Last updated: 18 September 2026
( Contents )
This notice is provided by Made in Evolve S.r.l. pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR) and Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 (the Italian Privacy Code), to the natural persons whose data are processed in the context of the company’s commercial and contractual relationships: customers and prospective customers (prospects), suppliers, partners and consultants, as well as their business contact persons (legal representatives, employees and collaborators acting on behalf of their organisation). For processing carried out through the website, please refer to the Privacy Policy and the Cookie Policy.
The Data Controller is Made in Evolve S.r.l., with registered office at Via Rosalba Carriera 26, 41126 San Damaso, Modena (MO), Italy, Tax Code and VAT no. 03497200364, REA MO-392876. Contacts: privacy@madeinevolve.com (dedicated data protection mailbox), hello@madeinevolve.com, certified email madeinevolve@pec.it, tel. +39 059 788 0854. No Data Protection Officer has been appointed.
The Controller processes only ordinary personal data, collected directly from the data subject or from the organisation on whose behalf they act, or obtained from public sources (company registers, corporate websites, professional profiles) in the course of its commercial activity.
| Category | Examples |
|---|---|
| B2B identification and contact data | First name, last name, role, company, business email address and telephone number, office address |
| Contractual and administrative data | Content of offers, contracts, orders, correspondence, meeting minutes, support tickets |
| Tax and payment data | Tax code and VAT number, bank details, billing data, payment terms |
| System access data | Named credentials to the platforms shared in the course of projects (for example Shopify, Klaviyo, Nucleo Platform) |
| Meeting data | Recordings and transcripts of online meetings made with Fireflies.ai, exclusively after notifying the participants |
No data belonging to special categories (Article 9 GDPR) or relating to criminal convictions and offences (Article 10 GDPR) are processed, except where strictly necessary to comply with legal obligations.
| Purpose | Legal basis | Retention |
|---|---|---|
| Management of negotiations, requests for proposals and quotations | Pre-contractual measures taken at the data subject’s request (Article 6(1)(b) GDPR); for business contact persons, legitimate interest in managing the relationship with their organisation (Article 6(1)(f) GDPR) | For as long as the interest remains active, subject to periodic review, and in any case until erasure is requested |
| Performance of the contract: delivery of services, project management, support, operational communications | Performance of the contract (Article 6(1)(b) GDPR); for business contact persons, legitimate interest (Article 6(1)(f) GDPR) | Duration of the relationship and subsequent limitation periods (10 years) |
| Administrative, accounting and tax obligations; invoicing; payment management | Legal obligation (Article 6(1)(c) GDPR) | 10 years (Article 2220 of the Italian Civil Code) |
| Supplier management: qualification, orders, performance verification, payments | Performance of the contract and legal obligation (Article 6(1)(b) and (c) GDPR) | Duration of the relationship and the following 10 years |
| Commercial communications to existing customers about services similar to those already purchased | Legitimate interest in direct marketing to the Controller’s own customers (Article 6(1)(f) and Recital 47 GDPR; Article 130(4) of the Italian Privacy Code for email) | Until the data subject objects or the relationship ends, subject to periodic review |
| Commercial communications to prospects and business contact persons | Legitimate interest in B2B marketing to persons acting on behalf of businesses potentially interested in the services (Article 6(1)(f) GDPR), or consent where required by Article 130(1) and (2) of the Italian Privacy Code | Until objection or withdrawal of consent, subject to periodic review |
| Recording and transcription of meetings for the preparation of minutes and notes | Legitimate interest in documenting project activities (Article 6(1)(f) GDPR), after notifying the participants, who may object before the recording starts | Duration of the project and subsequent periodic review |
| Protection of the Controller’s rights in or out of court | Legitimate interest (Article 6(1)(f) GDPR) | Duration of the dispute and related limitation periods |
The Controller may send its customers, at the email address provided in the context of the contractual relationship, communications relating to services similar to those already covered by the relationship, without the need for consent, pursuant to Article 130(4) of the Italian Privacy Code. Every communication clearly indicates the possibility of objecting to further messages, free of charge and with a simple click or reply. Business contact persons of prospects and suppliers may object at any time by writing to privacy@madeinevolve.com. The objection is recorded and no promotional communication is sent to those who have expressed it.
The provision of the data necessary to manage the negotiation and the contract, of the data required by law (for example tax data for invoicing) and of the contact details of business contact persons is necessary: failure to provide them makes it impossible to conclude or perform the contract. Any other provision of data is optional.
The data are processed by the Controller’s staff authorised pursuant to Article 29 GDPR and Article 2-quaterdecies of the Italian Privacy Code. They are not disseminated. They may be communicated to the following categories of recipients, to the extent necessary for the purposes indicated.
| Category of recipients | Role |
|---|---|
| Accountants, payroll consultants, auditors, lawyers and other professionals assisting the Controller | Independent controllers or processors, depending on the engagement |
| Banks and payment institutions, insurance companies | Independent controllers |
| Tax authorities, Chamber of Commerce, public and judicial authorities | Independent controllers, where communication is required by law |
| The Controller’s customers, where the supplier works on a customer project | Independent controllers, limited to contact and role data |
| IT and collaboration service providers (table below) | Data processors (Article 28 GDPR) |
The suppliers used by the Controller, bound by contract pursuant to Article 28 GDPR, are the following.
| Supplier | Service |
|---|---|
| DigitalOcean LLC | Hosting of the Controller’s systems, including Nucleo Brain (Frankfurt data centre) |
| Workspace (email, documents, storage), Cloud, Analytics, Tag Manager, reCAPTCHA, Ads, Gemini | |
| Microsoft | 365, Clarity, Copilot |
| Meta Platforms | Advertising platforms |
| Twilio SendGrid | Transactional email |
| Klaviyo Inc. | Email marketing |
| Shopify International Ltd. | Customers’ eCommerce platform |
| Slack Technologies (Salesforce) | Workplace messaging |
| Asana; Notion Labs; Figma | Project management, documentation, design |
| GitHub (Microsoft) | Source code management |
| Fireflies.ai | Meeting transcription, only after notifying the participants |
| OpenAI; Anthropic | Artificial intelligence service providers, on plans that exclude the training of models on the data processed |
Customer and prospect data are managed in Nucleo Brain, the proprietary CRM of Made in Evolve S.r.l., hosted on DigitalOcean in Frankfurt and under the direct control of the Controller.
Some suppliers are established or use infrastructure outside the European Economic Area, in particular in the United States. Transfers take place on the basis of the adequacy decision relating to the EU-US Data Privacy Framework of 10 July 2023, for participating US suppliers, or of the Standard Contractual Clauses adopted by the European Commission with Decision (EU) 2021/914, supplemented by any additional measures that may be necessary. A copy of the safeguards may be requested from privacy@madeinevolve.com.
| Category | Period |
|---|---|
| Contractual, tax and accounting documents | 10 years (Article 2220 of the Italian Civil Code); cannot be erased at the data subject’s request |
| Contracts | Duration of the relationship and subsequent limitation periods (10 years) |
| Data of prospects and commercial contact persons | For as long as the interest or relationship remains active, subject to periodic review, and in any case until erasure is requested or an objection is made; no predefined automatic expiry |
| Meeting recordings and transcripts | Duration of the project and subsequent periodic review |
Once the periods have expired, the data are erased or anonymised. Erasure requests relating to commercial and marketing data are always granted; those relating to data whose retention is required by law are granted upon expiry of the relevant period.
In delivering its services (development and management of Shopify stores, system integration, CRM and email marketing, Nucleo Platform, store management, Merchant of Record), Made in Evolve S.r.l. may access the personal data of its customers’ end customers, such as buyers, subscribers and users of the stores. In such cases it acts as a data processor pursuant to Article 28 GDPR, on behalf of the customer acting as controller and in accordance with its documented instructions. The relationship is governed by the Data Processing Agreement, which also regulates the use of sub-processors (the suppliers listed in section 5), security measures and the return or erasure of data at the end of the service. This notice does not apply to such processing: the notice is provided by the customer acting as controller.
The data subject may exercise the rights provided for in Articles 15-22 GDPR: access, rectification, erasure, restriction of processing, data portability, objection, in particular to processing based on legitimate interest and to direct marketing, and withdrawal of any consent given. Requests may be sent to privacy@madeinevolve.com, to madeinevolve@pec.it or through the form on the page /policy/data-removal. The Controller responds within one month, which may be extended by two months in the cases provided for in Article 12(3) GDPR. The data subject may also lodge a complaint with the Garante per la protezione dei dati personali (Italian Data Protection Authority), Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it (Article 77 GDPR).
The Controller does not take decisions based solely on automated processing which produce legal effects concerning data subjects (Article 22 GDPR).
This notice may be updated to reflect regulatory, organisational or service changes. The current version is published on this page together with the date of the last update; material changes are communicated to the contact persons of active customers and suppliers. Governing law: Italian. Competent court: Modena.
This English version is provided for convenience; in case of discrepancy the Italian version prevails.