Close x

Receive Moisturizing Restructuring After Sun Balm 50 ml with every order until 09/08

Discover >

Receive Moisturizing Restructuring After Sun Balm 50 ml with every order until 09/08 + Free delivery on orders over 50 €.

Contact Us

Privacy policy

Revised on 25.05.2018

Collistar S.p.A., with legal domicile in Via G. B. Pirelli 19, Milan (MI), Italy, (henceforth “Company”, “us” or “we”), as acting data controller and subsidiary of the Bolton Group (henceforth “Group”), hereby gives notice of the purposes and methods for and whereby it collects, processes and communicates your personal data through the website (“Site”) and the correlated services (“Services”), in compliance with all applicable legislation and regulations concerning the protection of personal data and, in particular, with the requirements of: (I) EU regulation 679 of 27 April, 2016 ( General Data Protection Regulation or “GDPR”), applicable from 25 May 2018; and (ii) any other law, regulation or provision of competent national and European authorities concerning the protection of personal data (hereinafter referred to collectively as “applicable privacy legislation”).

Note that the aforementioned Services include the purchase of products sold by the Company and participating in prize competitions, lotteries, contests and/or any other initiative organized individually by the Company or in collaboration with the Group.


The Company is the data controller in charge of the processing of personal information (in other terms, any information relating to an identified or identifiable natural person, denominated the ‘data subject’) acquired directly from you via the Site and the Services. This data will be processed in accordance with the terms of this Informative Notice and in compliance with Applicable Privacy Legislation.

This Privacy Policy and our Cookie Policy are applicable to all users, including those who use the Site and Services without registering themselves as users or utilizing a specific service.


The Company gathers (1) data that you have voluntarily shared with us and (2) data relative to your activities on the Site or your interaction with the Services. In particular, the Company gathers the following categories of data:

1. Registration data: acquired via the registration form.

2. Activity data: we may collect certain information concerning your usage of the Site and interaction with Services during your visits to the Site itself and interaction with the Services. For example, to allow you to connect to the Site and access Services, our servers gather and store information concerning the computer/device and browser you use, which includes your IP address, browser type and, potentially, other information on the software and hardware used. If you access from a mobile or other device, the unique device identifier assigned to this device may be acquired. First-party and third-party cookies and other tracking technology may also be used to gather and store information relative to your usage of the Site or Services, such as the pages you have visited, the content viewed, searches made and ‘liked’ postings. For further information, see our Cookie Policy.

If the information acquired from and regarding the user do not identify the user as a specific person (e.g. raw data and aggregated or anonymous data) either directly or indirectly, this may be used for any purpose or shared with third parties to the extent permitted by applicable personal data protection legislation.

We do not collect special categories of personal data: you are expressly requested not to send us or share, via the Site or Services or any other means, any information classified as special categories of personal data (”sensitive data”), such as social security numbers and information revealing racial or ethnic origin, political opinions, religion or other beliefs, state of health, criminal convictions or trade union membership.


We process the personal data acquired from you and concerning you in order to:

a) allow you to register on the Site, and to use the Site and our Services;

b) evaluate and improve the usability of our Services and the user experience when browsing our Site;

c) provide you with support, handle correspondence with you and send you service notifications;

d) process your purchase requests correctly in compliance with all the legal, administrative, accounting and fiscal obligations associated with purchases;

e) comply with legal requirements and respond to requests from state and public authorities;

f) verify the completeness, validity and correctness of the data provided to safeguard the rights of the Company and of other parties and, specifically, (ii) to ensure the security and privacy of the users of the Site and Services; and (iii) to protect against digital fraud;

g) to provide you, subject to your facultative consent, with commercial material and news concerning Collistar products and events via automated channels (SMS, MMS, e-mail, automated voice calls etc.) and non-automated channels (telephone calls with operator or printed correspondence).

Where the data acquired from you or concerning you does not identify you personally, we may use this information for other purposes or divulge it to third parties.


The processing of your personal data in accordance with:

a) paragraph 3, sub-paragraphs a), b), c) and d) of this Privacy Policy is necessary for the management of the website and the delivery of the Services;

b) paragraph 3, sub-paragraph e) of this Privacy Policy is a mandatory requirement of applicable legislation;

c) paragraph 3, sub-paragraph f) of this Privacy Policy is, where applicable, required for the pursuit of the legitimate interests of the company;

d) paragraph 3, sub-paragraph g) of this Privacy Policy, is subject to the facultative consent of the user.

These data processing activities are not mandatory, and the user may object to said processing or revoke their consent (where required) at any time with the methods described in paragraph 10 of this Privacy Policy. While the provision of the requested data is not mandatory, failure to do so will make it impossible for you to register on the site and for us to handle your request and process any purchases you intend to make.


The Company retains and processes your personal data for no longer than the period of time necessary for the purposes defined in paragraph 3. In any case, the following maximum time limits apply for the retention of your personal data:

a) data acquired for the purposes defined in paragraph 3, sub-paragraphs a), b), c) and d) is kept solely for the period of time strictly necessary to allow the user to use the Site or Services;

b) data acquired for the purposes defined in paragraph 3, sub-paragraph e) is kept for ten (10) years in order to fulfill legal and regulatory obligations;

c) data acquired for the purposes defined in paragraph 3, sub-paragraph f) is kept solely for the period of time strictly necessary to pursue the legitimate interests of the company;

d) data acquired for the purposes defined in paragraph 3, sub-paragraph g) is kept solely for the period of time strictly necessary to accomplish the purposes for which it was originally acquired and, in any case, will be deleted once the user ceases to interact with the Site or decides to revoke their consent.


Personal data is processed for the purposes defined above with electronic and manual means, and is protected with adequate security measures. In this regard, while the Company implements commensurate administrative, technical and physical measures to safeguard the data in its possession against loss, theft, unauthorized, dissemination and modification, it cannot guarantee against all possible digital risks.


For purposes conformant with those defined in paragraph 3 of this Privacy Policy, the Company may divulge personal data to the following categories of recipient within the European Union, in compliance with the provisions and limitations indicated in paragraph 7 of this Privacy Policy:

a) Other subsidiaries of the Group, where necessary and where the applicable conditions are met;

b) Third-party service providers appointed to carry out data processing activities as data processors or sub-processors, and officially nominated as such where required by applicable legislation (e.g. cloud service providers, providers of instrumental or accessory services for the delivery of Services - including, but not limited to: banking institutions, for the management of payments and revenue relative to purchases; IT service providers; direct marketing service providers; experts; consultants and lawyers; and companies deriving from mergers, demergers or other transformations); and

c) Competent national authorities, in order to comply with applicable legislation;


We do not transmit personal data to countries situated outside the European Economic Area (EEA).


The Site is not intended for use by persons under the age of 18 years and the Company does not knowingly gather the personal information of minors.


The user has the following rights, which he/she may exercise at any time at no cost:

a) the right to be informed of the purposes and methods of processing;

b) the right of access;

c) the right to obtain a copy of any data held in a foreign country, and information identifying the place in which this data is kept;

d) the right to request that their personal data is updated, rectified or amended;

e) the right to request the deletion, anonymization or blockage of their personal data;

f) the right to object to the processing and dissemination of their personal data, in whole or in part, even where said activities are conducted with an automated decision-making process;

g) the right to revoke their consent for the processing of their personal information, freely and at any time;

h) the right to contact the data protection officer, where applicable;

i) the right to lodge a complaint with the competent national data protection supervisory authority or judicial authorities;

j) the right to data portability, in other terms, the right to request an electronic copy of the personal data concerning them, which may be transferred to the user or to a different data controller;

k) right to restriction of processing.


The data controller is Collistar SpA, with legal domicile in Via G. B. Pirelli 19, Milan (MI), Italy. Please address any correspondence regarding this Informative Notice to the address of the operational head office of the Data Controller, at Via G. B. Pirelli 19, Milan (MI), Italy, or to the e-mail address

In compliance with article 37 of the Privacy Regulation, the Personal Data Protection Officer may be contacted by writing to the e-mail address, or to the physical address Via G. B. Pirelli 19, Milan (MI), Italy.


This Privacy Policy entered into effect on 25 May 2018. The Company may modify and/or amend this Privacy Policy to reflect any modifications and/or amendments to applicable legislation concerning personal data protection. Prior notification of any such modification will be given in advance by the Company, while the latest version of this Policy will always be available on this web page.


We are available from Monday to Friday 8.30 a.m. 1 p.m. and 2.30 p.m. to 6 p.m.

 Send us an email at

This website uses cookies (including third-party cookies) to send you advertising and services based on your preferences. To find out more or stop receiving some or all cookies, click here. By closing this banner, scrolling up or down the page or clicking anywhere on the page, you give your consent for the cookies. OK