Privacy Policy
Last updated: 7 May 2025
DATA CONTROLLER
The Data Controller is: Alessio Donigi
Registered Office: Via Umberto Giordano, 95 – 00124 Rome – Italy
Operational Office/Shop: Via Gianfilippo Usellini 459 – 00124 Rome – Italy
Contact Email: tuttiatavolasrls@gmail.com
01. Purpose of Processing
Users' personal data are processed for the following purposes:
-
Managing online orders and home delivery of food products (including gluten-free, vegan, or suitable for individuals with intolerances or allergies)
-
Responding to information requests via forms or email contacts
-
Fulfilling tax and administrative obligations
-
Sending informational and promotional newsletters (only with prior consent)
-
Performing anonymous statistical analysis on site usage (via analytical cookies)
-
Managing website security and preventing abuse or fraud
02. Legal Basis for Processing
Data processing is based on the following legal grounds:
-
Performance of a contract or pre-contractual measures (Art. 6.1.b GDPR)
-
Legal obligations of the Controller (Art. 6.1.c GDPR)
-
Data subject’s consent (Art. 6.1.a GDPR) for promotional activities and newsletter delivery
-
Legitimate interest of the Controller (Art. 6.1.f GDPR), such as website security
03. Types of Data Processed
-
Identification and contact data: name, surname, email address, phone number
-
Order-related data: delivery address, dietary preferences, intolerances, and allergies (only if voluntarily provided)
-
Browsing data: IP address, access logs, technical and statistical cookies
-
Any additional data voluntarily provided by the user in contact forms
04. Processing Methods
Processing is carried out electronically and, in some cases, on paper. Appropriate technical and organisational measures are in place to ensure data security.
05. Data Recipients
Data may be shared, within the limits of the purposes stated above, with:
-
Employees and collaborators authorised to process the data
-
Providers of IT services (hosting, e-commerce, email, CRM tools)
-
Accountants and legal consultants for tax compliance
-
Public authorities, where legally required
Data will not be disclosed publicly.
06. Data Transfers Abroad
Data are not transferred outside the EU, unless necessary for specific digital services (e.g., email marketing or cloud platforms), and always with adequate safeguards (e.g., standard contractual clauses).
07. Data Retention Period
-
Order-related data: 10 years (tax obligation)
-
Data collected via forms or emails: up to 24 months from the last contact, unless a contractual relationship is established
-
Data processed for marketing purposes: until consent is withdrawn, and in any case no longer than 24 months
-
Cookies: as specified in the Cookie Policy
08. Data Subject Rights
Users may exercise the following rights:
-
Access to their personal data
-
Rectification or update of data
-
Erasure (“right to be forgotten”)
-
Restriction of or objection to processing
-
Data portability
-
Withdrawal of consent (without affecting prior processing)
-
Lodge a complaint with the Supervisory Authority (www.garanteprivacy.it)
Requests must be sent via email to the Data Controller: tuttiatavolasrls@gmail.com
09. Changes to This Policy
This Privacy Policy may be subject to updates. Users are advised to check it periodically. In the event of substantial changes, users will be informed via appropriate channels.
