Privacy policy
Privacy Policy — Sienna & Gaia
At Sienna & Gaia, we treat your data with the same care we put into crafting our garments: with precision, transparency, and responsibility. This policy explains what data we process, for what purpose, under which legal basis, and how you can exercise your rights, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Spanish regulations.
-
Data Controller
Sienna & Gaia
Contact: hola@siennaegaia.com
Purpose of contact regarding privacy: inquiries and exercise of rights.
-
Data We Process
-
Identification and contact: name, surname, email, phone (if provided), shipping and billing address.
-
Transactional data: order history, returns, incidents, payment method (tokenized by the payment provider; we do not store your card details).
-
Communications and customer service: messages and requests.
-
Technical and website usage data: IP address, cookie identifiers, pages visited, device/browser (see Cookies).
-
Marketing preferences: subscription/consent, language.
-
Purposes and Legal Bases
-
Manage your purchase, payments, shipments, and returns
Legal basis: performance of a contract and legal obligation (invoicing/tax). -
Customer service and after-sales support
Legal basis: legitimate interest in responding and improving our service. -
Personalized commercial communications (email / social media)
Legal basis: consent (opt-in). You can withdraw it at any time. -
Fraud prevention and security
Legal basis: legitimate interest. -
Website analytics and user experience improvement
Legal basis: consent (non-essential cookies).
-
Recipients and Processors
We may share data with service providers necessary to deliver our services, under data processing agreements and confidentiality measures:
-
Logistics and courier services (order delivery/returns).
-
Payment gateways (secure payment processing).
-
E-commerce platform and hosting (site operation and hosting).
-
Marketing and analytics tools (e.g., Google Analytics, Meta Pixel, always with your consent when required).
We do not sell your data.
-
International Data Transfers
If any provider operates outside the EEA, we require appropriate safeguards (e.g., EU Standard Contractual Clauses or adequacy decisions) to protect your data.
-
Data Retention Periods
-
Purchases and invoicing: for the duration of the contractual relationship and thereafter for legal periods (e.g., tax/accounting).
-
Customer service: up to 12 months from the closure of the request.
-
Marketing: until you withdraw your consent or unsubscribe.
-
Cookies: according to their lifespan (see your preferences panel).
-
Your Rights
You can exercise your rights of access, rectification, erasure, objection, restriction, portability, and withdrawal of consent by writing to hola@siennaegaia.com.
You have the right to lodge a complaint with the AEPD (Spanish Data Protection Agency) if you consider it necessary.
-
Cookies and Similar Technologies
We use cookies for essential functions, statistics, and personalized advertising.
-
Essential cookies are installed as necessary for the service.
-
Analytics/marketing cookies require your consent.
You can manage or withdraw your choice at any time through the cookie banner/panel. More information is available in our Cookie Policy.
-
Minors
Our services are not directed at minors under 14 years of age. If we detect data from minors without valid authorization, we will delete it.
-
Security
We apply technical and organizational measures proportionate to the risk: encryption in transit (TLS), access control, incident logging, and regular supplier audits.
-
Updates
We may update this policy to reflect regulatory or service changes. We will indicate the date of the last modification and, if necessary, inform you through our usual communication channels.