06 / PRIVACY

Privacy Policy

This policy explains how the KORE DESIGN website handles project inquiries, uploaded files and related technical data. We process personal data only as necessary to respond to inquiries, take pre-contractual steps and keep the website secure.

Last updated / 7 September 2026

01 / Data Controller

KORE GROUP S.N.C. DI GUO KUNQI & C.

Milano, Italia

Privacy contactinfo@koredesignmilano.com
02

Data we collect

When you use the START A PROJECT form, we process the information you choose to provide.

  • Name, company or brand (optional), phone / WeChat and email address
  • Project location, area (optional), project type, current status, budget and expected start time
  • Project description and any plans, photographs or other project files you upload
  • IP address, request origin, time and basic request metadata processed temporarily for form security, abuse prevention and troubleshooting
03

Purposes and legal bases

Project information is used to understand and assess an inquiry, respond to a prospective client, arrange further communication and take steps requested before entering into a contract. This processing is primarily based on Article 6(1)(b) GDPR.

We process necessary technical data to verify request origin, limit abnormal submission rates, prevent automated abuse and protect the website and communication systems. This is based on our legitimate interests under Article 6(1)(f) GDPR. Where the law requires specific information to be retained or disclosed, Article 6(1)(c) GDPR applies.

The privacy checkbox confirms that you have read this policy. It is not consent to marketing or newsletters.

04

Required and optional information

Fields marked with an asterisk are required to assess and respond to the project. Company / brand, area and attachments are currently optional. Without the required information, we may be unable to understand the request or continue the conversation.

05

How we process and protect data

Data is transmitted over an encrypted connection. The server validates required fields, email format, file types and sizes, and uses origin checks, a honeypot, rate limiting and input sanitisation to reduce abuse. Uploaded files are processed only as needed to deliver the inquiry email.

No method of network transmission or storage can guarantee absolute security. We apply organisational and technical measures appropriate to the nature of the data and available technology, and restrict access to people who need it for their work.

06

Recipients and processors

The website and form use Cloudflare hosting, security and network infrastructure. Project inquiry emails and attachments are delivered through Zoho Mail's European data centre to the KORE DESIGN business mailbox. These providers process data only as required to provide their respective technical services.

Project information may be accessed by KORE DESIGN personnel responsible for initial assessment and communication. Necessary information may be shared with professional advisers involved in the inquiry only where the project requires it and an appropriate basis exists. We do not sell inquiry data.

07

Retention

Inquiry data is retained only for as long as needed to handle the request and reasonable follow-up communication. The period is determined by the status of the inquiry, whether a project relationship develops, the continuing relevance of the information and any deletion request.

If a contractual relationship is established, a legal obligation applies or a legal dispute must be handled, relevant records may be retained for the corresponding required period. Technical records used for rate limiting are processed only within the limited anti-abuse window.

08

International transfers

The Zoho Mail account uses the European data centre. Cloudflare provides website and security services through a global network, so some technical processing may involve infrastructure outside the European Economic Area. Where a transfer occurs, the relevant provider is expected to apply an appropriate safeguard, such as an adequacy decision or the European Commission's Standard Contractual Clauses.

09

Your rights

Where applicable, you may request access to, rectification or erasure of your personal data, restriction of processing, object to processing based on legitimate interests, and request data portability. You may also ask for information about how your data is handled.

10

Right to complain

You may lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali. You may also contact us first using the address shown on this page.

11

Cookies, language preference and analytics

The website currently does not use Google Analytics, Meta Pixel or marketing tracking. When you actively change language, the website stores that preference in browser localStorage; it is not used for advertising profiles. Cloudflare may use necessary technical mechanisms for operation, security and abuse prevention.

12

Policy updates

We may update this policy when website functions, service providers or legal requirements change. The revised date will be shown on this page, and material changes will be communicated appropriately where reasonable.