Privacy Policy
Who We Are
This notice is provided pursuant to Article 13 of European Regulation 2016/679 on the protection of personal data (“Regulation” or “GDPR”), Legislative Decree No. 196 of 30/06/2003 (“Privacy Code”), as amended and supplemented by Legislative Decree No. 101/2018, and subsequent amendments and additions – by Grifal S.p.A., with registered office in Cologno al Serio (BG), Via XXIV Maggio 1, Telephone +39 0354871487, email privacy@grifal.it, in its capacity as Data Controller of your personal data.
The purpose of this Privacy Policy is to inform the data subject about how their personal data are processed.
Methods of Processing Personal Data
The Personal Data provided or collected will be processed in accordance with the principles of fairness, lawfulness, transparency and protection of confidentiality, pursuant to the applicable legislation. The Data Controller processes Users’ Personal Data by adopting appropriate security measures aimed at preventing unauthorized access, disclosure, alteration or destruction of Personal Data. Processing is carried out using IT and/or electronic tools, with organizational methods and procedures strictly related to the purposes indicated.
Tools Used for the Processing of Personal Data
CONTACT FORM
By completing the contact form with their Data, the User consents to their use for the purpose of responding to requests for information or for any other purpose indicated in the heading of the form. Personal Data collected through the contact form: email address, telephone number, personal details.
Newsletter
By subscribing to the newsletter, the User’s email address is automatically added to a contact list to which email messages containing information, including commercial and promotional information, may be sent. The User may unsubscribe from the newsletter at any time by clicking on the relevant button included in the emails. Personal Data collected: email address and personal details.
Types of Data Processed
The website provides informational and, at times, interactive content.
This website uses cookies, i.e. small text files that may be used by websites to make the User experience more efficient and to personalize content and advertisements, provide social media features and analyze traffic – Cookie Policy
While browsing the website, the Company may therefore collect information about the visitor in the following ways:
Browsing Data
The IT systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes: IP addresses, the type of browser used, the operating system, the domain name and the addresses of websites from which access was made, information on the pages visited by Users within the website, access time, time spent on individual pages, internal navigation analysis and other parameters relating to the User’s operating system and IT environment.
Additional Categories of Data
These include all personal data provided by the visitor through the website, for example:
by completing a form to request a quotation and/or information about the services offered and/or to submit a contact request and/or to download exclusive content;
by writing to the email addresses provided on our website to request information;
by completing a form to submit their curriculum vitae;
by completing a form to receive our newsletter and marketing communications.
In addition to the above-mentioned categories of Personal Data, further data collected by the Data Controller through tracking tools may be processed, including marketing pixels and tags used to analyze the effectiveness of advertising campaigns; these tools collect only aggregated information relating to the User’s browsing activity, the device used, the pages visited and the actions performed on the website.
Purposes of Processing and Legal Basis
As indicated above, Personal Data may be collected independently by the Data Controller or through third parties. In the latter case, the IT systems and software procedures used to operate this website acquire certain technical and IT-related Personal Data of Users (e.g. IP address, type of browser used, operating system, domain name and the addresses of websites from which access or exit occurred, etc.), the transmission of which is inherent in the normal operation of the Internet. Such Data may be processed solely for the purpose of obtaining anonymous statistical information on the use of the website and/or monitoring its proper functioning and will be deleted immediately after processing.
The Data that the Data Subject chooses to provide voluntarily will be processed in compliance with the lawfulness conditions set out in Article 6 of the GDPR and will be processed to enable the website to provide its services, as well as for the Purposes indicated below, and will be retained for the time necessary to fulfill those Purposes.
The Data provided are processed for the following purposes:
to provide the goods and/or services requested by the User, manage contracts entered into by the User, carry out the related administrative, accounting, tax and legal obligations, and process requests submitted by the User. Processing carried out for these purposes is necessary for the performance of contractual obligations or to comply with the Data Subject’s requests and does not require specific consent;
to assess, in aggregate form, the experience of using our platforms and the products and services we offer, and to ensure the proper functioning of web pages and their content. Processing carried out for these purposes is based on the Data Controller’s legitimate interest;
to send communications and promotional, commercial and advertising material, or material relating to initiatives and events organized by the Data Controller, through newsletters. This processing is based on the User’s freely given consent;
to carry out statistical analyses on aggregated and anonymous data in order to analyze User behavior, improve the products and services provided by the Data Controller and meet the User’s expectations. Processing carried out for these purposes is based on the Data Controller’s legitimate interest.
Sharing and Transfer of Personal Data
The Data collected by the Data Controller will be shared only for the purposes stated above; we will not share or transfer Personal Data to third parties other than those indicated in this Privacy Policy.
In the course of our activities and exclusively for the same purposes as those listed in this Privacy Policy, the Personal Data collected may be transferred to the following categories of recipients:
personnel specifically appointed and trained for this purpose, involved in the organization of the website (administrative, commercial, marketing and legal personnel, system administrators);
PachInPro, a company of the Grifal Group;
service providers (e.g. IT system providers, cloud service providers, database providers and consultants);
Public Authorities for legal purposes;
any public and/or private entity to which the communication of your Personal Data is necessary in relation to the purposes indicated above.
The updated list of Data Processors is available at the Data Controller’s registered office and will be provided upon written request.
The Data are processed at the Data Controller’s operational headquarters. For further information, the Data Controller may be contacted. The Data may be processed by natural persons and/or legal entities acting on behalf of the Data Controller and bound by specific contractual obligations, with registered offices in EU or non-EU countries. If the Data are transferred outside the EEA, the Data Controller will adopt all appropriate contractual measures to ensure an adequate level of Data protection.
Protection of Personal Data
The Data Controller has implemented appropriate technical and organizational measures to provide an adequate level of security and confidentiality for Personal Data.
These measures take into account:
the state of the art of technology;
the costs of implementation;
the nature of the Data;
the risks associated with Processing.
The purpose is to protect Personal Data against accidental or unlawful destruction or alteration, accidental loss, unauthorized disclosure or access, and other forms of unlawful processing. Furthermore, the processing of Personal Data must be
adequate, relevant and not excessive, and the Data Controller must ensure that such Data remain up to date and accurate.
Data Retention Periods
Without prejudice to each User’s right to object to the processing of Personal Data and/or request their deletion, the Company will retain the Personal Data collected only for the time necessary to achieve the purpose for which they were collected and received, or to comply with legal or regulatory requirements, as provided for by Article 5(1)(e) of the GDPR.
In particular:
Data collected to fulfill contractual obligations will be retained for the time necessary to carry out the above-mentioned purposes and in accordance with the provisions of the law;
Data collected for purposes attributable to the Data Controller’s legitimate interest will be retained until that interest has been satisfied; the User may obtain further information regarding the legitimate interest pursued by the Data Controller by contacting the Data Controller;
Data collected on the basis of the User’s Consent may be retained until the expiry of the applicable legal period or until such Consent is withdrawn;
The Data may be retained by the Data Controller for a longer period in compliance with legal obligations or by order of an authority.
At the end of the retention period, Personal Data will be deleted and, therefore, the related rights may no longer be exercised.
Exercise of the Data Subject’s Rights
The Data Subject has the right to exercise the rights provided for in Articles 15–22 of European Regulation 679/2016. In particular, the following rights are recognized:
Right to rectification. The Data Subject may obtain the rectification of Personal Data concerning them or communicated by them to the Company, which makes reasonable efforts to ensure that the Personal Data in its possession are accurate, complete, up to date and relevant, based on the most recent information available;
Right to restriction. The User may obtain a restriction of the processing of their Personal Data where:
they contest the accuracy of their Personal Data for the period during which the Data Controller must verify its accuracy;
the processing is unlawful and they request a restriction of processing or the deletion of their Personal Data;
the Company no longer needs to retain the Personal Data collected;
the User objects to the processing while the Data Controller verifies whether its legitimate grounds override those of the User.
Right of access. The Data Subject may request information from the Data Controller regarding their stored Personal Data, including information on the categories of Personal Data the Company possesses or controls, the purposes for which they are used, where they were collected (if not directly from the User), and to whom they may have been disclosed;
Right to data portability. The Data Subject may request that the Company transfer their Personal Data to another Data Controller, where technically feasible, provided that the processing is based on the User’s consent or is necessary for the performance of a contract.
Right to erasure. The Data Subject may obtain from the Data Controller the deletion of their Personal Data where:
the Personal Data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
the User has the right to object to further processing of their Personal Data;
the Personal Data have been processed unlawfully.
Unless processing is necessary to comply with legal obligations or for the establishment, exercise or defense of legal claims.
Right to object. The Data Subject may object at any time to the processing of their Personal Data, provided that the processing is not based on their consent but on the legitimate interests of the Data Controller or third parties. In such cases, the Company will no longer retain the User’s Personal Data unless it can demonstrate compelling legitimate grounds, an overriding interest in the processing, or the establishment, exercise or defense of legal claims. If the User objects to the processing, it is necessary to specify whether they intend to have their Personal Data deleted or the processing restricted.
Right to lodge a complaint. In the event of an alleged violation of the applicable privacy legislation, the User may lodge a complaint with the competent authorities in their country or in the place where the alleged violation occurred.
Changes to this Privacy Policy
Any future changes or additions to the processing of Personal Data as described in this Privacy Policy will be communicated through the usual communication channels used by the Data Controller (for example, through the website).
Please note that the Data Controller is not responsible for updating all links available in this Privacy Policy; therefore, whenever a link is not functioning and/or is not up to date, Users acknowledge and accept that they must always refer to the document and/or section of the websites referred to by that link.
Privacy Policy updated as of 07.2026