(PRIVACY)

Privacy notice

This notice explains what personal data we collect through this website, why, and what you can ask us to do about it. It is given under art. 13 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003. The Italian version of this page is the authoritative one; this translation is provided for convenience.

Who is responsible

The data controller is «ragione sociale», «sede legale», VAT number «P.IVA».

For anything concerning your personal data, write to «email». We have not appointed a Data Protection Officer, as we are not required to.

What we collect

What you give us, by filling in the enquiry form:

  • the name you enter;
  • the contact you choose (phone, email or Telegram);
  • your message, if you write one;
  • which page and language you sent it from, and when.

What the site collects on its own: server logs, needed to deliver pages and to keep the site from being abused. Your IP address is used in the moment to throttle automated submissions, but it is not stored alongside your enquiry.

Cookies and similar tools are covered by the cookie policy.

Why, and on what legal basis

  • To answer your enquiry and prepare a quote. Legal basis: steps taken at your request before entering into a contract, art. 6(1)(b) GDPR. Without a name and a way to reach you we cannot reply, which is why those two fields are required and the message is not.
  • To run the site securely and stop automated submissions. Legal basis: our legitimate interest in keeping the service available and not buried in spam, art. 6(1)(f) GDPR.
  • For statistics and marketing, only if and when we switch those tools on and you accept them. Legal basis: your consent, art. 6(1)(a) GDPR, which you can withdraw at any time.

We do no profiling and no automated decision-making.

Who processes data for us

Your enquiries are stored privately and can be read only by us, after signing in. We rely on providers acting as processors under art. 28 GDPR:

  • Cloudflare, Inc. — website hosting, storage of enquiries, aggregate statistics;
  • Telegram FZ-LLC — delivers the notification that a new enquiry has arrived.

We do not sell your data and do not pass it to third parties for their own purposes. We may disclose it to the authorities where the law requires it.

Transfers outside the EU

Cloudflare, Inc. is based in the United States and is certified under the EU-US Data Privacy Framework; processing is additionally governed by an agreement incorporating the European Commission’s standard contractual clauses.

Telegram FZ-LLC is based in the United Arab Emirates, a country with no adequacy decision from the European Commission. The notification we receive may contain the name and contact you entered. If you would rather your data did not travel that way, write to us at «email» instead of using the form.

How long we keep it

  • Enquiries: 24 months from our last contact with you, then deleted. If the enquiry becomes a contract, the related documents are kept for the periods Italian tax and civil law require (as a rule, 10 years).
  • Server logs: as long as security requires, normally no more than 12 months.
  • Cookie consent: your choice stands for 6 months, then we ask again.

You can ask us to delete your data sooner at any time.

Your rights

At any time you may ask us:

  • to give you access to your data and a copy of it (arts. 15 and 20);
  • to correct it, if it is wrong or incomplete (art. 16);
  • to erase it (art. 17);
  • to restrict how it is used (art. 18);
  • to object to processing based on our legitimate interest (art. 21);
  • to withdraw a consent you have given, without affecting what was done before (art. 7(3)).

Write to «email». We answer within one month; if a request is complex we may take two more, and we will tell you.

Complaints

If you believe your data is being handled unlawfully, you can complain to the Italian supervisory authority, the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, or go to court.

Security and children

The site is served over an encrypted connection (HTTPS) only. Enquiries are stored in an area that is not publicly reachable and can be read only after signing in; administrative access is password-protected and rate-limited.

The site is not aimed at children and we do not knowingly collect data from anyone under 14. If we find that we have, we delete it.

Changes

We may update this notice, for instance if the tools we use change. The version in force is always the one published here, with its date at the foot of the page. If a change affects the purposes you consented to, we ask you again.