Privacy e Cookie Policy

PRIVACY & COOKIE POLICY Last Updated: April 24, 2026 1. DATA CONTROLLER The Data Controller is Az. Agr. DI MAREMMA S.S.AGR., with registered office at Loc. Castel di Pietra 13/a, 58023 Gavorrano (GR), Italy. Contact Email: info@lavandadimaremma.it VAT / Tax ID: 01580440533 The data is managed exclusively by the owners of the farm as authorized data processors. 2. TYPES OF DATA COLLECTED AND PURPOSES Personal data is processed for the following purposes: Order and Account Management: During registration and purchase, we collect name, surname, shipping and billing address, tax ID, phone number, and email. This data is necessary for the performance of the sales contract. Payments: We manage payments via Bank Transfer and the PrestaShop Checkout platform (which integrates PayPal and Credit Cards). Credit card data does not pass through our servers; it is handled securely and encrypted by the service provider. Shipping: Contact details and addresses are shared with the courier BRT (Bartolini) for product delivery. Newsletter: If you subscribe via the newsletter form, your email is stored internally within our website database (PrestaShop CMS) to send promotional communications. Statistics (GA4): We use Google Analytics 4 to analyze the number of visitors and their origin in an aggregate and anonymous form. 3. LEGAL BASIS FOR PROCESSING Pursuant to Art. 6 of the GDPR, processing is based on: Performance of a contract: For the sale and delivery of products. Legal obligation: For invoicing and tax accounting. Consent of the data subject: For newsletter subscription and the use of non-technical cookies. Legitimate interest: For website security and fraud prevention. 4. DATA PROCESSING LOCATION AND HOSTING Data is processed at the Controller's operating office and stored on servers located within the European Union. The hosting service is provided by Keliweb S.r.l., acting as an External Data Processor. 5. COOKIE POLICY The website uses a management module (banner) that allows users to grant or deny consent granularly. Technical Cookies: Essential for the shopping cart and account access. These cannot be deactivated. Statistical Cookies (GA4): Used to analyze website performance. Data is processed in an anonymized form. Marketing Cookies: We currently do not use Meta Pixels or other advertising profiling systems. 6. DATA RETENTION PERIOD Account/Order Data: Until the user requests deletion, except for the 10-year period required by law for tax documentation storage. Newsletter: Until the user unsubscribes (via the link at the bottom of the emails or by direct contact). Security Logs: Retained for a maximum of 60 days. 7. USER RIGHTS At any time, the user may exercise their rights (Art. 15-22 GDPR): Access their data and request a copy. Request rectification or erasure ("Right to be forgotten"). Object to processing for marketing purposes. Withdraw consent at any time. To exercise these rights, simply write to: info@lavandadimaremma.it. The user also has the right to lodge a complaint with the Data Protection Authority (Garante della Privacy