PRIVACY POLICY
Pursuant to Article 13 of Regulation (EU) 2016/679 (the “GDPR” or the “Regulation”), MyGold S.p.A. (hereinafter, the “Controller”) provides this privacy notice on the processing of the personal data of the users and visitors of the website www.mygold.world (hereinafter, respectively, the “Users” and the “Site”).
This Privacy Policy describes the manner in which the personal data collected through the Site are processed and is provided exclusively with reference to the Site. It does not apply to third-party websites that may be accessed through hyperlinks (links) available on the Site, in respect of which the Controller assumes no responsibility.
The Controller of the processing of personal data is MyGold S.p.A., with registered office in Piazzale Luigi Cadorna No. 9, 20123 Milan (MI), Italy, registered with the Milan Companies Register, REA No. MI-2667181, VAT No. 02592560243, a Professional Gold Operator (OPO) entered in the Register held by the Organismo degli Agenti e dei Mediatori (OAM), pursuant to Law No. 7 of 17 January 2000.
For any information concerning the processing of personal data or in order to exercise the rights provided for by Articles 15 et seq. of the GDPR, the Controller may be contacted at the following addresses:
The following categories of personal data may be collected and processed through the Site.
In the course of their normal operation, the IT systems and software procedures used to operate the Site acquire certain personal data whose transmission is implicit in the use of Internet communication protocols.
This category includes, by way of example:
Such data are processed exclusively in order to enable the proper functioning of the Site, ensure its security, carry out maintenance activities, obtain aggregate statistical information on the use of the Site and ascertain liability in the event of computer offences against the Site or third parties.
Browsing data are retained for the time strictly necessary to pursue the aforementioned purposes and, as a rule, for a period not exceeding 6 months, without prejudice to any need to retain them for the establishment, exercise or defence of a legal claim, for IT security purposes or to comply with legal obligations.
The optional, explicit and voluntary submission of personal data through the contact forms available on the Site, through the contact details indicated or through any other communication channel made available by the Controller entails the acquisition of the data necessary to respond to the User’s requests.
By way of example, the following may be collected:
Users are invited not to transmit personal data exceeding what is necessary for the handling of their request, nor special categories of personal data within the meaning of Article 9 of the GDPR. Any special categories of personal data spontaneously transmitted by the User will be processed exclusively where one of the conditions laid down by Article 9(2) of the GDPR applies — as a rule, with the data subject’s explicit consent — or will otherwise be erased.
The Site uses cookies and other tracking tools, where applicable, in compliance with applicable law.
For detailed information on the types of cookies used, on the related purposes, on the retention periods and on how to manage preferences, please refer to the Cookie Policy published on the Site, which forms an integral part of this notice.
The Site has a predominantly informational, corporate and contact-related nature and is intended to present MyGold S.p.A., its business and the services offered in the field of the purchase, sale and custody of physical gold and of physical gold accumulation plans.
The Site is not intended for the conclusion of online sale contracts and does not constitute an e-commerce platform.
Any requests for information, contact or further commercial details relating to the services presented on the Site may be handled by the Controller and, where necessary, by third parties cooperating with the Controller for organisational, commercial or support purposes, in compliance with the legislation in force on the protection of personal data.
The personal data collected through the Site are processed for the purposes, on the legal bases and for the retention periods indicated below.
4.1 Browsing on the Site and technical operation
Purpose: to enable browsing on the Site and to ensure its proper functioning, the security of the systems and the maintenance of the IT infrastructure, as well as to obtain aggregate statistical information on the use of the Site.
Legal basis: the legitimate interest of the Controller, pursuant to Article 6(1)(f) of the GDPR, in ensuring the proper functioning, security and reliability of the Site.
Retention period: the data are retained for the time strictly necessary to pursue the aforementioned purposes and, as a rule, for a period not exceeding 6 months, without prejudice to any need to retain them for the establishment, exercise or defence of a legal claim, for IT security purposes or to comply with legal obligations.
4.2 Handling of requests sent by the User
Purpose: to handle and respond to requests for information, contact, further details, support or quotations sent by the User through the Site or through the Controller’s contact details.
Legal basis: the implementation of pre-contractual measures taken at the data subject’s request pursuant to Article 6(1)(b) of the GDPR or, where applicable, the legitimate interest of the Controller in handling and responding to the requests received, pursuant to Article 6(1)(f) of the GDPR.
Retention period: the data are retained for the time necessary to handle the request and, thereafter, for a period not exceeding 24 months, unless their further retention is necessary to comply with legal obligations, to establish a contractual relationship or to establish, exercise or defend a legal claim.
4.3 Management of access to any restricted areas
Purpose: to enable access to any restricted areas of the Site, manage authentication credentials and ensure the security of access.
Legal basis: the performance of the relationship with the data subject or the implementation of pre-contractual measures taken at the data subject’s request pursuant to Article 6(1)(b) of the GDPR, as well as the legitimate interest of the Controller in ensuring the security and proper functioning of the restricted areas pursuant to Article 6(1)(f) of the GDPR.
Retention period: the data are retained for the entire duration of the access authorisation and, thereafter, for the period strictly necessary to comply with any legal obligations or to protect the Controller’s rights.
4.4 Compliance with legal obligations
Purpose: to comply with the obligations laid down by laws, regulations, European Union legislation, measures of the competent Authorities or other applicable provisions.
Legal basis: compliance with a legal obligation to which the Controller is subject, pursuant to Article 6(1)(c) of the GDPR.
Retention period: the data are retained for the period provided for by applicable law or, where not expressly provided, for the time necessary to comply with such obligations.
4.5 Informational, promotional and commercial communications
Purpose: to send informational, promotional or commercial communications relating to the Controller’s services.
Legal basis: the data subject’s consent pursuant to Article 6(1)(a) of the GDPR, which may be freely withdrawn at any time.
Retention period: until consent is withdrawn and, in any event, for a period not exceeding 24 months from the time it was given, without prejudice to any renewal.
The provision of browsing data is necessary to enable the proper functioning of the Site and the use of the related services.
The provision of the data requested through the contact forms or through the other communication channels made available by the Controller is optional. However, failure to provide the data marked as necessary may make it impossible for the Controller to respond to the User’s requests or to allow access to specific services or features of the Site.
Personal data are processed by means of electronic and online tools and, where necessary, on paper, in compliance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity and confidentiality laid down by the GDPR.
The data are processed by personnel expressly authorised by the Controller, adequately instructed and trained, as well as, where necessary, by third parties appointed as Data Processors pursuant to Article 28 of the GDPR.
The Controller adopts appropriate technical and organisational measures pursuant to Articles 5 and 32 of the GDPR, designed to ensure a level of security appropriate to the risk and to prevent unauthorised access to, and the loss, destruction, disclosure, alteration or unlawful use of, the personal data processed.
The processing carried out through the Site does not currently involve any automated decision-making, including profiling, within the meaning of Article 22 of the GDPR.
Personal data may be communicated, within the limits strictly relevant to the purposes indicated in this notice, to the following categories of recipients:
The recipients will process the personal data, depending on the circumstances, as Data Processors pursuant to Article 28 of the GDPR or as independent data controllers (in particular, public authorities and professionals subject to their own legal obligations), in compliance with applicable law.
Any communication of personal data to third parties for processing, as independent data controllers, for their own marketing purposes will take place exclusively with the data subject’s specific prior consent pursuant to Article 6(1)(a) of the GDPR.
Personal data are processed predominantly within the European Union or the European Economic Area (EEA).
Where, for technical, organisational or operational reasons, it becomes necessary to transfer personal data to countries outside the European Economic Area, such transfer will take place in compliance with the conditions and safeguards provided for by Articles 44 et seq. of the GDPR, adopting, where necessary, the appropriate safeguards provided for by applicable law, such as adequacy decisions of the European Commission or Standard Contractual Clauses (SCCs).
Data subjects may request further information on international data transfers and on the safeguards adopted by contacting the Controller at the addresses indicated in this notice.
In the cases and within the limits provided for by Articles 15 et seq. of the GDPR, data subjects may exercise the following rights:
In order to exercise their rights or request information on the processing of their personal data, data subjects may contact the Controller at the addresses indicated in this notice.
The exercise of these rights is free of charge, except in the case of manifestly unfounded or excessive requests, in respect of which the Controller may apply the provisions of Article 12 of the GDPR.
The Controller reserves the right to amend or update this Privacy Policy at any time, including as a result of regulatory changes, updates to the services, developments in the Site’s features or changes in the manner in which personal data are processed.
Amendments will be published on the Site and will take effect from the date of their publication, unless otherwise indicated.
Users are invited to consult this notice periodically in order to check for any updates.
Last updated: April 2026