Privacy Policy

Personal Data Processing

Bauli S.p.A. (hereinafter also only "Bauli"), in its capacity as Data Controller, informs you that browsing its websites and/or registering for the various sections of it and/or any requests for information or services require the provision of Personal Data that will be subject to processing in full compliance with European Regulation 2016/679 (hereinafter "GDPR"), the Privacy Code (Italian Legislative Decree 196/2003 as amended) and the provisions of the Italian Data Protection Authority.

Thanks to this policy, Data Subjects can find out how their Personal Data will be processed before browsing certain areas of the site attributable to Bauli S.p.A. and/or registering for competitions and/or newsletters.

Pursuant to the aforementioned regulations, this processing will be based on principles of correctness, lawfulness and transparency, protecting your privacy and your rights.

Amendments to this Policy

Bauli S.p.A. reserves the right to amend this policy at any time, informing Data Subjects directly on the specific web pages in the “Privacy Policy” section: We kindly ask you to consult this section on a regular basis, referring to the date of the last amendment indicated at the bottom.

If a Data Subject does not accept the changes made to this Policy, they may exercise their rights using the appropriate function in the reserved area or by making a request directly to the Data Controller, as indicated under the heading “Data Subject Rights”.

Unless otherwise specified, the previous Policy will continue to apply to the Personal Data collected up until that point.

The Data Controller and Data Processors

The Data Controller is Bauli S.p.A. with headquarters in Via Verdi 31, 37060 Castel D’Azzano (VR).

Bauli S.p.A. appointed a Data Protection Officer (DPO) that can be contacted by emailing to

The complete list of external Data Processors is available by writing to the Data Controller.

The purposes of the processing and the legal basis.

Depending on the needs expressed by the Data Subject at the time of accessing the contact services and/or the various sections of the websites attributable to Bauli S.p.A., the purposes of the processing of Personal Data are indicated below

The personal data processed may be those provided directly by the Data Subjects (including but not limited to: accessing Customer Service via telephone, filling in online forms, direct web or e-mail access), or those acquired automatically while browsing (hereinafter, "Personal Data"):

A1. Registering for the reserved area

Registration and access to the “Register/Login” sections on the websites attributable to Bauli S.p.A.;
Legal basis of the processing: implementation of pre-contractual measures or performance of a contract (Article 6.1.b of the GDPR).
A2. Participation in promotions, games and competitions

Any participation in promotions and/or games and/or competitions on Bauli S.p.A. websites, including the evaluation, allocation and communication of both the offer of digital discount coupons and the awarding of prizes;
Legal basis of the processing: implementation of pre-contractual measures or performance of a contract (Article 6.1.b of the GDPR).

A3. Customer service and “Contact” page

Responding to requests received from the contact channels used by Data Subjects, such as the Consumer Service, the “Contact Us” section (where present), the use of direct e-mails.
Legal basis of the processing: implementation of pre-contractual measures or performance of a contract (Article 6.1.b of the GDPR).
A4. Purchases on e-commerce platforms

Fulfilment of the obligations deriving from the stipulation of contracts for the purchase of products and services via e-commerce platforms attributable to Bauli S.p.A., as indicated in the specific Conditions of Sale
Legal basis of the processing: implementation of pre-contractual measures or performance of a contract (Article 6.1.b of the GDPR).

Marketing purposes distinct from the following points (B1-B2-B3) are described below to offer greater transparency only, therefore the consent necessary for the processing of personal data will be requested from users in a single form.

B1. Newsletters, sending of informative and promotional material and marketing activities
Carrying out marketing activities, including but not limited to: subscription to newsletters divided by brand, market research, sending information and promotional material, sending free product samples, marketing and advertising activities regarding Bauli S.p.A. products and services.
Legal basis of the processing: consent (Article 6.1.a of the GDPR).
B2. Market surveys on the quality of products and services

Determining the level of satisfaction of the Data Subject with the quality of the products, services rendered and the activity performed by Bauli S.p.A., carried out directly or through specialist companies by means of personal or telephone interviews, questionnaires etc.;
Legal basis of the processing: consent (Article 6.1.a of the GDPR).
B3. Statistical analysis for marketing activities

Statistical analysis for marketing purposes.
Legal basis of the processing: consent (Article 6.1.a of the GDPR).
B4. Profiling activities

Analysing consumption habits or choices and defining the profile of a Data Subject using:
a) The information provided at the time of registration;
b) The answers provided by filling in questionnaires;
c) Actions performed by the Data Subject while browsing the web;
d) Data relating to purchases made on e-commerce channels owned by or attributable to Bauli S.p.A.;
e) Interactions with the newsletter e-mails sent by Bauli S.p.A. in reference to the various brands;
f) Interactions with banners that sponsor Bauli and/or other brand products;
g) Interactions via social networks;
h) The use of digital coupons or receipts for the purchase of Bauli and/or other brand products;

Legal basis of the processing: consent (Article 6.1.a of the GDPR).
B5. Interaction with social networks

If the function is present, it allows the publication - by means of active and spontaneous behaviour from the interested party - of news and/or communications (hereinafter “posts”) generally directly on Bauli S.p.A. websites, or on sites managed independently by third parties, including but not limited to social networks such as Facebook, Twitter, YouTube, Instagram, TikTok etc. (hereinafter “Social Networks”).
Legal basis of the processing: consent (Article 6.1.a of the GDPR).
C1. Protection of rights and management of disputes

Management of contestations and any extrajudicial and/or judicial disputes.
Legal basis of the processing: legitimate interest (Article 6.1.f of the GDPR).
D1. Management of obligations required by law

Management and performance of the obligations to which the Data Controller is subject according to current legislation (relating to accounting, administration, tax etc.).
Legal basis of the processing: compliance with a legal obligation (Article 6.1.c of the GDPR).
D2. Supervision pursuant to Legislative Decree 231/2001

Auditing activities carried out by the Supervisory Body pursuant to Italian Legislative Decree 231/2001 on the prevention of administrative liability of entities with regard to crimes
Legal basis of the processing: compliance with a legal obligation (Article 6.1.c of the GDPR).

How data is processed and data security

Processing means “any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction”.

Personal Data will be processed mainly in an automated form but also on paper, in line with a logic strictly related to the aforementioned purposes, by way of example by:

  1. IT databases;
  2. electronic platforms managed by Bauli S.p.A. or by third parties appointed as Data Processors;
  3. integrated IT systems;
  4. websites owned or used by Bauli S.p.A.

The Data Controller has adopted suitable security measures to protect Data Subjects against the risk of loss, abuse or alteration of their Personal Data. Bauli S.p.A. and its suppliers undertake to maintain the physical, electronic and procedural security measures designed to protect Personal Data, in compliance with the requirements imposed by national and European legislation.

The duration of processing.

The data provided are kept for the time necessary to fulfil the specific purposes indicated above, in accordance with the principle of minimising processing, and precisely:

  1. For registration on the Bauli S.p.A. websites: maximum 36 months from the last documentable interaction.
  2. For signing up to newsletters or for other direct marketing purposes: maximum 24 months from the last documentable interaction (in accordance with the Provision of the Italian Data Authority dated 24/02/2005).
  3. For registering for competitions: for the time necessary to fulfil the legal obligation on the matter.
  4. For profiling activities: maximum 24 months.
  5. For purchase contracts through e-commerce platforms: for the period necessary to fulfil the obligations deriving from the contracts and demonstrate any legal obligations, until the end of the limitation period and forfeiture of rights.
  6. For requests for information from Customer Service: in relation to the type of request for the time necessary to reply to the Data Subject and in order to ensure a defence for the Data Controller.
  7. For dispute management: for its entire duration, until the expiry of the limitation period and/or time-barring of the action and/or the possibility of exercising legal remedies.

The location of processing and the contact details of the Data Controller.

Personal Data are mainly processed at the headquarters of the Data Controller, in Via Verdi n. 31, 37060 in Castel D’Azzano (VR) and/or in the company’s other offices and/or in the places in which the appointed Data Processors are located. For further information, Data Subjects can contact the Data Controller by e-mailing or by telephone, calling the toll-free number 800888166 (from Italy).

How Personal Data is provided by Data Subjects.

The provision of Personal Data is optional, but for certain purposes it is mandatory so that the Data Controller can meet the needs of the Data Subject: the fields relating to the mandatory Personal Data are highlighted during the phase in which they are entered or in any case are marked as such.

The partial, incorrect or non-provision of the Personal Data necessary for the requested service to be carried out means that it is not possible to provide said service and makes fulfilment impossible; the partial, incorrect or non-provision of optional Personal Data does not involve any consequence.

The Categories of Personal Data being processed.

The Data Processor only processes “common” Personal Data and under no circumstances requires the provision of special data pursuant to Article 9 of the GDPR.

In addition to the Personal Data provided directly, while registering on the Site, by Data Subjects (such as first name, surname, postal address, e-mail account, date of birth, data relating to electronic payment etc.), the IT systems and software procedures used to operate the Site itself automatically and indirectly administer and/or acquire certain information, the transmission of which is implicit in the use of internet communication protocols.

Reference is made, purely by way of example but not limited to, what are known as “cookies” (as specified in more detail below), “IP” addresses, domain names of the computers used by the Data Subjects who connect to the Site, the “URL” addresses of the requested resources, the geographical position.

If the Data Subject uses the authentication function via a Social Network, active for registration on the Site, access to the data of their Social Media account will be requested, specified in the appropriate “pop-up” window that is displayed at the time of the request, and there will be no need for the Data Subject to fill in other registration forms. Via social media platforms, the Data Subject can in any case always activate or deactivate the function that enables the transfer and sharing of any Personal Data provided autonomously and/or their social media experience to other websites or third-party applications. At any time, the Data Subject can deactivate data sharing from their social media account by accessing the settings of the relevant service provider.

Categories of subjects who may become aware of the Personal Data of Data Subjects.

Personal Data may be brought to the attention of employees or collaborators of the Data Controller who, operating under the direct authority of the latter, have received adequate operating instructions in this regard.
Personal Data will be processed by Bauli S.p.A. employees, with particular reference to the IT Systems, Marketing, Commercial and Compliance Areas.

Personal Data may also be brought to the attention of third-party companies or other subjects that carry out outsourced activities on behalf of Bauli S.p.A., and who - where required by European legislation on the protection of personal data - have been duly appointed as Data Processors pursuant to Article 28 of the GDPR. These are, by way of example and not limited to, subjects who are entrusted with assistance activities, communication, promotions and sales of products and/or services, organisation and management of promotional initiatives and competitions, competent authorities involved in the initiative and in sales via e-commerce, IT service providers, managers and/or developers of websites or applications, managers of electronic platforms, transport companies, service management companies etc.

For more information about the list of Bauli S.p.A. subsidiaries pursuant to Article 2359 of the Italian Civil Code, about the third-party companies to which the data may be communicated and about the Data Processors, Data Subjects can write to:

Further information about Personal Data.

Sap Customer Data Cloud (formerly Gigya)

This website uses SAP Customer Data Cloud (formerly Gigya), which is a registration and authentication service provided by SAP America Inc. In addition to its authentication capabilities, SAP Customer Data Cloud manages and in some cases analyses the identities of the Data Subjects in order to enable the web space manager to offer customised experiences. Bauli uses this service in order to offer customised experiences and to manage the registration of Data Subjects on the web pages on which this feature is active.

When a Data Subject logs in via SAP Customer Data Cloud, they are assigned an identification code (“BPS ID”) which could allow them to be identified.

For more information about the SAP Customer Data Cloud, you can visit the platform’s website.

Other third-party platforms

Bauli S.p.A. uses other third-party platforms that process the Personal Data of Data Subjects.

For a correct description of the platforms, of the data they collect and of the related purposes, Bauli S.p.A. has adopted the IT tool provided by Iubenda s.r.l. (, in order to guarantee the greatest possible clarity for Data Subjects.

At the link indicated below, it is possible to find details of the third-party platforms that process the Personal Data of Data Subjects, distinguished according to the different purposes:

Use of Cookies.

The complete Cookie Policy is available at this link:

Scope of dissemination of the Personal Data of Data Subjects.

Personal data will not be disseminated to third parties.

Transfer outside the EU of the Personal Data of Data Subjects.

Personal Data may be transferred to non-EU countries in compliance with the principles set out in the GDPR. Transfers will be based on a decision on adequacy, on the Standard Contractual Clauses approved by the European Commission or on another suitable legal basis.


Participation in the commercial activities offered by Bauli S.p.A. and registration in the Reserved Area of Bauli S.p.A. sites and those of its brands is reserved for adults only.

Participation in competitions that may be present on the websites of Bauli S.p.A. and its brands is intended exclusively for adults, by registering or logging in to the Reserved Area.

Data Subject rights

Data Subjects may at any time exercise the rights recognised by Article 7 and Articles 15 to 21 of the GDPR.
In particular:

  • For processing based on consent, without prejudice to the lawfulness of the processing carried out before the revocation, the Data Subject may at any time revoke the consent expressed previously by changing their preferences in the Reserved Area or by contacting the Data Controller directly.
  • The right of access: to obtain confirmation as to whether or not Personal Data concerning them are being processed and, where that is the case, access to said data and to specific information (e.g. purpose of the processing, categories of data in question, the recipients to whom the data will be communicated);
  • The right to rectification: to obtain the rectification of inaccurate data concerning them without undue delay. In this case, the Data Controller is obliged to communicate the rectification to all recipients to whom the data has been transmitted, unless this involves a disproportionate effort;
  • The right to erasure: to obtain the erasure of data concerning them, in the presence of certain conditions, without undue delay (e.g. Personal Data are no longer necessary in relation to the purposes for which they were collected; if a Data Subject revokes their consent; if they must be erased due to a legal obligation). In this case, the Data Controller is obliged to communicate the erasure to all recipients to whom the data has been transmitted, unless this involves a disproportionate effort;
  • The right to restrict processing: the Data Controller may be restricted in terms of data processing, for example to storage only with the exclusion of any other use, in certain cases (for example if the processing is unlawful and the Data Subject opposes the erasure of the data; if the Data Subject disputes the accuracy, within the limits of the accuracy verification period...). In this case, the Data Controller is obliged to communicate the processing restriction to all recipients to whom the data has been transmitted, unless this involves a disproportionate effort;
  • The right to data portability: to receive the Personal Data provided in a structured, commonly used and machine-readable format and for those data to be transmitted to another Controller without hindrance;
  • The right to oppose: to oppose the processing of personal data at any time, provided that there are no legitimate reasons which prevail over the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defence of a right in court.

Data Subjects can lodge a complaint with the competent Supervisory Authority in the event that they believe that their fundamental rights and freedoms have been violated, according to the methods, for example, indicated on the page

In order to exercise the aforementioned rights, as stated above, the attached form (link) can be posted to the address indicated in the “The Data Controller and Data Processors” section or by e-mail to:

In any case, after logging in, it is possible to modify the choices made independently and at any time and exercise the rights indicated above.

Links to third-party sites.

This policy only applies to sites owned by or attributable to Bauli S.p.A. and/or its brands and does not extend to other websites that may be consulted by the Data Subject via external links.

Bauli is not responsible for the policies applied by the linked sites or for the information or content contained therein. Links to other sites are present exclusively as points of information and/or in-depth analysis relating to certain topics that could be useful to Data Subjects.

Each external site has its own rules and policies, including with regard to Personal Data or cookie management: please read the statements present therein before proceeding with browsing, which remains entirely the responsibility of the Data Subject.

Links to third-party sites, or to any third-party product, publication process, service or offer, do not constitute or imply approval or recommendation of the products or services themselves by Bauli.

V 2.3 | 18-10-2021