Here is the professional English translation of your privacy policy, structured with clear headings and tables for readability.

Privacy Notice on the Processing of Personal Data

This privacy notice is provided pursuant to Art. 13 of Regulation (EU) 2016/679 (hereinafter “GDPR”) to those who interact with the website Eurosmalt.it.

This notice is provided solely for the aforementioned website and does not apply to any other websites that the user may consult via links.

1. Data Controller

EUROSMALT HQ S.r.l. Unipersonale

Via Cercone 11/A – 24060 Castelli Calepio (BG) – Italy

VAT and Tax Code: IT03942360169

Phone: +39 035 4425814

Email: info@eurosmalt.it

2. Types of Data Processed

2.1 Data voluntarily provided by the user

Through the “Request information” form on the Contacts page, the website collects the following data:

  • Name

  • Phone number

  • Email address

  • Subject of the request and message content

Providing this data is necessary to respond to your request. Additional personal data may be processed if the user voluntarily includes it in the body of the message.

The optional, explicit, and voluntary sending of emails to the contact addresses indicated on the website (info@eurosmalt.it, tecnico@eurosmalt.it, amministrazione@eurosmalt.it) entails the subsequent acquisition of the sender’s address, as well as any other personal data included in the communication.

2.2 Browsing data

During their normal operation, the computer systems and software procedures used to operate this website acquire certain personal data, the transmission of which is implicit in the use of Internet communication protocols. This category of data includes: IP addresses, browser type and operating system, domain names, URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server’s response, and other parameters relating to the user’s operating system and computer environment.

This data is used solely to obtain anonymous statistical information on website usage and to check its correct functioning. It is kept in the server logs only for the time strictly necessary and may be used to establish liability in the event of hypothetical computer crimes against the website.

2.3 Cookies and tracking tools

For detailed information on the cookies used by the website and how to manage your preferences, please refer to our Cookie Policy.

3. Purposes and Legal Bases of the Processing

Purpose Legal Basis
Responding to requests for information and quotes sent via the contact form or email Performance of pre-contractual measures taken at the request of the data subject – Art. 6(1)(b) GDPR
Management of any commercial relationship established following the request Performance of a contract – Art. 6(1)(b) GDPR
Ensuring the correct functioning and security of the website Legitimate interest of the Data Controller in securing its infrastructure – Art. 6(1)(f) GDPR
Compliance with statutory legal, accounting, and tax obligations Legal obligation – Art. 6(1)(c) GDPR
Statistical analysis of website usage through measurement tools Consent of the data subject – Art. 6(1)(a) GDPR
Establishment, exercise, or defense of legal claims Legitimate interest of the Data Controller – Art. 6(1)(f) GDPR

Note: The Data Controller does not process data collected through the website for direct marketing, profiling, or sending unsolicited commercial communications.

4. Nature of Data Provision

Providing the data marked as mandatory in the contact form is necessary to allow the Data Controller to respond to your request. Failure to provide this data will make it impossible to receive a reply.

Providing data for statistical analysis purposes is optional and subject to the user’s consent, which can be freely withdrawn at any time. Refusal to provide consent does not affect browsing the website or contacting the Data Controller in any way.

5. Processing Methods

Data is processed using electronic and, where necessary, paper-based tools, implementing appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in compliance with Art. 32 GDPR, and to prevent unauthorized access, loss, destruction, or unauthorized disclosure of the data.

Processing is carried out by the Data Controller’s personnel who have been specifically authorized and instructed in accordance with Art. 29 GDPR, as well as by external parties appointed as Data Processors pursuant to Art. 28 GDPR.

6. Retention Period

Data Category Retention Period
Data collected via the contact form and email communications, in the absence of a contractual relationship 24 months from the last contact.
Data relating to established contractual relationships 10 years from the termination of the relationship, in compliance with statutory legal, accounting, and tax obligations (Art. 2220 of the Italian Civil Code).
Browsing data contained in system logs 30 days.
Data collected via cookies and measurement tools According to the durations specified in the Cookie Policy.

Upon expiry of the specified retention periods, the data will be deleted or irreversibly anonymized, without prejudice to any further retention that may be required to establish, exercise, or defend a legal claim.

7. Recipients and Categories of Recipients

Personal data may be communicated to:

  • IT service providers, appointed as Data Processors pursuant to Art. 28 GDPR:

    • 1&1 IONOS – provider of domain, hosting, and email services, acting as a sub-processor. Servers are located within the European Economic Area (EEA).

    • Google Ireland Limited – for statistical measurement and map visualization services, subject to the user’s consent. Please see the Cookie Policy.

  • Consultants and professionals engaged by the Data Controller for accounting, tax, and legal compliance.

  • Public authorities and supervisory bodies, in cases provided for by law.

Under no circumstances is the data sold or transferred to third parties for marketing purposes.

8. Data Transfers Outside the EU

The use of services provided by Google Ireland Limited may involve the transfer of personal data to the United States of America. Such transfers are carried out based on the adequacy decision adopted by the European Commission regarding the EU-U.S. Data Privacy Framework, to which Google LLC adheres, and alternatively on the Standard Contractual Clauses approved by the European Commission, supplemented by additional safety measures.

9. Automated Decision-Making

The Data Controller does not adopt automated decision-making processes, including profiling, that produce legal effects concerning the data subject or similarly significantly affect them, pursuant to Art. 22 GDPR.

10. Rights of the Data Subject

The data subject has the right to obtain from the Data Controller, in the cases and within the limits provided for by Articles 15–22 of the GDPR:

  • Access (Art. 15): Confirmation as to whether or not personal data concerning them is being processed, and a copy of such data.

  • Rectification (Art. 16): Correction of inaccurate data or completion of incomplete data.

  • Erasure / “Right to be forgotten” (Art. 17): Deletion of data, in the cases provided for by law.

  • Restriction of processing (Art. 18).

  • Data Portability (Art. 20): Receiving the data in a structured, commonly used, and machine-readable format, and transmitting it to another controller.

  • Objection (Art. 21): Objecting to processing based on the legitimate interest of the Data Controller.

  • Withdrawal of Consent (Art. 7.3): Withdrawing consent at any time for processing based on consent, without affecting the lawfulness of processing based on consent before its withdrawal.

Requests may be submitted to the Data Controller at info@eurosmalt.it. The Data Controller will provide a response without undue delay and, in any case, within one month of receipt of the request. This period may be extended by two further months where necessary, taking into account the complexity of the request, in which case the data subject will be informed.

11. Right to Lodge a Complaint

If the data subject considers that the processing of personal data relating to them infringes the GDPR, they have the right to lodge a complaint with a supervisory authority, pursuant to Art. 77 GDPR:

Garante per la protezione dei dati personali

Piazza Venezia 11 – 00187 Rome, Italy

Phone: +39 06 696771

Email: garante@gpdp.it

PEC (Certified Email): protocollo@pec.gpdp.it

The right to bring proceedings before the competent judicial authority remains unaffected.

12. Changes to this Privacy Notice

The Data Controller reserves the right to modify this privacy notice at any time, notifying users by publishing the updated version on the website. Users are encouraged to consult this page periodically.

Last updated: November 22, 2021