Privacy Policy

Privacy Policy (GDPR Compliant)

1. Data Controller

The Data Controller responsible for the processing of your personal data is:

PERIOD. S.r.l.
Address: C.so XXII Marzo, 4, 20135 – Milano (MI)
Email: info@periodeurope.com

No Data Protection Officer (DPO) has been appointed at this time. All privacy-related inquiries should be directed to the email address above.

2. Personal Data Collected

We may collect the following categories of personal data:

  • Identification data: name, surname, email address, phone number.
  • Account and usage data: preferences, selections, interaction with the platform.
  • Special category data (Art. 9 GDPR): information voluntarily provided by users relating to menstrual product preferences and limited health-related considerations where necessary for personalization and service functionality. The provision of special category data is entirely voluntary; however, certain personalization features or services may not be available without it.

Such data is collected solely for the purposes described below and only where necessary.

3. Profiling and Personalization

We may process user preferences to match users with relevant sponsors and offers. This activity constitutes limited profiling under Article 4(4) GDPR and is carried out only on the basis of the user’s explicit, separate consent (see Section 15 below).

4. International Data Transfers

Personal data is primarily processed within the European Economic Area (EEA), including Switzerland. If data is transferred outside this area, we ensure it is done in accordance with the GDPR (e.g., using Standard Contractual Clauses or other appropriate safeguards recognized with the European Commission).

5. Purposes of Processing

Personal data is processed for the following purposes:

  • Creating and managing your user account.
  • Customizing your product and platform experience.
  • Matching users with relevant sponsors, offers, and content based on selected interest categories.
  • Managing product selection, waitlist access, and pickup-related operations.
  • Conducting market research and improving products and services.
  • Communicating with users regarding the platform, updates, support, and related initiatives.
  • Ensuring platform security and preventing misuse or fraud.

6. Legal Basis for Processing

Personal data is processed based on:

  • Consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) for special category data, profiling and personalization, and marketing communications where applicable. Consent for special category data is collected separately and granularly from general account registration (see Section 15).
  • Contractual necessity (Art. 6(1)(b) GDPR) for the performance of the service, including account creation and product delivery.
  • Legitimate interest (Art. 6(1)(f) GDPR) for account functionality, security, fraud prevention, and service improvement.

7. Data Minimization

We only collect personal data that is relevant and necessary for the purposes described in this Privacy Policy.

8. Data Processing and Security

Data is processed electronically using secure cloud-based infrastructure, encrypted storage systems, and internal technical tools. Access is restricted to authorized personnel only. Appropriate technical and organizational measures are in place to protect data from unauthorized access, loss, or disclosure.

9. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of users, PERIOD. will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Art. 33 GDPR. If the breach is likely to result in a high risk to users, we will notify them without undue delay.

10. Data Retention

Personal data will be stored only for as long as necessary to achieve the purposes described above and, in any case, no longer than 24 months from the user’s last meaningful interaction with the platform, unless a longer retention period is required by law or necessary to protect legal rights. Upon expiry of the retention period, personal data will be securely deleted or anonymized.

11. Age Requirement

The service is intended for users aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that a user is under the age of 18, the account will be terminated and all associated personal data will be deleted without undue delay.

12. Data Sharing

Personal data may be shared with service providers acting as data processors (e.g., cloud hosting, analytics, email services) or authorities where required by law. Personal data will not be sold to third parties.

Sponsors do not receive personal data directly unless explicitly authorized by the user or necessary for the redemption of a specific offer or service requested by the user. When a user redeems a sponsor offer, the sponsor may receive limited, anonymized interaction data but will not receive the user’s personal identity unless the user provides it directly to the sponsor.

Users may request a list of current sub-processors by contacting us at info@periodeurope.com.

13. Data Subject Rights

You have the right to access your personal data, rectify inaccurate data, request deletion or restriction of processing, object to processing, and request data portability where applicable. You may withdraw consent at any time without affecting the lawfulness of processing based on prior consent.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) or another competent supervisory authority.

To exercise your rights, please contact: info@periodeurope.com

14. Cookies and Tracking Technologies

We may use cookies, SDKs, and similar technologies for functionality, analytics, performance, and service improvement. Users will be presented with a consent mechanism where required by applicable law. For more information, please refer to our Cookie Policy.

15. Consent

By creating an account, you acknowledge that you have read and understood this Privacy Policy.

Consent for the processing of special category data (including menstrual product preferences and related health-adjacent information) is collected separately through a dedicated opt-in mechanism within the app. This consent is granular and independent from general account registration. You may withdraw this consent at any time through your account settings.

Consent for profiling and personalization (matching your selected interest categories with relevant sponsors) is also collected through a separate, clearly identified consent mechanism within the app.

Where required by applicable law, consent for marketing communications will be obtained separately.

16. Updates to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or posted on periodeurope.com. Continued use of the platform after notification of changes constitutes acceptance of the updated Privacy Policy.