Privacy

Privacy and Cookie Policy

Information provided pursuant to Art. 13 of EU Reg. 2016/679 (the GDPR) and Italian Legislative Decree 196/2003 (Personal Data Protection Code) as amended by Legislative Decree 101/18.

1) General information

Data subjects are informed of the following general points, which apply to all processing areas:

  • all data of the parties we interact with is processed lawfully, fairly and transparently, in accordance with the general principles of Art. 5 of the GDPR;
  • specific security measures are in place to prevent data loss, unlawful or incorrect use and unauthorised access, pursuant to Art. 32 of the GDPR.

Contacts and rights of data subjects

  • the Data Controller is this Organisation, which may be contacted to exercise all the rights provided by Art. 15-21 of the GDPR (access, rectification, erasure, restriction, portability, objection) and to withdraw consent previously given; if requests are not answered, data subjects may lodge a complaint with the supervisory authority for personal data protection (GDPR – Art. 13(2)(d)).
  • The company has appointed a DPO who can be contacted at dpo@gallidataservice.com

2) Processing related to the operation of this website

Browsing data

The IT systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of internet communication protocols. This information is not collected in order to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category includes IP addresses or domain names of the computers used by visitors, URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file returned, the numeric code indicating the status of the server response (success, error, etc.) and other parameters relating to the user's operating system and IT environment.

Purpose and legal basis of processing

(GDPR – Art. 13(1)(c))

This data is used solely to obtain statistical information on the use of the site and to check that it works correctly. The data may also be used to establish liability in the event of alleged computer crimes against the site (legitimate interests of the controller).

Scope of disclosure

(GDPR – Art. 13(1)(e),(f))

Data may be processed only by internal staff duly authorised and instructed to process it (GDPR – Art. 29) or by parties responsible for maintaining the web platform (appointed as external processors). It will not be disclosed to other parties, disseminated or transferred outside the EU. Only in the event of an investigation may it be made available to the competent authorities.

Data retention period

(GDPR – Art. 13(2)(a))

Data is normally kept for short periods of time, except where extended in connection with investigations.

Provision of data

(GDPR – Art. 13(2)(f))

The data is not provided by the data subject but acquired automatically by the site's technology systems.

Cookies

What cookies are: cookies are short pieces of text (letters and/or numbers) that allow a web server to store information on the client (the browser) to be reused during the same visit (session cookies) or later, even days afterwards (persistent cookies). Cookies are stored, according to the user's preferences, by the individual browser on the specific device used (computer, tablet, smartphone). Similar technologies, such as web beacons, transparent GIFs and all forms of local storage introduced with HTML5, can be used to collect information on user behaviour and use of the services. In the remainder of this notice we refer to cookies and all similar technologies simply as “cookies”.

Cookie policy and managing preferences

The full cookie policy can be consulted through the dedicated link in the banner (click the padlock icon at the bottom right).

The site may contain links to third-party sites and third-party cookies; for more information please review the privacy policy of any linked sites.

Managing preferences through the banner and dedicated button

In accordance with the “Guidelines on the use of cookies and other tracking tools” adopted by the Italian Data Protection Authority, published in Official Gazette no. 163 of 9 July 2021 and in force since 8 January 2022, users can always easily change their preferences by clicking the dedicated padlock button visible at the bottom right of every page.

Managing preferences through the main browsers

Users can decide whether or not to accept cookies using their browser settings (note that, by default, almost all web browsers are set to accept cookies automatically). The setting can be changed and defined specifically for different sites and web applications. In addition, the leading browsers allow different settings for “first-party” and “third-party” cookies. Cookie configuration is usually found in the “Preferences”, “Tools” or “Options” menu.

Below are links to cookie management guides for the main browsers:

Further information

Specific services

The site may contain data collection forms intended to provide visitors with services or functions (e.g. request information, registration, support, open a ticket, check ticket status, etc.).

Purpose and legal basis of processing

(GDPR – Art. 13(1)(c))

Identification and contact data necessary to respond to the data subject's requests may be requested. Sending the request is subject to specific, free and informed consent (GDPR – Art. 6(1)(a)).

Scope of disclosure

(GDPR – Art. 13(1)(e),(f))

Data is processed only by staff duly authorised and instructed to process it (GDPR – Art. 29) or by parties responsible for maintaining the web platform or delivering the service (appointed as external processors). Data will not be disseminated or transferred outside the EU.

Data retention period

(GDPR – Art. 13(2)(a))

Data is kept for periods compatible with the purpose of collection.

Provision of data

(GDPR – Art. 13(2)(f))

Providing the data in mandatory fields is necessary in order to receive a reply, while optional fields are intended to give our staff further useful details to facilitate contact.

Data voluntarily provided by the user

The optional, explicit and voluntary sending of email and/or ordinary mail to the addresses shown on this site entails the subsequent acquisition of the sender's address, necessary to reply to requests, as well as any other personal data included in the message. Should the sender submit a CV as a job application, they remain solely responsible for the relevance and accuracy of the data sent. Please note that any CV without authorisation to process the data will be deleted immediately.

3) Processing related to relationships with current and potential customers and suppliers

3.1 Subject of the processing

The organisation processes identifying personal data of customers/suppliers (for example name, surname, company name, personal/tax details, address, telephone, email, banking and payment references) and of their operational contacts (name, surname and contact details), acquired and used in the course of delivering the services provided.

3.2 Purpose and legal basis of processing

Data is processed in order to:

  • enter into contractual/professional relationships;
  • fulfil pre-contractual, contractual and tax obligations arising from existing relationships and manage the related communications;
  • comply with obligations laid down by law, regulation, EU legislation or an order of the authorities;
  • pursue a legitimate interest or right of the Controller (for example: the right of defence in legal proceedings, protection of credit positions, ordinary internal operational, management and accounting needs).

Failure to provide this data will make it impossible to establish a relationship with the Controller. The above purposes constitute, pursuant to Art. 6(b),(c),(f), appropriate legal bases for lawful processing. Should processing be intended for other purposes, specific consent will be requested from data subjects.

3.3 Processing methods

Personal data is processed by means of the operations set out in Art. 4(2) of the GDPR, namely: collection, recording, organisation, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, erasure and destruction. Personal data is processed both on paper and electronically and/or automatically. The Controller will process personal data for as long as necessary to fulfil the purposes for which it was collected and the related legal obligations.

3.4 Scope of processing

Data is processed by internal parties duly authorised and instructed pursuant to Art. 29 of the GDPR. You may also request details of the scope of disclosure of personal data, obtaining precise information on any external parties acting as Processors or autonomous Controllers (consultants, technicians, banks, carriers, etc.).

4) Policy updates

Please note that this notice may be revised periodically, also in relation to applicable legislation and case law. Data subjects are therefore invited to consult this policy from time to time.