Perfetto 👍
Si tratta di una traduzione legale estesa e deve essere accurata e coerente con la terminologia GDPR.
Per mantenere chiarezza e correttezza, dividerò la traduzione in sezioni (titoli, paragrafi e liste), ripulendo il codice HTML WordPress ma conservando la struttura leggibile per il web.
Ecco la prima parte tradotta e pulita 👇
⸻
Privacy Policy pursuant to EU Regulation No. 679/2016 (GDPR) and other applicable regulations
This privacy notice is addressed to all Users/Data Subjects who visit and interact with the website of Top Cucina Eventi Srl and its related e-commerce platform.
Top Cucina Eventi Srl manages sales carried out through the e-commerce system via:
- its own bank (in the case of payment by bank transfer); or
- PayPal or Nexi XPay (in the case of payment via PayPal/Nexi XPay account or credit card); or
- the courier (in the case of payment on delivery).
Furthermore, to purchase products from this website, registration on the e-commerce platform is required. Registration allows purchases to be made without the need to create an account beforehand.
Top Cucina Eventi Srl processes the personal data provided by the User/Data Subject during registration and for the possible conclusion of an online purchase contract, in full compliance with EU Regulation 679/2016 (GDPR) and applicable national legislation.
1. Data Controller (Processor and Authorized Personnel)
The Data Controller is Top Cucina Eventi Srl, with registered office at Viale Carso 23, 00195 Rome, Italy, contactable at info@natalegiunta.it.
Type and Purpose of Data Processing
The personal data voluntarily provided during the use of the e-commerce service and through registration will be processed for the following purposes:
- to allow registration on the e-commerce platform and manage access to related services;
- to enable and facilitate online product purchases and the conclusion of purchase contracts;
- to maintain and manage the account created after registration;
- to store personal data and information in the created account (e.g., personal details, order/purchase/return history, preferred delivery and billing addresses);
- to allow products to be added to the cart and complete the online purchase process;
- to execute purchase contracts and related obligations, and to comply with all applicable legal requirements;
- to fulfill administrative, accounting, and tax obligations connected to e-commerce services or concluded purchase contracts (e.g., bookkeeping, issuing invoices);
- to deliver products sold via courier services;
- to provide general assistance and customer care services (e.g., responding to user inquiries, handling complaints and feedback);
- to handle requests regarding the right of withdrawal, warranty of conformity, or any other rights arising from the purchase contract or applicable law, including related refunds if applicable;
- to respond to requests regarding data protection rights under the GDPR and to perform all related activities;
- for marketing and/or profiling purposes only when expressly, freely, and separately consented to by the User/Data Subject;
- to manage and, if necessary, prevent fraudulent or unlawful uses of the e-commerce platform;
- to ensure compliance with the contractual rights of the Data Controller and the related legitimate interest (e.g., demonstrating the fulfillment of contractual or legal obligations).
In addition, while browsing the e-commerce platform or accessing the personal area, navigation data may be collected solely to obtain anonymous statistical information on site usage and to ensure proper operation. Such data will not be associated with other sources unless concrete evidence of illegal use arises.
Regarding the use of cookies within the e-commerce platform, please refer to the Cookie Policy.
Data processing for purposes other than those specified above will only occur with the explicit consent of the Data Subject.
Nature of Data Provision
The provision of data:
- in the registration form fields for the personal area of the e-commerce platform; or
- in the order, delivery, or billing form fields within the personal area of the e-commerce platform;
is optional, except for the fields marked as mandatory.
These mandatory fields are necessary to ensure:
- compliance with contractual and legal obligations;
- the correct and lawful use of the e-commerce platform;
- the protection of intellectual property and related rights;
- the achievement of the purposes outlined above.
Therefore, refusal by the Data Subject to provide the required data will make it impossible to complete a purchase, conclude a contract, and receive the selected products through the e-commerce system.
After purchasing products through the e-commerce platform, data relating to purchases, shipping and tracking, complaints, returns, cancellations, and other activities performed by the Data Subject will be collected in order to maintain a record of their purchase history and current status.
4. Methods of Processing
Data will be processed using electronic, paper-based, and any other appropriate means necessary to achieve the purposes described in this notice and the related contract, in full compliance with applicable security standards and legislation.
The personal data provided by the Data Subject at the time of registration and for subsequent purchases will be stored within the e-commerce platform and in other archives located at the Data Controller’s headquarters, exclusively for the purposes specified above.
The Data Controller undertakes to adopt all appropriate security measures to prevent data loss, unlawful or improper use, and unauthorized access, in full compliance with laws and regulations.
5. Lawfulness of Processing
The Data Subject must give consent to the processing of their personal data for the purposes outlined in this Privacy Policy in order to register on the e-commerce platform.
With regard to product purchases through the e-commerce platform, the processing of data is necessary for the performance of the purchase contract and for compliance with the associated legal obligations.
6. Disclosure of Data to Third Parties
The Data Subject’s data will be disclosed to third parties only to the extent strictly necessary to fulfill contractual or legal obligations and/or solely upon explicit request from the Data Subject.
The entities to which the data may be disclosed act as external data processors appointed by the Data Controller through a specific contract (“Data Processors”) or as individuals authorized to process data under the direct authority of the Data Controller (“Authorized Persons”), except in cases where the recipient acts as an independent data controller, such as couriers.
Data may also be provided to competent authorities where required by law.
Data may therefore be disclosed by the Data Controller to the following categories of recipients:
- Companies, consultants, or professionals responsible for the installation, maintenance, updating, or general management of the Data Controller’s hardware and software systems, including cloud service providers;
- Companies providing logistics, warehousing, packaging, shipping, delivery, or product return support services for the e-commerce platform;
- Public authorities or institutions that have access to data under legal or administrative provisions;
- Public and/or private entities, whether individuals or legal persons (such as legal, administrative, or tax consultants), when communication is necessary or functional to the correct fulfillment of contractual or legal obligations, or for the establishment, exercise, or defense of a legal claim.
7. Data Transfers to Third Countries
The personal data of Data Subjects are not transferred to non-EU countries.
8. Retention of Personal Data
The data provided will be stored only for the time strictly necessary to perform each processing activity (for example: registration data will be processed until the account is closed, taking into account the necessary technical time for completion; data related to a purchase will be processed until delivery, or, in case of non-delivery, until the contract is terminated, etc.).
Once these periods have expired, data will still be retained for one additional year, unless a longer period is required by law or justified by the legitimate interest of the Data Controller.
After this period, personal data collected through the e-commerce platform will be deleted, except for data necessary to comply with legal or tax obligations, which will be retained for the maximum periods provided by applicable laws and regulations (for example: 10 years for fiscal obligations).
9. Security Measures
The transfer, storage, and processing of data collected through the e-commerce platform are protected by appropriate technical and security measures.
All information provided by the Data Subject is protected by access credentials chosen by the user. Passwords are not stored in plain text but encrypted using MD5 technology.
In addition, the e-commerce platform operates over an HTTPS encrypted connection using SSL certificates to ensure user and data protection.
All personal data are collected, stored, and maintained on secure servers protected by firewalls and located within controlled-access data centers in Italy or the EU. Any paper-based records are stored in secure physical archives, in full compliance with safety regulations.
10. Rights of the Data Subject
The Data Subject has the right to:
- Obtain confirmation of the existence, content, and origin of their personal data, even if not yet recorded, and receive such data in an intelligible form without undue delay.
- Request, in writing, information regarding their stored personal data (e.g., source, purposes, processing methods, categories, logic applied, retention period, rights, identification details of the Data Controller, and recipients).
- Withdraw consent to data processing at any time.
- Request the deletion of their data.
- Request restriction, anonymization, or blocking of unlawfully processed data.
- Update, correct, or integrate their personal data.
- Obtain their personal data, provided to the Data Controller, in a structured, commonly used, and machine-readable format, and transmit them to another Data Controller (data portability).
- Receive confirmation that the above operations have been communicated to those to whom the data were disclosed, unless this proves impossible or involves a disproportionate effort.
- Object, in whole or in part, for legitimate reasons, to the processing of personal data concerning them, even if relevant to the purpose of collection.
- Lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
For more information about privacy rights, the Data Subject is invited to visit the website of the Italian Data Protection Authority:
www.garanteprivacy.it.
Data Subjects wishing to exercise any of their rights may contact the Data Controller using the details provided below.
Useful Information
Company Name: TOP Cucina Eventi Srl (single-member company)
Registered Office: Viale Carso 23, 00195 Rome, Italy
VAT No.: 0640638082
REA: PA-318979
Chamber of Commerce: Palermo and Enna
Share Capital: €10,000.00 (fully paid)