Privacy policy

Last updated: 26/08/2026

This Privacy Policy (“Policy”) describes how personal data of users who browse the website www.sangiuseppesrl.com (“Site”) or interact with its features are processed, pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree no. 196/2003 as amended by Legislative Decree 101/2018 (“Privacy Code”).

1. Data Controller

The Data Controller is:
San Giuseppe S.r.l.
Registered Office: Via Divisione Nino Nannetti, 122 — 31029 Vittorio Veneto (TV), Italy
Administrative and Operational Office: Via Montello, 5 — 31020 San Fior (TV), Italy
VAT/Tax code: IT04841710264 — R.E.A.: TV 402654
Share capital: € 12,000.00 fully paid-up
Email: info@sangiuseppesrl.com
PEC: sangiuseppepec@pec.it
Phone: +39 0438 50.16.43

No Data Protection Officer (DPO) has been appointed, as the conditions set out in Art. 37 GDPR do not apply.

2. Categories of data processed

  • Contact data voluntarily provided through the “Contacts” form: first and last name, email address, phone number (optional), content of the message.
  • Browsing data: IP address, browser type, operating system, visited pages, date and time of access. Such data are automatically collected by the Site servers and related logs for security and technical-diagnostic purposes.
  • B2B area authentication data (for registered resellers only): login credentials, personal and business data provided upon registration.
  • Cookie and similar technology data: see the Cookie Policy for details.

3. Purposes and legal basis

Purpose Legal basis
Replying to contact requests submitted through the Site Art. 6.1.b GDPR (pre-contractual measures at the data subject’s request) and Art. 6.1.a GDPR (consent)
Management of the B2B reserved area and business relationships with resellers Art. 6.1.b GDPR (performance of a contract)
Ensuring Site security, preventing fraud, abuse and automated activity (e.g. reCAPTCHA) Art. 6.1.f GDPR (legitimate interest in system security)
Compliance with legal, tax and accounting obligations and legal defence Art. 6.1.c GDPR (legal obligation) and Art. 6.1.f GDPR (legitimate interest)

Providing mandatory data in the contact form is necessary to enable the Controller to respond to the request; failure to provide such data makes it impossible to reply. Providing the phone number is optional.

4. Processing methods

Data are processed using IT tools and, residually, on paper, with logic strictly related to the stated purposes and in compliance with the principles of lawfulness, fairness, transparency, minimisation, accuracy, storage limitation, integrity and confidentiality set out in Art. 5 GDPR. Appropriate technical and organisational measures are in place to prevent unauthorised access, loss, alteration or unauthorised disclosure.

5. Recipients of data

  • Authorised personnel of the Controller, duly instructed pursuant to Art. 29 GDPR;
  • Technical and hosting service providers, appointed as Data Processors pursuant to Art. 28 GDPR;
  • Professionals and consultants (accountant, lawyer, IT) for legal obligations or dispute management;
  • Public, judicial or supervisory authorities when required by law.

Data are not disseminated and not subject to automated decision-making, including profiling.

6. Third-party services

  • Google reCAPTCHA v2 (Google Ireland Limited) — anti-spam protection on the contact form. Data processed: IP address, browser information, user interactions. Policy: policies.google.com/privacy.
  • Google Maps (Google Ireland Limited) — map display on the Contacts page. Data processed: IP address, device information. Policy: policies.google.com/privacy.

7. Transfer outside the EU

Some third-party services (notably Google) may involve the transfer of personal data outside the European Economic Area. Such transfers take place on the basis of the safeguards provided for by Articles 44 et seq. GDPR, such as Standard Contractual Clauses approved by the European Commission and adequacy decisions (where applicable).

8. Retention period

  • Contact form data: retained for the time needed to manage the request and, in any case, no longer than 24 months from the last contact, unless other legal obligations or defence requirements apply.
  • Browsing logs: retained for up to 12 months.
  • B2B area data: retained for the duration of the business relationship and, thereafter, for legal prescription periods (typically 10 years for tax/accounting obligations).
  • Cookie-related data: retained according to the terms in the Cookie Policy.

9. Rights of the data subject

Pursuant to Articles 15-22 GDPR, you have the right to:

  • access your personal data and obtain a copy (Art. 15);
  • request rectification (Art. 16);
  • request erasure “right to be forgotten” (Art. 17);
  • request restriction of processing (Art. 18);
  • receive the data in a structured, commonly used format (portability, Art. 20);
  • object to processing based on legitimate interest (Art. 21);
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal (Art. 7.3);
  • not be subject to automated decisions (Art. 22).

Requests can be sent to: info@sangiuseppesrl.com. The Controller will respond within 30 days.

10. Right to lodge a complaint

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali — Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it) or with the supervisory authority of your EU Member State of residence.

11. Changes to this Policy

This Policy may be updated over time, including as a result of legal changes. The current version is always published on this page, with the date of the last update.