Home - Company - Privacy

Privacy

Privacy Policy

DATA COLLECTED

When you use our services, you agree that our company may collect certain personal data relating to you. This page is intended to inform you about which data we collect, why we collect it, and how we use it.

We only process data provided directly by the user; we do not collect or process data through automated means.

Third-party data

If you provide personal data relating to third parties, such as your family members or friends, you must ensure that these individuals have been properly informed and have given their consent to the relevant processing activities in the manner described in this privacy notice.

Data of minors under 16 years of age

If you are under 16 years old, you may not provide us with any personal data or register with Dofma Srl. In any event, we shall not be held responsible for any false statements provided by you. Should we become aware of the existence of inaccurate or false declarations, we will immediately delete any personal data acquired.


USE OF COLLECTED DATA

We may use the collected data, provided that you have expressly given your consent, to inform you about activities related to your interests.

In particular, we use your data to:

  • Send you promotional, commercial and advertising communications regarding events, initiatives or partnerships of Dofma Srl via email.
  • Carry out analysis and reporting activities related to promotional communication systems, such as monitoring the number of emails opened, clicks made on links contained in communications, the type of device used to read communications and the relevant operating system, or the list of users who have unsubscribed from the newsletter.

OBLIGATION TO PROVIDE DATA

The provision of personal data is mandatory exclusively for processing activities necessary to provide the services offered by Dofma Srl (any refusal to provide data required for service delivery purposes will make it impossible to use the service).


DATA CONTROLLER AND DATA PROCESSING PARTIES

The Data Controller is Dofma Srl, represented by its pro tempore legal representative, with registered office at:

Via Monte Grappa, 21 – 20811 Cesano Maderno (MB), Italy
VAT No. 00685120966 / Tax Code 00679310151

The Data Controller relies on Data Processors to achieve the purposes specified in section 1 and appoints a Data Protection Officer (DPO) to oversee the protection of personal data.

The data collected as part of the provision of the service may be communicated to:

  • Companies that perform functions strictly connected and instrumental to operational activities, including technical activities, such as providers of direct marketing and customer care services, companies providing archiving, administrative, payment and invoicing services, as well as administrative and judicial authorities where required by law.

Your personal data may be transferred outside the European Union to be processed by some of our service providers. In such cases, we ensure that the transfer takes place in compliance with applicable legislation and that an adequate level of protection of personal data is guaranteed, based on an adequacy decision, standard contractual clauses established by the European Commission, or Binding Corporate Rules.

Under no circumstances do we transfer or sell personal data to third parties.


MODIFICATION OF AND ACCESS TO DATA

You may withdraw your consent to processing at any time by sending an email request through the contact form available on our website, with the subject line: “Withdrawal of consent for the use of personal data”.

You may export your data at any time by submitting an email request through the contact form available on our website, with the subject line: “Personal data export”.

Your personal data will be exported within 30 days or, if the export process is particularly complex, within three months.

Any individual using our service may:

  • Obtain from the Data Controller, at any time, information regarding the existence of their personal data, its origin, the purposes and methods of processing and, where applicable, obtain access to personal data and the information referred to in Article 15 of the GDPR.
  • Request the updating, correction, integration, deletion, restriction of processing of personal data where one of the conditions provided for under Article 18 of the GDPR applies.
  • Request the anonymisation or blocking of personal data processed unlawfully, including data whose retention is unnecessary in relation to the purposes for which it was collected and/or subsequently processed.
  • Object, wholly or partially, for legitimate reasons, to the processing of personal data, even if relevant to the purpose of collection, as well as to the processing of personal data carried out for commercial information purposes or for sending advertising material, direct sales activities, market research or commercial communications.
  • Withdraw consent at any time without affecting the lawfulness of processing based on consent given before withdrawal.
  • Receive their personal data, knowingly and actively provided or collected through use of the service, in a structured, commonly used and machine-readable format, and transmit such data to another Data Controller without obstruction.
  • Lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).

DATA RETENTION

For analysis purposes aimed at developing and improving the service, users’ personal data may be retained for the same period.

For direct marketing and profiling purposes, we retain your data for a maximum period established by applicable legislation (respectively 24 and 12 months).

Invoices, accounting documents and transaction-related data are retained for 11 years as required by law (including tax obligations).

In the event of exercising the right to be forgotten through an explicit request for deletion of personal data processed by the Data Controller, please note that such data will be retained in a protected form with restricted access solely for the purposes of investigating and prosecuting crimes, for a period not exceeding 12 months from the date of the request. After this period, the data will be securely deleted or irreversibly anonymised.

Finally, please note that, for the same purposes, electronic traffic data, excluding the content of communications, will be retained for a period not exceeding 6 years from the date of communication, pursuant to Article 24 of Law No. 167/2017, which implemented EU Directive 2017/541 on counter-terrorism.


CHANGES TO THIS PRIVACY NOTICE

This privacy notice may be subject to changes. If substantial changes are made regarding the use of users’ data by the Data Controller, the Data Controller will notify users by publishing the updated information with maximum visibility on its webpages or through alternative or similar communication channels.