Data Controller: THE STYLE FACTORY S.R.L., with registered office at Via Bianche 10, 36010 Carrè (VI), Italy, Tax Code & VAT No.: 03794030241.
THE STYLE FACTORY S.R.L., as operator of the platform, acts in a dual role:
Data Controller: THE STYLE FACTORY acts as Data Controller for the personal data it collects and processes for its own purposes, as detailed in section 2A.
Data Processor: THE STYLE FACTORY acts as Data Processor for the personal data that the User (as an independent Controller) uploads and manages within the Platform (“User Content”), as detailed in section 2B.
Personal data: identification and contact data, professional data (role, qualification, commercial contacts, designers, stylists, etc.), data contained in documents and in the DPP (certifications, technical data sheets, price lists, orders, Digital Product Passport documentation).
Usage data and online tracking data: personal data acquired by the IT systems and software procedures used for the functioning of the Platform during their normal operation, the transmission of which is implicit in the use of Internet communication protocols. Such information is not collected to be associated with identified data subjects; however, by its very nature, through processing and associations with data held by third parties, it could allow Users to be identified (access logs, browsing data, tracking tools used by third-party services).
2.A – Processing as Data Controller
The Controller processes Users’ personal data (natural persons acting as contacts of Supplier or Buyer companies) for the following Primary Purposes:
a) Registration, profile verification, account and subscription management, contractual obligations: To allow the User to register on the Platform, create and manage their profile and obtain the “Verified Profile” badge with certifications and production capacities. The Controller adopts all appropriate technical and organisational measures to verify the identity of listing Users, implementing the principles of transparency, security and accountability provided for by the GDPR and the digital services legislation. Management of subscription, payment, renewal, upgrade and downgrade of Subscription plans and related tax and accounting obligations.
b) Provision of Platform features: Provision of the core services of the Platform, including visibility to international buyers, shared digital workflow, intelligent connection between Suppliers and Buyers (matching), real-time AI reporting, tools for the Digital Product Passport (DPP).
c) Compliance with legal obligations: Compliance with obligations under applicable tax, accounting and administrative legislation, including anti-money laundering regulations where applicable, as well as any other legal obligation incumbent on the Controller.
d) Platform security and abuse prevention: Ensuring the IT security of the Platform, preventing unauthorised access, fraud, identity theft and any other irresponsible or unlawful use of the Platform by anonymous users, in accordance with Articles 24, 25 and 32 GDPR.
e) Matching and profiling: For Premium Subscriptions (e.g. plans with advanced visibility and services), these features are included in the paid services and constitute an integral part of the contractual performance: the related processing is therefore also based on the performance of the contract (Article 6(1)(b) GDPR), as well as, where relevant, on the Controller’s legitimate interest in improving the service (Article 6(1)(f) GDPR).
Failure to provide personal data prevents the creation of the account and the use of the Platform’s services or, depending on the case, suspends or prejudices their performance.
In case of express consent, Users’ personal data will also be processed for the following Additional Purposes:
f) Marketing and promotional communications: Sending newsletters, updates on new Platform features, invitations to sector events, promotional communications relating to the services.
g) Analysis and profiling for service improvement: Analysis of Users’ behaviour on the Platform, processing of aggregated and anonymous data to improve its functionalities.
The User may in any case freely choose not to give consent for the Additional Purposes, without this affecting the use of the contractual services of the Platform.
2.B – Processing as Data Processor
Within the hosting and storage of User Content, the Controller acts as Data Processor on behalf of the Users.
The personal data that may be contained in User Content and processed in this capacity include, by way of example but not limited to:
Contact and identification data: first and last names, email addresses, phone numbers, photographs;
Data in communications: any personal data exchanged between Suppliers and Buyers through the Platform’s messaging and digital workflow tools.
In this capacity, the Controller processes such data exclusively on the instructions of the User-Controller, adopting appropriate technical and organisational security measures pursuant to Article 32 GDPR to protect the data against third parties. The User who uploads User Content containing personal data of third parties is solely responsible for the lawfulness of such processing.
3.1 Users’ personal data are processed using electronic and automated tools, through the technological infrastructure of the MakinIt Platform and the third-party services used by the Controller, described in section 4 below.
3.2 Processing may consist of any operation or set of operations among those indicated in Article 4(1)(2) GDPR, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, comparison, restriction, erasure or destruction.
3.3 Users’ personal data, for the proper management of the contractual relationship and the fulfilment of legal obligations, may be included in the Controller’s internal documentation and, where necessary, in the mandatory records and ledgers required by law.
3.4 The Controller adopts appropriate technical and organisational measures pursuant to Articles 24, 25 and 32 GDPR, taking into account the specific risks of an online marketplace context, including the risk of identity theft and the irresponsible use of the Platform by anonymous users.
The Controller uses the following third-party services to provide the Platform:
HubSpot CRM for user management and CRM;
Google Tag Manager;
Microsoft Clarity for heat mapping and session recording;
Cloudflare for traffic optimisation and security;
Google reCAPTCHA for protection against spam and bots;
Google Analytics 4 for statistics;
Google Ads and LinkedIn Insight Tag for advertising purposes;
Google Fonts and Font Awesome for external content;
Weev for DPP documentation.
The data processed through these services may include identification data, usage data, tracking tools, session information, clicks, mouse movements, IP address and, in the case of Weev, data relating to products and the supply chain, including any personal data of persons involved in the production process. For services provided by non-EU entities (e.g. Google LLC, Microsoft Corporation), data transfers take place on the basis of appropriate safeguards pursuant to Article 46 GDPR (e.g. Standard Contractual Clauses adopted by the European Commission or adequacy decisions).
5.1 The Controller lawfully processes Users’ personal data where the processing:
is necessary for the performance of a contract to which the User is party (the T&Cs and the Subscription contract) or to take steps at the User’s request prior to entering into a contract (Article 6(1)(b) GDPR);
is necessary for compliance with a legal obligation to which the Controller is subject in the tax, accounting or administrative field (Article 6(1)(c) GDPR);
is based on the Controller’s legitimate interest, provided that the User’s interests or fundamental rights and freedoms do not prevail, with particular reference to Platform security, fraud prevention and sending commercial communications in a B2B context (Article 6(1)(f) GDPR);
is based on the User’s express consent, for the Additional Purposes referred to in section 2.A(f) and (g) (Article 6(1)(a) GDPR).
5.2 Express consent is not required for processing related to the Primary Purposes in section 2.A(a)–(e), as it is based on the performance of the contract or compliance with a legal obligation.
The personal data processed as Controller are retained for the following periods:
Registration and account management data: for the entire duration of the contractual relationship and, after its termination, for the standard 10-year limitation period for the purpose of legal defence, subject to different legal obligations;
Invoicing and accounting data: for the period required by tax and accounting legislation;
Data processed on the basis of legitimate interest: until the legitimate interest is satisfied or the User exercises their right to object, subject to the balancing of interests;
Data processed on the basis of consent: until the User withdraws consent;
Browsing and statistical data: according to the policies of each third-party service used, in any case no longer than 26 months.
Personal data contained in User Content and processed as Processor are retained until the User-Controller deletes the account or issues a specific instruction, or until the Subscription contract is terminated.
7.1 Users’ personal data may be disclosed to:
a) Providers of technological services that offer services essential to the functioning of the Platform, acting as external Processors pursuant to Article 28 GDPR;
b) Employees and collaborators of the Controller, as persons authorised to process the data pursuant to Article 29 GDPR;
c) Other Users of the Platform (Suppliers and Buyers), to the extent strictly necessary to provide the matching and connection service between supply and demand;
d) External professionals (e.g. tax consultants, accountants, lawyers) providing services functional to the Primary Purposes, acting as external Processors;
e) Credit institutions for the management of payments arising from the contractual relationship;
f) Judicial or administrative authorities for compliance with legal obligations or for the protection of the Controller’s rights in legal proceedings; g) Entities processing the data in fulfilment of specific legal obligations.
7.2 Apart from the cases indicated above, Users’ personal data will not be disclosed to third parties without the data subject’s explicit consent.
8.1 Users’ personal data may be subject to automated processing for the purpose of intelligent matching between Suppliers and Buyers, i.e. to match Buyers’ purchase requests with the most suitable Suppliers’ offers. This processing does not constitute a decision based solely on automated processing within the meaning of Article 22 GDPR, as it does not produce legal or similarly significant effects concerning the User, being limited to a suggestion function.
8.2 Aggregated and anonymised User data, without any reference to identifiable natural persons, may be used for market statistical analysis and for producing reports, in compliance with the data minimisation principle set out in Article 5(1)(c) GDPR.
9.1 Users’ personal data are stored on servers located within the European Union.
9.2 Some third-party services used by the Controller (including Google Analytics, Google reCAPTCHA, Microsoft Clarity) involve the transfer of data to the United States of America. Such transfers take place on the basis of appropriate safeguards pursuant to Article 46 GDPR, in particular through the Standard Contractual Clauses adopted by the European Commission, or on the basis of the EU–US Data Privacy Framework where applicable.
9.3 Where personal data are transferred to a third country or an international organisation, the User has the right to be informed of the existence of appropriate safeguards pursuant to Article 46 GDPR and to obtain a copy of them.
As a data subject, the User has the right to:
Access their personal data and information relating to the processing (Article 15 GDPR);
Obtain the rectification of inaccurate data or the completion of incomplete data (Article 16 GDPR);
Obtain the erasure of their personal data where one of the conditions set out in Article 17 GDPR is met, subject to the exceptions provided therein;
Obtain restriction of processing in the cases referred to in Article 18 GDPR;
Receive their data in a structured, commonly used and machine-readable format, and transmit them to another Controller (right to data portability), where processing is based on contract or consent and carried out by automated means (Article 20 GDPR);
Object to the processing of their personal data on grounds relating to their particular situation, and to object at any time to processing for direct marketing purposes (Article 21 GDPR);
Withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal (Article 7(3) GDPR);
File a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) as the competent supervisory authority (Article 77 GDPR).
As a data subject, the User may at any time exercise the above rights by sending a written communication to the following contacts:
E-mail: hello@makinit.it;
Postal mail: THE STYLE FACTORY S.R.L., Via Bianche 10, 36010 Carrè (VI).
The Controller will respond to the request without undue delay and, in any event, within one month of its receipt, subject to a two-month extension in cases of particular complexity, of which the User will be promptly informed pursuant to Article 12(3) GDPR.
The Controller reserves the right to amend this notice at any time, by informing Users through the Platform. Users are advised to consult this notice regularly. Amendments will take effect from the date of their publication on the Platform.
Last update: July 2026