Privacy Policy

Who we are

Our website address is: https://almachiaragin.com.

Data Controller

The data controller of all personal data that is collected and used about Alma Chiara customers for the purposes of the EU General Data Protection Regulation (GDPR), and applicable national law transposing it is Roma & Ginger Srls (‘Roma & Ginger”), a company registered in Italy with company registration number xxx. Our registered offices are in Via Medaglie d’Oro 17, 31035 Crocetta del Montello, TV, Italy.

Roma & Ginger Srls is committed to protecting our customer data privacy and takes its responsibility regarding the security of customer information very seriously. We will be clear and transparent about the information we are collecting and what we will do with that information.

We may advertise third party services on our website and link to third party websites from our website in respect of these services. If you access these third party websites, the third party will be a “data controller” of your personal data in respect of the service they are providing. Please review the privacy policies/statements of these third party providers to understand how they process your data.

What personal data we collect

Personal data means any information relating to you which allows us to identify you, such as your full name, contact details, payment details and information about your access and use of our website.

We collect personal data from you when you: (i) purchase a product from us, (ii) subscribe to our newsletter and / or e-marketing services, (iii) apply for a refund, (iv) use our website and and other websites accessible through our website, (v) contact us, or (vi) otherwise enter into a contract with us. We may also process personal data about you, which we receive from trusted third parties in relation to your purchase.

We may collect and process your name, date of birth, home or business address, e-mail address, telephone number, credit/debit card, IBAN & BIC, and or Paypal Unique ID, information related to the products you have purchased (e.g., type and number of bottles), information about your use of our website including browser settings, domain name, browser type, browser language, device ID, operating system type, device name and model, pages or screens viewed, links clicked, IP address, when and the length of time you visit our website and the referring URL, or the webpage that led you to our website, your IP address and website market (e.g., English or Italian) for purchases of products, information contained in the communications you exchange with us or direct to us via letters, emails, chat service, calls, and social media and logs of data protection requests.

What we use your personal data for and legal basis for using it

We will need to process your personal data so we can process your order, enter into a contract, or otherwise perform a contract with you where you purchase one of our Alma Chiara products.

We collect and use data you provide during the purchase process to perform our purchase contract with you, to contact you in relation to your contract in line with the Alma Chiara Terms & Conditions.   The legal basis for processing this data is the performance of our contract with you.

We collect your identity information when you provide it through our web-form or by email to make a data subject request. The legal basis for processing this data is our legitimate interest to verify your identity to respond to GDPR requests and to demonstrate our compliance with GDPR obligations.

We process your date of birth to ensure we comply with applicable law prohibiting  the sale of alcohol to minors.

We collect and use Payment Information and combine it with Identity Information, Usage Data and Location Data to comply with payment scheme obligations and detect and prevent fraudulent activities. Our legal basis for processing this data is our legitimate interest in detecting and preventing fraudulent activities and complying with regulatory obligations and payment card scheme rules.

We may process all the categories of data listed above to defend our legitimate interest in enforcing our legal rights.

We process Purchase Data and Location Data to perform statistical and marketing analysis, systems testing, maintenance and development which may include the combination of data for profiling purposes. The legal basis for processing this data is our legitimate interest in improving and promoting our marketing services.

We process Identity Information and Travel History. The legal basis for processing this data is our legitimate interest in improving our services and enhancing your experience with us.

We collect Usage Data and Payment Information (which is connected to a myRyanair account where  applicable). To analyse traffic on our website to make improvements to our website and services. The legal basis for processing this data is Legitimate interest in improving our services for our customers.

How long we retain your data

We will not retain your data for longer than is necessary to fulfil the purpose it is being processed for. To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the purposes for which we process it and whether we can achieve those purposes through other means. We will also consider if and how we can minimise over time the personal data that we use, and if we can anonymise your personal data so that it can no longer be associated with you or identify you, in which case we may use that information without further notice to you.

Security of your personal data

We are committed to ensuring the security and confidentiality of your personal data. Taking into account the nature of your personal data and the risks of processing, we have put in place appropriate technical and organizational measures as required by applicable legal provisions to ensure an appropriate level of security and to prevent any accidental or unlawful destruction, loss, alteration, disclosure, intrusion of or unauthorized access to these data.

All payment details are transmitted and stored in compliance with Payment Card Industry Data Security Standards (PCI DSS).

We may disclose your information to trusted third parties for the purposes set out in this Privacy Policy, who have appropriate technical and operational security measures in place to protect your personal data, in line with Irish, UK and EU law on data protection rules.

In the event that Roma & Ginger suffers a breach involving your personal data and this breach creates a high risk to your rights, we will inform you about the breach, the likely consequences of it and the measures we have put in place to protect you and others in accordance with our GDPR obligations.

Sharing and transferring your personal data 

Roma & Ginger may sell its products outside the EEA. While countries outside the EEA do not have the same data protection laws, we require all partners and services providers to process your information in a secure manner and in accordance with GDPR requirements and mainly rely on European Commission approved standard contractual clauses that ensure protection for your data even when it leaves the EEA.

Service Providers – We may share your data with our trusted service providers who provide services on our behalf where such service providers are obliged to safeguard your data in accordance with the relevant data protection agreement:

  • Tranpsorter: to ship the products to your home or business address. Where these are transferred to the UK, the data will be processed in line with the Adequacy decision (link). Where the data is transferred to the US, we have in place European Commission approved standard contractual clauses.
  • Our cloud service and e-mail marketing service providers including IMS, Swrve, SurveyMonkey and Adobe to process purchasing and usage data to assist us with customer surveys and marketing campaigns.
  • payment service providers and currency conversion providers to process purchasing data and usage data to facilitate your payments to us.
  • legal and other professional advisers to process any and all data to enforce our legal rights in relation to our contract with you and to assist in the investigation of illegal or fraudulent activities or where required by law or court order. Generally non-EEA legal and professional advisors do not have access to EEA data. In the limited cases where they do, we put in place European Commission approved standard contractual clauses.
  • Customs and border control authorities to process purchasing and shipping data to comply withcustoms and border control requirements or binding law enforcement requests and court orders. Where the data is transfreed to the UK we rely on the adequacy decision (linked here). Where the data is transferred to other non-EEA countries: where possible, we rely on mutual legal assistance treaties (MLAT) per Article 50 of the  GDPR and in other cases, derogation for occasional transfers on basis of legal claims (Art 49(1)(e) GDPR).
  • Governmental agencies and law enforcement authorities for public health reasons. to demonstrate we have met these requirements to our regulators and to respond to legally binding requests from law enforcement and public health authorities. If transferred outside the EEA, we rely on the Derogation for occasional transfers for the transfer is necessary for important reasons of public interest (Art 49(1)(d) GDPR).
  • Digital and Social media marketing to deliver advertisements to you on other websites and apps, including on social media platforms.To share analytics data on the performance and reach of advertising campaigns with our partners.
  • Courts and law enforcement bodies in all countries we operate in. If the transfer occurs to non-EEA countries, where possible, we rely on mutual legal assistance treaties (MLAT) per Article 50 of the GDPR and in other cases, derogation for occasional transfers on basis of legal claims (Art 49(1)(e) GDPR)

Cookies

We use cookies on our website. Roma & Ginger is the data controller of any information we obtain from the use of cookies. Please refer to our Cookie Policy and cookie preference centre.

Data Protection Officer

Roma & Ginger’s Data Protection Officer (“DPO”) who monitors our compliance with applicable data protection laws may be contacted here: xxx. In addition, you always have the right to make a complaint at any time to a supervisory authority. The Italian Data Protection Commission is the lead data protection supervisory authority for Roma & Ginger so please be aware that your complaint may be transferred to the Italian Data Protection Commission where it involves cross-border processing.

Your Data Protection Rights

The GDPR and other data protection laws give you specific rights in relation to your personal data:

Opt out / Unsubscribe rom marketing e-mails, equest for erasure of your personal data (right to be forgotten)  may ask us to delete or remove personal data, where we have no legal basis to continue to process it However, we will retain the personal data that relates to a contract between you and Roma & Ginger , to perform the contract, defend or pursue our legal rights and meet our obligations towards regulatory or governmental authorities. Object to processing of personal data. Y ou may also object to the processing of your personal data where we are doing so based on legitimate interestsou have the right to object to the use of your data for direct marketing purposes at any time. Right to request information, Request access to the personal data we hold about you,r equest correction of the personal data that we hold about you , Object to automated decision-making including profiling, which produce a legal effect or similarly significant effects Request the restriction of processing of your personal data, which enables you to ask us to suspend the processing of personal data about you, but only in limited circumstances, which you must set out in detail, Request portability of your personal data in an electronic and structured form to you or to another party (commonly known as a right to “data portability”)., his enables you to receive personal data that you shared with us (on the basis of consent or contractual necessity) in an electronically useable format, and to be able to transfer your data to another party in an electronically useable format. withdraw consentn in the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal data for a specific purpose, you have the right to withdraw your consent for that specific processing at any time:

Your requests should be filed by email at or at the following postal address for the attentinog of: xxx

Changes to Privacy Policy

We may make changes to this privacy policy at any time and if we make any material changes we will bring these changes to your attention.

We will respond to any request you make to exercise your rights within one month. 7KK123000/

Comments

Suggested text: When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

Suggested text: If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Cookies

Suggested text: If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Suggested text: Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Who we share your data with

Suggested text: If you request a password reset, your IP address will be included in the reset email.

How long we retain your data

Suggested text: If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

Suggested text: If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where your data is sent

Suggested text: Visitor comments may be checked through an automated spam detection service.