INFORMATION ON THE PROCESSING OF PERSONAL DATA
As required by European Union Regulation no. 679/2016 (hereinafter "GDPR"), and in particular by Art. 13, we hereby provide the information required by law regarding the processing of your personal data.
Note for minors: If you are 16 years old or younger, please obtain permission from your parent/guardian before providing your personal data.
The website www.bartolucci.store (hereinafter the "Website") is owned and operated by Bartolucci s.r.l., with registered office in Camerano (AN), Via del Commercio, 1 (hereinafter "Bartolucci s.r.l.").
Bartolucci s.r.l. complies with applicable data protection laws and is constantly working to improve the protection of its customers.
1. DATA CONTROLLER
The data controller, as defined by Art. 26 of the GDPR – European Privacy Regulation – is Bartolucci s.r.l., with registered office in Camerano (AN), Via del Commercio 1, VAT No. 02614850424.
2. WHAT IS PERSONAL DATA?
Personal data refers to any information relating to an identified or identifiable natural person, such as name, surname, gender, email address, phone number, date of birth, and postal address.
3. WHAT PERSONAL DATA IS PROCESSED?
3.1 Data provided by the user
When the user creates a personal account, fills in registration forms on the site, or gives consent, we process the provided personal data, in particular the data defined in section 2.
3.2 Browsing data
The computer systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.
This information is not collected to be associated with identified individuals, but by its very nature could, through processing and association with data held by third parties, allow users to be identified.
This category of data includes IP addresses or domain names of the computers used by users, URI (Uniform Resource Identifier) addresses of requested resources, request time, method used to submit the request to the server, the size of the file obtained in response, the numeric code indicating the status of the server’s response (success, error, etc.), and other parameters related to the user's operating system and computer environment.
These data are recorded in anonymous and aggregated form, used solely to obtain anonymous statistical information about the use of the site and to ensure proper functioning, and are deleted immediately after processing. These data could be used to determine liability in the event of hypothetical cybercrimes against the site.
4. WHEN DO WE PROCESS YOUR DATA?
We process your personal data when you create your personal user account, when you order products via our website, or when you subscribe to our newsletter and WhatsApp Channel. Unless otherwise specified, the legal basis for such data processing is Article 6(1)(b) and (a) of the GDPR (contract performance and consent).
5. PURPOSES OF DATA PROCESSING
5.1 Account
To make purchases on our website, it is necessary to create a personal account ("user account"). You can store your personal information within your account and facilitate future purchases.
Creating a user account requires your name, surname, and, in some cases, address and phone number. Additionally, users must provide an email address and a password of their choice.
The email address serves as the login credential for the account. Personal information can be updated at any time in the account dashboard.
5.2 Order processing in our online store
Data processing for product orders is aimed at facilitating and optimizing order fulfillment, including payment and delivery.
When payment is made by credit card, we receive the payment ID and the last four digits of the credit card number from the payment provider. This information is necessary for authentication and for securely linking your order.
Personal data required for payment is collected directly by the payment provider.
The legal basis is Article 6(1)(b) (contract performance) and Article 6(1)(f) (legitimate interest in offering secure credit card payments).
We also review your previous orders and check for differences in billing and delivery addresses, new delivery addresses, or intermediary shipping locations.
If you create an account, billing and delivery address data are stored in your user account for easier future purchases. These can be updated at any time.
Personal data processed for order management is stored for 10 years, as required by tax regulations.
5.3 Email communications upon account registration
Upon registering on our website, the system automatically sends a confirmation email to the address provided by the user.
5.4 Email communication after cart abandonment
If a shopping cart is abandoned, Bartolucci s.r.l. reserves the right to contact the user via email once to offer customer service assistance.
The email is sent to the address used during registration or during the order process in case of guest checkout.
This email simply informs the user of available support channels and does not contain promotional content or discounts.
5.5 Email communication upon order placement
After completing a purchase, the system sends emails to update the user about the status of the order.
These emails are tailored to the selected payment method and include details about payment, order preparation, and shipping.
The last email, sent after delivery, invites the user to provide feedback on the service received.
5.6 Newsletter and WhatsApp Channel
We offer all members of our community (users of www.bartolucci.store) the opportunity to receive our newsletter and dedicated messages by subscribing to our WhatsApp channel. To activate this service, users can register with their email address on the appropriate page. Users may withdraw their consent at any time and without providing any reason. The easiest way to do so is by clicking the "Unsubscribe" link included in every newsletter. The newsletter may also contain advertising banners, advertisements, and promotional offers. The legal basis for this process is Article 6(1)(a) of the GDPR (consent).
Subscription to the WhatsApp channel can also be completed during account registration by checking the appropriate box. To unsubscribe from WhatsApp, simply send a message with the word “Unsubscribe”.
5.7 Contact via contact form
If you submit inquiries via the contact form, we will process the information provided, including your contact details, to respond to your request.
The legal basis is Article 6(1)(b) (contract performance) and Article 6(1)(f) (legitimate interest in responding to user inquiries).
With your consent, Bartolucci s.r.l. may also process your data for: a) sending informational and promotional material about the Bartolucci Fixing System brand (e.g. newsletters);
b) conducting statistical studies and research;
c) profiling to suggest products that may interest you.
6. METHODS AND LOCATION OF DATA PROCESSING
Personal data is processed using automated tools for the time strictly necessary to achieve the purposes for which it was collected.
Security measures are in place to prevent data loss, unlawful use, or unauthorized access.
The database is accessible only to authorized personnel using secure methods.
While we take all necessary precautions, we cannot completely guarantee against unauthorized access or misuse of services by third parties.
DATA PROCESSING LOCATION
Data processing related to this website takes place at the Data Controller’s registered office and is handled only by authorized personnel or technical staff in charge of occasional maintenance.
No data is communicated or disclosed unless necessary to fulfill the user’s service request. Bartolucci s.r.l. may process data directly or via external processors listed on the website.
7. USE OF THIRD-PARTY SERVICE PROVIDERS – DATA PROCESSORS
We use external service providers (e.g. order fulfillment, newsletter software, data centers) who may process personal data as needed.
These providers are carefully selected and monitored, and process data only according to our instructions.
With the user’s consent, Bartolucci s.r.l. may use automated tools (without human intervention) to process data for the purposes outlined above.
An updated list of all data processors is available at the Data Controller’s offices and can be requested via email: store@bartolucci.eu.
This list may be updated as needed.
8. DATA RETENTION PERIOD
Personal data will be retained only as long as necessary to fulfill the purposes described or as required by law.
User-submitted data (section 3.1) will be deleted no later than 10 years after the legal retention periods.
Automatically collected data (section 3.2) will be deleted or anonymized after 24 months.
9. YOUR RIGHTS
As a data subject, under Articles 15–21 of the GDPR, you have the right to:
confirm whether your personal data is being processed;
access your personal data and understand its origin, purpose, and recipients, and the criteria used to determine retention periods;
request updates or corrections to keep your data accurate;
request deletion or restriction of your data under Art. 17 of the GDPR;
obtain a copy of your personal data.
You may also request your data in a machine-readable format and ask us to transfer it to a third party of your choice (where technically feasible).
Requests will be processed within one month, extendable by two months in case of complexity or volume of requests.
If you have an account with Bartolucci s.r.l., you may view, edit, or delete your data directly from your user area.
10. CHANGES TO THE PRIVACY POLICY
We reserve the right to modify this Privacy Policy at any time.
We will notify you of significant changes by email.
Such changes will take effect seven (7) days after the notice is sent.