Privacy Policy
Privacy Policy
This is a courtesy translation. In case of discrepancies, the Italian version prevails.
Privacy policy pursuant to Art. 13 of European Regulation 679/2016
Pursuant to and for the purposes of the aforementioned legislation, SANTA S.A.S. di Sanfelici Luca e C. wishes to inform you in advance both of the use of your personal data and of your rights, as follows.
Data controller
The data controller is SANTA S.A.S. di Sanfelici Luca e C., registered office: Via Colombare 49, 25019 Sirmione (BS) – VAT No. 03944720980 – email: gardafoody@gmail.com. The Controller can be contacted by email or at the address indicated above.
Types of data processed and collected
The personal data collected by this website, either independently or through third parties, include: cookies, usage data, first name, last name, telephone number, company name, email, address and city.
Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed prior to the collection of the data.
Personal data may be freely provided by the user or, in the case of usage data, collected automatically while using this website.
Unless otherwise specified, all data requested are mandatory. If the user refuses to provide them, it may be impossible to provide the service. Where some data are indicated as optional, users are free to refrain from providing them, without any consequence on the availability of the service.
Users who are unsure which data are mandatory are encouraged to contact the Controller.
Any use of cookies or other tracking tools by this website or by the owners of the third-party services used, unless otherwise specified, serves to provide the service requested by the user, in addition to the further purposes described in this document and in the cookie policy.
The user assumes responsibility for any third-party personal data obtained, published or shared through this website and warrants that they have the right to communicate or disseminate such data, releasing the Controller from any liability towards third parties.
Purposes of processing
The data provided by the user will be processed in order to:
- enable the Controller to provide its services, manage orders and contact the user to provide further information;
- direct and indirect marketing purposes: for example, sending, by automated means (SMS or email) and traditional means (operator-assisted telephone calls or post), promotional and commercial communications relating to services/products offered by the Company, as well as market research and statistical analysis, advertising, remarketing and behavioral targeting, displaying content from external platforms, tag management, interaction with live chat platforms, and management of user databases.
Persons authorized to process data
The data may be processed by employees and collaborators of the company departments responsible for pursuing the purposes indicated above, who are expressly authorized to process the data and adequately trained.
Methods of processing
The Controller takes appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of personal data.
Processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the purposes indicated. In addition to the Controller, in some cases, the data may be accessed by other persons involved in the organization of the website (administrative, sales and marketing staff, legal advisers, system administrators) or by external parties (third-party technical service providers, couriers, hosting providers, IT companies, communication agencies), also appointed, where necessary, as data processors by the Controller. The updated list of processors may be requested from the Controller at any time.
Place
The data are processed at the Controller's operating offices and in any other place where the parties involved in the processing are located. For further information, please contact the Controller.
The user's personal data may be transferred to a country other than the one in which the user is located. The user has the right to obtain information regarding the legal basis for the transfer of data outside the European Union or to an international organization, as well as regarding the security measures adopted by the Controller to protect the data.
Retention period
The data are processed and stored for the time required by the purposes for which they were collected. Therefore:
- personal data collected for purposes related to the performance of a contract between the Controller and the user will be retained until the performance of such contract has been completed;
- personal data collected for purposes relating to the legitimate interest of the Controller will be retained until such interest has been satisfied;
- specifically for marketing purposes, the retention period is 24 months from the collection of the data; in the case of an ongoing contract, 24 months from its termination.
The Controller may be required to retain personal data for a longer period in compliance with a legal obligation or by order of an authority. At the end of the retention period, personal data will be deleted; therefore, once this period has expired, the right of access, erasure, rectification and the right to data portability can no longer be exercised.
Legal basis for processing
The Controller processes personal data relating to the user if one of the following conditions applies:
- the user has given consent for one or more specific purposes;
- processing is necessary for the performance of a contract with the user and/or for the performance of pre-contractual measures;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
- processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party.
In any case, it is always possible to ask the Controller to clarify the specific legal basis of each processing operation.
Transfer of data abroad
Your personal data may be transferred to Member States of the European Union and to countries outside the European Union, always within the scope of the purposes indicated in this policy and in compliance with applicable laws and international agreements.
Rights of the data subject
The rights granted by the GDPR include the right to:
- request access to your personal data and to information relating to them; the rectification of inaccurate data or the completion of incomplete data; the erasure of personal data concerning you (Art. 17(1) GDPR); the restriction of processing (Art. 18(1) GDPR);
- receive your personal data in a structured, machine-readable format, also for the purpose of transmitting them to another controller (right to data portability), where the legal basis is contract or consent and the processing is carried out by automated means;
- object at any time to the processing of your personal data on grounds relating to your particular situation;
- withdraw your consent at any time, limited to cases where processing is based on consent; processing carried out before the withdrawal remains lawful;
- lodge a complaint with the supervisory authority (Garante per la protezione dei dati personali, www.garanteprivacy.it).
You may exercise these rights at any time by writing to the Controller at the address or email indicated above. Requests will be handled free of charge as quickly as possible and in any case within one month of the request.
