PRIVACY POLICY OF THE WEBSITE OTTOLINA.IT
Pursuant to Art. 13 of Regulation (EU) 2016/679 (GDPR)
The Data Controller of the personal data collected through this website is: Caffè Ottolina S.r.l., with registered office at Via Decemviri 20/24, 20137 Milan, Italy.
Your personal data will be processed for the purposes illustrated below, each supported by a specific legal basis and subject to a precise retention period:
Purpose of Processing | Type of Data | Legal Basis | Retention Period |
|---|---|---|---|
Management of requests sent via the contact form or email (information, table bookings, delivery services). | Personal details, contact information (email, phone), and message content. | Art. 6, par. 1, lit. b) GDPR: execution of pre-contractual or contractual measures. | The time necessary to fulfill the request and in any case no later than 24 months from the last contact. |
Evaluation of job applications and Curriculum Vitae sent spontaneously or in response to job openings. | Personal details, contact information, professional experience, and education history. | Art. 6, par. 1, lit. b) GDPR: execution of pre-contractual measures; Art. 111-bis of Italian Legislative Decree 196/2003. | Maximum 12 months from the receipt of the CV, unless an employment relationship is established. |
Management of the customer account within the online shop. | Personal details, login credentials, and order history. | Art. 6, par. 1, lit. b) GDPR: execution of a contract to which the data subject is party. | Until the data subject requests the closure of the account. |
Order fulfillment and product sales through the e-commerce store (Shopify platform). | Personal details, shipping address, billing address, and contact data. | Art. 6, par. 1, lit. b) GDPR: execution of the purchase contract. | Until the successful delivery of the product and the management of any contractual guarantees or returns. |
Tax, civil, and accounting obligations related to online sales. | Billing data, transaction amounts, and payment references. | Art. 6, par. 1, lit. c) GDPR: compliance with a legal obligation to which the Data Controller is subject. | 10 years from the transaction, in accordance with Art. 2220 of the Italian Civil Code. |
Subscription to the Newsletter and delivery of promotional/commercial communications (news, events, initiatives). | Email address. | Art. 6, par. 1, lit. a) GDPR: express and optional consent of the data subject. | Until consent is withdrawn (opt-out), which can be done independently via the dedicated link at the bottom of each newsletter. |
Photo/video recording during events (public, corporate, or online events, e.g., general overviews, group shots). | Images, videos, and voice recordings. | Art. 6, par. 1, lit. f) GDPR: Legitimate interest of the Data Controller to document and promote corporate events on communication channels. | Up to 3 years on active communication channels; files classified as historical will be kept in the corporate archive indefinitely. |
Close-up photo/video recording (focused on an individual for targeted promotional purposes). | Detailed individual images or interviews. | Art. 6, par. 1, lit. a) GDPR: explicit consent collected via a specific release form. | Until consent is withdrawn and in any case no later than 3 years from the event. |
Website security and prevention of fraud or computer abuse. | Navigation data (IP addresses, server logs, timestamps, URI resources). | Art. 6, par. 1, lit. f) GDPR: Legitimate interest of the Data Controller to protect and ensure the correct functioning of the website. | Deleted immediately after anonymous statistical processing, unless required for the investigation of crimes by the Judicial Authority. |
Personal data is processed using computer, electronic, and paper tools suitable for ensuring confidentiality and security.
The collected personal data may be transferred or communicated to third parties appointed to carry out activities strictly connected and instrumental to the operation of the service:
These subjects operate either as Data Processors duly appointed pursuant to Art. 28 of the GDPR or as independent Data Controllers. Your data will not be disseminated indiscriminately.
Some of the service providers utilized by the Data Controller (including Shopify and its related applications) may involve the transfer of personal data to countries outside the European Economic Area (EEA), such as the United States or Canada. These transfers take place exclusively in full compliance with Articles 44 et seq. of the GDPR, guaranteed by:
In accordance with the GDPR, data subjects have the right to exercise the following rights at any time against the Data Controller:
To exercise these rights, request clarifications, or report changes, please contact the Data Controller by writing to: info@ottolina.it.
Last updated: July 2026