Shopping cart0
There are no products in the cart!
Continue shopping
0

Privacy Policy

Privacy Policy for the Processing of Personal Data

pursuant to Articles 13 – 14 of EU Regulation 2016/679 (GDPR)

Introduction

The Interested Party (user or visitor of the website) is informed that Legislative Decree 196/2003 (the so-called “Code regarding the protection of Personal Data”) – hereinafter, for brevity, the “Code”) and EU Regulation No. 2016/679 (hereinafter, for brevity, “GDPR”) provide for the protection of Personal Data Processing. In accordance with the provisions of the Code, the GDPR, and applicable regulations, Processing will be based on the principles of fairness, legality, and transparency, respecting the rights and fundamental freedoms, the dignity of the Interested Party, particularly regarding privacy, personal identity, and the right to protection of Personal Data.

This Policy is provided pursuant to Article 13 of the Code as well as Articles 13 and 14 of the GDPR and is subject to updates, which will be publicized on the Website. It is therefore advisable to regularly check the Policy and refer to the most updated version.

  1. Definitions
    • For the purposes of this Policy, the following terms are defined as:
  • Database”, any organized set of Personal Data, divided into one or more units located in one or more sites of the Data Controller;
  • Client”, the natural person, legal entity, public administration, and any other entity, association, or body that has signed a service contract with the Data Controller;
  • Communication”, making Personal Data known to one or more specific subjects other than the Interested Party, the representative of the Data Controller in the territory of the State, the Data Processor, and the Appointed Persons, in any form, also by making them available or consultable;
  • Consent”, any manifestation of free, specific, informed, and unequivocal will of the Interested Party, by which they express their assent, through a statement or unequivocal positive action, that their Personal Data may be subject to Processing;
  • Personal Data” any information relating to an identified or identifiable natural person, even indirectly, by reference to any other information;
  • Appointed Person” the natural person authorized to carry out Processing operations by the Data Controller or the Data Processor;
  • Interested Party”, the natural person to whom the Personal Data refers;
  • Policy”, this privacy policy issued pursuant to Articles 13 and 14 of the GDPR;
  • Products”, the wines branded “FIVI” produced by the Agricultural Company and marketed at the winery’s point of sale or through the Website;
  • Profiling” any form of automated Processing of Personal Data consisting of using such Personal Data to evaluate certain personal aspects relating to a natural or legal person, in particular to analyze or predict aspects concerning professional performance, economic situation, health, personal preferences, interests, reliability, behavior, location or movements, purchasing propensity, etc.;
  • Pseudonymization”, Processing of Personal Data in such a way that it cannot be attributed to a specific Interested Party without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that Personal Data is not attributed to an identified or identifiable natural person;
  • Data Processor”, the natural person, legal entity, public administration, and any other entity, association, or body entrusted by the Data Controller with the Processing of Personal Data;
  • Services” the services for promoting and organizing events and meetings, guided tours, and tastings at the winery, provided by the Agricultural Company Le Fraghe, also through the Website;
  • Website” the site www.fraghe.it with “Hypertext Transfer Protocol Secure” transfer protocol;
  • Data Controller”, the natural person, legal entity, public administration, and any other entity, association, or body responsible for deciding on the purposes, methods of Processing Personal Data, and the tools used, including security aspects;
  • Processing”, any operation or set of operations carried out, even without the aid of electronic tools, concerning the collection, registration, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, dissemination, deletion, and destruction of Data, even if not recorded in a Database;
  • User”, any natural person using the Website.

 

  1. Data Controller
    • The Data Controller is Azienda Agricola Le Fraghe of Matilde Poggi, with registered office in 37010 Cavaion Veronese (VR), Loc. Colombare, 3, Tax Code PGGMLD62L44L781J, VAT No. 02851860235 (hereinafter, for brevity, the “Data Controller” or the “Agricultural Company”).
    • Information and requests regarding privacy, including those related to the exercise of the rights of the Interested Party indicated in Article 9 below, can be directed to the Data Controller via email at info@fraghe.it.

 

  1. Location of Data Processing and Transfer
    • Processing of Personal Data takes place at the Agricultural Company and through authorized personnel. The Processing and storage of Data occur on servers located within the European Union. Currently, the servers are located in Italy. Data is not transferred outside the European Union. The Data Controller reserves the right to change the location of the servers also outside the European Union, ensuring that such transfer will be carried out in accordance with applicable legal provisions, with the appropriate guarantees provided by Article 46 of the GDPR.

 

  1. Types of Data processed

Browsing Data
The information systems and software procedures used to operate the Website acquire, during their normal operation, certain Personal Data whose transmission is implicit in the use of Internet communication protocols. These are information that is not collected to be associated with identified Interested Parties but which by their very nature could, through processing and associations with Data held by Third Parties, allow identification of Users. This category of Data includes IP addresses or domain names of the computers used by Users connecting to the Website, etc.), the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters related to the operating system and the User’s IT environment. This Data is used solely for the purpose of obtaining anonymous statistical information on the use of the Website and to check its correct functioning and is deleted immediately after processing. The Data is, in any case, not processed for Profiling purposes. Data may be used to ascertain responsibility in the case of hypothetical cyber crimes against the Website. In any case, Data is stored for the strictly necessary period and, in any case, in accordance with current legal provisions.

Cookies

Complete details on this type of Data are provided in the dedicated section “cookie policy” accessible via the specific link present on the Website or through a specific informative text displayed before the collection of Cookies for which User Consent is required.

Data voluntarily provided by Users

The voluntary, optional, and explicit sending of Data by the User (e.g., during the entry of their Data through the completion of specific forms, sending emails to the addresses indicated on the Website, etc.) results in the subsequent acquisition of the sender’s address and the Data provided by them, for which the User gives explicit Consent for their Processing.

If the User has explicitly given Consent, Personal Data will be collected and processed for the following purposes:

To conclude, manage, and execute the request made by the Interested Party to subscribe to the newsletter and the mailing list of the Data Controller in order to receive, via email or SMS, commercial and/or promotional and/or advertising communications about the Services provided by the Data Controller;
To organize, manage, and execute the contact request submitted by the Interested Party through the completion of specific forms available on the Website;
To comply with legal obligations or other requirements requested by competent Authorities.
To stop the transmission and to unsubscribe from the newsletter and the mailing list, the Interested Party can, at any time, follow the unsubscription procedure outlined in the communications received.

Dati raccolti tramite registrazione nel Sito Web
With registration in the designated “Customer Login” section of the Website, the User authorizes the Company to process Personal Data such as, for example and not limited to, name, surname, phone number, and email address, solely for the purpose of completing and managing the account creation and registration process to use the features of the Customer Area. For the provision of Services related to the Customer Area, the Company may acquire other types of data such as credit card information. Personal Data collected through the completion of forms on the Website are collected and processed for the following purposes:

Provision of Services and/or marketing of Products to the Customer, as outlined in the general contract terms signed by the Customer;
Management of administration and fulfillment of legal obligations (e.g., accounting, tax).
In any case, if the Data Controller intends to further process the Personal Data for a purpose different from that for which they were collected, they will provide the Interested Party, prior to such further Processing, with information regarding the different purpose, as well as any additional relevant information.

5. Methods, purposes, and duration of Processing
The collected Data are:

  1. Processed using automated electronic, IT, and telematic tools, or through manual processing with logic related to the purposes for which the Data were collected;
  2. Processed lawfully, fairly, and transparently in relation to the Interested Party;
  3. Collected for determined, explicit, and legitimate purposes, and subsequently processed in a manner that is not incompatible with those purposes;
  4. Adequate, relevant, and limited to what is necessary with respect to the purposes for which they are processed;
  5. Accurate and, if necessary, updated;
  6. Stored in such a way as to allow the identification of the Interested Party for a period of time not exceeding the achievement of the purposes for which they are processed;
  7. Processed in a way that ensures adequate security of Personal Data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, through appropriate technical and organizational measures.

In particular, the Processing of Personal Data is based on principles of fairness, lawfulness, and transparency, and pursues the following purposes, in accordance with Article 6, letter b) of the GDPR:

  1. To conclude, manage, and execute requests for contact or for the provision of Services and/or Products submitted by the Interested Party;
  2. To organize, manage, and execute requests for contact and for the provision of Services and/or Products, also through communication to Third Parties in general, including suppliers and/or collaborators of the Agricultural Company, for the purpose of providing Services and/or Products for the defense of rights and/or compliance with legal obligations and at the request of the competent Authorities.

The Personal Data of the Interested Party may be used to request information, including by phone, regarding the quality of the Services offered, for the purposes of marketing the Services. Such Data may also be retained for longer periods, but strictly necessary for achieving the purposes for which they are retained.

6. Optional Nature of Data Provision
Except for browsing data, the provision of data by the Interested Party is optional; however, refusal to provide such data may prevent the timely and correct management of the contact request or the provision of Services and/or Products submitted by the Interested Party.

7. Possible Recipients of Personal Data
Personal Data will not be disclosed to third parties unless it is essential, and in such cases, only to the extent strictly necessary to achieve the purposes of Processing outlined in this Notice.

Personal Data may be communicated to:

  1. Third-party suppliers of the Agricultural Company for the provision of Services and/or marketing of Products for the benefit of the Interested Party;
  2. Third parties who, on behalf of the Agricultural Company, provide administrative, payment, and invoicing services, as well as legal consultants and webmasters;
  3. Administrative or Judicial Authorities for compliance with legal obligations.

In any case, Personal Data will not be sold or transferred to third parties.

8. Information Security
All information collected on the Website is stored and maintained in secure facilities that limit access exclusively to authorized personnel. The Website is regularly monitored for any security breaches and to ensure that the collected information is secure from unauthorized viewing. The Data Controller adheres to the security measures prescribed by applicable laws and regulations and to all appropriate measures according to the currently most advanced criteria to ensure and guarantee the confidentiality of Users’ Personal Data and to minimize, as much as possible, the risks posed by unauthorized access, removal, loss, or damage to Users’ Personal Data.

In accordance with Article 32 of the GDPR, taking into account the state of the art and the costs of implementation, as well as the nature, scope, context, and purposes of Processing, and the risks having different probabilities and severities for the rights and freedoms of natural persons affected by the Processing, both at the time of determining the means of Processing and at the time of the Processing itself, the Company implements appropriate technical and organizational measures, such as pseudonymization and encryption of Personal Data, aimed at effectively implementing data protection principles, such as minimization, and integrating into the Processing the necessary safeguards to meet the requirements of current regulations and protect the rights of the Interested Parties.

9. Rights of the Interested Party
The Interested Party may exercise the rights recognized by the GDPR at any time. In particular, the Interested Party has the right to:

  1. Access to their Data to obtain information about the methods and purposes of Processing;
  2. Rectification to request the correction or completion of the Personal Data provided, if it is inaccurate;
  3. Erasure to request that Personal Data be deleted in the event of withdrawal of consent or opposition to Processing, in the case of unlawful Processing, or where there is a legal obligation to erase the data;
  4. Restriction of Processing of the Personal Data provided when one of the conditions of Article 18 of the GDPR applies;
  5. Objection, at any time, to the Processing of Personal Data, unless there is a legitimate interest of the Data Controller to proceed with the Processing that overrides the right to object;
  6. Data Portability, to request to receive Personal Data or have it transmitted to another Data Controller specified for this purpose, in a structured, commonly used, and machine-readable format.

Additionally, under Article 7, paragraph 3, of the GDPR, the Interested Party may exercise the right to withdraw Consent for the Processing of their Personal Data at any time. The withdrawal of Consent, however, does not affect the lawfulness of Processing based on Consent obtained prior to the withdrawal. In the event of withdrawal of Consent, the Interested Party’s Data will be permanently deleted, except for the retention obligations imposed by law on the Data Controller.
The Interested Party also has the right to lodge a complaint with the Supervisory Authority, which in Italy is the Guarantor for the Protection of Personal Data.

10. Minors
If the Interested Party is under 18 years of age, Processing is lawful only if and to the extent that Consent is given or authorized by the holder of parental responsibility, for which the identified data and a copy of identification documents must be obtained.

Shopping cart0
There are no products in the cart!
Continue shopping
0
To top