Data Protection Policy

Effective Date: April 21, 2025

Casa Suli & Shop Sicily (referred to as "we," "us," or "our") is committed to protecting the privacy and personal data of our users. This Data Protection Policy outlines how we collect, use, disclose, and safeguard your personal data when you use our website and services. By accessing our website, you agree to the terms of this policy.

1. Introduction

We process personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Italian Data Protection Code (Legislative Decree No. 196/2003, as amended). This policy applies to all personal data collected through our website, services, and interactions with customers.

2. Data Collection

We may collect the following types of personal data:

  • Personal Identification Information: Name, email address, phone number.

  • Billing and Shipping Information: Address, payment details.

  • Order History and Preferences: Details of purchases and preferences.

  • Communication Preferences and Consent: Marketing preferences and consent records.

  • Device and Browsing Information: IP address, browser type, cookies, and usage data.

3. Purpose of Data Processing

We process your personal data for the following purposes:

  • Order Fulfilment: To process orders, payments, and provide customer support.

  • Service Improvement: To enhance our products, services, and website functionality.

  • Marketing Communications: To send promotional materials with your consent. Providing your email during checkout for promotional purposes constitutes consent to receive marketing emails.

  • Legal Compliance: To comply with legal obligations, including tax and accounting requirements.

4. Legal Basis for Processing

Our processing of personal data is based on the following legal grounds:

  • Contractual Necessity: Processing is necessary for the performance of a contract with you.

  • Legal Obligation: Processing is required to comply with legal obligations.

  • Consent: You have given explicit consent for specific processing activities.

  • Legitimate Interests: Processing is necessary for our legitimate interests, provided these are not overridden by your rights and interests.

5. Data Disclosure

We may disclose your personal data to:

  • Payment Processors: To facilitate secure transactions.

  • Shipping Carriers: To deliver orders.

  • Service Providers: For website maintenance, marketing, and other operational services.

  • Legal Authorities: When required by law or to protect our legal rights.

  • Business Transfers: In the event of a merger, acquisition, or asset sale.

All third-party service providers are contractually obligated to protect your data in accordance with GDPR requirements.

6. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption: Securing data during transmission and storage.

  • Access Controls: Restricting access to authorised personnel.

  • Regular Security Assessments: Monitoring and testing our security measures.

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required by law. The retention period may vary depending on the type of data and applicable legal requirements.

8. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Access: Request access to your personal data.

  • Rectification: Request correction of inaccurate or incomplete data.

  • Erasure: Request deletion of your personal data, subject to legal obligations.

  • Restriction: Request restriction of processing under certain circumstances.

  • Data Portability: Request a copy of your data in a structured, commonly used format.

  • Objection: Object to processing based on legitimate interests.

  • Withdraw Consent: Withdraw consent at any time for processing based on consent.

To exercise any of these rights, please contact us at support@casasuli.com.

9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance user experience and analyse website traffic. You can manage your cookie preferences through your browser settings. For more information, please refer to our Cookie Policy.

10. Data Transfers

If we transfer your personal data outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place, such as:

  • Standard Contractual Clauses: Approved by the European Commission.

  • Adequacy Decisions: Recognising the recipient country as providing adequate data protection.

11. Data Protection Officer (DPO)

We have appointed a Data Protection Officer to oversee compliance with this policy and applicable data protection laws. You can contact our DPO at support@casasuli.com.

12. Changes to This Policy

We may update this Data Protection Policy to reflect changes in our practices or legal requirements. We will notify you of any significant changes by posting the updated policy on our website and indicating the effective date.

13. Contact Information

If you have questions, concerns, or requests related to your personal data, please contact us at:

Email: support@casasuli.com

By using our website and services, you acknowledge that you have read, understood, and agree to this Data Protection Policy.