Privacy Policy

    Last updated: December 9, 2025

    In accordance with the General Data Protection Regulation (GDPR - EU Reg. 2016/679), we inform you that personal data collected through the website www.sanvirgilio.eu is processed by two separate Data Controllers, each for the specific purposes indicated below.

    1. Data Controllers

    ControllerPurposeContact
    Le Piemont SAProduct sales (Olive Oil), management of contact requests related to products and newsletters.Avenue Monplaisir 91-95, 1030 Schaerbeek, Belgium (BE 0432.944.157)
    Società Agricola Sanvirgilio SRLManagement of contact requests related to room rentals and ancillary services (e.g., special requests, events).Contrada Cerasina, 72015 Fasano (BR), Italy (VAT IT02124260742)

    To exercise your GDPR rights, please contact: privacy@sanvirgilio.eu

    2. Data Collected, Purposes and Legal Bases

    Data SourcePersonal Data CollectedPurposeLegal Basis (GDPR)Retention Period
    Contact FormFirst Name, Last Name, Email, Message, Enquiry Type, Language, Email Status, Date/Time.Respond to user request (products or rooms).Performance of pre-contractual measures at the request of the data subject (Art. 6(1)(b)).12 months from resolution of the request, unless legal obligations require otherwise.
    Cookie ConsentConsent preferences (essential, analytics, marketing), timestamp.Store and respect user consent choices.Legitimate interest (Art. 6(1)(f)).12 months (automatic re-consent required after expiry).
    Embed ConsentSession-based consent for YouTube/Google Maps loading.Remember user choice to load third-party embeds during browsing session.Consent (Art. 6(1)(a)).Browser session only (cleared when tab/browser closes).
    Analytics (Google Analytics 4)Anonymous navigation data, page visits, time on site, device/browser information (IP anonymized).Statistical analysis to improve the website.Consent (Art. 6(1)(a)).14 months (GA4 configuration).
    Marketing Cookies (YouTube, Google Maps)Cookies set by embedded YouTube videos and Google Maps when loaded.Display embedded content and track interactions.Consent (Art. 6(1)(a)).Varies by provider (see provider policies).
    Newsletter (Future)Email (and optional name).Send commercial communications and updates (marketing).Free, specific and informed consent (Art. 6(1)(a)), via Double Opt-in.Until consent is withdrawn (Opt-out).
    Product Sales (Future - Stripe)Order Data (Products, Quantity, Amount), Shipping and Billing Address, Payment Data (tokenized by Stripe).Fulfillment of sales contract (shipping, invoicing, returns management).Performance of a contract (Art. 6(1)(b)) and Legal obligation (Art. 6(1)(c)).10 years (tax and accounting obligations).

    3. Recipients and Data Transfers

    Your personal data may be shared with the following parties (Data Processors):

    ServicePurposeLocationTransfer Basis
    SupabaseDatabase hosting for contact form data and site configuration.AWS EU (Frankfurt)Data remains in EU
    NetlifyWebsite hosting and serverless functions.US East (Ohio)EU-US Data Privacy Framework / SCC
    ResendEmail delivery service for contact form notifications.Global (US-based)Standard Contractual Clauses (SCC)
    Google Analytics 4Anonymous website usage statistics.Global (US-based)EU-US Data Privacy Framework / SCC
    YouTube (Google)Embedded video content.Global (US-based)EU-US Data Privacy Framework / SCC
    Google MapsEmbedded interactive maps.Global (US-based)EU-US Data Privacy Framework / SCC
    Stripe (Future)Payment processing for product sales.GlobalEU-US Data Privacy Framework / SCC
    DPD (Future)Shipping and delivery services.EUData remains in EU

    Extra-EU Transfers: Transfers to providers outside the EU are lawful based on Standard Contractual Clauses (SCC) and, where applicable, adequacy decisions (e.g., EU-US Data Privacy Framework).

    4. Cookies & Tracking Technologies

    Our website uses cookies and similar technologies to improve your experience and analyze site usage.

    Cookie Consent Banner

    When you first visit our site, a cookie consent banner appears allowing you to accept all cookies, reject non-essential cookies, or customize your preferences. Your choice is stored for 12 months, after which the banner will reappear for you to re-confirm your preferences.

    Types of Cookies We Use

    TypeDescriptionCookiesRetention Period
    Essential CookiesRequired for basic website functionality. These cookies store your language preference and cookie consent choices. They cannot be disabled.cookie-consent (localStorage, 12 months), embed-consent-youtube, embed-consent-maps (sessionStorage, browser session)12 months / Browser session
    Analytics Cookies (Google Analytics 4)We use Google Analytics 4 to understand how visitors interact with our website. IP addresses are anonymized. Google Signals and advertising features are disabled. These cookies are only loaded after you grant consent._ga, _ga_* cookies14 months
    Marketing Cookies (YouTube, Google Maps)YouTube videos and Google Maps embeds may set cookies when loaded. These embeds are blocked by default and only load when you: (1) grant global marketing consent via the cookie banner, or (2) click 'Load Video' or 'Load Map' on individual embeds. Your click-to-load choice is remembered for your browsing session.Various cookies set by YouTube and Google MapsVaries by provider

    Embedded Content (YouTube & Google Maps)

    To protect your privacy, YouTube videos and Google Maps are not loaded automatically. Instead, you see a placeholder explaining that the content requires marketing consent. You can either grant global consent via the cookie banner, or click to load individual embeds. If you click to load an embed, this choice is stored in your browser's session storage and applies to all embeds of that type during your current browsing session.

    Google Analytics 4 Configuration

    • IP Anonymization: GA4 anonymizes IP addresses by default for EU users.
    • Data Retention: User-level data is retained for 14 months (minimum available setting).
    • Google Signals: Disabled. We do not collect data for advertising personalization.
    • Conditional Loading: GA4 scripts only load after you grant analytics consent.

    Managing Your Cookie Preferences

    You can change your cookie preferences at any time by clicking the "Manage Cookie Preferences" button in the footer. After 12 months, your consent expires and the cookie banner will reappear for you to re-confirm your choices. You can also disable cookies through your browser settings, though this may affect website functionality.

    5. Your Rights (GDPR)

    As a data subject, you have the following rights:

    • Right of Access: Obtain confirmation of whether your data is being processed and access to it.
    • Right to Rectification: Request correction of inaccurate personal data.
    • Right to Erasure: Request deletion of your data ('right to be forgotten').
    • Right to Restriction: Request limitation of processing in certain circumstances.
    • Right to Portability: Receive your data in a structured, commonly used format.
    • Right to Object: Object to processing based on legitimate interests.
    • Right to Withdraw Consent: Withdraw consent at any time without affecting prior lawful processing.
    • Right to Lodge a Complaint: File a complaint with a supervisory authority (Italian Garante or Belgian DPA, depending on your residence or the location of the alleged violation).

    6. Contact

    For questions regarding this privacy policy or to exercise your rights, please contact us at privacy@sanvirgilio.eu