Privacy policy
Last updated: 24 August 2026
This privacy notice describes how VIKKIN SRLS processes the personal data of users of the website vipertactical.eu, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
1. Data Controller
- VIKKIN SRLS
- Registered office: Contrada Ulmi 703, 91018 Salemi (TP), Italia
- VAT and Tax Code: IT02846720817
- Email: info@vipertactical.it
No Data Protection Officer (DPO) has been appointed, as the conditions set out in Article 37 GDPR are not met.
2. What data we collect
- Personal and contact details: first name, last name, billing and shipping address, email, phone number.
- Payment data: transaction details. We never have access to the full card number, which is processed directly by the payment service provider.
- Account data: credentials, preferences, saved addresses, wish list.
- Order data: products purchased, returns, exchanges, communications with customer support.
- Browsing data: IP address, browser and device type, pages visited, referral source, cookie identifiers.
We do not process special categories of personal data within the meaning of Article 9 GDPR.
3. Purposes, legal basis and retention
| Purpose | Legal basis | Retention |
|---|---|---|
| Order management, shipping, returns and customer support | Performance of a contract — Art. 6(1)(b) | For the duration of the relationship and until contractual rights become time-barred |
| Invoicing and tax and accounting obligations | Legal obligation — Art. 6(1)(c) | 10 years from the date of recording, pursuant to Art. 2220 of the Italian Civil Code |
| Legal guarantee of conformity | Legal obligation — Art. 6(1)(c) | 26 months from delivery, plus applicable limitation periods |
| Customer account management | Performance of a contract — Art. 6(1)(b) | Until the user requests deletion |
| Newsletter and promotional communications | Consent — Art. 6(1)(a) | Until consent is withdrawn, and in any case no longer than 24 months after the last interaction |
| Non-technical profiling or measurement cookies and technologies | Consent — Art. 6(1)(a) | As specified in the Cookie Policy |
| Fraud prevention and website security | Legitimate interest — Art. 6(1)(f) | Up to 12 months from collection |
| Legal defence and dispute management | Legitimate interest — Art. 6(1)(f) | For the duration of the proceedings and subsequent appeal periods |
Providing data required for the performance of the contract and for compliance with legal obligations is mandatory: without it, the purchase cannot be completed. Providing data for marketing purposes is optional, and refusal does not affect the purchase.
4. Who we share data with
Data may be shared with the following categories of recipients, acting as data processors pursuant to Article 28 GDPR or as independent data controllers:
- Shopify International Ltd., provider of the e-commerce platform hosting the store.
- Payment service providers, which process transaction data as independent controllers under their own privacy policies.
- Couriers and logistics operators, for delivery and return management.
- Email marketing service providers, for sending newsletters subject to consent.
- Tax, accounting and legal advisors, and auditing firms.
- Public authorities, where required by law or by an official order.
Data is not disclosed to or sold to third parties.
5. Transfers outside the European Economic Area
Some providers may process data outside the EEA. In such cases, the transfer takes place on the basis of an adequacy decision by the European Commission or of Standard Contractual Clauses adopted pursuant to Article 46 GDPR, accompanied by any necessary supplementary measures. You may request a copy of the safeguards in place by contacting us at the details provided in Section 1.
6. Automated decision-making
We do not carry out solely automated decision-making processes that produce legal effects on data subjects within the meaning of Article 22 GDPR. The payment provider's anti-fraud systems may flag a transaction as suspicious, but the final decision is always subject to human review.
7. Cookies
The website uses technical cookies, which are necessary for its operation and are installed without consent, as well as measurement and profiling cookies, which are installed only upon express consent given through the dedicated banner. Consent may be withdrawn at any time. The types, purposes and durations are described in the Cookie Policy.
8. Your rights
Under Articles 15 to 22 of the GDPR, you may exercise the following rights:
- Access: obtain confirmation of processing and a copy of your data.
- Rectification: correct inaccurate data or complete incomplete data.
- Erasure: request the deletion of your data, subject to any legally required retention obligations.
- Restriction: request that processing be restricted in certain circumstances.
- Portability: receive your data in a structured, machine-readable format or request its transfer to another controller.
- Objection: object to processing based on legitimate interest and, at any time and without giving reasons, to direct marketing.
- Withdrawal of consent: at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
To exercise your rights, write to info@vipertactical.it. We will respond within one month of your request, extendable by two months in cases of particular complexity, of which we will notify you.
9. Complaint to the supervisory authority
If you believe that the processing of your data infringes the GDPR, you have the right to lodge a complaint with the Garante per la protezione dei dati personali (Italian Data Protection Authority), Piazza Venezia 11, 00187 Roma — www.garanteprivacy.it — or with the supervisory authority of the Member State in which you reside or work.
10. Security
We implement technical and organisational measures appropriate to the risk, including encryption of communications via the HTTPS protocol, access controls on management tools, and the selection of providers offering sufficient guarantees pursuant to Article 28 GDPR. However, no security measure can be considered absolute.
11. Minors
Our services are not intended for individuals under the age of 16 and we do not knowingly collect their data. Some products are also restricted by law to adults. If you believe a minor has provided us with their personal data, please contact us at the details above and we will arrange for its deletion.
12. Changes
This privacy notice may be updated to reflect changes in processing activities or regulatory requirements. The current version is always published on this page, with the date of the last update indicated. In the event of material changes, we will provide adequate prior notice.




