Suggestions
Menu

INFORMATION DOCUMENT PURSUANT TO ARTICLE 13 OF REGULATION (EU) 2016/679 – GDPR

Notice regarding the processing of personal data collected from the data subject/user – Newsletter

WHY THIS INFORMATION?

Pursuant to Regulation (EU) 2016/679 (hereinafter “GDPR”), this page describes the methods of processing personal data. This notice is provided pursuant to Article 13 of the GDPR. It does not apply to third-party websites that may be accessible through links on the domain websites of the data controller, for which no responsibility is assumed.

PROCESSED DATA

Personal Data (Article 4 GDPR):

Any information concerning an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.

Data of Contractors/Users

  • Browsing Data: Information automatically collected by computer systems and software procedures necessary for the website’s operation.
  • Data Voluntarily Provided: Information provided by users through messages, emails, or data collection forms.

For browsing data and cookies, please refer to the privacy policy and cookie policy available in the website footer.

1.DATA CONTROLLER

Pursuant to Articles 4 and 24 of the GDPR, the Data Controller is Boffi S.p.A., Via Oberdan, 70 – 20823 Lentate sul Seveso (MB), Italy.
Contact: privacy@boffi.com.

2.DATA PROTECTION OFFICER (DPO)

Appointed in accordance with Articles 37 – 39 of the GDPR.
Contact: dpo.boffi@dpoprofessionalservice.it.

3.PURPOSES OF PROCESSING – LEGAL BASIS – DATA RETENTION PERIOD

Purpose of ProcessingLegal BasisRetention Period

Website navigation and use of cookies

Processing is necessary for the legitimate interest of the data controller or third parties (Article 6(1)(f) GDPR).

Data is retained only for the session duration and no longer than seven days, except when required for judicial investigations

Direct marketing (sending newsletters, promotional communications, market research)Processing is based on the data subject’s consent (Article 6(1)(a) GDPR).

Until withdrawal of consent (opt-out). Data will be deleted at the end of the period.

Handling data subject requests under Articles 15 et seq. GDPRProcessing is necessary to comply with a legal obligation (Article 6(1)(c) GDPR).5 years from the closure of the request, unless litigation arises. Data will be deleted at the end of the period.

4.NATURE OF DATA PROVISION AND REFUSAL

Providing data for website navigation and handling data subject requests is mandatory. Providing data for marketing purposes is optional and subject to the user’s explicit consent.

5.DATA RECIPIENTS

Data may be disclosed to:

  • Boffi Group companies
  • IT service providers, email, web, and cloud platforms
  • Consulting firms or companies
  • Entities with economic agreements with the Data Controller
  • Database/CRM managers
  • Competent authorities for legal compliance

The updated list of data processors is available upon request at privacy@boffi.com.

6.DATA TRANSFER TO THIRD COUNTRIES

The website is hosted in EU countries. If data is transferred outside the EU, it is done in compliance with the guarantees set forth in Articles 44 et seq. of the GDPR.

7.AUTOMATED DECISION-MAKING

Personal data is processed manually and electronically. No fully automated decision-making processes are carried out.

8.DATA SUBJECT RIGHTS

Users have the right to:

  • Access their data (Article 15 GDPR)
  • Rectification and erasure (Articles 16-17 GDPR)
  • Restriction of processing (Article 18 GDPR)
  • Data portability (Article 20 GDPR)
  • Object to processing (Article 21 GDPR)
  • Withdraw consent without affecting the lawfulness of prior processing

To exercise these rights, users may contact privacy@boffi.com or dpo.boffi@dpoprofessionalservice.it.

In case of violations, users may lodge a complaint with the Italian Data Protection Authority (https://www.garanteprivacy.it/) or take legal action.

9.CHANGES TO THIS PRIVACY POLICY

The Data Controller reserves the right to modify this notice. Changes will be published with an updated date.

Updated: January 27, 2025