Privacy Policy of www.fattoriasantostefano.it
This Web Site collects certain Personal Data of its Users.
This document can be printed by using the print command in the settings of any browser.
Data Controller
Fattoria Santo Stefano di Bendinelli Elena e Fratelli Società Agricola – via Collegalle, 3- 50022 – Greve in Chianti (FI) – P.Iva 05031980484
Owner’s email address: info@fattoriasantostefano.it

Types of Data Collected
Among the Personal Data collected by this Website, either autonomously or through third parties, there are: name; surname; telephone number; email; various types of Data; Cookie; Usage Data; address; VAT number; company name; Tax Code; country; state; province; postal code; city; billing address; street number; Data communicated during the use of the service.
Full details on each type of data collected are provided in the dedicated sections of this privacy policy or by means of specific information texts displayed before the data is collected.
Personal Data may be freely provided by the User or, in the case of User Data, automatically collected during the use of this Web Site.
Unless otherwise specified, all Data requested by this Web Site are mandatory. If the User refuses to provide it, it may be impossible for this Web Site to provide the Service. In cases where this Web Site indicates certain Data as optional, Users are free to refrain from communicating such Data, without any consequences on the availability of the Service or its operation.
Users in doubt as to which Data are mandatory are encouraged to contact the Data Controller.
The possible use of Cookies – or of other tracking tools – by this Website or by the owners of third party services used by this Website, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to the further purposes described in this document and in the Cookie Policy, if available.
The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Web Site and warrants that he/she has the right to communicate or disseminate it, releasing the Owner from any liability towards third parties.

Method and place of processing of collected Data
Methods of processing
The Data Controller adopts appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of Personal Data.
The processing is carried out using computer and/or telematic tools, with organisational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, other subjects involved in the organisation of this Web Site (administrative, sales, marketing, legal, system administrators) or external subjects (such as third party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) also appointed, if necessary, Data Processors by the Data Controller, may have access to the Data. The updated list of Data Processors can always be requested from the Data Controller.
Legal basis of the processing
The Data Controller Processes Personal Data relating to the User where one of the following conditions exists
the User has given consent for one or more specific purposes; Note: in some jurisdictions, the Controller may be authorised to process Personal Data without the User’s consent or another of the legal bases specified below, until the User objects (“opts-out”) to such processing. However, this does not apply if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
processing is necessary for the performance of a contract with the User and/or the performance of pre-contractual measures;
processing is necessary for the performance of a legal obligation to which the Controller is subject;
processing is necessary for the performance of a task carried out in the public interest or in the exercise of public authority vested in the Controller;
processing is necessary for the pursuit of the legitimate interest of the Controller or of third parties.
However, it is always possible to request the Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on law, required by a contract or necessary to conclude a contract.
Location
The Data are processed at the Data Controller’s premises and at any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one where the User is located. To obtain further information on the location of the processing, the User may refer to the section on Personal Data processing details.
The User has the right to obtain information about the legal basis for the transfer of Data outside the European Union or to an international organisation under public international law or consisting of two or more countries, such as the UN, as well as about the security measures taken by the Controller to protect the Data.
The User can verify whether one of the transfers just described takes place by examining the section of this document relating to details on the processing of Personal Data or request information from the Controller by contacting him at the contact details given at the beginning.
Retention period
Data are processed and stored for the time required by the purposes for which they were collected.
Therefore:
Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the performance of such contract is completed.
Personal Data collected for purposes related to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Controller in the relevant sections of this document or by contacting the Controller.
When the processing is based on the User’s consent, the Data Controller may keep the Personal Data longer until such consent is revoked. Moreover, the Controller may be obliged to keep the Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
At the end of the retention period the Personal Data will be deleted. Therefore, at the end of this period, the right of access, cancellation, rectification and the right to Data portability can no longer be exercised.

Purposes of the Data collected
The User’s Data are collected to enable the Data Controller to provide the Service, to comply with legal obligations, to respond to requests or enforcement actions, to protect its rights and interests (or those of Users or third parties), to detect any malicious or fraudulent activities, and for the following purposes: Contacting the User, Managing payments, Managing contacts and sending messages, Managing User databases, Registration and authentication provided directly by this Website, Displaying content from external platforms, Interaction with social networks and external platforms, Managing data collection and online surveys and Statistics.
To obtain detailed information on the purposes of the processing and the Personal Data processed for each purpose, the User may refer to the section “Details on the processing of Personal Data”.

Details of Personal Data processing
Personal Data is collected for the following purposes and using the following services:
Contact Form (this Web Site)
• The User, by filling out the contact form with his/her Data, consents to their use to respond to requests for information, quotes, or any other nature indicated by the header of the form.
Personal Data processed: last name; email; first name; phone number; various types of Data.
Mailing list or newsletter (this Web Site)
• By registering for the mailing list or newsletter, the User’s email address is automatically added to a list of contacts to whom email messages containing information, including of a commercial and promotional nature, relating to this Web Site may be sent. The User’s email address may also be added to this list as a result of registering with this Web Site or after making a purchase.

Personal Data Processed: email; name.

User Database Management
• These types of services allow the Data Controller to build User profiles from an email address, name or any other information the User provides to this Web Site, as well as to track the User’s activities through statistical features. This Personal Data may also be cross-referenced with publicly available information about the User (such as profiles on social networks) and used to build private profiles that the Owner may view and use to improve this Web Site.
Some of these services may also allow the scheduled sending of messages to the User, such as emails based on specific actions taken on this Web Site.
– SendinBlue Marketing Automation (SendinBlue SAS).
SendinBlue is a User database management service provided by SendinBlue SAS.
Personal Data Processed: Cookies; Usage Data; Email.
Place of processing: France – Privacy Policy.
– Divinea Wine Suite Database and Newsletter ( https://divinea.com/privacy )
Personal Data Processed: Cookies; Usage Data; email.
Place of processing: Italy – Privacy Policy.

Management of data collection and online surveys
• This type of service allows this Web Site to manage the creation, implementation, administration, distribution and analysis of online forms and surveys in order to collect, save and reuse Data from responding Users.
The Personal Data collected depend on the information requested and provided by Users in the corresponding online form.
• These services may be integrated with a wide range of third-party services to enable the Owner to perform subsequent actions with the processed Data – for example, contact management, message sending, statistics, advertising, and payment processing.
• Facebook Contact Acquisition Ads (Meta Platforms Ireland Limited).
Facebook Contact Acquisition Ads is an advertising and data collection service provided by Meta Platforms Ireland Limited that enables it to show Users advertisements in the form of forms already pre-populated with Personal Data from their Facebook profiles, such as names and email addresses. Depending on the type of ad, Users may be asked to provide additional information. Submission of the form involves the collection and processing of this Data by the Data Controller pursuant to this privacy policy and only for the specific purpose stated in the form and/or within this privacy policy, where applicable. You may exercise your rights, at any time, including the right to withdraw your consent to the processing of your Data, as specified in the section containing information about your rights in this privacy policy.
Personal Data Processed: Data disclosed during the use of the service.
Place of processing: Ireland – Privacy Policy – Opt out.

Registration and authentication provided directly by this Web Site
• By registration or authentication, the User allows this Web Site to identify him/her and give him/her access to dedicated services. Personal Data are collected and stored for registration or identification purposes only. The Data collected are only those necessary to provide the service requested by the User.
Direct Registration (this Website)
• The User registers by filling in the registration form and directly providing this Web Site with his/her Personal Data.
Personal Data processed: ZIP code; city; tax code; last name; email; address; billing address; country; name; house number; phone number; VAT number; province; company name; state; various types of Data.

Displaying content from external platforms
• This type of service allows users to view content hosted on external platforms directly from the pages of this Web Site and interact with them.
However, this type of service may collect web traffic data related to the pages where the service is installed, even when users are not using it.
Font Awesome (Fonticons, Inc. )
Font Awesome is a font style display service operated by Fonticons, Inc. that allows this Web Site to integrate such content within its pages.
Personal Data Processed: Usage Data; Tracking Tools.
Place of processing: United States – Privacy Policy.
• Google Fonts (Google Ireland Limited)
Google Fonts is a font style display service operated by Google Ireland Limited that enables this Web Site to integrate such content within its pages.
Personal Data Processed: Usage Data; Tracking Tools.
Place of processing: Ireland – Privacy Policy.
• YouTube Video Widget (Google Ireland Limited).
YouTube is a video content display service operated by Google Ireland Limited that enables this Web Site to embed such content within its pages.
Personal Data Processed: Cookies; Usage Data.
Place of processing: Ireland – Privacy Policy.

Managing contacts and sending messages
• These types of services allow the management of a database of email contacts, telephone contacts, or contacts of any other type used to communicate with the User.
These services may also allow for the collection of data related to the date and time of the User’s viewing of messages, as well as the User’s interaction with them, such as information about clicks on links included in messages.
• SendinBlue Email (SendinBlue SAS).
SendinBlue is an address management and email message sending service provided by SendinBlue SAS.
Personal Data Processed: Cookies; Usage Data; email.
Place of processing: France – Privacy Policy.
• Divinea Wine Suite Database and Newsletter ( https://divinea.com/privacy )
Personal Data Processed: Cookies; Usage Data; email.
Place of processing: Italy – Privacy Policy.

Payment Handling
• Payment processing services allow this Web Site to process payments by credit card, bank transfer or other means. The data used for payment is acquired directly from the operator of the requested payment service without being processed in any way by this Web Site.
Some of these services may also allow the scheduled sending of messages to the User, such as emails containing invoices or notifications regarding payment.
• PayPal (Paypal)
PayPal is a payment service provided by PayPal Inc. that allows the User to make online payments.
Personal Data processed: various types of Data as specified by the privacy policy of the service.
Place of processing: See Paypal’s privacy policy – Privacy Policy.
• Stripe (Stripe Inc)
Stripe is a payment service provided by Stripe Inc.
Personal Data processed: various types of Data as specified by the privacy policy of the service.
Place of processing: United States – Privacy Policy.

Interaction with social networks and external platforms
• This type of service allows for interactions with social networks, or other external platforms, directly from the pages of this Web Site.
Interactions and information captured by this Web Site are in each case subject to the User’s privacy settings related to each social network.
This type of service may still collect traffic data for the pages where the service is installed, even when Users are not using it.
It is recommended to disconnect from the respective services to ensure that the data processed on this Website is not linked back to the User’s profile.
• Facebook Like Button and Social Widgets (Meta Platforms Ireland Limited).
The Facebook “Like” button and social widgets are services for interaction with the social network Facebook, provided by Meta Platforms Ireland Limited
Personal Data Processed: Usage Data; Tracking Tool.
Place of processing: Ireland – Privacy Policy.

Statistics
• The services contained in this section allow the Data Controller to monitor and analyze traffic data and are used to track User behavior.
• Matomo (this Website)
Matomo is a statistical software used by this Web Site to analyze data directly and without the help of third parties.
Personal Data Processed: Usage Data; Tracking Tools.

Information on how to turn off interest-based advertisements
In addition to any opt-out features provided by any of the services listed in this document, Users can read more about how to turn off interest-based advertisements in the appropriate section of the Cookie Policy.

Further information on the processing of Personal Data
Sale of goods and services online
The Personal Data collected is used to provide services to the User or to sell products, including payment and possible delivery. The Personal Data collected to finalize the payment may be that related to the credit card, bank account used for the transfer or other payment instruments provided. The Payment Data collected by this Web Site depends on the payment system used.

User Rights
Users may exercise certain rights with respect to the Data processed by the Data Controller.
In particular, the User has the right to:
– revoke consent at any time. The User may revoke the consent to the processing of its Personal Data previously expressed.
– object to the processing of their Data. The User may object to the processing of its Data when it is done on a legal basis other than consent. Further details on the right to object are provided in the section below.
– access to one’s own Data. The User has the right to obtain information about the Data processed by the Data Controller, certain aspects of the processing and to receive a copy of the Data processed.
– verify and request rectification. The User may verify the correctness of its Data and request that it be updated or corrected.
– obtain restriction of processing. When certain conditions are met, the User may request the limitation of the processing of its Data. In this case, the Data Controller will not process the Data for any purpose other than its preservation.
– Obtain the deletion or removal of their Personal Data. When certain conditions are met, the User may request the deletion of their Data by the Data Controller.
– Receive their Data or have it transferred to another Data Controller. The User has the right to receive its Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred unimpeded to another data controller. This provision is applicable when the Data are processed by automated means and the processing is based on the User’s consent, a contract to which the User is a party or contractual measures related thereto.
– Propose Complaint. The User may propose a complaint to the competent data protection supervisory authority or take legal action.
Details on the right to object
When Personal Data are processed in the public interest, in the exercise of public powers vested in the Data Controller or in pursuit of a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.
Users should note that if their Data were processed for direct marketing purposes, they may object to the processing without providing any reasons. To find out whether the Data Controller processes Data with direct marketing purposes, Users may refer to the respective sections of this document.
How to Exercise Rights
To exercise the User’s rights, Users may address a request to the contact details of the Controller indicated in this document. Requests are filed free of charge and processed by the Owner as soon as possible, in any case within one month.
Cookie Policy
This Website makes use of Tracking Tools. To learn more, the User may consult the Cookie Policy.

Additional information on treatment
Defense in Court
The User’s Personal Data may be used by the Data Controller in court or in the preparatory stages of its possible establishment for the defense against abuses in the use of this Web Site or related Services by the User.
The User declares that he/she is aware that the Data Controller may be obliged to disclose the Data by order of public authorities.
Specific Disclosures
Upon the User’s request, in addition to the information contained in this privacy policy, this Web Site may provide the User with additional and contextual disclosures regarding specific Services, or the collection and processing of Personal Data.
System Logs and Maintenance
For operation and maintenance purposes, this Web Site and any third-party services it uses may collect system logs, i.e., files that record interactions and may also contain Personal Data, such as the User’s IP address.
Information not contained in this policy
Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.
Responding to “Do Not Track” Requests
This Web Site does not support “Do Not Track” requests.
To find out whether any third-party services used support them, the User is encouraged to consult their respective privacy policies.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Website as well as, if technically and legally feasible, by sending a notification to Users through one of the contact details it has. Therefore, please consult this page frequently, referring to the date of last modification indicated at the bottom.
If the changes affect processing whose legal basis is consent, the Controller will collect the User’s consent again, if necessary.

Definitions and legal references
– Personal Data (or Data)
Personal Data is any information that, directly or indirectly, including in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.
– Usage Data
This is the information collected automatically through this Web Site (including by third party applications integrated into this Web Site), including: the IP addresses or domain names of the computers used by the User who connects with this Web Site, the addresses in URI (Uniform Resource Identifier) notation, the time of the request, the method used in forwarding the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc.. ) the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (e.g. the length of time spent on each page) and the details of the itinerary followed within the Application, with particular reference to the sequence of pages consulted, the parameters relating to the User’s operating system and computer environment.
– User
The individual using this Web Site who, except where otherwise specified, coincides with the Data Subject.
– Data Subject
The natural person to whom the Personal Data refers.
– Data Controller (or Processor)
The natural person, legal entity, public administration and any other entity that processes Personal Data on behalf of the Data Controller, as set out in this privacy policy.
– Data Controller (or Controller).
The natural or legal person, public authority, service or other body which, individually or jointly with others, determines the purposes and means of the processing of personal data and the instruments adopted, including the security measures relating to the operation and use of this Web Site. The Data Controller, unless otherwise specified, is the owner of this Web Site.
– This Web Site (or this Application)
The hardware or software tool by which Users’ Personal Data are collected and processed.
– Service.
The Service provided by this Web Site as defined in the relevant terms (if any) on this site/application.
– European Union (or EU).
Unless otherwise specified, any reference to the European Union in this document shall be deemed to extend to all current member states of the European Union and the European Economic Area.
– Cookies
Cookies are Tracking Tools that consist of small portions of data stored within the User’s browser.

– Tracking Tool
Tracking Tool means any technology – e.g., Cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting – that enables tracking of Users, for example, by collecting or storing information on the User’s device.
– Legal references
This privacy policy is written on the basis of multiple legislative orders, including Articles 13 and 14 of Regulation (EU) 2016/679.

Unless otherwise stated, this privacy policy covers this Website only.

Last modified: August 3, 2022