Fattoria Castello di Monteriggioni based in Strada delle Torri Cimate n. 2, Monteriggioni (SI), VAT number 01445960527, as Data Controller, informs you pursuant to art. 13 Legislative Decree 30.6.2003 n. 196 (hereinafter, “Privacy Code”) and art. 13 EU Regulation no. 2016/679 (hereinafter, “GDPR”) that your data will be processed in the manner and for the following purposes:

1. OBJECT OF THE PROCESSING The Data Controller processes the personal identification data (for example, name, surname, company name, address, telephone number, e-mail address, bank and payment details – hereinafter “personal data” or even “data”) communicated by you on the occasion of the conclusion of contracts for the services provided by Fattoria Castello di Monteriggioni in the case of websites, provided by you as interested parties, at the time of filling in the contact form.

2. PURPOSE OF TREATMENT Your personal data are processed for the following Service Purposes: to conclude contracts for the services provided by Fattoria Castello di Monteriggioni; fulfill pre-contractual, contractual and tax obligations; fulfill the obligations established by law, by Italian and EU legislation or by an order of the Authority (such as for anti-money laundering); exercise the rights of the owner, for example the right to defense in court; prevent and manage possible disputes or take legal action in case of need; send communications, technical and regulatory updates, report agreements, conventions or commercial proposals.

3. PROCESSING METHOD AND DURATION The processing of your personal data is carried out by means of the operations indicated in art. 4 of the Privacy Code and art. 4 n. 2) GDPR and more precisely: collection, registration, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, cancellation and destruction of data. Your personal data are subjected to both paper and electronic and / or automated processing. The Data Controller will process personal data for the time necessary to fulfill the aforementioned purposes and in any case for no more than 10 years from the termination of the relationship for Service Purposes and for civil, accounting and tax purposes.

4. ACCESS TO DATA Your data may be made accessible for the purposes referred to in art. 2: to employees and collaborators of the Data Controller, in their capacity as persons in charge and / or internal managers of the processing and / or system administrators; to third-party companies or other subjects (by way of example, credit institutions, professional firms, consultants, insurance companies for the provision of insurance services, etc.) who carry out outsourced activities on behalf of the Data Controller, in their capacity as external managers of the treatment. For cloud services, the data being processed may be disclosed to third party suppliers based within the European Union and abroad in non-EU countries within and within the limits set out in Chapter V of the European Regulation no. 679 of 2016.

5. COMMUNICATION OF DATA Without the need for express consent (pursuant to Article 24 letter a), b), d) Privacy Code and art. 6 lett. b) and c) GDPR), the Data Controller may communicate your data for the purposes referred to in art. 2 to Supervisory Bodies, Judicial Authorities, to insurance companies for the provision of insurance services, as well as to those subjects to whom the communication is mandatory by law for the accomplishment of the aforementioned purposes. These subjects will process the data in their capacity as independent data controllers. Your data will not be disclosed.

6. DATA TRANSFER Personal data may be stored on servers located within the European Union. In any case, it is understood that the Data Controller, if necessary, will have the right to move the servers even outside the EU. In this case, the Data Controller ensures from now on that the transfer of data outside the EU will take place in accordance with the applicable legal provisions, subject to the stipulation of the standard contractual clauses provided for by the European Commission.

7. NATURE OF DATA PROVISION AND CONSEQUENCES OF THE REFUSAL TO ANSWER The provision of data for the purposes referred to in art. 2 is mandatory and essential in order to carry out the services governed by the contracts stipulated with Fattoria Castello di Monteriggioni (as well as for legal obligations). Without it, we will not be able to guarantee the Services contractually requested.

8. DATA OF THIRD PARTIES PROVIDED BY THE CUSTOMER The CUSTOMER guarantees, with reference to the data of third parties processed by him during the use of Software and / or infrastructures provided by Fattoria Castello di Monteriggioni, that he has previously provided third parties with the information in compliance to the European Regulation n. 679 of 2016 and Legislative Decree 196/2003 and to have acquired their consent to the processing and the right to transfer such data to other subjects. However, it is understood that the CUSTOMER, with respect to the data of third parties, is an independent data controller assuming all the obligations and responsibilities connected to it, relieving Fattoria Castello di Monteriggioni from any dispute, claim or other that may come from third parties in reference. to such hypotheses of treatment.

9. RIGHTS OF THE INTERESTED PARTY In your capacity as an interested party, according to current legislation you have the rights referred to in art. 7 of the Privacy Code and art. 15 GDPR and precisely you can ask for: confirmation of the existence or not of personal data concerning you and further details on the treatments carried out by Fattoria Castello di Monteriggioni; copy of your personal data; to update any data inaccuracy; to delete any data for which there is no legal basis for processing; to withdraw your consent; to oppose any treatment; to limit the way in which we process your personal data when investigating a complaint. Where applicable, it also has the rights referred to in Articles. 16-21 GDPR (Right of rectification, right to be forgotten, right to limitation of treatment, right to data portability, right of opposition), as well as the right of complaint to the Guarantor Authority.

10. METHOD OF EXERCISING RIGHTS You can exercise your rights at any time by sending: a registered letter with return receipt. at Fattoria Castello di Monteriggioni, Strada delle Torri Cimate n. 2, Monteriggioni (SI); an email to info@fattoriacastellodimonteriggioni.com

11. OWNER, MANAGER AND RESPONSIBLE The Data Controller is Fattoria Castello di Monteriggioni, Strada delle Torri Cimate n. 2, Monteriggioni (SI). The updated list of data processors and persons in charge of processing is kept at the registered office of the Fattoria Castello di Monteriggioni.

12. INFORMATION SECURITY All information collected is kept in secure facilities that limit access to authorized personnel only. Fattoria Castello di Monteriggioni complies with security measures in accordance with applicable laws and regulations and with all appropriate measures, to ensure and guarantee the confidentiality of users’ personal data and to minimize, as far as possible, the risks of unauthorized access. , removal, loss or damage of users’ personal data.

COOKIE POLICY GENERAL INFORMATION ON COOKIES When you access Fattoria Castello di Monteriggioni or use one of our services, our system or that of one of our partners may set or read cookies and / or other types of identifiers about the browser and / or device. you are using. A cookie is a small text file that is stored on the computer of those who view a website in order to record some information relating to the visit as well as to create a system to recognize the user even at subsequent times. Device identifiers, on the other hand, are generated by collecting and processing certain information such as the IP address and / or the user agent (browser version, type and version of the operating system) or other characteristics of the device, again in order to reconnect certain information. to a specific user. A website can set a cookie on the browser only if the preferences configured for the latter allow it. It is important to know that a browser can allow a particular website to access only and exclusively the cookies set by it and not those set by other websites: there is no risk to your privacy in this regard.

PRACTICES RELATING TO COOKIES AND OTHER SIMILAR TECHNOLOGIES Fattoria Castello di Monteriggioni may use cookies or other types of identifiers for a number of reasons, including: Keeping track of user preferences while using the site and / or services incorporated therein or connected to it. Process statistical analysis (analytics) about the use of the site and / or the services incorporated therein. Fattoria Castello di Monteriggioni does NOT directly use any profiling cookies: the only cookies generated and managed directly by Fattoria Castello di Monteriggioni are the so-called technical cookies (which are used only and exclusively to correctly offer the services offered to the public) and, in extremely limited, analytics cookies (which are used to count the number of readings on the various pages of the site and / or for other statistical purposes). However, we inform users that profiling cookies may be generated by third parties through our pages (Ref. “Cookies from other companies”).

COOKIES FROM OTHER COMPANIES Fattoria Castello di Monteriggioni integrates, within its pages, third-party services that may set up and use their own cookies and / or similar technologies. The use of these cookies and similar technologies by these companies is governed by the privacy policies of these companies and not by this information as Fattoria Castello di Monteriggioni srlt is totally unrelated to the management of these tools and to the processing of data deriving from them. Below is a (non-exhaustive) list of some of the partner companies that may use cookies while browsing the Fattoria Castello di Monteriggioni network: Google Analytics (information) Google Maps (information). In case of doubts or reports regarding the use of cookies, you can contact us on this page.

GOOGLE ANALYTICS COOKIES. This site uses the service offered by Google Analytics in order to have a complete and reliable service of statistics on the use of the site. In order to guarantee the privacy of users in the most rigorous way possible, we communicate that we have carried out the anonymization of the IPs (therefore Google Analytics will anonymize the IP address of the user / visitor as soon as this is technically possible in the passage more upstream of the network in which the data is collected). The Data Controller also informs that it has accepted the Amendment on data processing (Google Analytics Data Processing Amendment) made available by Google Analytics in compliance with Directive 95/46 / EC. In particular, by virtue of this amendment, Google guarantees that it will process the personal data recorded through the service only within the limits of the instructions given by the site operator and not to share them with other Google services unless this has been explicitly requested and authorized by the owner of the site itself. As a result of the above, the user is informed that the advertising and data sharing options with Google have not been activated and that Google Analytics has not been connected to any additional service: the processing, therefore, is carried out for mere statistical purposes. and therefore, on the basis of what is explicitly provided by the Privacy Guarantor, Analytics cookies have been equated to technical cookies and as such installed without the prior consent of the user.

DISABLING COOKIES You can configure your browser to accept or reject all cookies or particular types of cookies (such as third-party cookies) or you can choose to be warned whenever a cookie is set on your computer. It is important to know that refusing all cookies may prevent you from using the Fattoria Castello di Monteriggioni products and services that require you to access areas reserved for registered users using a username and password. All these services, in fact, require cookies in order to function properly and, consequently, any blocking of cookies would make it impossible to use. Below are the instructions relating to the most popular browsers for the purpose of making a personalized configuration regarding cookies: Microsoft Internet Explorer click on “Tools” at the top of the browser window; select “Internet Options”; click on the “Privacy” tab; to activate cookies, the privacy level must be set to “Medium” or below; by setting the privacy level above “Medium”, the use of cookies will be disabled. Mozilla Firefox click on “Tools” at the top of the browser window; select “Options”; select the “Privacy” icon; click on “Cookies”; select whether or not the items “Accept cookies from sites” and “Accept third-party cookies”; Google Chrome click the menu icon; select “Settings”; at the bottom of the page, select “Show advanced settings”; in the “Privacy” section, select “Content settings”; select whether or not the item “Block sites from setting any data”. Apple Safari click on the “Safari” label at the top of the browser window; select the “Preferences” option; click on “Privacy”; set your choice under “Cookies and website data”.

DELETE ALL COOKIES OF “Fattoria Castello di Monteriggioni” You can delete all cookies of Fattoria Castello di Monteriggioni using the cleaning tools of your browser.