Notice provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the "GDPR") and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the "Italian Privacy Code"), to users who visit the website www.pms-metalli.com (the "Site") and to anyone who gets in touch with P.M.S. S.r.l.
1. Data controller
The Data Controller is P.M.S. S.r.l., with registered office at Via A. De Gasperi, 4, 20831 Seregno (MB), and operating facility at Via A. Volta, 10, 23888 La Valletta Brianza (LC) – VAT no. and tax code 08985610966 – REA MB-1900408.
The Controller can be contacted at the following addresses: e-mail [email protected] · PEC (certified e-mail) [email protected] · tel. +39 031 4151514.
The Controller has not appointed a Data Protection Officer (DPO), as the conditions set out in Article 37 GDPR do not apply.
2. Categories of data processed
2.1 Browsing data
The IT systems and software procedures used to operate the Site acquire, in the course of their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols: IP addresses, domain names of the devices used, URI/URL addresses of the resources requested, time of the request, method used, size of the file obtained, numeric code indicating the status of the response, browser and operating system. These data are not collected in order to be associated with identified data subjects, but by their very nature could allow identification. They are processed by the hosting provider for security, anonymous statistics and the proper functioning of the service and are deleted or anonymised within the provider's technical retention periods, without prejudice to the need to investigate computer crimes.
2.2 Data provided voluntarily through the contact form
By filling in the form on the "Contact" page, the user provides: full name, company (optional), e-mail address, telephone (optional), subject of the request, material and approximate quantity (optional), message text. Sending unsolicited e-mails or communications to the addresses shown on the Site entails the acquisition of the sender's address and of any other data included in the communication.
2.3 Data of customers, suppliers and their contact persons
In the course of its business relationships the Controller processes identification, contact, tax and banking data of customers and suppliers (natural persons, sole traders) and identification and contact data of company contact persons, together with the data required by environmental legislation for waste traceability (waste identification forms, registers, RENTRI) and by anti-money-laundering legislation where applicable.
The Site is not intended for children under 16 and does not knowingly collect data from minors. No special categories of data (Article 9 GDPR) or data relating to criminal convictions are processed, except where required by law.
3. Purposes, legal bases and retention
| Purpose | Legal basis | Retention |
|---|---|---|
| Enabling browsing and ensuring the security and proper functioning of the Site | Legitimate interest of the Controller (Art. 6(1)(f) GDPR) | Hosting provider access logs retained for up to 30 days |
| Responding to requests for information, quotations, collections and documentation sent via the form, e-mail or telephone | Pre-contractual measures taken at the data subject's request (Art. 6(1)(b) GDPR) | 24 months from the last contact, unless a contractual relationship is established |
| Management of contractual relationships with customers and suppliers (orders, deliveries, invoicing, payments) | Performance of a contract (Art. 6(1)(b) GDPR) | Duration of the relationship and 10 years thereafter (Art. 2220 Italian Civil Code) |
| Compliance with legal obligations: accounting, tax, environmental (waste traceability, loading/unloading registers, RENTRI, Albo Gestori Ambientali), anti-money-laundering and public security | Legal obligation (Art. 6(1)(c) GDPR) | Periods laid down by the individual regulations (3 to 10 years) |
| Protection of the Controller's rights in and out of court, fraud prevention | Legitimate interest (Art. 6(1)(f) GDPR) | Applicable limitation periods |
| Sending commercial communications to existing customers concerning similar products and services (soft spam) | Legitimate interest (Art. 6(1)(f) GDPR; Art. 130(4) Italian Privacy Code), with the right to object at any time | Until the data subject objects |
The provision of the data marked as mandatory in the contact form is necessary in order to process the request; failure to provide them makes it impossible to reply. The provision of optional data is voluntary.
4. Processing methods
Data are processed using IT and paper-based tools, by authorised and instructed personnel pursuant to Article 29 GDPR, with technical and organisational measures appropriate to ensure their security, integrity and confidentiality (Article 32 GDPR): encrypted HTTPS connection, access control, backups, system updates. No automated decision-making or profiling is carried out.
5. Recipients of the data
For the purposes set out above, data may be disclosed to the following categories of recipients, appointed where necessary as Data Processors pursuant to Article 28 GDPR:
- Formspree, Inc. (United States) – service for managing and forwarding messages sent through the contact form; data are transferred on the basis of the Standard Contractual Clauses approved by the European Commission (Article 46 GDPR).
- Cloudflare, Inc. (San Francisco, USA) and Cloudflare Germany GmbH – hosting of the Site (Cloudflare Pages service), content delivery network (CDN), protection against attacks and management of access logs; Cloudflare is certified under the EU-U.S. Data Privacy Framework and applies the Standard Contractual Clauses; access logs are retained for security purposes for no longer than 30 days.
- Google Ireland Ltd. – only if the user chooses to activate the interactive map (Google Maps) and for the loading of typefaces (Google Fonts); see the Cookies section.
- Consultants and professionals (accountant, payroll consultant, environmental consultant, lawyers), credit and insurance institutions, debt collection companies, carriers and providers of logistics and IT services.
- Public authorities, supervisory and control bodies (Province, ARPA – regional environmental agency, Albo Nazionale Gestori Ambientali, Italian Revenue Agency, judicial authorities) in the cases provided for by law.
Data are not disseminated or sold to third parties for marketing purposes.
6. Transfer of data outside the EU
Data are processed mainly within the European Union. The use of Cloudflare and Formspree services and, if activated, Google services may involve the transfer of data to the United States; such transfers take place on the basis of the EU-U.S. Data Privacy Framework adequacy decision for providers certified under it and, in any event, of the Standard Contractual Clauses set out in Decision (EU) 2021/914, with the supplementary safeguards provided for. A copy of the safeguards is available on request.
7. Rights of the data subject
Pursuant to Articles 15–22 GDPR, the data subject has the right to obtain from the Controller: access to their data and information about the processing; rectification of inaccurate data and completion of incomplete data; erasure ("right to be forgotten") in the cases provided for; restriction of processing; portability of the data provided, in a structured, commonly used format; objection, at any time, to processing based on legitimate interest, including the sending of commercial communications; withdrawal of consent, where given, without affecting the lawfulness of processing carried out beforehand.
Requests may be sent informally to [email protected] or by PEC to [email protected] or by post to the registered office. The Controller replies within one month of receipt, which may be extended by two months in cases of particular complexity.
Data subjects who consider that the processing infringes the applicable legislation have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (Piazza Venezia 11, 00187 Rome, Italy – www.garanteprivacy.it) or with the supervisory authority of the Member State of their habitual residence, or to bring proceedings before the courts.
8. Cookies and tracking technologies
Pursuant to Article 122 of the Italian Privacy Code and the Guidelines of the Italian Data Protection Authority of 10 June 2021, please note that the Site does not use profiling cookies, whether first- or third-party, and does not use statistical analysis tools (analytics) or tracking pixels.
8.1 Technical cookies
The Site does not install its own technical cookies. The contact form and the storage of browsing preferences work without cookies. User consent is not required for technical cookies.
8.2 Third-party content
Google Maps – The "Facility" and "Contact" pages contain an interactive map that is not loaded automatically: it is displayed only after the user clicks the "Show the map" button. Only in that case does the browser connect to the servers of Google Ireland Ltd., which may install its own cookies and process the user's IP address in accordance with its own privacy policy (policies.google.com/privacy). Clicking the button constitutes consent to the loading of the third-party content; alternatively, the address of the facility is shown in plain text on the same pages.
Google Fonts – The Site uses the "Manrope" typeface provided by Google Fonts. When pages load, the browser requests the font files from Google's servers, which receive the user's IP address. Google states that it does not use cookies for this service and does not associate the requests with other user data. Should a complete absence of third-party connections be preferred, the fonts can be hosted directly on the Controller's server (a setting provided for at publication stage).
8.3 How to manage cookies
Users can block or delete cookies at any time through their browser settings: Chrome · Firefox · Safari · Edge. Disabling third-party cookies does not affect browsing of the Site.
9. Links to external websites
The Site may contain links to other websites (e.g. certification bodies, authorities). The Controller is not responsible for the processing of data carried out by such websites, to which their respective privacy notices apply.
10. Changes to this notice
The Controller reserves the right to update this notice in response to changes in legislation or in the services used. The current version is always available on this page, together with the date of the last update.
