Privacy Policy
DATA CONTROLLER
MALLEI S.r.l.s.
Giardini Baltimora 1, 16121 Genoa, Italy
VAT No. 02752820999
Data Controller email address: [email protected]
TYPES OF DATA COLLECTED
Among the Personal Data collected by this website, either independently or through third parties, are: Usage Data; Cookies; first name; last name; gender; date of birth; phone number; VAT number; company name; address; country; state; province; email; ZIP/postal code; various types of Data; city; tax code; business sector; website; username; password; profession; billing address; shipping address; street number.
Full details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information notices displayed prior to data collection.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically while using this website.
Unless otherwise specified, all Data requested by this website are mandatory. If the User refuses to provide them, this website may be unable to provide the Service. In cases where this website indicates certain Data as optional, Users are free not to provide such Data, without any consequences on the availability or operation of the Service.
Users who have doubts about which Data are mandatory are encouraged to contact the Data Controller.
Any use of Cookies—or other tracking tools—by this website or by the owners of third-party services used by this website, unless otherwise stated, is intended to provide the Service requested by the User, in addition to the other purposes described in this document and in the Cookie Policy.
The User assumes responsibility for the Personal Data of third parties obtained, published, or shared through this website and guarantees that they have the right to communicate or disseminate such data, releasing the Data Controller from any liability toward third parties.
METHODS AND PLACE OF PROCESSING OF COLLECTED DATA
METHODS OF PROCESSING
The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.
Data processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the stated purposes. In addition to the Data Controller, in some cases other parties involved in the organization of this website (administrative, commercial, marketing staff, legal advisors, system administrators) or external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) may have access to the Data. These parties may also be appointed as Data Processors by the Data Controller, if necessary. The updated list of Data Processors may always be requested from the Data Controller.
LEGAL BASIS OF PROCESSING
The Data Controller processes Personal Data relating to the User when one of the following conditions applies:
- The User has given consent for one or more specific purposes.
Note: In some jurisdictions, the Data Controller may be authorized to process Personal Data without the User’s consent or another legal basis until the User objects (“opt-out”). This does not apply where the processing of Personal Data is governed by European data protection legislation. - Processing is necessary for the performance of a contract with the User and/or for pre-contractual measures.
- Processing is necessary to comply with a legal obligation to which the Data Controller is subject.
- Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller.
- Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by third parties.
It is always possible to request the Data Controller to clarify the specific legal basis applicable to each processing activity, and in particular whether the processing is based on law, a contract, or necessary to enter into a contract.
PLACE
Data are processed at the Data Controller’s operating offices and in any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information about the place of processing, the User may refer to the section concerning details on the processing of Personal Data.
The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization, as well as the security measures adopted by the Data Controller to protect the Data.
The User may verify whether any of the above-mentioned transfers take place by examining the relevant section of this document or by contacting the Data Controller using the contact details provided above.
RETENTION PERIOD
Data are processed and stored for as long as required by the purposes for which they were collected.
Therefore:
- Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User shall be retained until such contract has been fully performed.
- Personal Data collected for purposes related to the legitimate interest of the Data Controller shall be retained until such interest is satisfied. The User may obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
- When processing is based on the User’s consent, the Data Controller may retain Personal Data until such consent is withdrawn. Additionally, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, after this period, the rights of access, deletion, rectification, and data portability can no longer be exercised.
PURPOSES OF PROCESSING
User Data are collected to allow the Data Controller to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect its rights and interests (or those of Users or third parties), detect fraudulent or malicious activities, as well as for the following purposes: Interaction with social networks and external platforms; Display of content from external platforms; Statistics; Contacting the User; Payment management; Registration and authentication; Contact management and message sending; Heat mapping and session recording.
For detailed information on the purposes of processing and the Personal Data processed for each purpose, the User may refer to the section “Details on the Processing of Personal Data.”
DETAILS ON THE PROCESSING OF PERSONAL DATA
- CONTACTING THE USER VIA CONTACT FORM (this website)
By filling in the contact form with their Data, the User consents to their use to respond to requests for information, quotes, or any other purpose indicated in the form header.
Personal Data processed: ZIP code; city; tax code; last name; email; address; first name; phone number; VAT number; province; company name; various types of Data.
- IP TRACKING (Leadinfo B.V.)
A service that identifies B2B website visitors and reaches them within the same platform. This service may also collect data related to the date and time of page views and user interactions, such as clicks on links.
Personal Data processed: company name, address, phone number, email, and other data.
Place of processing: Netherlands – Privacy Policy.
- INTERACTION WITH SOCIAL NETWORKS AND EXTERNAL PLATFORMS
These services allow interactions with social networks or other external platforms directly from the pages of this website. The interactions and information acquired are subject to the User’s privacy settings on each social network. These services may also collect traffic data for the pages where they are installed, even when Users do not use them. Users are advised to log out of the respective services to ensure that processed data are not linked to their profiles.
YouTube Social Buttons and Widgets (Google Inc.)
Personal Data processed: Usage Data.
Place of processing: United States – Privacy Policy. Privacy Shield participant.
Meta Like Button and Social Widgets
Personal Data processed: Cookies; Usage Data.
Place of processing: United States – Privacy Policy. Privacy Shield participant.
- REGISTRATION AND AUTHENTICATION
By registering or authenticating, the User allows the Application to identify them and provide access to dedicated services.
Direct Registration (this website)
Personal Data processed: city; tax code; last name; email; address; billing address; shipping address; first name; street number; phone number; VAT number; password; province; username; various types of Data.
- DISPLAY OF CONTENT FROM EXTERNAL PLATFORMS
YouTube Video Widget (Google Inc.)
Personal Data processed: Cookies; Usage Data.
Place of processing: United States – Privacy Policy.
Facebook and Instagram Widgets (Meta)
Personal Data processed: Cookies; Usage Data.
Place of processing: United States – Privacy Policy
Font Awesome (Fonticons Inc.)
Personal Data processed: Usage Data.
Place of processing: United States – Privacy Policy.
- STATISTICS
Matomo Analytics
GDPR compliant analytics service used to monitor and analyze traffic data.
https://matomo.org/privacy-policy – GDPR Compliant https://matomo.org/gdpr-analytics [matomo_opt_out]
Google Analytics (Google Inc.)
Personal Data processed: Cookies; Usage Data.
Place of processing: United States – Privacy Policy – Opt Out. Privacy Shield participant. - LEADINFO
We use the lead generation service provided by Leadinfo B.V., Rotterdam, Netherlands, which identifies company visits to our website based on IP addresses and displays publicly available information such as company names and addresses. Leadinfo places two first-party cookies to provide transparency about website usage and processes domains to correlate IP addresses with companies.
Opt-out available at: www.leadinfo.com/en/opt-out - HUBSPOT
Our website and marketing communications may use HubSpot, a marketing and sales platform, to collect website usage data and optimize marketing campaigns. This may include IP addresses, device information, browsing data, and other information used to personalize the user experience and send relevant communications. HubSpot processes Personal Data on our behalf as described in its Privacy Policy. For further information, contact us at [indirizzo email].
USER RIGHTS
Users may exercise certain rights regarding their Data processed by the Data Controller, including:
- withdraw consent at any time;
- object to processing;
- access their Data;
- verify and request rectification;
- obtain restriction of processing;
- obtain deletion of Personal Data;
- receive their Data or have them transferred to another controller;
- lodge a complaint with the competent data protection authority.
DETAILS ON THE RIGHT TO OBJECT
When Personal Data are processed for public interest, official authority, or legitimate interests, Users may object for reasons related to their particular situation.
Users are informed that they may object to processing for direct marketing purposes at any time, without providing justification.
HOW TO EXERCISE USER RIGHTS
To exercise their rights, Users may send a request to the contact details of the Data Controller provided in this document. Requests are submitted free of charge and will be handled as soon as possible, in any case within one month.
