PRIVACY POLICY

PRIVACY POLICY – INFORMATION ON PERSONAL DATA PROCESSING

The GDPR requires that the privacy notice specifies, among other things, the identity of the data controller, purposes and legal bases, recipients, retention periods, data subject rights, any transfers to third countries, and information on consent where applicable.

INFORMATION ON PERSONAL DATA PROCESSING

Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679

Last updated: 17 September 2026

This privacy notice describes how ARATA DOLCE CREMA S.r.l. processes the personal data of users who visit the website www.gruppoarata.it or who use the services and features available through the website.


1. Data Controller

The Data Controller is:

ARATA DOLCE CREMA S.r.l.

Registered office:
Via Virgilio, 1 – 91100 Trapani (TP), Italy

Plant:
Viale P. Borsellino, 4 – 90010 Geraci Siculo (PA), Italy

VAT no.: IT04238540829

Tel. +39 0921 643809
Tel. +39 329 6428416
E-mail: commerciale@gruppoarata.it


2. What personal data may be processed

Various categories of personal data may be processed through the website, depending on how the user interacts with it.

These may include:

  • first name and surname;
  • email address;
  • telephone number;
  • company and professional role;
  • data contained in requests sent via contact forms;
  • information relating to commercial enquiries;
  • IP address and technical information relating to the device and browser;
  • browsing data, within the limits permitted by the user's cookie preferences.

The provision of data through any contact forms is normally voluntary; however, some data may be necessary to respond to the user's request.


3. Purposes of processing

Personal data may be processed for the following purposes:

A. Management of contact requests

To respond to requests for information, commercial enquiries, and requests relating to the company's products, resellers, and services.

Legal basis: performance of pre-contractual measures adopted at the request of the data subject and/or legitimate interest of the Controller in managing received requests.

B. Management of commercial relationships

If a commercial relationship arises from the request, the data may be used for the management of the contractual, administrative, and operational relationship.

Legal basis: performance of the contract and fulfilment of legal obligations.

C. Fulfilment of legal obligations

Data may be processed to comply with obligations under applicable laws, regulations, and rules.

Legal basis: fulfilment of a legal obligation.

D. Website security

Technical data and any browsing data may be processed to ensure website security, prevent abuse, cyber-attacks, and fraudulent activities.

Legal basis: legitimate interest of the Controller in the security of its systems and services.

E. Statistical analysis and website improvement

If analytical tools requiring consent are used, the relevant data will be processed only after obtaining the user's consent.

Legal basis: consent of the data subject.

F. Marketing and promotional communications

If the website or other company tools provide for consent-based marketing activities, data may be used for sending commercial and promotional communications.

Legal basis: consent of the data subject.

Consent may be withdrawn at any time.


4. Processing methods

Personal data is processed using IT, electronic, and, where necessary, paper-based tools.

Data is processed in compliance with the principles of:

  • lawfulness;
  • fairness;
  • transparency;
  • data minimisation;
  • accuracy;
  • storage limitation;
  • integrity;
  • confidentiality.

Appropriate technical and organisational measures are adopted commensurate with the nature of the data and the risks associated with processing.


5. Data recipients

Personal data may be communicated, to the extent necessary for the stated purposes, to subjects who provide services functional to the Controller's activity, such as, by way of example:

  • IT service providers;
  • hosting and technological infrastructure providers;
  • email service providers;
  • security service providers;
  • consultants and professionals;
  • statistical analysis service providers;
  • marketing service providers, if used and authorised by the user;
  • public authorities and subjects to whom communication is required by law.

When such subjects process personal data on behalf of the Controller, where required, they are designated as data processors pursuant to Article 28 GDPR.


6. Transfer of data to third countries

Some technology service providers may be based or process data outside the European Economic Area.

In such cases, the Controller ensures that the transfer takes place in compliance with the provisions of the GDPR and through a mechanism provided for by applicable law, such as an adequacy decision by the European Commission or the appropriate safeguards provided for in Articles 44 et seq. of the GDPR.

This section must, however, be verified based on the services actually installed on the website before final publication.


7. Retention period

Personal data is retained for the period necessary to achieve the purposes for which it was collected.

In particular:

  • data relating to contact requests are retained for the time necessary to manage the request and for the subsequent period necessary to protect the Controller's rights;
  • data relating to contractual relationships are retained for the period provided for by civil, tax, and administrative law;
  • data processed based on consent are retained until consent is withdrawn, unless further retention requirements are provided for by law;
  • data relating to cookies and tracking tools are retained according to the periods indicated in the Cookie Policy and its settings.

8. Data subject rights

The data subject, in the cases provided for by law, may exercise the rights provided for in Articles 15-22 of the GDPR and in particular:

  • obtain confirmation as to whether or not personal data concerning them is being processed;
  • obtain access to their data;
  • request rectification of inaccurate data;
  • request erasure of data;
  • request restriction of processing;
  • object to processing;
  • obtain data portability in the cases provided for;
  • withdraw previously given consent, without affecting the lawfulness of processing carried out before withdrawal.

The data subject also has the right to lodge a complaint with the Garante per la protezione dei dati personali (Italian Data Protection Authority) if they believe that the processing of their personal data violates applicable law.


9. How to exercise rights

To exercise your rights, you can contact the Controller:

ARATA DOLCE CREMA S.r.l.
Via Virgilio, 1 – 91100 Trapani (TP)
E-mail: commerciale@gruppoarata.it
Tel. +39 0921 643809
Tel. +39 329 6428416

The request will be handled within the timeframes provided by the GDPR.


10. Cookies and tracking tools

For specific information on the cookies used by the website, their purposes, categories, duration, and consent management methods, please refer to the Cookie Policy.

The website currently has a consent management system that allows the user to modify their preferences.


11. Changes to this privacy notice

The Controller reserves the right to modify or update this Privacy Policy in the event of regulatory, technical, or organisational changes relating to the processing of personal data.

The updated version will be published on this page, indicating the date of the last update.