Skip to main content

Privacy Policy

Information notice pursuant to Art. 13 of EU Regulation 2016/679 (GDPR) — Last updated: 3 September 2025

Welcome to the website of the Chiarli Group, the excellence of Modena wines.

The following applies to the pages, domains and sub-domains registered for each of the brands and/or companies belonging to the Chiarli Group: CHIARLI 1860, CHIARLI MODENA, CLETO CHIARLI and QUINTO PASSO.

Current regulations require us to provide information regarding the processing of personal data for this website (hereinafter also "site") in relation to the processing of personal data of users/visitors who consult and use it.

This notice is provided pursuant to EU Regulation 2016/679 (hereinafter also "Regulation" or "GDPR") and subsequent amendments to all users who interact with the site. The validity of the information contained on this page is limited to this site only and does not extend to other external websites that may be consulted via hypertext links.

Under the personal data protection regulations:

  • We, i.e. the Entity whose details are listed on the institutional site to which this site is linked, are the "Controller" of the Processing;
  • You are the "Data Subject", and have the rights and obligations we describe below.

1. Data Controller

This Privacy Policy describes how PR.I.V.I. S.r.l., with registered office at Via Manin 15, 41122 Modena (MO), as Data Controller (hereinafter "we" or the "Company"), collects, uses and protects the personal data of users who visit and use the website www.chiarli.it. The Data Controller processes data according to the principles of lawfulness, fairness, transparency, purpose and storage limitation, data minimisation, accuracy, integrity and confidentiality.

2. Categories of data processed

While browsing and using the Site, we may collect:

  • Browsing data;
  • Cookies and similar technologies;
  • Data voluntarily provided.

2.1 Browsing data

The computer systems and software procedures used to operate this website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of users' computers, URI (Uniform Resource Identifier) addresses of requested resources, time of the request, method used to submit the request to the server, size of the response file, numeric code indicating the status of the server's response (successful, error, etc.) and other parameters relating to the user's operating system and computing environment.

2.2 Cookies and similar technologies

Cookies are small text files that visited sites send to the user's terminal, where they are stored and then retransmitted to the same sites on subsequent visits. Third-party cookies, on the other hand, are set by a different website from the one the user is visiting, because each site may contain elements (images, maps, sounds, specific links to web pages in other domains, etc.) that reside on servers other than that of the visited site. Cookies are used for different purposes: computer authentication, session monitoring, storage of information about specific configurations of users accessing the server, preferences, and so on. For further information on the cookies used by this website, please refer to the cookie policy in the footer of the site.

2.3 Data voluntarily provided by the user

No personal data is required to consult the site. However, any contact with the Controller — for example to request information via a form, to be informed about Chiarli Group initiatives, to purchase products on the dedicated platform, or to send unsolicited messages by email or post — entails the subsequent acquisition of the sender's personal data, necessary to respond to the requests, as well as any other personal data voluntarily included by the user in their communications. Please note that browsing and providing personal data is permitted only to audiences over 14 years of age, pursuant to Art. 2-quinquies of Legislative Decree 101/2018.

3. Purposes of processing

The Controller processes data in order to:

  • Allow you to browse and use the Service;
  • Deliver the requested Service or performance;
  • Fulfil administrative, financial, accounting and/or tax obligations;
  • Comply with any obligation provided by law and/or an order of the Public Authority;
  • Where relevant, assert or defend a right in court.

3.1 Website browsing

Data required to use web services are also processed to obtain statistical information on the use of the services (e.g. most-visited pages, number of visitors by time slot or day, geographical areas of origin, always in anonymised form) and to monitor the correct operation of the services offered. The data will also be used to investigate liability in case of any alleged cyber offences against the site.

3.2 Information requests, visit bookings, product purchases

Through the contact details provided or the forms on our site, we will handle your request for the specific service offered by the Controller (e.g. an information request collects and processes only the data necessary to respond). Data collection and processing are limited to the minimum dataset necessary to deliver the proposed service securely.

3.3 Soft spam

Occasional commercial/promotional communications (e.g. discount codes) and newsletters sent to the email address you provided at the time of sale, concerning the same type of product and/or service analogous to the one purchased, as permitted by Art. 130 paragraph 4 of Legislative Decree 196/03 — legitimate interest (Art. 6 (f) GDPR). The contact/user may always object to such processing pursuant to point 9 below.

3.4 Direct marketing

The Controller may use the data for direct-marketing activities only with the explicit, free consent of the data subject.

3.5 Profiling

No profiling activities are carried out on the basis of browsing the Chiarli Group sites, except as provided in the Cookie Policy. Any profiling activities will be subject to a dedicated notice and accepted only with the explicit, free consent of the data subject.

4. Legal basis

The legal bases for the processing are:

  • Need to allow browsing and access to the requested Web Service, and to provide the service itself;
  • Perform the activities listed in point 3;
  • Where processing is necessary for a task in the public interest or the exercise of public authority vested in the Controller;
  • Tax data: need to fulfil obligations pursuant to points 3.1 c–e.

Specifically:

  • Website browsing — legitimate interest of the Controller or third parties (Art. 6(1)(f) and Recital 47 GDPR).
  • Information requests, bookings, purchases — execution of a contact requested by the data subject or of a contract to which the data subject is party, or pre-contractual measures (Art. 6(1)(b) GDPR).
  • Soft spam — legitimate interest of the Controller (Art. 6(1)(f) and Recital 47 GDPR).
  • Direct marketing / profiling — consent (Art. 6(1)(a) GDPR).

5. Disclosure and dissemination of data

Data may be communicated to third-party recipients (including public administration or judicial authorities) only to the extent strictly necessary for the purposes set out above, or for service requirements or legal obligations. Categories of recipients:

  • Parties necessary for the execution of activities related to the Service, bound by a data-processing agreement (external processors);
  • Persons authorised by the Controller who have undertaken confidentiality or have an appropriate legal obligation of confidentiality (e.g. employees and collaborators).

The Controller may also need to disclose data to comply with legal obligations or orders from public authorities, including judicial authorities. Data will not be disseminated.

6. Retention period

The Controller retains your data for the time strictly necessary to achieve the purposes set out in point 3. Data will be deleted when no longer needed for the above purposes, subject to additional legal retention obligations.

  • Website browsing: for the duration of the browsing session.
  • Information requests, bookings, purchases: for product purchases, data are retained in compliance with Italian legislation for related administrative purposes, with subsequent anonymisation or deletion. In other cases, data are deleted after 6 months.
  • Soft spam: until the data subject objects.
  • Direct marketing: until consent is withdrawn (opt-out).
  • Profiling: not stored.

7. Nature of data communication

The communication of the personal data referred to in point 2.1 is necessary for browsing: failure to provide them would make browsing impossible. The communication of the personal data referred to in point 2.3 is optional.

8. Consequences of refusal

As specified in point 7, it is not technically possible to refuse to communicate browsing data (to the extent they are personal data). If you refuse to communicate the personal data referred to in point 2.3, it will not be possible to respond to requests and/or deliver the service.

9. Rights of the data subject

As a Data Subject, you have the right to:

  • Access your data held by the Controller and obtain a copy;
  • Request rectification and/or erasure, where the conditions are met;
  • Request restriction of processing, where the conditions are met;
  • Object, for reasons connected to your particular situation, to the processing of personal data concerning you;
  • Exercise your right to withdraw consent to the processing of personal data;
  • Lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).

10. Processing and transfer outside the European Economic Area (EEA)

The personal data you provide are processed only within the European Economic Area (EEA).

This information refers to how the personal data of visitors are processed while browsing and using the website. The entry into force of new sector regulations, as well as the ongoing review and update of the site, may require changes over time. Please check this page periodically. This document indicates the last update date.