← Back to site

Privacy Policy

Last updated: 24 August 2026

1. Data controller

MRTC LAB — Martucci Consulting, sole trader Armando Martucci, VAT / P.IVA IT03919610786, Italy.
Email info@mrtclab.it · PEC martucciconsulting@pec.it · +39 351 175 1846.

We have not appointed a Data Protection Officer, as we are not required to.

2. What we collect and why

DataWhyLegal basis
Email addressTo send your order confirmation, the tracking link and delivery updates, and to answer your messagesPerformance of a contract (art. 6(1)(b) GDPR)
Username or post linkTo deliver the service to the profile or post you chosePerformance of a contract
Order details (service, quantity, amount, status)To process, deliver and track your orderPerformance of a contract
Payment dataTo take payment. Card and wallet details are handled directly by our payment providers — we never receive or store them; we only see whether a payment succeededPerformance of a contract
Invoicing and accounting recordsTo meet Italian tax and accounting obligationsLegal obligation (art. 6(1)(c) GDPR)
Technical logs (IP address, browser, timestamps), country of connectionSecurity, fraud prevention, and to show the correct product options and pricingLegitimate interest (art. 6(1)(f) GDPR)

We do not ask for, and never receive, your social media password or login credentials. We do not knowingly collect data from anyone under 18.

3. Who we share it with

We share the minimum necessary with the providers that make the service work. Each acts as a data processor on our instructions, or as an independent controller where indicated.

ProviderPurposeWhere
SupabaseDatabase hosting for ordersEU (Frankfurt)
NetlifyWebsite and application hostingEU / USA
Payment providersProcessing your payment (independent controllers for the payment itself)EU / international
Delivery network providersThey receive only the public username or post link and the quantity — never your email or payment dataInternational
Email providerSending transactional emailsEU / USA
Our accountantStatutory accounting and tax filingsItaly

Where a provider is outside the European Economic Area, transfers are made under the European Commission's Standard Contractual Clauses or an adequacy decision. We do not sell your data, and we do not share it for advertising.

4. How long we keep it

5. Your rights

Under the GDPR you may ask us to give you access to your data, correct it, delete it, restrict how we use it, or provide it in a portable format. You may also object to processing based on our legitimate interest. Where processing is based on consent, you can withdraw it at any time without affecting what we did beforehand.

Write to info@mrtclab.it from the address you used to order. We reply within 30 days. Some data must be kept regardless of a deletion request, because tax law requires it.

If you think we have handled your data incorrectly, you can complain to the Italian supervisory authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or to the authority in your country of residence.

6. Automated decisions

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects for you. Orders are processed automatically, but that is the execution of your instruction, not a decision about you.

7. Security

Data is transmitted over encrypted connections and stored on access-controlled infrastructure. Access is limited to what is needed to run the service. No system is perfectly secure; if a breach ever affects your rights, we will notify the supervisory authority and, where required, you, within the deadlines set by the GDPR.

8. Changes

If we change this policy we update the date at the top. Substantial changes affecting how we use your data will be notified by email where we have one.