Privacy policy
3DR-I store
Privacy policy
Version: 16 September 2026 · pursuant to Art. 13 of Regulation (EU) 2016/679 (GDPR)
This policy explains how DR-I S.r.l. Innovative Startup processes personal data collected through the website dr-i.tech, where the 3DR-I store operates, when you browse the Site, place an order, contact us or subscribe to our communications. Cookies and similar technologies are described in the separate Cookie policy.
1. Controller
DR-I S.r.l. Innovative Startup, VAT and tax code IT04678810617, registered office Via E. Ruggiero 123, 81100 Caserta (CE), Italy. Privacy contact: privacy@dr-i.tech. PEC: certificate@pec.dr-i.tech. No Data Protection Officer has been appointed, as the conditions of Art. 37 GDPR are not met.
2. Personal data we process
- Account and order data: first and last name, email address, password (stored encrypted by our e-commerce platform), billing and shipping address, telephone number where provided, VAT number and SDI code for business invoices, order history.
- Payment data: the transaction record (date, amount, items, transaction identifier, payment method). Card numbers and security codes are handled by the payment provider and never reach our systems.
- Communications: the content of emails, contact form messages and support requests, including any files, drawings or specifications you send for a custom order.
- Browsing data: data transmitted automatically by your browser, such as IP address, date and time of the request, pages viewed, referring page, device and browser characteristics, approximate location derived from the IP address.
- Marketing data: subscription status, and whether our emails were opened or clicked, where the sending platform records it.
We do not deliberately collect special categories of data (Art. 9 GDPR). Please do not include health data or other sensitive information in your messages.
3. Purposes, legal bases and retention
| Purpose | Legal basis | Retention |
|---|---|---|
| Processing and delivering your order, invoicing, returns, warranty and customer support | Performance of a contract, Art. 6(1)(b) GDPR. Providing the data is necessary: without it we cannot accept the order | For the duration of the relationship, then archived under the tax rules below |
| Accounting, tax and other legal obligations | Legal obligation, Art. 6(1)(c) GDPR | 10 years from the accounting entry, as required by Italian law |
| Answering questions, quotations and custom order requests | Pre-contractual measures taken at your request, Art. 6(1)(b) GDPR | Until the request is closed, then 12 months. Files sent for a quotation are deleted within 12 months if no order follows |
| Site security, fraud prevention and troubleshooting | Legitimate interest in protecting the Site and our business, Art. 6(1)(f) GDPR | Server and security logs: up to 12 months |
| Statistics on the use of the Site, through analytics tools | Consent given through the cookie banner, Art. 6(1)(a) GDPR | As stated in the Cookie policy |
| Newsletter and promotional emails | Consent, Art. 6(1)(a) GDPR | Until you unsubscribe, and in any case 24 months after the last interaction |
| Emails about products similar to those you have already bought ("soft spam") | Legitimate interest, Art. 6(1)(f) GDPR, under Art. 130(4) of the Italian Privacy Code. You can object at any time | 24 months from the last purchase |
| Establishing, exercising or defending legal claims | Legitimate interest, Art. 6(1)(f) GDPR | Until the claim is time barred, ordinarily 10 years |
4. Who receives your data
Your data are not sold and are not published. They are disclosed only to:
- Shopify, which provides the e-commerce platform and hosting for the Site;
- payment providers (such as Shopify Payments, Stripe and PayPal), acting as independent controllers for the payment itself;
- carriers used to deliver your order (such as BRT, GLS, DHL, Poste Italiane), which receive only the delivery details;
- email, analytics and IT service providers that support the Site and our communications;
- our accountants and professional advisers, for tax and legal obligations;
- public authorities, where disclosure is required by law.
Providers acting on our instructions are appointed as processors under Art. 28 GDPR. An up-to-date list of processors can be requested at privacy@dr-i.tech.
5. Transfers outside the European Economic Area
Some providers, including Shopify, are established outside the European Economic Area or use infrastructure there. In that case the transfer is covered by an adequacy decision of the European Commission or by the Standard Contractual Clauses, with the additional safeguards required by the GDPR. A copy of the safeguards in place can be requested at privacy@dr-i.tech.
6. Automated decision making
We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and we do not profile you for advertising purposes.
7. Your rights
Under Arts. 15 to 22 GDPR you have the right to obtain access to your data, their rectification, their erasure, the restriction of processing, data portability, and to object to processing based on our legitimate interest, including direct marketing. Where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal: the link at the bottom of every marketing email is enough to unsubscribe.
To exercise your rights, write to privacy@dr-i.tech or to the registered office. We reply within one month, which may be extended by two further months for complex requests, as provided by Art. 12 GDPR.
8. Complaints to the supervisory authority
If you consider that the processing of your data infringes the GDPR, you may lodge a complaint with the Italian Data Protection Authority, Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, garanteprivacy.it, or with the supervisory authority of the country where you live or work (Art. 77 GDPR).
9. Children
The Site is not directed at minors under 16 and we do not knowingly collect their data. If you believe a minor has provided us with personal data, write to privacy@dr-i.tech and we will delete them.
10. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls limited to authorised staff and periodic review of the systems we use. Where a personal data breach is likely to result in a high risk to your rights, we will notify you and the supervisory authority within the terms of Arts. 33 and 34 GDPR.
11. Changes
This policy may be updated. The version and date at the top of the page always identify the text in force; material changes are announced on the Site or by email.
DR-I S.r.l. Innovative Startup · Registered office: Via E. Ruggiero 123, 81100 Caserta (CE), Italy · Operating address: Via Dalmazia 10, 13100 Vercelli (VC), Italy · VAT and tax code IT04678810617 · REA CE-346222 · Share capital € 3,000.00 fully paid up · PEC certificate@pec.dr-i.tech