DEMETRIA

Privacy Policy

Last updated: 02/25/2026

This Privacy Policy describes how Demetria (hereinafter, the "Site") collects, uses, and protects the personal data of users.

Pursuant to EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, the Data Controller is committed to protecting users' privacy and processing personal data in a lawful, fair, and transparent manner.

1. Data Controller

The Data Controller is:
Demetria
Email: info@demetria.co
Phone: +39 334 336 3924

2. Types of Data Collected

2.1 Data provided voluntarily by the user

The Site collects the following personal data when voluntarily provided by users:

  • Newsletter: email address for sending commercial communications, product updates, and special offers.
  • "Get In Touch" contact form: name, email address, message, and product of interest to respond to information requests.

2.2 Navigation data

The computer systems and software procedures used to operate the Site acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified parties, but by its very nature could, through processing and association with data held by third parties, allow users to be identified.

This category includes:

  • IP addresses or domain names of computers used by users
  • URI (Uniform Resource Identifier) addresses of requested resources
  • Time of the request
  • Method used to submit the request to the server
  • Size of the file obtained in response
  • Numerical code indicating the status of the response given by the server
  • Other parameters relating to the user's operating system and computing environment

This data is used solely to obtain anonymous statistical information on Site usage and to monitor its proper functioning. The data could be used to ascertain liability in the event of hypothetical computer crimes against the Site.

3. Purpose and Legal Basis of Processing

3.1 Newsletter

Purpose: Sending commercial communications, product news, special offers, and updates about Demetria products.

Legal basis: Explicit consent of the data subject (Art. 6, par. 1, lett. a) GDPR).

Consent can be withdrawn at any time using the unsubscribe link in every email or by writing to info@demetria.co.

3.2 Contact form

Purpose: Responding to information requests, assistance, and support regarding products and services offered.

Legal basis: Performance of pre-contractual measures taken at the request of the data subject (Art. 6, par. 1, lett. b) GDPR) and legitimate interest of the Controller to provide assistance to its customers (Art. 6, par. 1, lett. f) GDPR).

3.3 Navigation data

Purpose: Ensuring the proper functioning of the Site, preventing abuse and fraud, compiling anonymous statistics on Site usage.

Legal basis: Legitimate interest of the Controller in the security and proper functioning of the Site (Art. 6, par. 1, lett. f) GDPR).

4. Third-Party Services

The Site uses the following third-party services that may collect personal data:

4.1 Sanity CMS

Content management service used to store and distribute Site content (products, images, descriptions).

Provider: Sanity.io
Privacy Policy: https://www.sanity.io/legal/privacy

4.2 Mux Video

Video streaming service used for playing video content on the Site.

Provider: Mux, Inc.
Privacy Policy: https://www.mux.com/privacy

4.3 Adobe Fonts (Typekit)

Service used for custom fonts on the Site. Adobe may collect font usage data (IP address, browser type).

Provider: Adobe Inc.
Privacy Policy: https://www.adobe.com/privacy.html

5. Processing Methods

Personal data is processed using automated tools for the time strictly necessary to achieve the purposes for which it was collected.

The Controller adopts specific technical and organizational security measures to prevent data loss, illicit or incorrect use, and unauthorized access, in compliance with GDPR provisions.

6. Data Communication and Disclosure

Personal data may be communicated to:

  • Technical service providers: companies providing hosting, maintenance, database management, and IT infrastructure services.
  • Communication service providers: companies managing email and newsletter sending (when implemented).
  • Competent authorities: in case of legitimate requests from judicial or public security authorities.

Personal data will not in any way be subject to disclosure (understood as communication to unspecified subjects).

7. Data Transfer Abroad

Some of the third-party services used (Sanity, Mux, Adobe) may transfer personal data outside the European Economic Area (EEA). In these cases, the Controller ensures that the transfer occurs in compliance with GDPR through the adoption of standard contractual clauses approved by the European Commission or other appropriate transfer mechanisms.

8. Data Retention Period

Personal data will be retained for the period necessary to achieve the purposes for which it was collected:

  • Newsletter: until consent is withdrawn by the user or for a maximum of 24 months from the last interaction (email opening, click).
  • Contact requests: for the time necessary to fulfill the request and for any retention obligations required by law (up to 10 years for tax and accounting purposes).
  • Navigation data: for a maximum period of 7 days, except in case of need to ascertain computer crimes.

9. Data Subject Rights

Pursuant to Articles 15-22 of the GDPR, the data subject has the right to:

  • Access: obtain confirmation of the existence or not of personal data concerning them and, if so, obtain a copy.
  • Rectification: obtain the rectification of inaccurate personal data or the integration of incomplete data.
  • Erasure: obtain the erasure of personal data ("right to be forgotten") in the cases provided for by Art. 17 GDPR.
  • Restriction: obtain the restriction of processing in the cases provided for by Art. 18 GDPR.
  • Portability: receive personal data in a structured, commonly used, and machine-readable format, and transmit it to another controller.
  • Objection: object at any time to the processing of personal data for reasons related to their particular situation.
  • Withdrawal of consent: withdraw consent at any time without prejudice to the lawfulness of processing based on consent given before withdrawal.
  • Complaint: lodge a complaint with the Supervisory Authority for the Protection of Personal Data.

To exercise their rights, the data subject can contact the Data Controller at: info@demetria.co

10. Complaint to the Supervisory Authority

Without prejudice to any other administrative or judicial remedy, any data subject who believes that the processing concerning them violates the GDPR has the right to lodge a complaint with the Italian Data Protection Authority:

Garante per la Protezione dei Dati Personali
Piazza Venezia, 11 - 00187 Rome, Italy
Phone: +39 06 696771
Fax: +39 06 69677785
Email: garante@gpdp.it
PEC: protocollo@pec.gpdp.it
Website: www.garanteprivacy.it

11. Changes to the Privacy Policy

The Controller reserves the right to modify this Privacy Policy at any time. In case of substantial changes, users will be informed through a notice on the Site or via email. It is recommended to periodically consult this page to check for any updates.

12. Contact

For any questions or requests regarding this Privacy Policy or the processing of personal data, please contact:

Demetria
Email: info@demetria.co
Phone: +39 334 336 3924

This site uses cookies

We only use strictly necessary technical cookies for the site's functionality (sessions, language preferences, fonts). We do not use profiling or marketing cookies. Currently, the site does not track or analyze user behavior.