This notice explains how the personal data of merilin.store users are processed under Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”).
1. Data controller
Postal Music S.a.s. di Terzilio Mancinelli
Via delle Ginestre 21, 06083 Bastia Umbra (PG), Italy
VAT and Tax Code: IT01872610546
Email: info@merilin.it
2. Data processed
Depending on the services used, we may process:
- identification and contact data, such as first and last name, address, email address and telephone number;
- account, order, invoicing, delivery and after-sales support data;
- information required to manage payments; full card details are processed by payment providers and are not stored by Merilin Store;
- communications sent to customer service and documentation relating to returns, warranties or complaints;
- technical and usage data, such as IP address, logs, device, browser, pages viewed and cookies.
3. Purposes and legal bases
- Managing accounts, orders, payments, deliveries, returns and support: performance of a contract or pre-contractual measures requested by the data subject.
- Tax, accounting and legal compliance: compliance with legal obligations.
- Website security, fraud prevention and protection of rights: the Controller’s legitimate interest, balanced against data-subject rights.
- Responding to requests and complaints: performance of a contract, pre-contractual measures, or the legitimate interest in properly managing customer relationships.
- Promotional communications: consent, where required; consent may be withdrawn at any time.
- Non-essential cookies and measurement tools: express consent through the preference-management system where required by applicable law.
4. Provision of data
Data marked as mandatory are needed to create an account, place and manage an order, or reply to a request. Failure to provide them may make the service unavailable. Data requested for optional purposes, such as marketing, may be omitted without affecting a purchase.
5. Processing methods and security
Data are processed using electronic and, where necessary, paper-based tools by authorised staff following procedures consistent with the stated purposes. We implement technical and organisational measures appropriate to the risk to prevent unauthorised access, loss, disclosure or alteration.
6. Recipients
Where necessary, data may be shared with hosting and IT service providers, payment providers and banks, carriers and logistics operators, administrative, tax and legal advisers, service centres, authorities and public bodies. These parties act as independent controllers or processors according to their role. An up-to-date list of processors may be requested from the Controller.
Data are not disclosed to the public or sold.
7. Transfers outside the European Economic Area
Where a supplier processes data outside the European Economic Area, the transfer is made under an adequacy decision, standard contractual clauses approved by the European Commission, or another GDPR mechanism.
8. Retention
Data are retained for as long as necessary for the purposes for which they were collected. Order, invoice and administrative data are retained for the periods required by law; data needed to manage disputes may be retained until the relevant limitation periods expire. Marketing data are retained until consent is withdrawn or erasure is requested, unless further obligations apply. Cookie duration and management are set out in the preference panel.
9. Data-subject rights
In the cases provided by Articles 15–22 GDPR, data subjects may request access, rectification, erasure, restriction, portability and objection, and may withdraw consent without affecting the lawfulness of prior processing.
Requests may be sent to info@merilin.it. To protect data, we may request information needed to verify the requester’s identity. A complaint may also be lodged with the Italian Data Protection Authority.
10. Cookies
The website uses technical cookies necessary for its operation and may use optional tools only in accordance with the preferences expressly selected by the user. Choices can be changed at any time through the cookie-management panel on the site.
11. Updates
This notice may be updated to reflect regulatory, organisational or technical changes. The version published on this page is the applicable version.
Last updated: 13 July 2026.