Privacy policy
Privacy Policy on the Processing of Personal Data
Pursuant to Article 13 of EU Regulation 2016/679, hereinafter referred to as GDPR (General Data Protection Regulation), also considering Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, we inform you of the following:
Data Controller
- The data controller is: Profisced S.r.l.s.
- VAT No.: 03989750249
- Registered office: Via Beato Angelico, 9 – 36061 Bassano del Grappa (VI) Italy
- Tel. +39 0424 504308
- E-mail: info@profisnet.it
Purposes of Processing and Legal Basis
Browsing Data
The Data Controller will process certain personal data of users who interact with the IT systems and software procedures used to operate the website. In particular, browsing data automatically acquired by IT systems during website use—such as IP addresses, domain names, and browser types—will be processed. These data are not associated with any additional personal information and are used to obtain anonymous statistical information on website usage, to monitor its correct functioning, and to ascertain responsibility in case of potential cybercrimes.
Data Provided Voluntarily by the User
The personal data you provide will be processed exclusively for the following purposes:
- a. conclusion and performance of the contract (registration, use of website services) and all related activities, such as, by way of example, invoicing, credit protection, protection of the Controller’s rights and interests, administrative, managerial, logistical/organizational services necessary for contract execution;
- b. compliance with obligations established by law, regulations, applicable legislation, and provisions issued by authorities and supervisory bodies as required by law.
The legal bases for processing personal data for the purposes referred to in points a) and b) above are: the performance of a contract and/or pre-contractual measures at the request of the data subject, and compliance with legal obligations or the pursuit of legitimate interest.
Methods of Data Processing
Personal data processing is carried out through the operations indicated in Article 4 no. 2) GDPR, for the purposes stated above, both in paper and electronic/telematic form, using electronic and/or automated tools, in compliance with current regulations, particularly regarding confidentiality and security, and in accordance with the principles of fairness, lawfulness, transparency, and protection of the Client’s rights. Processing is carried out directly by the Controller’s organization, by its processors pursuant to Article 28 GDPR, and by authorized internal personnel.
Mandatory or Optional Nature of Data Provision and Consequences of Refusal
The data required for the purposes indicated above must be provided in order to comply with legal obligations and/or to establish and perform the contractual relationship requested by you or to pursue the Controller’s legitimate interest. Therefore, any refusal, even partial, to provide such data may result in the impossibility for the Controller to establish and manage the relationship.
Communication and Disclosure
Your personal data may be communicated, within the limits strictly relevant to the obligations, duties, and purposes indicated above and in compliance with applicable regulations, to the following categories of recipients:
- entities to whom communication is required in order to comply with or enforce specific contractual obligations or legal provisions, regulations, and/or EU legislation;
- external individuals and/or legal entities providing services instrumental to the Controller’s activities for the purposes indicated above (e.g., business partners, suppliers, consultants, companies, entities, professional firms). These parties will act as data processors pursuant to Article 28 GDPR.
Personal data will not be disclosed in any way without your explicit consent or written request.
Data Retention Period
Personal data will be retained for the entire period necessary to perform the contract concluded with the Controller; thereafter, data will be retained to fulfill legal obligations and for administrative record-keeping in compliance with applicable laws.
Data Transfer
Personal data are stored on servers located within the European Union. However, the Controller may, if necessary, transfer the servers outside the EU. In such cases, the Controller ensures that any transfer of data outside the EU will be carried out in compliance with applicable legal provisions, including the adoption of standard contractual clauses approved by the European Commission. If the User uses online payment methods, they may be redirected to platforms managed by third parties (such as Multisafepay, PayPal, etc.), which act as independent data controllers with all obligations provided by the GDPR and applicable legislation.
Minors
The Controller does not knowingly collect personal information relating to minors.
Data Subject Rights
As a data subject, you have the rights provided for by the GDPR, including the right to:
-
-
- obtain confirmation as to whether or not personal data concerning you exist, even if not yet recorded, and receive them in an intelligible form;
- obtain information regarding:
- the origin of personal data;
- the purposes and methods of processing;
- the logic applied in case of processing carried out with the aid of electronic tools;
- the identification details of the Controller, processors, and the designated representative pursuant to Article 3(1) GDPR;
- the subjects or categories of subjects to whom personal data may be communicated or who may become aware of them as designated representatives, processors, or authorized persons;
- obtain:
- updating, rectification, or, where interested, integration of the data;
- erasure, anonymization, or blocking of data processed unlawfully, including data whose retention is not necessary for the purposes for which they were collected or subsequently processed;
- certification that the operations referred to in letters a) and b) have been notified to those to whom the data were communicated, unless this proves impossible or involves a disproportionate effort;
- object, in whole or in part:
- on legitimate grounds to the processing of personal data concerning you, even if relevant to the purpose of collection;
- to the processing of personal data concerning you for sending advertising material, direct sales, market research, or commercial communication, carried out through automated or traditional means (such as telephone or postal mail).
-
Please note that each data subject has the right to object, in whole or in part, to data processing for marketing purposes. Therefore, the data subject may choose to receive only communications via traditional methods, only automated communications, or neither. Where applicable, you also have the rights under Articles 16–21 GDPR (right to rectification, right to erasure, right to restriction of processing, right to data portability, right to object), as well as the right to lodge a complaint with the supervisory authority.
To exercise the above rights or to request information regarding the processing of your data and the security measures adopted, you may contact our company at the following address: info@profisnet.it
