Privacy policy
Last updated: 27 September 2026
This policy is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), the Italian Personal Data Protection Code (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018) and the measures of the Italian Data Protection Authority (Garante per la protezione dei dati personali). It concerns visitors to www.solobio.com, people who contact me, retailers using the ordering area and contact persons of businesses I approach to offer the products of the companies I work for.
The website is intended for businesses. Data about companies as such are not personal data; data about the individuals who represent or work for them (for example the name, email or phone number of an owner or contact person) and about sole traders are.
1. Data controller
Bashoo di Lorenzo Cesario (sole trader), acting as a commercial intermediary for organic food companies
Via Raffaele Paolucci 4, 70033 Corato (BA), Italy
VAT no. IT08416920729
Phone: +39 345 743 1732
Email: ![]()
Or through the contact form.
No Data Protection Officer (DPO) has been designated, as this is not mandatory for this activity under Art. 37 GDPR.
2. What data I process, why, on what basis and for how long
a) Browsing and website security
Data: IP address, browser and device type, pages visited, date and time of access, login attempts to the reserved area.
Purpose: to run the website, protect it from attacks, spam and unauthorised access, and fix technical problems.
Legal basis: legitimate interest of the controller in the security and proper functioning of the website (Art. 6(1)(f) GDPR).
Retention: for the technically necessary time, normally no longer than 12 months, unless needed to investigate unlawful activity.
b) Enquiries via contact form, email, phone or WhatsApp
Data: name, company, email, phone, subject, message and any attached files (for example catalogues or price lists).
Purpose: to answer enquiries from customers, retailers and producers proposing a business collaboration, and to assess a possible collaboration.
Legal basis: pre-contractual steps taken at your request (Art. 6(1)(b) GDPR) and legitimate interest in managing the business contacts received (Art. 6(1)(f) GDPR).
Retention: up to 24 months from the last contact, unless a business relationship is established (in which case section c applies).
Files attached to the form are sent to my mailbox and deleted immediately from the website server. Please do not send unnecessary personal data or special categories of data (for example health data).
c) Retailer area, orders and business relationships
Data: company name, VAT number, tax code, e-invoicing recipient code (SDI), IBAN, business and delivery address, contact person, email, phone, login credentials, order details and any documents uploaded for verification (chamber of commerce certificate, optional identity document of the owner or legal representative).
Purpose: to verify that the request comes from a business based in Puglia or Basilicata, manage the account, collect orders and forward them to the principal companies for opening the customer account, fulfilment and invoicing, and manage the business relationship and any disputes.
Legal basis: performance of pre-contractual measures and of the contract (Art. 6(1)(b) GDPR); compliance with civil and tax law obligations (Art. 6(1)(c) GDPR).
Retention: for as long as the account and the business relationship last; accounts inactive for more than 24 months are closed. Verification documents are kept only as long as needed for verification and transmission to the principal company, and in any case no longer than 12 months. Order data and records relevant for civil or tax purposes are kept for up to 10 years (Art. 2220 of the Italian Civil Code).
The principal companies (Euro Company, Econoce brand, and Azienda Agricola Durante, Le Spinèe brand) receive the data needed for the order and process them as independent controllers under their own privacy policies.
d) Contact persons of businesses approached for the first time (Art. 14 GDPR)
Data: business name, address, phone, email, website and, where available, the name of the owner or contact person.
Purpose: to present the products of the companies I work for and arrange sales visits.
Legal basis: legitimate interest in developing my business with other professional operators (Art. 6(1)(f) GDPR). Promotional messages by email, SMS or WhatsApp are sent only with the consent of the person concerned (Art. 130 of the Italian Privacy Code); phone calls made by a person comply with the Italian public opt-out register (Registro pubblico delle opposizioni) and with any objection you raise.
Retention: up to 24 months from collection or from the last contact if no relationship arises; immediately upon objection, except for keeping your contact details in a suppression list so that you are not contacted again.
Source of the data: publicly available sources, such as business listings on Google Maps, business websites and social media pages, public lists and registers, including data collected through public-data extraction services, or details provided directly during visits, trade fairs and events. You receive this notice at the first contact and can object at any time, with immediate effect.
e) Monthly promotions and commercial communications
Data: email, name, phone and business name.
Purpose: to send retailer promotions and product news by email or WhatsApp.
Legal basis: consent (Art. 6(1)(a) GDPR and Art. 130 of the Italian Privacy Code), given when subscribing to the newsletter or expressly requested (also verbally, by email or WhatsApp). Customers who have already ordered may receive offers on similar products by email without prior consent, within the limits of Art. 130(4) of the Italian Privacy Code, after being informed and with the option to object in every message.
Retention: until you withdraw consent or object, which you can do at any time by replying to the message (for example writing “stop”), using the unsubscribe link or writing to me. Promotional emails are sent with recipients in blind copy.
f) Statistics, marketing and external content (cookies)
The website uses Google Analytics for visitor statistics, the Meta Pixel to measure campaigns on Facebook and Instagram, and embedded YouTube videos. These tools are activated only after your consent through the cookie banner (Art. 6(1)(a) GDPR, Art. 122 of the Italian Privacy Code and the Italian Data Protection Authority guidelines of 10 June 2021); without consent, only strictly necessary technical cookies are used. You can change or withdraw your choices at any time from the preferences panel. Details are in the Cookie Policy (in Italian).
For the collection and transmission to Meta of the data captured by the Pixel, the controller and Meta Platforms Ireland Ltd act as joint controllers (Court of Justice of the EU, case C-40/17 Fashion ID), on the basis of the joint controller addendum provided by Meta; further processing is the sole responsibility of Meta. You can also exercise your rights directly against Meta.
g) Spam protection
The website forms are protected by Google reCAPTCHA and Akismet, which analyse some data (for example IP address, behaviour on the page and message content) to tell people apart from automated programs. Legal basis: legitimate interest in website security (Art. 6(1)(f) GDPR).
h) Legal obligations and protection of rights
Data may be processed to comply with legal obligations or requests from authorities (Art. 6(1)(c) GDPR) and, where necessary, to establish, exercise or defend legal claims (Art. 6(1)(f) GDPR), for the period required by law or until the dispute is settled.
3. Providing your data
Fields marked as required in the forms are needed to reply or to activate an account: without them I cannot follow up on your request. All other data are optional. Consent to promotional communications and to non-technical cookies is always optional and does not affect your use of the website or your ability to order.
4. How data are protected
The website uses an encrypted connection (HTTPS), limits login attempts to the reserved area, displays email addresses as images to reduce spam and runs regular backups. Access to the data is restricted to the controller, with personal credentials. I apply technical and organisational measures appropriate to the risk (Art. 32 GDPR). No decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects are made (Art. 22 GDPR).
5. Who receives the data
Data are not sold or passed on to third parties for their own marketing. They may be received, only as far as necessary, by:
- processors (Art. 28 GDPR) acting on my behalf: Aruba S.p.A. (website hosting and email, Italy), Cloudflare Inc. (content delivery and website security), Google (Analytics), Automattic Inc. (Akismet);
- independent controllers, for the services they provide under their own terms and privacy policies: Google (Gmail, also used to send promotions, storage of backups on Google Drive, reCAPTCHA, YouTube), Meta (WhatsApp; for the Pixel see section 2.f), providers of IT tools supporting my work, including artificial-intelligence assistants for drafting and managing correspondence;
- the companies I work for, as independent controllers, for the orders and enquiries concerning them;
- my accountant and other advisers, bound by professional secrecy;
- authorities and public bodies, where required by law.
The CRM software I use to organise contacts and visits is installed on my own computer and is not hosted by third parties.
6. Transfers outside the European Union
Some providers (Google, Meta, Cloudflare, Automattic) may process data in the United States. Transfers are based on the European Commission adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, for certified companies, and in any case on the standard contractual clauses approved by the Commission (Art. 46 GDPR), which the providers adopt as an additional safeguard. You can ask me for information on the safeguards in place.
7. Your rights
At any time and free of charge you can ask to:
- access your data and receive a copy (Art. 15);
- rectify or complete them (Art. 16);
- erase them (Art. 17);
- restrict processing (Art. 18);
- receive them in a structured, machine-readable format and transmit them to another controller (portability, Art. 20);
- object to processing based on legitimate interest on grounds relating to your particular situation and, at any time and without giving reasons, to direct marketing (Art. 21);
- withdraw any consent given, without affecting the lawfulness of earlier processing (Art. 7(3)).
To exercise your rights, use the contact form or write to the address in section 1. I will reply without undue delay and in any case within one month, extendable by two months for complex requests (Art. 12). I may ask for information to verify your identity.
If you believe the processing breaches the law, you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it (Art. 77 GDPR), or with the supervisory authority of the EU country where you live or work, or bring legal proceedings (Art. 79 GDPR).
8. Minors
The website is intended for businesses and is not directed at persons under 18. I do not knowingly collect data from minors.
9. Changes
This policy may be updated following changes in the law, in my organisation or in the website; the date of the latest update is shown at the top. This is a translation of the Italian privacy policy; in case of discrepancies, the Italian version prevails.

