Privacy Policy
Pursuant to Articles 13-14 of Regulation (EU) 2016/679 (GDPR) and Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 (Italian Data Protection Code)
Last updated: 9 July 2026
1. Data Controller
The Data Controller responsible for the personal data collected through the website davito.food is:
Tortorici Giacomo, sole proprietor of the individual business Vitokm0 di Tortorici Giacomo Registered address: Via Indipendenza 216/218 — 57021 Venturina Terme (LI), Italy VAT/Tax ID: 01965810490 Email: giacomotortorici13t@gmail.com
2. Categories of Data Collected
The website collects the following categories of personal data:
| Source | Data collected |
|---|---|
| Contact form | First name, last name, email address, phone number, message content |
| “Work with us” form (job applications) | First name, last name, email address, phone number, curriculum vitae (attached file), explicit consent to processing |
| Website browsing | Browsing data collected in aggregated/statistical form via Google Analytics 4 (see Cookie Policy) |
The curriculum vitae, being a document freely provided by the data subject, may also contain special categories of data (Article 9 GDPR) should the candidate voluntarily include information such as a photograph, health-related information, trade union membership, or other information not requested. The Data Controller does not request or solicit such data and invites candidates not to include it unless strictly relevant to the application.
No data relating to minors is deliberately collected; the website does not require age verification for general browsing, while submitting a job application presupposes that the applicant meets the minimum working age requirements set out under applicable Italian law.
3. Purposes of Processing and Legal Basis
| Purpose | Legal basis (Art. 6 GDPR) | Data involved |
|---|---|---|
| Responding to requests submitted via the contact form | Performance of pre-contractual measures at the data subject’s request / legitimate interest of the Data Controller in handling received requests (Art. 6(1)(b) and (f)) | Identification data, contact details, message |
| Managing spontaneous job applications (“Work with us”) | Pre-contractual measures at the data subject’s request (Art. 6(1)(b)); explicit consent collected when submitting the form (Art. 6(1)(a)) for retention purposes in view of future opportunities | Identification data, contact details, CV |
| Aggregated statistical analysis of website usage (Google Analytics 4) | Consent of the data subject (Art. 6(1)(a)), collected via the cookie banner prior to the activation of non-technical cookies | Browsing data, technical identifiers (see Cookie Policy) |
| Compliance with legal obligations (e.g., requests from competent authorities) | Legal obligation (Art. 6(1)(c)) | Data requested by the authority, where applicable |
Providing data through the forms is optional; however, failure to provide it makes it impossible to respond to the contact request or to process the application.
4. Methods of Processing
Data is processed using IT and telematic tools, following logic strictly related to the purposes indicated above and, in any case, in such a way as to ensure the security and confidentiality of the data.
Data collected through the contact form and the job application form is managed through the Contact Form 7 plugin, with submissions archived via the Flamingo plugin in the website’s database, in addition to automatic email delivery to the Data Controller’s mailbox.
5. Data Disclosure and Data Processors
Personal data collected is not disclosed to or shared with third parties for their own marketing purposes.
Data may be made accessible, for the purposes indicated above, to parties acting as data processors pursuant to Article 28 GDPR, including:
- The provider of the hosting service on which the website and the related database are hosted;
In addition, for statistical purposes, aggregated browsing data is processed by Google Ireland Limited, acting as data processor for the Google Analytics 4 service (see Section 6 and the Cookie Policy).
6. Transfer of Data Outside the EU
The Google Analytics 4 service is provided by Google Ireland Limited but may involve the transfer of data to servers located in the United States, as part of Google’s global infrastructure. Such transfer takes place on the basis of the Standard Contractual Clauses (SCCs) approved by the European Commission, as an adequate safeguard pursuant to Article 46 GDPR.
No other transfers of data outside the EU occur in relation to the services currently used on the website.
7. Data Retention Period
| Data | Retention period |
|---|---|
| Requests submitted via the contact form | For the time necessary to handle the request, and subsequently for a maximum of 12 months, for evidentiary purposes in the event of disputes, unless otherwise required by law |
| Spontaneous job applications (“Work with us”) | 24 months from receipt, in line with the guidance issued by the Italian Data Protection Authority (Garante) on personnel selection, unless the candidate withdraws consent earlier |
| Browsing data (Google Analytics 4) | According to the retention settings configured in the GA4 property (by default, and unless otherwise configured, event-level data is retained for a maximum period of 14 months) |
Once the above periods have elapsed, data is deleted or anonymized, unless retention obligations are provided for by law.
8. Data Subject Rights (Articles 15-22 GDPR)
As a data subject, you have the right to:
- Access (Art. 15) — obtain confirmation of the existence of processing and access your personal data;
- Rectification (Art. 16) — obtain the correction of inaccurate data or the completion of incomplete data;
- Erasure / “right to be forgotten” (Art. 17) — obtain the erasure of data, in the cases provided for by law;
- Restriction of processing (Art. 18) — obtain restriction of processing in specific circumstances;
- Data portability (Art. 20) — receive the data provided in a structured, commonly used, machine-readable format, and transmit it to another controller;
- Object (Art. 21) — object at any time to the processing of your data for reasons connected to your particular situation, where processing is based on legitimate interest;
- Not be subject to automated decision-making, including profiling, which produces legal effects or similarly significantly affects you (Art. 22) — not applicable, as the Data Controller does not carry out any automated decision-making or profiling activity;
- Withdraw consent at any time, without affecting the lawfulness of processing based on consent given before its withdrawal;
- Lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali — www.garanteprivacy.it), should you believe that the processing violates the GDPR.
9. How to Exercise Your Rights
To exercise the rights listed above, you may send a written request to:
- Email: giacomotortorici13t@gmail.com
- Postal address: Via Indipendenza 216/218, 57021 Venturina Terme (LI), Italy
The Data Controller will respond within 30 days of receiving the request, subject to extension in the cases provided for under Article 12(3) GDPR.
10. Data Protection Officer (DPO)
The Data Controller has not appointed a Data Protection Officer (DPO), as the conditions for mandatory appointment under Article 37 GDPR do not apply to the activity carried out.
11. Minors
The website is freely accessible and does not provide for age verification for browsing. Submitting an application through the “Work with us” form presupposes that the applicant meets the minimum working age requirements set out under applicable Italian law. The Data Controller invites parents/guardians to supervise the use of the website by minors who lack the capacity to validly consent to the processing of their own data.
12. Automated Decision-Making and Profiling
The Data Controller does not carry out any processing based solely on automated decision-making, nor any profiling of users for marketing or advertising purposes.
13. Security Measures
The Data Controller adopts appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Website connection secured via the HTTPS/SSL protocol;
- Regular updates of the WordPress CMS, plugins, and software components used;
- Access to the website’s administrative area protected by confidential credentials and restricted to authorized personnel;
- Periodic data backups;
- Handling of data collected through forms in accordance with the principles of data minimization and storage limitation.
14. Changes to This Policy
The Data Controller reserves the right to modify or update this Privacy Policy at any time, including as a result of regulatory changes or changes to the services used on the website. Please check this page periodically. The date of the last update is indicated at the top of this document.

