This policy contains the guidelines that Fattoria Sardi applies in processing personal data, in accordance with the objectives and obligations arising from the General Data Protection Regulation, i.e. Regulation (EU) 2016/679 of 27 April 2016 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (‘GDPR’).
Fattoria Sardi Giustiniani, hereinafter Fattoria Sardi, with registered office at via della Maulina 747, 55100 Lucca (LU) registered under VAT number 02090550464, acts as data controller.
Fattoria Sardi confirms that it complies with the current legislation, namely the Law of 8 December 1992 on the protection of privacy and its implementing decisions and the European General Data Protection Regulation of 27 April 2016.
(a) “Personal data”: all information about an identified or identifiable natural person (“the data subject”). A natural person is regarded as identifiable if he or she can be identified directly or indirectly, in particular by means of an identifier such as a name, an identification number, location data, an online identifier or one or more elements characterising the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person. Appendix 1 lists the Personal Data that the Processer will process in accordance with this agreement and the purposes for which the data are processed.
(b) “Processing”: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
(c) “Controller”: a natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data.
(d) “Processor”: a natural or legal person which processes personal data on behalf of the Controller
(e) “Sub-processor”: the subcontractor appointed by the Processor to carry out part of the processing on behalf of the Controller.
(f) “Personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed, also known as a “data leak” ;
(g) “GDPR”: The General Data Protection Regulation, i.e. Regulation (EU) 2016/679 of 27 April 2016 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC.
III. Processing of personal data
Below is a summary of the personal data which are processed and the purposes for which Fattoria Sardi processes them, as well as the legal basis for doing so.
- In connection with the provision of services by Fattoria Sardi, the following personal data are processed:
- Your surname and first name
- Your address
- Your telephone number
- Your email address
- Your bank account number
- Your purchase history
- Credit card number
- The above data are processed with a view to the performance of the agreement that you have concluded with Fattoria Sardi. The processing of your personal data takes place more specifically in connection with delivery to the agreed location, as well as invoicing and the monitoring of invoice payments.
- In connection with your accessing and use of our website, the following personal data will be processed:
- Your IP address
- Your browsing behaviour
- Your email address
Fattoria Sardi processes the above data with a view to optimising the content and functioning of the website, in accordance with the needs of the visitor.
Fattoria Sardi justifies this processing of personal data on the basis of the legitimate interest that Fattoria Sardi has in offering a readily accessible, understandable, appropriate, comprehensive and relevant website.
- In connection with sending electronically newsletters, the following personal data are processed:
- Your surname and first name
- Your email address
The above data are processed with a view to inform you about current promotions and special offers.
Fattoria Sardi justifies its processing of these personal data on the legitimate interest it has in providing high-quality information about its products.
You may object to the use of your personal data for direct marketing purposes free of charge at any time. To do so, simply send your request to firstname.lastname@example.org.
Fattoria Sardi undertakes not to use your personal data for any purpose other than those mentioned above, unless you have given your express consent to do so. Fattoria Sardi guarantees that your personal data will not be retained if it no longer requires them for the provision of services, or if it is no longer subject to a statutory retention obligation.
You are not obliged to transfer your personal data to Fattoria Sardi. However, you should be aware that a refusal to provide certain basic data to Fattoria Sardi may result in it being unable to provide you with certain services.
IV. Retention period
Your personal data which are processed by Fattoria Sardi will be kept for as long as you are registered as an active customer.
If your user profile shows no activity for an uninterrupted period of five years, the profile, including all associated personal data, will be deleted by Fattoria Sardi.
As a data subject whose personal data are processed, you have a number of rights with regard to the processing operations carried out by Fattoria Sardi.
To exercise these rights, you should contact us at email@example.com
Fattoria Sardi is obliged to respond to this request within a period of one month. You will only receive a response within the set period if you send your request for the exercise of your rights to firstname.lastname@example.org using the above-mentioned procedure.
You have the following rights:
- Right of inspection and access
You have the right to access your personal data and the right to check how they are being used via email@example.com . You may request a free copy of your available personal data at any time by sending an email to the address mentioned above, provided you include proof of identity by attaching a copy of your identity card to your request.
- Right to correction, erasure and restriction
Except for those personal data that must be processed in connection with the performance of an agreement, in connection with the services we provide or in connection with storage because of a legal obligation, you may indicate which personal data may not be processed at all or may only be processed for a limited number of processing operations. In addition, you may request that personal data which you do not wish to be processed in whole or in part, be deleted. You may also ask to check and, if necessary, correct your personal data.
- Right to object, automated decisions and profiling
You may oppose the processing of your personal data at any time if your objection is based on serious and legitimate reasons. If you wish to oppose the use of your personal data for direct marketing purposes, you do not have to give any reasons for this.
The processing of personal data by Fattoria Sardi is not carried out on the basis of automated decisions; in other words it is not carried out without human intervention.
Fattoria Sardi does not engage in profiling on the basis of the available personal data.
- Right to portability
Under the conditions stipulated in the GDPR, you have the right to obtain your personal data in a structured, commonly used and machine-readable form. You may ask Fattoria Sardi to transfer your data in this way to another Controller.
If you believe that your rights as a data subject are being infringed by or during the processing of your personal data, you have the right to make a complaint to the Data Protection Authority, Piazza di Monte Citorio, 121, 00186 Roma, Italy, email : firstname.lastname@example.org, tel. +39 06696771, fax +39 06696773785, without prejudice to any other possibility of initiating a judicial review or seeking a judicial remedy.
VI. Transfer to third parties
Fattoria Sardi may pass on your personal data to subcontractors or suppliers in connection with the performance of the agreement, if it considers this necessary for its services and/or continuity.
Fattoria Sardi in other respects undertakes not to sell, rent, distribute or otherwise disclose your personal data to third parties, unless the communication is made to the third party under a legal obligation. In exceptional cases, mandatory laws oblige Fattoria Sardi to transfer your personal data to the competent government authorities. Likewise, a court order may require Fattoria Sardi to communicate personal data to people authorised by the order to inspect the personal data concerned.
Fattoria Sardi makes an exception to its non-disclosure undertaking in the event of a partial or complete reorganisation or a transfer of the company’s business operations. In such cases, your personal data will be conveyed along with the business operations to the third parties involved in the transfer and in the confidential negotiations prior to the transfer.
As far as possible, Fattoria Sardi will inform you of the transfer to the aforementioned third parties.
VII. Security and confidentiality
Fattoria Sardi guarantees that the processing of your personal data will take place in an appropriate, correct and secure manner. If you wish, you will be informed in a transparent manner about the processing procedures and the technical and organisational measures taken to prevent any loss, falsification or unlawful alteration of or unlawful access to your personal data.
Fattoria Sardi reserves the right to change this policy.
If substantial adjustments are made, Fattoria Sardi will take all reasonable measures to notify you before the changes take effect.