Privacy Statement (EU)

Notice on the Processing of Personal Data collected through this website
Last revised: 23/01/2026

1. Introduction and regulatory references
This notice describes the processing of personal data collected through this website, including data acquired by means of cookies, tracking technologies and - where present - contact forms, financial transactions and any other features that may be active on the site.
This notice is addressed to anyone who accesses or uses this website, describing how the user’s personal data is collected, used and protected, as well as the rights granted by law.
These provisions do not concern other websites, pages or online services accessible through external links that may be present on the site, in respect of which you are invited to consult the relevant privacy notices.
This notice is provided in compliance with the principal national and international regulations on the protection of personal data, including:

2. Who manages your data and how can you contact us?
Your personal data is processed by:
De Carlo S.r.l.
Via XXIV Maggio 54/B, Bitritto (BA) – Italy
info@oliodecarlo.com
VAT ID: 05376450721

For any information concerning the processing of personal data or to exercise the rights granted by law, data subjects may contact the Data Controller.

3. On what legal bases do we process your data?
The processing of personal data collected through this site (including data collected by means of cookies, similar technologies, contact forms, financial transactions and any other features that may be active on the site) is based on one or more of the following legal bases:

  1. Performance of pre-contractual or contractual measures: where processing is necessary to respond to user requests, provide requested services and, where the site so provides, manage orders, accounts or contractual relationships.
  2. Compliance with legal obligations: where processing is necessary to comply with tax, accounting, administrative or security obligations or with requests from the authorities.

The Data Controller may also process the necessary data on the basis of its own legitimate interest, pursuing interests consisting in the security of the site, the prevention of abuse and fraud and the protection of its rights in legal proceedings. The user may in any case object to the processing in accordance with the applicable legislation, in the cases provided for by Article 21 GDPR.

For non-essential cookies and tracking tools - such as those for non-anonymised analytics, profiling or marketing - the processing is based on the user’s consent in the jurisdictions where such consent is required by the applicable legislation. The related methods of giving, managing and withdrawing it are described in the Cookie Policy.

Additional legal bases for Brazil (LGPD):
Where processing falls within the scope of the LGPD, further legal bases provided for by Article 7 of the LGPD may also apply, solely where the relevant conditions are met and in relation to the activities actually carried out by the Data Controller, including:

Failure to accept or the withdrawal of consent may limit certain features or services of the site.

The provision of data supplied directly by the user is generally optional, except for any data indicated as mandatory in the individual forms or where it is required by a legal or contractual obligation or is necessary to perform a contract or pre-contractual measures requested by the user; in such cases, failure to provide it may make it impossible to follow up on the request or to deliver the service. Technical navigation data is in any case collected automatically and is necessary for the functioning of the site.

4. What data do we collect when you visit the site?
While browsing this site, the following data may be collected, including by means of cookies and similar technologies such as pixel tags, web beacons, local storage and equivalent technologies, namely:

5. How do we process your data, how do we protect it and how long do we keep it?
The personal data collected through this site is processed mainly by electronic and digital means in accordance with the principles of lawfulness, fairness, data minimisation, integrity and confidentiality.

Appropriate technical and organisational measures are adopted to prevent unauthorised access, loss, alteration or unauthorised disclosure of data, including:

Data is retained according to the following timeframes:

6. Who can receive your data?
The following may access the personal data collected through this site, within the limits of their respective responsibilities and purposes:

The updated list of external recipients can be made available on request by writing to the Data Controller’s contact details.

7. Where can your data be transferred?
The personal data collected through this site is processed, as a rule, in the country where the Data Controller is established and at the service providers it uses. Where data is transferred or made accessible outside the relevant territory under the applicable legislation, the transfer takes place by means of one of the mechanisms it permits, including adequacy decisions, appropriate or suitable safeguards and, where applicable, derogations or other conditions provided for by the applicable legislation. For transfers subject to the GDPR, the relevant territory is the European Union / European Economic Area and, in particular, the EU-U.S. Data Privacy Framework, limited to certified organisations, and the Standard Contractual Clauses adopted by the European Commission are relevant. Information on the applicable mechanism and, where provided for, a copy of the relevant safeguards, possibly redacted in the confidential parts, may be requested at the Data Controller’s contact details.

For transfers subject to the UK GDPR, lawfulness is based on the United Kingdom’s adequacy decisions (for the United States, the UK Extension to the EU-US Data Privacy Framework, the so-called “UK-US Data Bridge”, limited to certified providers) or on appropriate safeguards such as the International Data Transfer Agreement (IDTA) or the UK Addendum to the Standard Contractual Clauses, subject to a transfer risk assessment based on the “data protection test” criterion (protection not materially lower than that of the United Kingdom).

8. What are your rights regarding the data collected?
The user, under the applicable legislation, has the right to:

In Italy, the rights concerning the personal data of deceased persons may be exercised, within the limits of Article 2-terdecies of the Privacy Code, by anyone who has a personal interest, acts to protect the data subject as an agent or invokes family reasons worthy of protection.

To exercise these rights, it is sufficient to send a request to the Data Controller’s contact details. The Data Controller will respond without undue delay and within the time limits provided for by the applicable legislation. For requests subject to the GDPR or the UK GDPR, a response is provided within the ordinary period of one month, calculated in accordance with the applicable legislation; that period may be extended by a further two months, taking into account the complexity and number of the requests, and the data subject is informed of the extension and the related reasons within the ordinary period.

In the United Kingdom, the time limit for responding may be paused where the Data Controller reasonably requests the information needed to confirm the user’s identity or to clarify the subject of the request; the Data Controller carries out reasonable and proportionate searches in order to comply with access requests.

9. How is minors’ data processed?
The protection of minors is a fundamental priority.

This site is not directed at minors and does not intentionally collect their data through its forms. Where, in the context of a request or query, the user provides personal data relating to third parties - including any minors - they must ensure that they are authorised to do so; such data will be processed within the limits and for the purposes of the request, in compliance with the applicable legislation. For requests for rectification, restriction or erasure, you may write to the Data Controller’s contact details.

10. How can you make reports or complaints to the authorities?
If you believe that the processing of your personal data through this site does not comply with the applicable legislation, you may lodge a complaint free of charge, pursuant to Article 77 of the GDPR, with the competent authorities indicated below, in accordance with the applicable legislation:

For users in the United Kingdom, it is possible to make a data protection complaint to the Data Controller, who will acknowledge receipt within 30 days and take appropriate steps to respond to the complaint without undue delay according to a documented procedure, informing the data subject of the progress and outcome. This is without prejudice to the right to approach the competent UK supervisory authority.

11. How do we inform you of changes to this notice?
This notice is subject to periodic revision to reflect regulatory changes or modifications to the services offered through the site. Any significant change will be communicated through this page.
Last revised: 23/01/2026

Warning: some page functionalities could not work due to your privacy choices: