Privacy policy

Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended.

Last updated: 24 September 2026

1. Data controller

Verde Vercelli di Andrea Vetri
Ditta individuale
Via dei Ciudin 8
13100 Vercelli (VC), Italy
VAT no. 02482010028
Email: [email protected]
Phone: +39 348 438 4139

The controller is also the point of contact for data protection. No Data Protection Officer (DPO) has been appointed, as the conditions set out in Article 37 GDPR do not apply.

2. Types of data collected

We collect and process the following personal data:

Website usage statistics

To know how many people visit the site and which pages they read, we collect a few browsing statistics ourselves, without cookies or any other identifier stored on the device and without third-party tools. For each page viewed we record: the page, the referring page, the browser language, the browser, operating-system and device family (e.g. "Safari", "smartphone"), any campaign parameters in the address, time spent on the page and clicks on phone, e-mail, WhatsApp and map links and on contact buttons. The IP address is used only at the time of the request to derive an approximate location (country, region, city) and a pseudonymous identifier that changes every day, and is not stored. None of this data makes it possible to identify a person.

3. Purposes and legal basis of the processing

The data are processed for the following purposes:

4. How the data are processed

The data are processed electronically and on paper, in compliance with the technical and organisational security measures required by Article 32 GDPR. Access to the data is limited to the controller and to collaborators who have been expressly authorised and instructed.

The main IT systems (database, management application, email) are hosted by providers with data centres located in the European Union. CDN, DNS management, TLS termination and DDoS protection for the website verdevercelli.it are provided by Cloudflare; given the global nature of the service, some traffic metadata (IP addresses, HTTP headers, access logs) may pass through nodes located in non-EU countries, on the basis of the safeguards set out in section 6.

5. Retention period

6. Disclosure and transfer of data to third parties

Personal data may be disclosed to the following parties, solely for the purposes set out above:

The data are not disseminated and are not systematically transferred to non-EU countries. Any transfer needed for technical services to work (e.g. WhatsApp/Meta, Cloudflare) takes place on the basis of the EU-US Data Privacy Framework (for certified providers) and/or the Standard Contractual Clauses approved by the European Commission, together with the other appropriate safeguards provided for in Chapter V GDPR.

7. Your rights as a data subject

You may exercise the following rights at any time, under Articles 15–22 GDPR:

To exercise these rights, write to [email protected]. We will reply within 30 days of receiving the request.

Complaint to the supervisory authority

You also have the right to lodge a complaint with the Garante per la Protezione dei Dati Personali, the Italian data protection authority (Piazza Venezia 11, 00187 Rome — garanteprivacy.it), if you believe that the processing of your data infringes the applicable law.

8. Changes to this policy

This policy may be updated at any time. Previous versions are kept as evidence. Any substantial change will be communicated to data subjects through the available contact channels.

For any question about the processing of your personal data, write to [email protected].