INFORMATION DOCUMENT PURSUANT TO ARTICLE 13 OF REGULATION (EU) 2016/679 – GDPR.
Notice regarding the processing of personal data collected from the data subject/user – and Article 130 – Unsolicited communications under Legislative Decree 196/2003
WHY THIS INFORMATION?
Pursuant to Regulation (EU) 2016/679 (hereinafter “GDPR”), this page describes the methods of processing personal data. This notice is provided pursuant to Article 13 of the GDPR. It does not apply to third-party websites that may be accessible through links on the domain websites of the data controller, for which no responsibility is assumed.
PROCESSED DATA
Personal Data (Article 4 GDPR):
Any information concerning an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.
Data of Contractors/Users
- Browsing Data: Information automatically collected by computer systems and software procedures necessary for the website’s operation.
- Data Voluntarily Provided: Information provided by users through messages, emails, or data collection forms.
- Information on Personal Data Processed through Social Media: For processing carried out by social media platform providers, please refer to their respective privacy policies. The Data Controller processes personal data provided by users for managing interactions (comments, public posts, etc.) in compliance with applicable regulations.
COOKIES AND OTHER TRACKING SYSTEMS
For information on cookies and other tracking technologies used, please refer to the cookies policy available in the website footer.
1.DATA CONTROLLER
Pursuant to Articles 4 and 24 of the GDPR, the Data Controller is Boffi S.p.A., Via Oberdan, 70 – 20823 Lentate sul Seveso (MB), Italy.
Contact: privacy@boffi.com.
2.DATA PROTECTION OFFICER (DPO)
Appointed in accordance with Articles 37 – 39 of the GDPR.
Contact: dpo.boffi@dpoprofessionalservice.it.
3. PURPOSES OF PROCESSING – LEGAL BASIS – DATA RETENTION PERIOD
Website browsing and collection of statistical information | Processing is necessary for pursuing the legitimate interest of the Data Controller or third parties, in accordance with Article 6(1)(f) of the GDPR | Browsing data is retained for the duration of the session and no longer than seven days, except when required for judicial investigations. |
Ensuring the proper functioning of services | Processing is necessary for pursuing the legitimate interest of the Data Controller or third parties, in accordance with Article 6(1)(f) of the GDPR. | Browsing data is retained for the duration of the session and no longer than seven days, except when required for judicial investigations. |
Investigating responsibility in cases of cybercrimes | Processing is necessary for pursuing the legitimate interest of the Data Controller or third parties, in accordance with Article 6(1)(f) of the GDPR. | Browsing data is retained for the duration of the session and no longer than seven days, except when required for judicial investigations. |
4.NATURE OF DATA PROVISION AND REFUSAL
Except for browsing data, which is necessary, users are free to provide their personal data. Failure to provide such data will result in the inability to receive the requested services.
5.DATA RECIPIENTS
Data may be disclosed to:
- Website service providers
- Consulting firms or companies
- Social media platforms
- Competent authorities for legal compliance
The updated list of data processors is available upon request at privacy@boffi.com.
6.DATA TRANSFER TO THIRD COUNTRIES
The website is hosted in EU countries. If data is transferred outside the EU, it is done in compliance with the guarantees set forth in Articles 44 et seq. of the GDPR.
7.AUTOMATED DECISION-MAKING
Personal data is processed manually and electronically. No fully automated decision-making processes are carried out.
8.DATA SUBJECT RIGHTS
Users have the right to:
- Access their data (Article 15 GDPR)
- Rectification and erasure (Articles 16-17 GDPR)
- Restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR)
- Object to processing (Article 21 GDPR)
- Withdraw consent without affecting the lawfulness of prior processing
To exercise these rights, users may contact privacy@boffi.com or dpo.boffi@dpoprofessionalservice.it.
In case of violations, users may lodge a complaint with the Italian Data Protection Authority (https://www.garanteprivacy.it/) or take legal action.
9.CHANGES TO THIS PRIVACY POLICY
The Data Controller reserves the right to modify this notice. Changes will be published with an updated date.
Updated: January 27, 2025