments to the Privacy Policy
This Notice may be updated over time to comply with new regulations or operational changes. Substantial changes will be notified via a notice on the site. Continued use of the service after publication of the changes constitutes acceptance thereof.
14. Regulatory References
- Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR)
- Legislative Decree of 30 June 2003, no. 196 — Privacy Code (as amended by Legislative Decree 101/2018)
- Legislative Decree of 6 September 2005, no. 206 — Italian Consumer Code (Art. 59 letter c; Art. 130)
- Provisions of the Italian Data Protection Authority (Garante)
- Decision (EU) 2021/914 — Standard Contractual Clauses (SCCs)
- Presidential Decree 633/1972 — VAT rules (retention obligations)