Vatican Design

Re-Design My Church. Designing for the Kingdom because God deserves the best design


Privacy Policy

vaticandesign.com

This Privacy Policy explains who processes your personal data when you visit vaticandesign.com or buy from our shop, what we do with that data, how long we keep it, and what rights you have. It is written to satisfy Article 13 of Regulation (EU) 2016/679 (“GDPR”), which applies where we collect data directly from you, and Article 14 for the limited data we receive about you from others (section 2.4).

The short version: we use your data to fulfil your order, to keep the shop working, and to meet our tax and accounting obligations. We do not sell your data and we do not send marketing emails.


1. Who is the controller of your data

The Vatican Design shop is operated by two companies. Which one is the controller of your data depends on where your order is shipped.

Orders shipped to an address in Italy — dispatched from our point in Rome:

Orders shipped anywhere else, and all use of the website itself (browsing, customer account, contact, product reviews):

Both companies trade under the Vatican Design brand, are owned and directed by the same person, and share one shop platform, one customer database and one set of procedures. Because they jointly determine the purposes and means of that shared processing, they are joint controllers within the meaning of Article 26 GDPR. The allocation of responsibility between them, which Article 26(2) requires us to make available to you, is:

  • each company is responsible for the orders it fulfils, invoices and stores the accounting records for;
  • BIBLE SPA is responsible for the website, the customer accounts and the technical infrastructure;
  • you may exercise all of your rights against either company, and you do not need to work out which one holds your data — one email to the address below reaches both.

Our physical shop, dispatch and returns point:
Vatican Design, Borgo Santo Spirito 14, 00193 Roma, Italy

Neither company is required to appoint a Data Protection Officer and neither has done so. All privacy matters go to dayenudesign@gmail.com and are handled by the controller directly.


2. What data we collect

Data you give us:

WhenData
Placing an orderfirst and last name, billing address, delivery address, email, phone number, order contents, chosen delivery and payment method, VAT number and company name (business orders), any note you add to the order
Creating an accountemail address, password (stored only as a cryptographic hash — we never see it), order history, saved addresses
Contacting us — by email, by phone or through the contact form on the siteyour email address or phone number, your name, and whatever you write to us
Returns, withdrawal from the contract, complaintsyour statement, proof of purchase, bank account number for the refund, correspondence
Product reviewsdisplay name, review content, rating, and whether the purchase was verified

Data we collect automatically:

  • IP address, browser and device type, operating system, language;
  • pages viewed, time of the request, referring URL;
  • server logs kept by our hosting provider;
  • where you consent to it, the website, search engine or campaign that brought you to the shop, so that we can attribute an order to a traffic source;
  • cookies and similar technologies — see our Cookie Policy.

What we do not collect. Payment card numbers never reach our servers — you enter them directly into fields hosted by Stripe or PayPal. We do not ask you for, and we do not knowingly collect, special category data under Article 9 GDPR: health, political opinions, religious or philosophical beliefs, and so on.

A word about what we sell. We sell devotional and religious articles, and we recognise that in some circumstances a purchase history of such products could allow inferences to be drawn about a person’s religious beliefs. We take that seriously and we limit what we do accordingly:

  • we do not use your order history to infer anything about your beliefs;
  • we do not segment, profile, score or target customers by religion or by any inference about religion;
  • we do not disclose order contents to anyone beyond what is strictly required to ship the parcel, take the payment and issue the invoice;
  • access to order details inside our business is restricted to the people who need it to fulfil orders and keep the accounts;
  • we periodically assess whether any product or processing operation brings us within Article 9 GDPR, and if it does, we will identify and publish the Article 9(2) condition we rely on before continuing.

2.4 Data we receive from others

We receive a small amount of data about you from third parties rather than from you directly:

  • from Stripe and PayPal — the status of your payment, the transaction reference and the result of their fraud checks (we never receive your full card number);
  • from InPost and FedEx — parcel tracking and delivery status, and any delivery problem reported;
  • from customs authorities, for shipments outside the EU — the status of the customs clearance.

We receive this data at the time it arises, in order to perform your contract, and we use it only for that purpose and for the related purposes in section 3.

We do not currently operate a newsletter. If we start one, it will be by separate opt-in consent and this policy will be updated first.


3. Why we process your data, on what legal basis, and for how long

PurposeLegal basisRetention
Processing and delivering your order, handling payment and delivery, contacting you about the orderArt. 6(1)(b) — performance of a contractFor the duration of the contract, then for the applicable limitation period for claims
Issuing and storing invoices and accounting records — DAYENU S.R.L.S. (Italy)Art. 6(1)(c) — legal obligation10 years from the last entry, under Art. 2220 of the Italian Civil Code
Issuing and storing invoices, VAT and accounting records — BIBLE SPA (Malta)Art. 6(1)(c) — legal obligation6 years as a general rule under Maltese VAT record-keeping requirements, extended to 10 years for the records that Maltese law requires to be kept for that period, including electronic records of intra-EU distance sales
Records of intra-EU distance selling declared through the OSS/IOSS schemeArt. 6(1)(c) — legal obligation10 years from the end of the year of the transaction, as required by the EU VAT e-commerce rules
Running your customer accountArt. 6(1)(b)Until you delete the account, plus up to 30 days while backups rotate out
Handling returns, withdrawal from the contract and complaintsArt. 6(1)(c) — consumer law obligations; Art. 6(1)(f) — defending claims6 years from closing the case
Establishing, exercising or defending legal claimsArt. 6(1)(f) — our legitimate interestUntil the claim is time-barred
Answering your messages (email, phone, contact form, social media)Art. 6(1)(f) — legitimate interest in responding to enquiries2 years from the last message
Publishing product reviews in the shopArt. 6(1)(a) — your consentUntil you ask us to remove the review
Fraud prevention, securing the site and the payment processArt. 6(1)(f) — legitimate interest; Art. 6(1)(c) for anti-fraud duties12 months for logs, longer only while an incident is under investigation
Working out which channel an order came from (traffic attribution)Art. 6(1)(a) — your consent, given in the cookie banner6 months
Analytics and measuring how the shop is usedArt. 6(1)(a) — your consent, given in the cookie bannerAs set out in the Cookie Policy

Where we rely on legitimate interest, we have weighed our interest against your rights and concluded that the processing is limited in scope, expected in the context of an online shop, and not intrusive. You can object at any time — see section 7.

Is providing data mandatory? Providing data is voluntary, but the fields marked as required in the order form are necessary to conclude and perform the sales contract. Without them we cannot accept or ship your order. Everything else — an account, a review, a phone number beyond what the courier needs — is optional, and refusing it does not affect your ability to shop with us.


4. Who we share your data with

We do not sell your personal data and we do not share it for third-party advertising. We disclose it to the following recipients, who act either as our processors under a data processing agreement (Art. 28 GDPR) or as independent controllers where the law makes them so:

RecipientRoleWhat they receive
Stripe Payments Europe, Ltd. (Ireland)Independent controller — card paymentsName, email, billing address, order amount; card details entered directly into Stripe’s fields
PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg)Independent controller — PayPal paymentsName, email, order amount, transaction data
InPostController for the delivery serviceName, delivery address or parcel locker code, phone number, email, parcel details
FedEx ExpressController for the delivery serviceName, delivery address, phone number, email, parcel contents and value, and customs data for shipments outside the EU
Zenbox sp. z o.o. (Poland)Processor — website hosting and backupsAll data stored in the shop, server logs
Google Ireland Limited — GmailProcessor for our business emailThe content of any email correspondence with us, including your address and whatever you write
Meta Platforms Ireland Ltd., LinkedIn Ireland, and the operators of any other profile you write toIndependent controllersOnly what you choose to send us in a direct message on that platform. Please do not send order details or documents this way — use email
Google Ireland LimitedIndependent controller — the Google map on our home page and the YouTube videos embedded on some pagesYour IP address, browser and device data, the referring page — and only if you consent to external media
Legal and IT advisers, postal operatorsProcessors or separate controllersOnly the data needed for the specific service
Courts, tax authorities, law enforcement, supervisory bodiesSeparate controllersOnly where a lawful request obliges us to disclose

We keep this list current. If you want to know exactly which providers we use on the day you ask, write to dayenudesign@gmail.com.


5. Transfers outside the EEA

Our shop, our hosting and our own systems are located within the European Economic Area — the site is hosted by Zenbox in Poland.

Some of the providers listed above may nonetheless transfer personal data outside the EEA, in particular to the United States: Stripe, PayPal, FedEx (for international shipments and customs clearance) and Google (Maps and YouTube, and only where you have consented to external media).

Where that happens, the transfer relies on a safeguard permitted by Chapter V GDPR:

RecipientWhereMechanism relied on
Stripe Payments Europe, Ltd.Ireland; onward transfer to Stripe, Inc. in the United StatesEU–US Data Privacy Framework adequacy decision, and Standard Contractual Clauses for transfers not covered by it
PayPal (Europe) S.à r.l. et Cie, S.C.A.Luxembourg; onward transfer to PayPal, Inc. in the United States and to other group companiesStandard Contractual Clauses, with supplementary measures
Google Ireland Limited (Gmail, Maps, YouTube)Ireland; onward transfer to Google LLC in the United StatesEU–US Data Privacy Framework adequacy decision
FedExNetherlands and the United States, plus the destination country of the shipmentStandard Contractual Clauses; for the destination country, Art. 49(1)(b) GDPR — necessary to perform your contract
Customs authorities outside the EUDestination countryArt. 49(1)(b) and (d) GDPR — necessary to perform your contract and required by that country’s law

Where we rely on Standard Contractual Clauses, we have also assessed the law of the destination country and applied supplementary technical and organisational measures where needed.

For deliveries outside the EU, customs authorities in the destination country will also receive the data required by that country’s customs rules. This transfer is necessary for the performance of your contract (Art. 49(1)(b) GDPR).

You can request a copy of the safeguards we rely on by writing to dayenudesign@gmail.com.


6. Automated decision-making and profiling

We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

Our payment providers (Stripe, PayPal) run automated fraud checks on transactions, which can result in a payment being declined. Those checks are performed by them, under their own rules, and you can contact them directly to contest such a decision.


7. Your rights

Under the GDPR you have the right to:

  • access your data and obtain a copy of it (Art. 15);
  • rectify data that is inaccurate, and complete data that is incomplete (Art. 16);
  • erase your data — the “right to be forgotten” (Art. 17), except where we are legally obliged to keep it, for example invoices;
  • restrict processing (Art. 18);
  • data portability — where the processing is based on your consent or on a contract with you and is carried out by automated means, receive the data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller (Art. 20);
  • object to processing based on our legitimate interest (Art. 21), including an absolute right to object to direct marketing at any time;
  • withdraw consent at any time where processing is based on consent (Art. 7(3)) — this does not affect the lawfulness of processing carried out before the withdrawal;
  • lodge a complaint with a supervisory authority (Art. 77).

How to exercise them. Write to dayenudesign@gmail.com. We answer within one month of receiving your request. For complex requests we may extend this by two further months — if so, we will tell you within the first month and explain why. Exercising your rights is free of charge; for manifestly unfounded or excessive requests we may charge a reasonable fee or refuse to act, and we will explain the reason. We may ask you for information needed to confirm your identity.

Where to complain. You can lodge a complaint with the supervisory authority of the EU/EEA country where you live or work, or where you believe the infringement took place — for example:

We would rather hear from you first, though — most things are faster to fix directly.


8. Cookies

We use cookies and similar technologies. Cookies that are strictly necessary to run the shop — session, basket, checkout, security — are set without consent, because the law allows it. Every other category — preferences, traffic attribution, analytics, and external media such as the Google map and the embedded YouTube videos — is set only after you agree in the cookie banner, and you can change or withdraw your choice at any time via “Cookie settings” in the footer.

Full details, including a list of the individual cookies with their purpose and lifetime, are in our Cookie Policy.


9. Security

We apply technical and organisational measures appropriate to the risk: encrypted transmission (TLS/HTTPS) across the whole site, individually assigned and restricted access to the shop administration, hashed passwords, regular backups, prompt updates of the platform and its plugins, and written data processing agreements with our providers. Card data is entered directly into the payment provider’s own fields and neither passes through nor is stored on our servers.

No system is perfectly secure. If a personal data breach occurs:

  • we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms (Art. 33 GDPR);
  • we notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms (Art. 34 GDPR).

10. Children

Our shop is not directed at children. We do not knowingly collect data from anyone under 16, and orders may only be placed by people with the legal capacity to enter into a contract. If you believe a child has given us personal data, write to dayenudesign@gmail.com and we will delete it.


11. Changes to this policy

We may update this Privacy Policy — for example when we add a payment method, a courier, or a new tool. The current version is always published at vaticandesign.com/privacy-policy/, with its effective date at the top. If a change materially affects your rights, we will notify you by email (where we have your address) or by a clear notice on the site before it takes effect.


12. Contact

Questions about this policy, or about anything we do with your data:

dayenudesign@gmail.com · +48 512 288 620
Vatican Design, Borgo Santo Spirito 14, 00193 Roma, Italy
DAYENU S.R.L.S., Borgo Santo Spirito 14, 00193 Roma (RM), Italy — P. IVA IT 17983511001, REA RM–1753957
BIBLE SPA Dorota Mayer-Gawron, Mattew Pulis Street, Sliema SLM 3051, Malta — VAT MT31576318