This Privacy Policy describes how Olio di Nonno Tullio ("Controller") collects, uses and protects the personal data of users who browse or purchase on this website, in compliance with EU Regulation 2016/679 (GDPR).
1. Data Controller
Olio di Nonno Tullio -Ofena (AQ), Abruzzo, Italy. To exercise your rights or request information, please contact us through the Contact page.
2. Data Collected
We collect only the data strictly necessary for the stated purposes: first and last name, email address, shipping and billing address, payment data (processed securely by Stripe, without direct access on our part), language and communication preferences.
3. Purpose and Legal Basis
- Account management and authentication -legal basis: contract performance (Art. 6.1.b GDPR)
- Order processing and shipping -legal basis: contract performance (Art. 6.1.b GDPR)
- Transactional communications (order confirmation, shipping updates) -legal basis: contract performance
- Tax and legal compliance -legal basis: legal obligation (Art. 6.1.c GDPR)
- Newsletter and promotional communications -legal basis: consent (Art. 6.1.a GDPR), withdrawable at any time
4. Data Retention
Order-related data is retained for 10 years in compliance with Italian tax obligations. Account data is deleted upon request, unless legal obligations prevent this. Newsletter data is removed upon unsubscription.
5. Data Sharing
Your data is never sold or transferred to third parties for marketing purposes. It is shared only with parties necessary to provide the service: Appwrite (authentication and database, EU infrastructure), Stripe (payments), couriers for order delivery.
6. Cookies and Tracking
This website uses only strictly necessary technical cookies for functionality (login session). We do not use profiling cookies, third-party cookies or behavioural tracking tools.
7. Your Rights
As a data subject, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request erasure (right to be forgotten)
- Object to or request restriction of processing
- Request data portability
- Withdraw consent at any time, without affecting prior processing
To exercise these rights, contact us via the Contact page. You also have the right to lodge a complaint with your national data protection authority.
8. Security
We implement appropriate technical and organisational measures to protect your data from unauthorised access, loss or disclosure. All communications are encrypted via HTTPS.