1. Data Controller
The Data Controller is:
Sicilcanditi srls
Via G. Pascoli 11
95025 Aci Sant’Antonio (CT) – Italy
VAT Number: IT05909560871
Email: [insert email]
Phone: [insert phone number]
The Privacy Manager is Giovanni Di Bella, who can be contacted at: [dedicated email].
2. Types of Data Collected
Through the WooCommerce-based e-commerce website, the following personal data may be collected:
Identification Data
- First and last name
- Billing and shipping address
- Phone number
- Email address
Order Data
- Purchased products
- Order history
- Shipping details
Payment Data
Payments are processed through external payment providers (such as PayPal, Stripe, or banking institutions).
The website does not store full payment card details.
Browsing Data
Some technical data may be automatically collected, including:
- IP address
- browser information
- server access logs
- technical cookies necessary for the functioning of the website
3. Purpose of Processing
Personal data are processed for the following purposes:
- processing online orders
- shipping purchased products
- managing customer accounts
- customer support
- communications related to orders
- compliance with legal and tax obligations
- website security and fraud prevention
The website does not use tracking or profiling systems for advertising purposes.
4. Legal Basis for Processing
Personal data processing is based on:
- performance of a contract (Art. 6.1.b GDPR)
- compliance with legal obligations (Art. 6.1.c GDPR)
- legitimate interest of the controller for security and abuse prevention (Art. 6.1.f GDPR)
5. Processing Methods
Personal data are processed using appropriate technical and organizational measures to ensure:
- security
- integrity
- confidentiality
Access to data is limited to authorized personnel and service providers strictly necessary for the operation of the website.
6. Data Retention
Personal data are stored only for the time necessary to fulfill the purposes for which they were collected.
Specifically:
- order data: 10 years for tax and accounting purposes
- customer account data: until deletion request
7. Data Sharing
Personal data may be shared with third parties necessary to provide the service, including:
- shipping and delivery companies
- payment service providers
- accounting and tax consultants
- IT and hosting providers
Personal data will not be publicly disclosed.
8. Data Subject Rights
Users may exercise their rights under Articles 15-22 of the GDPR at any time, including:
- right of access
- right to rectification
- right to erasure
- right to restriction of processing
- right to object
- right to data portability
Users also have the right to lodge a complaint with their national data protection authority.
Requests can be sent to:
[privacy email]
9. Cookies
The website uses technical cookies necessary for the operation of the website and the WooCommerce shopping cart.
For further information please refer to the dedicated Cookie Policy.
10. Updates
This Privacy Policy may be updated over time.
The latest version will always be available on the website:
Last update: [date]