15% OFF con il codice ALMACHIARA2026 al checkout.

Privacy Policy​

1. Data Controller

The Data Controller for the personal data collected via the website www.almachiaragin.com is Roma & Ginger S.r.l.s., a Single-Member Simplified Limited Liability Company registered in Italy at Via Medaglie d’Oro 17, 31035 Crocetta del Montello (TV) – VAT No. 05540440269 (hereinafter also referred to as “Roma & Ginger” or “Controller”). The Data Controller is the individual or legal entity, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of personal data processing.

Roma & Ginger is committed to confidentiality, security, and transparency in the handling of personal data, in compliance with Legislative Decree 196/2003 (“Privacy Code”), as amended by Legislative Decree 101/2018 and Regulation (EU) 2016/679 (“GDPR”).

2. Types of Data Collected

The personal data processed may include:

  • Personal and contact details: name, surname, date of birth, email address, phone number, address

  • Payment information: credit/debit card details, IBAN, BIC, PayPal ID

  • Browsing data: IP address, browser type, operating system, pages visited, session duration, referring URLs

  • Purchase-related data: order history, product preferences, payment methods

  • Communications: messages sent via email, chat, social media, or other channels

Data may be collected:

  • when purchasing a product

  • upon subscription to newsletters or promotional materials

  • while using the website

  • when requesting support or exercising privacy rights

  • via reliable third parties involved in order management

Personal data may be processed by personnel expressly authorized by the Controller — including employees and third party service providers — within the scope of their duties and in accordance with instructions provided. These individuals may act as:

  • Authorized processors: natural persons acting under the direct authority of the Controller or Processor, following documented instructions (pursuant to Art. 29 of the GDPR and Art. 2-quaterdecies of the Privacy Code, as amended by Legislative Decree 101/2018)

  • or, where appointed, as Processors, i.e., entities processing data on behalf of the Controller, based on a contract or other binding legal act (Art. 28 of the GDPR)

 

3. Purpose, Legal Basis, and Data Retention Period

The Controller collects and uses personal data for specific, explicit, and legitimate purposes, based on a valid legal basis as required by Article 6 of the GDPR and Articles 2-ter and 2-sexies of the Privacy Code, as amended by Legislative Decree 101/2018.

Personal data is retained only for as long as strictly necessary to fulfill the purposes for which it was collected, in compliance with the principle of storage limitation (Art. 5(1)(e) of the GDPR and Art. 2-sexies(1)(f) of the Privacy Code, as amended by Legislative Decree 101/2018).

The following table outlines:

  1. The data category

  2. Purpose of processing

  3. Legal basis

  4. Data retention period

Data Category

Purpose

Legal Basis

Retention Period

Personal and contact details

Order management, billing, customer support

Contract performance

10 years (for civil and tax obligations)

Payment data

Transactions, fraud prevention

Legal obligation and legitimate interest

10 years unless litigation arises

Browsing data (IP, logs)

Security, analytics, website optimization

Legitimate interest

12 months, unless longer required

Marketing data

Newsletters, promotions, surveys

Consent

Until consent is withdrawn or max 24 months

Purchase history

After-sales support, warranty, analytics

Contract and legal obligation

10 years (for warranty and accounting)

4. Data Security

The Controller adopts appropriate technical and organizational measures to ensure data security, in compliance with Art. 32 of the GDPR, including:

  • Encryption of payment data

  • Restricted access to authorized personnel

  • Systems to prevent unauthorized access, data loss, or alteration

Authorized personnel are properly trained and bound by confidentiality obligations. If a data breach occurs that could pose a high risk to the rights and freedoms of individuals, the Controller will notify the affected individuals without undue delay, as required by Articles 33 and 34 of the GDPR, and Art. 2-septies of the Privacy Code, as amended by Legislative Decree 101/2018.

5. Data Communication and Transfers

Data may be shared with trusted third parties duly appointed as Data Processors, including:

  • Payment service providers

  • Couriers and shipping companies

  • Legal and tax advisors

  • Providers of cloud and marketing services

In the case of transfers to non-EU countries, Roma & Ginger ensures that adequate security measures are in place, such as:

  • Standard contractual clauses approved by the European Commission

  • Other adequate guarantees as per Articles 44 and following of the GDPR

  • Transfers to countries with an adequacy decision

  • In specific situations, reliance on derogations under Art. 49 of the GDPR (e.g., based on contractual necessity or explicit consent)

These transfers are also carried out in compliance with Art. 2-septies of the Privacy Code, as amended by Legislative Decree 101/2018 and the guidelines issued by the Italian Data Protection Authority.

6. Facebook Permissions and Tracking Technologies

This website may integrate functionalities provided by Meta Platforms Inc., which require the User’s explicit authorization to connect with their Facebook account and access basic information, such as name, ID, profile picture, gender, language, and visible contacts—depending on the user’s privacy settings.

In addition, tracking technologies may be used—including Meta Pixel and tools from third-party partners—such as cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting. These tools help monitor user activity, analyze preferences, and enhance both website navigation and ad campaigns.

All processing is carried out in accordance with the GDPR and the Privacy Code, as amended by Legislative Decree 101/2018. For more details, please refer to Meta’s Privacy Policy and the site’s “Cookie Policy” section.

7. Data Subject Rights

Users can exercise their rights under Articles 15–22 of the GDPR and, where applicable, under Articles 2-undecies and 2-duodecies of the Privacy Code, as amended by Legislative Decree 101/2018. These rights include:

  • Right to access, correct, or delete data

  • Right to restrict or object to processing

  • Right to data portability

  • Right to withdraw consent

  • Right to lodge a complaint with the Data Protection Authority (www.garanteprivacy.it)

Requests can be submitted to: 📧 info@roma-ginger.com 📮 Roma & Ginger S.r.l.s., Via Medaglie d’Oro 17, 31035 Crocetta del Montello (TV), Italy

8. Data Protection Officer (DPO)

The Data Protection Officer (DPO) for Roma & Ginger can be contacted at: info@roma-ginger.com. The DPO monitors compliance with privacy regulations and acts as a contact point for users and the Supervisory Authority.

9. Changes to the Privacy Policy

This privacy notice may be updated at any time. In case of significant changes, users will be notified.

Last updated: July 30, 2025

EN

Are you of legal age?

You must be of legal drinking age to access this website.