Privacy Policy

Last updated: 20 July 2026

This privacy notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and of Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the “Italian Privacy Code”), and describes how we process the personal data of users who browse the tintichianti.it website, purchase products through the online shop, book tastings, or stay at our accommodation facility.

1. Data Controller

Az. Agricola Scarpeto di Sotto di Tinti Daniele Registered office: Via Felice Cavallotti 41 – 50052 Certaldo (FI), Italy Winery and local unit: Via Pino Scarpeto 21, loc. Pino Scarpeto – 50052 Certaldo (FI) VAT no. (P. IVA): 05390610482 Tax code and registration no. in the Florence Company Register: TNTDNL77E23D403G REA (Economic and Administrative Index): FI – 543036 Certified email (PEC): tntdnl77e23d403g@impresa.italia.it

Contact for privacy matters: info@tintichianti.it Telephone: +39 333 826 8985

The Controller has not appointed a Data Protection Officer (DPO), as the conditions set out in Article 37 GDPR do not apply.

2. Categories of data collected

Depending on the type of interaction, we may process:

  • Identification and contact data: first name, surname, email address, telephone number, place of residence or shipping address, country of origin.
  • Tax and billing data: tax code, VAT number, recipient code (Codice Destinatario) or PEC for purchases requiring electronic invoicing.
  • Order-related data: products purchased, quantities, amounts, delivery address, purchase history, correspondence, any returns or complaints.
  • Payment data: handled directly by the payment service providers. The Controller does not collect or store the full payment card numbers; it receives only confirmation that the transaction has taken place and partial identification data (last four digits, card network, outcome).
  • Data relating to tasting and experience bookings: requested date and time, number of participants, preferred language, any food intolerances or allergies communicated voluntarily, special requests.
  • Data relating to the stay: arrival and departure dates, number and composition of the group, personal details and identity document details of all guests, collected at check-in in compliance with a legal obligation (see § 3.6).
  • Browsing data: IP address, browser and device type, operating system, language, pages visited, date and time of access, referring website. These are collected automatically through the server logs and, subject to consent, through cookies and similar technologies.
  • Voluntarily provided data: the content of messages sent via the contact form, by email, telephone, WhatsApp, or through the company’s social media profiles. Messages sent via the website contact form are delivered by email to the Controller and, at the same time, stored in the website database together with the sender’s email address, the date of submission, and the originating IP address.
  • Special categories of data. We do not request data belonging to special categories within the meaning of Article 9 GDPR. Should a user voluntarily provide information relating to food allergies or intolerances ahead of a tasting, such data will be processed on the basis of the explicit consent expressed through the communication itself, for the sole purpose of ensuring the safety of the service, and will then be deleted once the service has concluded.

Minors. The services offered through the website are not intended for persons under the age of 18: the sale and serving of alcoholic beverages to minors are prohibited by applicable law. We do not knowingly collect data relating to minors through the website. In the context of a stay at the accommodation facility, the data of minor guests is processed solely to the extent necessary to fulfil the obligations to report to the public security Authorities, and under the responsibility of those exercising parental authority.

3. Purposes, legal bases, and retention periods

3.1 Sale of products through the online shop

  • Purpose: order management, payment collection, shipping, handling of returns, warranties and after-sales support, tax and accounting obligations.
  • Legal basis: performance of a contract to which the data subject is party (Art. 6.1.b GDPR); for tax obligations, legal obligation (Art. 6.1.c GDPR).
  • Retention: for the entire duration of the relationship and, thereafter, for 10 years from its conclusion, in compliance with civil-law and tax obligations (Art. 2220 of the Italian Civil Code and VAT legislation).

3.2 Booking of tastings, tours, and cellar experiences

  • Purpose: managing the request, checking availability, confirmation, organising the service, communications regarding the appointment (confirmations, reminders, changes).
  • Legal basis: performance of pre-contractual measures taken at the data subject’s request and of the subsequent contract (Art. 6.1.b GDPR).
  • Retention: 24 months from the date of the service; where a tax document is issued, 10 years for the accounting data only.

3.3 Booking and stay at the accommodation facility

  • Purpose: managing the booking and the stay, operational communications, issuing accounting documents, collecting and remitting the tourist tax to the Municipality of Certaldo.
  • Legal basis: performance of the contract (Art. 6.1.b GDPR) and compliance with legal obligations (Art. 6.1.c GDPR).
  • Retention: 10 years for tax and accounting documentation; booking data not relevant for tax purposes is deleted within 24 months.

3.4 Responding to requests for information

  • Purpose: responding to requests sent via the contact form, email, telephone, WhatsApp, or social networks.
  • Legal basis: performance of pre-contractual measures at the data subject’s request (Art. 6.1.b GDPR) or, for requests of a non-commercial nature, the Controller’s legitimate interest in providing a response (Art. 6.1.f GDPR).
  • Retention: 24 months from the last relevant contact. Messages received via the contact form remain stored in the website database, hosted in Italy, for the same period, after which they are deleted.

3.5 Newsletter and promotional communications

  • Purpose: sending updates on the company’s activities, new vintages, cellar events, initiatives, and commercial offers.
  • Legal basis: free, specific, informed, and revocable consent (Art. 6.1.a GDPR), collected through a double opt-in procedure (confirmation of subscription via a link sent to the address provided). With regard to those who have already made a purchase, communications relating to products and services similar to those purchased may be sent pursuant to Art. 130 para. 4 of the Italian Privacy Code (soft spam), with the right to object free of charge at any time.
  • Retention: until consent is withdrawn or the subscriber is removed from the list, and in any case no longer than 24 months of subscriber inactivity. Data relating to the consent given (date, time, IP address of subscription and of confirmation) is retained as evidence of compliance for the same period and for the following 5 years.
  • Withdrawal: via the unsubscribe link at the bottom of each message, or by writing to info@tintichianti.it.

3.6 Reporting of guests’ details to the Authorities

  • Purpose: communicating guest data to the “Alloggiati Web” Portal of the Italian State Police and transmitting statistical flows to the Tuscany Region and to ISTAT (National Institute of Statistics).
  • Legal basis: compliance with a legal obligation to which the Controller is subject (Art. 6.1.c GDPR; Art. 109 of the Consolidated Law on Public Security – Royal Decree 773/1931; Decree-Law 113/2018).
  • Procedure: guests’ identity documents are examined and the relevant data recorded at check-in by the facility’s staff. We do not retain photocopies or scans of the documents beyond the time strictly necessary for transmission.
  • Nature of the provision: mandatory. Refusal to present a valid identity document makes it impossible to proceed with check-in.
  • Retention: the transmission receipts issued by the Alloggiati Portal are retained for 5 years, as required by sector-specific legislation.

3.7 Browsing statistics, measurement, and online marketing

  • Purpose: aggregated analysis of website usage, measurement of the effectiveness of advertising campaigns, ad optimisation, and remarketing activities.
  • Legal basis: the user’s consent given through the cookie banner (Art. 6.1.a GDPR and Art. 122 of the Italian Privacy Code). These tools remain inactive until consent is given.
  • Retention: according to the durations set out in the Cookie Policy for each cookie, and in any case no longer than 14 months for Google Analytics 4 data.
  • Details: please refer to the Cookie Policy available in the website footer.

3.8 Security, abuse prevention, and legal defence

  • Purpose: ensuring the security and proper maintenance of the website, preventing fraud and unauthorised access attempts, establishing liability in the event of computer crime, and asserting or defending a right in legal proceedings.
  • Legal basis: the Controller’s legitimate interest in the security of its systems and in the protection of its rights (Art. 6.1.f GDPR).
  • Retention: technical server logs are retained for a maximum period of 12 months, unless further retention is required for the purposes of legal proceedings.

4. Nature of the provision of data

The provision of the data marked as mandatory in the website forms is necessary in order to act on the user’s request: failure to provide it makes it impossible to process an order, confirm a booking, or reply to a message.

The provision of data for newsletter, marketing, and statistical purposes is, by contrast, optional: refusal or subsequent withdrawal of consent in no way affects access to the products and services offered.

5. Processing methods and security measures

Data is processed mainly by electronic means and, to a residual extent, on paper, adopting technical and organisational measures appropriate under Article 32 GDPR, including:

  • encrypted TLS/HTTPS connection on all pages of the website;
  • access to the administrative area limited to authorised persons, using individual credentials;
  • periodic updating of the CMS, plugins, and infrastructure;
  • regular backups and recovery procedures;
  • storage of paper documentation in premises with controlled access.

Processing is carried out by the Controller and by persons authorised and instructed by the Controller pursuant to Article 29 GDPR (collaborators, family members assisting in the business, and facility staff).

No automated decision-making is carried out, nor any profiling producing legal effects or otherwise significantly affecting the data subjects, within the meaning of Article 22 GDPR.

6. Recipients of the data

Data may be communicated to the following parties, appointed where necessary as Data Processors pursuant to Article 28 GDPR:

ProviderRolePurposeData location
Serverplan S.r.l.ProcessorWebsite and database hosting, management of email accountsItaly (EU)
Automattic Inc. / WooCommerceProcessorE-commerce platform (software installed on the Controller’s server)Italy (EU)
Stripe Payments Europe Ltd.Independent ControllerCollection of card, Apple Pay, and Google Pay payments, fraud preventionIreland (EU), with transfers to the USA
PayPal (Europe) S.à r.l. et Cie, S.C.A.Independent ControllerCollection of payments via PayPal accountLuxembourg (EU)
The Controller’s bankIndependent ControllerCollection of payments by bank transferItaly (EU)
Mail Boxes Etc. (MBE Worldwide S.p.A. and affiliates)ProcessorCollection, shipping, and delivery of productsItaly (EU)
MailPoet / Automattic Inc.ProcessorManagement of the subscriber list and delivery of the newsletter via the MailPoet Sending ServiceItaly (EU) for storage; USA for delivery
Google Ireland Ltd.Independent ControllerGoogle Analytics 4 and Google Ads conversion tagsIreland (EU), with transfers to the USA
Meta Platforms Ireland Ltd.Joint Controller / Independent ControllerMeta Pixel for measuring advertising campaignsIreland (EU), with transfers to the USA
CookieYes LimitedProcessorManagement of the cookie banner and consent registerUnited Kingdom
WhatsApp Ireland Ltd.Independent ControllerCommunications initiated via the WhatsApp contact buttonIreland (EU), with transfers to the USA
Tax and accounting consultantProcessorBookkeeping and declaratory obligationsItaly (EU)
Italian State Police – Alloggiati Portal; Tuscany Region; ISTAT; Municipality of CertaldoIndependent ControllersCompliance with legal obligationsItaly (EU)

Note on MailPoet. The software is installed directly on the website and the subscriber list is stored on the Controller’s server in Italy. The actual delivery of messages is entrusted to the MailPoet Sending Service, operated by Automattic Inc. (USA), which processes the recipients’ email addresses for the purposes of sending, message authentication (SPF and DKIM), handling of delivery failures, and automatic removal of invalid addresses, on the basis of the safeguards set out in § 7.

Note on the WhatsApp button. The button on the website is simply a link that opens the WhatsApp application on the user’s device: it does not install cookies and does not transmit any data before it is clicked. Once a conversation is started, the processing of the related metadata is governed by WhatsApp’s own privacy notice, for which the Controller is not responsible.

Data is under no circumstances disseminated, nor transferred, sold, or communicated to third parties for the marketing purposes of parties other than the Controller.

An up-to-date list of the appointed Data Processors is available on request by writing to info@tintichianti.it.

7. Transfer of data outside the European Economic Area

The main website infrastructure is hosted in Italy. Some of the providers listed in § 6 may, however, process data on servers located outside the EU/EEA, in particular in the United States. In such cases, the transfer takes place on the basis of one of the safeguards provided for under Chapter V of the GDPR:

  • an adequacy decision of the European Commission: for the United Kingdom (decision of 28 June 2021) and, for the participating US providers, the EU–U.S. Data Privacy Framework (decision of 10 July 2023), under which Google LLC, Meta Platforms Inc., Stripe Inc., and Automattic Inc. are certified;
  • on a residual basis, Standard Contractual Clauses approved by the European Commission by Implementing Decision (EU) 2021/914, accompanied by supplementary technical and organisational measures.

A copy of, or information on, the safeguards adopted may be requested by writing to info@tintichianti.it.

8. Rights of the data subject

Pursuant to Articles 15–22 GDPR, the data subject has the right to:

  • access their personal data and obtain a copy of it (Art. 15);
  • obtain the rectification of inaccurate data and the completion of incomplete data (Art. 16);
  • obtain the erasure of data, in the cases provided for by Art. 17;
  • obtain the restriction of processing (Art. 18);
  • receive the data provided in a structured, commonly used, and machine-readable format, and transmit it to another controller (data portability, Art. 20);
  • object to processing based on legitimate interest (Art. 21), as well as, at any time and without the need to give reasons, to processing for direct marketing purposes;
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal (Art. 7.3).

Requests should be sent to info@tintichianti.it or by post to the registered office address. The Controller will respond without undue delay and in any case within one month of receiving the request, a period that may be extended by a further two months in the case of particularly complex or numerous requests, with notice to the data subject. The exercise of these rights is free of charge, except in the case of manifestly unfounded or excessive requests.

Complaint to the supervisory Authority. A data subject who believes that the processing of their data infringes applicable law has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome – tel. +39 06 696771 – garante@gpdp.it – www.garanteprivacy.it), or to bring the matter before the competent judicial authority.

9. Cookies and tracking technologies

The website uses technical cookies, which are necessary for its operation and are installed without the need for consent, and — solely subject to consent given through the dedicated banner — third-party analytics cookies as well as profiling and marketing cookies.

Consent management is entrusted to the CookieYes platform, which records and stores evidence of the preferences expressed. Users may modify or withdraw their choices at any time via the “Cookie preferences” link in the footer of every page.

The complete list of cookies used, with details of their purpose, provider, and duration, can be found in the Cookie Policy, which is always accessible from the website footer.

10. Third-party links and content

The website may contain links to third-party websites and platforms (social media profiles, messaging services, maps). The Controller exercises no control over such sites and is not responsible for any processing of personal data carried out there: users are invited to consult the respective privacy notices.

11. Changes to this privacy notice

The Controller reserves the right to update this privacy notice at any time, including as a result of legislative changes or the introduction of new services. Changes will be published on this page, with the date of the latest update shown at the top.

In the case of substantial changes concerning processing based on consent, the data subject will be asked to provide fresh consent.