Privacy Policy
Last updated: 14 September 2026
This notice explains how NOEMA VISION S.r.l. handles personal data in connection with its website, B2B portal, retailer applications, orders and support requests, including those concerning GLARE and Opificio Cadorino. It applies to individual customers and to the people who represent or work for our business customers.
1. Who is responsible for your data?
NOEMA VISION S.r.l. is the data controller.
Registered office: Via G. Casaregis 50/7, 16129 Genova (GE), Italy.
VAT number: IT02015150994.
Email: info@noemavision.com.
Telephone: +39 010 8441012.
You can use these contact details for questions about this notice or to exercise your data protection rights.
2. Data we use and where it comes from
- Contact and business details: name, business email, telephone, company or optical store, VAT or tax number, country, addresses and information supplied in a retailer application.
- Account information: login credentials, account status, access permissions, registration requests and account recovery information.
- Orders and payments: products, delivery and invoicing details, order history, agreed payment terms, payment status and transaction references.
- Enquiries and assistance: messages, product references, warranty information and photographs or documents you choose to submit. Please provide only information relevant to the request and avoid including patient details, health information or unrelated personal data.
- Technical information: IP address, browser and device information, access times, request logs and information needed to operate and protect the website.
Data comes from you, your company and its authorised representatives, communications with our team, and our existing commercial records. For existing NOEMA customers, a B2B profile may be prepared from customer records, invoices and past orders, including the business contact details and payment terms already held by NOEMA. You can ask us to correct outdated details or help you recover access. Importing a customer record does not by itself constitute consent to marketing.
3. Why we use your data and our legal grounds
- Applications, enquiries and B2B access: to respond to requests, assess professional eligibility, create or recover an account and provide the requested service. The grounds are steps requested before entering a contract or performance of a contract (Article 6(1)(b) GDPR). When you act for a company, our legitimate interest in managing that business relationship also applies (Article 6(1)(f)).
- Orders, deliveries, payments and after-sales support: to fulfil contracts and handle related requests (Article 6(1)(b)); for business representatives, to manage the commercial relationship (Article 6(1)(f)).
- Invoicing and legal requirements: to meet applicable tax, accounting and other legal obligations (Article 6(1)(c)).
- Security and protection of rights: to prevent misuse, verify account recovery requests, maintain service reliability and establish, exercise or defend legal claims. These are our legitimate interests (Article 6(1)(f)), assessed against your rights and interests.
- Optional marketing: on consent where required (Article 6(1)(a)). Any permitted existing-customer exception is limited to its applicable legal conditions and includes an opportunity to object.
Reading this notice, submitting a service request or opening a B2B account does not give general consent to promotional communications.
4. Required information and account approval
Fields marked as required are needed to assess an application, respond to a request, process an order or comply with invoicing obligations. If they are not provided, we may be unable to supply the relevant service. Optional fields can be left blank.
Access to the professional area is subject to NOEMA approval. Technical checks may match an email address or VAT number with existing records to prevent duplicate accounts and support account recovery. Contact our team if a match is incorrect or you cannot access the registered email address. You can request a review of an account access or approval issue.
5. Who can receive your data?
Data may be accessed by authorised NOEMA staff and by providers involved in delivering the relevant service: website hosting and technical support, business email, payment processing, banks, delivery companies, accounting and professional advisers, and providers used for communications. Authorities may receive data where disclosure is required by law.
The portal uses Hostinger for hosting, Google for business email and Stripe for card payments. Providers may act as processors on our behalf or as independent controllers for their own payment, regulatory or security obligations, depending on their role.
Card details are handled through the payment provider. NOEMA uses the payment confirmation and transaction information needed to manage the order. Do not send card numbers or security codes through contact forms or email.
6. Processing outside the European Economic Area
International service providers may process data in countries outside the European Economic Area. Where this occurs, a lawful transfer mechanism is required under Chapter V GDPR, such as an applicable European Commission adequacy decision or standard contractual clauses with appropriate safeguards. You can contact us for information about the safeguards applicable to your data and how to obtain a copy.
7. How long is data kept?
Retention depends on the purpose and on applicable legal obligations:
- Account and business contact data: for the period needed to provide account access and manage the commercial relationship; further retention must relate to a legal obligation, an outstanding matter or the protection of rights.
- Orders, invoices and payment records: for the retention periods required by applicable tax and accounting law, and longer where a specific dispute or legal requirement makes this necessary.
- Enquiries, applications and support attachments: for the time needed to assess or resolve the request and document any resulting service, warranty obligation or dispute.
- Technical and security logs: for the period needed to operate, troubleshoot and secure the service, taking account of any incident requiring investigation.
- Marketing preferences: until consent is withdrawn or an objection is made, subject to any earlier loss of the basis for processing. A minimal record of an opt-out may be retained to honour that choice.
These criteria also apply to historical customer records used for B2B access. Closing an account does not remove records that must be retained for tax, accounting or legal reasons. Contact us for the retention criteria applicable to a particular record or to request erasure where available.
8. Cookies and external services
The portal uses cookies and similar storage for functions such as sign-in, account sessions, shopping baskets and security. These functions may not work correctly if the relevant cookies are blocked or deleted in your browser. Technical cookies necessary to provide a service requested by you do not require marketing consent.
Optional advertising or other non-essential tracking requires consent where applicable; it cannot be authorised simply by continuing to browse or by accepting this privacy notice. If optional tracking is offered, the relevant notice and preference controls must explain its purpose and allow the applicable choice.
Links to brand websites, maps and other external sites lead to services governed by their own privacy notices. The Italian Data Protection Authority’s cookie guidance explains the distinction between technical cookies and tracking that requires consent.
9. Marketing choices
You can unsubscribe using the link in a promotional email or write to info@noemavision.com. Withdrawing consent does not affect processing that was lawful before withdrawal. An objection to direct marketing stops processing for that purpose.
Necessary service messages, such as password recovery, account decisions and order updates, are separate from marketing and may still be sent when needed to provide the service.
10. Your rights
Subject to the conditions in the GDPR, you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing and portability. You may object to processing based on legitimate interests on grounds relating to your situation, and to direct marketing at any time. You may withdraw consent where processing relies on it.
Send requests to info@noemavision.com. We may request proportionate information to verify your identity. Requests are normally answered within one month; any permitted extension and its reasons will be communicated within that period.
You may lodge a complaint with the Garante per la protezione dei dati personali or another competent supervisory authority, including in the country where you normally live or work. This does not affect your other available remedies.
11. Security and responsible use
Personal data is handled through the portal, business systems and communications needed for the purposes above. Keep your account credentials confidential and tell us promptly if you suspect unauthorised access. When supplying information about colleagues or other people, ensure that you are authorised to do so and make this notice available to them.
The portal is intended for professional business use. Please contact us if personal data has been submitted in error so that we can assess the appropriate action.
12. Changes and contact
The date at the top identifies this version. We may update the notice when the portal, processing activities or legal requirements change. Where required, material changes will be communicated and any necessary consent requested before the relevant new processing begins.
For privacy questions, corrections to an existing customer record or help exercising your rights, contact info@noemavision.com. Further information about the legal framework is available from the GDPR information page of the Italian Data Protection Authority.