The Data Controller is the natural or legal person who determines the purposes and means of the processing of personal data. For any question regarding the processing of your personal data, you can contact us at the email address indicated above.
This website collects personal data exclusively through the contact and quote request forms present on its pages. No personal data is collected through profiling cookies or advertising tracking systems.
| Data category | Purpose | Legal basis | Retention period |
|---|---|---|---|
| First name, last name, email, phone, organization | Responding to requests for information and quotes | Legitimate interest (Art. 6(1)(f) GDPR) | 24 months from the last interaction |
| Email (newsletter) | Sending regulatory updates and informational content | Explicit consent (Art. 6(1)(a) GDPR) | Until consent is withdrawn |
| Browsing data (server logs) | System security, error analysis | Legitimate interest (Art. 6(1)(f) GDPR) | 30 days |
| Contractual data (clients) | Performance of the service contract | Contract performance (Art. 6(1)(b) GDPR) | 10 years (tax obligations) |
Personal data is never transferred to third parties for marketing purposes, nor sold or exchanged with other commercial entities.
Personal data may be disclosed, exclusively for the purposes indicated, to the following categories of parties:
Technical service providers: hosting providers, email services, client management platforms. These parties act as Data Processors pursuant to Art. 28 GDPR, with adequate contractual guarantees.
Professionals and consultants: accountants, legal consultants and other professionals who assist the Data Controller in the exercise of its activities, to the extent strictly necessary.
Competent authorities: where required by law or by orders of the judicial authority.
Personal data is not transferred outside the European Economic Area (EEA). Should this become necessary, adequate safeguards will be guaranteed pursuant to Chapter V of the GDPR.
This website exclusively uses technical cookies necessary for the pages to function (session management, display preferences). No profiling cookies, third-party cookies for advertising purposes, or behavioral analysis systems requiring consent under Art. 25 GDPR are used.
Technical cookies do not require user consent and cannot be disabled without compromising the functioning of the site. To manage or delete technical cookies already stored, you can use the settings of the browser in use.
Pursuant to Articles 15–22 of the GDPR, you have the right to exercise the following rights at any time with respect to the Data Controller:
Obtain confirmation as to whether or not personal data concerning you is being processed and, if so, access the data and related information about the processing.
Obtain the rectification of inaccurate personal data concerning you, or the completion of incomplete personal data.
Obtain the erasure of personal data concerning you ("right to be forgotten") where the conditions set out in Art. 17 GDPR are met.
Obtain the restriction of processing in the cases provided, for example when you contest its accuracy, for the period necessary to verify it.
Receive your personal data in a structured, commonly used and machine-readable format, and transmit it to another controller.
Object at any time to the processing of personal data concerning you based on the Data Controller's legitimate interest.
To exercise any of the rights indicated above, simply send a request to the address porcacchia.beniculturali@gmail.com. The Data Controller will respond within 30 days of receiving the request, with the possibility of an extension of a further 60 days in cases of particular complexity.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) (Garante Privacy), headquartered at Piazza Venezia 11 — 00187 Rome, website: www.garanteprivacy.it.
The Data Controller adopts appropriate technical and organizational measures to ensure a level of security proportionate to the risk, pursuant to Art. 32 GDPR. These measures include, among others: data transmission via HTTPS/TLS protocol, access to personal data limited to authorized personnel, backup and disaster recovery procedures, periodic staff training on personal data processing.
In the event of a personal data breach that presents a high risk to the rights and freedoms of data subjects, the Data Controller will notify the breach to the supervisory authority within 72 hours and communicate it directly to data subjects in the cases provided for by Art. 34 GDPR.
The Data Controller reserves the right to modify this policy at any time, in particular to adapt it to any regulatory changes or changes in data processing methods. Changes will be published on this page with an updated date at the top. In the event of substantial changes, users who have provided their data for the newsletter will be informed by email.
The current version of this policy is the one published on this page. The date of the last revision is indicated in the header.