30 JULY 2026

Privacy Policy

CANTINA DEL PORTO SNC, with registered office at 47522 - Cesena (FC), Via Romea, 1100, VAT number: 01252170392, e-mail: amministrazione@eccomicesena.it, in the person of its temporary legal representative (hereinafter referred to as the "Data Controller" or "Controller"), is constantly committed to protecting the online privacy of natural persons while browsing this website (hereinafter the "Website"). This document describes every aspect related to the processing of Personal Data carried out with respect to visitors and users of the Website's services (hereinafter also referred to as "Data Subjects") in accordance with the provisions of Article 13 of EU Regulation No. 2016/679 - GDPR (hereinafter the "Regulation" or "GDPR").

1. Data controller

CANTINA DEL PORTO SNC, with registered office in 47522 - Cesena (FC), Via Romea, 1100, VAT number: 01252170392, contactable in the manner indicated in the [Contacts] section.

2. Categories of Personal Data processed

This Website collects, independently or through the intervention of third parties, the following categories of personal data: a) Navigation / usage data: information collected during the visit to the Website (e.g. IP address, URI notation addresses, browsing history, information relating to the user's computer environment, browser type and language, operating system, location, date and time of the request); b) Cookies: small text files that visited sites send and record on the user's device. For more information, please consult the Cookie Policy; c) Data voluntarily provided by the user: personal information voluntarily released through the specific forms on the Website (e.g. "Contact", "Login", "Book", etc.), which may include common data (First Name, Last Name, E-mail, Phone No., Service of interest) and free messages expressed through the "Request" field of the contact form. The User assumes responsibility for the Personal Data of third parties communicated through the Website and guarantees that they have the right to communicate them, freeing the Controller from any liability towards third parties.

3. Purpose of the processing

The Data Controller uses the Personal Data collected through this Website for: a) Provision of services: responding to requests for information and providing content and services covered by the Website; b) Security guarantee, prevention of abuse and fraud, debugging; c) Statistical analysis of Website and ad performance; d) Direct marketing: sending newsletters and commercial communications via email; e) Profiling and personalized ads/content; f) Legal protection of their rights; g) Compliance with legal obligations; h) Soft spam: sending commercial communications relating to services/products similar to those already purchased.

4. Legal basis of processing

The Controller processes personal data based on the following legal bases: performance of a contract or pre-contractual measures (art. 6.1.b GDPR); consent of the data subject (art. 6.1.a GDPR), which can be revoked at any time by contacting the Controller or via the specific cookie/consent form; legitimate interest of the Controller (art. 6.1.f GDPR); compliance with a legal obligation (art. 6.1.c GDPR).

5. Methods of processing

The processing is carried out using manual and/or automated methods, including with the help of IT and telecommunications technologies, subject to the application of appropriate technical and organizational security measures to guarantee security, integrity, and confidentiality, minimizing the risks of destruction, loss, unauthorized access, modification, and unauthorized disclosure, in compliance with Art. 32 of the GDPR.

6. Transfer of Personal Data outside the EU/EEA

Personal Data may be transferred to a Third Country (outside the EU/EEA) as a result of accessing IT and cloud services provided by foreign providers, selected after verifying adequate security standards. Transfers will be carried out in compliance with the guarantees provided for by Articles 44-49 of the GDPR. For more information on the providers appointed as Data Processors, the Data Subject may contact the Controller as indicated in the [Contacts] section.

7. Retention periods

The Controller retains Personal Data only for the time necessary to achieve the purposes indicated in this document, or for the timeframes provided for by law. In particular: data processed for the provision of services is retained for the time necessary and in any case for no longer than 10 years; data processed under legal obligation is retained for the period provided for by the relevant regulations; data processed for direct marketing/soft spam is retained for no longer than 10 years or until consent is revoked; the duration of individual cookies is indicated in the Cookie Policy. This is without prejudice to the possibility of retaining data for the period allowed by Italian law for the judicial protection of one's interests (Articles 2946 and 2947 of the Italian Civil Code).

8. Recipients

The Personal Data collected may be communicated or made accessible to: employees and collaborators who assist the Data Controller in processing operations; entities providing outsourcing services on behalf of the Data Controller (IT/cloud service providers, DEM services, freelancers, web and system administrators); independent Data Controllers necessary for the provision of the requested service (e.g., couriers and shipping services); independent Data Controllers subject to the data subject's consent (e.g., third-party cookies); public authorities, when communication is required by law.

9. Rights of the Data Subject

The Data Subject may at any time access the information concerning them and request its rectification, erasure, restriction of processing, and portability. They may also object in whole or in part to the processing and have the right not to be subject to a decision based solely on automated processing, including profiling. To exercise the rights referred to in Articles 15-22 of the GDPR, the Data Subject may contact the Data Controller as indicated in the "Contacts" section. The Controller will respond within 1 month of the request (subject to a maximum extension of a further 2 months in the event of numerous or complex requests). The Data Subject also always has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali), pursuant to Art. 77 of the Regulation.

10. Contacts

For further information regarding the processing of Personal Data carried out through this Website, or to submit a request to exercise your rights, you can contact the Data Controller at the e-mail address: amministrazione@eccomicesena.it.