1. Introduction
This Privacy Policy explains how Duppy Sensi collects, uses, stores and protects personal data when users visit or place an order on www.duppysensi.com.

The website is dedicated to the presentation and sale of Cannabis sativa L. seeds strictly as botanical, taxonomic and collectible items. No flowers, extracts, resins, oils or other psychoactive derivatives are sold.

We process personal information in full compliance with Regulation (EU) 2016/679 (GDPR) and all applicable data-protection laws. By accessing this website, users acknowledge and accept the practices described in this Privacy Policy.


2. Data Controller
Duppy Sensi
Email: info@duppysensi.com
Website: www.duppysensi.com

As Data Controller, Duppy Sensi is responsible for deciding how and why personal data is processed.


3. Data We Collect
We collect only the data required for order management, customer communication and legal compliance.

3.1 Data provided directly by the user

  • First name and surname

  • Shipping and billing address

  • Email address

  • Phone number (optional)

  • Order details

  • Payment-related information (limited to what is necessary to identify the transaction)

3.2 Data collected automatically

  • IP address

  • Browser type and version

  • Device information

  • Website usage data (analytics, cookies – see Cookie Policy)


4. Payment Information
All payments are processed securely by external payment service providers.

We do not store or have access to full credit or debit card details on our servers.

Payment providers may include:

  • Card payment gateways

  • Bank transfer services

  • Other regulated online payment platforms

Each provider acts as an independent data controller (or joint controller) for the payment transaction and processes data in accordance with its own privacy policy.


5. Purpose of Data Processing
Personal data is processed exclusively for the following purposes:

  • To manage, confirm and fulfil customer orders

  • To process payments and verify transactions

  • To ship products and track delivery

  • To handle customer service and support requests

  • To comply with tax, accounting, regulatory or legal obligations

  • To prevent fraud, abuse and security incidents

  • To improve website security, performance and user experience

We do not use personal data for profiling, automated decision-making or marketing without the user’s explicit consent.


6. Legal Basis for Processing (GDPR Articles 6 & 7)
Data is processed based on:

  • Contractual necessity: to perform and manage the sales contract with the customer

  • Legal obligation: to comply with tax, accounting and consumer-protection requirements

  • Legitimate interest: to prevent fraud, ensure website security and improve our services

  • User consent: for non-essential cookies, analytics and any optional communications


7. Data Storage & Security
We implement appropriate technical and organisational measures to protect personal data, including:

  • Encrypted connections (HTTPS/SSL)

  • Secure hosting infrastructure

  • Access-restricted administrative areas

  • Regular monitoring and security updates

Personal data is stored only for as long as necessary to fulfil the purposes for which it was collected or to comply with applicable legal retention periods.


8. Data Sharing
Personal data may be shared only with:

  • Payment service providers (for transaction management)

  • Shipping and logistics partners (to deliver orders)

  • IT and hosting providers (website operation, security, analytics)

  • Professional advisers or authorities when required by law

We do not sell, rent or share personal data with third parties for advertising or purely commercial purposes.


9. User Rights (GDPR Articles 12–23)
Users have the right to:

  • Access their personal data

  • Rectify inaccurate or incomplete data

  • Request deletion of personal data (“right to be forgotten”), where applicable

  • Restrict or object to specific processing activities

  • Request data portability

  • Withdraw consent at any time (when processing is based on consent)

  • File a complaint with a Data Protection Authority (e.g. Garante per la Protezione dei Dati Personali in Italy)

To exercise these rights, users can contact: info@duppysensi.com.


10. Cookies & Tracking Technologies
This website uses cookies and similar technologies for:

  • Essential website functions

  • Performance and traffic analytics

  • User experience improvement

A detailed explanation is available in our Cookie Policy.
Users can manage or modify cookie preferences at any time via the cookie banner or browser settings.


11. International Data Transfers
If personal data is transferred outside the European Union or European Economic Area, such transfer takes place only:

  • Towards countries covered by an adequacy decision, or

  • Under Standard Contractual Clauses (SCC) or equivalent safeguards, and

  • With GDPR-compliant data-processing agreements in place.

We work exclusively with providers that guarantee an adequate level of data protection.


12. Protection of Minors
This website and its services are not intended for individuals under 18 years of age.

We do not knowingly collect personal data from minors. If we become aware that data relating to a minor has been collected, we will take reasonable steps to delete it without undue delay.


13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect regulatory changes or improvements in our data-management practices.

The updated version will always be published on this page and will include the date of the latest revision.


14. Contact Information
For questions, comments or requests regarding this Privacy Policy or the processing of personal data, users can contact:

📧 info@duppysensi.com