Privacy Policy
PRIVACY NOTICE (Art. 13 GDPR) Last updated: 29/06/2026
Pursuant to Regulation (EU) 2016/679 GDPR (hereinafter the “Regulation”), this page describes the methods of processing personal data of users who consult this website. This information does not concern other websites, pages or online services that can be reached via hyperlinks that may be published on the site.
As a result of consulting the site, data relating to identified or identifiable natural persons may be processed.
DATA CONTROLLER
The Data Controller is Biosa Onofrio, VAT no. 01560090118, with registered office at Piazza Domenico Chiodo n. 5, 19121 La Spezia (SP), Tel. 320 711 2159, e-mail: info@onytcg.it.
The regulatory provisions cited above govern the confidentiality of personal data and impose a series of obligations on those who process information relating to other persons. Among the obligations to be complied with is that of adequately informing the natural person to whom the data relate (the Data Subject) about the use made of the relevant data so that consent to the processing of such data is freely given and unambiguous.
Where required by law, the user’s consent will be requested before proceeding with the processing of their personal data.
If the user provides personal data of third parties, they must ensure that the communication of the data to the Controller and the subsequent processing for the purposes specified in the privacy notice complies with the applicable legislation on the processing of personal data. For example, the user may provide personal data of third parties only after having duly informed them and obtained their consent to the processing.
2. TYPES OF DATA PROCESSED
The site collects and processes the following categories of data:
- Identification and contact data: Name, surname, e-mail address, telephone number, shipping and billing address.
- Payment data: Transactional information necessary to complete the purchase. Note: The Controller does not have access to nor store credit card data, which are managed exclusively by the payment gateways.
- Browsing and tracking data: Computer systems automatically collect data such as IP addresses, system logs and details on how the user interacts with the platform. The site also uses cookies and similar technologies for technical, analytical and marketing purposes; for the complete list and management of preferences, please refer to the dedicated Cookie Policy.
The provision of data marked with an asterisk (*) in the registration form (Name, Surname, Email, Password) is mandatory. Failure to enter these data will make it impossible to create the reserved area and to use the related services. The provision of the Telephone number is entirely optional. The user can register and use the site’s services even without providing this data. However, entering the telephone number becomes necessary if the user decides to activate communication services via WhatsApp.
Processing of data of minors (Art. 8 GDPR and Art. 2-quinquies of Legislative Decree 101/2018) The services on this Site and the sale of goods through our e-commerce platform are not intended for minors under 14 years of age. The User who proceeds with registration in the reserved area, the submission of orders or the granting of consent for marketing purposes (e.g. Newsletter) declares that they have reached the age of 14.
3. PURPOSES AND LEGAL BASES OF PROCESSING
The data are processed for the following purposes:
- Performance of a contract to which the data subject is party or of pre-contractual measures (Art. 6(1)(b) GDPR): Management of orders, shipment of products, management of pre-orders and customer assistance. This purpose expressly also covers the advanced services of the reserved area such as the creation and management of the Wishlist, the issuance, sending and redemption of Gift Cards / Gift Vouchers, as well as registration for the holding of tournaments, matches and other competitive events requested by the user.
- Legal obligations (Art. 6(1)(c) GDPR): Tax, accounting and regulatory obligations arising from online sales.
- Payment management (Art. 6(1)(b) GDPR): Processing of transactions through secure circuits.
- Direct marketing (Art. 6(1)(a) GDPR): Sending of commercial, promotional communications, notifications on offers, discounts and news regarding the Controller’s products and services, carried out through automated tools such as Email (Newsletter). The user may withdraw consent at any time via the unsubscribe link present in every communication.
- Performance of the sales contract (Art. 6(1)(b) GDPR) for customers who enter their telephone number for service communications via WhatsApp: Sending of strictly operational notifications linked to purchase orders, payment status, pre-order availability and shipment tracking information via the WhatsApp application.
- Security and Fraud Prevention (Art. 6(1)(f) GDPR): Based on the Controller’s legitimate interest in protecting the platform from unlawful activities.
4. SERVICE PROVIDERS AND PAYMENT MANAGEMENT
For the provision of services, the Controller communicates the data to the following parties, who operate as Processors or Independent Controllers:
- Hosting and Technical Infrastructure: Provider of the website hosting service.
- Payment Services:
- Stripe Technology Europe, Limited (STEL): For the management and secure processing of electronic payments by credit and debit cards enabled on the platform. The user’s credit card data neither transit nor are stored in any way on the servers of the Controller of this Site.
- PayPal: Management of payments via PayPal account and credit card circuit.
- Satispay: Direct mobile payments.
- Scalapay: Financing and instalment payment service. In this case, the data are communicated to Scalapay for creditworthiness assessment.
- Klarna: For deferred payment solutions.
- Logistics Services: Couriers in charge of product delivery.
5. TRANSFER OF DATA OUTSIDE THE EU
Where the processing involves the transfer of data to countries not belonging to the European Economic Area (e.g. via third-party services), such transfer will be regulated by the Data Privacy Framework or the Standard Contractual Clauses (SCCs) approved by the European Commission to ensure an equivalent level of protection.
6. RETENTION PERIOD
- Contractual and tax data: Retained for 10 years as required by current legislation.
- Marketing data: Retained until consent is withdrawn (opt-out).
- Technical data: Retained for the time strictly necessary for the provision of the service (e.g. abandoned cart).
7. RIGHTS OF THE DATA SUBJECT
Pursuant to Arts. 15-22 of the GDPR, the user may exercise the following rights:
- Access to their data and request for a copy.
- Rectification or erasure (Right to be forgotten).
- Restriction of processing or objection (e.g. for marketing purposes).
- Data portability in a structured format.
- Complaint: The user has the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
How to exercise the rights:
- The exercise of rights may be carried out through the contact details indicated in the Data Controller section.
- The request is free of charge and does not require any particular formalities. The Controller will provide a response within one month of the request.
- If the user believes that the processing of personal data is carried out in violation of the GDPR, they have the right to lodge a complaint with the Data Protection Authority via the website www.garanteprivacy.it or to take legal action before the competent courts.