Privacy policy
Dear User, thank you for visiting our website. Below, we explain how the website is managed with regard to the processing of personal data of users who visit it.
This privacy notice is also provided pursuant to Article 13 of Legislative Decree No. 196/03 (Personal Data Protection Code) and Articles 13 and 14 of European Regulation 679/2016 (hereinafter also referred to as the “GDPR”) to those who interact with the web services provided directly by the Company. This notice applies to this website and not to any other websites that the user may access via links. This notice is based on Recommendation No. 2/2001, which the European data protection authorities, meeting within the Working Party established by Article 29 of Directive 95/46/EC, adopted on 17 May 2001 to set out certain minimum requirements for the online collection of personal data, and, in particular, the methods, timing and nature of the information that data controllers must provide to users when they access web pages, regardless of the purpose of the visit. We therefore invite you to read our Privacy Policy, set out below. The Privacy Policy and Standards used to protect personal data are based on the following principles:
A) DATA CONTROLLER
The data controller is the company whose contact details are provided in the footer of this website.
B) PRINCIPLE OF ACCOUNTABILITY
The processing of personal data is managed over time by data processors appointed within the company organisation.
C) PRINCIPLE OF TRANSPARENCY
Personal data is collected and subsequently processed in accordance with the principles set out in this Privacy Policy. At the time of any provision of data, the data subject is provided with a concise yet comprehensive information notice, in accordance with the provisions of Article 13 of Legislative Decree No. 196/03 and Articles 13 and 14 of the GDPR. PRINCIPLE OF RELEVANCE OF DATA COLLECTION.
Personal data is processed lawfully and fairly; it is collected for specific, explicit and legitimate purposes; it is relevant and does not go beyond the purposes of the processing; it is retained for the time necessary to fulfil the purposes for which it was collected.
D) PRINCIPLE OF PURPOSE LIMITATION
The purposes of the processing of personal data are disclosed to data subjects at the time of collection. Any new processing operations, if unrelated to the stated purposes, are carried out only after the data subject has been provided with a new privacy notice and, where required by Legislative Decree No. 196/03 and the GDPR, consent has been obtained. In any event, personal data shall not be disclosed to third parties or disseminated without the data subject’s prior consent, except in the cases expressly provided for in Article 24 of Legislative Decree No. 196/03 and the GDPR.
E) PRINCIPLE OF VERIFIABILITY
Personal data is accurate and kept up to date. It is also organised and stored in such a way as to enable the data subject, should they so wish, to ascertain which data has been collected and recorded, as well as to verify its quality and request any correction, supplementation or erasure on the grounds of a breach of the law or objection to processing, and to exercise all other rights, in accordance with and within the limits of Article 7 of Legislative Decree No. 196/03 and Article 15 et seq. of the GDPR, at the addresses indicated in the privacy notices pursuant to Article 13 of Legislative Decree No. 196/03 and Articles 13 and 14 of the GDPR, available on the Company’s website.
F) PRINCIPLE OF SECURITY
Personal data is protected by technical, IT, organisational, logistical and procedural security measures against the risks of destruction or loss, including accidental loss, and unauthorised access or unauthorised processing. These measures are periodically updated in line with technical progress, the nature of the data and the specific characteristics of the processing, and are constantly monitored and reviewed over time. Third parties carrying out support activities of any kind for the provision of services requested by the Company, in connection with which they process personal data, are designated by the Company as Data Processors and are contractually bound to comply with the security and confidentiality measures governing such processing. The identity of these third parties is disclosed to users. Furthermore, the Company accepts no liability for: the rules and methods governing the processing of personal data on other websites, which can be accessed from our pages via links and references;
The content of any email services, web spaces or chat forums provided to users.
Data processing relating to the web services offered by this website takes place at the Company’s premises and, where applicable, at the premises of the Data Processors; it is carried out by data processors responsible for managing the requested services, marketing activities – where requested by the user – data retention and occasional maintenance operations.
G) SCOPE OF DATA DISCLOSURE
The personal data provided may be disclosed to third parties in order to comply with legal obligations, in response to orders from public authorities duly authorised to issue such orders, or to assert or defend a right in court. Where necessary in relation to specific services or products requested, personal data may be disclosed to third parties who, acting as independent data controllers, perform functions strictly connected with and instrumental to the provision of the services or supply of the products. Without such disclosure, these services and products could not be provided. Personal data will not be disclosed to the public, unless required by the service requested.
H) DATA PROVIDED VOLUNTARILY BY THE USER
The types of personal data collected and processed on this website are those necessary for the provision of the various services offered. The data collected are processed using paper-based, automated and electronic methods, in accordance with procedures strictly related to the purposes of the processing. Your telephone number and email address may also be used to provide you with these services. It is therefore clear that, should such data not be provided, we will be unable to provide you with those services that require the use of these means of communication. Any voluntary sending of e-mails to the addresses indicated on the website entails the collection of the sender’s address as well as any other information contained in the message; such personal data will be used solely for the purpose of performing the service or task requested.
I) NAVIGATION DATA
It is worth noting that, during normal operation, the website’s software procedures collect certain personal data whose transmission is implicit in the use of internet communication protocols. Although this information is not intended to be associated with identified users, by its very nature, if combined with other data held by third parties (e.g. your internet service provider), it could enable users to be identified. This category of data includes the IP addresses or domain names of the computers used by users connecting to the website, the URL (Uniform Resource Locator) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the user’s operating system and IT environment. This data is used solely for the purposes of compiling anonymous statistics on the use of the website and to monitor its correct functioning. The Data Controller and, depending on the service requested, the designated Data Processors retain, for a limited period in accordance with the law, the log of connections and browsing activity carried out in order to respond to any requests from the judicial authorities or other public bodies authorised to request such logs for the purpose of establishing liability in the event of cybercrimes. Apart from what is specified regarding browsing data, the user is free to choose whether or not to provide the personal data requested in the service registration form. However, some fields on this form may be marked as mandatory; it should be understood that such data is necessary for the provision of the requested service. If this data is not provided, the requested service cannot be provided. At the time of any provision of data, in accordance with Article 13 of Legislative Decree No. 196/03 and Articles 13 and 14 of the GDPR, the data subject is provided with a brief but comprehensive and transparent information notice regarding the purposes and methods of processing, whether the provision of data is mandatory or optional, the consequences of failure to provide data, the individuals or categories of individuals to whom the personal data may be disclosed and the scope of such disclosure, the rights referred to in Article 7 of Legislative Decree No. 196/03 and Articles 15 et seq. of the GDPR (access, integration, updating, rectification, erasure for breach of law, objection to processing, etc.), and on the identity and registered office of the Data Controller and Data Processors. The data subject is therefore required to give their informed, free and specific consent, documented in the manner prescribed by law, where required by law. Should the provision of personal data take place in successive stages, additions may be made to the information notices previously provided, and new consents to processing may be requested in accordance with the Privacy Code and the GDPR.
L) SECURITY MEASURES IMPLEMENTED TO PROTECT THE DATA COLLECTED
The Company uses ‘secure’ architectures and technologies to protect personal data against unauthorised disclosure, alteration or misuse. The safeguards put in place for personal data are designed, in particular, to minimise the risks of destruction or loss – including accidental loss – of data, unauthorised access, or processing that is unauthorised or inconsistent with the purposes for which the data was collected. These security measures naturally meet the minimum requirements set out by the legislator (Technical Regulations on minimum security measures referred to in Articles 33 to 36 of Legislative Decree No. 196/03). Data subjects have the right at any time to obtain confirmation as to whether or not personal data concerning them exist, and to be informed of the content and origin of such data, to verify their accuracy, or to request that they be supplemented, updated or rectified (Article 7 of Legislative Decree No. 196/03 and Article 16 of the GDPR). Pursuant to the same article, the data subject has the right to request the erasure, anonymisation or blocking of data processed in breach of the law, as well as to object, in any case and on legitimate grounds, to the processing of such data. Requests should be addressed to the Company’s contact details indicated in the website footer.