Privacy Policy
Last updated: 2026-07-16 · version 2.0
Data Controller
- Company name
- [DA COMPLETARE: denominazione/ragione sociale legale] ([DA COMPLETARE: forma giuridica, es. "Ditta individuale" o "S.r.l."])
- Owner
- [DA COMPLETARE: titolare/legale rappresentante]
- Registered office
- [DA COMPLETARE: via e numero civico] — [DA COMPLETARE: CAP] [DA COMPLETARE: città] ([DA COMPLETARE: provincia]), Italia
- VAT number
- [DA COMPLETARE: P.IVA, es. IT01234567890]
- Certified email (PEC)
- [DA COMPLETARE: indirizzo PEC]
- Privacy email
- privacy@acasadidante.it
This policy describes how the personal data of users who visit this site and use our services is processed, pursuant to Regulation (EU) 2016/679 (“GDPR”) and to Legislative Decree 196/2003 (D.Lgs. 196/2003) as amended by Legislative Decree 101/2018 (D.Lgs. 101/2018). The identification details and contact information of the Data Controller are indicated in the box above.
1. Categories of data processed
We process the following categories of personal data:
- Registration and account data: name, email address, password (stored exclusively in encrypted form via hashing), and possibly telephone number and address.
- Order and shipping data: first and last name, shipping address (street, city, postal code, country), email, telephone (optional), order contents, amount, delivery notes.
- Payment data: payment is made via PayPal; card or account data does not transit through nor is it stored on our servers. From the payment provider we receive only the outcome of the transaction and an identifier.
- Browsing data and cookies: IP address, browser/device type, pages visited and interactions, collected via cookies and similar tools (see the Cookie Policy) only with your prior consent for the non-necessary categories.
- Newsletter data: email address and subscription status, if you subscribe.
- Reviews and support communications: content of product reviews and of messages sent to customer support.
2. Purposes and legal bases
| Purpose | Legal basis (art. 6 GDPR) |
|---|---|
| Account registration, order management, shipping and support | Performance of the contract or of pre-contractual measures (art. 6.1.b) |
| Tax and accounting obligations (issuance and retention of tax documents) | Legal obligation (art. 6.1.c) |
| Sending the newsletter and commercial communications | Consent, revocable at any time (art. 6.1.a) |
| Statistics and site improvement (analytics cookies) | Consent (art. 6.1.a) |
| Marketing and campaign measurement (marketing cookies) | Consent (art. 6.1.a) |
| Site security, prevention of fraud and abuse | Legitimate interest (art. 6.1.f) |
| Management and publication of reviews | Consent and legitimate interest (art. 6.1.a/f) |
Providing the data necessary for the performance of the contract is optional, but refusal makes it impossible to register or to fulfil the order. Providing data for marketing purposes is always optional.
3. Recipients of the data
The data may be disclosed to the following parties, who act as data processors or independent controllers, within the limits of the purposes indicated above:
- PayPal (Europe) S.à r.l. et Cie, S.C.A. — payment processing.
- BRT S.p.A. — courier for the shipping and delivery of orders.
- Email service provider (SMTP) — sending of transactional emails and of the newsletter.
- Google Ireland Ltd. — Google Analytics 4 and Google Ads (only with cookie consent).
- Google Ireland Ltd. — Google Maps Platform for address autocompletion: the script loads only when you interact with the address field at checkout or in your profile.
- Microsoft Ireland — Microsoft Clarity (only with consent to analytics cookies).
- Meta Platforms Ireland Ltd. — Meta Pixel (only with consent to marketing cookies).
- Authorities and supervisory bodies, where required by law.
The site is hosted on proprietary servers located in Italy. Some providers (Google, Microsoft, Meta) may entail transfers of data to third countries: such transfers take place on the basis of adequacy decisions, the Data Privacy Framework, or Standard Contractual Clauses approved by the European Commission.
We do not sell your personal data to third parties.
4. Retention periods
- Account data: for the entire duration of the relationship; in the event of a deletion request, the identification data is removed or anonymised, without prejudice to legal obligations.
- Orders and tax documents: 10 years from issuance, pursuant to art. 2220 of the Italian Civil Code (art. 2220 c.c.) and tax legislation.
- Newsletter data: until consent is withdrawn (unsubscription), after which it is retained only for the time necessary to demonstrate the withdrawal.
- Cookies and browsing data: according to the durations indicated in the Cookie Policy.
- Support messages and reviews: for the time necessary for their management and, for published reviews, until any removal.
5. Your rights
As a data subject you may exercise at any time the rights provided for by artt. 15–22 GDPR:
- access to your data and a copy thereof;
- rectification of inaccurate data and completion of incomplete data;
- erasure (“right to be forgotten”), within the limits of retention obligations;
- restriction of and objection to processing;
- portability of the data in a structured, machine-readable format;
- withdrawal of consent at any time, without affecting the lawfulness of the previous processing.
You can exercise most of these rights independently from your account area (“Privacy and data”: export your data, delete your account, manage your consents and unsubscribe from the newsletter), or by writing to the Controller’s contact details indicated above. We will respond within one month of the request.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (www.garanteprivacy.it) or with the competent authority of your State of residence.
6. Cookies and tracking tools
The site uses necessary technical cookies and, only with prior consent, analytics and marketing cookies, managed via Google Consent Mode v2. For the full details, the categories and the management of preferences, please consult the Cookie Policy.
7. Security
We adopt appropriate technical and organisational measures: encryption of passwords via hashing (bcrypt), secure HTTPS/TLS connections, token-based authentication with rotation, and limitation of login attempts to prevent abuse.
8. Minors
The services are not directed at minors under 16 years of age. We do not knowingly collect data of minors without the consent of the person exercising parental responsibility.
9. Changes
We reserve the right to update this policy. The version in force is always published on this page, indicating the date of the last update and the version.