Privacy Policy
This Privacy Policy, provided pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR” or “Regulation”), is intended to inform the User about how their Personal Data (i.e., any information capable of identifying them directly or indirectly) will be processed when visiting and/or making a purchase on the website www.mydolcevitaitaly.com (hereinafter, the “Site”).
This notice, together with the Cookie Policy and the Terms of Use and General Conditions of Sale, sets out the basis on which the Users’ personal data will be processed.
Data Controller
The Data Controller of the personal data collected through the Site is: My Dolce Vita S.r.l., Via Torre Annunziata 28, 00177 Rome (RM), VAT no. 17763961004 (hereinafter the “Data Controller”), Email address: info@mydolcevitaitaly.com
Method of Processing Personal Data
We place the utmost importance on the right to privacy and the protection of our Users’ personal data, which will be processed lawfully.
The Personal Data provided or collected will be processed in accordance with the principles of fairness, lawfulness, transparency, and confidentiality as per current regulations, using appropriate security measures to prevent unauthorized access, disclosure, alteration, or destruction of Personal Data.
Processing is carried out using IT and/or electronic tools, with organizational methods and logic strictly related to the purposes indicated.
Personal Data Processed
When the User visits the Site, contacts us (via email, phone, post, etc.), subscribes to the newsletter, or places an order, we process certain Personal Data, either independently or through third parties.
The categories of personal data processed include:
- Identification, contact, and access data: first and last name, email address, shipping address, phone number, and account login credentials, as well as any other Personal Data voluntarily provided by the User;
- Purchase data: data related to completed purchases;
- Browsing data: data related to the connection, IP addresses, domain names, and other parameters concerning the browser and operating system used;
- Usage data: information generated while visiting the Site or making purchases: log data, data related to user registrations, interactions and transactions, performance indicators, navigation flow data, and use of features;
- Billing and payment data: VAT number, card number, tax code, address.
Purpose of Processing and Legal Basis
The Data Controller will process the Users’ Personal Data, as listed above, in the context of its economic and commercial activities and for the specific purposes indicated below.
1. Purposes Related to the Contract and Legal Obligations
- Browsing the Website;
- Registration and management of the account (password recovery, account deletion, etc.) and use of related services;
- Activities necessary for the conclusion and execution of the contract for the purchase of products sold through the Website;
- Order processing;
- Customer service and support activities, as well as responding to inquiries, complaints, reports, and disputes submitted by Users via email or other communication channels;
- Managing User requests through remote communication tools such as email, chat, telephone, and other online communication tools available on the Website;
- Fulfillment of legal obligations under current legislation, regulations, or EU law (e.g., tax and accounting obligations), as well as handling and responding to requests from competent administrative, tax, or judicial authorities;
- Administrative, accounting, and tax-related activities connected to the contract concluded through the Website, such as issuing receipts and/or invoices, maintaining accounting records;
- Responding to requests for the exercise of rights granted to Users by the contract with the Data Controller, by law in relation to the contract, or by the GDPR, and any resulting activities.
The legal basis for these purposes is the necessity to perform pre-contractual and contractual obligations to which the User is a party (Art. 6.1.b) of the GDPR), or to comply with legal obligations to which the Data Controller is subject (Art. 6.1.c) of the GDPR).
Therefore, except for account registration data, which is optional, processing is necessary to allow the conclusion and execution of the contract via the Website or to respond to the User’s pre-contractual requests related to the Website. Failure to provide such data will make it impossible for the User to conclude a contract through the Website and/or receive responses to submitted requests.
2. Purposes of Analytics and Statistics and Other Non-Consent-Based Purposes
- To carry out statistical analyses regarding the use of the Website, browsing behavior, and product searches, in order to improve the Website and the product offerings available on it;
- To ensure compliance with the contractual rights of the Data Controller or to demonstrate that the obligations arising from the contract with the data subject or imposed by law have been fulfilled, as well as to prevent and/or suppress fraudulent or harmful actions;
- To remind the User that they have begun the purchase process by adding a product to their shopping cart.
The legal basis for this processing is the legitimate interest (Art. 6.1.f of the Regulation). In certain cases, the legal basis consists of legitimate interest (Art. 6(1)(f) in conjunction with Recital 47 of the Regulation), for sending transactional emails (e.g., abandoned cart emails).
3. Soft-spam
To send commercial communications regarding similar products to the email address provided by the User when purchasing products through the Website. This activity does not require the User’s prior express consent, as it is carried out on the legal basis provided under Article 130, paragraph 4 of the Italian Privacy Code (Legislative Decree No. 196 of 30 June 2003), which expressly permits such use, provided that the User does not initially or subsequently object to it.
Modification of Choices and Withdrawal of Consent
If consent is given, the User may withdraw it at any time and/or object to the processing of personal data for general marketing and profiling purposes through the methods indicated in the “Data Subjects’ Rights” section of this Privacy Policy.
In case of withdrawal of consent, any processing previously carried out based on the consent remains lawful. If the User withdraws their consent and/or objects to the processing of their data for general marketing purposes, the data will no longer be processed for that purpose and will only be retained by the Controller if another legal basis for processing exists (e.g., contractual performance, legal obligations, or legitimate interest).
Data Retention Period
The Controller will process Users’ personal data for the time necessary to achieve the purposes for which the data was collected, as defined in this policy. In any case, for each of the purposes indicated, the data will be retained for the following periods:
- Contractual purposes. Data will be processed for the time strictly necessary to carry out the individual processing activities. Once this period has expired, data may be retained for other purposes and for the maximum retention periods indicated elsewhere in this Policy, or in accordance with the GDPR and/or applicable law.
- Tax, administrative, accounting, and legal purposes. Until the expiration of the legal deadlines for each obligation and/or the legally required retention periods. If the account is closed at the User’s request, the related data will be retained for administrative purposes for 3 months from the closure request.
- Legitimate interest purposes. Data will be processed for the time strictly necessary to fulfill the legitimate interest, unless, in the case of disputes or complaints, the Controller needs to retain personal data for defense purposes for up to 10 years (statute of limitations) or longer in case of ongoing litigation or specific requests from authorities. Users may obtain more information about the pursued legitimate interest by contacting the Controller.
Once these retention periods have expired, the Personal Data will be deleted, and the User will no longer be able to exercise the rights of access, deletion, rectification, or data portability.
Data Disclosure and Sharing
In addition to the Controller, in some cases, the following may have access to the Data:
- Individuals involved in operating the Website (e.g., administrative, sales, and marketing staff);
- Third parties performing auxiliary and instrumental tasks related to the Controller’s activities and processing personal data on the Controller’s behalf (e.g., payment services, legal advisors, accountants, system administrators, logistics providers, newsletter services);
- Public or private entities that can access the Data in compliance with laws, regulations, or measures issued by competent authorities;
- Potential buyers of the Controller’s business or entities resulting from a merger or other form of transformation.
These recipients, depending on the case, may process the Users’ personal data as data processors, controllers, or autonomous controllers. The User may request an up-to-date list of Data Processors pursuant to Article 28 of the GDPR.
Data Processing Location and Transfer of Data Abroad
Data is mainly processed in Italy and in EU countries. However, some third-party tools may process the personal data of users of this Website in countries outside the European Economic Area (“Third Countries”).
The transfer of data to Third Countries may occur through the use of external tools that provide specific services (e.g., newsletters, remarketing, advertising, use of social media buttons, video playback).
In some cases, the use of such tools may involve the transfer of personal data of users visiting this Website to a Third Country for which there is no adequacy decision by the European Commission.
If data needs to be transferred to Third Countries, the Controller undertakes to ensure that the destination country guarantees an adequate level of protection as required by Article 45 of the GDPR; such transfer will be governed by the European Commission’s standard contractual clauses for the transfer of personal information outside the EEA under Article 46.2 of the GDPR.
Cookies
This website uses cookies. Cookies are small text files that can be installed by websites on users’ devices to make the browsing experience more efficient, personalize content and ads, provide social media features, and analyze traffic. For more information, read the Cookie Policy.
Personal Data Processing Tools
Site Registration
Facebook Login (Meta Platforms Ireland Limited)
Facebook Login is a service provided by Meta Platforms Ireland Limited and linked to the Facebook network, which allows users to register on the site and log in using their Facebook credentials.
Personal Data processed: Tracking tools; various types of data.
Data processing location: Ireland – Privacy Policy.
Instagram Login (Meta Platforms Ireland Limited)
Instagram Login is a service provided by Meta Platforms Ireland Limited and linked to the Instagram network, which allows users to register on the site and log in using their Instagram credentials.
Personal Data processed: Tracking tools; various types of data.
Data processing location: Ireland – Privacy Policy.
Contact Form
By filling out the contact form, the User consents to the processing of the personal data entered therein and to its use for responding to information requests. The personal data processed includes those requested by the form (first name, last name, company, email address, phone number), as well as any other personal data optionally entered by the user in the message body.
Social Media Buttons
The User can use social media buttons to visit the social media pages of the Site via the following tools, which may also collect personal data such as traffic data on the pages where they are installed. The Site provides the following social buttons:
Instagram (Meta Platforms Ireland Limited) — The Instagram button is a service for interacting with the Instagram social network, provided by Meta Platforms Ireland Limited. Personal Data collected: Cookies, Usage Data, and other data as outlined in the corresponding privacy policy. Data processing location: IRELAND – UNITED STATES – Privacy Policy
Facebook (Meta Platforms Ireland Limited) — The Facebook button and widgets are services for interacting with the Facebook social network, provided by Facebook Ireland Ltd. Personal Data collected: Cookies and Usage Data. Data processing location: IRELAND – UNITED STATES – Privacy Policy
Payment Management
PayPal (PayPal Europe S.à.r.l. et Cie, S.C.A Inc.)
PayPal is a payment service provided by PayPal Europe S.à.r.l. et Cie, S.C.A Inc., which allows the User to make online payments using their PayPal credentials. Personal Data collected: Cookies and various types of data, as specified in the service’s privacy policy. Data processing location: LUXEMBOURG – Privacy Policy
Data Subjects’ Rights
Data subjects have the right to exercise the powers provided under Articles 7 and 15–22 of the Regulation. In particular, Users have the right to obtain:
- access, updating, rectification, or, where of interest, integration of data;
- deletion, anonymization, or blocking of data processed unlawfully, including data that does not need to be retained for the purposes for which it was collected or subsequently processed;
- confirmation that the above operations have been notified, including their content, to those to whom the data was disclosed, unless this proves impossible or involves a disproportionate effort compared to the protected right.
Furthermore, Users have the right to:
- withdraw consent at any time, if processing is based on their consent;
- request data portability, i.e., to receive all personal data concerning them in a structured, commonly used, and machine-readable format;
- request restriction of processing and/or deletion (“right to be forgotten”);
- object to the processing of their personal data and to processing for direct marketing or market research purposes.
According to applicable law, the Controllers inform Users of the right to be informed of: (i) the source of the personal data; (ii) the purposes and methods of processing; (iii) the logic applied if the processing is carried out with the help of electronic tools; (iv) the identifying details of the Controllers and processors; (v) the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of it as processors or authorized personnel.
Data subjects may exercise their rights by sending a specific request to the Controller or using the data subject rights form available at this link, duly completed, signed, and with attachments, to be sent by email to: info@mydolcevitaitaly.com
If data subjects believe that the processing of their personal data violates the Regulation, they also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), located at Piazza Venezia 11 – 00187 – Rome (http://www.garanteprivacy.it/).
To download the Exercise of Rights Regarding Personal Data Protection module, click here.
Changes to This Privacy Policy
The Data Controller reserves the right to make changes to this Privacy Policy at any time by notifying Users on this page. Please check this page regularly, referring to the last modified date indicated at the bottom. If the User does not accept the changes made to this Privacy Policy, they must stop using this website and may request the Data Controller to delete their personal data.
Unless otherwise stated, the previous version of the Privacy Policy will continue to apply to personal data collected up to that point. The Controller is not responsible for updating all links shown in this Privacy Policy. Therefore, whenever a link is inactive and/or outdated, Users acknowledge and accept that they must always refer to the document and/or section of the websites referenced by that link.
Privacy Policy updated in June 2025