PRIVACY POLICY
Privacy, clearly stated.
Last updated: 20 July 2026
Who we are
Portico Gelato is the controller for this website. Contact us at Via della Consolata 18, 10122 Torino TO, Italy, [email protected], or +39 011 555 0186.
Laws that apply
We process data under GDPR and Italian Codice Privacy Legislative Decree 196/2003 as amended.
Data we collect
We collect your name, email, telephone number, message, booking or order details, and technical data such as IP address, device, browser, requested pages and cookie choices.
Purposes and legal bases
We reply to enquiries, arrange and perform contracts, maintain records required by law, and operate and secure the site. Contract, legal obligation, legitimate interests and consent are our legal bases. Optional analytics use consent only.
Sharing and transfers
We do not sell data. Hosting, email, security, payment and delivery processors may act under our instructions. International transfers use an adequacy decision or standard contractual clauses and safeguards.
Retention and security
Enquiries are generally kept for 24 months after meaningful contact; transaction and tax records for the period required by law. We use access controls and reputable providers, although no online system is fully secure.
Your rights and complaints
You may request access, correction, erasure, restriction, portability, or object to legitimate-interest processing. You may withdraw consent. Email us to exercise rights; we may verify identity. You may complain to Garante per la protezione dei dati personali.
Children, changes and contact
We do not knowingly collect children data. Contact us if you believe this has happened. We may update this policy when practice or law changes. Contact Portico Gelato at [email protected].
Further information about processing
Providing contact information is voluntary, but we cannot reply or arrange a requested service without the details needed to do so. We do not make decisions about you solely by automated means and do not use personal data for profiling that produces legal or similarly significant effects. If we receive information from a third party, it will normally be limited to details they give us so that we can deal with an enquiry or fulfil a request.
Our processors may only access data needed for their task. We assess suppliers with regard to confidentiality, security and reliability, and require them to notify us of relevant incidents. We review access permissions and do not keep personal information merely because storage is technically possible. Where information is anonymised so that it can no longer identify you, this policy does not apply to that anonymised information.
How to exercise your rights
Please state which right you wish to use and the information to which your request relates. We may ask for reasonable evidence of identity before disclosing or changing information, particularly where a request is made by someone else on your behalf. We normally respond within one month; if a request is complex or numerous, applicable law may allow an extension and we will tell you why. Requests are normally free, although we may charge a reasonable fee or refuse a request where permitted for manifestly unfounded or excessive requests.
If you object to processing based on legitimate interests, we will stop unless we have compelling legitimate grounds or need the information for legal claims. If you ask us to erase information, some copies may remain temporarily in secure backups and we may retain a limited record where law requires it or a claim remains possible. These limits will be explained when relevant.
Marketing and links
We do not use your enquiry details for unsolicited marketing without a lawful basis. If we send a message that is marketing, you can ask us to stop at any time. This site may link to other websites; their privacy practices are their responsibility. Please read their policies before submitting information to them.
Data accuracy and accountability
Please let us know if your personal information changes so that our records remain accurate. We train access holders to handle information carefully and investigate suspected misuse or security incidents. If a breach is likely to create a risk to people, we will take the steps required by law, including notifying the appropriate authority and affected individuals where applicable. Our records of processing and supplier arrangements are reviewed as our business and website develop.
Additional information
We aim to keep this notice clear and practical. If you need it in another format or have questions about how this policy applies to a particular enquiry, please contact us before providing information. We will consider reasonable requests and explain any limit that applies under law.