Personal Data
Processing Notice

Pursuant to EU Regulation 2016/679 (GDPR) and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 — Last updated: January 2025

Art. 1

Data Controller

Company name
Porcacchia Egidio Srl
Registered office
Via Giovan Battista Molinelli, 82 — 00166 Rome (RM), Italy
VAT number
15718791005
Phone
+39 06 65 77 14 99

The Data Controller is the natural or legal person who determines the purposes and means of the processing of personal data. For any question regarding the processing of your personal data, you can contact us at the email address indicated above.

Art. 2

Types of data collected and purposes of processing

This website collects personal data exclusively through the contact and quote request forms present on its pages. No personal data is collected through profiling cookies or advertising tracking systems.

Data categoryPurposeLegal basisRetention period
First name, last name, email, phone, organization Responding to requests for information and quotes Legitimate interest (Art. 6(1)(f) GDPR) 24 months from the last interaction
Email (newsletter) Sending regulatory updates and informational content Explicit consent (Art. 6(1)(a) GDPR) Until consent is withdrawn
Browsing data (server logs) System security, error analysis Legitimate interest (Art. 6(1)(f) GDPR) 30 days
Contractual data (clients) Performance of the service contract Contract performance (Art. 6(1)(b) GDPR) 10 years (tax obligations)

Personal data is never transferred to third parties for marketing purposes, nor sold or exchanged with other commercial entities.

Art. 3

Disclosure and transfer of data

Personal data may be disclosed, exclusively for the purposes indicated, to the following categories of parties:

Technical service providers: hosting providers, email services, client management platforms. These parties act as Data Processors pursuant to Art. 28 GDPR, with adequate contractual guarantees.

Professionals and consultants: accountants, legal consultants and other professionals who assist the Data Controller in the exercise of its activities, to the extent strictly necessary.

Competent authorities: where required by law or by orders of the judicial authority.

Personal data is not transferred outside the European Economic Area (EEA). Should this become necessary, adequate safeguards will be guaranteed pursuant to Chapter V of the GDPR.

Art. 4

Cookies and tracking technologies

This website exclusively uses technical cookies necessary for the pages to function (session management, display preferences). No profiling cookies, third-party cookies for advertising purposes, or behavioral analysis systems requiring consent under Art. 25 GDPR are used.

Technical cookies do not require user consent and cannot be disabled without compromising the functioning of the site. To manage or delete technical cookies already stored, you can use the settings of the browser in use.

Art. 5

Your rights

Pursuant to Articles 15–22 of the GDPR, you have the right to exercise the following rights at any time with respect to the Data Controller:

Right of access (Art. 15)

Obtain confirmation as to whether or not personal data concerning you is being processed and, if so, access the data and related information about the processing.

Right to rectification (Art. 16)

Obtain the rectification of inaccurate personal data concerning you, or the completion of incomplete personal data.

Right to erasure (Art. 17)

Obtain the erasure of personal data concerning you ("right to be forgotten") where the conditions set out in Art. 17 GDPR are met.

Right to restriction of processing (Art. 18)

Obtain the restriction of processing in the cases provided, for example when you contest its accuracy, for the period necessary to verify it.

Right to data portability (Art. 20)

Receive your personal data in a structured, commonly used and machine-readable format, and transmit it to another controller.

Right to object (Art. 21)

Object at any time to the processing of personal data concerning you based on the Data Controller's legitimate interest.

To exercise any of the rights indicated above, simply send a request to the address porcacchia.beniculturali@gmail.com. The Data Controller will respond within 30 days of receiving the request, with the possibility of an extension of a further 60 days in cases of particular complexity.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) (Garante Privacy), headquartered at Piazza Venezia 11 — 00187 Rome, website: www.garanteprivacy.it.

Art. 6

Security measures

The Data Controller adopts appropriate technical and organizational measures to ensure a level of security proportionate to the risk, pursuant to Art. 32 GDPR. These measures include, among others: data transmission via HTTPS/TLS protocol, access to personal data limited to authorized personnel, backup and disaster recovery procedures, periodic staff training on personal data processing.

In the event of a personal data breach that presents a high risk to the rights and freedoms of data subjects, the Data Controller will notify the breach to the supervisory authority within 72 hours and communicate it directly to data subjects in the cases provided for by Art. 34 GDPR.

Art. 7

Changes to this policy

The Data Controller reserves the right to modify this policy at any time, in particular to adapt it to any regulatory changes or changes in data processing methods. Changes will be published on this page with an updated date at the top. In the event of substantial changes, users who have provided their data for the newsletter will be informed by email.

The current version of this policy is the one published on this page. The date of the last revision is indicated in the header.