PRIVACY POLICY
Information Notice pursuant to Article 13 of Regulation (EU) 2016/679
Dear User,
V.O.LA s.n.c. (“V.O.LA”), as Data Controller, pursuant to Article 13 of EU Regulation 2016/679 (“GDPR”) and Legislative Decree 196/2003 as amended by Legislative Decree 101/18, hereby provides information on how it processes the personal data of users who access the website available at:
This notice does not apply to other websites, pages or online services that may be accessed via hyperlinks published on this site.
In this document, we explain:
What does “data processing” mean?
Under Article 4 of EU Regulation 2016/679, “processing” means any operation or set of operations, whether or not performed by automated means, applied to personal data or sets of personal data—such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission or dissemination, comparison or interconnection, restriction, erasure, or destruction.
Who is the Data Controller?
The Data Controller is V.O.LA s.n.c., VAT no. 01095670723, with registered office in Via Ravanas 1, 70037 Ruvo di Puglia (BA), Italy.
The Controller may be contacted at: vinicola@lamonarca.it
What types of data do we process?
V.O.LA processes two categories of personal data:
Browsing data generated through access to the website
Identifying data voluntarily provided by the user
Browsing Data
This includes information implicitly transmitted through Internet communication protocols, such as IP addresses, domain names of computers or devices used by users, URI/URL identifiers of requested resources, time of request, method used to submit the request, size of the response, numerical status code (success, error, etc.), and other parameters relating to the user’s operating system and device environment.
Some data may also be collected using cookies. Although not collected to identify users directly, such data could, through processing or association with third-party data, allow user identification.
Information about cookies and similar technologies is available in the dedicated COOKIE POLICY section of the site.
Identifying Data
Voluntary, explicit submission of messages to the Controller’s contact addresses, messages sent to our social media pages (where applicable), and the completion of the contact form all imply the acquisition of the sender’s contact details and any personal data included in the communication.
This may include: name, surname, place and date of birth, residence, phone number, email address.
Why do we process your data?
Purposes relating to browsing data:
enabling navigation of the website
obtaining statistical information on service use (most visited pages, number of visitors by time slot, geographical origin, etc.)
verifying the proper functioning of the services offered
Purposes relating to identifying data provided by the user:
– access to services offered by V.O.LA
– responding to requests for information submitted via the contact details listed on the website
– responding to requests submitted through the contact form (name, email, phone number, etc. are processed exclusively to respond to the request)
– direct marketing activities, such as sending advertising material, promotions, offers, newsletters, or conducting market research or opinion surveys—only where consent is provided
– processing and managing purchase orders made through the website (including order fulfilment and shipping)
– inviting users to leave product reviews following a purchase, which may be published on the website
– managing payments made via bank transfer, credit card, or PayPal (for PayPal payments, data is processed by PayPal according to its own privacy policy: https://www.paypal.com/webapps/mpp/ua/privacy-full)
Purposes required by law:
compliance with legal obligations under national, EU, or international regulations
establishing, exercising, or defending legal claims
What is the legal basis for processing your data?
Processing is carried out pursuant to Article 6 of the GDPR:
Browsing data: Art. 6(1)(f) — legitimate interest of the Controller
Identifying data for services, information requests, orders, payments:
Art. 6(1)(a) — consent
Art. 6(1)(b) — performance of a contract or pre-contractual measures
Marketing and reviews:
Art. 6(1)(a) — consent
Art. 130(4) of the Italian Privacy Code (email marketing for similar services)
Art. 6(1)(f) — legitimate interest, where appropriate
Legal obligations: Art. 6(1)(c)
Legal claims: Art. 6(1)(f)
How are your data processed, communicated, and disclosed?
Data are not disseminated but may be communicated to:
– authorised staff or external data processors (e.g., hosting providers, web agencies)
– insurance entities (in case of claims)
– public authorities when required by law
– lawyers, law enforcement, or judicial authorities in case of unlawful acts or disputes
– third parties performing administrative, accounting, or tax activities on behalf of the Controller
The Controller will appoint external processors under Article 28 GDPR.
A list of processors is available upon request.
How long do we retain your data?
Browsing data: not retained beyond the browsing session, except for cookie-related data
Information requests: retained only for the time required to fulfil the request
Service provision / contracts: retained according to applicable legal and contractual requirements
Legal obligations: retention is determined by the applicable law
Legal claims: retained only while necessary for possible judicial proceedings
Marketing:
until consent is withdrawn (Art. 7 GDPR), or
until objection is raised (Art. 21 GDPR) for processing based on legitimate interest or Art. 130(4)
Where is your data processed? Is data transferred outside the EU?
Data processing is carried out at the Controller’s operating sites or where involved parties are located.
The Controller does not transfer data outside the EU.
If a transfer becomes necessary, it will comply with Articles 44–49 GDPR.
What are your rights?
You may exercise the rights provided in Articles 15–22 of the GDPR, including the rights to:
– access your personal data
– know the origin, purposes, and methods of processing
– request rectification, updating, or completion
– request erasure, anonymisation, or restriction of processing
– object to processing for legitimate reasons or for marketing purposes
– request data portability, where applicable
– withdraw consent at any time
Requests can be made directly to the Controller using the contact details above.
The Controller will respond within 14 days.
Data breaches
If you become aware of a data breach or unlawful disclosure of your personal data, you must promptly notify the Controller.
The Controller must notify the Italian Data Protection Authority within 72 hours and inform you where required.
You may also lodge a complaint with the Italian Data Protection Authority:
www.garanteprivacy.it
In case of disputes regarding this document, jurisdiction lies with the Consumer’s Court, pursuant to Legislative Decree 206/2005.
Cookie Notice
Information about cookies and similar technologies is available in the Cookie Policy located in the footer of the website.
For any information, clarification, or to exercise your rights, contact the Controller at the email listed above.
Privacy Policy updated on April 18, 2023