Villa Tatti is committed to protecting our customer privacy and takes its responsibility regarding the
security of customer information very seriously. We will be clear and transparent about the information we are
collecting and what we will do with that information.
Villa Tatti, (referred to as “we”, “us”, “our” or “Villa Tatti” in this policy) is the “data controller” of
all personal information that is collected and used about Villa Tatti customers for the purposes of EU-wide GPDR.
Villa Tatti is registered in Italy, with VAT number IT01213000530 and registered offices at Via Poggio Bernone, 16 - frazione Tatti Massa Marittima (GR) - Italy.
Personal data means any information relating to you which allows us to identify you, such as your name,
contact details, reference number, payment details and information about your access to our website.
We may collect personal data from you when you purchase our products and services (either directly or
indirectly through our trusted third-party partners), create an Villa Tatti account, use our tutorials, use
our website and / or App and other websites accessible through our website and / or App, receive our
newsletters, participate in a survey or competition, or when you contact us.
Specifically, we may collect the following categories of information:
We may also obtain information from other sources and combine that with information we collect through our
Services. We may receive updated information about you, such as an updated billing address, from the
financial institution or ecommerce platforms issuing your credit card or in connection with our billing
for the Services.
What do we use your personal data for, why and for how long
Your data may be used for the following purposes:
We will only process your personal data where we have a legal basis to do so. The legal basis will depend
on the reasons we have collected and need to use your personal data for.
In most cases we will need to process your personal data so we can provide you the products and/or services
We may also process your personal data for one or more of the following:
Only children aged 16 or over can provide their own consent. For children under this age, consent of the
children’s’ parents or legal guardians is required.
We will not retain your data for longer than is necessary to fulfil the purpose it is being processed for.
To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal
data, the purposes for which we process it and whether we can achieve those purposes through other means.
We must also consider periods for which we might need to retain personal data in order to meet our legal
obligations (e.g. in relation to tax) or to deal with complaints, queries and to protect our legal rights
in the event of a claim being made. For retention of information on your Villa Tatti account, please see the
below section about my Villa Tatti
When we no longer need your personal data, we will securely delete or destroy it. We will also consider if
and how we can minimize over time the personal data that we use, and if we can anonymize your personal data
so that it can no longer be associated with you or identify you, in which case we may use that information
without further notice to you.
We follow strict security procedures in the storage and disclosure of your personal data, and to protect it
against accidental loss, destruction or damage. The data you provide to us is protected using SSL (Secure
Socket Layer) technology. SSL is the industry standard method of encrypting personal information and credit
card details so that they can be securely transferred over the Internet.
All payment details are transmitted over SSL across dedicated network infrastructure and stored in compliance
with Payment Card Industry Data Security Standards (PCI DSS) Level 1 certified (Payment Card Industry Data
Security Standard). PCI DSS is the most important security standard for the card payment industry and
includes a set of comprehensive requirements for security management, policies, procedures, network
architecture, software design and other critical protective measures.
We also have a variety of other security standards we comply with: ISAE 3402 and SSAE 16, Safe Harbor
US-EU/EEA and Switzerland, 3-D Secure vendor/client protection, VeriSign certificate for secure SSL
(Secure Socket Layer) orders, BBB Accreditation.
We require all third parties to have appropriate technical and operational security measures in place to
protect your personal data, in line with Spanish and EU law on data protection rules.
Villa Tatti operates businesses in multiple jurisdictions, some of which are not located in the European Economic
Area (EEA), such as Lithuania and USA. While countries outside the EEA do not always have strong data
protection laws, we require all services providers to process your information in a secure manner and
n accordance with Spanish and EU law on data protection. We utilize standard means under EU law to
legitimize data transfers outside the EEA.
Your personal data shall not be shared except:
Your personal data may be shared with other companies within the Villa Tatti.
Under certain circumstances, by law you have the right to:
If you want to exercise any of these rights, then please contact our DPO in the following email: email@example.com
You will not have to pay a fee to access your personal information (or to exercise any of the other rights).
However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive.
Alternatively, we may refuse to comply with the request in such circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right
to access the information (or to exercise any of your other rights). This is another appropriate security
measure to ensure that personal information is not disclosed to any person who has no right to receive it.
request availability now
Via Poggio Bernone, 16 - frazione Tatti
Massa Marittima (GR) - Italy
+39 0566 871008
+39 339 8479191