Privacy Policy

Effective date / Data di efficacia: 31 August 2025

Controller / Titolare del trattamento
Royal Innovation SRL
via Marconi, 123 – 24020 Ranica (BG), Italy
Website: https://royal-laser.com
Email: info@royal-laser.com
Phone: +39 035 300929


EN — Privacy Policy

1) Who we are

Royal Innovation SRL (“we”, “us”, “our”) is the controller of personal data processed through https://royal-laser.com and related contact channels.

2) What personal data we collect

We collect and process the following categories of personal data:

  • Identification and contact data: name, surname, company, email, phone number, address, country/region.
  • Communication data: content of messages sent via contact forms, email, phone, or chat; support and sales notes.
  • Transactional data (if applicable): order details, invoicing and shipping information, payment status (we do not store full card details; payments are handled by the selected payment processor).
  • Technical/usage data: IP address, device information, browser and OS, language settings, pages visited, time spent, referring pages, general location inferred from IP, and other analytics data collected via cookies or similar technologies.
  • Marketing preferences: newsletter opt-ins/opt-outs, consent records, interaction with our marketing communications.
  • Recruitment data (if you apply): CV/resume, cover letter, professional history, and any information you voluntarily provide.
  • Data from third parties (if provided to us lawfully): e.g., business directories or service providers that help us verify business information and prevent abuse.

3) Purposes and legal bases

We process personal data for the purposes and on the following legal bases:

  • To respond to enquiries and provide quotations — performance of a contract or pre-contractual steps; legitimate interest to operate our business and answer requests.
  • To provide our services and manage customer relationships — performance of a contract; legitimate interest to ensure service quality and continuity.
  • To issue invoices, manage accounting and comply with legal obligations — legal obligation.
  • To ensure website security and prevent fraud/abuse (e.g., logs, rate-limiting) — legitimate interest.
  • To understand and improve our website (analytics) — consent (via our Cookie Policy/consent banner).
  • To send marketing communications (e.g., newsletters, special offers) — consent; you can withdraw consent at any time.
  • Recruitment — pre-contractual steps; legitimate interest to manage applications; and consent where required by law.

Where we rely on legitimate interests, we balance our interests with your rights and freedoms and implement safeguards. You may object to processing based on legitimate interests at any time (see Section 10).

4) Cookies and similar technologies

Our Cookie Policy explains the types of cookies we use (functional, statistics, and marketing/tracking), their purposes, retention periods, and how you can manage your preferences through the consent banner and your browser settings.
See: Cookie Policy available on our website.

5) Recipients of personal data

We share personal data only as necessary with:

  • Service providers (processors) acting on our instructions (e.g., hosting and infrastructure, email and newsletter tools, analytics providers, CRM/support tools, payment processors where relevant).
  • Professional advisers (e.g., accountants, lawyers) bound by confidentiality.
  • Public authorities when required by applicable law or court order.
    We require processors to implement appropriate security measures and to process data only per our documented instructions. We can provide an up-to-date list of processors upon request.

6) International data transfers

Some recipients may be located outside the EEA/Switzerland. Where such transfers occur, we use adequacy decisions (where available), and/or Standard Contractual Clauses (SCCs) with supplementary measures, or other lawful safeguards. For transfers to the United States, we may rely on recipients’ participation in the EU–U.S. and/or Swiss–U.S. Data Privacy Frameworks (if certified) or on SCCs.

7) Data retention

We keep personal data only for as long as necessary for the purposes described above, and thereafter for the period required by law or to establish, exercise, or defend legal claims. Typical retention:

  • Enquiry data: up to 24 months after last interaction.
  • Client and contractual data: up to 10 years after contract end (to meet tax/accounting obligations).
  • Marketing data: until you withdraw consent or after 24 months of inactivity.
  • Recruitment data: up to 12 months (unless you consent to a longer period).

8) Security

We apply appropriate technical and organisational measures to protect data (e.g., encryption in transit, access controls, least-privilege, backups, logging and monitoring, staff confidentiality). No method of transmission or storage is 100% secure, but we continuously improve our safeguards.

9) Children

Our website and services are not intended for children under 14. We do not knowingly collect data from children. If you believe a child has provided data, please contact us and we will promptly delete it.

10) Your rights (EEA & Switzerland)

Subject to legal conditions and limits, you have the right to: access, rectify, erase, restrict processing, object to processing (including direct marketing), and data portability. Where processing is based on consent, you may withdraw consent at any time (this does not affect processing prior to withdrawal).
You also have the right to lodge a complaint with a supervisory authority (see Section 12).

11) How to exercise your rights

To exercise your rights or ask any question, contact us at info@royal-laser.com. We may need to verify your identity. We will respond without undue delay and, in any event, within the timeframe required by applicable law.

12) Supervisory authorities

  • Italy (lead authority for our company): Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Roma, Italy — https://www.garanteprivacy.it
  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern — https://www.edoeb.admin.ch

13) Automated decision-making

We do not engage in decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. If this changes, we will update this Policy and provide the information required by law.

14) Third‑party links

Our website may contain links to third‑party sites and services. Those sites have their own privacy policies; we are not responsible for their practices.

15) Changes to this Policy

We may update this Policy from time to time. The latest version is always published on this page with the effective date. If changes are material, we will provide a prominent notice.

Scroll to Top