Privacy Policy
Privacy Policy
This privacy policy describes the methods of processing personal data of users who browse and use this website (hereinafter, the “Application”), in compliance with the current legislation on personal data protection, with particular reference to the Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and the applicable national legislation.
This information is provided pursuant to Articles 13 and 14 of the GDPR and is intended for all users who interact with the Application, regardless of the purpose of navigation.
1. General principles of processing
The processing of personal data is based on the principles of:
- lawfulness, fairness, and transparency;
- purpose limitation;
- data minimization;
- accuracy and updating;
- storage limitation;
- integrity and confidentiality;
- accountability of the Data Controller.
Personal data are processed exclusively for specific, explicit, and legitimate purposes and are not further processed in a manner incompatible with those purposes.
2. Types of personal data processed
The Application may process the following categories of personal data:
a) Browsing data
The computer systems and software procedures used to operate the Application acquire, during their normal operation, some data whose transmission is implicit in the use of Internet communication protocols.
This category includes, by way of example: IP addresses, domain names of the devices used, request times, method used to submit requests to the server, size of files obtained in response, server status codes, operating system parameters, and the user's computing environment.
b) Data voluntarily provided by the user
The optional, explicit, and voluntary sending of personal data through forms, contact forms, registrations, or other tools entails the acquisition of the data provided by the user, necessary to fulfill the requests made.
c) Data related to the use of services
In the case of using digital services, software, or advanced features, data related to access, use, and management of the service may be processed, within the strictly necessary limits.
3. Purpose of processing
Personal data are processed for the following purposes:
- allow navigation and proper functioning of the Application;
- provide the services requested by the user;
- comply with legal and regulatory obligations;
- manage requests for assistance and support;
- ensure the security of the Application;
- perform aggregated statistical analysis;
- carry out communication and marketing activities, where provided and within the limits allowed by law.
4. Legal basis of processing
The processing of personal data is based on one or more of the following legal bases:
- execution of a contract or pre-contractual measures;
- compliance with legal obligations;
- legitimate interest of the Data Controller, adequately balanced;
- consent of the data subject, where required.
5. Processing methods and security measures
Data processing is carried out using IT and telematic tools, with logic strictly related to the purposes pursued and in compliance with the security measures provided by the GDPR.
Appropriate technical and organizational measures are adopted to ensure a level of security commensurate with the risk, in order to prevent unauthorized access, disclosure, loss, destruction, or unlawful use of personal data.
6. Data retention
Personal data are retained for the time strictly necessary to achieve the purposes for which they were collected, unless different legal obligations or needs to protect the rights of the Data Controller exist.
At the end of the retention period, the data will be deleted or anonymized.
7. Data communication and dissemination
Personal data are not disseminated.
They may be communicated to third parties acting as Data Processors or independent Data Controllers, within the strictly necessary limits and in compliance with current legislation.
8. Data transfer to third countries
If personal data are transferred to countries located outside the European Union or the European Economic Area, the transfer will take place in compliance with the guarantees provided by the GDPR, such as adequacy decisions, standard contractual clauses, or other legitimate instruments.
9. Rights of the data subject
The data subject may exercise, within the limits and under the conditions provided by the GDPR, the following rights:
- right of access;
- right to rectification;
- right to erasure;
- right to restriction of processing;
- right to data portability;
- right to object;
- right to withdraw consent.
The exercise of rights can be made by request to the Data Controller, without formalities.
10. Right to lodge a complaint
The data subject who believes that the processing of personal data is carried out in violation of the applicable legislation has the right to lodge a complaint with the Data Protection Authority or to take legal action in the competent courts.
11. Minors
The Application is not intended for minors under the age limits provided by the current legislation. The Data Controller does not knowingly collect personal data of minors without the consent of those exercising parental responsibility.
12. Changes to this policy
The Data Controller reserves the right to modify or update this policy at any time. Changes will be published on this page and will become effective from the date of publication.
13. Scope of application
This policy applies exclusively to this Application and does not extend to websites, platforms, or third-party services that may be accessible via external links.