Data Processing Subjects
The Data Controller, pursuant to applicable laws, is M.A. S.R.L., which can be contacted through the CONTACTS section (link at the bottom of the page).
Legal Basis for Processing
This website processes personal data primarily on the basis of users’ consent. By using or browsing this website, visitors and users acknowledge this Privacy Policy and consent to the processing of their personal data in accordance with the methods and purposes described below, including disclosure to third parties where necessary for the provision of a service. Additional consent relating to the specific purpose of the service is collected through contact forms or service request forms.
Data relating to website security and the prevention of abuse and SPAM is processed on the basis of the Data Controller’s legitimate interest in protecting the website and its users. In such cases, users always have the right to object to the processing of their personal data.
Purposes of Processing
The processing of data collected through this website, in addition to purposes related, instrumental and necessary to the provision of the service, is carried out for the following purposes:
– Security
Collection of data and information in order to protect the security of the website (anti-spam filters, firewalls, virus detection) and its users, and to prevent or detect fraud or abuse affecting the website. The data is recorded automatically and may also include personal data (IP addresses), which may be used, in accordance with applicable laws, to block attempts to damage the website, harm other users, or carry out harmful or unlawful activities.
Such data is never used to identify or profile users and is periodically deleted.
– Ancillary Activities
Disclosure of data to third parties that perform functions necessary or instrumental to the operation of the service, and to enable third parties to carry out technical, logistical and other activities on our behalf.
Data Collected
While users browse the website, the following information may be collected and stored in the website server (hosting) log files: name, surname, telephone number, email address, Internet Protocol (IP) address, browser type, parameters of the device used to connect to the website, Internet Service Provider (ISP) name, and date and time of the visit.
The IP address is used exclusively for security purposes and is not cross-referenced with any other data.
Place of Processing
The data is processed at the Data Controller’s premises and at the data center of the web hosting provider (Aruba Business S.r.l.). The web hosting provider (Aruba Business S.r.l., VAT No. 01497070381) acts as a Data Processor, processing data on behalf of the Data Controller. Aruba Business S.r.l. is located within the European Economic Area (EEA) and operates in compliance with European regulations.
Data Retention Period
Data collected by the website during its operation is retained only for the period strictly necessary to carry out the activities described above. Upon expiry of the retention period, the data will be deleted or anonymized, unless there are additional legitimate purposes requiring its continued retention.
Data (IP addresses) used for website security purposes (to block attempts to damage the website) is retained for 30 days. Data used for analytics (statistical) purposes is retained in aggregated form for 24 months.
Transfer of Collected Data to Third Parties
Data collected through the website is generally not disclosed to third parties, except in specific cases: upon a legitimate request by judicial authorities and only where required by law; where necessary to provide a specific service requested by the User; or to carry out website security or optimization checks.
Transfer of Data to Countries Outside the EU
Data collected through the website is generally not transferred to third parties in countries outside the European Union, except in specific cases: upon a legitimate request by judicial authorities and only where required by law; where necessary to provide a specific service requested by the User; or to carry out website security or optimization checks.
Security Measures
We process visitors’ and users’ data lawfully and fairly, adopting appropriate security measures to prevent unauthorized access, disclosure, alteration or destruction of data. We are committed to protecting the security of your personal data during transmission by using Secure Sockets Layer (SSL) software, which encrypts information in transit. The processing is carried out using IT and/or telematic tools, with organizational methods and procedures strictly related to the purposes indicated. In addition to the Data Controller, in some cases, categories of persons involved in the operation of the website may have access to the data, as well as external parties (such as third-party technical service providers and hosting providers).
Users’ Rights
Users may exercise certain rights regarding the personal data processed by the Data Controller. In particular, within the limits provided by law, Users have the right to:
Withdraw their consent at any time.
Object to the processing of their Data.
Access their Data.
Verify their Data and request its rectification.
Obtain restriction of processing.
Obtain the erasure or removal of their Personal Data.
Receive their Data or have it transferred to another Data Controller.
Lodge a complaint.
How to Exercise Your Rights
To exercise their rights, Users may submit a request using the Data Controller’s contact details provided in this document. The request may be submitted free of charge, and the Data Controller will respond as soon as possible and, in any event, within one month, providing the User with all information required by law. Any rectification, erasure or restriction of processing will be communicated by the Data Controller to each recipient, if any, to whom the Personal Data has been disclosed, unless this proves impossible or involves disproportionate effort. The Data Controller will inform the User of such recipients upon request.