Privacy Policy
PRIVACY POLICY
This privacy policy describes how this website manages the processing of personal data of users who visit it, as well as the processing practices applied to data transmitted by users through this website.
In compliance with Articles 13 (for data collected from the data subject) and 14 (for data not collected from the data subject) of Regulation (EU) 2016/679 (GDPR), the following information is provided to Users of this Website. This information refers exclusively to the processing carried out through this Website and not through other websites that may be accessed via links contained herein. Users are encouraged to consult the privacy policies provided by the respective data controllers of those websites.
This Website and any services offered through it are intended for individuals who are at least eighteen years old. The Data Controller does not knowingly collect personal data relating to individuals under the age of 18. Upon request, any personal data inadvertently collected relating to minors will be promptly deleted.
1. Data Controller
MAPPY ITALIA S.p.A., with registered office at Via Tevere, 3 – 20031 Cesate (MI), Italy – VAT Number: IT04938620962 (hereinafter also referred to as the “Data Controller”), as the controller of the personal data of users of this website (hereinafter “Users”), provides this privacy policy pursuant to Article 13 of Legislative Decree 196/2003 and Regulation (EU) 2016/679 (GDPR).
Data Controller contact details:
Phone: +39 02 99431100
Email: info@mappyitalia.com
VAT Number: IT04938620962
SDI Code: J6URRTW
The Data Controller may appoint external service providers, web agencies, or technical consultants as Data Processors for activities related to technical support, maintenance, and management of the Website. Personal data may also be processed by authorized personnel within the organization who have received appropriate instructions.
For any request regarding the processing of personal data, Users may contact the Data Controller at info@mappyitalia.com.
2. Categories of Data Processed and Sources
- Browsing data
- Cookies (please refer to the Cookie Policy section)
- Data voluntarily provided by the user, including:
- Identification and contact data
- Personal data
- Billing or company data
Data may be collected through website browsing, contact forms, email communications, or other voluntary interactions with the website.
Data may also originate from public sources or from previous interactions with the website, including cookies or similar technologies used to improve the browsing experience.
3. Purposes of Data Processing
The personal data of Users will be processed in accordance with applicable data protection regulations and used exclusively for purposes related to the operation of the Website and the services offered.
In particular, personal data may be processed for the following purposes:
- to respond to requests for information submitted through the website or via email;
- to manage contractual or commercial relationships;
- to send informational communications relating to the services and products offered;
- to manage newsletter subscriptions and send marketing communications with the user’s consent;
- to comply with legal, administrative, and fiscal obligations;
- to improve the functionality of the website and the browsing experience.
Data collected automatically during browsing are used exclusively for statistical purposes and to ensure the security of the website.
Data collected through email platforms
For sending email communications, the Data Controller may use platforms that allow the collection of statistical data such as email opening rates, clicks on links, IP addresses, browser types, and similar technical details. Such data are used solely to improve the quality of communications.
Users may unsubscribe from newsletters at any time by clicking the unsubscribe link contained in the emails received.
4. Legal Basis for Processing
The processing of personal data is based on:
- the performance of contractual or pre-contractual obligations;
- compliance with legal obligations;
- the legitimate interest of the Data Controller;
- the explicit consent of the data subject where required.
5. Legitimate Interest of the Data Controller
The processing of personal data may also be based on the legitimate interest of the Data Controller, such as managing the website, ensuring IT security, preventing misuse, and promoting its services.
6. Provision of Data
The provision of browsing data depends on the privacy settings configured by the user in their browser. In some cases, disabling such settings may affect the proper functioning of the website.
The provision of data through contact forms is voluntary but necessary in order to respond to the user’s request.
7. Recipients of Personal Data
Personal data may be communicated to third parties that cooperate with the Data Controller for the management of the website and the services provided, including:
- IT consultants and technical service providers;
- hosting providers and digital platform managers;
- legal and tax advisors;
- public authorities where required by law.
Personal data will not be publicly disclosed.
8. Data Retention Period
Personal data will be retained for the period strictly necessary to achieve the purposes for which they were collected and in compliance with applicable legal obligations.
Data used for marketing purposes will be retained until the user withdraws their consent.
9. Rights of the Data Subject
Pursuant to Articles 15–22 of the GDPR, the data subject has the right to:
- access their personal data;
- request rectification or updating of their data;
- request erasure of their data;
- request restriction of processing;
- object to the processing;
- request data portability.
These rights may be exercised by contacting the Data Controller at info@mappyitalia.com.
10. Withdrawal of Consent
The data subject may withdraw consent at any time by sending a request to info@mappyitalia.com.
11. Complaints
Data subjects have the right to lodge a complaint with the competent supervisory authority, which in Italy is the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
12. Profiling
Personal data may be used for profiling activities aimed at analyzing users’ preferences, interests, and behavior in relation to the products and services offered by the Data Controller, in order to provide more relevant communications and services.