Privacy Policy
Last updated: 5 August 2025
1. About this notice
This privacy notice explains how Tessiland Limited, trading as Piazza Castello, collects, uses, stores and shares personal information.
It applies when you:
- visit or use our website;
- create an account or place an order;
- shop at one of our stores;
- contact customer service;
- request a return, exchange, alteration or made-to-measure service;
- subscribe to marketing communications;
- enter a competition, promotion or event;
- interact with us through social media; or
- otherwise provide personal information to us.
This notice should be read together with our Cookie Policy, Terms of Service and any additional privacy information provided when we collect particular information from you.
2. Who we are
Tessiland Limited is the controller responsible for your personal information.
Company name: Tessiland Limited
Trading name: Piazza Castello
Company number: 11292234
Registered office: 207 Kings Road, London, England, SW3 5ED
Email: support@piazzacastello.com
Data-protection complaints: Please email as at support@piazzacastello.com for any issues.
In this notice, “Piazza Castello”, “we”, “us” and “our” mean Tessiland Limited.
We have appointed a person responsible for overseeing data-protection matters. You can contact that person using the details above and marking your correspondence “For the attention of the Data Protection Lead.”
We are not currently required to appoint a statutory data protection officer. [Confirm this before publication.]
3. Personal information we collect
Depending on how you interact with us, we may collect the following categories of personal information.
Identity information
This may include your:
- name;
- title;
- date of birth, where genuinely required;
- username or account identifier;
- signature; and
- proof of identity where reasonably necessary to verify a rights request, prevent fraud or meet a legal obligation.
Contact information
This may include your:
- billing address;
- delivery address;
- email address;
- telephone number; and
- social-media contact details.
Account information
This may include:
- your account login details;
- saved addresses;
- order history;
- saved preferences;
- wish-list information; and
- communication settings.
We do not have access to your account password in readable form.
Order and transaction information
This may include:
- products purchased or considered;
- order value;
- order date;
- gift-card information;
- discounts or promotional codes;
- delivery and collection details;
- customs information;
- return, refund and exchange records;
- alterations and repair records; and
- information relating to complaints, warranties and product claims.
Payment-related information
Payment information may include:
- the selected payment method;
- payment status;
- transaction references;
- partial card details, such as the last four digits;
- billing information; and
- fraud-screening results.
Payments are processed through authorised payment providers. We do not ordinarily receive or store complete payment-card numbers or card security codes. [Confirm this against every payment method offered, including in-store payments.]
Customer-service information
This may include:
- emails, messages and correspondence;
- telephone call notes or recordings, where calls are recorded;
- live-chat transcripts;
- enquiries and complaints;
- information you provide about an order;
- records of resolutions offered; and
- feedback about our products or service.
We will tell you if a telephone call is being recorded.
Marketing and preference information
This may include:
- whether you have agreed to receive marketing;
- your preferred communication channels;
- the types of products that interest you;
- responses to promotions;
- email delivery, opening and interaction information;
- your marketing opt-in and opt-out history; and
- information used to avoid sending you irrelevant or repeated communications.
Website, device and usage information
This may include:
- IP address;
- browser type and version;
- device type;
- operating system;
- language;
- time zone;
- approximate location derived from an IP address;
- pages viewed;
- links selected;
- products viewed or added to a basket;
- referring website;
- website session information;
- error and performance information; and
- cookie or similar technology identifiers.
More information is provided in section 9 and in our Cookie Policy.
Made-to-measure and alteration information
Where you use our made-to-measure, tailoring or alteration services, we may collect:
- body measurements;
- fit and styling preferences;
- alteration requirements;
- appointment information;
- photographs provided for fitting purposes; and
- notes needed to prepare or alter a garment.
Body measurements are not ordinarily special-category personal information. However, information about a medical condition, disability or other health matter may be special-category information. We will only collect such information where it is necessary to provide the requested service and where we have an appropriate legal basis and condition for doing so.
Store and security information
Where used in our stores or premises, we may collect:
- CCTV images;
- information concerning suspected theft, fraud or misconduct;
- accident and incident reports; and
- building access or visitor information.
Appropriate signs will be displayed where CCTV is in operation. [Confirm which locations use CCTV and publish a separate CCTV notice where appropriate.]
Competition, event and ambassador information
Where applicable, this may include:
- competition entries;
- event registrations;
- eligibility information;
- social-media handles;
- photographs or content submitted by you;
- delivery information for prizes or products;
- ambassador agreements; and
- records required to administer the relevant arrangement.
Information about other people
You may provide information about another person, for example when sending a gift, providing an alternative collection contact or naming the recipient of a delivery.
You should only provide another person’s information where you are authorised to do so. Where appropriate, please direct that person to this privacy notice.
4. Information we do not normally request
We do not normally ask customers to provide information about:
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade-union membership;
- genetic information;
- biometric information used for identification;
- health;
- sex life or sexual orientation; or
- criminal convictions and offences.
Please do not provide this type of information unless it is genuinely necessary and we have asked you to do so.
Where we need to process special-category or criminal-offence information, we will identify an additional legal condition and provide further information where required.
5. How we obtain personal information
We obtain personal information:
Directly from you
This includes information provided when you:
- place an order;
- create an account;
- make a payment;
- subscribe to marketing;
- contact customer service;
- visit a store;
- book an appointment;
- request alterations or made-to-measure services;
- complete a form;
- leave a review;
- enter a promotion; or
- exercise a data-protection right.
Automatically
We may collect technical and usage information through:
- cookies;
- pixels;
- software development kits;
- local storage;
- server logs; and
- similar technologies.
Non-essential technologies are used only where permitted under applicable law and subject to the choices described in section 9.
From other organisations
We may receive information from:
- our e-commerce and website platform providers;
- payment providers;
- fraud-prevention and identity-verification providers;
- delivery and returns providers;
- customer-support platforms;
- marketing and analytics providers;
- social-media platforms;
- review providers;
- event or competition partners; and
- publicly available sources where the use is fair and lawful.
We may also receive updated delivery or contact information from a courier, payment provider or customer-service provider in connection with your order.
6. How we use personal information and our lawful bases
UK data-protection law requires us to have a valid lawful basis for each use of personal information.
| What we do | Lawful basis |
|---|---|
| Create and manage your account | Performance of a contract, or steps requested before entering into a contract |
| Process, accept, deliver and manage an order | Performance of a contract |
| Take and administer payment | Performance of a contract and our legitimate interests in receiving payment and maintaining accurate records |
| Arrange delivery, collection, returns, refunds and exchanges | Performance of a contract and compliance with legal obligations |
| Provide tailoring, alteration or made-to-measure services | Performance of a contract |
| Provide customer service and respond to enquiries | Performance of a contract where the enquiry concerns an order, and legitimate interests in providing customer service in other cases |
| Handle complaints, warranties and product claims | Performance of a contract, compliance with legal obligations and legitimate interests in resolving disputes |
| Keep accounting, customs, VAT and tax records | Compliance with legal obligations |
| Prevent and investigate fraud, theft, misuse and security incidents | Legitimate interests in protecting customers, our business and payment systems, and compliance with legal obligations where applicable |
| Verify identity in connection with an order or rights request | Legitimate interests in protecting personal information and preventing fraud, and compliance with legal obligations |
| Operate, secure and maintain our website and systems | Legitimate interests in operating a secure and reliable retail business |
| Analyse website performance and improve our services | Consent where required for cookies or similar technologies; otherwise legitimate interests where an applicable legal exception permits the processing |
| Remember preferences and provide optional website functions | Consent where required; otherwise legitimate interests where an applicable legal exception applies |
| Personalise content, products or marketing | Consent where required, or legitimate interests where the use is limited, expected and permitted by law |
| Send marketing emails or text messages | Consent, or the existing-customer exception known as the soft opt-in where its legal conditions are met |
| Maintain a record of marketing objections | Compliance with legal obligations and legitimate interests in respecting your preferences |
| Administer competitions, events and promotions | Performance of the relevant promotion terms, consent where appropriate, and legitimate interests in administering the activity |
| Publish a review, photograph or other submitted content | Consent or performance of the applicable submission terms, depending on the circumstances |
| Operate CCTV and protect stores, staff and customers | Legitimate interests in security, crime prevention and the investigation of incidents |
| Establish, exercise or defend legal claims | Legitimate interests and, where applicable, compliance with legal obligations |
| Respond to regulators, courts, police or other authorities | Compliance with legal obligations, recognised legitimate interests where applicable, and legitimate interests in protecting legal rights |
| Restructure, sell or transfer part of our business | Legitimate interests in managing and developing our business, subject to appropriate safeguards |
Where we rely on legitimate interests, those interests may include:
- operating and improving our retail business;
- delivering effective customer service;
- protecting customers, staff, stores and systems;
- preventing fraud and misuse;
- keeping appropriate business records;
- understanding how customers use our services;
- promoting relevant products in a proportionate manner; and
- enforcing or defending our legal rights.
Before relying on ordinary legitimate interests, we consider whether the processing is necessary and whether your interests, rights or freedoms override our interests.
We will not use personal information for a purpose that is incompatible with the reason it was collected unless the use is permitted by law. Where required, we will provide additional information before beginning a materially different use.
7. When information is required
Certain information is needed to enter into or perform a contract with you. For example, we normally need your name, contact details, delivery information and payment information to fulfil an online order.
Where required information is not provided, we may be unable to:
- create an account;
- accept or deliver an order;
- process payment;
- issue a refund;
- provide tailoring or alteration services; or
- respond properly to a request.
Optional fields will be identified where reasonably possible.
8. Marketing communications
We may send you information about Piazza Castello products, collections, events, promotions and services where:
- you have consented to receive it; or
- you are an existing customer and the legal soft opt-in conditions are met.
Where we rely on the soft opt-in, we will only market our own similar products or services, and we will have offered you a clear opportunity to opt out when we obtained your details and in every subsequent message.
We do not treat an order-service communication, such as an order confirmation, delivery update, recall notice or return message, as marketing.
You can stop marketing at any time by:
- selecting the unsubscribe link in an email;
- using the preference link provided in a message;
- changing your account preferences, where available; or
- contacting support@piazzacastello.com.
Withdrawing from marketing will not prevent us from sending necessary service messages about an active order or account.
After you unsubscribe, we may retain your email address or other contact identifier on a suppression list. This allows us to honour your request and avoid adding you back to a marketing list accidentally.
We do not sell marketing lists containing our customers’ personal information.
9. Cookies and similar technologies
Our website uses cookies and similar technologies for purposes that may include:
- operating the shopping basket and checkout;
- maintaining security;
- remembering your country, language and currency;
- maintaining account sessions;
- remembering optional preferences;
- measuring website performance;
- understanding how visitors use the website;
- personalising content; and
- measuring or delivering advertising.
Strictly necessary technologies
Technologies that are strictly necessary to provide a service requested by you, maintain security or complete checkout may be used without consent where the law permits.
Functional and statistical technologies
Some limited functional or statistical technologies may qualify for a legal exception from consent. Where we rely on such an exception, we will provide clear information and a simple way to object where required.
Where an exception does not apply, we will obtain consent before using these technologies.
Advertising and cross-site tracking
We will not activate advertising, behavioural tracking or social-media targeting technologies unless you have given the required consent.
You can accept, reject or change non-essential cookie choices through our cookie banner or the Cookie Preferences link in the website footer.
Rejecting non-essential cookies will not prevent you from making a purchase, although some optional features may not function as intended.
Our separate Cookie Policy or cookie preference centre identifies, for each technology where possible:
- its name;
- its provider;
- its purpose;
- whether it is first-party or third-party;
- its duration; and
- how to manage it.
We periodically review our website to ensure the published cookie information matches the technologies actually in use.
10. Who we share personal information with
We share personal information only where reasonably necessary for the purposes described in this notice.
Recipients may include:
E-commerce and technology providers
This includes providers that host or operate our website, online store, databases, account functions and related infrastructure, including Shopify group companies where they provide our e-commerce platform.
Payment providers
Payment processors, card networks, banks, digital-wallet providers and providers offering a payment method selected by you may process information needed to authorise and manage a transaction.
Some payment providers act as independent controllers and provide their own privacy information.
Delivery, fulfilment and returns providers
We share necessary information with:
- couriers;
- postal operators;
- customs agents;
- warehouses;
- collection points;
- fulfilment providers; and
- returns-service providers.
This may include your name, delivery address, email address, telephone number and order information.
Fraud-prevention and security providers
We may share information with providers that help us:
- verify transactions;
- identify suspicious activity;
- protect accounts;
- prevent payment fraud; and
- investigate security incidents.
Customer-service providers
This may include providers of:
- email;
- telephone systems;
- live chat;
- appointment booking;
- customer-service software; and
- complaint-management tools.
Marketing, analytics and advertising providers
Where legally permitted and subject to your cookie and marketing choices, we may share information with providers that help us:
- distribute marketing messages;
- measure campaign performance;
- analyse website use;
- personalise communications; or
- advertise on third-party platforms.
Professional advisers
We may disclose information to our:
- accountants;
- auditors;
- insurers;
- banks;
- legal advisers;
- tax advisers; and
- other professional consultants.
Public authorities and legal recipients
We may disclose information where required or permitted to:
- courts;
- regulators;
- tax and customs authorities;
- police and law-enforcement bodies;
- government departments; or
- parties involved in legal proceedings.
Business transactions
If we sell, acquire, finance, reorganise or transfer all or part of the business, relevant personal information may be disclosed to prospective or actual purchasers, investors, advisers or other parties, subject to confidentiality and appropriate safeguards.
At your request
We may share information with another organisation where you ask or authorise us to do so.
We require providers acting on our instructions to protect personal information, use it only for agreed purposes and comply with applicable data-protection requirements.
A current list of our principal processors and other key recipients is available by contacting support@piazzacastello.com. [The company should maintain this list internally and consider publishing it as an appendix.]
11. International transfers
Some of our service providers, their group companies or their technical infrastructure may be located outside the United Kingdom.
Where personal information is transferred to a country that is not covered by UK adequacy regulations, we use an appropriate transfer mechanism where required, such as:
- the United Kingdom International Data Transfer Agreement;
- the United Kingdom Addendum to the European Commission’s standard contractual clauses;
- another approved contractual safeguard; or
- a legally permitted exception for a specific transfer.
We also assess relevant risks and apply additional protections where appropriate.
You may contact us for more information about the safeguards used for a particular transfer and, where legally available, request a copy. Information may be redacted where necessary to protect commercial confidentiality or the rights of others.
[Before publication, identify every country outside the UK in which customer information is stored or accessed, including locations used by Shopify, payment providers, marketing platforms, support tools and analytics providers.]
12. How long we keep personal information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, tax, fraud-prevention and dispute-resolution purposes.
Our proposed standard periods are:
| Record | Proposed retention period |
|---|---|
| Orders, invoices, payments and accounting records | Six years from the end of the financial year to which the record relates, or longer where legally required |
| Basic customer account | While the account is active and normally for two years after closure or the last meaningful activity |
| Information within an account that forms part of an order record | The applicable order or accounting retention period |
| Customer-service enquiries not linked to a transaction | Normally three years after the enquiry is closed |
| Returns, refunds, warranties and complaints | Normally six years after resolution where connected with a purchase or possible legal claim |
| Made-to-measure and alteration measurements | Normally three years after the last relevant service, unless you ask us to retain them for future orders or request earlier deletion |
| Marketing contact information | Until consent is withdrawn, you object, or the information is no longer reasonably required, subject to periodic review |
| Marketing suppression records | For as long as necessary to ensure we continue to honour the opt-out |
| Abandoned baskets | Normally 30 days, unless retained for longer with consent or as part of a customer account |
| Cookie and online identifier information | As stated in the cookie preference centre or Cookie Policy |
| Fraud and security records | Normally two years, or up to six years where associated with an investigation, dispute or legal claim |
| CCTV recordings | Normally 30 days, unless footage is required for an incident, investigation or legal claim |
| Competition entries | Normally six months after the competition ends; winner records may be retained for longer where required for accounting or legal purposes |
| Data-protection requests and complaints | Normally three years after final resolution |
| Consent records | For as long as needed to demonstrate the consent and for a reasonable period afterwards |
These periods may be shortened or extended where:
- the information is no longer needed;
- a legal obligation requires longer retention;
- a dispute or investigation is active;
- a court or regulator requires preservation;
- there is a reasonable prospect of legal proceedings; or
- you exercise a right that requires deletion or restriction.
At the end of the applicable period, information will be deleted, anonymised or placed beyond ordinary use.
13. Security
We use appropriate technical and organisational measures designed to protect personal information against:
- unauthorised access;
- loss;
- misuse;
- alteration;
- disclosure; and
- destruction.
Measures may include:
- access controls;
- authentication;
- encryption where appropriate;
- secure payment processing;
- system monitoring;
- backups;
- staff confidentiality obligations;
- staff training;
- processor due diligence; and
- incident-response procedures.
Access to personal information is limited to staff members, contractors and providers who need it for an authorised purpose.
No internet-based system is completely risk-free. However, we do not ask you to waive legal rights or accept responsibility for a security breach caused by our failure to comply with data-protection law.
Where a personal-data breach creates a legal duty to notify you or the Information Commissioner, we will provide the required notification.
14. Children
Our website and retail services are intended primarily for adults. We do not knowingly invite children to create accounts, subscribe to marketing or make purchases without appropriate adult involvement.
Where we learn that we have collected a child’s information inappropriately, we will take reasonable steps to delete or otherwise address it.
A parent or guardian who believes that a child has provided information to us should contact support@piazzacastello.com.
Where our online services are likely to be accessed by children, we will take their needs into account when designing how personal information is used and protected.
15. Automated decision-making and profiling
We may use automated tools to:
- detect suspected fraud;
- identify unusual account or payment activity;
- personalise website content;
- select marketing audiences; or
- recommend products.
Most of these activities do not produce legal or similarly significant effects.
A payment provider or fraud-prevention provider may use automated screening when deciding whether to authorise or flag a transaction. Where a decision is made solely through automated processing and has a legal or similarly significant effect on you, we will apply the safeguards required by law. Depending on the circumstances, these may include the ability to:
- obtain meaningful information about the decision;
- express your point of view;
- contest the decision; and
- request human intervention.
You can contact us if you believe an order or account decision was made solely through automated processing.
16. Your data-protection rights
Depending on the circumstances and the lawful basis being used, you may have the right to:
Access
You can ask whether we process your personal information and request a copy, together with related information about its use.
Rectification
You can ask us to correct information that is inaccurate or complete information that is incomplete.
Erasure
You can ask us to delete personal information in circumstances where there is no continuing lawful reason to retain it.
The right to erasure is not absolute. For example, we may need to retain transaction information to comply with tax obligations or defend a legal claim.
Restriction
You can ask us to restrict the use of information in certain circumstances, including while its accuracy or lawful use is being considered.
Data portability
Where processing is based on consent or contract and carried out by automated means, you may be able to receive information you provided in a structured, commonly used and machine-readable format, or ask us to transfer it to another controller where technically feasible.
Object to processing
You may object to processing based on ordinary legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the information is required for legal claims.
Object to direct marketing
You have the right to object at any time to our use of your personal information for direct marketing, including related profiling. When you object, we will stop using your information for that purpose.
Withdraw consent
Where we rely on consent, you may withdraw it at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Rights concerning automated decisions
Where applicable, you have rights and safeguards in relation to decisions based solely on automated processing that have legal or similarly significant effects.
17. How to exercise your rights
To exercise a right, contact:
Email: support@piazzacastello.com
Postal address: Data Protection Lead, Tessiland Limited, 207 Kings Road, London, England, SW3 5ED
You do not need to use particular wording or complete a specific form.
We may ask for information reasonably necessary to:
- confirm your identity;
- locate the relevant records; or
- clarify the information or processing covered by your request.
We will not request excessive identification information.
We normally respond without undue delay and within one month. Where the law permits, the period may be extended for a complex request or multiple requests. The response period may also be paused where reasonably necessary information or clarification is required.
Rights requests are normally free. We may charge a reasonable fee or refuse to act only where the law permits, including where a request is manifestly unfounded or excessive or where additional copies are requested.
Certain rights are subject to exemptions and may not apply in every situation. If we cannot comply fully, we will explain the reason unless the law prevents us from doing so.
18. Data-protection complaints
You can complain to us if you believe that we have:
- used your information unfairly or unlawfully;
- failed to keep it secure;
- retained it for too long;
- sent unwanted marketing;
- failed to respect a data-protection right; or
- otherwise failed to comply with data-protection law.
You can submit a complaint through:
Email: support@piazzacastello.com
Post: Data Protection Complaint, Tessiland Limited, 207 Kings Road, London, England, SW3 5ED
Please include:
- your name and contact details;
- a description of the concern;
- relevant dates, order references or communications;
- the outcome you are seeking; and
- copies of relevant supporting material.
We will:
- provide a clear way for you to submit the complaint;
- acknowledge it within 30 days;
- investigate it appropriately;
- keep you informed where a response is delayed; and
- communicate the outcome without undue delay.
We may contact you for additional information where reasonably necessary.
19. Complaining to the Information Commissioner
We would appreciate the opportunity to resolve your concern directly. However, you also have the right to complain to the Information Commissioner’s Office, the United Kingdom’s data-protection supervisory authority.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
You can also make a complaint through the Information Commissioner’s website.
If you live outside the United Kingdom, you may also have the right to contact the data-protection authority in the country where you live or work.
20. Customers outside the United Kingdom
This notice is written primarily to meet United Kingdom data-protection requirements.
Customers in other jurisdictions may have additional rights. Where another country’s law applies to our activities, we will comply with applicable requirements and provide supplementary information where necessary.
21. Third-party websites and services
Our website may contain links to websites, payment services, social-media platforms or other services operated by third parties.
Those organisations are responsible for their own processing activities. Their privacy notices apply when you interact directly with them.
We are not responsible for a third party’s privacy practices merely because our website contains a link to its service.
22. Changes to this notice
We may update this notice where:
- our services or systems change;
- we appoint new providers;
- our processing activities change;
- legal or regulatory requirements change; or
- we identify that clearer information is needed.
The current version will be published on our website with its effective date.
Where a change materially affects how we use personal information, we will take reasonable steps to bring it to your attention. Where required, we will obtain consent before beginning the changed processing.
23. Contact us
Questions about this notice or our handling of personal information should be sent to:
Data Protection Lead
Tessiland Limited, trading as Piazza Castello
207 Kings Road
London
England
SW3 5ED
Email: support@piazzacastello.com
