Privacy Policy EN

PRIVACY POLICY

Thank you for your interest in our website. The protection of your personal data is very important to us. Below you will find information on how we handle the data collected through your use of our website. Your data is processed in accordance with the statutory provisions on data protection.

If you interact with us in your capacity as a consumer, supplier, business partner, job applicant, visitor or any other person who maintains or is interested in a business relationship with us, you can find our specific privacy policy for business partners by clicking on the LINK below.

Introduction and general information

Thank you for your interest in our website. The protection of your personal data is very important to us. Below you will find information on how we handle the data collected when you access our website. Your data will be processed in accordance with the statutory provisions on data protection.

1. Data controller

The data controller within the meaning of the General Data Protection Regulation is:

NIHON KOHDEN FIRENZE S.r.l.

Via Torta, 72/74

50019 Sesto Fiorentino, Florence

NIHON KOHDEN FIRENZE S.r.l. is part of the group of companies managed in Europe by NIHON KOHDEN EUROPE GmbH (“NKE Group”), one of the world’s leading suppliers of medical devices.

NIHON KOHDEN EUROPE GmbH is also responsible for the information relating to other companies within the NKE Group on its website, including:

  • NIHON KOHDEN DEUTSCHLAND GmbH
  • NIHON KOHDEN FRANCE Sarl
  • NIHON KOHDEN IBERICA S.L.
  • NIHON KOHDEN ITALIA S.r.l.
  • NIHON KOHDEN UK Ltd.
  • NIHON KOHDEN FIRENZE S.r.l.

2. Contact details of the Data Protection Officer

You can contact the Data Protection Officer at

Proliance GmbH
www.proliance.ai

Data Protection Officer
Leopoldstr. 21
80802 Munich

Email: datenschutzbeauftragter@proliance.ai

When contacting the Data Protection Officer, please indicate the company to which your request relates. Please also refrain from attaching sensitive information to your request, such as a copy of your identity document.

3. General information on data transfers to third countries

If necessary, your data may also be processed in countries outside the European Union (EU) and the European Economic Area (EEA).

For data transfers to certain third countries, an adequacy decision of the European Commission pursuant to Art. 45(1) GDPR may exist. Such a decision establishes that an adequate level of data protection exists in the third country. A list of adequacy decisions adopted to date is available at the following link: Adequacy decisions on data protection for non-EU countries.

The scope of an adequacy decision may also be limited to a specific category of recipients or subject to the fulfilment of additional requirements.

For example, the adequacy decision for data transfers to the United States applies only to companies certified under the EU-U.S. Data Privacy Framework. The certification status of a participating company can be checked at the following link: Participant Search (dataprivacyframework.gov).

If your data is transferred to recipients located in third countries for which no adequacy decision exists, there is a risk that local authorities may access your data for security and surveillance purposes without your knowledge or the possibility of legal recourse.

In order to ensure an adequate level of data protection when your data is transferred to recipients in such third countries, we therefore ensure that appropriate safeguards pursuant to Art. 46 GDPR are in place.

Accordingly, both we and the service providers commissioned by us regularly conclude the European Commission’s standard contractual clauses pursuant to Art. 46(2)(c) GDPR. These clauses oblige the data recipient in the third country to process the data in accordance with the European level of protection. The clauses can be consulted at the following link: Publications on standard contractual clauses (SCCs) – European Commission. Should you require further information on the modules of the standard contractual clauses concluded by us in individual cases or on the supplementary measures adopted, we will be happy to provide you with a copy. In this case, please simply contact us using the contact details provided above under “Controller”.

For certain recipients, data transfers may also be based, pursuant to Art. 46(2)(b) GDPR, on approved binding corporate rules (BCRs). These can be consulted at the following link: Approved Binding Corporate Rules | European Data Protection Board.

Where standard contractual clauses or binding corporate rules are not sufficient to ensure the required level of protection, additional technical, contractual, or organisational measures are adopted to ensure the security of the data transfer. Furthermore, it is regularly reviewed and assessed whether these supplementary measures continue to ensure an adequate level of data protection or whether additional measures must be adopted where necessary.

Further information on data transfers to third countries is available, where relevant, at the end of the page in the sections relating to data processing or the services used, under the heading “Data processing in third countries”.

4.  Data protection information for website visitors

4.1. Data processing in connection with web hosting

4.1.1. Usage data and server log files

Description of data processing and purpose

When you visit our website, it is technically necessary for data to be transmitted between your internet browser and our systems in order to enable communication. During an active connection for communication between the internet browser and the web server, the following data is regularly collected:

  • IP address of the requesting device (router or mobile device),
  • date and time of the request,
  • name of the requested file,
  • website from which the file was requested (referrer URL),
  • access status,
  • amount of data transferred,
  • web browser and operating system used,
  • language used.

The data listed above is stored in log files and analysed where necessary.

The purpose of the data processing and our legitimate interest consist in ensuring a smooth connection between your internet browser and our website, as well as a technically flawless provision of our services, and in detecting, preventing, and tracing attacks on our website. The log files serve to assess the stability, functionality, and security of the system. The processing of this data is absolutely necessary in order to make the website available to you.

Legal basis for data processing

The data processing is based on Art. 6(1)(f) GDPR (legitimate interest of the controller in the security and proper functioning of the website).

Recipients

In the context of the data processing, your data is disclosed to the following categories of recipients or to recipients that we use in the context of the data processing in order to achieve the stated purposes:

  • hosting service and IT infrastructure providers
  • maintenance and technical support service providers
  • providers of security tools and log analysis tools (where used)

In the event of anomalies or attacks, the data may also be disclosed, in individual cases, to:

  • cybersecurity consultants and forensic IT experts
  • lawyers,
  • investigative authorities,
  • courts.

Our website is hosted on infrastructure operated by IONOS SE. The server is located in Germany, within the European Union.

Data processing in third countries

In connection with the hosting of this website, personal data is processed within the European Union and is not transferred to third countries.

Retention period

For reasons of technical security, in particular to defend ourselves against attempts to attack our web server, this data is stored by us for a short period. Within 7 days at the latest, the data is anonymised by shortening the IP address at domain level so that it is no longer possible to establish a link to the individual user.

In specific cases, in the event of attacks or attempted attacks, the data may be stored for a longer period to the extent necessary until the conclusion of investigative or judicial proceedings or for the assertion of legal claims.

In anonymised form, the log file data may be retained and further processed for statistical purposes.

4.1.2. Authorisation checks during login

Description of data processing and purpose

When you access a restricted area of our website, we process your access data (username and password) to ensure that only authorised persons can log in.
In order to ensure that no unauthorised person can access the protected area and to identify, clarify, and prevent misuse of access data in the future, we store the following data in log files:
• username
• IP address of the router or end device from which access took place
• time of access
• subpages visited within the restricted area
• failed login attempts
• functions used within the restricted area
The log files are reviewed and assessed at regular intervals or in the event of anomalies.
Cookies and similar techniques, in particular JavaScript, may be used to store and read data on your device. Further details are available above under “Data processing in connection with cookies and similar techniques”.
The purpose of the data processing and our legitimate interest consist in being able to identify, clarify, and prevent misuse of your access data.

Legal basis for data processing

To the extent that we use cookies and similar techniques in connection with the integration of the service or to the extent that the service stores data on your device or reads it from it, this takes place pursuant to Art. 122 of the Italian Privacy Code (Legislative Decree No. 196/2003 – “Privacy Code”). Subsequent data processing is based on Art. 6(1), first sentence, lit. f GDPR.

Recipients

In the context of the data processing, your data will be disclosed to the following categories of recipients or to recipients that we use in the context of the data processing in order to achieve the stated purposes:

  • hosting and cloud infrastructure service providers,
  • website management and maintenance service providers,
  • software service providers that make log data analysis solutions available to us (log file data).

In the event of anomalies or attacks, the data may also be disclosed, in individual cases, to:

  • cybersecurity consultants and forensic IT experts
  • lawyers,
  • investigative authorities,
  • courts.

Data processing in third countries

Your data may be transferred to recipients in third countries.

For data transfers to the USA, the European Commission has adopted an adequacy decision pursuant to Article 45 of the GDPR for organisations certified under the EU-U.S. Data Privacy Framework.

Retention period

The data is processed for as long as necessary to achieve the stated purposes, up to a maximum of 90 days. In individual cases, in the event of attacks or attempted attacks, the data may be retained for a longer period to the extent necessary until the conclusion of investigative or judicial proceedings or for the assertion of legal claims.

4.2. Data processing in connection with cookies and similar technologies

4.2.1. Access to and storage of information on end devices

The use of our website may involve access to information (e.g. IP address) or the storage of information (e.g. cookies) on users’ devices. Such access or storage may involve further processing of personal data under the GDPR.

Where such access to information or such storage of information is strictly necessary for the technically correct provision of our services, this takes place on the basis of Art. 122 of the Italian Privacy Code (Legislative Decree No. 196/2003 – “Privacy Code”), in conjunction with Art. 6(1)(c) or (f) GDPR, as applicable.

Where such operation serves other purposes (e.g. personalisation of our website according to your needs), it is carried out on the basis of Art. 122 of the Italian Privacy Code only with your consent. Consent may be withdrawn at any time with effect for the future.

Where the use of cookies or similar technologies is intended for additional purposes, such as statistical analysis or content personalisation, the processing is based on the user’s consent pursuant to Art. 122 of the Privacy Code and Art. 6(1)(a) GDPR.

Consent may be withdrawn at any time with effect for the future.

4.2.2. Cookies and similar technologies

4.2.2.1. General information

On this website we use services that employ cookies and similar techniques to store data in the browser of your device and read data already stored there. For this purpose, cookies, your browser’s local storage, pixels, and so-called tags may be used.

Cookies are small text files that can be stored and read on your device.

A distinction is made between session cookies, which are deleted as soon as you close your browser, and persistent cookies, which are stored for a specific period beyond the individual session.

In addition to cookies, we may use session storage or local storage in the user’s browser to store and read data.

In addition, we may integrate pixels on our websites. Pixels are small custom and invisible image files that are loaded when the page is loaded and can be used to track user activities.

Finally, we may use tags on our websites. Tags are small snippets of HTML or JavaScript code or markers that allow website analytics or user tracking services to distinguish or identify users and track certain user activities.

Further information on the cookies and similar techniques used by us is provided below in the descriptions of the cookie categories and in our consent management platform, which is displayed when you visit our website. Through the platform you can give your consent and easily withdraw it.

You can access the platform again at any time via the “cookie icon” at the bottom left at the end of the web page to change your settings.

Please note that without the use of certain cookies and similar techniques, our websites may not be displayed correctly and some functions may no longer be technically available

4.2.2.2. Necessary Category

The services in this category may use cookies and similar technologies to store and read information on your device. We use them for the purpose and in the interest of:

  • allowing the display of the website and providing its basic functions, in particular navigation between pages and access to restricted areas,
  • allowing the granting and withdrawal of consent,
  • protecting our forms from abusive entries and protecting our website against cyberattacks and fraud attempts.

The use of the services, as well as the related cookies and similar technologies in this category, takes place on the basis of Art. 122 of the Italian Privacy Code. Subsequent data processing takes place on the basis of Art. 6(1), first sentence, lit. f GDPR.

4.2.2.3.Functional Category

Services or external content and media from third-party providers in this category may use cookies and similar technologies to store and read information on your device. We use them:

  • to allow the loading of content and media from third-party providers,
  • to make our web pages attractive and manage them efficiently,
  • to make certain settings and additional website functions available to you.

The use of the services, as well as the related cookies and similar technologies in this category, takes place on the basis of the user’s consent pursuant to Art. 122 of the Italian Privacy Code. Subsequent data processing takes place on the basis of the user’s consent pursuant to Art. 6(1), first sentence, lit. a GDPR.

4.2.2.4. Statistics Category

The services in this category may use cookies and similar technologies to store and read information on your device. We use them:

  • to identify and distinguish you as an individual website visitor and to carry out statistical analyses of your interactions with and use of our websites,
  • to design our websites according to users’ needs and adapt them to user interactions,
  • to test changes to the website and measure users’ reactions (A/B testing),
  • to monitor the technical functionality of our website and enable error correction.

For this purpose, we and the services regularly store individual pseudonymous identifiers (recognition features) composed of numbers and letters on your device via cookies when you visit our website and read them again when you visit it again.

The use of pseudonyms allows users to be individually distinguished and recognised. However, the natural person behind a pseudonym generally cannot be directly identified, in particular by name, without additional data.

Other technologies may also regularly be used to read recognition features from your device, such as so-called browser or device fingerprinting, whereby data relating to the characteristics of the browser you use (e.g. type and version of browser) and its configuration (e.g. preferred language), the characteristics of your device (e.g. manufacturer and model of your mobile phone, operating system) or the hardware you use (e.g. screen resolution) are used to recognise you pseudonymously as a distinct user.

The use of the services, as well as the related cookies and similar technologies in this category, takes place on the basis of your consent pursuant to Art. 122 of the Italian Privacy Code. Subsequent data processing takes place on the basis of your consent pursuant to Art. 6(1), first sentence, lit. a GDPR.

4.2.2.5. Marketing Category

The services in this category may use cookies and similar technologies to store and read information on your device. We use them:

  • to identify and distinguish you as an individual website visitor and to carry out statistical analyses of your interactions with and use of our websites,
  • to track your interactions with advertisements published by us on other websites via third-party providers across different devices and websites (so-called “conversion tracking”),
  • to reconstruct and evaluate your interactions with our website and subsequently use them as the basis for targeted advertising campaigns on advertising networks, directed at you or at a specific target group of which you are part (so-called retargeting and remarketing),
  • to improve the effectiveness of our advertising measures and manage our advertising campaigns.

For this purpose, when you visit another website or our website, individual pseudonymous identifiers composed of numbers and letters are regularly stored on your device, both for us and for the services, in cookies, which are then read again when you revisit this or another website.

Other technologies may also regularly be used to read recognition features from your device, such as so-called browser or device fingerprinting, whereby data relating to the characteristics of the browser you use (e.g. type and version of browser) and its configuration (e.g. preferred language), the characteristics of your device (e.g. manufacturer and model of your mobile phone, operating system) or the hardware you use (e.g. screen resolution) are used to recognise you pseudonymously as a distinct user.

If necessary, the processed pseudonymous recognition data may also be combined by us or by the service providers used with other data.

In this way, the services used by us and their providers may exchange and compare recognition features (IDs) with one another in order, in the event of a match, to merge the features and assign them to the same pseudonymous user (so-called ID matching/ID syncing). This enables the recognition and advertising targeting of website visitors across different devices, platforms, and advertising networks.

If the user identifies themselves with their clear data, such as their name or e-mail address, or enters their user data on our websites, or registers on social networks or online services of third-party providers that also provide us with tracking and advertising services, the pseudonymous identifiers may also be linked to the user’s clear data or user data.

In this way, we or the service providers may create and analyse complete user profiles, both pseudonymous and non-pseudonymous, in order to subsequently use them for targeted advertising purposes based on your interests.

The use of the services, as well as the related cookies and similar technologies in this category, is based on your consent pursuant to Art. 122 of the Privacy Code (Legislative Decree No. 196/2003 – “Privacy Code”). The subsequent processing of data is based on your consent pursuant to Art. 6(1), first sentence, lit. a GDPR.

4.3. Consent management via the Complianz consent management platform

On our websites we use the Complianz consent management platform provided by Complianz BV, Kalmarweg 14-5 9723 JG, Groningen, Netherlands.

The consent management system is implemented via a plugin installed locally on our website. The processing of personal data takes place primarily on our website servers or on those of our hosting provider under the nkf.it domain.

Description of data processing and purpose

The Complianz plugin is used to:

  • manage and document the user’s consent to the use of cookies and similar technologies,
  • technically control the cookies activated on the website,
  • fulfil the legal obligations of proof and documentation required by applicable data protection legislation.

When the user gives consent through the cookie management banner, the following data is processed:

  • consent status (acceptance or refusal),
  • date and time of the decision,
  • technical information about the device and browser used,
  • randomly generated anonymous consent identifier,
  • cookie categories selected or refused.

The purpose of the data processing is:

  • the management and storage of consents relating to cookies,
  • the technical control of cookies used on the website,
  • to comply with proof and documentation obligations laid down by law under the GDPR and Art. 122 of the Italian Privacy Code.

Legal basis for data processing

The processing of data relating to technical cookies and the consent management system takes place pursuant to ePrivacy legislation (Art. 5(3) of Directive 2002/58/EC) and Art. 122 of Legislative Decree No. 196/2003 (Privacy Code).

The subsequent processing of personal data is based on Art. 6(1)(c) GDPR (compliance with legal obligations) and Art. 6(1)(f) GDPR (legitimate interest in ensuring proof of consent and system security).

For the installation and reading of cookies that are not technically necessary, the legal basis is the user’s consent pursuant to Art. 6(1)(a) GDPR.

Recipients

The data collected through the consent management system is generally not disclosed to third parties.

Exceptions are:

  • the plugin provider Complianz B.V., limited to technical support for the service, where applicable,
  • the hosting provider that manages the website infrastructure.

No disclosure of the data for commercial or profiling purposes takes place (Privacy Statement di Complianz).

Retention period

Data relating to consent is stored for the time necessary to demonstrate compliance with legal obligations in the field of data protection.

The retention period is determined by the system configuration and the need to prove consent.

After expiry of the retention period, the data is automatically deleted unless legal obligations require further retention.

Data processing in third countries

The consent management system is configured to operate locally on the website servers and does not normally involve the transfer of personal data to third countries.

However, if external technical elements are loaded (for example scripts, updates, or CDN components), the possibility of a technical data transfer to countries outside the European Union cannot be completely excluded.

In such cases, the transfer takes place exclusively in compliance with Arts. 44 et seq. GDPR and, where applicable, on the basis of appropriate contractual safeguards or adequacy decisions of the European Commission.

4.4. GTRANSLATE

On our web pages, we use the GTranslate plugin by GTranslate Inc., 4394 NW 120th Ave, Coral Springs, FL 33065, USA, for the automatic translation of content.

The service uses translation technologies based on Google Translate and may involve the transfer of personal data to Google LLC, headquartered at 1600 Amphitheatre Parkway, Mountain View, California 94043, USA. In the European Union (EU) and the European Economic Area (EEA), the service is managed by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Description of data processing and purpose

The service enables the automated translation of website content into various languages. In this context, personal data of website visitors is transmitted to Google, in particular:

  • IP address
  • device information
  • browser information
  • content accessed
  • any other technically necessary data

The purpose of data processing is to provide a convenient, accessible and user-friendly translation function for the website.

Legal basis for data processing

The legal basis for the integration and use of the service is your consent, provided that you have given it via our consent management platform.

The use of cookies and similar technologies takes place on the basis of Art. 122 of the Italian Privacy Code. Subsequent data processing is based on Art. 6(1), first sentence, lit. a GDPR.

Consent is voluntary and may be freely withdrawn at any time with effect for the future. To exercise the withdrawal, please click at the bottom left of the web page on “The website uses cookies” to reopen the consent management platform and modify the settings.

Recipients

In the context of the use of the services, the data collected through our websites is transmitted to the following recipients:

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland,
  • Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA.

Further information on the processing of personal data by the service provider is available at https://policies.google.com/privacy?hl=de.

Data processing in third countries

Your data is transferred to recipients in third countries. For data transfers to the United States, there is an adequacy decision of the European Commission for companies certified under the EU-U.S. Data Privacy Framework. Google LLC is certified under the EU-U.S. Data Privacy Framework.

Further information on this subject and related links are available in the section “General information on data transfers to third countries” above.

Retention period

The transmitted data is processed by Google for the period necessary to provide the translation function. It does not retain in its systems the data processed by Google beyond such period of translation use.

4.5. GOOGLE RECAPTCHA

On our website, we use the “Google reCAPTCHA” service. For users located in the European Union (EU) and the European Economic Area (EEA), the service is provided by:

Google Ireland Limited
Gordon House
Barrow Street ifornia 94043, USA, may also process personal data in connection with the provision of the service.

Description of the data processing and its purpose

Google reCAPTCHA enables us to assess whether data entered on our website, for example through a contact form, has been entered by a human user or by an automated program, commonly referred to as a bot.

Automated programs may be used to overload websites with excessive requests, submit spam messages through contact or other web forms, or attempt to gain unauthorised access to systems through login forms.

Since the service is provided by Google and is loaded from its servers each time a page is accessed, the usage data technically required for accessing the page is also transmitted in the process. In this context, technical data required to provide and secure the service may be transmitted to Google, including:

  • the IP address of the requesting device;
  • the date and time of the request;
  • the name or address of the resource requested;
  • the website from which the request originated, where available;
  • the access status;
  • the web browser and operating system used;
  • the language settings of the browser or device.

To protect the websites, the service analyzes the behavior of the website visitor based on various characteristics and assigns a probability score to determine whether the input is more likely to come from a human or a bot.

Depending on the configuration of the service and the user’s interaction with the website, the information analysed may include:

  • the type of interaction, such as mouse movements or keystrokes;
  • the speed and duration of the interaction;
  • the time spent on a page;
  • information about the device, browser and related settings;
  • pseudonymous identifiers generated through cookies or similar technologies.

The data collected during this analysis may be transmitted to Google.

Cookies and similar technologies, including JavaScript, may be used to store or access information on the user’s device. Further information is provided in the section “Data processing in connection with cookies and similar technologies.”

The purpose of the processing is to protect our web forms against automated submissions, spam, abuse and unauthorised access, thereby ensuring the secure and reliable operation of the website and the systems connected to it.

Legal basis for the data processing

The legal basis for embedding and using Google reCAPTCHA is the user’s consent, provided through our consent management platform before the service is activated.

The storage of information on the user’s device or access to information already stored on the device is based on Article 122 of Italian Legislative Decree No. 196/2003, as amended, also referred to as the Italian Privacy Code.

The subsequent processing of personal data is based on Article 6(1)(a) GDPR.

Consent is voluntary and may be withdrawn at any time with effect for the future. To withdraw or modify consent, users may select the “Cookie Settings” link available at the bottom of the website and change their preferences through the consent management platform.

Recipients

In connection with the use of Google reCAPTCHA, personal data may be transmitted to the following recipients:

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland;
  • Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA.

Further information about Google’s processing of personal data is available in Google’s Privacy Policy.

Data processing in third countries

Personal data may be transferred to Google LLC and processed in the United States of America.

For transfers of personal data to organisations in the United States that are certified under the EU-U.S. Data Privacy Framework, the European Commission has adopted an adequacy decision pursuant to Article 45 GDPR.

Google LLC is certified under the EU-U.S. Data Privacy Framework.

Further information and relevant references are provided in the section “General information on data transfers to third countries.”

Storage period

We do not separately retain the personal data processed through Google reCAPTCHA within our own systems.

Personal data transmitted to Google is retained by Google for periods that may vary depending on the type of data, the purposes for which it is processed and the applicable technical or account settings. Further information is available in Google’s Privacy Policy and data retention information.

4.6. MAPS AND OPENSTREETMAP

On our websites we use the WP Maps plugin, which is based on open-source technologies such as OpenStreetMap.

OpenStreetMap is a collaborative open-source project managed by the OpenStreetMap Foundation, headquartered in the United Kingdom.

Description of data processing and purpose

The service enables us to provide you with interactive online maps directly on our websites.

For this purpose, the user’s browser may establish a connection with the servers used to provide the maps, with possible transmission of technical data such as:

  • IP address of the requesting device (router or mobile device),
  • date and time of the request,
  • name of the requested file,
  • website from which a file was requested (referrer URL),
  • access status,
  • web browser and operating system used,
  • language used.

In addition, the service may process the following data:

  • information about your location, which you may provide after giving consent through your browser or operating system,
  • data relating to your searches, if any, carried out via the input fields of the interactive map.

Cookies and similar techniques, in particular JavaScript, may be used to store and read data on your device. Further details are available above under “Data processing in connection with cookies and similar techniques”.

The purposes of the data processing are to make our website attractive to users, facilitate the search for our locations and premises, and enable simple route planning.

Legal basis for data processing

The legal basis for the integration and use of the service is the user’s consent, provided that it has been given via our consent management platform.

The use of cookies and similar technologies takes place on the basis of Art. 122 of the Personal Data Protection Code (Legislative Decree No. 196/2003 – “Privacy Code”). Subsequent data processing is based on Art. 6(1), first sentence, lit. a GDPR.

Your consent is voluntary and may be freely withdrawn at any time with effect for the future. To exercise the withdrawal, please click at the bottom left of the web page on “The website uses cookies” to reopen the consent management platform and modify the settings.

Recipients

In the context of the use of the map service, the data collected through our website is generally not transmitted to third parties for profiling or marketing purposes.

The map service is based on open-source technologies (OpenStreetMap) and may involve the transmission of technical data to the servers necessary for providing the service.

Further information on the processing of personal data is available at the following link: https://www.openstreetmap.org

Data processing in third countries

As a rule, no transfer of personal data to third countries is envisaged in connection with the use of the map service based on open-source technologies (OpenStreetMap).

Any transfers to third countries may take place exclusively in the presence of additional external services integrated into the website and limited to the data strictly necessary for their operation.

Retention period

Any data processed in connection with the use of the map service is retained for the time strictly necessary to achieve the purposes indicated above.

No storage of personal data takes place in our systems beyond what is necessary for the technical functioning of the service.

Any data transmitted to third-party providers is processed according to their respective retention policies.

4.7. General enquiries by email

Description of data processing and purpose

If you send us requests by e-mail, your data contained in the e-mail, including the personal data you provide, will be stored by us at the address for the purpose of processing the request and in the event of follow-up questions.

Providing an e-mail address is necessary in order to contact you, whereas providing your first name, last name, and telephone number is optional. Under no circumstances will we transmit this data without your consent.

Legal basis for data processing

The legal basis for processing your data is your and our legitimate interest in responding to your request pursuant to Art. 6(1), first sentence, lit. f GDPR and, where applicable, Art. 6(1), first sentence, lit. b GDPR to the extent that your request is aimed at the conclusion of a contract.

Recipients

In the context of the data processing, your data is disclosed to the following categories of recipients or to recipients that we use in the context of the data processing in order to achieve the stated purposes:

  • Hosting service and IT infrastructure providers
  • Website management and maintenance service providers
  • Software service providers for communication and email delivery (including external SMTP services and email providers).

Data processing in third countries

Your data may be transferred to recipients in third countries. For data transfers to the United States, there is an adequacy decision of the European Commission for companies certified under the EU-U.S. Data Privacy Framework.

The service providers used that receive such data are certified under the EU-U.S. Data Privacy Framework or ensure an adequate level of data protection.

Further information on this subject and related links are available in the section “General information on data transfers to third countries” above.

Retention period

Your data will be deleted after your request has been finally processed, as soon as no further requests for clarification are expected and provided that there are no legal retention obligations.

5. Privacy information for other data processing

5.1. Fulfilment of other legal obligations

Description of data processing and purpose

We process personal data to the extent necessary to fulfil a legal obligation. The scope of the data to be processed derives from the legal obligation with which we are required to comply.

Legal basis for data processing

In these cases, the legal basis for processing your data is Art. 6(1), first sentence, lit. c GDPR (legal obligation) in conjunction with the respective legal provision imposing such obligation on us.

This may, for example, involve commercial and tax law retention obligations, such as those under the Italian Civil Code (Codice civile), in particular Article 2214 and Article 2220 of the Codice civile, as well as under Italian tax regulations (e.g. Presidential Decree 633/1972 and Presidential Decree 600/1973). Depending on the circumstances, criminal procedure regulations (Italian Code of Criminal Procedure, Codice di procedura penale – c.p.p.) may also be relevant.

Recipients

In the context of the data processing, your data will be disclosed to the following categories of recipients or recipients that we use in the context of the data processing in order to achieve the stated purposes:

  • accountants,
  • auditors,
  • financial or investigative authorities,
  • lawyers,
  • experts,
  • courts.

No systematic disclosure to persons not necessary for the pursuit of the stated purposes is envisaged.

Retention period

The data is retained for the time necessary to achieve the purposes indicated above.

In particular:

  • for tax and accounting obligations: up to 10 years, in accordance with the applicable legislation
  • for disputes or legal proceedings: until the final conclusion of the proceedings and expiry of the appeal periods

Subsequently, the data is deleted or anonymised, unless further legal obligations apply.

Subsequently, we will delete your data unless the processing of the data, including in other systems if applicable, is still permitted on the basis of another legal basis.

5.2. Exercise or defence of legal claims

Description of data processing and purpose

We process personal data to the extent necessary for the establishment, exercise, and defence of legal claims in judicial or extrajudicial proceedings.

This includes, by way of example:

  • recovery of receivables arising from contractual relationships or unpaid invoices
  • management of disputes or legal controversies
  • defence against claims for damages or other legal claims

The processing takes place exclusively when the data is relevant and necessary to the specific dispute.

Legal basis for data processing

The legal basis for the processing of your data is Article 6(1)(f) of the GDPR.

Recipients

The data may be disclosed, within the limits of the purposes indicated above, to the following categories:

  • lawyers and legal advisors
  • accountants and tax advisors
  • auditors
  • experts and technical consultants
  • judicial authorities and courts
  • tax or investigative authorities, where applicable

No generalised or unnecessary disclosures to parties unrelated to the stated purposes are envisaged.

Retention period

The data is retained for the time strictly necessary to manage the specific dispute.

In the event of litigation, the data may be retained until:

  • the final conclusion of the proceedings
  • the expiry of the applicable appeal or limitation periods

Subsequently, the data is deleted or anonymised, unless further legal obligations apply.

6. Your rights

Below you will find information on the data subject rights granted to you by applicable data protection law vis-à-vis the controller with regard to the processing of your personal data:

The right, pursuant to Article 15 of the GDPR, to request information about your personal data processed by us. In particular, you may request information regarding the purposes of processing, the categories of personal data, the categories of recipients to whom your data has been or will be disclosed, the intended storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data where it was not collected by us, as well as the existence of automated decision-making, including profiling, and, where applicable, meaningful information regarding its details.

The right, pursuant to Article 16 of the GDPR, to request the immediate rectification of inaccurate personal data or the completion of your personal data stored by us.

The right, pursuant to Article 17 of the GDPR, to request the erasure of your personal data stored by us, unless processing is necessary for the exercise of the right to freedom of expression and information, to comply with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims.

The right, pursuant to Article 18 of the GDPR, to request the restriction of the processing of your personal data, provided that you contest the accuracy of the data, the processing is unlawful but you oppose its erasure and we no longer require the data, but you require it for the establishment, exercise or defend legal claims, or you have objected to the processing in accordance with Article 21 of the GDPR.

The right, pursuant to Article 20 of the GDPR, to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transmitted to another controller.

The right to lodge a complaint with a supervisory authority in accordance with Article 77 of the GDPR. As a rule, you may contact the supervisory authority of the federal state in which our registered office is located, as stated above, or, where applicable, the supervisory authority of your usual place of residence or place of work.

The right to withdraw consent pursuant to Article 7(3) of the GDPR: You have the right to withdraw your consent to the processing of data at any time with effect for the future. In the event of withdrawal, we will delete the relevant data without delay, provided that further processing cannot be based on a legal basis for processing without consent. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to withdrawal.

6.1. Right to object

Where your personal data is processed by us on the basis of legitimate interests pursuant to Art. 6(1), first sentence, lit. f GDPR, you have the right, pursuant to Art. 21 GDPR, to object to the processing of your personal data to the extent that this takes place for reasons arising from your particular situation. If the objection is directed against the processing of personal data for direct marketing purposes, you have a general right to object without the need to indicate a particular situation.

If you wish to exercise your right of withdrawal or objection, please contact us using the contact details provided above under “Controller”.

7. Current version of the privacy policy

This privacy notice was last amended on 12/06/2026.

``