Privacy Notice
https://anticocaffegreco.eu/
Data Controller
Antico Caffè Greco S.r.l., Tax Code 02153540642, with registered office at Via dei Condotti 86, 00187 Rome, Italy (the “Controller”), in the person of its pro tempore legal representative, provides this notice to explain how your personal data are collected, processed and used in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable national legislation (together, the “Privacy Laws”).
1. Purposes and methods of processing
Personal data collected through registration are processed to allow access to services provided via the website and reserved for registered users.
Where the user has given consent at the time the service is activated—or thereafter, until such consent is withdrawn—the Controller may process personal data in order to:
- enable access to the services provided via the websites and reserved for registered users;
- send—where consent has been given and until withdrawn—commercial communications regarding the Controller’s (or third-party) products and services, including by automated means, for direct marketing purposes, as well as market research and customer-satisfaction surveys;
- disclose and transfer user data to third parties—where consent has been given and until withdrawn—for the purpose of sending commercial communications regarding their own products and services, including by automated means, for direct marketing and market-research purposes;
- carry out—where consent has been given and until withdrawn—analysis of specific behaviours and purchasing habits, including by electronic tools, in order to improve services and tailor commercial offers to the user’s interests, and to provide third parties with aggregated statistics of opens/clicks obtained via a cookie-based tracking system;
- use the data to provide commercial and purchasing services, including related shipping activities, and for administrative and accounting purposes and to perform contractual obligations towards users who are customers.
The Controller adopts specific security measures to prevent data loss, unlawful or incorrect use, and unauthorized access.
Personal data are stored in electronic databases located in Italy, in countries of the European Economic Area (EEA), and in third countries that ensure an adequate level of data protection.
Processing of personal data provided by users may also be carried out by companies, entities or consortia appointed as Processors pursuant to Article 28 GDPR to provide, on the Controller’s behalf, specific processing services or related, instrumental or support activities.
Among these processors is the website hosting provider Contabo GmbH (www.contabo.com).
Personal data provided by users may also be disclosed to:
- subsidiaries or affiliates;
- third parties for service delivery and contract performance (e.g., shipping companies);
- entities entitled to access personal data by virtue of EU, national or regulatory provisions;
- entities to whom disclosure is required by law or regulation, or public bodies in the exercise of their institutional functions.
2. Categories of data processed
Data provided voluntarily by the user
The Controller processes the personal data you provide in the relevant sections of the website, including the data necessary to purchase and ship products.
These data include:
- Identity data, such as first name, last name, and age;
- Contact details, including—by way of example—residential address, telephone numbers, email addresses, and emergency contact details;
- Payment information, including credit-card number, required to process payments.
Browsing data
Browsing data include all information automatically collected through the Site concerning, for example, the types of actions performed by the user and how the Site is used. We may also automatically record the user’s IP address (i.e., the unique address that identifies the user’s device on the Internet), which is automatically recognized by our server. Unless the user has expressly consented (e.g., in relation to the use of cookies), browsing data are used solely to obtain anonymous statistical information on Site usage and to verify its proper operation, and are deleted immediately after processing. Such data may also be used to ascertain liability in case of computer crimes against the Site or to protect our rights.
3. Data retention
The Controller retains users’ personal data only for as long as strictly necessary to achieve the purposes for which they were collected; once that period has expired, personal data will be deleted or anonymized.
With respect to personal data processed on the basis of the user’s consent, if consent is withdrawn the relevant data will be promptly deleted.
4. Data subject rights
The data subject may exercise the rights provided for by Article 7 of Legislative Decree 196/2003 and by Articles 15–22 GDPR, including: the right of access; the right to obtain erasure, updating or rectification; the right to restriction and to object to processing (including objection to automated decision-making); and the right to data portability.
For information, clarifications or requests, please contact: info@caffegreco.it
To lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), please refer to the contact details available at: http://www.garanteprivacy.it
5. Cookie notice
This Site uses technical cookies and—subject to consent—analytics and profiling cookies, including those of third parties. You can manage your preferences through the cookie banner or cookie-management module.
6. Legal references
This notice is provided pursuant to Regulation (EU) 2016/679 (GDPR), Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, and the Italian DPA’s Guidelines on cookies and other tracking tools (decision of 10 June 2021).
This notice applies exclusively to the website https://anticocaffegreco.eu.
7. Contact details
If you have questions about this Privacy Notice or wish to exercise your privacy rights, please contact the Controller at:
info@caffegreco.it