Privacy Policy
This Privacy Policy is provided pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”) to users who visit vinitramonti.it, contact the company or place orders through the online shop.
1. Data Controller
Strada Provinciale 29
07037 Sorso (SS), Italy
VAT No.: 02393130907
Tax Code: MRGNNV59D15I452S
Email: vendite@vinitramonti.it
Certified Email (PEC): marognaa@pec.it
Phone: +39 329 4878245
For any request relating to personal data protection, users may contact the Data Controller using the above details.
2. Types of personal data processed
The Data Controller may process the following categories of personal data:
- Browsing data: IP address, technical logs, browser and device data, operating system, date and time of requests, requested URLs, technical response status and other data transmitted automatically through Internet protocols.
- Data voluntarily provided by the user: name, surname, email address, phone number and the content of communications sent by email, phone, WhatsApp or any other contact channels indicated on the website.
- Data required for online orders and purchases: identification details, billing address, shipping address, contact details, order details, purchased products, amounts, delivery notes, order status and any data required for administrative, tax, logistics and after-sales management.
- Payment-related data: electronic payments are handled by specialised third-party providers. The Data Controller does not store full payment card data, except for the minimum information that may be communicated by the payment provider for administrative purposes, such as transaction result, transaction identifier, payment circuit, amount and date.
- Data relating to bookings, commercial requests or tastings: if the user requests information, vineyard visits, tastings or other experiences, the Data Controller may process the data necessary to manage the request and contact the user.
3. Purposes of processing and legal basis
Personal data are processed for the following purposes:
- Enabling website browsing and technical functioning: legal basis: legitimate interest of the Data Controller in ensuring the functioning and security of the website.
- Managing contact requests, information requests, bookings and customer assistance: legal basis: performance of pre-contractual measures requested by the data subject or performance of a contract.
- Managing orders, online sales, payments, shipments, invoicing, returns, withdrawal and after-sales assistance: legal basis: performance of a contract to which the data subject is party.
- Compliance with legal, administrative, accounting, tax and security obligations: legal basis: compliance with a legal obligation to which the Data Controller is subject.
- Prevention of fraud, abuse and unlawful use of the website, as well as defence of rights in or out of court: legal basis: legitimate interest of the Data Controller in protecting its business, assets and systems.
- Possible newsletter, promotional communications or direct marketing: this purpose will be pursued only if effectively activated and, where required by law, on the basis of the data subject’s consent. At present, unless specific services are activated in the future, the Data Controller does not carry out profiling activities or systematic newsletter marketing through the website.
4. Nature of the provision of data
Providing data necessary for the technical operation of the website is required for its functioning.
Providing data for contact requests, bookings or commercial enquiries is optional, but failure to provide them may make it impossible to respond.
Providing data requested during the purchase process is necessary to conclude the contract, process the payment, issue tax documents and ship the products. Failure to provide such data makes it impossible to complete the order.
5. Processing methods
Processing is carried out using paper, electronic and telematic tools, in accordance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, integrity and confidentiality.
The Data Controller adopts appropriate technical and organisational measures to protect personal data against unauthorised access, loss, disclosure, alteration or destruction.
No fully automated decision-making process or automated profiling producing legal or similarly significant effects on the data subject is carried out.
6. Recipients of the data
Personal data may be disclosed, strictly within the limits relevant to the above purposes, to:
- hosting, maintenance and technical service providers for the website and online shop;
- e-commerce platform providers;
- couriers, carriers and logistics operators;
- payment service providers;
- administrative, tax, accounting, legal or IT consultants;
- public authorities, bodies or persons entitled by law.
Such parties act, depending on the case, either as independent data controllers or as data processors appointed pursuant to Article 28 GDPR.
7. Transfer of data outside the European Economic Area
As a rule, the Data Controller processes data within the European Economic Area.
Where, for technical reasons or due to the use of specific suppliers, it becomes necessary to transfer data outside the EEA, such transfer will take place in compliance with applicable law and, depending on the case, on the basis of an adequacy decision of the European Commission or through the adoption of appropriate safeguards, including Standard Contractual Clauses where necessary.
8. Data retention
Personal data are retained for the time strictly necessary to achieve the purposes for which they were collected and, subsequently, for the periods required by law.
- Browsing data and technical logs: usually for a limited period, generally not exceeding 30 days, unless further retention is necessary for the investigation of unlawful acts or security incidents.
- Data relating to contact requests, information requests, tastings or quotations without any subsequent contractual relationship: up to 12 months from the closure of the request, unless further retention is necessary to protect the Data Controller.
- Data relating to orders, sales, invoicing, shipments, payments and administrative/accounting obligations: for the entire duration of the relationship and thereafter for the period required by civil, tax and accounting laws.
- Data processed for legal defence or dispute management: until the dispute is definitively settled and for the subsequent statutory limitation periods.
- Data processed for marketing: if such activity is activated, until consent is withdrawn and in any case no longer than 24 months, unless renewed.
9. Rights of the data subject
The data subject may exercise, where applicable, the following rights: right of access to personal data, right to rectification of inaccurate data, right to erasure of personal data, right to restriction of processing, right to object to processing, right to data portability where applicable, and right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Requests may be sent to the Data Controller using the contact details indicated in this Policy.
10. Complaint to the supervisory authority
The data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), without prejudice to any other administrative or judicial remedy provided by law.
11. Minors
The sale of alcoholic beverages is prohibited to persons under 18 years of age. The website, online shop and related services are not intended for minors under 18 for the purpose of purchasing alcoholic products.
The Data Controller reserves the right not to process orders or requests where circumstances suggest that this requirement has not been met.
12. Cookies and tracking tools
The website may use cookies and technical tools strictly necessary for the functioning of the website and the online shop, session management, shopping cart, checkout, security and technical preferences.
If tools other than strictly necessary technical tools are used, the Data Controller will update this Policy and, where required, collect the user’s consent in compliance with applicable law.
For further details, please refer to the website’s Cookie Policy, if available.
13. Changes to this Policy
The Data Controller reserves the right to amend or update this Privacy Policy at any time, including as a result of regulatory, organisational or technical changes. Any updates will be published on this page together with the date of the latest revision.