Privacy Policy

1. Data Controller
The Data Controller is Tezenis. For any requests regarding the processing of your personal data, you can contact the Data Controller.

2. Personal Data Processed
We process the following categories of personal data.

A. Browsing Data
The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the user’s IT environment. These data are used for the sole purpose of obtaining anonymous statistical information on the use of the site and to check its correct functioning and are deleted immediately after processing. The data could be used to ascertain responsibility in case of hypothetical computer crimes against the site.

B. Data Provided Voluntarily by the User
The optional, explicit, and voluntary sending of electronic mail to the addresses indicated on this site entails the subsequent acquisition of the sender’s address, necessary to respond to requests, as well as any other personal data included in the message. We collect and process the personal data you provide when you register on our e-commerce platform tezenisusa.com, make a purchase, or interact with our services. This data includes, for example, your identification details, contact information, and payment details necessary for contract execution.

C. Cookies
For detailed information on the cookies used by this website, please refer to the specific Cookie Policy available at tezenisusa.com.

3. Purpose and Legal Basis of the Processing
Your personal data will be processed for the following purposes:

  • Contractual Obligations (Legal Basis: Article 6(1)(b) GDPR): To execute the purchase contract for the products you order, including activities related to order management, payment processing, shipping, handling of returns, and providing customer support services.
  • Legal Obligations (Legal Basis: Article 6(1)(c) GDPR): To fulfill obligations required by law, regulations, or community legislation (e.g., for accounting purposes or upon request from judicial authorities).
  • Legitimate Interest (Legal Basis: Article 6(1)(f) GDPR): To prevent and prosecute fraudulent activities; to enable the Data Controller to defend itself in court; to carry out activities related to corporate transactions; to improve our products and services and the functionality of our website.
  • With Your Consent (Legal Basis: Article 6(1)(a) GDPR): For marketing activities, such as sending you—via email, SMS, MMS, social media, and push notifications—promotional communications and material regarding products, services, and initiatives of the Data Controller to update you on special offers and new products. This consent is optional and can be withdrawn at any time by contacting the Data Controller or by using the unsubscribe link present in every commercial communication.

4. Nature of Data Provision
Providing your personal data for the purposes referred to in section 3 (Contractual and Legal Obligations) is mandatory. Any refusal to provide such data will make it impossible for us to execute the purchase contract and fulfill your requests. The provision of data for marketing purposes is entirely optional. Failure to provide consent for marketing activities will not affect your ability to make purchases but will mean you do not receive promotional communications.

5. Data Processing Methods
Your personal data will be processed both electronically and on paper. The Data Controller will process the personal data for the time necessary to fulfill the purposes for which they were collected and in compliance with the principles of lawfulness, purpose limitation, and data minimization as required by the GDPR.

6. Data Access and Disclosure
Your data may be made accessible for the purposes outlined in Article 3:

  • To employees and collaborators of the Data Controller, in their capacity as persons authorized to process data.
  • To third-party companies or other subjects (e.g., logistics partners, payment service providers, IT service providers, consultants) that perform outsourced activities on behalf of the Data Controller, in their capacity as data processors.

Your data may also be disclosed to subjects entitled to access it by virtue of legal provisions. Your data will not be otherwise disseminated.

7. Data Transfer
The management and storage of personal data will take place on servers located within the European Union. The data will not be transferred outside the European Union. In any case, it is understood that the Data Controller, if necessary, will have the right to move the servers’ location. In such a case, the Data Controller ensures that the transfer of data outside the EU will occur in accordance with the applicable legal provisions, subject to stipulating the standard contractual clauses provided by the European Commission.

8. Rights of the Data Subject
As a data subject, you have the right to exercise the rights granted by the GDPR at any time. These include:

  • The right to access your personal data, obtaining evidence of the purposes pursued by the Data Controller, the categories of data involved, the recipients to whom they may be disclosed, the applicable retention period, and the existence of automated decision-making.
  • The right to obtain the rectification of inaccurate personal data concerning you without undue delay.
  • The right to obtain the erasure of your personal data in the cases provided for by the GDPR.
  • The right to obtain the restriction of processing in the cases provided for by the GDPR.
  • The right to data portability, i.e., to receive the personal data concerning you in a structured, commonly used, and machine-readable format, and to transmit those data to another controller.
  • The right to object at any time to the processing of your personal data carried out for the pursuit of a legitimate interest of the Data Controller.
  • The right to withdraw your consent at any time for processing based on consent, without affecting the lawfulness of processing based on consent before its withdrawal.

To exercise your rights, you can contact the Data Controller using the methods indicated in Section 1. You also have the right to lodge a complaint with the competent supervisory authority.

9. Changes to the Privacy Policy
The Data Controller reserves the right to make changes to this Privacy Policy. In this case, users will be promptly informed upon connecting to the website.