Privacy Policy
Privacy Policy
Effective date: 25 August 2026
1. Who is responsible for your personal data?
The data controller is [INSERT LEGAL NAME OF THE CONTROLLER], with registered address at [INSERT REGISTERED ADDRESS] (“Shocolana Sale”, “we”, “us” or “our”).
Privacy contact: [INSERT PRIVACY EMAIL ADDRESS]. If a data protection officer has been appointed, their contact details will be provided here.
2. Scope of this Policy
This Policy explains how we process personal data when you visit this website, submit an inquiry, communicate with us about the business offer, or exercise your data-protection rights. It provides information required by Articles 12–14 of Regulation (EU) 2016/679 (the “GDPR”).
3. Personal data we process
- Inquiry data: your name, country, telephone number, email address and message.
- Communication data: subsequent correspondence and information you voluntarily provide.
- Technical data: IP address, browser and device information, timestamps, request logs and security-related data processed when the website or form service is accessed.
Please do not submit special-category or other unnecessary sensitive personal data through the form.
4. Purposes and legal bases
- To receive, assess and respond to your inquiry and take steps at your request before a possible agreement — Article 6(1)(b) GDPR.
- To manage business correspondence, prevent misuse, maintain website and form security, and establish, exercise or defend legal claims — our legitimate interests under Article 6(1)(f) GDPR.
- To comply with applicable legal and regulatory obligations — Article 6(1)(c) GDPR.
We do not use inquiry data for unrelated direct marketing without an appropriate legal basis.
5. Whether you must provide the data
Fields marked as required are necessary for us to receive and respond to your inquiry. If you do not provide them, the form cannot be submitted. You are not otherwise legally or contractually required to contact us through the form.
6. Recipients and service providers
Personal data may be disclosed only where necessary to:
- authorised persons working for or advising the controller;
- website hosting, infrastructure, email and security providers;
- Formspree, which processes and delivers website form submissions;
- Google Fonts infrastructure, which may receive technical request data when fonts are loaded;
- public authorities, courts or professional advisers where required by law or necessary for legal claims.
Service providers are required to process personal data only for the relevant service and subject to appropriate contractual, confidentiality and security obligations where required by law.
7. International transfers
Some service providers may process data outside the European Economic Area. Where GDPR Chapter V applies, transfers must rely on an adequacy decision or appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where necessary. You may request information about applicable safeguards by contacting us at the privacy address above.
8. Retention
Inquiry and related communication data is normally retained for up to 24 months after the last substantive contact. It may be retained longer where necessary to comply with law, document a transaction, resolve a dispute, or establish, exercise or defend legal claims. Technical and security logs are retained according to the relevant provider’s documented retention settings and only for as long as necessary for their purpose.
9. Your rights
Subject to the conditions and limitations in the GDPR, you may:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request erasure or restriction of processing;
- receive data you provided in a structured, commonly used and machine-readable format and request its transmission where data portability applies;
- object to processing based on legitimate interests, including direct marketing;
- withdraw consent where consent is the legal basis, without affecting earlier lawful processing;
- lodge a complaint with the supervisory authority in the EU/EEA country of your habitual residence, place of work or the alleged infringement.
To exercise a right, contact us using the privacy email above. We may request information reasonably necessary to verify your identity. We normally respond within one month, subject to the GDPR.
Competent lead supervisory authority, where applicable: [INSERT NAME AND CONTACT/LINK OF THE COMPETENT DATA PROTECTION AUTHORITY].
10. Automated decision-making
We do not use personal data submitted through the inquiry form for solely automated decisions that produce legal effects or similarly significantly affect you, and we do not perform profiling through the form.
11. Cookies and external resources
This website does not currently use analytics or advertising cookies. It loads fonts from Google Fonts and submits inquiries through Formspree; accessing these services may cause technical data, including your IP address, to be transmitted to those providers. If the website’s technologies change, this Policy and any required consent mechanism must be updated before the new technology is used.
12. Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. No internet transmission or storage system can be guaranteed to be completely secure.
13. Changes to this Policy
We may update this Policy when our processing activities or legal obligations change. The current version and effective date will be published on this page. Material changes will be communicated where required by law.