Privacy Policy
Last updated: August 21, 2026
This privacy policy describes how personal data is processed when users browse the website Perfect Gelato (https://www.perfectgelato.com), in accordance with Regulation (EU) 2016/679 (GDPR). The website does not require user registration, does not manage user accounts, and does not send marketing newsletters or perform profiling.
1. Data Controller
- Data Controller: Due Elle Finance Srl - Italy
- Contact Email: [email protected]
2. Types of Data Processed and Purposes
Browsing Data and Technical Logs
The computer systems and software operating this website automatically acquire certain technical data whose transmission is implicit in Internet protocols (e.g. IP address, browser type, timestamp of access, pages visited).
- Purpose: Ensuring network security, preventing cyberattacks (DDoS), and ensuring proper content delivery.
- Legal Basis: Legitimate interest of the Controller in service security and continuity (Art. 6(1)(f) GDPR).
Data Voluntarily Provided by the User
The voluntary sending of emails to the address provided on the website entails the acquisition of the sender’s address and any personal details included in the message.
- Purpose: Responding to inquiries or technical support requests.
- Legal Basis: Performance of pre-contractual or contractual measures requested by the data subject (Art. 6(1)(b) GDPR).
3. Data Recipients and Third-Party Services
Personal data is never sold, transferred, or disclosed to third parties for marketing purposes. Data may be processed by technical service providers appointed as Data Processors:
- Hosting & CDN: Cloudflare Inc. (content delivery, cybersecurity, and traffic routing). International data transfers to non-EU servers are governed by Standard Contractual Clauses (SCC) and the EU-U.S. Data Privacy Framework.
4. Data Retention Period
- System and Security Logs: Retained strictly for security management and automatically purged according to network infrastructure standards (typically within days or weeks).
- Received Emails: Retained for the time necessary to fulfill the request, then deleted unless legal retention obligations apply.
5. Rights of the Data Subject
Under Articles 15–22 of the GDPR, users have the right to:
- Request access, rectification, erasure, or restriction of processing of their personal data.
- Object to processing on legitimate grounds at any time.
- Lodge a complaint with a supervisory authority (e.g., Garante Privacy – www.garanteprivacy.it).