Free shipping on orders over €60 | Estimated delivery time: 3 to 5 business days

Privacy Policy

Introduction
Dear User, when you access and browse this website (hereinafter the “Site”), certain personal data about you is collected, stored, and managed (technically referred to as “processed”) through the device you are using, including through the analysis and storage of your IP address, browsing data, “cookies,” and other online identifiers such as “pixels.”

In light of these processing activities, and in compliance with applicable regulations governing the protection, confidentiality, and security of your data,Noberasco in Via Dei Mille s.r.l. sets forthbelow the purposes and methods of processing in its capacity as Data Controller.

Data Controller
The processing of personal data resulting from access to and interaction with the Website will be carried out byNoberasco in Via Dei Mille s.r.l., with registered office at Regione Bagnoli No. 5, Albenga (SV), VAT No. 01416380093, acting as the Data Controller.

Noberasco in Via Dei Mille s.r.l. can be contacted at the following addresses:

  • by sending an email to privacy@noberasco1908.it
  • by regular mail to the address of the office indicated.

Categories of data processed
The categories of data processed are as follows:

  • information regarding the user’s browsing activity on the Site, including so-called online identifiers and data relating to the devices used;
  • personal identification and contact information voluntarily provided by the user on the Website, including information necessary to complete purchases of goods and services, even without registration (so-called “guest checkout”), such as: first name, last name, email address, and phone number;
  • personal data necessary for managing shipping methods and systems, such as: residential address, domicile, or place of residence; delivery address for the purchased goods;
  • personal data necessary for the management of payment methods and systems, such as: credit card number and related information, bank account information, and information regarding accounts with the selected payment system (e.g., PayPal);
  • personal data obtained from third parties or third-party sources in connection with specific initiatives or purposes promoted by the Data Controller;
  • additional, specifically identified personal data, in the event that new features or services are implemented.

Purposes, Legal Bases, and Data Retention Periods
In the table below, the Data Controller lists the specific purposes for which personal data is processed, each accompanied by the relevant legal basis and the maximum data retention period, if it can be specified precisely (otherwise, the retention criterion on which the relevant technological tool was based is indicated).

Purpose
Legal basis
Shelf life
(1) Providing navigation features for the Website, its pages, and content, such as product catalogs
6 (1) (b), for the fulfillment of needs related to pre-contractual activities
for the duration of the user's visit to the Site, up to a maximum of 24 months.
(2) Responses to contact requests or requests for information submitted by the user
6 (1) (f), for the purpose of pursuing the Data Controller’s legitimate interest in maintaining relationships with users of the Website
for up to 10 years following interaction with the data subject.
(3) Registration, access, and use of the e-commerce store by the user, including when making a “guest purchase,” such as purchasing, paying for, managing, and receiving products, as well as handling returns and refunds
6 (1) (b), for the fulfillment of obligations related to the contract and related pre-contractual activities, including for the purpose of enabling, facilitating, or simplifying the purchase
for the time necessary to achieve the stated purposes, up to a maximum of 10 years from the user’s removal from the e-commerce platform.
(4) Management of the user’s shopping cart with regard to the so-called “abandoned cart” feature following an interruption in the purchase process or issues with the e-commerce store
6 (1) (f), for the purpose of pursuing the Data Controller’s legitimate interest in promoting the resumption of purchase interactions that were interrupted for technical reasons
for the time necessary to achieve the stated purpose, up to a maximum of 7 days following an interruption due to technical reasons.
(5) Management of accounting and tax records related to purchases made through the e-commerce store
6 (1) (c), for the purpose of complying with a legal obligation to which the Data Controller is subject (in particular, accounting and tax obligations)
for up to 10 years after the purchase
(6) Handling unsolicited contact from users of the Website, such as the submission of resumes and/or other communications
6 (1) (b), for the fulfillment of needs related to pre-contractual activities
for a maximum period of 12 months from the end of the selection process, unless further retention is necessary or the user has given consent.
(7) Analysis of usage statistics and improvement of the Website’s functionality through technologies that involve data processing activities pursuant to Directive 2002/58/EC (“ePrivacy”)
6 (1) (a), based on the consent given by the data subject
until the expiration of the online identifier associated with the user who has been retained the longest, unless a request for deletion or anonymization is made.
(8) Analysis of usage statistics and improvement of the Website’s functionality, to which, due to their specific technical nature, Directive 2002/58/EC (“ePrivacy”) does not apply
6 (1) (f), for the purposes of pursuing the Data Controller’s legitimate interests, aimed at improving its products and services
only for the period necessary to fully anonymize the collected data.
(9) Contacting the user via email following the purchase of goods or services offered by the Data Controller, for the purpose of offering additional similar goods or services
6 (1) (f), for the pursuit of the Data Controller’s legitimate interest in promoting its sales of goods and services, in accordance with the limits set forth in Article 130, paragraph 4, of Legislative Decree 196/2003 (so-called “soft spam”)
for up to 24 months from the user’s last purchase, unless the user has exercised their right to object in any manner.

Further information on how we process data
If the data subject wishes to obtain further information regarding the balancing of the legitimate interests pursued by the Data Controller against the fundamental rights and freedoms of the individual, they may contact the Data Controller at the contact details provided, and are entitled to receive a response as soon as possible and in any case within the time limits established by law.
In the event of a dispute with the user or with third parties, or in the event of an audit by the relevant authorities, the retention period may be extended until the expiration of the last applicable statute of limitations.
The data will not be disclosed in any way, except with the express and prior consent of the data subject and within the limits provided by law.

Consequences of Failure to Provide Data
The provision of personal data marked as mandatory is necessary to pursue the relevant purposes: failure to provide such data will make it impossible to proceed with the related processing.
The provision of other personal data is optional: failure to provide such additional data may result in the total or partial inability to access certain functions or features of the Site. With regard to so-called marketing and profiling purposes, as well as in relation to so-called “online identifiers” that are not purely technical, consent to the processing of personal data is optional: there is no legal or contractual obligation on the user to provide such data for this purpose and/or to consent to the processing of their personal data for this purpose.

Automated decision-making
No processing of personal data through automated decision-making processes is envisaged in accordance with applicable legislation, and in particular pursuant to Article 22, paragraphs 1 and 4, of the GDPR.
In any case, any automated processing will not result in a legal effect concerning the data subject or significantly affecting him or her, unless specific informed consent is obtained and, in any event, in compliance with legal limits.

Categories of entities that process personal data
Within the limits of the obligations, duties, or purposes indicated above, personal data may be processed, made available, and/or disclosed to:

  • employees and/or contractors of the Data Controller;
  • third parties designated as Data Processors (in particular, suppliers of goods or services), including their employees and/or contractors;
  • Judicial, administrative, and/or public safety authorities, in accordance with applicable regulations.

The complete list of data processors and other third parties may be requested from the data controller at any time using the contact information provided.

Transfer of Personal Data Outside the European Economic Area
Personal data will be transferred to countries outside the European Economic Area for technical reasons, to entities based in countries recognized as “adequate” by the European Commission, including those adhering to the “EU-US Data Privacy Framework,” or to entities that have entered into specific Standard Contractual Clauses in the current version as approved by the European Commission.

Rights of the Data Subject
The data subject may, at any time, exercise the rights provided for in European Regulation No. 2016/679. In particular, the data subject has the right to:

  • to access their personal data, as well as to have such data corrected or deleted;
  • to have the processing of your data restricted;
  • to object to the processing, where permitted;
  • to obtain data portability, where applicable;
  • to withdraw consent: such withdrawal does not affect the lawfulness of processing carried out on the basis of consent given prior to the withdrawal;
  • to file a complaint with the supervisory authority: in Italy, with the Italian Data Protection Authority (www.gpdp.it).

You may exercise the rights described above by sending a request to the Data Controller’s contact information provided above, specifically to the email address listed in the “Data Controller” section.

Back to top