Privacy Policy
1. Data Controller
The Data Controller for the personal data collected via the website www.almachiaragin.com is Roma & Ginger S.r.l.s., a Single-Member Simplified Limited Liability Company registered in Italy at Via Medaglie d’Oro 17, 31035 Crocetta del Montello (TV) – VAT No. 05540440269 (hereinafter also referred to as “Roma & Ginger” or “Controller”). The Data Controller is the individual or legal entity, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of personal data processing.
Roma & Ginger is committed to confidentiality, security, and transparency in the handling of personal data, in compliance with Legislative Decree 196/2003 (“Privacy Code”), as amended by Legislative Decree 101/2018 and Regulation (EU) 2016/679 (“GDPR”).
2. Types of Data Collected
The personal data processed may include:
-
Personal and contact details: name, surname, date of birth, email address, phone number, address
-
Payment information: credit/debit card details, IBAN, BIC, PayPal ID
-
Browsing data: IP address, browser type, operating system, pages visited, session duration, referring URLs
-
Purchase-related data: order history, product preferences, payment methods
-
Communications: messages sent via email, chat, social media, or other channels
Data may be collected:
-
when purchasing a product
-
upon subscription to newsletters or promotional materials
-
while using the website
-
when requesting support or exercising privacy rights
-
via reliable third parties involved in order management
Personal data may be processed by personnel expressly authorized by the Controller — including employees and third party service providers — within the scope of their duties and in accordance with instructions provided. These individuals may act as:
-
Authorized processors: natural persons acting under the direct authority of the Controller or Processor, following documented instructions (pursuant to Art. 29 of the GDPR and Art. 2-quaterdecies of the Privacy Code, as amended by Legislative Decree 101/2018)
-
or, where appointed, as Processors, i.e., entities processing data on behalf of the Controller, based on a contract or other binding legal act (Art. 28 of the GDPR)
3. Purpose, Legal Basis, and Data Retention Period
The Controller collects and uses personal data for specific, explicit, and legitimate purposes, based on a valid legal basis as required by Article 6 of the GDPR and Articles 2-ter and 2-sexies of the Privacy Code, as amended by Legislative Decree 101/2018.
Personal data is retained only for as long as strictly necessary to fulfill the purposes for which it was collected, in compliance with the principle of storage limitation (Art. 5(1)(e) of the GDPR and Art. 2-sexies(1)(f) of the Privacy Code, as amended by Legislative Decree 101/2018).
The following table outlines:
-
The data category
-
Purpose of processing
-
Legal basis
-
Data retention period
|
Data Category |
Purpose |
Legal Basis |
Retention Period |
|
Personal and contact details |
Order management, billing, customer support |
Contract performance |
10 years (for civil and tax obligations) |
|
Payment data |
Transactions, fraud prevention |
Legal obligation and legitimate interest |
10 years unless litigation arises |
|
Browsing data (IP, logs) |
Security, analytics, website optimization |
Legitimate interest |
12 months, unless longer required |
|
Marketing data |
Newsletters, promotions, surveys |
Consent |
Until consent is withdrawn or max 24 months |
|
Purchase history |
After-sales support, warranty, analytics |
Contract and legal obligation |
10 years (for warranty and accounting) |
4. Data Security
The Controller adopts appropriate technical and organizational measures to ensure data security, in compliance with Art. 32 of the GDPR, including:
-
Encryption of payment data
-
Restricted access to authorized personnel
-
Systems to prevent unauthorized access, data loss, or alteration
Authorized personnel are properly trained and bound by confidentiality obligations. If a data breach occurs that could pose a high risk to the rights and freedoms of individuals, the Controller will notify the affected individuals without undue delay, as required by Articles 33 and 34 of the GDPR, and Art. 2-septies of the Privacy Code, as amended by Legislative Decree 101/2018.
5. Data Communication and Transfers
Data may be shared with trusted third parties duly appointed as Data Processors, including:
-
Payment service providers
-
Couriers and shipping companies
-
Legal and tax advisors
-
Providers of cloud and marketing services
In the case of transfers to non-EU countries, Roma & Ginger ensures that adequate security measures are in place, such as:
-
Standard contractual clauses approved by the European Commission
-
Other adequate guarantees as per Articles 44 and following of the GDPR
-
Transfers to countries with an adequacy decision
-
In specific situations, reliance on derogations under Art. 49 of the GDPR (e.g., based on contractual necessity or explicit consent)
These transfers are also carried out in compliance with Art. 2-septies of the Privacy Code, as amended by Legislative Decree 101/2018 and the guidelines issued by the Italian Data Protection Authority.
6. Facebook Permissions and Tracking Technologies
This website may integrate functionalities provided by Meta Platforms Inc., which require the User’s explicit authorization to connect with their Facebook account and access basic information, such as name, ID, profile picture, gender, language, and visible contacts—depending on the user’s privacy settings.
In addition, tracking technologies may be used—including Meta Pixel and tools from third-party partners—such as cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting. These tools help monitor user activity, analyze preferences, and enhance both website navigation and ad campaigns.
All processing is carried out in accordance with the GDPR and the Privacy Code, as amended by Legislative Decree 101/2018. For more details, please refer to Meta’s Privacy Policy and the site’s “Cookie Policy” section.
7. Data Subject Rights
Users can exercise their rights under Articles 15–22 of the GDPR and, where applicable, under Articles 2-undecies and 2-duodecies of the Privacy Code, as amended by Legislative Decree 101/2018. These rights include:
-
Right to access, correct, or delete data
-
Right to restrict or object to processing
-
Right to data portability
-
Right to withdraw consent
-
Right to lodge a complaint with the Data Protection Authority (www.garanteprivacy.it)
Requests can be submitted to: info@roma-ginger.com
Roma & Ginger S.r.l.s., Via Medaglie d’Oro 17, 31035 Crocetta del Montello (TV), Italy
8. Data Protection Officer (DPO)
The Data Protection Officer (DPO) for Roma & Ginger can be contacted at: info@roma-ginger.com. The DPO monitors compliance with privacy regulations and acts as a contact point for users and the Supervisory Authority.
9. Changes to the Privacy Policy
This privacy notice may be updated at any time. In case of significant changes, users will be notified.
Last updated: July 30, 2025