Informativa Privacy
Information on the processing of personal data.
Effective as of October 20, 2025
INTRODUCTION
This policy takes into account the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and the Italian Data Protection Code (Legislative Decree No. 196 of 30 June 2003). The document has also been drafted in accordance with the Guidelines of the Italian Data Protection Authority (in particular the Anti-Spam Guidelines issued by the Italian Data Protection Authority on 4 July 2013).
Data Controller: Rosso Maranello Srl, Via Alfredo Dino Ferrari 61 – 41053 Maranello (MO), Italy; VAT No.: IT03761460363, Economic and Administrative Index (REA): MO – 398831, Share Capital: €10,000.00 fully paid, Email: info@motorsportitalia.it, Telephone: +39 0536941779
Website to which this privacy policy refers: https://www.motorsportitalia.it/ (Website).
The Data Controller has not appointed a DPO (Data Protection Officer). Therefore, you can send any inquiries directly to the Data Controller.
GENERAL INFORMATION
This document describes how the Data Controller processes your personal data provided on the Website.
The main types of processing of your personal data are described below. Specifically, the legal basis for processing is explained, whether providing personal data is mandatory, and the consequences of failure to provide it. To better describe your rights, where necessary, we have specified whether and when a specific processing of personal data is not carried out. On the Site, you have the option to enter the personal data of third parties. In this case, you guarantee that you have obtained the consent of these parties to enter this personal data. Therefore, you undertake to indemnify and hold the Data Controller harmless from any liability.
Registration on the Site
The Site does not offer the option of registration. Therefore, the Data Controller does not process your personal data for this purpose.
Purchases on the Site
Your personal data will be processed to allow you to make purchases on the Site. In the event of an online purchase order, to allow the conclusion of the purchase contract and the correct execution of related transactions (and, where necessary under applicable legislation, to comply with tax obligations). This processing of personal data also includes the possibility of sending communications (e.g., tracking, order information, and requests to leave a review) via automated tools such as email and/or text message and/or WhatsApp. The legal basis for processing is the Data Controller’s obligation to perform the contract with the data subject or to comply with legal obligations. Regardless of the above (and therefore your consent), the Data Controller may process your data for so-called “soft spam” purposes, governed by Article 130 of the Privacy Code. This means that, limited to the email address you provide in the context of a purchase through the Site, the Data Controller will process the email address to enable direct offers of similar products/services, unless you object to such processing in the manner provided for in this policy. The legal basis for processing is the Data Controller’s legitimate interest in sending this type of communication. This legitimate interest can be considered equivalent to the data subject’s interest in receiving “soft spam” communications. The Data Controller may send emails to remind the user to complete a purchase. The legal basis for this processing is the Data Controller’s legitimate interest in sending this type of communication. The Data Controller does not offer products or services prohibited to minors under 18. Therefore, no specific age verification system is provided, as there are no content subject to legal restrictions.
Responding to Your Requests
Your data will be processed to respond to your requests for information. Providing your data is optional, but your refusal will make it impossible for the Data Controller to respond to your questions. The legal basis for the processing is the Data Controller’s legitimate interest in responding to your requests. This legitimate interest is equivalent to the user’s interest in receiving a response to communications sent to the Data Controller.
General Marketing
With your prior consent, the Data Controller may process the personal data you provide to send you advertising material and/or newsletters relating to its own or third-party products. The legal basis for this processing is your consent. Providing personal data for this purpose is purely optional. Failure to consent to data processing for marketing purposes will make it impossible for you to receive advertising material relating to the Data Controller’s and/or third-party products/services, as well as the Data Controller’s ability to conduct market research, including those aimed at assessing user satisfaction, and to send you newsletters. These communications will be sent to the email address you provided on the Website. We use Google services, such as Google Ads and Google Analytics, to personalize advertising and improve user experience. This includes the collection of personal data and cookies, which are used to show you ads tailored to your preferences. Upon consent, you will be asked to authorize the use of this data. Further details on the use of cookies and consent management are available in this website’s cookie policy.
Profiling
The Data Controller does not perform “profiling” with your personal data. Therefore, it will not send you advertising materials and/or newsletters relating to its own or third-party products of specific interest to you.
Data Transfer
The Data Controller does not transfer your personal data to third parties.
Geolocation
The Site does not implement tools to geolocate the user’s IP address.
Resume
It is not possible to send resumes via the Site. Therefore, your data will not be processed for these purposes.
Appointment Booking
There are no third-party appointment booking systems active on the Site with the Data Controller. Therefore, your data will not be processed for this purpose. In any case, you can always contact the Data Controller using the contact details provided above.
Photographs and Videos
The Data Controller does not request the publication of photographs and/or videos of you. Therefore, your data will not be processed for these purposes.
Web Scraping
The use of any automated process or system to access, acquire, copy, or monitor any portion of our website, including, but not limited to, web scraping, crawling, or spidering techniques, is expressly prohibited. The Data Controller reserves the right to take all necessary measures, including legal action, to prevent and prosecute any unauthorized scraping activity. By using the Site, you or any third party agree not to: (i) use automated systems, such as bots, scrapers, or spiders, to access or interact with the Site; (ii) collect content, data, or other information from the Site without express written permission; and (iii) distribute, display, publish, or otherwise use content acquired through scraping techniques without consent. Any violation of this clause will be considered a material breach of the Site’s Terms of Use and will result in the adoption of appropriate measures, including the possible suspension of access to the Site and the initiation of legal action to protect the Data Controller’s interests.
Disclosure of Personal Data
As part of its ordinary activities, the Data Controller may disclose your personal data to certain categories of parties. Article 2 lists the parties to whom the Data Controller discloses your personal data. To facilitate the protection of your rights, Article 2 may specify in certain cases when your data will not be disclosed to third parties.
Disclosure of personal data to third parties is different from disclosure (regulated in the previous paragraph). In disclosure, the third party to whom the data is disclosed may use it only for the specific purposes described in the relationship with the Data Controller. In disclosure, however, the third party becomes the independent Data Controller of the personal data. Furthermore, your consent is always required to disclose your personal data to third parties.
Notwithstanding the foregoing, it is understood that the Data Controller may still use your personal data to properly fulfill the obligations set forth in applicable laws.
SPECIFIC PRIVACY NOTICE
Article 1 Processing Methods
1.1 Your personal data will be processed primarily using electronic or automated means, using methods and tools that ensure the security and confidentiality of your personal data.
1.2 The information acquired and the processing methods will be relevant and not excessive in relation to the type of services provided. Your data will also be managed and protected in secure IT environments appropriate to the circumstances.
1.3 The Site does not process “specially-identified data.” Specially-identified data is data that may reveal racial or ethnic origin, religious, philosophical, or other beliefs, political opinions, membership of political parties, trade unions, associations, or organizations of a religious, philosophical, political, or trade union nature, health, or sexual orientation.
1.4 The Site does not process judicial data.
Article 2 Disclosure of Personal Data
The Data Controller may disclose your personal data to certain categories of entities. The following are the entities to which the Data Controller reserves the right to disclose your data:
The Data Controller may disclose your personal data to all entities (including public authorities) who have access to personal data pursuant to regulatory or administrative provisions.
Your personal data may also be disclosed to all public and/or private entities, natural and/or legal persons (legal, administrative, and tax consultancy firms, judicial offices, Chambers of Commerce, Labor Chambers and Offices, etc.), if disclosure is necessary or functional to the proper fulfillment of legal obligations.
The Data Controller employs employees and/or collaborators in any capacity. For the proper functioning of the Website, the Data Controller may disclose your personal data to these employees and/or collaborators.
In its ordinary management of the Site, the Data Controller uses companies, consultants, or professionals responsible for the installation, maintenance, updating, and, in general, management of the Data Controller’s hardware and software, or those used by the Data Controller to provide its services. Therefore, your data may be processed by these parties only for these purposes.
To send its communications, the Data Controller uses external companies tasked with sending this type of communications (CRM platforms). Your personal data (in particular, your email address) may therefore be disclosed to these companies.
The Data Controller does not use external companies to provide customer care services.
The Data Controller uses banks and companies that manage national and international payment circuits for online payments for products and services purchased through the Site.
Purchasers’ personal data is not disclosed to couriers or shipping agents.
The Data Controller reserves the right to modify the above list based on its ordinary operations. Therefore, you are invited to regularly access this policy to check to which parties the Data Controller discloses your personal data.
Article 3 Retention of Personal Data
3.1 This article describes how long the Data Controller reserves the right to retain your personal data.
Your personal data will be retained only for the time necessary to ensure the proper provision of the services offered through the Site.
For the purpose of fulfilling the sales contract, the data will be retained for 10 years from the date of receipt of the purchase order. This is to allow the Data Controller to exercise its right of defense and to demonstrate that the contract has been properly performed.
For customer care purposes, the data will be deleted once the customer service has been completed and, in any case, within a maximum of 3 months from the last email exchange with the data subject.
As required by Article 2220 of the Italian Civil Code, invoices, as well as all accounting records in general, are retained for a minimum period of ten years from the date of registration, so that they can be presented in the event of an audit.
For marketing purposes, unless consent is withdrawn first, the data is retained for 24 months from the date of provision. After consent is withdrawn or at the end of the 24-month period, the personal data will be deleted and no longer used for marketing purposes.
3.2 Without prejudice to the provisions of Article 3.1, the Data Controller may retain your personal data for the period required.
Â
Article 4 Transfer of Personal Data
4.1 The Data Controller is based in a country that offers an adequate level of security from a regulatory perspective. If your personal data is transferred to a non-EU country for which the European Commission has issued an adequacy ruling, the transfer is deemed to be secure from a regulatory perspective. This Article 4.1 indicates the countries to which your personal data may be transferred and where the European Commission has issued an adequacy ruling.
Your personal data may be transferred to the United States pursuant to the European Commission’s adequacy ruling. With this ruling, the European Commission has determined that the United States offers personal data protection comparable to that offered by the European Union.
4.2 Without prejudice to Article 4.1, your data may also be transferred to non-EU countries for which the European Commission has not issued an adequacy ruling. You are therefore invited to regularly review this Article 4.2 to determine to which of these countries your data may be transferred.
4.3 In this Article, the Data Controller indicates the countries in which it may specifically conduct its business. This circumstance may imply the application of the legislation of the relevant country, together with that governing the relationship with the user as indicated in the Introduction.
At the user’s request, the Data Controller will apply any more favorable legislation provided by the user’s national legislation to the processing of personal data.
Article 5. Rights of the Data Subject
The Data Controller informs you that you have the right to:
ask the Data Controller for access to your personal data and to rectify or erase it, limit its processing, or object to its processing, as well as the right to data portability.
Withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Lodge a complaint with a supervisory authority.
The above rights may be exercised by submitting an informal request to the contact details indicated in the Introduction.
Article 6. Amendments and Miscellaneous
The Data Controller reserves the right to make changes to this policy at any time, providing appropriate publicity to users of the Site and ensuring, in any case, adequate and comparable protection of personal data. To review any changes, you are invited to consult this policy regularly. In the event of substantial changes to this privacy policy, the Data Controller may also notify you via email.