Privacy Policy
Privacy policy
pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter the “GDPR”)
Last updated September 15, 2026
With this privacy policy (hereinafter the “Privacy Policy”) relating to the website vegans.it (hereinafter the “Website”), Vegan Solutions provides users with information on the data controller, the personal data collected through the Website, the purposes and legal bases for processing such data, the methods by which processing is carried out, any third parties involved, any transfers of data abroad, retention periods, the security measures adopted and how users may exercise their rights under the GDPR, including the right to lodge a complaint with the supervisory authority.
1. Data controller
The data controller is Vegan Solutions S.r.l., with registered office at Contrà delle Morette, 17 - Vicenza, VAT no./Tax ID 03192340242.
The Controller has appointed a Data Protection Officer (DPO), who can be contacted at the e-mail address dataprotection@vegans.it.
2. Types of personal data collected and processed
2.1 Browsing data
The technology platform through which the Website is made available automatically records certain browsing data - the transmission of which is implicit in the use of Internet communication protocols - such as the name of the Internet access provider, the referring website, the pages visited, the date and duration of each visit, and the URI/URL addresses of the resources requested. This information enables access to the Website and the use of certain services, and may be used in anonymous, aggregated form for statistical purposes and to verify that the Website is functioning correctly.
Vegan Solutions does not collect this data in order to associate it with other information for the purpose of identifying users; however, by its very nature, such data could allow identification following processing and association with other information. Browsing data may be used to establish liability in the event of computer crimes committed against or through the Website.
Legal basis: the Controller's legitimate interest in ensuring the operation, security and proper delivery of the Website (Art. 6(1)(f) GDPR). Retention: browsing data (logs) are retained for 30 days, without prejudice to any further retention for the purpose of investigating unlawful acts within the limits of the law.
Cookies and tracking tools are governed by the separate Cookie Policy
2.2 Personal data provided voluntarily by the user
Vegan Solutions collects and processes the personal data that users provide voluntarily when interacting with the features and services of the Website, for example by filling in the contact form to receive information on Vegan Solutions' services and activities, subscribing to the community or newsletter to receive communications on events, initiatives and news, submitting unsolicited job applications, or sending requests and communications to the Controller.
The data requested is limited to what is necessary for the specific purpose. With regard to unsolicited applications, users are asked not to include in their CV or attachments any special categories of data (Art. 9 GDPR) that are not relevant to the professional assessment.
3. Purposes of processing and legal bases
Purposes, legal bases and retention periods
| # Purpose | Legal basis | Retention |
| A Enabling browsing, operation and security of the Website | Legitimate interest - Art. 6.1.f | Logs for 30 days |
| B Responding to requests submitted through the contact form | Pre-contractual measures/response to the data subject's request - Art. 6.1.b (or legitimate interest - Art. 6.1.f) | Time required to handle the request and in any case no longer than 24 months |
| C Handling unsolicited job applications | Pre-contractual measures taken at the data subject's request - Art. 6.1.b | Maximum 24 months, then deletion, unless consent is given to further retention |
| D Subscription to the community/newsletter and sending of communications on events, initiatives and news, as well as other commercial communications from the Controller (by e-mail) | Data subject's consent - Art. 6.1.a (see also section 4 on “soft opt-in”) | Until consent is withdrawn or, in the event of inactivity, for 24 months |
| E Compliance with legal obligations and establishment/exercise/defense of legal claims | Legal obligation - Art. 6.1.c / legitimate interest - Art. 6.1.f | Statutory/limitation periods |
4. Marketing: clarifications on consent
Providing data for marketing purposes (point D) is optional: refusing consent in no way affects browsing of the Website or the handling of requests submitted through the contact form. Merely reading this Policy does not constitute consent to marketing, which is collected separately and specifically.
Consent may be freely withdrawn at any time, as easily as it was given, without affecting the lawfulness of processing carried out before withdrawal; in addition, every commercial communication contains an immediate unsubscribe (opt-out) mechanism.
Where the user is already a customer, the Controller may send commercial communications relating to its own products or services similar to those already purchased, pursuant to Art. 130, paragraph 4, of Legislative Decree 196/2003 (Italian Privacy Code), without prejudice to the data subject's right to object to such use at any time, both when the data is collected and on the occasion of each subsequent communication.
5. Nature of data provision
For purposes A and E, processing does not require the user's consent. For purpose B, the provision of data marked as mandatory in the form is necessary in order to respond to the request; failure to provide it will make it impossible to handle the request. For purpose D, the provision of data is optional and subject to consent, as indicated in section 4.
6. Categories of recipients
Personal data may be processed, for the purposes indicated above, by authorized internal personnel and by external parties appointed as data processors pursuant to Art. 28 GDPR, including by way of example: hosting and IT maintenance service providers, providers of the newsletter delivery and communications management platform, providers of statistical analysis and Website security tools, as well as any consultants supporting the Controller. Data may also be disclosed to authorities and supervisory bodies in compliance with legal obligations. Data is not disseminated and is not disclosed to third parties for their own independent marketing purposes.
7. Transfer of data to non-EU countries
Some of the third-party providers and services used to operate the Website and for the purposes described above (for example, statistical analysis, security, newsletter delivery or social network interaction tools) may involve the transfer of personal data to countries outside the European Union and the European Economic Area, in particular to the United States of America. Such transfers take place only where appropriate safeguards are in place pursuant to Art. 44 et seq. GDPR, such as an adequacy decision of the European Commission (including the EU-U.S. Data Privacy Framework, for U.S. providers that adhere to it) or the Standard Contractual Clauses (Art. 46 GDPR). Users may request further information on the safeguards adopted by contacting the Controller at the details indicated in section 1.
8. Processing methods and security measures
Processing is carried out using primarily electronic and, where necessary, paper-based means, in accordance with logic strictly related to the purposes indicated and in any case in a manner that ensures the security, integrity and confidentiality of the data through appropriate technical and organizational measures pursuant to Art. 32 GDPR.
9. Rights of the data subject
Users may at any time exercise the rights provided for in Arts. 15-22 GDPR: access to their data, rectification, erasure, restriction of processing, objection to processing and data portability, as well as the right to withdraw consent at any time without affecting the lawfulness of processing based on consent given before its withdrawal.
The Controller does not carry out automated decision-making, including profiling.
To exercise these rights, users may write to the Data Protection Officer at dataprotection@vegans.it or to the Controller at the details indicated in section 1. Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the competent supervisory authority.
10. Changes to this Policy
The Controller reserves the right to amend or update this Policy, including as a result of regulatory changes. Any changes will be published on this page with an indication of the date of the last update.