GDPR

1. Legal Basis

This data protection policy is drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and current legislation on data protection in Italy.

It governs how personal data processed through the website is collected, processed, stored and protected.

Data processing is carried out in compliance with the principles of lawfulness, fairness, transparency, purpose limitation and data minimization.

2. Data Controller

The data controller for personal data is the store management unit, responsible for the technical and organizational administration of information provided by users when using the digital services offered through the website.

Data processing is carried out exclusively for purposes related to order management, communication with users and the proper functioning of the services.

3. Types of data collected

The following categories of personal data may be collected during the use of the website:

Contact data: e-mail address, telephone number (optional), shipping or billing address
Order and transaction data: products purchased, amounts, payment method used
Technical and usage data: IP address, browser type, date and time of access, preferences, cookies

Data may be provided directly by the user or collected through technical tools necessary for the proper functioning of the website.

4. Purposes and legal bases of processing

Personal data is processed for the following purposes:

execution of purchase contracts and order management
fulfillment of legal and administrative obligations
protection of the legitimate interests of store management, including service improvement and prevention of improper use
guarantee of the security and proper technical functioning of the website

Processing is based on the execution of the contract, legal obligations, legitimate interests or the explicit consent of the user.

The user may withdraw any consent given at any time, without prejudice to the lawfulness of processing carried out prior to withdrawal.

5. Data retention and security

Personal data are stored exclusively for the time necessary to achieve the purposes indicated above.

For administrative and legal reasons, order-related data may be retained for up to 10 years.
Data processed on the basis of consent is retained until consent is revoked.

Adequate technical and organizational measures are adopted to prevent unauthorized access, loss, disclosure or alteration of data.

Information is stored on servers protected by security protocols and SSL encryption systems.

6. User Rights

Pursuant to Articles 15 to 22 of the GDPR, the user has the right to:

· obtain information on processed personal data

· request the rectification or updating of data

· request data erasure

· obtain restriction of processing

· request data portability

· object to processing for legitimate reasons

· withdraw consent at any time

· lodge a complaint with the competent supervisory authority in Italy

Requests related to the exercise of these rights can be sent by e-mail to customer service.

7. Policy Update

This data protection policy may be updated periodically to reflect regulatory changes or technical adjustments.

Changes come into effect upon their publication on the website. Users are advised to consult this policy regularly.

8. Contacts

For any questions regarding this data protection policy, please contact us via:

E-mail: info@mercatonecilea.com
Phone: +39 081 579 7167
Address: Via Cilea 123, 80127 Naples, Italy
Monday to Friday, from 09:00 to 18:00 Italian Time CET/CEST
Service area: Italy