Free worldwide express shipping on orders over €350 · Delivered chilled in 24–72h
Last updated: September 2026

Privacy Policy

This Privacy Policy explains how Ciacci Steaks, a brand of
Kilometro 25 di Ciacci Giovanni & C. S.a.s.,
collects, uses, stores and protects personal data when you visit our
website, place an order, contact us, subscribe to our communications or
otherwise interact with our services.

We process personal data in accordance with the General Data Protection
Regulation (EU) 2016/679 (“GDPR”), applicable Italian data protection
legislation and other applicable privacy requirements.

This website is operated in English and our online store ships worldwide.
Depending on where you are located, additional mandatory privacy
requirements may apply to the processing of your personal data.

Data Controller

The data controller responsible for the processing of personal data
described in this Privacy Policy is:

Kilometro 25 di Ciacci Giovanni & C. S.a.s.
Via Italo Svevo 39
61036 Colli al Metauro (PU)
Italy

VAT / Tax Code: IT02621710413
REA: PS-196515
PEC:

km25@pec.it

Legal Representative: Giovanni Ciacci

For privacy-related requests, you can contact us at:

privacy@ciaccisteaks.com

Personal Data We Collect

The personal data we collect depends on how you interact with our
website and services. Depending on the circumstances, this may include:

  • Name and surname.
  • Billing and delivery address.
  • Email address.
  • Telephone number.
  • Order details and purchased products.
  • Information contained in messages or customer service requests.
  • Newsletter subscription and communication preferences.
  • Technical information relating to your device and website usage.
  • Cookie and similar technology information, where applicable.

We only request information that is reasonably necessary for the relevant
purpose. Certain information is required to process an order or provide a
service, while other information is optional and may depend on your
consent.

Order and Customer Data

When you place an order, we process information such as your name,
delivery and billing address, email address, telephone number, order
details and the products purchased.

We use this information to process and fulfil your order, arrange
delivery, communicate with you about your purchase, provide customer
support, manage refunds or complaints and comply with our legal
obligations.

The primary legal basis for processing information necessary to fulfil
your order is the performance of the contract under Article 6(1)(b) GDPR.
Where processing is required to comply with a legal obligation, such as
accounting or tax requirements, the applicable legal basis is Article
6(1)(c) GDPR.

Payment Information

Payments made through our online store are processed by
Stripe, a third-party payment service provider.

We do not receive or store your full payment card number on our own
systems. Payment information is submitted directly to the relevant
payment provider and processed according to its applicable security,
privacy and payment-processing requirements.

Stripe may process information necessary to authorize and complete your
payment, prevent fraud and comply with applicable financial and legal
requirements.

For more information, please review the

Stripe Privacy Policy
.

Contact Forms and Customer Service

If you contact us through a contact form, email, telephone or another
customer service channel, we may process the information you provide,
including your name, contact details and the contents of your request.

We use this information to respond to your enquiry, provide customer
support, investigate order-related issues and communicate with you about
our services.

Depending on the nature of the request, the legal basis may be the
performance of a contract, steps taken at your request before entering
into a contract, compliance with a legal obligation or our legitimate
interest in responding to and managing customer enquiries under Article
6(1)(f) GDPR.

Contact form enquiries are generally retained for up to 24 months unless
a longer retention period is necessary because of an ongoing customer
relationship, legal obligation, dispute or other legitimate purpose.

Newsletter and Marketing Communications

If you subscribe to our newsletter or marketing communications, we may
process your email address to send you information about products,
offers, news and other content from Ciacci Steaks.

Marketing communications based on consent are sent only where the
applicable consent has been obtained. The legal basis for this processing
is your consent under Article 6(1)(a) GDPR.

You can withdraw your consent at any time by using the unsubscribe
mechanism included in our marketing communications or by contacting us.
Withdrawal of consent does not affect the lawfulness of processing carried
out before consent was withdrawn.

Your newsletter subscription data is retained until you unsubscribe or
otherwise request its deletion, unless we have another lawful basis or
legal obligation requiring continued retention.

Website Analytics and Cookies

We use technical information and cookies to operate, secure and improve
our website. Essential technologies may be used where necessary for the
operation of the website and online shop.

Optional analytics and marketing technologies are used only where the
applicable consent has been provided through our cookie preference
mechanism.

Depending on your choices, these services may include Google Analytics,
Meta advertising technologies and TikTok advertising technologies.

For detailed information about the cookies and similar technologies used
on this website and how to manage your preferences, please see our
Cookie Policy.

Legal Bases for Processing

Depending on the circumstances, we process personal data on one or more
of the following legal bases provided by Article 6 GDPR:

  • Contract: processing necessary to enter into or perform
    a contract with you, including processing and delivering your order.
  • Legal obligation: processing required to comply with
    applicable accounting, tax, consumer protection or other legal
    requirements.
  • Consent: processing for optional activities such as
    certain marketing, analytics or advertising activities where consent is
    required.
  • Legitimate interests: processing necessary for our
    legitimate business interests, such as responding to enquiries,
    maintaining website security, preventing fraud or managing and
    defending legal claims, provided that these interests do not override
    your rights and freedoms.

How Long We Keep Personal Data

We retain personal data only for as long as necessary to fulfil the
purposes for which it was collected, comply with applicable legal
obligations, resolve disputes and enforce or defend legal claims.

Order and transaction records may be retained for up to 10 years where
necessary to comply with applicable accounting and tax obligations.

Contact form information is generally retained for up to 24 months,
unless a longer period is necessary because of the nature of the request,
an ongoing customer relationship, a legal obligation or a dispute.

Newsletter data is retained until you withdraw your consent or unsubscribe,
unless another lawful basis or legal obligation requires continued
retention.

Different retention periods may apply to technical, security, payment,
accounting and other records depending on the applicable legal and
operational requirements.

Who We Share Data With

We do not sell your personal data. We may share personal data with
trusted service providers where this is necessary to operate our
business, provide our services, fulfil your order or comply with legal
obligations.

Depending on the service being provided, recipients may include:

  • Stripe — payment processing and payment-related
    services.
  • DHL, UPS and other delivery providers — shipment and
    delivery of orders.
  • Hosting and technical service providers — hosting,
    maintenance, security and operation of our website and systems.
  • Email and communication providers — transactional
    messages, customer service and, where applicable, newsletters.
  • Google — analytics services where the applicable
    consent has been provided.
  • Meta and TikTok — advertising and measurement services
    where the applicable consent has been provided.

Where service providers process personal data on our behalf, we take
appropriate contractual and organizational measures as required by
applicable data protection law.

International Data Transfers

Some of our service providers may process personal data outside the
European Economic Area (EEA). Where personal data is transferred outside
the EEA, we use an appropriate legal mechanism permitted under applicable
data protection law.

Depending on the destination and service provider, this may include an
applicable European Commission adequacy decision or Standard Contractual
Clauses, together with additional safeguards where required.

Further information about specific international transfers may be
available from the relevant third-party provider’s privacy documentation.

Data Security

We implement appropriate technical and organizational measures designed
to protect personal data against unauthorized access, accidental loss,
destruction, alteration or unlawful processing.

Access to personal data is limited to people and service providers who
need it for legitimate business, contractual or legal purposes.

However, no method of transmission or electronic storage can be
guaranteed to be completely secure. We therefore continuously review
appropriate security measures in light of the nature and risks of the
processing.

Your Privacy Rights

Subject to the conditions and limitations provided by applicable law, you
may have the following rights concerning your personal data:

  • Access: request confirmation as to whether we process
    your personal data and obtain a copy of the data.
  • Rectification: request correction of inaccurate or
    incomplete personal data.
  • Erasure: request deletion of personal data where the
    legal requirements for erasure are satisfied.
  • Restriction: request that processing be restricted in
    circumstances provided by law.
  • Data portability: receive certain personal data in a
    structured, commonly used and machine-readable format and, where
    technically feasible and legally applicable, request its transmission
    to another controller.
  • Objection: object to processing based on legitimate
    interests and, where applicable, object to direct marketing.
  • Withdrawal of consent: where processing is based on
    consent, withdraw that consent at any time. Withdrawal does not affect
    the lawfulness of processing carried out before withdrawal.

These rights are subject to the conditions and exceptions established by
the GDPR and applicable Italian law. The Italian Data Protection
Authority confirms that data subjects can exercise the rights provided
under Articles 15–22 GDPR by contacting the data controller. :contentReference[oaicite:1]{index=1}

How to Exercise Your Rights

To exercise your privacy rights or ask a question about how your personal
data is processed, contact us at:

Privacy Email:

privacy@ciaccisteaks.com

Please provide sufficient information for us to identify your request and,
where necessary, verify your identity before disclosing or changing
personal data.

We generally respond to valid requests without undue delay and, in
accordance with the GDPR, normally within one month of receiving the
request. Where permitted by law, this period may be extended by up to
two additional months because of the complexity or number of requests.
:contentReference[oaicite:2]{index=2}

Right to Lodge a Complaint

If you believe that the processing of your personal data violates
applicable data protection law, you may contact us first so that we can
investigate and address your concern.

You also have the right to lodge a complaint with the competent data
protection supervisory authority. In Italy, the relevant authority is:

Garante per la protezione dei dati personali
Piazza Venezia 11
00187 Rome, Italy


www.garanteprivacy.it

The Italian Garante provides procedures for submitting complaints where a
person considers that the processing of their personal data infringes the
GDPR. :contentReference[oaicite:3]{index=3}

Children’s Privacy

Our online services are intended for customers and visitors who are
legally able to use the services in accordance with applicable law. We do
not knowingly seek to collect personal data from children where such
collection is not permitted by applicable law.

If you believe that a child has provided us with personal data
unnecessarily or without the appropriate authorization, please contact us
at

privacy@ciaccisteaks.com

so that we can review the situation.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in
our services, the personal data we process, our service providers,
applicable legislation or our privacy practices.

When changes are made, the updated version will be published on this page.
We encourage you to review this Privacy Policy periodically to remain
informed about how we process personal data.

Contact Details

Data Controller:
Kilometro 25 di Ciacci Giovanni & C. S.a.s.

Registered Office:
Via Italo Svevo 39
61036 Colli al Metauro (PU)
Italy

VAT / Tax Code: IT02621710413
REA: PS-196515
PEC:

km25@pec.it

Privacy Requests:

privacy@ciaccisteaks.com

Customer Service:

info@ciaccisteaks.com

·

+39 0721 1796540

· Monday–Friday, 09:00–18:00 CET

Restaurant

Via Giuseppe Toniolo 25
61032 Fano (PU)
Italy


www.kilometro25.it