When you use our services, you agree that our company may collect certain personal data relating to you. This page is intended to inform you about which data we collect, why we collect it, and how we use it.
We only process data provided directly by the user; we do not collect or process data through automated means.
If you provide personal data relating to third parties, such as your family members or friends, you must ensure that these individuals have been properly informed and have given their consent to the relevant processing activities in the manner described in this privacy notice.
If you are under 16 years old, you may not provide us with any personal data or register with Dofma Srl. In any event, we shall not be held responsible for any false statements provided by you. Should we become aware of the existence of inaccurate or false declarations, we will immediately delete any personal data acquired.
We may use the collected data, provided that you have expressly given your consent, to inform you about activities related to your interests.
In particular, we use your data to:
The provision of personal data is mandatory exclusively for processing activities necessary to provide the services offered by Dofma Srl (any refusal to provide data required for service delivery purposes will make it impossible to use the service).
The Data Controller is Dofma Srl, represented by its pro tempore legal representative, with registered office at:
Via Monte Grappa, 21 – 20811 Cesano Maderno (MB), Italy
VAT No. 00685120966 / Tax Code 00679310151
The Data Controller relies on Data Processors to achieve the purposes specified in section 1 and appoints a Data Protection Officer (DPO) to oversee the protection of personal data.
The data collected as part of the provision of the service may be communicated to:
Your personal data may be transferred outside the European Union to be processed by some of our service providers. In such cases, we ensure that the transfer takes place in compliance with applicable legislation and that an adequate level of protection of personal data is guaranteed, based on an adequacy decision, standard contractual clauses established by the European Commission, or Binding Corporate Rules.
Under no circumstances do we transfer or sell personal data to third parties.
You may withdraw your consent to processing at any time by sending an email request through the contact form available on our website, with the subject line: “Withdrawal of consent for the use of personal data”.
You may export your data at any time by submitting an email request through the contact form available on our website, with the subject line: “Personal data export”.
Your personal data will be exported within 30 days or, if the export process is particularly complex, within three months.
Any individual using our service may:
For analysis purposes aimed at developing and improving the service, users’ personal data may be retained for the same period.
For direct marketing and profiling purposes, we retain your data for a maximum period established by applicable legislation (respectively 24 and 12 months).
Invoices, accounting documents and transaction-related data are retained for 11 years as required by law (including tax obligations).
In the event of exercising the right to be forgotten through an explicit request for deletion of personal data processed by the Data Controller, please note that such data will be retained in a protected form with restricted access solely for the purposes of investigating and prosecuting crimes, for a period not exceeding 12 months from the date of the request. After this period, the data will be securely deleted or irreversibly anonymised.
Finally, please note that, for the same purposes, electronic traffic data, excluding the content of communications, will be retained for a period not exceeding 6 years from the date of communication, pursuant to Article 24 of Law No. 167/2017, which implemented EU Directive 2017/541 on counter-terrorism.
This privacy notice may be subject to changes. If substantial changes are made regarding the use of users’ data by the Data Controller, the Data Controller will notify users by publishing the updated information with maximum visibility on its webpages or through alternative or similar communication channels.