Privacy Policy — Customers
NOTICE ON THE PROCESSING OF PERSONAL DATA PURSUANT TO ART. 13 OF EU REGULATION 2016/679 — CUSTOMERS
Pursuant to EU Regulation 2016/679 (hereinafter the “Regulation”), we hereby provide the notice on the processing of personal data provided by the customer (hereinafter the “Customer”) in the process of purchasing the products or experiences available on the website www.apothekealimentare.com of the Data Controller, as indicated below, (hereinafter, for brevity, the “Site”).
In this regard, we note that the Regulation applies solely to natural persons and not to legal entities; however, in the context of the relationship, data that may be classified as personal data may be processed, namely data that renders a natural person identified or identifiable. Whoever completes the registration process or subsequently provides personal data therefore undertakes to fulfil the information obligations, where necessary, towards the natural persons (“data subjects” pursuant to the Regulation) whose data they communicate.
1. Data Controller
Data Controller: Gigante Alimentari S.R.L.
Data Controller details: Via Pizunzo, Zona Industriale, 70015 Noci (BA); VAT/Tax Code 05246760721; REA 407911
Contact details: Via Pizunzo, Zona Industriale, 70015 Noci (BA); EMAIL privacy@gigantealimentari.com; PEC gigantealimentari@pec.it
2. Personal data collected
The categories of personal data that the Data Controller collects and processes are mainly the following: personal identification data, contact details, payment and financial data, data relating to purchases, data relating to the use of IT systems such as IP address, logs, device type, operating system type and version, browser language, activities carried out, as well as special categories of data such as health-related data (e.g. health issues occurring during an experience or arising from complaints).
The provision of data marked with specific wording in the data collection forms is necessary for the performance of the relationship, or for the provision of the requested service, so that, should such data not be provided, it will not be possible to complete a purchase. Likewise, the provision of certain personal data automatically recorded by our systems (e.g. the IP address) is necessary. The provision of all other data is optional and does not affect the performance of the contractual relationship.
More specifically:
a. To conclude and perform the purchase of a product or experience through the Site
To conclude and perform the purchase of a product or experience through the Site, the Data Controller collects the necessary personal data, mainly personal identification data, contact details, and payment and financial data.
b. When the Customer contacts the Data Controller in order to obtain general information
When the Customer contacts the Data Controller in order to obtain general information, mainly personal identification data, contact details, and other data provided by the Customer when formulating the request may be processed.
c. When the Customer contacts customer service
When the Customer makes use of the customer service (by e-mail or telephone), the Data Controller mainly collects personal identification data, contact details, and details of products to be purchased or already purchased.
d. When the Customer browses the Data Controller's Site or social media
When the Customer browses the Site or uses social media and interacts with the Data Controller's pages, the Data Controller may collect personal data such as personal identification data, contact details, and data relating to the use of the Site or social media.
e. To comply with obligations imposed by law
To comply with obligations imposed by law, the Data Controller mainly collects personal identification data, contact details, payment and financial data, data relating to purchases, data relating to the use of IT systems such as IP address, logs, device type, operating system type and version, browser language, activities carried out.
f. Should the Data Controller need to handle complaints or bring or defend legal proceedings
Should the Data Controller need to handle complaints or bring or defend legal proceedings, it may process mainly personal identification data, contact details, payment and financial data, data relating to purchases, data relating to the use of IT systems such as IP address, logs, device type, operating system type and version, browser language, activities carried out, data relating to the use of the Site.
3. Purposes and legal basis of the processing
a. The personal data collected will be processed, using automated and non-automated means, for the purposes indicated below, according to the legal basis set out hereunder.
a.1 Purpose: Compliance with legal obligations – Legal basis: Necessary for compliance with a legal obligation to which the Data Controller is subject (Art. 6(1)(c) GDPR).
a.2 Purpose: Management of the contractual relationship or of the requested service – Legal basis: Necessary for the performance of a contract or in order to take steps prior to entering into a contract (Art. 6(1)(b) GDPR)
a.3 Purpose: Security and functionality of IT systems – Legal basis: Necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party (Art. 6(1)(f) GDPR)
a.4 Purpose: Management of requests – Legal basis: Necessary for the performance of a contract or in order to take steps prior to entering into a contract (Art. 6(1)(b) GDPR)
a.5 Purpose: Management of disputes/litigation – Legal basis: Necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party (Art. 6(1)(f) GDPR)
a.6 Purpose: Management of disputes/litigation with reference to special categories of data – Legal basis: Necessary for the establishment, exercise or defence of legal claims, whether in judicial or out-of-court proceedings (Art. 9(2)(f) GDPR in conjunction with Recital 52 GDPR)
a.7 Purpose: Direct marketing activities for similar services by e-mail, so-called “soft spam” – Legal basis: Necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party (Art. 6(1)(f) GDPR and Art. 130(4) of Legislative Decree 196/2003, the Italian Data Protection Code).
a.8 Purpose: Customer satisfaction activities (The Data Controller may use contact details in the course of conducting satisfaction surveys aimed at improving services and the relationship with customers. For example, the Data Controller may send a request to the Customer's e-mail address to complete a satisfaction questionnaire or survey strictly related to the product just purchased or the experience just concluded. It is specified that the Customer is free to choose whether or not to express their opinion) – Legal basis: Necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party (Art. 6(1)(f) GDPR).
4. Categories of recipients
In connection with the purposes indicated above, the data collected may be disclosed, in fulfilment of a legal or contractual obligation or for ancillary/instrumental reasons, to the following parties: public bodies, bodies responsible for controls and audits, entities assimilated to public bodies; companies specialising in IT and telematic services; professionals; consultants; couriers; companies operating on behalf of the Data Controller (e.g. IT service providers, or marketing service providers); other organisations that provide services for the Data Controller.
5. Dissemination of data
The data will not be disseminated.
6. Transfer of data
The Data Controller may transfer personal data to a third country for reasons instrumental to the purposes referred to above. Should it be necessary to engage parties resident outside the territory of the European Union, the Data Controller informs that the precautions required by the Regulation will be adopted, basing the transfer on: adequacy decisions concerning the recipient third countries issued by the European Commission; appropriate safeguards provided by the party resident outside the territory of the European Union; binding corporate rules.
7. Data retention
The Data Controller retains personal data for a limited period of time, which varies depending on the purposes for which it is collected. Once this period has elapsed, the data will be retained for other purposes or, if it cannot be used for other purposes, will be permanently deleted or irreversibly anonymised. The personal data collected will be retained: (i) for the time strictly necessary for the management of the contractual relationship or of the requested service, as well as for the further period prescribed by legally binding provisions for the purposes referred to in point 3.a, namely 10 (ten) years from the last registration; (ii) until the expiry of the time limits within which judicial remedies and/or actions for annulment may be brought, for the purposes referred to in points 3.a.5 and 3.a.6.
8. Rights of the data subject
In relation to the data provided, the Customer may request to exercise, where applicable, the following rights: access, erasure, rectification, restriction of processing, objection to processing, data portability, and withdrawal of consent where the processing is based on consent.
To exercise these rights, the Customer may send a request to the Data Controller's contact details indicated in point 1.
Lastly, if the Customer believes that any processing infringes Regulation (EU) 2016/679, they may lodge a complaint with the supervisory authority of the Member State in which they reside, work, or in which the alleged infringement occurred (in Italy, the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali)).
Ultimo aggiornamento: 16/07/2026