Dolcefy S.R.L.S. Privacy Policy
Last updated 7.6.2026
This Privacy Policy explains how Dolcefy S.R.L.S. ("we", "us", "our") collects, uses, and protects personal data through our websites (for example dolcefy.com and dolcefy.eu), the Dolcefy platform, and our services. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR).
1. Controller
Dolcefy S.R.L.S. Via di Luiano 26, 50026 San Casciano in Val di Pesa (FI), Italy VAT number: IT07543460484 Email: ciao@dolcefy.com
2. Our Role and Scope
This Privacy Policy describes the processing for which Dolcefy S.R.L.S. is the data controller, namely personal data relating to our website visitors, account holders, and customers.
When you use the Dolcefy platform to process personal data about your own contacts, customers, students, or audience, you act as the data controller and we act as the data processor on your behalf. That processing is governed by our Data Processing Agreement (DPA), which forms part of our Terms and Conditions, and is not the subject of this Privacy Policy.
3. Legal Basis for Processing
We process personal data on the following legal grounds:
- your explicit and informed consent, for example for marketing communications or downloadable resources;
- the performance of a contract, for fulfilling orders and delivering services;
- our legitimate interests, for maintaining customer relationships, improving our services, and ensuring the security of our platform;
- compliance with legal obligations, such as accounting and tax reporting.
We do not use your data for automated decision-making that produces legal or similarly significant effects on you.
4. Purposes of Processing
Personal data is collected and processed to:
- deliver digital products, memberships, and services;
- manage customer accounts and orders;
- provide support and service-related updates;
- send marketing communications where you have consented;
- ensure platform functionality and security;
- comply with legal obligations, such as tax and payment records.
5. Data We Collect
We may collect:
- name, email address, telephone number, and business name;
- billing and payment information;
- IP address and browser or device data;
- social media profiles, if you provide them;
- order and subscription history;
- responses to forms, quizzes, and surveys;
- files or materials you voluntarily submit;
- tax identification information (VAT number, tax code, electronic invoicing address) for business customers.
We collect only the personal data necessary for the purposes described in Section 4.
6. Cookies and Analytics
We use strictly necessary cookies that are required for the website and platform to function. These do not require consent.
For analytics, we use a privacy-respecting analytics tool that we host ourselves on our own European infrastructure. We run a cookieless configuration: it does not set analytics cookies, does not store your full IP address, and does not track you across sites or sessions. Because it does not store information on your device and does not process personal data in an identifying way, it does not require your consent. Your analytics data stays on our European servers and is not shared with any third party.
You can manage cookies through your browser settings.
7. Artificial Intelligence Features (Dolce Intelligence)
Where you use our AI assistant features, the input you provide is processed by a provider located and hosted in the European Union. We access AI directly through its European API and not through any non-EU cloud provider. Our AI does not use this input or the resulting output to train its models. Your data is not transferred to the United States for these features. Our AI acts as our sub-processor under a data processing agreement and is listed in our sub-processor list.
8. Third-Party Service Providers and Sub-processors
We use trusted third-party service providers to help us operate our websites, process payments, and deliver our services. These providers may process personal data on our behalf and are contractually bound to comply with applicable data protection law, including the GDPR. The current list of our sub-processors and their locations is maintained in or alongside our DPA, and all of them are located within the EU or EEA.
9. Data Storage and Retention
We retain personal data for as long as necessary to fulfil contractual and legal obligations, provide customer service, and meet accounting and tax requirements. Order and transaction data is retained for at least 10 years as required under Italian tax law. Inactive contacts are reviewed periodically and deleted when no longer needed.
10. Data Transfers
We process personal data within the European Union and the European Economic Area. We do not transfer personal data to, or process it in, countries outside the EU or EEA, including the United States. This applies regardless of where you are located: if you use Dolcefy from outside the EU, your data is still stored and processed on our European infrastructure.
One point is inherent to card and wallet payments. Our payment provider is European, but if you choose to pay using an international card scheme or a mobile wallet, for example a Visa or Mastercard card or Apple Pay or Google Pay, the data needed to complete that payment is processed by that scheme or wallet provider as an independent controller, and some of these providers are established outside the EEA. This processing is limited to completing the payment you have chosen to make.
11. Your Rights Under the GDPR
You have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion, the right to be forgotten;
- restrict or object to processing;
- data portability;
- withdraw consent at any time, for example for marketing or optional services;
- lodge a complaint with a supervisory authority. In Italy, this is the Garante per la protezione dei dati personali.
To exercise these rights, contact us at ciao@dolcefy.com.
12. Data Security
We take appropriate technical and organisational measures to protect your data, including hosting on European infrastructure, encryption of data in transit, access restricted to authorised personnel, strong authentication, regular backups, and timely software updates. A fuller description of the measures relevant to platform data is set out in our DPA.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version is always available on our website, and we will notify you of any significant changes by email or platform notice.
14. Contact
If you have any questions or requests regarding your personal data, please contact:
Dolcefy S.R.L.S.
Via di Luiano 26, 50026 San Casciano in Val di Pesa (FI), Italy
ciao@dolcefy.com
© 2026 Dolcefy S.R.L.S. All rights reserved.