Privacy Policy & Legal Notice

Last updated: 23 June 2026

This Privacy Policy describes how the personal data of the users of this website is processed, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Italian law, for those who connect to the corporate website of Oria 1.618 Società Agricola Semplice at www.oriatoscana.com.

Please read this Policy carefully before submitting any personal data and/or completing any electronic form on the website.

1. Data controller

The controller of your personal data is:

  • Oria 1.618 Società Agricola Semplice
  • Località Bivio dell'Asso snc, Montalcino (SI), Italy
  • VAT no. (Partita IVA): 01537790527
  • Email: info@oriatoscana.com

2. Purpose of processing

The personal data managed through this site —provided by users via online forms, social networks, or acquired automatically during browsing— is processed for the following purposes:

  • To improve and personalise the website experience.
  • To enable access to specific sections of the site and to provide and manage the various services offered.
  • To allow the publication of user content on the site or on platforms managed by third parties with whom Oria has reached agreements (for example, social networks such as Facebook, Instagram, etc.).
  • With prior consent, to carry out marketing activities, such as sending promotional material and information relating to Oria or to third parties related to your interests, by email, MMS, or text message.
  • To respond to user requests regarding Oria's products and services.

For specific operations (events, campaigns, contests, etc.), additional information notices may be provided and published on the site.

3. Methods of processing

Personal data is processed using automated tools (such as HubSpot and Stripe) and/or manually, for the time strictly necessary to achieve the purposes for which it was collected and in all cases in compliance with current regulations. Oria has adopted the security measures required by law to ensure the integrity and confidentiality of the data.

4. Type and source of the data processed

4.1 Browsing data. In principle, it is possible to browse the site without providing personal data. The computer systems and software procedures of the site acquire, during their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols (for example, IP addresses, domain names, etc.). This information is mainly used to compile statistics, verify the correct functioning of the site, and improve navigation, and is not retained after processing, except as necessary to investigate any computer crimes against the site.

4.2 Data provided voluntarily. When the user sends personal data to access certain services (newsletters, subscriptions) or to make requests by email or WhatsApp, Oria acquires their address and other personal data, which will be processed exclusively to respond to the request or provide the service. Users must complete the forms with true, accurate, complete, and up-to-date data, and are liable for any damage arising from defective completion. Data will only be communicated to third parties where necessary to fulfil the user's requests.

5. Legal basis

The processing of your data is based on:

  • The explicit consent of the data subject (Art. 6.1.a GDPR).
  • The performance of a contract or pre-contractual measures (Art. 6.1.b GDPR).
  • The legitimate interest in providing and improving the service (Art. 6.1.f GDPR).

6. Recipients and data processors

Your data may be processed by duly authorised Oria employees and collaborators, and shared with the following service providers acting as data processors:

  • HubSpot, Inc. — CRM management and contact forms.
  • Stripe, Inc. — payment processing and identity verification (KYC).
  • Meta Platforms, Inc. (Facebook / Instagram) — advertising measurement and remarketing via the tracking pixel.
  • Google LLC — web traffic analysis and measurement.
  • Twilio Inc. — WhatsApp communications.
  • Anthropic PBC — AI processing for user assistance.

All providers are subject to data processing agreements compliant with the GDPR. Data is not subject to general dissemination.

7. International transfers

Some of our providers (HubSpot, Stripe, Meta, Google, Twilio, Anthropic) are established in the United States. Such transfers are carried out under adequacy mechanisms compliant with the GDPR (adequacy decisions and/or standard contractual clauses).

8. Data retention

We retain your data for as long as necessary to fulfil the purposes of processing or until you request its deletion, and in any case for the applicable legal periods (a minimum of 5 years for contractual documentation).

9. Your rights

Under the GDPR (EU) 2016/679, you have the right to:

  • Access: to obtain confirmation as to whether your data is being processed and to access it.
  • Rectification: to correct or complete inaccurate data.
  • Erasure: to request the deletion of your data.
  • Portability: to receive your data in a structured format.
  • Objection: to object to processing for direct marketing, commercial communications, and market research.
  • Restriction: to request the restriction of processing.

To exercise these rights, send a communication to info@oriatoscana.com, accompanied by a copy of an identity document, or use the unsubscribe link included in our commercial communications. You may also lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali.

10. Cookies and tracking technologies

This site uses essential technical cookies and, subject to consent, third-party cookies and technologies for measurement and advertising, in particular the Meta (Facebook/Instagram) pixel and HubSpot tracking. On your first visit, a banner allows you to accept or limit use to essential cookies; these third-party trackers are not loaded until you give your consent. You may change your choice at any time by clearing your browser data.

11. Legal notice and intellectual property

The website www.oriatoscana.com is owned by Oria 1.618 Società Agricola Semplice. The intellectual and industrial property rights of the site, its source code, design, navigation structure, and the elements it contains belong to Oria, which holds the exclusive rights to exploit them (reproduction, distribution, public communication, and transformation). The viewing, printing, and partial downloading of the contents is authorised solely for personal and private use; their use for commercial purposes, as well as their distribution, public communication, or transformation without Oria's express consent, is expressly prohibited.

Links. The site may provide links to pages managed by third parties over which Oria exercises no control; their use is the sole responsibility of the user.

Exclusion of warranties and liability. Oria endeavours to provide accurate and up-to-date information, but does not guarantee the absence of errors or the uninterrupted availability of the site. Access to and use of the information are the sole responsibility of the user. Oria is not liable for damages arising from force majeure, connection failures, or the user's equipment.

Suspension of service. Oria reserves the right to suspend the display of the site, in whole or in part, for reasons of efficiency and security.

12. Governing law and jurisdiction

This Policy and the use of the site are governed by Italian law and by the GDPR (EU) 2016/679. For any dispute arising from the interpretation or application of these clauses, or relating to the existence, access, use, or content of the site, the parties submit, expressly waiving any other jurisdiction, to the Courts and Tribunals of the city of Siena (Italy).

13. Amendments

We reserve the right to update this policy at any time. The current version will always be available on this page; we will notify you of significant changes by email.

Contact for privacy matters:
Oria 1.618 Società Agricola Semplice
Località Bivio dell'Asso snc, Montalcino (SI), Italy · VAT 01537790527
info@oriatoscana.com