Italian Cooking Experience, owned by Lavinia Santo,
Str. Pasquale Poggio 15, 01030 Vitorchiano VT
(hereinafter, the “Data Controller” or “Controller”), is constantly committed to protecting the online privacy of natural persons during their navigation and use of the services offered on the website https://www.italiancookingexperience.com/ (hereinafter, the “Portal” or the “Website”).
This document describes all aspects related to the processing of Personal Data of users (hereinafter, the “Data Subjects”) carried out through the Website, in accordance with Article 13 of EU Regulation No. 2016/679 (hereinafter, the “Regulation” or “GDPR”).
According to the Regulation, the processing performed by the Controller through the Website is based on the principles of lawfulness, fairness, transparency, purpose and storage limitation, data minimisation, accuracy, integrity, and confidentiality.
1. Data Controller
The Controller of the processing carried out through the Portal is Italian Cooking Experience, as defined above, and can be contacted using the methods indicated in the “Contacts” section (see Art. 10).
2. Categories of Personal Data Processed
Navigation / usage data
Information collected during the user’s visit to the Website (e.g., IP address, URI notation addresses, browsing history, information on interactions with the site, details regarding the user’s IT environment, browser type and language, operating system, location, date and time of the request).
These data are not collected to be associated with identified individuals; however, by their very nature, they may allow users to be identified through processing or association with data held by third parties.
Data voluntarily provided by the user
Personal information voluntarily provided by the user through specific Website forms (e.g., subscription/registration, contact, comments, reviews, posts, etc.). These may include, by way of example: identification data (name, surname, tax code, username, user ID, password, place and date of birth, etc.), personal image, contact and location data (residential/domicile address, email address, phone number, postal address, etc.).
Commercial data
Information necessary for the performance of economic and fiscal obligations related to the provision of Website services (e.g., payment information, VAT number, purchase history, product or service usage information, credit and billing information, support requests, etc.).
Sensitive data
“Special categories of personal data” as per Article 9 of the Regulation, namely personal information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to uniquely identify a natural person, health data, or data concerning a person’s sex life or sexual orientation.
3. Purposes of Processing
The Controller processes Personal Data collected through the Website for the following purposes:
Service provision
Responding to information requests submitted via the Website; providing content and services available on the Website; sending users notifications and updates related to the requested service.
Payments and invoicing
Managing the economic and fiscal aspects related to the sale of products/services through the Website.
Security, fraud prevention, and debugging
Monitoring and preventing fraudulent activities and ensuring systems and processes operate correctly and securely.
Judicial protection
Allowing the Controller to defend or exercise a right in legal proceedings.
Legal obligation
Complying with legal obligations to which the Controller is subject.
4. Legal Bases for Processing
The Controller processes Personal Data collected through the Website based on the following legal grounds:
Contract / Pre-contractual measures
Processing is based on Article 6(1)(b) GDPR (“[…] processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract”).
Consent of the data subject
Processing is based on Article 6(1)(a) GDPR (“[…] the data subject has given consent to the processing of his or her personal data for one or more specific purposes”).
Consent is voluntary and does not affect the use of other Website services. It can be withdrawn at any time via the cookie preference tool or by contacting the Controller using the details provided in the “Contacts” section.
Legitimate interest of the Controller
Processing is based on Article 6(1)(f) GDPR (“[…] processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party”).
Legal obligation
Processing is based on Article 6(1)(c) GDPR (“[…] processing is necessary for compliance with a legal obligation to which the controller is subject”).
Protection of vital interests
Processing is based on Article 6(1)(d) GDPR (“[…] processing is necessary in order to protect the vital interests of the data subject or of another natural person”).
Public interest task
Processing is based on Article 6(1)(e) GDPR (“[…] processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller”).
5. Processing Methods
Processing is carried out using manual and/or automated methods, including the use of IT and telematic tools (e.g., CRM systems, management software, mailing list services), applying appropriate technical and organisational security measures to ensure the protection, integrity, and confidentiality of Personal Data, in order to minimise the risks of destruction, loss, unauthorised access, alteration, or disclosure, in accordance with Articles 6 and 32 GDPR.
6. Transfer of Personal Data outside the EU/EEA
The Controller does not intend to transfer Personal Data outside the European Economic Area.
However, should such a transfer become necessary for organisational or operational reasons (e.g., using cloud service providers), appropriate safeguards will be adopted for transfers to third countries, including:
• verification of the existence of European Commission adequacy decisions;
• adoption of Standard Contractual Clauses and/or Binding Corporate Rules;
• assessment of any supplementary measures in accordance with EDPB Recommendation 01/2020.
Provider Name | Description | Provider Privacy Policy
(Table placeholder—let me know if you need it completed.)
7. Storage Periods
Personal Data are retained only for the time necessary to fulfil the purposes described in this document or for the periods established by applicable law.
Specifically:
• Personal Data processed for “Service Provision” will be retained for no longer than 10 years.
• Personal Data processed for “Payments and Invoicing” will be retained for no longer than 10 years (Art. 2220 Italian Civil Code).
• Personal Data processed for Direct Marketing purposes will be retained for no longer than 2 years, or until consent is withdrawn.
• The duration of individual cookies is specified in the “Cookie Policy”.
• The Controller may retain Personal Data for the period permitted by Italian law for “Judicial Protection” of its interests (Art. 2946 and 2947 Italian Civil Code).
At the end of the retention period, Personal Data will be deleted or anonymised unless retained for other purposes under an appropriate legal basis.
8. Recipients
Personal Data collected by the Controller may be communicated or made accessible, for the purposes described above, to the following categories:
• Employees and collaborators assisting the Controller in processing operations, duly authorised and subject—where required—to confidentiality agreements;
• Third-party service providers acting as Data Processors: cloud service providers, consultants, professionals assisting the Controller, hosting providers, and technical/IT maintenance service providers (including software, network, and communication system maintenance);
• Independent Data Controllers where communication is necessary for the provision of the requested service;
• Independent Data Controllers pursuing their own purposes (subject to user consent);
• Public authorities where communication is required by law.
At the end of applicable retention periods, Personal Data will be deleted or anonymised unless retained for other purposes under a suitable legal basis.
9. Rights of the Data Subject
At any time, the Data Subject may access their Personal Data and request rectification, deletion, restriction of processing, or data portability. They may also object, in whole or in part, to processing and have the right not to be subject to automated decision-making, including profiling.
To exercise the rights referred to in Articles 15–22 GDPR, the Data Subject may contact the Controller using the methods indicated in the “Contacts” section (see Art. 10).
The Controller must respond within 1 month, with the possibility of a justified extension (not exceeding 2 additional months) in cases of numerous or complex requests.
Data Subjects always have the right to lodge a complaint with the competent Supervisory Authority (Garante per la Protezione dei Dati Personali) pursuant to Article 77 GDPR if they believe the processing of their data violates applicable law.
10. Contacts
For further information regarding the processing of Personal Data performed during contract execution, or to submit a rights request, the Controller can be contacted at:
info@italiancookingexperience.com