Privacy Policy
PERSONAL DATA PROCESSING NOTICE (PRIVACY POLICY)
Provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679
FRESH TRADE ONLINE S.R.L.
Registered and operating office: Rome, Italy ([full address: _____]).
VAT number and Tax Code: [to be assigned: ].
Economic and Administrative Index (REA) No.: [].
Website: www.freshtrade.online. Privacy contact: privacy@freshtrade.online. Certified electronic mail (PEC): [_____].
Last updated: 22 June 2026. Effective date: 22 June 2026.
1. Introduction and purpose of this document
FRESH TRADE ONLINE S.R.L. attaches substantial importance to the protection of the personal data of those who come into contact with the FreshTrade private trading network (hereinafter, the “Platform”). By means of this notice, provided in its capacity as data controller and in compliance with Regulation (EU) 2016/679 (hereinafter, the “GDPR”) and with Legislative Decree No. 196 of 30 June 2003 (Personal Data Protection Code), as amended by Legislative Decree No. 101 of 10 August 2018, the Company describes, in a transparent manner, the categories of data processed, the purposes and legal bases of the processing, the recipients, the retention periods, and the rights recognised to data subjects. The document applies to the data collected through the website www.freshtrade.online, during the application process, and over the entire course of the membership relationship, and is to be read together with the Cookie Policy and the Terms and Conditions of use.
2. Data controller and Data Protection Officer
The data controller is FRESH TRADE ONLINE S.R.L., with registered office in Rome, contactable at the details set out in the heading. In view of the nature of the processing operations, which include the systematic monitoring of commercial counterparties and the assessment of creditworthiness, the Company has appointed a Data Protection Officer, reachable at the address dpo@freshtrade.online. Any request concerning the processing of one’s data may alternatively be addressed to the mailbox privacy@freshtrade.online.
3. B2B scope and categories of data subjects
The Platform is reserved to professional operators, so the data processed predominantly concern legal persons, which fall outside the scope of the GDPR. Personal data protection legislation nevertheless applies in respect of the natural persons who act in the name and on behalf of the member or applicant undertakings. The following are therefore data subjects of the processing: the legal representatives, directors, partners, commercial and operational contacts, and employees of the undertakings that submit an application or accede to the network, as well as visitors to the website and persons who send contact requests. In the case of sole proprietorships or self-employed professionals, the company data may coincide with personal data and receive the same protection.
4. Categories of personal data processed
The processing may concern the following types of data, collected directly from the data subject or from the undertaking to which they belong, or acquired from accessible third-party sources:
• Identification and contact data: name, surname, company role, professional e-mail address, telephone contacts, and identifying details of the contact person.
• Company data attributable to natural persons: company name, registered office, tax code or VAT number, and identifying data in the case of sole proprietorships or professional firms.
• Creditworthiness and reputational data: economic, financial, and commercial reliability information acquired through specialised providers, also referable to company owners or representatives.
• Payment data: information necessary for the collection of fees and commissions, handled through payment gateways, without the Company storing the complete details of the instruments used.
• Platform usage data: access logs, activity on the directory and on the RFQ Board, content of requests for quotation, and communications exchanged within the network.
• Browsing data: IP address, device identifiers, and data collected through cookies or similar technologies, as described in the Cookie Policy.
5. Purposes of the processing and relevant legal bases
The data are processed for the purposes set out below, each based on a distinct legal basis pursuant to Article 6 of the GDPR:
• Management of the application and due diligence: assessment of the request for accession, verification of corporate identity, and admission procedure, on the basis of the performance of pre-contractual measures requested by the data subject (Article 6(1)(b)) and of the legitimate interest of the Company in preserving the integrity of the network (Article 6(1)(f)).
• Verification of creditworthiness and reputation: acquisition and analysis of commercial information through third-party providers, on the basis of the legitimate interest of the Company and of the other Members in operating in an environment of reliable counterparties, following a documented balancing by means of a Legitimate Interest Assessment, consistent with EDPB Guidelines 1/2024.
• Performance of the membership contract: activation of the profile, provision of the network services, management of requests for quotation, and assistance, on the basis of the performance of the contract (Article 6(1)(b)).
• Administrative, accounting, and tax obligations: invoicing, payment management, and document retention, on the basis of the legal obligation incumbent on the controller (Article 6(1)(c)).
• Platform security and prevention of abuse: monitoring aimed at ensuring technical integrity and at preventing fraud or unlawful use, on the basis of the legitimate interest of the controller (Article 6(1)(f)).
• Commercial communications and direct marketing: sending of updates, sector reports, and proposals relating to services similar to those subscribed to, on the basis of legitimate interest within the limits of marketing between professional operators, or, where required, of the consent of the data subject (Article 6(1)(a)), revocable at any time.
• Defence in legal proceedings and exercise of rights: processing aimed at the establishment, exercise, or defence of a right in judicial proceedings, on the basis of the legitimate interest of the controller.
6. Nature of the provision of data
The provision of identification, contact, and company data, and of the data necessary for the verification and management of the relationship, is mandatory for the purposes of assessing the application and of providing the services; refusal to provide them entails the impossibility of acting upon the request for accession or of continuing the relationship. The provision of data for marketing purposes based on consent is, by contrast, optional, and refusal does not prejudice access to the network.
7. Creditworthiness and reputational verification: clarifications
In view of the importance that the verification activity has in the FreshTrade model, specific indications are provided regarding the related processing. The assessment of creditworthiness is conducted through specialised providers of commercial information, including Creditsafe, to which the Company communicates the identifying data of the undertaking and of its representatives in order to obtain summary reliability indices. Such indices, indicative in nature and referring to the moment of collection, may be made visible in aggregate form to the other Members as an informative element of the network. The processing does not entail the formation of assessments of a punitive content, nor registration in centralised credit information systems managed by the Company, and is based on legitimate interest, balanced against the rights and freedoms of data subjects according to the parameters referred to in Article 5 above.
8. Methods of processing and security measures
The processing is carried out with predominantly automated tools, according to logics correlated to the purposes indicated, and in compliance with the principles of lawfulness, fairness, minimisation, and storage limitation laid down by Article 5 of the GDPR. The Company adopts technical and organisational measures appropriate within the meaning of Article 32, including encryption of sensitive data in transit and at rest, multi-factor authentication, access segregation, periodic backup, and business-continuity procedures. The acquisition of recognised security certifications, such as the ISO/IEC 27001 standard, is envisaged within the third year of activity.
9. Recipients of the data and data processors
The data may be communicated, within the limits of the purposes described, to the following categories of recipients: providers of technological and cloud-hosting services that host the Platform; providers of creditworthiness and reputational verification; operators of payment systems; providers of transactional e-mail, analytics, and assistance services; the Company’s legal, tax, and accounting advisers; and the competent authorities, where required by law. The parties that process data on behalf of the controller are appointed as data processors within the meaning of Article 28 of the GDPR, by means of agreements governing their obligations and safeguards. The data are not subject to indiscriminate dissemination, save for visibility within the reserved network in accordance with the functionalities described in the Terms and Conditions.
10. Transfers of data to third countries
Some of the controller’s providers, including the operators of the cloud infrastructure, of payments, and of verification services, are established in or process data in the United States of America or in other countries outside the European Economic Area. Every transfer takes place solely in the presence of appropriate safeguards within the meaning of Chapter V of the GDPR. In particular, transfers to certified United States providers are based on the adequacy decision relating to the EU-US Data Privacy Framework, adopted by the European Commission on 10 July 2023 and still in force; for recipients that are not certified or that are established in other third countries, the Company resorts to the Standard Contractual Clauses approved by Implementing Decision (EU) 2021/914 of 4 June 2021, supplemented where necessary by additional measures, or to the derogations provided for by Article 49 of the GDPR. The data subject may request a copy of the safeguards adopted by writing to the privacy contact details indicated.
11. Data retention period
The data are retained for the time strictly necessary to achieve the purposes for which they are processed. Data relating to an unsuccessful application are retained for the period useful to document the decision and to defend any claims, and in any case for no longer than twenty-four months. Data connected to the membership relationship are retained for the entire duration of the relationship and for the ten years following its termination, in compliance with the civil-law and tax obligations set out in Article 2220 of the Italian Civil Code. Data processed for marketing purposes are retained until the withdrawal of consent or the exercise of the right to object, and in any case for no longer than twenty-four months from the last contact. Once the periods have elapsed, the data are erased or irreversibly anonymised.
12. Rights of the data subject
In relation to the data processed, the data subject may exercise the rights recognised by Articles 15 to 22 of the GDPR, and in particular:
• Right of access: to obtain confirmation of the existence of processing and a copy of the data concerning them.
• Right to rectification: to obtain the correction of inaccurate data and the integration of incomplete data.
• Right to erasure: to obtain the removal of the data in the cases provided for by Article 17, where no retention obligations apply.
• Right to restriction: to obtain the suspension of processing in the cases set out in Article 18.
• Right to portability: to receive, in a structured format, the data provided and to transmit them to another controller, where technically feasible.
• Right to object: to object, on grounds relating to their particular situation, to processing based on legitimate interest, and, in any event and without need for justification, to processing for direct-marketing purposes.
• Right to withdraw consent: to withdraw at any time the consent given, without prejudice to the lawfulness of the processing carried out beforehand.
Requests are to be sent to the details referred to in Article 2, and receive a response without undue delay, and in any event within one month, extendable in cases of particular complexity.
13. Absence of solely automated decision-making
The reliability indices and scoring tools made available within the network have an informative and decision-support function. The controller does not take decisions producing legal effects or similarly significantly affecting the data subject based solely on automated processing, within the meaning of Article 22 of the GDPR. Decisions on admission, suspension, or exclusion always involve the evaluative intervention of the Company’s personnel.
14. Cookies and tracking technologies
The website uses technical cookies necessary for its operation and, subject to consent collected through the dedicated banner, analytics and profiling cookies. The types employed, the purposes, and the methods for managing preferences are described in the Cookie Policy, accessible from the domain and forming an integral part of this notice.
15. Amendments to this notice
The controller reserves the right to update this notice in order to adapt it to supervening regulatory, organisational, or technological needs. Material amendments are brought to the attention of data subjects through publication on the domain and, where appropriate, by direct communication. Data subjects are invited to consult the document periodically; its date of last update, shown in the heading, attests to the version in force.
16. Complaint to the Supervisory Authority
Without prejudice to any other administrative or judicial remedy, a data subject who considers the processing of their data to be unlawful has the right to lodge a complaint with the competent supervisory authority. For Italy, the authority is the Garante per la protezione dei dati personali, with offices in Rome, Piazza Venezia No. 11, reachable through the website www.garanteprivacy.it, pursuant to Article 77 of the GDPR and Article 141 of the Personal Data Protection Code.
