
Privacy Policy
Last updated: July 28, 2026
1. Data Controller
Cosmetic Solutions S.r.l.
Via Niccolò Tommaseo 11 59100 Prato (PO) – Italy
-
VAT No.: 02636630978
-
Certified Email (PEC): cosmeticsolutions@pec.it
-
Website: www.cosmetic-solutions.it
-
Telephone: +39 338 3446012
The Data Controller guarantees that the processing of personal data is carried out in compliance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR).
Considering the size of the organization, no Data Protection Officer (DPO) has been appointed.
2. Categories of Personal Data Collected
2.1 Data voluntarily provided by the data subject
-
First name and last name
-
Company information (company name, VAT number, registered address)
-
Contact details (email, telephone number, certified email/PEC)
-
Technical data relating to cosmetic consultancy (PIF, formulations, documentation, R&D, GMP, etc.)
-
Contractual and invoicing documentation
2.2 Data collected automatically
-
Technical cookies
-
Analytics cookies (where anonymised)
-
System logs and IP addresses
-
Website browsing and interaction data
2.3 Special categories of personal data
These are not processed unless required for the establishment, exercise or defence of legal claims.
3. Purposes and Legal Basis for Processing
Personal data are processed for the following purposes:
-
Provision of consultancy services in the cosmetic, chemical and pharmaceutical sectors, including compliance with applicable regulatory obligations, such as:
-
general regulatory assessments;
-
declarations, registrations or other regulatory compliance activities;
-
preparation of self-certification templates for communications with customers and/or Supervisory Authorities;
-
preparation of applications and documentation for registrations, amendments and deregistrations to be submitted to competent territorial authorities and supervisory bodies;
-
preparation of applications and documentation for the issue or renewal of authorisations and licences granted by any competent authority or public body;
-
preparation of payment forms relating to taxes, subscriptions and registrations;
-
business, technical-scientific and regulatory consultancy in general.
-
-
Management of specific requests and communications received via email, certified email (PEC), telephone and website forms.
-
Contractual, administrative and accounting management.
-
Compliance with legal obligations (including invoicing, EU legislation and product safety requirements).
-
Sending technical and regulatory updates relating to the cosmetic and chemical sectors, as well as technical and operational communications concerning the services provided.
-
Protection of legal rights and management of disputes.
-
Technical operation of the website and IT security.
-
Direct marketing activities, carried out exclusively upon the data subject's explicit consent.
The main legal bases for processing are:
-
Article 6(1)(b) GDPR: performance of a contract or implementation of pre-contractual measures.
-
Article 6(1)(c) GDPR: compliance with a legal obligation.
-
Article 6(1)(f) GDPR: legitimate interests pursued by the Data Controller.
-
Article 6(1)(a) GDPR: consent for newsletters, marketing activities and non-essential cookies.
4. Nature of the Personal Data
For the purposes of the processing described above, the Data Controller may become aware of personal data falling within the special categories referred to in Regulation (EU) 2016/679, including data revealing racial or ethnic origin, religious or philosophical beliefs, or membership of religious or philosophical organisations.
The processing may therefore concern personal data, special categories of personal data and data relating to criminal convictions and offences where strictly necessary for the provision of the requested services.
During the performance of the services, it may be necessary to collect and process special categories of personal data and data relating to criminal convictions and offences. Where applicable, the necessary legal basis for such processing shall be ensured in accordance with the GDPR. Where consent is required by law, such consent shall be deemed to have been provided following the communication of the relevant processing results.
5. Source of Personal Data
Personal data may originate from:
-
copies of identity documents required for customer identification;
-
copies of company registration certificates;
-
copies of articles of incorporation and amendments thereto;
-
invoices and incoming and outgoing correspondence containing tax and statutory information required by law for the identification of parties involved in legal or commercial relationships;
-
copies of documents and authorisations generally required for communications with public authorities;
-
banking and/or postal information together with related documentation, including cheques, bank payment and collection receipts, bills of exchange and other negotiable instruments or documentation relating to relationships with credit institutions;
-
insurance policies covering corporate and personal liability risks;
-
mandatory tax returns from which personal identification and family-related information may also be derived;
-
receipts relating to regulatory compliance obligations;
-
copies of property deeds and mortgage documentation relating to real estate;
-
copies of articles of incorporation and amendments thereto;
-
any other documentation or communication useful and/or necessary for the performance of consultancy services.
6. Methods of Processing
For the purposes described above, personal data are processed by means of:
-
digital and paper-based tools;
-
technical security measures (encryption, firewalls, European cloud infrastructure, backups);
-
restricted access granted exclusively to authorised personnel;
-
internal policies and access logging systems.
Personal data are processed:
-
by the Data Controller and/or authorised persons acting under the Controller's authority;
-
through one or more of the following operations: collection, recording, organisation, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, restriction, communication, erasure and dissemination of data;
-
through manual and automated procedures, solely to the extent necessary for the purposes described above.
7. Disclosure and Communication of Personal Data
Personal data may be disclosed to:
-
public authorities and entities entitled to access the data under applicable laws or regulations;
-
external collaborators bound by non-disclosure agreements (NDAs) and employees, within the scope of their respective duties;
-
notified bodies and laboratories where such disclosure is necessary or functional to the provision of our services, for example to carry out safety testing;
-
cloud service providers established within the European Union;
-
tax advisors and legal consultants;
-
recipients where disclosure is required by law.
Personal data are never sold or transferred to third parties for commercial purposes.
Unless expressly refused by the data subject, the company name/logo and/or commercial trademarks may be displayed on the homepage of the website in order to highlight and promote collaborations with recognised institutions and brands within the industry.
8. Storage Methods and Retention Period of Personal Data
All documents are stored in secure cloud environments and are regularly backed up. Documents are accessed solely for purposes related to the consultancy services provided and copies are made available to the customer upon request.
Personal data are retained for the following periods:
-
Contractual and administrative data: 10 years.
-
Cosmetic technical documentation (PIF, audits, GMP): for the duration of the contractual relationship plus 5 years. Product Information Files (PIFs) are retained for 10 years after the product has ceased to be placed on the market.
-
Marketing and newsletter data: until consent is withdrawn.
-
Website technical logs: from 30 to 180 days.
-
Cookies: according to the technical retention period specified in the relevant section.
Upon expiry of the applicable retention period, personal data may be erased upon explicit request. Copies of all documentation shall first be provided to the customer before permanent deletion.
Contractual documentation and, in exceptional cases, certain documents relating to consultancy activities are also retained in paper format at the company's registered office. Such documentation is retained for the periods required by law and is subsequently destroyed by specialised service providers or returned in its original form upon explicit request.
9. Transfer of Personal Data to Third Countries
Personal data are not transferred to countries outside the European Union or to international organisations unless expressly requested.
Where transfers are necessary, for example in connection with the use of cloud services, they shall take place exclusively by means of:
-
transfers to countries benefiting from an adequacy decision adopted by the European Commission;
-
Standard Contractual Clauses (SCCs);
-
additional technical and organisational safeguards.
10. Rights of the Data Subject
Data subjects may exercise all rights provided for by Regulation (EU) 2016/679 (GDPR).
10.1 Right of Access and Right to Rectification – Articles 15 and 16 GDPR
The data subject has the right to obtain confirmation from the Data Controller as to whether or not personal data concerning them are being processed and, where that is the case, access to the personal data and the following information:
-
the purposes of the processing;
-
the categories of personal data concerned;
-
the recipients or categories of recipients to whom the personal data have been or will be disclosed, particularly recipients in third countries or international organisations;
-
the envisaged period for which the personal data will be stored or, where that is not possible, the criteria used to determine that period;
-
the existence of the right to request from the Data Controller the rectification or erasure of personal data, restriction of processing concerning the data subject or to object to such processing;
-
the right to lodge a complaint with a supervisory authority;
-
the existence of automated decision-making, including profiling, and, at least in such cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
10.2 Right to Erasure ("Right to be Forgotten") – Article 17 GDPR
The data subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay. The Data Controller shall erase personal data without undue delay where one of the following grounds applies:
-
the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
-
the data subject withdraws the consent on which the processing is based pursuant to Article 6(1)(a) or Article 9(2)(a) GDPR, and there is no other legal ground for the processing;
-
the data subject objects to the processing pursuant to Article 21(1) GDPR and there are no overriding legitimate grounds for the processing, or the data subject objects pursuant to Article 21(2) GDPR;
-
the personal data have been processed unlawfully;
-
the personal data must be erased in order to comply with a legal obligation under Union or Member State law applicable to the Data Controller;
-
the personal data were collected in relation to the offer of information society services referred to in Article 8(1) GDPR.
10.3 Right to Restriction of Processing – Article 18 GDPR
The data subject has the right to obtain restriction of processing from the Data Controller where one of the following applies:
-
the accuracy of the personal data is contested by the data subject, for a period enabling the Data Controller to verify the accuracy of the data;
-
the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
-
although the Data Controller no longer needs the personal data for the purposes of the processing, they are required by the data subject for the establishment, exercise or defence of legal claims;
-
the data subject has objected to processing pursuant to Article 21(1) GDPR, pending verification whether the legitimate grounds of the Data Controller override those of the data subject.
10.4 Right to Data Portability – Article 20 GDPR
The data subject has the right to receive the personal data concerning them, which they have provided to a Data Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another Data Controller without hindrance from the original Data Controller.
10.5 Right to Object – Article 21 GDPR
The data subject has the right to object, at any time, to the processing of their personal data. This right may be exercised for reasons relating to the data subject's particular situation or, without providing any justification, in relation to direct marketing activities, including advertising and market research.
10.6 Withdrawal of Consent
The data subject may withdraw consent to the processing of their personal data by sending a registered letter with acknowledgement of receipt to:
Cosmetic Solutions S.r.l. Via Niccolò Tommaseo 11 59100 Prato – Italy
Alternatively, a certified email (PEC) may be sent to: cosmeticsolutions@pec.it.
The request must include a copy of a valid identity document and contain the following statement:
Withdrawal of my consent to the processing of all my personal data.
Upon completion of the procedure, personal data will be removed from the archives within 60 days, without prejudice to any data whose retention is required by applicable law.
For further information regarding the processing of personal data or to exercise any of the rights described in this section, a registered letter with acknowledgement of receipt may be sent to the address indicated above, a certified email (PEC) to cosmeticsolutions@pec.it, or an email to info@consulting-in-cosmetics.com.
Before providing or amending any information, it may be necessary to verify the identity of the requesting party and ask additional questions for identification purposes. A response will be provided within 10 days.
11. Data Security
In order to ensure the security of the personal data processed, the Data Controller adopts the following measures:
-
data encryption;
-
two-factor authentication;
-
secure backups;
-
access control systems;
-
confidentiality policies;
-
internal GDPR training.
12. Cookie Policy
12.1 Necessary Technical Cookies
These cookies are used to ensure the proper functioning of the website, save user preferences and enable internal navigation.
-
Retention period: from the current session up to 12 months.
-
Consent: not required.
12.2 Analytics Cookies
These cookies are used for:
-
Google Analytics with anonymised IP addresses;
-
collection of aggregated website traffic statistics.
-
Retention period: from 1 to 24 months.
-
Consent: required through the cookie banner where the cookies are not anonymised.
12.3 Optional Profiling Cookies
These cookies are disabled by default.
They require the user's explicit consent before being activated.
13. Cookie Management – Banner and Preferences
Users may:
-
accept or reject individual categories of cookies;
-
modify their preferences through the "Manage Cookies" link;
-
delete cookies directly from their browser.
14. Competent Supervisory Authority
The data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) if they believe that the processing of their personal data infringes the GDPR or the applicable Italian data protection legislation.
Complaints may be submitted in writing by registered mail, certified email (PEC), hand delivery or through the online forms available on the Authority's official website.
Italian Data Protection Authority (Garante per la Protezione dei Dati Personali)
15. Amendments to this Privacy Policy
The Data Controller reserves the right to amend or update this Privacy Policy at any time.
Any amendments will be published on the website and shall become effective upon publication.
16. Privacy Contacts
Data Controller: Cosmetic Solutions S.r.l.
Email: info@consulting-in-cosmetics.com
Certified Email (PEC): cosmeticsolutions@pec.it