Privacy Policy - Privacy Policy
This Privacy Policy is provided pursuant to Article 13 of EU Regulation 2016/679 (GDPR) and the current Italian legislation for the protection of personal data, Legislative Decree no. 196/2003 and subsequent amendments, in particular Legislative Decree no. 101/2018, and applies exclusively to those who interact with the website
It aims to describe the management methods of the site with reference to the processing of personal data of those who consult its content and to allow them, in case of data provision, to know the purposes, methods, times, and place of processing by the Data Controller.
1. Data Controller
The Data Controller, according to current legislation, is:
Azienda Agricola Prunotto Mariangela ssa
Via Osteria 14, 12051 Alba (CN), ITALY
VAT and Tax Code: 03091730048
Email: info@mprunotto.com
2. Methods of Personal Data Processing
The processing of Personal Data is carried out using IT and/or telematic tools, with organizational methods strictly related to the purposes indicated. The Controller ensures that data processing will be based on the principles of lawfulness, fairness, transparency, accuracy, and minimization, adopting appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction.
3. Personal Data Subject to Processing
3.1. Browsing Data
The IT systems and software procedures used to operate the site acquire, during normal operation, some technical-computer data, the transmission of which is inherent to the use of Internet protocols, such as IP address, browser type, operating system, pages visited, date and time of the request. These data are used only for anonymous statistics and to check the correct functioning of the site and are deleted immediately after processing.
3.2. Data Collected through the Online Shop
During the completion of B2C orders, the following mandatory data are collected:
- First and last name
- Shipping address
- Phone
- Any delivery notes
- Payment data (managed through external gateways Satispay and PayPal)
These data are necessary to process the order, manage shipping and invoicing, and to fulfill tax and accounting obligations.
3.3. Data Collected through Newsletter
Subscription to the newsletter is done via Mailchimp and is optional. The data collected are exclusively the email address and, if provided, the name. No personalized profiling is carried out.
4. Purpose of Processing and Legal Basis
Contract execution / order management: processing necessary for the conclusion and management of orders (art. 6, c.1, lett. b GDPR)
Newsletter: sending commercial and informational communications, with the explicit consent of the user (art. 6, c.1, lett. a GDPR)
Anonymous statistics: analysis of site usage to improve services, without identifying the user (art. 6, c.1, lett. f GDPR)
Legal and tax obligations: processing necessary to fulfill legal obligations (art. 6, c.1, lett. c GDPR)
The provision of data is optional, but failure to provide mandatory data for orders makes it impossible to process the order itself.
5. Data Recipients
In addition to the Controller, data may be processed by:
- Internally appointed personnel (administrative, commercial, marketing, legal, IT technicians)
- External service providers appointed as Data Processors, such as Mailchimp, payment gateways, hosting providers
Data will not be communicated to other parties except for legal obligations.
6. Data Retention
Browsing data: deleted immediately after processing in anonymous form
Newsletter data: retained until consent is withdrawn
Online shop data: retained until the fulfillment of contractual and tax obligations, unless further legitimate purposes exist
7. Place of Processing and Transfer to Third Countries
Data are processed at the Controller’s headquarters. Some data may be processed by entities outside the EU or non-EU (Mailchimp, PayPal, Satispay). The Controller ensures that such transfers are carried out in compliance with GDPR regulations.
8. Cookies
The site uses cookies to improve the browsing experience. For more details and consent management, refer to the Cookie Policy.
9. Social Networks
The site incorporates links to Instagram and Facebook for content sharing and access to social pages. Data collection is governed by the respective social network policies. No login/social login is present on the site.
10. Third-Party Services
1. Newsletter: Mailchimp (The Rocket Science Group LLC, Atlanta, USA), data managed as Data Processor and transferred according to GDPR.
Subscription to the newsletter is optional and is done through the Mailchimp service (The Rocket Science Group LLC, Atlanta, USA), appointed as External Data Processor under the GDPR. The data collected are exclusively the email address and, if provided, the name.
Purpose of processing: sending informational and promotional communications related to the Controller’s products and services. Data will not be used for other purposes or shared with external parties without the user’s consent.
Legal basis: explicit consent of the user (art. 6, c.1, lett. a GDPR).
Data transfer: data collected by Mailchimp are transferred to the United States. Mailchimp ensures GDPR-compliant protection through Standard Contractual Clauses approved by the European Commission.
Rights of the data subject: the user can revoke consent and unsubscribe from the newsletter at any time by clicking the unsubscribe link in each email or by directly contacting the Controller at info@mprunotto.com.
2. Payments: PayPal and Satispay manage payment data as External Data Processors.
The Customer will pay for purchases without sharing financial information with Azienda Agricola Prunotto Mariangela ssa, which therefore cannot be held responsible for any fraudulent use. For any information, visit: www.satispay.com or www.paypal.com.
The data necessary for processing payments made through PayPal and Satispay are processed exclusively by the respective providers as External Data Processors. These data may include name, surname, address, email, and payment information (card, IBAN, account).
Purpose of processing: payment management, order fulfillment, invoicing, and tax compliance. Processing is necessary for the execution of the sales contract (art. 6, c.1, lett. b GDPR).
Data transfer: some data may be transferred outside the European Union. PayPal and Satispay ensure that such transfers are carried out in compliance with GDPR, through adequate legal guarantees such as the Standard Contractual Clauses approved by the European Commission.
Rights of the data subject: the user can exercise their rights (access, rectification, deletion, restriction, portability) by directly contacting the Controller at info@mprunotto.com . For further details on data processing by PayPal or Satispay, refer to their respective Privacy Policies:
11. Rights of the Data Subject
The User has the right to:
Revoke consent (Art. 7)
Access personal data (Art. 15)
Rectify inaccurate or incomplete data (Art. 16)
Obtain data deletion (Art. 17)
Restrict processing (Art. 18)
Receive data in a portable format (Art. 20)
Object to processing for personal reasons or direct marketing (Art. 21)
In case of violations, the user can file a complaint with the Authority: www.garanteprivacy.it
12. Changes to the Privacy Policy
The Controller reserves the right to update this information in compliance with regulatory or legislative changes. The user is invited to regularly consult the page. The current version applies to data collected up to that time.
Update date: August 27, 2025