Notice pursuant to art. 13 of Regulation (EU) 2016/679.
Privacy Notice for Tirrena
Tirrena website, contact forms and contact channels published on the website. This notice describes the personal data processing carried out within the indicated scope, the related purposes and how data subjects may exercise their rights.
Data Controller
The entity indicated below acts as Data Controller and determines the purposes and means of the processing described in this notice.
- Legal name
- TIRRENA S.r.l.
- Registered office or address
- Viale Domenico Zaccagna, 6 - 54033 Avenza Carrara (MS), Italia
- VAT number
- 01374420451
- Tax code
- 01374420451
- Privacy contact
- privacy@tirrena.it
- Contact page
- en/contacts/
- Certified email
- tirrenasrl2018@legalmail.it
- Telephone
- +39 0585 50731
Personal data processing activities
Browsing, operation and security data
The technical systems collect browsing data required to make pages available, protect the website and diagnose possible anomalies.
- Categories of personal data
- IP address
- date and time of the request
- requested URL or resource
- technical information about browser and device
- technical, diagnostic and security logs
- Source of personal data
- Collection: from the data subject - Source type: data subject - Data generated while browsing the website
- Purposes and related legal basis
- allow the display of requested pages and resources - art. 6, par. 1, lett. f GDPR - legitimate interest of the Controller
- keep the website secure, operational and protected against abuse - art. 6, par. 1, lett. f GDPR - legitimate interest of the Controller in website security
- Legitimate interests pursued
- keeping the website available and secure
- preventing abuse, unauthorised access and automated submissions
- diagnosing technical errors and protecting the Controller's rights
- Retention period
- Criteria: For the time strictly necessary for technical, diagnostic and security purposes; any further retention occurs only in case of anomalies, abuse, legal obligations or the need to protect a right.
- Recipients or categories of recipients
- hosting, maintenance, security and technical infrastructure providers - processors, where applicable
- personnel authorised by the Controller - authorised persons
- Transfers to third countries
- No transfers to third countries carried out by the Controller are envisaged within this activity.
- Necessity of processing and consequences
- Provision required - The processing of technical and browsing data is necessary to make the website available. - Consequences: Without the necessary technical data, the website or some essential features may not be available correctly.
Contact requests and communications
Collection and management of data voluntarily sent through contact forms, email, telephone or other contact details published on the website, including commercial requests, quotation requests and spontaneous applications.
- Categories of personal data
- name and surname, if provided
- company name or employer, if provided
- contact details provided, such as email and telephone
- subject, content and details of the request
- any information contained in CVs or attachments sent spontaneously
- technical data essential for sending the request
- Source of personal data
- Collection: from the data subject - Source type: data subject - Data provided directly by the data subject through the contact channels
- Purposes and related legal basis
- reply to information, quotation, support or contact requests - art. 6, par. 1, lett. b GDPR - pre-contractual or contractual measures taken at the request of the data subject
- manage spontaneous applications sent through the published contact details - art. 6, par. 1, lett. b GDPR - pre-contractual measures taken at the request of the data subject
- keep evidence of communications in case of administrative, legal or defensive needs - art. 6, par. 1, lett. f GDPR - legitimate interest of the Controller in managing and protecting received communications
- Legitimate interests pursued
- managing the operational follow-up to received communications
- keeping evidence of requests in case of disputes or protection needs
- Retention period
- Criteria: For the time necessary to manage the request and any subsequent developments. Data sent through the website is not stored permanently inside the website; further retention may occur for legal obligations or for the establishment, exercise or defence of a right.
- Recipients or categories of recipients
- personnel authorised by the Controller - authorised persons
- technical website and email providers - processors, where applicable
- consultants or professionals - independent controllers or processors, where necessary for administrative obligations or protection of a right
- Transfers to third countries
- No transfers to third countries carried out by the Controller are envisaged within this activity.
- Necessity of processing and consequences
- Provision required - Providing the data needed for the request is necessary to receive a reply or the requested service. - Consequences: Failure to provide the data may make it impossible to process the request.
Technical cookies and other technical identifiers
The current website uses only cookies and technical identifiers strictly necessary for operation, security and delivery of the features requested by the user. No profiling, advertising, analytics or other third-party cookies are used.
- Categories of personal data
- technical session identifiers
- preferences or technical information required for essential operation
- information required to protect requests and forms
- Source of personal data
- Collection: from the data subject - Source type: data subject - Data generated while using the essential website features
- Purposes and related legal basis
- manage session, security and essential website features - art. 6, par. 1, lett. f GDPR - legitimate interest of the Controller in essential website operation
- protect forms, requests and technical infrastructure against abuse - art. 6, par. 1, lett. f GDPR - legitimate interest of the Controller in website security
- Access to or storage on the terminal
- Rule: Article 122 of the Italian Privacy Code - Category: strictly necessary technical cookies and identifiers - Prior consent: not required - Access to or storage on the terminal is limited to what is necessary to provide features requested by the user, ensure security and maintain the correct operation of the website. - The website does not use profiling, advertising, analytics or other third-party cookies.
- Declared cookies or technical identifiers
- Name or category: technical session or security identifier - Type: technical cookie or equivalent identifier - Purpose: maintain the session, protect requests and enable the essential features requested by the user - Duration: session or different period strictly necessary for the technical feature - Provider: first party or technical website provider
- Legitimate interests pursued
- keeping the essential website features available and secure
- protecting forms, requests and technical infrastructure against abuse or abnormal use
- Retention period
- Criteria: Browsing session or different period strictly necessary for the specific technical purpose.
- Recipients or categories of recipients
- hosting, maintenance and technical infrastructure providers - processors, where applicable
- personnel authorised by the Controller - authorised persons
- Transfers to third countries
- No transfers to third countries carried out by the Controller are envisaged within this activity.
- Necessity of processing and consequences
- Provision required - The use of technical identifiers is necessary for the features to which they relate. - Consequences: Their unavailability may prevent or compromise the correct operation of the website.
Information on declared cookies and technical identifiers is provided in this notice. Prior consent is not required for strictly necessary technologies.
Processing methods and security measures
Personal data is processed using paper, electronic and automated methods, with logic strictly related to the stated purposes and in a way that ensures security and confidentiality.
- Technical measures
- protected administrative access
- hosting configured with the provider's security measures
- limitation of data permanently stored by the website
- Organisational measures
- access to data limited to authorised persons
- involvement of providers and consultants only when necessary and with consistent privacy roles
Data subject rights
Where the conditions are met, the data subject may exercise the rights recognised by arts. 15-22 GDPR.
- access to personal data - art. 15 GDPR
- rectification of inaccurate data - art. 16 GDPR
- erasure of data - art. 17 GDPR
- restriction of processing - art. 18 GDPR
- data portability - art. 20 GDPR
- objection to processing - art. 21 GDPR
The Controller replies without undue delay and normally within one month of receiving the request. This period may be extended by a further two months, taking into account the complexity and number of requests; in that case, the data subject is informed of the extension and the reasons for it.
Requests may be sent to the Controller at privacy@tirrena.it.
Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, the data subject has the right to lodge a complaint with a supervisory authority pursuant to art. 77 GDPR. In Italy, the competent authority is the Garante per la protezione dei dati personali.
Minors
Users under 16 years of age must not provide personal data without the consent of their parents or the person exercising parental responsibility.
Current cookie setup
The current website uses only strictly necessary technical cookies or identifiers, without profiling, advertising, analytics or other third-party cookies.
Legal references
This notice has been prepared taking into account, in particular, the following legal references.
- Regulation (EU) 2016/679 (GDPR), in particular arts. 5, 6, 12, 13, 15-21, 28, 32 and 77.
- Italian Legislative Decree no. 196 of 30 June 2003 (Personal Data Protection Code), as amended by Italian Legislative Decree no. 101 of 10 August 2018.
- Article 122 of the Italian Privacy Code and the Italian supervisory authority guidelines on cookies and other tracking tools of 10 June 2021.
Updates to this notice
The Controller may update this notice in case of changes to processing, services or applicable law. The updated version is made available through the same channels used for publishing the document.