Privacy Policy
How we collect, use, and protect your personal data. A comprehensive, transparent policy compliant with EU GDPR Regulation 2016/679 and all applicable national regulations in the countries where we operate.
- Data Controller
- Types of Data Collected
- Purposes and Legal Bases for Processing
- Cookies and Tracking Technologies
- Data Retention
- Recipients and Data Transfer
- Non-EU Data Transfer
- Rights of the Data Subjects
- Form – Exercise of Rights
- Data Security
- Applicable Regulations by Country
- Minors
- Changes to the Policy
- Form – Data Deletion Request
- Form – Withdrawal of Consent
- Form – Privacy Complaint / Report
- DPO Contact and Supervisory Authority
Pursuant to Art. 13 of EU Regulation 2016/679 (hereinafter "GDPR") and Art. 13 of Legislative Decree 196/2003 (Italian Privacy Code, as amended by Legislative Decree 101/2018), this Policy is provided by GASPA S.R.L MACCHINE, the controller of personal data collected through the website gaspa-macchine.com.
GASPA S.R.L MACCHINE
Brand: GASPA MACCHINE
Z.I. Predda Niedda Strada 30
07100 Sassari (SS), Italy
IT 03006910909
+39 377 390 1146
Mon–Sat 09:00–18:00 CET
Data Protection Officer (DPO): GASPA S.R.L MACCHINE, as a small and medium-sized enterprise that does not perform large-scale processing of special categories of data, is not obliged to appoint a DPO pursuant to Art. 37 GDPR. For any privacy-related requests, you may contact the controller directly at info@gaspa-macchine.com.
GASPA MACCHINE collects users' personal data through different channels and methods, always in compliance with the principle of data minimization provided for by Art. 5 GDPR: only data strictly necessary for the stated purposes are collected.
| Data Category | Specific Examples | Collection Occasion | Mandatory? |
|---|---|---|---|
| Personal details | First name, last name, company name | Account registration, purchase order, information request | Yes |
| Contact details | E-mail address, phone number | Registration, order, contact forms, newsletter | Yes |
| Shipping and billing data | Full address, ZIP code, city, country, VAT number (for companies) | Purchase order finalization | Yes |
| Payment data | Partial card data (managed by PCI-DSS certified processors), bank transfer details | Checkout and payment process | Yes |
| Communications | Content of e-mails, messages via contact form, support requests | Correspondence with customer service | Only if initiated by the user |
| Professional data | Company name, sector of activity, VAT number | B2B purchases, company quote requests | For B2B purchases |
- Technical browsing data: IP address, browser type and version, operating system, screen resolution, browser language settings.
- Site usage data: pages visited, time spent on each page, navigation path, searches performed on the site, clicks on products.
- Device data: device type (desktop, tablet, smartphone), unique device identifier (in anonymized form).
- Source data: referral website, advertising campaign through which the user reached the site (UTM parameters).
- Server logs: automatic recordings of requests to the web server, kept for a maximum of 30 days for IT security purposes.
Special Categories of Data: GASPA MACCHINE does not intentionally collect special categories of personal data pursuant to Art. 9 GDPR (data relating to health, ethnic origin, political opinions, religious beliefs, sexual orientation, criminal convictions). If such information is spontaneously communicated by the user, it will be immediately deleted and will not be processed.
Every processing of personal data carried out by GASPA MACCHINE is based on a specific legal basis provided for by Art. 6 GDPR. The following table transparently illustrates for what purpose your data are used and on what legal basis each processing is founded.
| Purpose of Processing | Legal Basis (Art. 6 GDPR) | Data Involved | Consent Required? |
|---|---|---|---|
| Processing and management of purchase orders – order receipt, availability check, billing, shipping, and delivery of the machine. | Art. 6(1)(b) – Performance of a contract | Personal details, contact, billing, shipping, payment | No |
| After-sales service and warranty management – technical assistance, complaints, warranty procedures, returns, and refunds. | Art. 6(1)(b) – Performance of a contract | Personal details, contact, order data | No |
| Tax and accounting compliance – issuance of invoices, accounting records, tax returns, intra-community obligations (INTRASTAT). | Art. 6(1)(c) – Legal obligation | Personal details, billing, tax data | No |
| User account management – registration, access to personal area, order history, credential management. | Art. 6(1)(b) – Performance of a contract | Personal details, contact, access credentials | No |
| Service communications – notifications on order status, shipping updates, payment confirmations, account-related notices. | Art. 6(1)(b) – Performance of a contract | E-mail, phone, order data | No |
| Direct marketing and newsletter – sending commercial communications, promotions, new arrivals in the catalog, price updates on machines of interest. | Art. 6(1)(a) – Consent of the data subject | E-mail, name | Yes |
| Statistical analysis of the site – traffic monitoring, analysis of browsing behavior to improve the user experience (anonymized Google Analytics). | Art. 6(1)(a) – Consent / Art. 6(1)(f) – Legitimate interest (aggregated data only) | Anonymized browsing data | For analytical cookies |
| Personalized advertising (remarketing) – display of personalized ads on Google, Meta, and other online advertising channels, based on site browsing. | Art. 6(1)(a) – Consent of the data subject | Tracking cookies, anonymized IP | Yes |
| Fraud prevention and security – detection of unauthorized access, suspicious activity, fraud attempts, protection of the IT infrastructure. | Art. 6(1)(f) – Legitimate interest | Technical logs, IP, session data | No |
| Management of complaints and disputes – documentation and management of complaints, ADR/ODR proceedings, potential legal litigation. | Art. 6(1)(c) – Legal obligation / Art. 6(1)(f) – Legitimate interest | Personal details, correspondence, order data | No |
Legitimate Interest: in cases where processing is based on the legitimate interest of GASPA MACCHINE (Art. 6(1)(f) GDPR), a balance has been struck between the interests of the controller and the fundamental rights of the data subject, verifying that such interests do not override those of the user. The user always has the right to object to such processing pursuant to Art. 21 GDPR.
The gaspa-macchine.com website uses cookies and similar tracking technologies in compliance with Italian legislation (Art. 122 of Legislative Decree 196/2003, as amended by Legislative Decree 101/2018) and the Privacy Guarantor Guidelines No. 231 of June 10, 2021 on cookies. Each category of cookie used is transparently illustrated below.
Cookie Preference Management: you can change your preferences on analytical and marketing cookies at any time using the cookie management panel on the site (accessible via the "Cookie Settings" link in the footer). For third-party cookies, it is also possible to manage preferences directly through the providers' official sites: Google Analytics Opt-out and Meta Privacy Center.
GASPA MACCHINE retains personal data only for the time necessary to achieve the purposes for which they were collected, in compliance with the principle of storage limitation provided for by Art. 5(1)(e) GDPR. Specific retention periods are indicated in the following table.
| Data Category | Retention Period | Reasoning |
|---|---|---|
| Order and invoice data | 10 years from the date of issue | Legal obligation – tax and accounting retention (Presidential Decree 600/1973; Art. 2220 Civil Code) |
| Shipping and delivery data | 5 years from the date of delivery | Ordinary limitation period for contractual disputes (Art. 2946 Civil Code) |
| Customer support correspondence | 3 years from the closing of the request | Historical documentation for any subsequent complaints |
| Registered user account | Until account deletion + 12 months | To ensure the completion of any ongoing orders and after-sales management |
| Data for marketing / newsletter | Until withdrawal of consent + 3 months (for security) | Based on consent; withdrawal results in immediate cessation of sending |
| Technical server logs | 30 days | IT security; after the term, they are automatically deleted |
| Analytical cookies (browsing data) | 26 months (Google Analytics) or until withdrawal of consent | Analysis of user behavior for site improvement |
| Data for management of complaints and disputes | 5 years from the closing of the case | Legal protection in case of litigation (ordinary limitation period) |
Automatic Deletion: at the end of the indicated retention periods, data are deleted or irreversibly anonymized, unless retention is required for legal or regulatory reasons. Deletion procedures are automated and periodically verified by our technical team.
GASPA MACCHINE does not sell, rent, or transfer users' personal data to third parties for commercial purposes. However, data may be communicated to specific categories of third parties, exclusively within the limits necessary for the stated purposes and in the presence of adequate contractual guarantees.
Personal details and delivery address data are transmitted to specialized carriers in charge of transporting the machines (first name, last name or company name, delivery address, phone number for delivery coordination). These subjects act as Data Processors pursuant to Art. 28 GDPR, bound by a specific confidentiality agreement.
Data necessary for payment processing are transmitted to the PCI-DSS certified payment processors used by GASPA MACCHINE (e.g., Stripe, PayPal, or banking institutions for transfers). These subjects process payment data as independent data controllers, according to their own privacy policies, and GASPA MACCHINE never stores complete payment card data.
Billing data and accounting documents are transmitted to the accounting firm and/or tax consultant of GASPA MACCHINE for the fulfillment of tax and accounting obligations. These subjects act as Data Processors, bound by an agreement pursuant to Art. 28 GDPR.
- WordPress hosting provider: hosts the website and related databases. Acts as a Data Processor with GDPR guarantees.
- Google LLC: provides Google Analytics (traffic analysis) and Google Ads (advertising). Anonymized or pseudonymized data. Transfer to USA with standard contractual clauses (SCC).
- Meta Platforms Ireland Ltd.: provides the Meta Pixel service for tracking advertising conversions on Facebook and Instagram. Subject to transfers to USA with SCC.
- E-mail marketing service: provider used for sending the newsletter to subscribers who have provided consent. Acts as a Data Processor.
Data may be communicated to the competent public authorities (Revenue Agency, Finance Guard, Customs Authority, law enforcement) exclusively when required by applicable law, by a court order, or in fulfillment of specific regulatory obligations.
Register of Data Processors: GASPA MACCHINE maintains an updated register of all Data Processors designated pursuant to Art. 28 GDPR, with an indication of the contractual guarantees adopted. This register is available upon request by contacting info@gaspa-macchine.com.
GASPA MACCHINE may transfer some personal data to countries outside the European Economic Area (EEA) only in the presence of adequate guarantees pursuant to Arts. 44–49 GDPR. The main situations in which such transfers occur are indicated below.
Data processed by Google LLC (Google Analytics, Google Ads) and Meta Platforms Ireland Ltd. (Meta Pixel) may be transferred and processed in the United States. Such transfers take place in compliance with the Standard Contractual Clauses (SCC) adopted by the European Commission (EU Implementing Decision 2021/914), as well as based on the EU-US Data Privacy Framework, adopted by the European Commission by Decision of July 10, 2023, which recognized an adequate level of protection for personal data transferred to US organizations participating in the framework.
- Standard Contractual Clauses (SCC) approved by the European Commission – applied in contracts with Google, Meta, and other US providers.
- EU-US Data Privacy Framework – for US providers participating in the framework, recognized as adequate by the EU Commission in July 2023.
- Adequacy decisions: for transfers to countries that the European Commission has recognized as having an adequate level of protection (e.g., Switzerland, pursuant to Decision 2000/518/EC).
Switzerland: although Switzerland is not an EU member state, the European Commission has adopted an adequacy decision regarding Switzerland, which means that data transfers to Switzerland do not require additional measures beyond those applied within the EEA. GASPA MACCHINE ships to Switzerland, and the data of Swiss customers are processed with the same guarantees applied to EU customers.
Every natural person whose personal data are processed by GASPA MACCHINE has the right to exercise the following rights guaranteed by the GDPR Regulation. GASPA MACCHINE undertakes to respond to all requests within 30 days of receipt, with the possibility of an extension of a further 60 days for particularly complex requests, upon notice to the data subject.
Right of Access (Art. 15)
Obtain confirmation that GASPA MACCHINE is processing your personal data and receive a copy of all processed data, with information on the purposes, categories of data, and recipients.
Right to Rectification (Art. 16)
Request the correction of inaccurate or incomplete personal data concerning you, without undue delay.
Right to Erasure (Art. 17)
Request the deletion of your personal data (right to be forgotten) when they are no longer necessary for the purposes for which they were collected or when you have withdrawn consent.
Right to Restriction (Art. 18)
Request the restriction of the processing of your data in specific circumstances (e.g., during verification of data accuracy or in case of objection to processing).
Right to Portability (Art. 20)
Receive your personal data in a structured, commonly used, and machine-readable format, or transmit them directly to another data controller.
Right to Object (Art. 21)
Object at any time to the processing of your data based on legitimate interest or for direct marketing purposes, including profiling related to marketing.
Withdrawal of Consent (Art. 7) 7(3))
Withdraw at any time the consent given for processing based on it (marketing, analytical/profiling cookies), without affecting the lawfulness of processing prior to withdrawal.
Automated Decisions (Art. 22)
Not be subject to decisions based solely on automated processing, including profiling, which produce significant legal effects. GASPA MACCHINE does not make such automated decisions.
Right to Lodge a Complaint (Art. 77)
Lodge a complaint with the competent supervisory authority (Italian Privacy Guarantor) if you believe that the processing of your personal data violates the GDPR.
How to Exercise Your Rights: to exercise one or more of the rights indicated above, fill out the interactive form in Section 9 of this page or send a written request to info@gaspa-macchine.com, specifying the right you wish to exercise, your identification data and, if necessary, a copy of a valid identity document. The response will be provided within 30 days of receipt of the complete request.
Fill out the following form to send a formal request to exercise your rights under the GDPR Regulation. You will receive a response at the e-mail address indicated within 30 days of receipt of the request.
Fields marked with * are mandatory. Your identity will be verified before proceeding with the request, in compliance with Art. 12 GDPR.
GASPA MACCHINE adopts appropriate technical and organizational measures to protect personal data from unauthorized access, disclosure, alteration, or destruction, in compliance with Art. 32 GDPR and the principle of privacy by design and by default enshrined in Art. 25 GDPR.
- TLS/HTTPS encryption: all communications between the user's browser and the site's servers are encrypted via TLS 1.2 protocol or higher.
- Password hashing: user account passwords are never stored in plain text, but in the form of an irreversible hash (bcrypt).
- Limited data access: personal data are accessible only to authorized personnel of GASPA MACCHINE who need them for their specific duties (need-to-know principle).
- Regular backups: data are subject to periodic encrypted backups, stored on servers separate from production.
- Firewalls and anti-intrusion systems: the site is protected by a web application firewall (WAF) and intrusion detection systems (IDS).
- Security updates: WordPress, the plugins, and the themes used are kept updated to the latest available security version.
In the event of a personal data security breach that involves a risk to the rights and freedoms of data subjects, GASPA MACCHINE undertakes to notify the Italian Privacy Guarantor within 72 hours of discovering the breach, pursuant to Art. 33 GDPR. If the breach involves a high risk, data subjects will be informed individually without undue delay, pursuant to Art. 34 GDPR.
Vulnerability Reporting: if you believe you have identified a security vulnerability on the gaspa-macchine.com website that could compromise the protection of users' personal data, please report it promptly to info@gaspa-macchine.com. We will respond within 48 business hours.
In addition to the GDPR (applicable in all EU countries), each country to which GASPA MACCHINE ships has implemented and integrated the GDPR with specific national regulations. The main national data protection laws and the competent supervisory authorities for each country are listed below.
| Country | National Privacy Regulation | Supervisory Authority (DPA) | Official Website |
|---|---|---|---|
| Italy | Legislative Decree 196/2003 (Privacy Code), as amended by Legislative Decree 101/2018 | Garante per la Protezione dei Dati Personali | garanteprivacy.it |
| Austria | Datenschutzgesetz (DSG) 2018 | Österreichische Datenschutzbehörde (DSB) | dsb.gv.at |
| Finland | Tietosuojalaki (1050/2018) | Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) | tietosuoja.fi |
| France | Loi Informatique et Libertés (Law No. 78-17), as amended in 2018 | Commission Nationale de l'Informatique et des Libertés (CNIL) | cnil.fr |
| Germany | Bundesdatenschutzgesetz (BDSG) 2018 | Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) + DPAs of the individual Länder | bfdi.bund.de |
| Netherlands | Uitvoeringswet Algemene verordening gegevensbescherming (UAVG) | Autoriteit Persoonsgegevens (AP) | autoriteitpersoonsgegevens.nl |
| Poland | Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych | Urząd Ochrony Danych Osobowych (UODO) | uodo.gov.pl |
| Romania | Legea nr. 190/2018 | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) | dataprotection.ro |
| Spain | Ley Orgánica 3/2018 (LOPDGDD) | Agencia Española de Protección de Datos (AEPD) | aepd.es |
| Switzerland | Federal Act on Data Protection (FADP, in force since September 1, 2023) | Federal Data Protection and Information Commissioner (FDPIC) | edoeb.admin.ch |
Lead Authority: since GASPA MACCHINE is a company based in Italy, the lead supervisory authority for cross-border processing pursuant to Art. 56 GDPR is the Italian Garante per la Protezione dei Dati Personali. Consumers in other EU countries have the right to lodge their complaint with the supervisory authority of their country of residence, which will coordinate with the Italian Garante according to the GDPR's one-stop-shop procedure.
The gaspa-macchine.com website and the products marketed therein (agricultural and construction machinery of high economic value, intended for professional use) are aimed exclusively at adults (aged 18 or over). GASPA MACCHINE does not intentionally collect personal data from minors under 18.
Pursuant to Art. 8 GDPR and Art. 2-quinquies of Legislative Decree 196/2003 (as amended by Legislative Decree 101/2018), in Italy the age threshold for autonomous consent to the processing of data for information society services is set at 14 years. However, since the activity of GASPA MACCHINE presupposes the legal capacity to enter into purchase contracts for high-value goods, the site is accessible and usable exclusively by adults.
Reporting Minors' Data: if parents or legal guardians believe that a minor has provided personal data to GASPA MACCHINE without their consent, they are requested to contact our team immediately at info@gaspa-macchine.com. We will proceed with the immediate deletion of such data as soon as we have confirmation.
GASPA S.R.L MACCHINE reserves the right to update this Privacy Policy at any time to reflect regulatory changes (e.g., new measures from the Privacy Garante, updates to the GDPR or national regulations), changes in data processing activities, or the introduction of new services on the site.
In the event of substantial changes affecting the rights of data subjects or the methods of data processing, GASPA MACCHINE will communicate the changes to registered users via email to the address provided during registration, with at least 30 days' notice before the new conditions come into effect. For processing based on consent, any substantial changes will require the collection of new informed consent.
The current version of this Policy is dated June 12, 2026. Previous versions of the Policy can be requested by sending an email to info@gaspa-macchine.com. We recommend that users regularly consult this page to stay updated on any changes.
Pursuant to Art. 17 GDPR (Right to Erasure – Right to be Forgotten), you have the right to request the deletion of your personal data in the cases provided for by law. Please fill out the following form to submit your request. We will verify the applicability of the right to erasure in your specific case and respond within 30 days.
Limitations to the Right to Erasure: the right to erasure is not absolute. It is not possible to delete data that GASPA MACCHINE is legally obliged to retain (e.g., tax and accounting data for 10 years, data relating to orders in progress). In these cases, you will be provided with a reasoned response indicating the remaining mandatory retention period.
Specify the data you wish to delete and the reason for the request. You will be asked to verify your identity before proceeding with the deletion.
Pursuant to Art. 7(3) GDPR, you have the right to withdraw your consent at any time for one or more specific processing operations based on consent, without affecting the lawfulness of processing based on consent before its withdrawal. The withdrawal takes effect immediately from the date the request is processed by GASPA MACCHINE.
Select the processing operations for which you wish to withdraw consent. Withdrawal is free of charge and without consequences for the use of the site for non-commercial purposes.
If you believe that the processing of your personal data by GASPA MACCHINE violates the provisions of the GDPR or applicable national law, you have the right to lodge a complaint. We invite you in the first instance to contact us directly: we are committed to resolving the issue quickly and transparently. If the response received is not satisfactory, you have the right to lodge a complaint with the competent Supervisory Authority (see Section 11).
Describe the problem encountered in detail. GASPA MACCHINE will respond within 30 days of receiving the complaint, as provided for by Art. 12 GDPR.
Privacy Contacts – DPO and Supervisory Authority
For any privacy-related issues, the exercise of your rights, or to request information on the processing of your personal data, please contact us. The competent Italian Supervisory Authority is the Garante per la Protezione dei Dati Personali (garanteprivacy.it).