Privacy policy made pursuant to Art. 13 of EU Regulation 679/2016


Pursuant to and in accordance with Article 13 of the General Data Protection Regulation 2016/679, Harmonic Shapes srl, VAT number 12048710961. no. REA MI-2637049, paid-up share capital: 10,000 €, with registered office in Via Molino delle armi 11 ZIP code 20123 Milan, Italy, as Data Controller, provides its users with some information concerning the processing of their personal data.

The Data Controller can be contacted at any time to receive information concerning the processing of personal data at the email address:

The processing carried out by Harmonic Shapes srl will be based on the principles of lawfulness, fairness, transparency, purpose limitation and storage, data minimization, accuracy, integrity and confidentiality.

This information is provided only for this Site and not also for other websites that may be consulted by the user through links. Please refer to any specific sections of those sites where the user can find specific disclosures and any requests for consent for individual processing.


Websites, paper forms, cookies, social networks, wifi network services, surveys and market research conducted by automated and traditional means.


The personal data that the Data Controller processes are as follows:

  • those that the user voluntarily provides: these are all those personal data freely released by the visitor on the Website, for example, to request information about a specific product or service through the “contact” form, write to an e-mail address or when subscribing to our newsletter; those that the user communicates to us through third-party social channels;
  • those collected when browsing the site (for example: IP addresses, the type of browser used, the operating system, the domain name and addresses of websites from which access or exit was made, information about the pages visited by users within the site, access time, the length of time spent on the individual page, internal path analysis and other parameters related to the user’s operating system and computer environment)

The types of personal data that the Data Controller collects are:

  • identification and contact data (first name, last name, email address, phone no.) necessary to identify the user when using one of the services offered on the site (e.g. contact form or newsletter subscription);
  • historical data regarding the user’s contacts with Harmonic Shapes srl;


Personal data provided by the user may be processed for the following purposes:

A) enjoyment of the services offered on the website;

B) statistical purposes on anonymized data;

C) sending newsletters with the express consent of the user;

D) direct marketing: sending of commercial or promotional communications by Harmonic Shapes to promote products, services sold and/or provided by the Data Controller on the basis of a legitimate interest in pursuing its business purpose through automated (telephone without operator, sms, mms, email, fax) or traditional (telephone with operator, mail) contact methods;

E) indirect marketing: sending commercial or promotional communications relating to products or services of third parties with the express consent of the user mendiate automated or traditional contact mode;

F) fulfill obligations under applicable national and supranational regulations or legislation;

G) ascertain and exercise or defend the rights of the Owner in court.


The legal basis for the processing of personal data is the execution of a contract for the purposes under (A); for the purposes under (C)E) the optional and revocable consent at any time given by users who have reached the age of 16. The user’s consent is not necessary for the processing of data in anonymous form for the purposes referred to in subparagraph B). As for (F) the legal basis is the need to fulfill legal obligations and (D)G) legitimate interest.


The provision of personal data is optional.

However, the provision of data relating to the user’s generalities and contact details (first name, last name, telephone number, email address) is necessary in order to allow the Data Controller to provide the services offered on the site.

The Data Controller conducts statistical surveys and analysis with data in aggregate form to understand how users use the site, to improve the offer and services provided.

Also with the user’s consent, the aforementioned data will allow the Data Controller to send its newsletters, to send commercial or promotional communications regarding products or services, including those of third parties, by means of automated (telephone without operator, sms, mms, email, fax) or traditional (telephone with operator, mail) contact methods. In any case, the user may at any time object to the processing or limit it to specific contact methods by notifying the Data Controller at the email address:


Your Personal Data may be shared, for the above purposes, with:

  • persons authorized by Harmonic Shapes srl to process Personal Data necessary to perform activities strictly related to the provision of the Services, who have committed to confidentiality or have an appropriate legal obligation of confidentiality (e.g. employees and system administrators);
  • third parties who may be involved in the management of the Sites and who typically act as Data Processors. A complete list of Data Processors can be obtained by contacting the following email address:
  • subjects, entities or authorities to whom it is mandatory to communicate the user’s personal data under provisions of the law or orders of the authorities.

Processed personal data are also processed through the creation of a centralized database with computer and telematic tools. The database containing the personal data of users is accessible only by authorized and specifically appointed persons – such as employees or other collaborators – who may become aware of the data in the processing necessary for or related to the sending of advertising material or the fulfillment of an order; possibly third-party service providers strictly functional to the execution of the contractual relationship may also become aware of it. Each appointee is given specific directives for data processing, instructions that suppliers are required to comply with in order not to incur disciplinary sanctions and/or initiatives in court.


Some of your Personal Data is shared with recipients that may be located outside the European Economic Area. Harmonic Shapes srl ensures that the processing of your Personal Data by these Recipients is done in compliance with the Regulations. Indeed, transfers may be based on an adequacy decision, Standard Contractual Clauses approved by the European Commission, or another appropriate legal basis.


The Data Controller retains users’ personal data throughout the contractual period and, after termination, for as long as is strictly necessary and dependent on the purposes for which it was collected. Upon termination, personal data will be destroyed, deleted or anonymized consistent with the technical procedures for deletion and backup.

To stop receiving the newsletter, the user can click on the “Unsubscribe” button at the bottom of the email. In case of technical problems, you can send a report to: Personal data processed for the purpose of fulfilling legal obligations, will be retained by the Data Controller for the period required by specific legal obligations or applicable legislation.

Personal data processed for Marketing purposes, will be retained by Harmonic Shapes until the consent given by the user is revoked. Once consent is revoked, the use of the data for such purposes will cease, but Harmonic Shapes may retain it in order to protect its interests from possible liability based on such processing.

Personal data processed for the purpose of sending promotional offers to users will be retained by Harmonic Shapes until the user objects to the processing by writing to:

Personal data processed for the purpose of preventing abuse and/or fraud will be retained by the Data Controller for the time strictly necessary for the aforementioned purpose.

Personal data used to send newsletters, or will be kept until the user requests to stop sending them.


As provided for in Article 15 of the Regulations, the data subject may access his or her personal data, request that it be corrected and updated if incomplete or erroneous, request that it be erased if it was collected in violation of a law or regulation, and object to the Processing for legitimate and specific reasons.

In particular, we set out below all the rights that can be exercised, at any time, against the data controller and/or co-processors:

  • Right of access: the right, pursuant to Article 15(1) of the Regulation, to obtain from the data controller confirmation as to whether or not personal data are being processed and, if so, to obtain access to such personal data and to the following information: (a) the purposes of the processing; (b) the categories of personal data in question; (c) the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular if recipients in third countries or international organizations; (d) when possible, the period for which the personal data are to be retained or, if this is not possible, the criteria used to determine this period; (e) the existence of the data subject’s right to request from the controller the rectification or erasure of personal data or the restriction of the processing of personal data concerning him or her or to object to their processing (f) the right to lodge a complaint with a supervisory authority; (g) where the personal data are not collected from the data subject, all available information about their origin; (h) the existence of automated decision-making, including profiling as referred to in Article 22(1) and (4) of the Regulation and, at least in such cases, meaningful information about the logic used, as well as the importance and the envisaged consequences of such processing for the data subject. All this information can be found within the notice that will always be available within the Privacy section of each of the websites.
  • Right to rectification: right to obtain, pursuant to Article 16 of the Regulations, the rectification of personal data that are inaccurate, taking into account the purposes of processing, in addition, you can obtain the integration of personal data that are incomplete, including by providing a supplementary statement.
  • Right to erasure: right to obtain, pursuant to Article 17(1) of the Regulations, the erasure of personal data without undue delay and the data controller will be obliged to erase your personal data, if there is even one of the following reasons: (a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; (b) you have withdrawn the consent on which the processing of your personal data is based and there is no other legal basis for their Processing; c) you have objected to the processing in accordance with Article 21(1) or (2) of the Regulations and there is no longer any overriding legitimate ground for the processing of your personal data; d) your personal data have been processed unlawfully; e) it is necessary to delete your personal data in order to comply with a legal obligation under an EU or domestic law. In some cases, as provided for in Article 17(3) of the Regulations, the data controller is entitled not to provide for the erasure of your personal data if their processing is necessary, for example, for the exercise of the right to freedom of expression and information, to comply with a legal obligation, for reasons of public interest, for archiving purposes in the public interest, for scientific or historical research or statistical purposes, for the establishment, exercise or defense of a right in court.
  • Right to limitation of processing: right to obtain the limitation of processing, pursuant to Article 18 of the Regulation, in the event that one of the following occurs, the data subject: (a) has disputed the accuracy of his or her personal data (the restriction will last for the period necessary for the data controller to verify the accuracy of such personal data); (b) the processing is unlawful but he or she has objected to the erasure of his or her personal data, requesting, instead, that its use be restricted; c) although the data controller no longer needs them for the purposes of processing, the personal data are needed for the establishment, exercise or defense of a legal claim; d) he or she has objected to the processing pursuant to Article 21(1) of the Regulations and is awaiting verification as to whether the data controller’s legitimate grounds prevail over his or her own. If processing is restricted, personal data will be processed, except for storage, only with consent or for the establishment, exercise or defense of a right in court or to protect the rights of another natural or legal person or for reasons of substantial public interest.
  • Right to data portability: the right to request at any time and receive, in accordance with Article 20(1) of the Regulation, all personal data processed by the data controller and/or co-processors in a structured, commonly used and readable format or request its transmission to another data controller without hindrance. In this case, it will be the responsibility of the data subject to provide us with all the exact details of the new data controller to whom he/she intends to transfer his/her personal data by providing us with written authorization.
  • Right to object: in accordance with Article 21(2) of the Regulation and as also reiterated by Recital 70, you can object, at any time, to the Processing of your personal data if they are processed for direct marketing purposes, including profiling insofar as it is related to such direct marketing.
  • Right to lodge a complaint with the supervisory authority: without prejudice to the right to appeal in any other administrative or jurisdictional forum, if you believe that the processing of your personal data conducted by the data controller and/or co-processors occurs in violation of the Regulation and/or the applicable legislation, you can lodge a complaint with the competent Data Protection Authority (for Italy, Garante Privacy,

These rights may be exercised by the user at any time by writing to the Data Controller Harmonic Shapes srl with registered office in Via Molino delle armi 11 ZIP code 20123 Milan, Italy; by e-mail by writing to: or by pec to:


Personal data will be processed by automated tools for the time strictly necessary to achieve the purposes for which they were collected and in accordance with the principle of necessity and proportionality, avoiding the processing of personal data if the operations can be achieved through the use of anonymous data or by other means.

The Data Controller has adopted specific security measures to prevent the loss of personal data, illicit or incorrect use and unauthorized access.


Harmonic Shapes srl. uses social media for the purpose of communicating content related to its products and services.

This site may contain links or references to access other sites, such as Instagram social networks. Clicking on the appropriate links will allow the user to share Harmonic Shapes content.

Harmonic Shapes srl does not control the cookies or other tracking technologies of such websites to which this policy does not apply.

Please note that this policy is not provided for other websites that may be consulted by the user through links on, which are to be considered autonomous Data Controllers and must refer to their own Privacy Policy.


The Owner periodically checks its privacy and security policy and, if necessary, revises it in relation to regulatory, organizational or technological changes. If the policy changes, the new version will be posted on this page of the site.

Harmonic Shapes srl uses technical and profiling cookies in order to collect and access information stored on your device. For more information please see the extended cookie usage policy available on our site.

Last revision of this privacy policy as of 11/15/2021