Privacy policy
Last updated: 16 September 2026
This policy explains how Masterpiece Srl handles personal data collected through www.provena.it, including the buyer access form. Provena is the commercial brand of Masterpiece Srl.
Data controller
Masterpiece Srl, Via Giovanni Bovio 398, 76011 Bisceglie (BT), Italy — VAT no. IT08978180720.
For any privacy request, write to [email protected].
What we collect
Buyer access form: full name, company or legal name, type of business, country or target market, professional email, VAT number or business registration and — if you add them — website, volumes or categories of interest and a message.
Emails you send us: whatever you choose to include.
Technical data: to deliver the site and protect it from abuse, our hosting and network providers process data such as your IP address and browser type. The form also uses your IP address to limit repeated submissions; it is held only in the server's memory and never written to storage.
Why we use it, and on what legal basis
- To review your application and, if it is approved, open and manage your trade account — steps taken at your request before and under a contract (Art. 6(1)(b) GDPR).
- To answer your enquiries — the same basis, or our legitimate interest in replying to business contacts (Art. 6(1)(f)).
- To keep the site secure and prevent abuse — our legitimate interest (Art. 6(1)(f)).
- To meet tax and accounting obligations once you become a customer (Art. 6(1)(c)).
Required fields are needed to review your application: without them we cannot process it. We do not use your data for automated decisions or profiling, and we do not sell it.
Who handles it
Masterpiece Srl staff, and providers acting on our instructions:
- Shopify — wholesale store platform: your application is saved as a customer record in our store.
- Railway — hosting of www.provena.it.
- Cloudflare — content delivery and security.
- Aruba — email.
We may also share data with professional advisers, such as our accountant, and with public authorities when the law requires it.
Transfers outside the EU
Some of these providers may process data outside the European Economic Area, including in the United States and Canada. These transfers rely on European Commission adequacy decisions (including the EU-U.S. Data Privacy Framework, for certified providers) or on the Commission's Standard Contractual Clauses.
How long we keep it
Applications that do not lead to a trade account are deleted within 12 months. Customer data is kept for as long as the trade relationship lasts; accounting records are kept for the 10 years required by Italian law.
Your rights
You can ask to access, correct or delete your data, to restrict or object to its processing, and to receive it in a portable format (Articles 15–22 GDPR). Write to [email protected].
You can also lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the authority in your country of residence.
Cookies
See our Cookie policy.
Changes
We will publish any update on this page, together with the date it takes effect.