Privacy Policy — Visitors
NOTICE ON THE PROCESSING OF PERSONAL DATA PURSUANT TO ART. 13 OF EU REGULATION 2016/679 VISITORS
In accordance with EU Regulation 2016/679 (hereinafter the “Regulation”), we provide below the notice on the processing of personal data carried out when a user (hereinafter the “Visitor”) visits the website www.apothekealimentare.com of the Data Controller as indicated below (hereinafter, for brevity, the “Site”), and is addressed to anyone visiting the Site.
1. Data Controller
Data Controller: Gigante Alimentari S.R.L.
Data Controller's details: Via Pizunzo, Zona Industriale, 70015 Noci (BA); VAT/Tax No. 05246760721; REA 407911
Contact details: Via Pizunzo, Zona Industriale, 70015 Noci (BA); EMAIL privacy@gigantealimentari.com; PEC (certified email) gigantealimentari@pec.it
2. Personal data collected
The categories of personal data collected and processed by the Data Controller are mainly the following: identification data, contact details, browsing data (e.g. IP address, logs, device type, operating system type and version, browser language), data voluntarily provided by the User when submitting requests, data relating to use of the Site, data relating to approximate location.
The provision of data marked with specific symbols and/or wording in the data collection forms is necessary in order to respond to requests submitted through the forms or to provide the requested service. Likewise, the provision of certain personal data automatically recorded by our systems (e.g. the IP address) is necessary. The provision of all other data is optional and does not affect the provision of the requested service.
More specifically:
a. When the Visitor contacts the Data Controller to obtain general information
When contacting the Data Controller to obtain general information, mainly identification data, contact details, payment and financial data, as well as other data provided by the Visitor when submitting the request, may be processed.
b. When the Visitor browses the Site
When browsing the Site, the Data Controller may collect identification data, contact details, browsing data (e.g. IP address, logs, device type, operating system type and version, browser language), and data relating to use of the Site.
c. To fulfil legal obligations
To fulfil the obligations imposed by law, the Data Controller mainly collects identification data, contact details, browsing data (e.g. IP address, logs, device type, operating system type and version, browser language), and data relating to use of the Site.
d. Should the Data Controller need to act or defend itself in legal proceedings
Should the Data Controller need to act or defend itself in legal proceedings, it may process mainly identification data, contact details, browsing data (e.g. IP address, logs, device type, operating system type and version, browser language), data voluntarily provided by the Visitor when submitting requests, and data relating to use of the Site.
e. When the Visitor subscribes to the Data Controller's newsletter service
When the Visitor subscribes to the newsletter service in order to receive information regarding news, promotions, tips and suggestions from the Data Controller, the Data Controller mainly collects identification data and contact details (such as the e-mail address).
3. Purposes and legal basis of the processing
a. The personal data collected will be processed, by automated and non-automated means, for the purposes indicated below, according to the legal basis set out alongside each of them.
a.1 Purpose: Compliance with legal obligations – Legal basis: Necessary for compliance with a legal obligation to which the Data Controller is subject (Art. 6(1)(c) of the Regulation)
a.2 Purpose: Management of the Site – Legal basis: Necessary for the performance of a contract or for the implementation of pre-contractual measures (Art. 6(1)(b) of the Regulation)
a.3 Purpose: Management of requests – Legal basis: Necessary for the performance of a contract or for the implementation of pre-contractual measures (Art. 6(1)(b) of the Regulation)
a.4 Purpose: Management of disputes – Legal basis: Necessary for the purposes of the legitimate interests pursued by the Data Controller or by third parties (Art. 6(1)(f) of the Regulation)
a.5 Purpose: Security and functionality of IT systems – Legal basis: Necessary for the purposes of the legitimate interests pursued by the Data Controller or by third parties (Art. 6(1)(f) of the Regulation)
b. In addition, certain data will be processed, by automated and non-automated means, for the following purposes, which are optional and ancillary in nature. These further purposes are pursued subject to the Visitor's prior consent, and failure to give consent does not affect the provision of the requested service, or the handling of a response to the Visitor's request.
b.1 Purpose: Data Controller's newsletter by e-mail – Legal basis: Consent (Art. 6(1)(a) of the Regulation).
4. Categories of recipients
For the purposes indicated above, the data collected may be disclosed, in compliance with a legal or contractual obligation or for reasons of an ancillary nature, to the following parties: Public bodies, bodies responsible for controls and inspections, entities equivalent to public bodies; Professionals, consultants or companies acting on behalf of the Data Controller; Other organisations providing services to the Data Controller (e.g. IT and telematic services, marketing activities).
4. Disclosure of data
The data will not be disclosed to the public.
5. Transfer of data
The Data Controller may transfer personal data to a third country for reasons ancillary to the purposes referred to above. Should it be necessary to rely on parties resident outside the territory of the European Union, we inform you that the safeguards required by the Regulation will be adopted, basing the transfer on: adequacy decisions issued by the European Commission in respect of the recipient third countries; appropriate safeguards provided by the party resident outside the territory of the European Union; binding corporate rules.
6. Data retention
The Data Controller retains personal data for a limited period of time, which varies depending on the purposes for which it is collected. Once this period has elapsed, the data will be retained for other purposes or, if it cannot be used for other purposes, will be permanently deleted or irreversibly anonymised. The personal data collected will be retained: (i) for the time strictly necessary for the management of the contractual relationship or the requested service, as well as for the further period prescribed by binding legal provisions for the purposes referred to in point 3.a, namely 10 (ten) years from the last entry; (ii) until the expiry of the time limits for pursuing judicial remedies and/or actions for challenge for the purposes referred to in point 3.a.4; (iii) for 24 (twenty-four) months from the giving of consent for the purposes referred to in point 3.b.1 (unless consent is withdrawn). Certain data may be retained for a longer period of time in the event of potential computer crimes committed against the Site.
7. Rights of the data subject
With regard to the data provided, the user may request to exercise, where applicable, the following rights: access, erasure, rectification, restriction of processing, objection to processing, data portability, and withdrawal of consent where the processing is based on consent.
To exercise these rights, the Visitor may send a request to the Data Controller's contact details indicated in point 1.
Finally, if the data subject believes that a processing operation infringes EU Regulation 2016/679, they may lodge a complaint with the supervisory authority of the Member State in which they habitually reside, work, or in which the alleged infringement occurred (in Italy, the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali)).
Ultimo aggiornamento: 15/07/2026