Blog
November 2025

Data protection 

sacred-soul.it collects personal data from its users.

This document can be printed out for storage purposes using the “Print” command in the browser.

 

Provider and responsible person

Martina Bocek

Bocek vGmbH

Via Bolzano 78

39011 Lana

 

E-mail address of the provider: info@sacred-soul.it

 

Types of data collected

Among the types of Personal Data that sacred-soul.it collects, by itself or through third parties, there are Usage Data; Cookies; email address; first name; last name; gender; phone number; company name; address; state; ZIP/Postal code; various types of Data; city; User ID.

 

Full details on each type of Personal Data processed are provided in the dedicated sections of this privacy policy or selectively through explanatory texts displayed before the Data is collected.

Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using sacred-soul.it.

Unless otherwise specified, the provision of all data requested by sacred-soul.it is mandatory. If the user refuses to provide the data, sacred-soul.it may not be able to provide its services to the user. In cases where sacred-soul.it expressly states that the provision of personal data is optional, users may choose not to provide such data without any consequences for the availability or functionality of the service.

Users who are unclear about which personal data is mandatory can contact the provider.

Any use of Cookies - or of other tracking tools - by sacred-soul.it or by the owners of third-party services used by sacred-soul.it serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy, if available.

 

Users are responsible for all personal data of third parties obtained, published or shared by sacred-soul.it and confirm that they have obtained consent to the transfer of personal data of any third parties to sacred-soul.it.

 

Nature and place of data processing

Processing methods

The provider processes user data in a proper manner and takes appropriate security measures to prevent unauthorized access and the unauthorized forwarding, modification or destruction of data.

Data processing is carried out using computers or IT-based systems in accordance with organizational procedures and practices that are specific to the purposes indicated. In addition to the Data Controller, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of sacred-soul.it (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Data Controller. A current list of these parties can be requested from the provider at any time.

 

Legal basis of the processing

The provider may only process users' personal data if one of the following applies:

  • Users have given their consent for one or more specific purposes. Note: In some jurisdictions, the provider may be permitted to process personal data until the user objects to such processing (“opt-out”), without having to rely on consent or any other of the following legal bases. However, this does not apply if the processing of personal data is subject to European data protection law;
  • the collection of data is necessary for the performance of a contract with the user and/or for pre-contractual measures arising therefrom
  • the processing is necessary for compliance with a legal obligation to which the provider is subject
  • the processing is related to a task carried out in the public interest or in the exercise of official authority vested in the provider
  • the processing is necessary for the purposes of the legitimate interests pursued by the provider or by a third party.

In any case, the provider will be happy to provide information about the specific legal basis on which the processing is based, in particular whether the provision of personal data is a legal or contractual obligation or a prerequisite for the conclusion of a contract.

 

Location

The data is processed at the provider's premises and at all other locations where the entities involved in the data processing are located.

 

Depending on the location of the users, data transfers may involve the transfer of the user's data to a country other than their own. To find out more about the place of processing of the transferred data, users can consult the section detailing the processing of personal data.

Users also have the right to obtain information about the legal basis for the transfer of Data to a country outside the European Union or to an international organization governed by public international law or established by two or more countries, such as the UN, as well as about the security measures taken by the Owner to protect their Data.

If such a transfer takes place, the User can find out more by checking the relevant sections of this document or by contacting the Owner using the information provided in the contact section.

 

Storage period

Personal data is processed and stored for as long as required for the purpose for which it was collected.

 

The following therefore applies:

  • Personal data collected for the purpose of fulfilling a contract concluded between the provider and the user will be stored until this contract has been completely fulfilled.
  • Personal data collected to protect the legitimate interests of the provider will be retained for as long as necessary to fulfill these purposes. Users can obtain more information about the legitimate interests of the Owner in the relevant sections of this document or by contacting the Owner.

In addition, the Owner may retain Personal Data for longer periods of time if the User has consented to such processing, as long as the consent is not withdrawn. Furthermore, the provider may be obliged to store personal data for a longer period of time if this is necessary to fulfill a legal obligation or by order of an authority.

 

After the retention period has expired, personal data will be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be asserted after the retention period has expired.

 

Purposes of the processing

Personal data about the User is collected to enable the Provider to provide the Service and also to comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of Users or third parties), detect malicious or fraudulent activity. In addition, data is collected for the following purposes: Tag management, analytics, managing contacts and sending messages and contacting the user.

 

Users can find more detailed information on these processing purposes and the Personal Data used for each purpose in the “Detailed information on the processing of Personal Data” section of this document.

 

Detailed information on the processing of personal data

Personal data is collected for the following purposes using the following services:

 

Analytics

The services listed in this section allow the Owner to monitor and analyze traffic and track Users' behavior.

 

Google Analytics with IP anonymization (Google Ireland Limited)

Google Analytics is a web analytics service provided by Google Ireland Limited (“Google”). Google uses the Data collected to track and examine how sacred-soul.it is used, to compile reports on its activities and share them with other Google services.

Google may use the data collected to contextualize and personalize the ads of its own advertising network.

IP anonymization has been activated on this website so that the IP address of Google users within member states of the European Union or in other contracting states of the Agreement on the European Economic Area is shortened beforehand. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there.

Processed personal data: Cookie; usage data.

Processing location: Ireland - Privacy Policy.

 

Contacting the user

Mailing list or newsletter (sacred-soul.it)

By subscribing to the mailing list or newsletter, the User's e-mail address will be added to the contact list of people who may receive e-mail messages containing commercial or promotional information relating to sacred-soul.it. In addition, your e-mail address may be added to this list if you have subscribed to sacred-soul.it or after you have made a purchase.

 

Processed personal data: E-mail; gender; surname; first name.

 

Contact form (sacred-soul.it)

By filling in the contact form with their Data, the User authorizes sacred-soul.it to use these details to reply to requests for information, quotes or any other kind of request as indicated by the form's header.

Personal Data processed: Address; User ID; email address; last name; company name; ZIP/Postal code; state; city; phone number; various types of Data; first name.

 

Tag management

This type of service helps the Owner to centrally manage the tags or scripts needed on sacred-soul.it.

This results in the user's data flowing through these services and possibly being stored.

 

Google Tag Manager (Google Ireland Limited)

Google Tag Manager is a tag management service provided by Google Ireland Limited.

Personal data processed: Usage data.

Processing location: Ireland - Privacy Policy.

 

Managing contacts and sending messages

These types of services allow the management of a database of email contacts, phone numbers or any other contact information to communicate with the user.

The services may also collect data about the date and time messages were read by the user, as well as when the user interacts with incoming messages, for example by clicking on links contained therein.

 

CleverReach (CleverReach GmbH & Co. KG)

CleverReach is a service provided by CleverReach GmbH & Co. KG for the management of e-mail addresses and the sending of messages.

Personal data processed: Email.

Place of processing: Germany - Privacy Policy.

 

Further information on personal data

This service is not intended for children under the age of 13

The user declares to be of legal age in accordance with the applicable legislation. Minors may only use sacred-soul.it under the supervision of a parent or guardian. Persons under the age of 13 may not use sacred-soul.it under any circumstances.

 

The rights of users

Users may exercise certain rights in relation to their data processed by the provider.

In particular, users have the right to do the following:

  • Revoke consent at any time. If the user has previously consented to the processing of personal data, they can withdraw their consent at any time.
  • Object to the processing of their data. The user has the right to object to the processing of their data if the processing takes place on a legal basis other than consent. Further information on this is provided below.
  • Obtain information about their data. The user has the right to know whether the data is being processed by the provider, to receive information about individual aspects of the processing and to receive a copy of the data.
  • Verification and rectification. The user has the right to verify the accuracy of their data and to request that it be updated or corrected.
  • Request restriction of the processing of their data. Users have the right to restrict the processing of their data under certain circumstances. In this case, the provider will not process the data for any purpose other than storage.
  • Request erasure or other removal of personal data. Under certain circumstances, users have the right to request that the provider erase their data.
  • Receive your data and have it transferred to another controller. The user has the right to receive their data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transmitted to another controller without hindrance. This provision applies where the data is processed by automated means and the processing is based on the user's consent, on a contract to which the user is party or on pre-contractual obligations.
  • Lodge a complaint. Users have the right to lodge a complaint with the competent supervisory authority.

 

Details on the right to object to processing

If personal data is processed in the public interest, in the exercise of an official authority vested in the provider or to safeguard the legitimate interests of the provider, the user may object to this processing by providing a justification relating to their particular situation.

Users are informed that they can object to the processing of personal data for direct marketing purposes at any time without giving reasons. Users can find out whether the provider processes personal data for direct marketing purposes in the relevant sections of this document.

 

How the rights can be exercised

All requests to exercise User rights may be addressed to the Owner using the contact details provided in this document. Requests can be exercised free of charge and will be processed by the Owner as soon as possible and within one month at the latest.

 

Cookie policy

sacred-soul.it uses trackers. Further information can be found in the cookie policy.

 

Further information on the collection and processing of data

Legal measures

The User's personal data may be processed by the Owner for the purpose of taking legal action within or in preparation for legal proceedings arising from improper use of sacred-soul.it or related services.

The User declares to be aware that the Provider may be required by the authorities to disclose personal data.

 

Further information about the User's personal data

In addition to the information contained in this privacy policy, sacred-soul.it may provide the User with additional contextual information concerning particular Services or the collection and processing of Personal Data upon request.

 

System logs and maintenance

For operation and maintenance purposes, sacred-soul.it and third-party services may collect files that record interaction with sacred-soul.it (System logs) or use other Personal Data (e.g. IP Address) for this purpose.

 

Information not contained in this privacy policy

Further information about the collection or processing of personal data can be requested from the provider at any time using the contact details provided.

 

How "Do Not Track" requests are handled

sacred-soul.it does not support "Do Not Track" requests through web browsers.

Users can find information on whether integrated third-party services support the Do Not Track protocol in the privacy policy of the respective service.

 

Changes to this privacy policy

The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within sacred-soul.it and/or - as far as technically and legally feasible - sending a notice to Users via any contact information available to the Owner. Users are therefore advised to visit this page regularly and in particular to check the date of the last change indicated at the bottom of the page.

If changes affect the use of data based on the user's consent, the provider will - if necessary - obtain new consent.

 

Definitions and legal information

Personal information (or data)

All information by which the identity of a natural person is or can be determined, either directly or in conjunction with other information.

 

Usage data

This information includes the country of origin, the functions of the browser and operating system used by the user, the various time details per request (e.g. how much time was spent on each page of the application) and details of the path followed within an application, in particular the sequence of pages visited, as well as other information about the device's operating system and/or the user's IT environment.

 

User

The person using sacred-soul.it who, unless otherwise specified, coincides with the data subject.

 

Data subject

The natural person to whom the personal data relates.

 

Processor (or data processor)

Natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller, as described in this privacy policy.

 

Controller (or provider, sometimes also owner)

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of sacred-soul.it. Unless otherwise specified, the controller is the natural or legal person through whom sacred-soul.it is offered.

sacred-soul.it (or this application)

The hardware or software tool used to collect and process the User's Personal Data.

 

Service

The service offered by sacred-soul.it as described in the relevant terms of use (if any) and on this page/application.

 

European Union (or EU)

Unless otherwise stated, all references in this document to the European Union refer to all current Member States of the European Union and the European Economic Area (EEA).

 

Cookies

Cookies are trackers that consist of a small set of data stored in the user's browser.

 

Tracker

The term tracker refers to any technology - e.g. cookies, unique identifiers, web beacons, embedded scripts, e-tags or fingerprinting - that can track users, e.g. by enabling access to or storage of information on the user's device.

 

Legal notice

This Privacy Policy has been drafted on the basis of provisions of various legislations, including Art. 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation).

This privacy policy relates solely to sacred-soul.it, if not stated otherwise within this document.

Continue shopping