PRIVACY POLICY – WEBSITE
Information document pursuant to and for the purposes of Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
WHY THIS INFORMATION?
Pursuant to Regulation (EU) 2016/679 (hereinafter the “GDPR”), this page describes how personal data are processed. This is a notice provided pursuant to Articles 13-14 GDPR. This notice is not to be considered valid for other third-party websites that may be accessed through links on this website, for which no responsibility is accepted.
PERSONAL DATA THAT MAY BE PROCESSED
- Browsing data
The computer systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes IP addresses or the domain names of the computers and terminals used by users, the URI/URL (Uniform Resource Identifier/Locator) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the user’s operating system and computer environment. - Data provided by the user
The optional, explicit and voluntary sending of messages to the Controller’s contact addresses, private messages sent by users to institutional profiles/pages on social media, as well as the completion and submission of the forms on the Controller’s websites, entail the acquisition of the sender’s contact details, necessary to reply, as well as of all personal data included in the communications. - Personal data
any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (C26, C27, C30 GDPR). - Data of contracting parties/users.
COOKIES AND OTHER TRACKING SYSTEMS. WHAT ARE THEY? WHAT ARE THEY FOR?
COOKIES
Cookies are text files that the websites visited by users send to their terminals and that are sent back to those same websites on the next visit. For cookies and other tracking systems, please refer to the cookies policy shown in the website footer and at the following link. For cookies and equivalent technologies that are not technically necessary, processing is based on consent to the processing of personal data (Art. 6(1)(a) and C42, C43 GDPR). Consent is given through the banner and the cookie policy in the website footer.
PIXEL TRACKING IN E-MAILS
Tools for tracking or acquiring information on users’ behaviour and on how they use services, especially in the online environment. Tracking pixels in e-mail messages: these are images, often transparent and very small, equal to a single pixel, not directly contained in the e-mail in question but hosted on remote servers. As a rule, each time the recipient opens the e-mail message, whether for the first time or on any subsequent occasion, an HTML code inserted in the message automatically triggers a command that sends a request to the sender’s server. In response to this request, the image is downloaded by the recipient’s e-mail client (specific software or a browser) and stored in the memory of the data subject’s terminal in order to be “displayed” in the body of the e-mail. In order to compare and possibly improve the results of automated communications, the Controller uses systems with reporting (pixel tracking). Thanks to pixel tracking the Controller may know, for example: the number of readers, of openings, of unique “clickers” and of “clicks”; the devices and operating systems used to read the communication; details of individual users’ activity; details of the e-mails sent, e-mails delivered and not delivered, and those forwarded. All these data are used in order to compare, and possibly improve, the results of the communications. Processing is based on consent to the processing of personal data (Art. 6(1)(a) and C42, C43 GDPR).
Information on the processing of personal data carried out through Social Media platforms
As regards the processing of personal data carried out by the operators of the Social Media platforms used by the Controller, please refer to the information they provide through their respective privacy policies. The Controller processes the personal data provided by users through the dedicated Social Media platform pages in order to manage interactions with users (comments, public posts, etc.) and in compliance with applicable legislation.
WHO IS THE DATA CONTROLLER? HOW CAN THEY BE CONTACTED?
THE “CONTROLLER” is BOFFI|DE PADOVA SPA, with registered office at via Oberdan, 70 – 20823 Lentate sul Seveso (MB) Italy, in the person of its legal representative pro tempore. The Controller’s contact e-mail address is privacy@boffi.com
HAS A DATA PROTECTION OFFICER BEEN APPOINTED? WHAT ARE THEIR CONTACT DETAILS?
The DATA PROTECTION OFFICER (RPD/DPO – Data Protection Officer) is appointed pursuant to Articles 37 to 39 of Reg. EU 2016/679. The DPO’s contact e-mail address is dpo.boffi@dpoprofessionalservice.it
PURPOSES OF PROCESSING, LEGAL BASIS, DATA RETENTION PERIOD, NATURE OF THE PROVISION OF DATA
PURPOSES OF PROCESSING
Browsing this website, use of the web services; data are also processed in order to:
- obtain statistical information on the use of the services (most visited pages, number of visitors by time slot or day, geographical areas of origin, etc.)
- check that the services offered are working properly
- establish liability in the event of hypothetical computer crimes against the website
LEGAL BASIS
Processing is necessary for the purposes of the legitimate interests pursued by the controller or by third parties, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, taking into account the reasonable expectations of the data subject and the activities strictly necessary for the operation of the website and for browsing itself (Art. 6(1)(f) and C47 GDPR).
DATA RETENTION PERIOD
Browsing data will be retained for the duration of the browsing session. In any case, they are not retained for more than seven days (except where crimes need to be established by the judicial authorities).
NATURE OF THE PROVISION OF DATA
The provision of data is necessary in order to browse this website.
In addition to browsing, personal data will be processed for:
A.1) CONTACTS
PURPOSES OF PROCESSING
Sending contact requests, information.
LEGAL BASIS
Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. Art. 6(1)(b) GDPR.
DATA RETENTION PERIOD
Maximum 2 years from the time the data are collected. At the end of the retention period the personal data will be anonymised.
NATURE OF THE PROVISION OF DATA
The provision of data is necessary. Failure to provide the necessary data will make it impossible to be contacted and to receive information.
A.2) SOURCE OF THE DATA
For this purpose the data may come from another source (e.g. EDILPORTALE.com spa from the “archiproducts” website).
A.3) RESERVED AREA
PURPOSES OF PROCESSING
To register and manage the account (including any account checks and credential recovery) in order to access the reserved areas of the website, by means of authentication credentials, and to use the functions connected to the account. The functions connected to the account include downloading the project models. If you download the project you will be contacted for pre-contractual purposes relating to the service.
LEGAL BASIS
Processing is necessary for the performance of a contract/service to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (C44), Art. 6(1)(b) GDPR.
DATA RETENTION PERIOD
Maximum 12 months from the deactivation of the credentials, or until the contract/service ends and for the technical time needed to disable the credentials. At the end of the retention period the personal data will be anonymised.
NATURE OF THE PROVISION OF DATA
The provision of data is necessary. Failure to provide the data makes it impossible to register for/access the reserved area.
SOURCE OF THE DATA
For this purpose the data may come from another source (e.g. EDILPORTALE.com spa from the “archiproducts” website).
B) DIRECT MARKETING
PURPOSES OF PROCESSING
For sending advertising or direct selling material, or for carrying out market or customer satisfaction research or commercial communications, newsletters by automated means (e-mail, including with pixel tracking, and through social networks and sponsorships) and traditional means (paper mail and telephone calls through an operator).
LEGAL BASIS
Processing is based on consent to the processing of personal data (C42, C43). Art. 6(1)(a) GDPR.
DATA RETENTION PERIOD
Maximum 24 months from the time the data are collected or from the renewal of consent, unless consent is withdrawn.
NATURE OF THE PROVISION OF DATA
The provision of data is optional. Failure to provide the necessary data will make it impossible to receive direct marketing communications.
C) NON-AUTOMATED PROFILING
PURPOSES OF PROCESSING
Personal data will be entered into databases/web platforms in order to carry out analyses, to divide data subjects into homogeneous groups by specific characteristics with the application of assessments, for better management of the services and for sending targeted promotional communications.
LEGAL BASIS
Processing is based on consent to the processing of personal data (C42, C43). Art. 6(1)(a) GDPR.
DATA RETENTION PERIOD
Maximum 24 months from the time the data are collected, unless consent is withdrawn. At the end of the retention period the personal data will be anonymised.
NATURE OF THE PROVISION OF DATA
The provision of data is optional. Failure to provide the necessary data will make it impossible to carry out analyses and send targeted communications.
D) RIGHTS OF THE DATA SUBJECT
PURPOSES OF PROCESSING
Management of data subjects’ requests, pursuant to Articles 15 et seq. GDPR.
LEGAL BASIS
Processing is necessary for compliance with a legal obligation to which the controller is subject (C45) following your request to exercise your rights. Art. 6(1)(c) GDPR.
DATA RETENTION PERIOD
5 years from the closure of the request, except in the event of disputes.
NATURE OF THE PROVISION OF DATA
The provision of personal data is mandatory, as it is essential in order to fulfil legal obligations.
TO WHOM WILL THE PERSONAL DATA BE DISCLOSED? DATA RECIPIENTS
Personal data will be disclosed to parties that will process the data as independent data controllers, or as data processors (Art. 28 GDPR), and processed by natural persons (Art. 29 GDPR) acting under the authority of the Controller and of the processors on the basis of specific instructions given as to the purposes and means of the processing. The data will be disclosed to recipients belonging to the following categories:
- Parties providing services for the website and communication networks, including e-mail, hosting and website management;
- Parties managing the Information System and telecommunications networks (including e-mail, web and Cloud platforms, CRM);
- social network platforms;
- parties managing marketing activities, subject to consent;
- Competent authorities for the fulfilment of legal obligations and/or provisions of public bodies, upon request.
The list of data processors pursuant to Art. 28 is available by writing to privacy@boffi.com or to the other contact details indicated above.
WILL THE DATA BE TRANSFERRED TO NON-EEA COUNTRIES?
Personal data may be transferred to non-EEA countries in order to fulfil the related purposes indicated above. In particular, for interaction on social networks, the transfer of personal data outside EEA countries will then be managed as established in the general terms and conditions and in the privacy policies of the relevant social networks. Data will be transferred to parties adhering to the Data Privacy Framework (DPF) Program or through the European Commission’s Standard Contractual Clauses (“SCC”). For information on the safeguards relating to the transfer of data outside the EEA, write to privacy@boffi.com.
IS THERE AN AUTOMATED PROCESS?
Personal data will be subject to traditional manual, electronic and automated processing. Please note that no fully automated decision-making processes are carried out. With reference to profiling activities, where carried out on the express consent of the data subject as indicated in the purposes, these will be performed through the intervention of an operator who will build the data subject’s profile and analyse their consumption habits and choices, in order to improve the controller’s commercial offer and services (non-automated profiling).
WHAT ARE YOUR RIGHTS? HOW CAN YOU EXERCISE THEM?
Data subjects may exercise their rights as set out in Articles 15 et seq. GDPR by contacting the DPO/RPD at the e-mail address: dpo.boffi@dpoprofessionalservice.it or by contacting the Data Controller at the e-mail address: privacy@boffi.com.
The controller guarantees data subjects the possibility of requesting, at any time, access to their personal data (Art. 15), rectification (Art. 16), erasure (Art. 17) and restriction of processing (Art. 18). The controller communicates (Art. 19) to each of the recipients to whom the personal data have been disclosed any rectification or erasure or restriction of processing carried out. The controller informs data subjects about those recipients if they request it. The controller guarantees the right to data portability (Art. 20) and, in the event of requests pursuant to Art. 20, will provide data subjects with the data in a structured, commonly used and machine-readable format. Data subjects have the right to object (Art. 21), at any time, to the processing of data based on the legitimate interest of the controller, by writing to the e-mail address dpo.boffi@dpoprofessionalservice.it with the subject line “objection”. In the event of exercise of the right to object to processing based on legitimate interest. Data subjects have the right to withdraw the consent given, without affecting the lawfulness of processing based on consent given before its withdrawal. In order to stop receiving automated direct marketing communications (e-mail or through social networks and sponsorships) it is sufficient to write an e-mail to the address dpo.boffi@dpoprofessionalservice.it with the subject line “cancellation from automated” or to use our automatic cancellation systems provided for e-mails only (opt-out). In order to stop receiving traditional direct marketing communications (telephone calls with an operator and paper mail) it is sufficient to write an e-mail to the address dpo.boffi@dpoprofessionalservice.it with the subject line “cancellation from traditional”. In order to stop receiving any marketing communication you may write an e-mail to the address dpo.boffi@dpoprofessionalservice.it with the subject line “marketing cancellation”. In order to withdraw consent to non-automated profiling it is sufficient to write, at any time, an e-mail to the address dpo.boffi@dpoprofessionalservice.it with the subject line “no profiling”. Consent for pixel tracking is managed through the footer of the e-mail communications (preferences). Should data subjects consider that the processing of personal data carried out by the Controller infringes the provisions of Regulation (EU) 2016/679, they are free to lodge a complaint with the national supervisory authority, in particular in the Member State where they habitually reside or work, or in the place where the alleged infringement of the Regulation occurred (Italian Data Protection Authority https://www.garanteprivacy.it/), or to bring proceedings before the appropriate courts.
CHANGES TO THIS NOTICE
The controller may change, modify, add to or remove any part of this Privacy Policy. In order to make it easier to check for any changes, the notice will indicate the date on which it was updated.
Date of update: 11 August 2026
BOFFI|DE PADOVA SPA