NOTICE UPDATED AS OF NOVEMBER 2025
Privacy Notice on the Protection of Personal Datas
PURSUANT TO ARTS. 13 AND 14 OF EU REG. 2016/679 AND SUBSEQUENT AMENDMENTS
1. Data Controller
Data controller: NOSCHESE S.R.L. SOCIETÀ AGRICOLA, with registered office in Battipaglia (SA) at Via G. Noschese no. 11, tax code and VAT number 05019440659. Contacts: info@noschesesrl.com, PEC noschesesrl@legalmail.it, Telephone: +39 (0828) 1733444.
2. Purposes and Legal Bases of Processing
We process website users’ personal data to:
- provide online services and respond to contact/support requests (performance of pre-contractual measures/contract);
- comply with legal obligations;
- ensure website security, prevent abuse, and defend legal claims (legitimate interest, balanced);
- send promotional communications/newsletters, only with consent;
- manage cookies and, where applicable, profiling based on consent.
3. Categories of Personal Data Processed
Browsing/technical logs: IP address, user agent, date/time, requested URL, referrer, device information, security logs.
“Contact” form data: name, email, telephone (optional), message.
Cookies/similar technologies: strictly necessary technical cookies; analytics (GA4) subject to prior consent, with IP masking and Consent Mode; no advertising profiling without consent.
4. Processing Methods and Security Measures
We apply appropriate technical and organizational measures to ensure the confidentiality, integrity, and availability of data and to prevent unauthorized or unlawful processing.
5. Nature of the Provision of Data
Providing data for contractual/response purposes is necessary to handle requests; for marketing purposes and for non-technical cookies it is optional and subject to consent, which may be withdrawn at any time with the same ease with which it was given.
6. Data Retention
We retain data for the time strictly necessary to pursue the purposes indicated, applying transparent criteria to determine the periods; once such period has elapsed, data are erased, anonymized, or archived in accordance with the law.
7. Data Recipients
Data may be disclosed to parties acting as processors (IT, hosting, email, support providers), to authorized internal personnel, as well as to entities/authorities where required by legal obligations or lawful orders. Unauthorized access is prohibited and contractual arrangements compliant with Art. 28 GDPR are in place.
8. Data Subjects' Rights
Data subjects may exercise the rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent; they also have the right not to be subject to decisions based solely on automated processing, including profiling, within the limits of the law. We respond without undue delay and within one month.
9. Cookies and Similar Technologies
We use technical cookies necessary for the operation of the site and, with your consent, functionality, analytics, and profiling cookies. You can manage or withdraw your preferences at any time via the dedicated banner/preferences center. Further information is available in the Cookie Policy.
10. Complaints and Remedies
Data subjects may lodge a complaint with the Italian Data Protection Authority or contact the supervisory authority competent based on their residence or the place of the alleged violation.
Italian Data Protection Authority (Garante per la protezione dei dati personali) – Piazza di Monte Citorio 121, 00186 Roma – Email: garante@gpdp.it – PEC: protocollo@pec.gpdp.it.
11. Updates to this Notice
We reserve the right to update this notice to reflect regulatory or technical changes. The current version indicates at the bottom the date of the last update.
12. How to Exercise Your Rights
To exercise your rights, contact: info@noschesesrl.com o PEC noschesesrl@legalmail.it. We may request additional information to verify your identity. Requests are free of charge unless they are manifestly unfounded or excessive.
Privacy Notice on the Protection of Customers' Personal Datas
UNDER ARTICLES 13 AND 14 OF EU REG. 2016/679 AND PURSUANT TO LEGISLATIVE DECREE NO. 196/2003 AS AMENDED
1. Data Controller
Data controller: NOSCHESE S.R.L. SOCIETÀ AGRICOLA, with registered office in Battipaglia (SA) at Via G. Noschese no. 11, tax code and VAT number 05019440659. Contacts: info@noschesesrl.com, PEC noschesesrl@legalmail.it, Telephone: +39 (0828) 1733444.
2. Purposes and Legal Bases of Processing
We process customers’ data (natural persons or contacts of customer entities) for the following purposes:
- Handling of pre-contractual requests and conclusion/performance of the contract with the Client or with the organization to which the contact person belongs (B2B): legal basis Art. 6(1)(b) GDPR.
- Administrative, tax and accounting obligations connected with the provision of goods/services: legal basis Art. 6(1)(c) GDPR.
- Payment management and related requirements, including proportionate anti-fraud systems: legal bases Art. 6(1)(b)(c) GDPR; possible legitimate interest under Art. 6(1)(f) for reasonable security measures.
- After-sales support, customer care and complaints handling: legal basis Art. 6(1)(b) GDPR.
- Security of systems/premises and protection of rights (prevention of abuse, litigation management, defense in court): Controller’s legitimate interest under Art. 6(1)(f) GDPR.
- Keeping the record of processing activities and accountability obligations: organizational obligations under the GDPR.
- Marketing and newsletters to data subjects who are not yet Clients: freely given, specific, informed and revocable consent at any time, Art. 6(1)(a) and 7 GDPR.
- Email marketing to Clients for products and services of the same Controller that are similar to those already purchased (so‑called soft spam), in compliance with the safeguards laid down by law and with the right to object immediately and free of charge: legal basis other than consent where the conditions and safeguards set by the Authority are met (direct sends for similar goods/services of the same controller and contact details provided in the context of the sale), with an opt‑out always available and honored.
- Profiling only if provided: specific and informed consent is required for marketing purposes based on analysis of preferences/behaviors; you may always object and/or withdraw consent.
3. Data Subjects and Categories of Personal Data
Data subjects: natural-person Customers; contact persons/employees of legal-entity Customers; prospective Customers at the pre-contractual stage.
Data processed: identification and contact data; contractual and invoicing data; payment data; support history and communications; preferences expressed for commercial purposes; logs relating to responses to rights requests; for optional marketing and/or any profiling, data relating to interactions with communications/services; special categories of data are not requested unless required by law or specifically requested with consent, where necessary.
4. Sources of Personal Data
Data provided directly by the data subject or by their employer/organization (in B2B contexts) at the pre-contractual or contractual stage.
Data generated during the performance of the relationship (e.g., support, payments, communications).
Where data are not collected from the data subject, upon request information on their origin is made available within the limits provided.
5. Nature of the Provision of Data
Providing the data necessary for managing the relationship and legal obligations is a contractual requirement and/or a legal obligation; failure to provide such data may prevent the conclusion or execution of the contract and the proper handling of requests.
Providing data for marketing and profiling purposes is optional; lack of consent does not affect the execution of the contract.
6. Retention Periods and Criteria
Data are retained for the time necessary to pursue the purposes indicated above, in compliance with the storage limitation principle; for contractual and accounting data, for the applicable statutory periods; for support, for the time needed to handle tickets and warranties; for legal defense, until the expiry of the relevant limitation and forfeiture periods.
For marketing purposes based on consent, data are retained until withdrawal and/or objection, without prejudice to shorter times indicated at the time of collection; for so-called soft spam, data are processed as long as the relevance to similar offers remains and until the exercise of the opt-out.
The criteria and, where possible, indicative periods are periodically reviewed and documented in the record of processing activities.
7. Data Recipients and Categories of Recipients
Third parties acting as processors (IT service providers, cloud, customer support, consultants, outsourcers), contractually bound under Art. 28 GDPR with documented instructions, security measures, and confidentiality obligations.
Independent third-party controllers (e.g., professionals for tax/legal obligations, payment institutions, authorities and administrations where provided) within the limits of the stated purposes.
The updated list of processors and main recipients is available upon request via the contact channels indicated.
8. Data Subjects' Rights and How to Exercise Them
The data subject may request: access; rectification; erasure; restriction of processing; portability; objection to processing, including objection to direct marketing and any related profiling; withdrawal of consent at any time.
Timing and method of response: without undue delay and in any case within one month of the request, extendable by two months in case of complexity or numerous requests; information is provided free of charge, except for manifestly unfounded or excessive requests.
Right to obtain a copy of personal data and, for requests made by electronic means, a response in a commonly used electronic format unless otherwise indicated.
In case of no response, the data subject is informed of the reasons and of the possibility to lodge a complaint and seek judicial remedy.
9. Complaints and Remedies
Data subjects may lodge a complaint with the Italian Data Protection Authority or contact the supervisory authority competent based on their residence or the place of the alleged violation.
Italian Data Protection Authority (Garante per la protezione dei dati personali) – Piazza di Monte Citorio 121, 00186 Roma – Email: garante@gpdp.it – PEC: protocollo@pec.gpdp.it.
10. Updates to this Notice
We reserve the right to update this notice to reflect regulatory or technical changes. The current version indicates at the bottom the date of the last update.
11. How to Exercise Your Rights
To exercise your rights, contact: info@noschesesrl.com o PEC noschesesrl@legalmail.it. We may request additional information to verify your identity. Requests are free of charge unless they are manifestly unfounded or excessive.
Privacy Notice on the Protection of Suppliers' Personal Datas
UNDER ARTICLES 13 AND 14 OF EU REG. 2016/679 AND PURSUANT TO LEGISLATIVE DECREE NO. 196/2003 AS AMENDED
1. Data Controller
Data controller: NOSCHESE S.R.L. SOCIETÀ AGRICOLA, with registered office in Battipaglia (SA) at Via G. Noschese no. 11, tax code and VAT number 05019440659. Contacts: info@noschesesrl.com, PEC noschesesrl@legalmail.it, Telephone: +39 (0828) 1733444.
2. Purposes and Legal Bases of Processing
We process suppliers’ data (natural persons or contacts of supplier entities) for the following purposes:
- pre-contractual and contractual fulfilments;
- administrative, tax, and accounting obligations;
- management of business relationships and protection of contractual rights (including disputes);
- compliance checks and regulatory conformity relating to the supply relationship.
Legal basis: performance of pre-contractual measures/contract; compliance with legal obligations; legitimate interest in the efficient and secure management of the relationship.
3. Data Subjects and Categories of Personal Data
Identification and contact data (e.g., first name, last name, e-mail/PEC, phone).
Tax, banking, and invoicing data.
Data relating to contract performance and compliance (e.g., DURC, certifications).
4. Nature of Data Provision
Providing the data necessary for the above purposes is optional but essential to establish and execute the supply relationship; without it, it will not be possible to conclude or to continue the relationship.
5. Sources of Personal Data
Data provided directly by the data subject or by their employer/affiliated organization (in B2B contexts) during pre-contractual or contractual stages.
Data generated in the course of performing the relationship (e.g., support, payments, communications).
Where data are not collected from the data subject, upon request information on their origin is made available within applicable limits.
6. Processing Methods and Security
Processing is carried out using manual and electronic tools, applying appropriate technical and organizational measures to ensure the confidentiality, integrity, and availability of the data.
7. Data Recipients and Categories of Recipients
Where necessary, data may be disclosed to: credit institutions; insurance companies; consultants and professionals (e.g., legal, tax, auditors); IT providers and maintenance providers (including system administrators); couriers/shippers; debt collection and commercial information companies; public bodies and authorities in cases provided by law; subsidiaries/affiliates, if involved for the same purposes.
The Controller informs that personal data are not transferred outside the European Union/European Economic Area. In any case, no disclosure to non-EU third countries nor any dissemination is envisaged.
8. Retention Periods
Data are retained for the duration of the contractual relationship and, thereafter, for statutory limitation periods (e.g., civil and tax obligations) and for the time necessary to protect rights related to the relationship in judicial or out-of-court proceedings.
9. Data Subjects' Rights
Data subjects may exercise the rights of access, rectification, erasure, restriction, objection, and portability, as well as the right not to be subject to decisions based solely on automated processing, within the limits and under the conditions of Articles 12–23 GDPR, by contacting the Controller at the indicated addresses.
10. Complaints and Remedies
Data subjects have the right to lodge a complaint with the competent supervisory authority and to seek judicial remedy if they believe their personal data protection rights have been violated.
Italian Data Protection Authority (Garante per la protezione dei dati personali) – Piazza di Monte Citorio 121, 00186 Roma – Email: garante@gpdp.it – PEC: protocollo@pec.gpdp.it.
11. Updates to this Notice
We reserve the right to update this notice to reflect regulatory or technical changes. The current version indicates at the bottom the date of the last update.
12. How to Exercise Your Rights
To exercise your rights, contact: info@noschesesrl.com o PEC noschesesrl@legalmail.it. We may request additional information to verify your identity. Requests are free of charge unless they are manifestly unfounded or excessive.