This Privacy Policy explains how we collect, use, and process your personal data when you use our online store at https://asseto3d.com. We are committed to protecting your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and ensuring your data is handled securely and lawfully.
Data Controller
The data controller is the operator of this online store. For any questions or requests related to your personal data, you can contact us via email: info@asseto3d.com
Data We Collect
We may collect the following categories of personal data:
- Email address
- Order and transaction details
- IP address and device data
- Cookies and session-related technical data
- Name and other contact information (if voluntarily provided)
We do not collect any sensitive personal data (special categories of data under Article 9 of the UK GDPR).
Purpose and Legal Basis for Processing
We process your personal data only for specific and legitimate purposes, based on the legal grounds provided by the UK GDPR:
- To fulfil and manage orders – based on the necessity for contract performance
- To comply with legal obligations, such as tax or accounting – based on legal compliance
- To prevent fraud, provide support, and improve our services – based on our legitimate interest
- To send marketing communications – only with your prior consent
Cookies and Analytics
We use cookies and analytics tools to improve the website’s performance. Analytics tools (e.g. Google Analytics or similar) are only activated after you provide consent through the cookie banner or settings. For more information, see our Cookie Policy.
Data Sharing
We do not sell your personal data. We may share it only with third parties where necessary to operate our store:
- Payment processors (e.g. Stripe, PayPal)
- Hosting and cloud service providers
- Legal and accounting advisors (if applicable)
- Competent public authorities – only as required by law
If data is transferred outside the UK or EEA, we ensure an adequate level of protection through appropriate safeguards such as Standard Contractual Clauses (SCC) or equivalent mechanisms recognised under UK law.
Data Retention
We retain personal data only as long as necessary for the purposes described above or to comply with legal obligations:
- Orders and transaction data – at least 6 years (in accordance with UK tax and accounting requirements)
- Contact details – until consent is withdrawn or 2 years of inactivity
- Cookies – according to their specific expiration periods (see Cookie Policy)
Your Rights Under UK GDPR
You have the following rights under the UK GDPR:
- Right to access your data
- Right to rectify inaccurate data
- Right to erasure (“right to be forgotten”)
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time
- Right to lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk
To exercise these rights, please contact us via the email provided above.
Data Security
We implement appropriate technical and organisational measures to ensure the security of your personal data, including encryption, access control, authentication, and system monitoring.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on users.
Changes to This Policy
We may update this Privacy Policy to reflect changes in data practices or legal requirements. Updates will be published on this page with the revised date.
Data Controller
This website is owned and operated by:
SOTUS TELECOM LTD: Studio No. 15, 2 Old Brompton Road, London, England, SW7 3DQ. Company number 07132865
Email: info@asseto3d.com
Phone: +447458148544
Website: https://asseto3d.com
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, SOTUS TELECOM LTD is the data controller responsible for the processing of your personal data.
Payment Card Data and PCI DSS Compliance
We take the security of your payment information very seriously. When you pay for an order on asseto3d.com, your card details (including the full card number, expiry date and CVV/CVC) are entered directly into a secure form hosted by our payment service provider and are transmitted over an encrypted TLS connection.
We do not store, process or transmit full cardholder data on our own servers. The handling of cardholder data is delegated to acquiring banks and payment service providers that are certified as compliant with the Payment Card Industry Data Security Standard (PCI DSS) at the level required by the card schemes (Visa, Mastercard).
Depending on the payment method selected, transactions may be authenticated using 3‑D Secure (Verified by Visa / Mastercard Identity Check) to reduce the risk of unauthorised use of your card.
The personal data that may be stored by us in relation to a payment is limited to: a transaction reference issued by the payment provider, the billing name and address, the card network (e.g. Visa, Mastercard), the last four digits of the card, the issuer country, the authorisation result and the amount and currency of the transaction. This information is retained only for the purposes described in the “Retention of Data” section of this Privacy Policy and, where applicable, to meet our legal obligations (for example, under anti-money-laundering and accounting legislation).
Card Data and PCI DSS Compliance
SOTUS TELECOM LIMITED does not store, process, or transmit raw cardholder data on its own servers. All card payments are handled exclusively by our PCI DSS Level 1 certified payment service provider — the highest tier of compliance defined by the Payment Card Industry Security Standards Council (PCI SSC).
When you submit card details on our checkout page, the data is transmitted directly to the payment processor over an encrypted TLS 1.2+ connection, tokenized at the gateway, and never reaches our infrastructure. The only payment-related information we retain on our side is:
- the transaction reference (provided by the gateway);
- the last four digits of the card and the card brand (Visa, Mastercard, etc.) — for order-management, refunds, and chargeback evidence;
- the billing name, address, and email address you provided at checkout — for invoicing and customer-support purposes.
If you exercise your right to access, rectify, or delete your data under the UK GDPR or the EU GDPR (see Your Rights section above), the order metadata may be retained for up to seven (7) years after the transaction in compliance with anti-money-laundering, accounting, and tax-record-keeping obligations applicable to SOTUS TELECOM LIMITED.
For details on how the payment provider itself handles your data, please consult the privacy notice of the gateway disclosed at the moment of checkout.