Legal information
Privacy Policy
How we handle the personal data of those who visit the site, write to us or subscribe to our newsletter. Under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
This translation is provided for convenience. The Italian version is the legally binding one.
Last updated: July 21, 2026
1. Who processes your data
The data controller is the company shown below, which decides the purposes and means of processing.
Saottini Società Agricola, società semplice
Via Tugurio, 3 — 25017 Lonato del Garda (BS), Italia
VAT and tax code 04059720989
PEC: cantinasaottini@legalmail.it
Email: info@saottinivini.com
We have not appointed a Data Protection Officer (DPO): the conditions of Article 37 GDPR do not apply. For any question about your data you can write to the addresses above.
2. What data we collect
Data you give us
- Tasting requests: first name, last name, email, phone, preferred date, number of guests (adults and children).
- Event requests: first name, last name, email, phone, type of event and the message you write to us.
- Newsletter: first name, last name and email.
Please do not send us, through the forms, data belonging to special categories (Article 9 GDPR) — for example information about health, allergies or intolerances. If you have dietary requirements to tell us about, we discuss them directly on the phone when we confirm the visit.
Data collected automatically
- Browsing data: IP address, browser and device type, date and time of the request, pages visited. These are the technical logs that every web server records in order to work and to be protected from abuse.
- Browser local storage: the site saves some technical preferences on your device. They are not used to profile you and are not transmitted to anyone. See the Cookie Policy.
Measurement and marketing tools: with your consent, we collect statistical and interaction data through the tools listed in the Cookie Policy.
3. Why we process it and on what legal basis
| Purpose | Legal basis | Retention |
|---|---|---|
| Replying to your tasting or event requests and organising the visit | Pre-contractual measures at your request (Art. 6(1)(b)) | 24 months from the last contact |
| Sending you the newsletter and news about events and initiatives | Your freely given, revocable consent (Art. 6(1)(a)) | Until consent is withdrawn |
| Running the site and protecting it from abuse and attacks | Our legitimate interest in security (Art. 6(1)(f)) | Technical logs: 12 months maximum |
| Meeting legal, tax and accounting obligations | Legal obligation (Art. 6(1)(c)) | 10 years (Art. 2220 Italian Civil Code) |
| Website usage statistics and marketing activities | Your consent, given through the banner (Art. 6(1)(a)) | See Cookie Policy |
Once these periods expire the data is deleted or anonymised, unless it must be kept to defend a legal claim.
4. Do you have to give us your data?
No. Providing it is voluntary. However, the fields marked as required in the forms are what we need in order to reply: without a name, email or phone number we cannot get back to you. Marketing consent, on the other hand, is entirely optional: if you do not give it, you will still receive a reply to your request.
5. Who we share the data with
Your data is neither sold nor transferred to third parties for their own purposes. It may be processed, on our behalf and on our instructions, by the suppliers that make our work possible, appointed as data processors (Article 28 GDPR):
- Hosting provider — the servers hosting the site are located in the European Union (Frankfurt, Germany).
- Adobe Fonts (Adobe Inc.) — supplies some of the site's typefaces. To serve them it receives your IP address. It sets no profiling cookies and does not use this data for advertising.
- Email and certified email providers — to receive and store your requests.
- Google, Microsoft and Meta — for statistics and marketing, only with prior consent. Details in the Cookie Policy.
- Advisors and professionals (e.g. accountants) and public authorities, where the law requires it.
6. Transfers outside the European Union
The site is hosted on European servers. Some suppliers may however be based in the United States or process data outside the European Economic Area. In those cases the transfer only takes place with the appropriate safeguards set out in Articles 44 ff. GDPR: an adequacy decision of the European Commission (for those adhering to the EU–U.S. Data Privacy Framework) or Standard Contractual Clauses. You can ask us for a copy of the safeguards in place by writing to info@saottinivini.com.
7. Your rights
At any time, and free of charge, you can exercise the rights set out in Articles 15–22 GDPR:
- Access: find out whether we process your data and obtain a copy of it.
- Rectification: correct inaccurate or incomplete data.
- Erasure: be forgotten, where we have no legitimate grounds to keep the data.
- Restriction: ask us to suspend the processing.
- Portability: receive the data in a machine-readable format, or have it transferred to another controller.
- Objection: object to processing based on legitimate interest.
- Withdrawal of consent: at any time, without affecting the lawfulness of processing already carried out. For the newsletter, the unsubscribe link at the bottom of every email is enough.
To exercise them, write to info@saottinivini.com or by certified email to cantinasaottini@legalmail.it. We reply within one month (Article 12(3) GDPR).
8. Complaint to the supervisory authority
If you believe the processing of your data breaches the GDPR, you can lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — garanteprivacy.it), or take the matter to court.
9. Children
The site is not aimed at children under 14 and we do not knowingly collect their data. If we realise we have received any, we delete it. The number of children given in a tasting request is used only to organise the welcome: we do not collect their identifying data.
10. Security
We adopt appropriate technical and organisational measures (Article 32 GDPR) to protect data from destruction, loss, unauthorised access or misuse: encrypted HTTPS connection, access limited to authorised people only, systems kept up to date.
11. Automated decision-making
We do not use automated decision-making processes or profiling that produce legal effects concerning you (Article 22 GDPR).
12. Changes to this notice
We may update this notice, for example if the services or tools we use change. The version in force is always the one published here, with the date of the last update shown at the top. If the changes are significant, we will let you know.