PRIVACY POLICY

PRIVACY POLICY

Last updated: 23 July 2026

This Privacy Policy describes how the personal data of users who browse and/or make purchases on the website www.siculiani.com (hereinafter referred to as the "Website") is processed, in accordance with Regulation (EU) 2016/679 ("GDPR") and Legislative Decree 196/2003 ("Privacy Code"), as amended by Legislative Decree 101/2018.

This information notice is provided pursuant to Articles 13 and 14 of the GDPR to anyone interacting with the services of the Website and has been drafted in accordance with the guidelines issued by the Italian Data Protection Authority and the European Data Protection Board (EDPB).

1. DATA CONTROLLER

The Data Controller is:

GREEN LAB SRL
Registered office: via Eremo 13, 95017 Piedimonte Etneo (CT)
Operational office: corso Italia 31, 95014 Giarre (CT)
VAT number: 06005950875
REA: 456496 CCIAA of Catania
E-mail: [email protected]
Certified email (PEC): [email protected]

For any request relating to the processing of their personal data, users may contact the Data Controller at the addresses indicated above.

Data Protection Officer (DPO): no DPO has been appointed, as the processing activities carried out by GREEN LAB SRL do not fall within the cases requiring mandatory appointment pursuant to Article 37 of the GDPR (large-scale processing of special categories of data or systematic and large-scale monitoring of data subjects). Should this situation change, this information notice will be updated accordingly.

2. TYPES OF DATA COLLECTED

When using the Website, GREEN LAB SRL may collect the following categories of personal data:

2.1 Data voluntarily provided by the user, for example when creating an account, making a purchase, subscribing to the newsletter or contacting Customer Service: first name, surname, e-mail address, telephone number, shipping and/or billing address, billing information (for legal entities), date of birth (where required for age verification purposes in relation to the sale of alcoholic products), and the content of communications sent to Customer Service.

2.2 Payment-related data: credit/debit card details or PayPal account information are not collected or stored by GREEN LAB SRL, as the transaction is managed directly by the payment service providers Stripe and PayPal, on their respective secure and protected servers. GREEN LAB SRL only receives confirmation of the outcome of the transaction. For information on the processing of data by these providers, please refer to their respective privacy policies: Stripe and PayPal.

2.3 Browsing data: the IT systems and software procedures used to operate the Website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols (e.g. IP address, browser type, operating system, pages visited, date and time of visit). This data is used solely to obtain anonymous statistical information on the use of the Website and to verify its correct functioning, and is deleted immediately after processing, unless its retention is necessary to establish liability in the event of possible cybercrimes against the Website.

2.4 Cookies and similar technologies: for detailed information regarding the cookies used by the Website, please refer to the Cookie Policy, which forms an integral part of this information notice.

3. PURPOSES AND LEGAL BASIS OF PROCESSING

Users' personal data is processed for the following purposes:

a) Conclusion and performance of the purchase contract (order management, shipping, invoicing, management of returns/replacements/warranties, and customer assistance relating to the order).

Legal basis: performance of a contract to which the data subject is party or of pre-contractual measures taken at the request of the data subject (Article 6(1)(b) GDPR).

b) Compliance with legal obligations (e.g. tax and accounting obligations, issuance of receipts/invoices, age verification for the sale of alcoholic products in accordance with applicable legislation, management of requests from competent authorities).

Legal basis: compliance with a legal obligation to which the Data Controller is subject (Article 6(1)(c) GDPR).

c) Direct marketing activities relating to products or services similar to those already purchased (soft spam), in compliance with the conditions set out in Article 130(4) of the Privacy Code, where the e-mail address was provided by the Customer in connection with a purchase and the Customer has not objected to such use either at the time of collection or on the occasion of subsequent communications.

Legal basis: legitimate interest of the Data Controller (Article 6(1)(f) GDPR), within the limits established by Article 130(4) of the Privacy Code. The user may object to this processing at any time and free of charge, both at the time the data is collected and when receiving each subsequent communication, by using the unsubscribe link provided at the bottom of each communication or by writing to [email protected].

d) Sending newsletters and promotional communications relating to products, offers and initiatives of the Data Controller, other than those referred to in point c), where the user has voluntarily subscribed to the relevant service.

Legal basis: free, specific, informed and unambiguous consent of the data subject (Article 6(1)(a) GDPR and Article 130(1) and (2) of the Privacy Code). Consent is requested through an unchecked box, separate from acceptance of the General Terms and Conditions of Sale, and may be withdrawn at any time without affecting the lawfulness of processing based on consent given before withdrawal, by using the unsubscribe link included in every communication or by contacting [email protected].

e) Management of complaints, disputes and legal proceedings, and protection of the Data Controller's rights in judicial or extrajudicial proceedings.

Legal basis: legitimate interest of the Data Controller in the establishment, exercise or defence of a legal right (Article 6(1)(f) GDPR).

f) Statistical analysis of Website usage through third-party tools (Google Analytics), in order to understand users' browsing behaviour and improve the content and services offered.

Legal basis: user's consent, provided through the cookie banner (Article 6(1)(a) GDPR and Article 122 of the Privacy Code), unless the analytics tool is configured in such a way that it can be considered equivalent to technical cookies according to the guidelines of the Italian Data Protection Authority (e.g. IP anonymisation, no combination with other data). For further details, please refer to the Cookie Policy.

g) Website security and fraud prevention, including the identification of orders lacking a genuine purchase interest or cases of abuse of the right of withdrawal.

Legal basis: legitimate interest of the Data Controller (Article 6(1)(f) GDPR).

4. MANDATORY OR OPTIONAL NATURE OF DATA PROVISION

4.1 The provision of data necessary for the performance of the purchase contract (personal details, shipping address, contact details) and for compliance with legal obligations is mandatory: refusal to provide such data will make it impossible to process the order.

4.2 The provision of data for marketing purposes and newsletter subscription is optional: refusal to provide consent, or subsequent withdrawal of consent, will not affect the possibility of purchasing products on the Website.

5. METHODS OF PROCESSING

5.1 Personal data is processed using both automated and manual tools, according to procedures strictly related to the purposes indicated above and, in any case, in such a way as to guarantee the security, integrity and confidentiality of the data, in compliance with the organisational, physical and technical measures required by applicable legislation.

5.2 GREEN LAB SRL does not carry out any automated decision-making process, including profiling, which produces legal effects concerning the data subject or similarly significantly affects them, pursuant to Article 22 GDPR.

6. COMMUNICATION AND DISCLOSURE OF DATA — CATEGORIES OF RECIPIENTS

6.1 The user's personal data is not subject to disclosure. However, it may be communicated, to the extent strictly necessary, to the following categories of recipients, acting either as independent Data Controllers or as Data Processors specifically appointed pursuant to Article 28 GDPR:

– couriers and shipping companies responsible for delivering products;

– payment service providers (Stripe, PayPal), limited to the data necessary for processing the transaction;

– providers of IT services, hosting, maintenance and management of the Website and information systems;

– consultants and professionals (accountants, lawyers) for compliance with accounting and tax obligations or for the protection of the Data Controller's rights;

– providers of newsletter delivery services and commercial communication services, where applicable;

– Google LLC, as provider of the Google Analytics service, as further described in the Cookie Policy;

– public authorities, supervisory and control bodies, and judicial authorities, where required by applicable law or for the exercise of a right in judicial proceedings.

6.2 The updated list of any appointed Data Processors may be requested by writing to [email protected].

7. TRANSFER OF DATA OUTSIDE THE EU

7.1 Some of the providers referred to in point 6 (in particular Google LLC, Stripe Inc. and PayPal, in relation to certain processing activities) may transfer personal data outside the European Economic Area, in particular to the United States.

7.2 Where such transfers take place, they are carried out in compliance with the safeguards provided for by Chapter V of the GDPR, in particular through the adoption of Standard Contractual Clauses approved by the European Commission (Commission Implementing Decision (EU) 2021/914), and/or through the providers' participation in the EU-US Data Privacy Framework, where applicable and certified, and/or in the presence of an adequacy decision by the European Commission.

7.3 Users may request further information regarding the safeguards adopted for such transfers by contacting the Data Controller at the addresses indicated in point 1.

8. DATA RETENTION PERIOD

8.1 Personal data is retained for a period no longer than necessary to achieve the purposes for which it was collected, in compliance with the principle of storage limitation (Article 5(1)(e) GDPR), and in particular:

– data relating to the performance of the purchase contract is retained for the entire duration of the contractual relationship and, subsequently, for the period required by applicable civil and tax legislation (normally 10 years from completion of the transaction, pursuant to Article 2220 of the Italian Civil Code and tax regulations concerning the retention of accounting records);

– data processed on the basis of consent for marketing and newsletter purposes is retained until consent is withdrawn by the data subject and, in any case, for a maximum period of 24 months from the user's last interaction with the communications received, unless otherwise provided by updated guidance from the Italian Data Protection Authority;

– data collected for soft spam purposes pursuant to Article 130(4) of the Privacy Code is retained for a maximum period of 24 months from collection, unless the data subject objects earlier;

– browsing data is retained only for the time strictly necessary for the purposes referred to in point 2.3 and, in any case, no longer than 6 months, without prejudice to specific requirements related to the investigation of criminal offences;

– data processed through cookies is retained according to the periods indicated in the Cookie Policy.

8.2 Once the retention periods have expired, the data will be deleted, destroyed or irreversibly anonymised, except where retention is required by law or is necessary for the establishment, exercise or defence of a right before the courts.

9. RIGHTS OF THE DATA SUBJECT

9.1 In relation to the processing of their personal data, users may exercise, under the conditions and within the limits provided for by Articles 15-22 of the GDPR, the following rights:

right of access (Article 15 GDPR): obtain confirmation as to whether or not personal data concerning them is being processed and, where this is the case, access the personal data and information relating to the processing;

right to rectification (Article 16 GDPR): obtain the correction of inaccurate personal data concerning them and the completion of incomplete personal data;

right to erasure ("right to be forgotten", Article 17 GDPR): obtain the deletion of personal data concerning them, in the cases provided for by law;

right to restriction of processing (Article 18 GDPR): obtain the restriction of processing where one of the situations provided for by law applies;

right to data portability (Article 20 GDPR): receive personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used and machine-readable format, and obtain the transmission of such data directly to another Data Controller where technically feasible, limited to data processed by automated means on the basis of consent or a contract;

right to object (Article 21 GDPR): object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them based on the legitimate interest of the Data Controller, as well as object at any time and free of charge to the processing of their personal data for direct marketing purposes, including profiling insofar as it is related to such direct marketing;

right to withdraw consent at any time, without affecting the lawfulness of processing based on consent given before its withdrawal;

right to lodge a complaint with the Italian Data Protection Authority, headquartered at Piazza Venezia 11, 00187 Rome, e-mail [email protected], PEC [email protected], website www.garanteprivacy.it, if the user believes that the processing of their personal data has been carried out in violation of applicable legislation.

9.2 To exercise the rights listed above, the user may send a request to [email protected] or via PEC to [email protected]. The Data Controller will provide a response to the request without undue delay and, in any case, within one month from receipt of the request. This period may be extended by two months in the case of complex or numerous requests, provided that the user is informed of the reasons for the delay.

10. MINORS

10.1 The Website is not intended for persons under 18 years of age and GREEN LAB SRL does not knowingly collect personal data relating to minors. Some products sold (alcoholic beverages) may not be sold to persons under 18 years of age, as specified in the General Terms and Conditions of Sale. Should the Data Controller become aware that it has collected personal data relating to a minor without the consent of the holder of parental responsibility, it will promptly delete such data.

11. DATA SECURITY

11.1 GREEN LAB SRL adopts appropriate technical and organisational security measures to ensure a level of security appropriate to the risk, pursuant to Article 32 GDPR, in order to reduce the risks of destruction, loss, alteration, unauthorised disclosure of, or accidental or unlawful access to, the personal data processed.

12. CHANGES TO THIS PRIVACY POLICY

12.1 This Privacy Policy may be subject to changes over time, including changes related to the possible entry into force of new sector-specific regulations, updates or provision of new services, or technological developments. The Data Controller therefore invites users to periodically consult this page.

12.2 In the event of substantial changes affecting the purposes or methods of processing, where the processing is based on the user's consent, new consent will be requested where required by law.

13. CONTACTS

For any information relating to this Privacy Policy or the processing of personal data, users may contact the Data Controller at [email protected] or via PEC at [email protected].