GDPR Compliance
General Data Protection Regulation Information
Our Commitment to GDPR
Regalo Italiano is committed to compliance with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Union.
Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: When you submit a consultation request or subscribe to communications
- Contract Performance: To fulfill services you've requested
- Legitimate Interests: To improve our services and communicate with clients
- Legal Obligations: When required to comply with applicable laws
Data Controller
Regalo Italiano acts as the data controller for personal information collected through our website and services:
Regalo Italiano
Via Roma 45
20121 Milano, Italy
[email protected]
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee for additional copies beyond the first request.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
You have the right to request deletion of your personal data under certain conditions, including when the data is no longer necessary for the purposes it was collected.
Right to Restrict Processing
You have the right to request restriction of processing your personal data under certain conditions.
Right to Object
You have the right to object to our processing of your personal data under certain conditions, including processing for direct marketing purposes.
Right to Data Portability
You have the right to request transfer of your data to another organization or directly to you, in a structured, commonly used, and machine-readable format.
Right to Withdraw Consent
Where we rely on consent to process your data, you have the right to withdraw that consent at any time.
Exercising Your Rights
To exercise any of these rights, contact us at [email protected] with the subject line "GDPR Request". We will respond within 30 days.
You will need to provide:
- Your full name
- Contact information we have on file
- Specific details of your request
- Proof of identity for security purposes
Data Protection Officer
For questions regarding data protection or to reach our Data Protection Officer, email [email protected]
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR. In Italy, the relevant authority is:
Garante per la protezione dei dati personali
Piazza Venezia, 11
00187 Roma, Italy
International Data Transfers
Your personal data is processed and stored within the European Union. If we transfer data outside the EU, we ensure appropriate safeguards are in place to protect your information.
Data Retention
We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy or as required by law. Consultation records are typically retained for three years, after which they are securely deleted unless you request earlier deletion.
Automated Decision Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
Updates to This Statement
We may update this GDPR compliance statement as regulations evolve or our practices change. Significant updates will be communicated through our website.