Privacy Policy
Last updated: December 9, 2025
In accordance with the General Data Protection Regulation (GDPR - EU Reg. 2016/679), we inform you that personal data collected through the website www.sanvirgilio.eu is processed by two separate Data Controllers, each for the specific purposes indicated below.
1. Data Controllers
| Controller | Purpose | Contact |
|---|---|---|
| Le Piemont SA | Product sales (Olive Oil), management of contact requests related to products and newsletters. | Avenue Monplaisir 91-95, 1030 Schaerbeek, Belgium (BE 0432.944.157) |
| Società Agricola Sanvirgilio SRL | Management of contact requests related to room rentals and ancillary services (e.g., special requests, events). | Contrada Cerasina, 72015 Fasano (BR), Italy (VAT IT02124260742) |
To exercise your GDPR rights, please contact: privacy@sanvirgilio.eu
2. Data Collected, Purposes and Legal Bases
| Data Source | Personal Data Collected | Purpose | Legal Basis (GDPR) | Retention Period |
|---|---|---|---|---|
| Contact Form | First Name, Last Name, Email, Message, Enquiry Type, Language, Email Status, Date/Time. | Respond to user request (products or rooms). | Performance of pre-contractual measures at the request of the data subject (Art. 6(1)(b)). | 12 months from resolution of the request, unless legal obligations require otherwise. |
| Cookie Consent | Consent preferences (essential, analytics, marketing), timestamp. | Store and respect user consent choices. | Legitimate interest (Art. 6(1)(f)). | 12 months (automatic re-consent required after expiry). |
| Embed Consent | Session-based consent for YouTube/Google Maps loading. | Remember user choice to load third-party embeds during browsing session. | Consent (Art. 6(1)(a)). | Browser session only (cleared when tab/browser closes). |
| Analytics (Google Analytics 4) | Anonymous navigation data, page visits, time on site, device/browser information (IP anonymized). | Statistical analysis to improve the website. | Consent (Art. 6(1)(a)). | 14 months (GA4 configuration). |
| Marketing Cookies (YouTube, Google Maps) | Cookies set by embedded YouTube videos and Google Maps when loaded. | Display embedded content and track interactions. | Consent (Art. 6(1)(a)). | Varies by provider (see provider policies). |
| Newsletter (Future) | Email (and optional name). | Send commercial communications and updates (marketing). | Free, specific and informed consent (Art. 6(1)(a)), via Double Opt-in. | Until consent is withdrawn (Opt-out). |
| Product Sales (Future - Stripe) | Order Data (Products, Quantity, Amount), Shipping and Billing Address, Payment Data (tokenized by Stripe). | Fulfillment of sales contract (shipping, invoicing, returns management). | Performance of a contract (Art. 6(1)(b)) and Legal obligation (Art. 6(1)(c)). | 10 years (tax and accounting obligations). |
3. Recipients and Data Transfers
Your personal data may be shared with the following parties (Data Processors):
| Service | Purpose | Location | Transfer Basis |
|---|---|---|---|
| Supabase | Database hosting for contact form data and site configuration. | AWS EU (Frankfurt) | Data remains in EU |
| Netlify | Website hosting and serverless functions. | US East (Ohio) | EU-US Data Privacy Framework / SCC |
| Resend | Email delivery service for contact form notifications. | Global (US-based) | Standard Contractual Clauses (SCC) |
| Google Analytics 4 | Anonymous website usage statistics. | Global (US-based) | EU-US Data Privacy Framework / SCC |
| YouTube (Google) | Embedded video content. | Global (US-based) | EU-US Data Privacy Framework / SCC |
| Google Maps | Embedded interactive maps. | Global (US-based) | EU-US Data Privacy Framework / SCC |
| Stripe (Future) | Payment processing for product sales. | Global | EU-US Data Privacy Framework / SCC |
| DPD (Future) | Shipping and delivery services. | EU | Data remains in EU |
Extra-EU Transfers: Transfers to providers outside the EU are lawful based on Standard Contractual Clauses (SCC) and, where applicable, adequacy decisions (e.g., EU-US Data Privacy Framework).
4. Cookies & Tracking Technologies
Our website uses cookies and similar technologies to improve your experience and analyze site usage.
Cookie Consent Banner
When you first visit our site, a cookie consent banner appears allowing you to accept all cookies, reject non-essential cookies, or customize your preferences. Your choice is stored for 12 months, after which the banner will reappear for you to re-confirm your preferences.
Types of Cookies We Use
| Type | Description | Cookies | Retention Period |
|---|---|---|---|
| Essential Cookies | Required for basic website functionality. These cookies store your language preference and cookie consent choices. They cannot be disabled. | cookie-consent (localStorage, 12 months), embed-consent-youtube, embed-consent-maps (sessionStorage, browser session) | 12 months / Browser session |
| Analytics Cookies (Google Analytics 4) | We use Google Analytics 4 to understand how visitors interact with our website. IP addresses are anonymized. Google Signals and advertising features are disabled. These cookies are only loaded after you grant consent. | _ga, _ga_* cookies | 14 months |
| Marketing Cookies (YouTube, Google Maps) | YouTube videos and Google Maps embeds may set cookies when loaded. These embeds are blocked by default and only load when you: (1) grant global marketing consent via the cookie banner, or (2) click 'Load Video' or 'Load Map' on individual embeds. Your click-to-load choice is remembered for your browsing session. | Various cookies set by YouTube and Google Maps | Varies by provider |
Embedded Content (YouTube & Google Maps)
To protect your privacy, YouTube videos and Google Maps are not loaded automatically. Instead, you see a placeholder explaining that the content requires marketing consent. You can either grant global consent via the cookie banner, or click to load individual embeds. If you click to load an embed, this choice is stored in your browser's session storage and applies to all embeds of that type during your current browsing session.
Google Analytics 4 Configuration
- IP Anonymization: GA4 anonymizes IP addresses by default for EU users.
- Data Retention: User-level data is retained for 14 months (minimum available setting).
- Google Signals: Disabled. We do not collect data for advertising personalization.
- Conditional Loading: GA4 scripts only load after you grant analytics consent.
Managing Your Cookie Preferences
You can change your cookie preferences at any time by clicking the "Manage Cookie Preferences" button in the footer. After 12 months, your consent expires and the cookie banner will reappear for you to re-confirm your choices. You can also disable cookies through your browser settings, though this may affect website functionality.
5. Your Rights (GDPR)
As a data subject, you have the following rights:
- •Right of Access: Obtain confirmation of whether your data is being processed and access to it.
- •Right to Rectification: Request correction of inaccurate personal data.
- •Right to Erasure: Request deletion of your data ('right to be forgotten').
- •Right to Restriction: Request limitation of processing in certain circumstances.
- •Right to Portability: Receive your data in a structured, commonly used format.
- •Right to Object: Object to processing based on legitimate interests.
- •Right to Withdraw Consent: Withdraw consent at any time without affecting prior lawful processing.
- •Right to Lodge a Complaint: File a complaint with a supervisory authority (Italian Garante or Belgian DPA, depending on your residence or the location of the alleged violation).
6. Contact
For questions regarding this privacy policy or to exercise your rights, please contact us at privacy@sanvirgilio.eu