Information pursuant to Article 13 of Regulation (EU) 2016/679
Website: boscolivo.com
Last updated: 29 August 2026
This notice explains how Azienda Agricola Boscolivo collects and processes the personal data of users who visit https://boscolivo.com, use its forms, create an account, subscribe to the newsletter or purchase products through the online store. Processing is carried out in accordance with Regulation (EU) 2016/679 (the “GDPR”), Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, and other applicable Italian laws.
Data Controller
Azienda Agricola Boscolivo
Via Dante Alighieri, 11, 98036 Graniti (ME), Italy
VAT number: IT03678990833
Email: info@boscolivo.com
For information about processing or to exercise data-protection rights, data subjects may write to support@boscolivo.com.
Categories of personal data processed
Browsing and technical data
When users browse the website, the IT systems and software used to operate it may automatically collect:
- IP address;
- date and time of the request;
- requested page and referring URL;
- browser type, operating system and device;
- technical connection information and session identifiers;
- shopping-cart data and information about the source of the visit;
- operational, error and security logs.
These data are used to operate and secure the website, prevent abuse and fraud, diagnose technical problems and produce statistics within the limits permitted by law.
Data submitted through the contact form
When a user sends an enquiry, Boscolivo may collect the user’s name, email address, subject, message and any additional information voluntarily provided.
Users are asked not to include special-category, sensitive or unnecessary personal data in their message.
Order data
When a user makes a purchase, Boscolivo may process:
- name, surname and contact details;
- billing and delivery addresses;
- country, province or state, city and postal code;
- products, quantities, prices, totals and order notes;
- shipping, delivery, return and refund information;
- tax, accounting and order-history information.
These data are required to process the order, conclude the sales contract, deliver the products and comply with administrative, tax and accounting obligations.
Customer-account data
If a user creates an account, Boscolivo may process the user’s name, surname, email address, username, securely stored password, saved addresses, order history and account preferences.
Users may update their details through the account area or request their correction or deletion by contacting the Data Controller.
Payment data
Payments are handled through external providers, including WooPayments/Stripe and Klarna. Full payment-card details are normally collected directly by the provider through secure hosted forms and are not stored in full by Boscolivo.
- payment result and payment method;
- transaction identifier, amount, date and time;
- limited or masked payment-instrument information;
- information required for disputes, refunds and fraud-prevention checks.
Payment providers may process additional information as independent controllers or processors, depending on the service and their own privacy notices.
Newsletter data
When a user subscribes to the newsletter, Boscolivo processes the email address, date and method of consent, subscription status, preferences and, where enabled and permitted, information about delivery, opens and interactions with messages.
The newsletter is managed through Mailchimp or an equivalent service. Subscription is optional and separate from purchasing.
Cookies and tracking technologies
The website uses technical cookies required to maintain sessions, manage the cart and checkout, authenticate users, protect the website and remember privacy preferences.
Functional, analytical or advertising cookies, pixels and other non-essential technologies are used only after consent where required. Details must be provided in a separate Cookie Policy and in the preference-management panel.
Purposes and legal bases
Personal data are processed for the purposes and on the legal bases set out below. Where processing relies on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
| Purpose | Legal basis |
| Website browsing, operation and security | Data Controller’s legitimate interests — Article 6(1)(f) GDPR |
| Responding to contact enquiries | Pre-contractual steps requested by the user — Article 6(1)(b) GDPR |
| Creating and managing an account | Performance of a contract — Article 6(1)(b) GDPR |
| Orders, payments, shipping, returns and support | Performance of a contract — Article 6(1)(b) GDPR |
| Tax, accounting and administrative obligations | Compliance with a legal obligation — Article 6(1)(c) GDPR |
| Purpose | Legal basis |
| Fraud prevention and defence of legal rights | Legitimate interests — Article 6(1)(f) GDPR |
| Newsletter and promotional communications | Consent — Article 6(1)(a) GDPR |
| Non-essential cookies and technologies | Consent — Article 6(1)(a) GDPR |
| Handling data-protection requests | Compliance with a legal obligation — Article 6(1)(c) GDPR |
Mandatory and optional data
Data marked as mandatory are required to manage an enquiry, create an account, process an order, receive payment or deliver products.
If those data are not provided, Boscolivo may be unable to answer the enquiry, conclude the sales contract, process payment, deliver the order or manage returns and support.
Providing data for newsletters, marketing and non-essential cookies is optional. Refusal does not prevent browsing or purchasing.
Processing methods and security
Personal data are processed using electronic systems and, where necessary, paper records. The Data Controller implements technical and organisational measures appropriate to the risk to protect data against loss, destruction, unauthorised access, disclosure, alteration, unlawful use or accidental unavailability.Access is limited to authorised personnel and suppliers that need the information to perform assigned activities. No information system can, however, guarantee absolute security.
Recipients of personal data
Personal data may be disclosed, where necessary, to the following categories of recipients:
- hosting, server, backup and IT-infrastructure providers;
- website developers, administrators and maintenance providers;
- WordPress and WooCommerce platform-service providers;
- WooPayments, Stripe, Klarna and fraud-prevention providers;
- Mailchimp and newsletter-service providers;
- couriers, logistics operators and shipment-tracking providers;
- email and customer-support providers;
- banks and tax, accounting, legal and insurance advisers;
- public, judicial or administrative authorities where required by law.
Providers processing data on Boscolivo’s behalf are appointed as processors under Article 28 GDPR where required. Some providers may act as independent controllers. Boscolivo does not sell or publicly disclose users’ personal data.
External services and embedded content
The website may use or link to external services such as Google Maps, Google Fonts, Instagram and social content, Mailchimp, Stripe/WooPayments, Klarna, fraud-prevention, shipping and tracking services.
When a user views or interacts with external content, the provider may receive technical information such as the IP address, device information and browsing data. Where required, these services are activated only after the user gives consent through the cookie-preference panel.
External websites and their processing activities are governed by the privacy notices of their respective operators.
Transfers outside the European Economic Area
Some providers may process personal data in countries outside the European Economic Area. In those cases, transfers are made using one of the safeguards provided by Articles 44–49 GDPR, including adequacy decisions, Standard Contractual Clauses and additional technical, organisational or contractual safeguards.
Data subjects may contact the Data Controller for information about the safeguards applicable to a particular transfer.
Retention periods
Personal data are retained only for as long as necessary for the purposes for which they were collected. As a general rule:
- contact enquiries: up to 12 months after the enquiry is closed;
- orders, invoices and accounting records: for the period required by law, ordinarily 10 years;
- returns, complaints and disputes: until the matter is resolved and the relevant limitation periods expire;
- customer accounts: for the lifetime of the account, subject to applicable legal obligations;
- newsletter data: until consent is withdrawn, with periodic review of continued interest;
- proof of consent and cookie preferences: for the period required to demonstrate lawfulness and according to the consent-management configuration;
- technical and security logs: normally no longer than 30 days, unless required for incidents, abuse investigations or authority requests;
- data required to establish, exercise or defend claims: until the matter is concluded and applicable limitation periods expire.
At the end of the applicable period, data are deleted, anonymised or retained only where required by law.
Newsletter and marketing
Promotional messages are sent only to users who have given specific, freely given and demonstrable consent. Newsletter consent is separate from purchasing, must not be preselected and may be withdrawn at any time.
Each message includes an unsubscribe link. Consent may also be withdrawn by writing to support@boscolivo.com. Withdrawal does not affect the handling of orders or customer-support enquiries.
Automated decision-making
Boscolivo does not make decisions based solely on automated processing that produce legal or similarly significant effects on users.
Payment providers may carry out automated fraud-prevention or security checks. Klarna may carry out assessments required to provide its payment services. Those activities are governed by the privacy notices of the relevant providers.
Children
The website is not intended knowingly to collect personal data from children. Alcoholic products may be purchased only by adults.
If the Data Controller becomes aware that a child’s data have been collected improperly, appropriate steps will be taken to delete them.

