Information on the processing of personal data and cookies of the website
1. Introduction
In compliance with the obligations arising from Regulation (EU) No. 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter, the “Regulation” or “GDPR”) and current national legislation, including Legislative Decree 196/2003 (Privacy Code, as amended by Legislative Decree 101/2018), Drafinsub S.r.l. respects and protects the personal data of visitors and users (hereinafter, the “Data Subjects”) of the website www.drafinsub.com/ (hereinafter, the “Website”). This document provides information on the processing of personal data collected by Drafinsub S.r.l. through the Website and therefore constitutes a notice to the Data Subjects pursuant to the above legislation. It does not apply to personal data collected by Drafinsub S.r.l. through other channels. In accordance with the Regulation, the processing of personal data is carried out lawfully, fairly and transparently, and with due regard to confidentiality. The Website contains links to other websites: this notice does not apply to those websites, which may have privacy policies that differ, in whole or in part, from this one. Drafinsub S.r.l. therefore invites Data Subjects to carefully read the privacy policies of any third-party websites they may visit, especially before entering any personal information.
2. Identity and contact details of the Data Controller
The Data Controller is Drafinsub S.r.l. (hereinafter, “Drafinsub S.r.l.” or the “Data Controller“), VAT No. 02627860105, with registered office at Corso Concordia 11, 20129 – Milan (MI), Italy (tel: +39 3393299740; email: [email protected]).
3. Types of data processed through the Website
The Data Controller may process the following data through the Website:
Automatically collected data – traffic and navigation data
The IT systems and software procedures used to operate the Website acquire, during normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.
This category includes IP addresses or domain names of the computers and terminals used by users, the type of browser, the name of the Internet Service Provider, URI/URL (Uniform Resource Identifier/Locator) addresses of the requested resources, the date and time of access, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the response status (success, error, etc.), the referring web page, the exit page, and other parameters relating to the user’s operating system and IT environment.
The Website does not intentionally collect special categories of personal data (e.g., health data, religious, political, or union beliefs) unless with specific informed consent.
4. Data provided by Data Subjects
The voluntary, explicit and optional sending of messages to the contact addresses of the Data Controller, as well as filling out and submitting forms on the Website, involves the acquisition of the sender’s contact details necessary to respond, as well as any personal data included in the communications (such as, by way of example, name, surname, email address). In any case, Data Subjects are required to provide accurate and truthful data and to promptly inform the Data Controller of any subsequent changes.
5. Cookies and other tracking technologies
The Website uses cookies and similar technologies. For details on the use of cookies, please refer to our Cookie Policy.
6. Purpose and legal basis of data processing
The Data Controller processes traffic and navigation data for the following purposes: (a) to manage, administer, and improve the Website; verify proper functioning of the services provided; (b) to comply with legal obligations and/or regulations and/or orders from judicial authorities; (c) to prevent and/or detect fraudulent and/or harmful activities on the Website; (d) to perform technical and/or commercial analysis; obtain statistical information on the use of services (most visited pages, number of visitors by time or day, geographical origin, etc.). Processing this data is necessary for browsing the Website. The Data Controller processes data voluntarily provided by Data Subjects for the following purposes: (e) to respond to requests for assistance and, in general, to any inquiries and/or requests submitted by users; (f) to send users administrative and/or technical support emails (e.g., technical notes, reminders, updates, etc.); (g) to send newsletters, promotional communications, and/or advertising material about the Data Controller’s products and/or services by post and/or email. Processing of such data for the purposes mentioned above requires the consent of the Data Subjects. Such consent is always optional; however, without it, Drafinsub S.r.l. will not be able to process the data for the specified purposes.
7. Data disclosure
Personal data collected may be disclosed to supervisory bodies, judicial authorities, and any parties to whom disclosure is mandatory by law and/or necessary for fulfilling the purposes described above.
8. Data processing methods and retention period
Data may be processed using both paper-based and electronic and/or automated means. In any case, the Data Controller will process the collected data for as long as necessary to fulfill the purposes of this notice, and in accordance with applicable legislation (including tax regulations). Data will be retained for the following periods:
- Navigation data: maximum of 12 months;
- Voluntarily provided data: up to 10 years for legal or administrative obligations;
- Marketing data: until consent is withdrawn, and in any case not beyond 24 months.
9. Possible transfer of personal data
The data will be managed and stored on servers located within the European Union, either by the Data Controller or third-party companies duly appointed as Data Processors. Currently, servers are located in Italy. Should the Data Controller need to relocate the servers to other countries within the EU and/or outside the EU, such transfer will comply with applicable legal provisions by entering into appropriate agreements and/or adopting the standard contractual clauses established by the European Commission.
10. Security measures
The Data Controller processes personal data lawfully and correctly, adopting appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction, as well as unlawful use. Processing is carried out using IT and/or telematic tools with organizational methods and logic strictly related to the purposes indicated, and data is stored in secure facilities with restricted access and personnel verification. Access to the data is strictly limited to authorized personnel. The Website is continuously monitored for possible security breaches. In addition to the Data Controller, other individuals may access the data as part of Website operations (administrative, commercial, marketing, legal staff, system administrators), or external parties (third-party technical service providers, hosting providers, IT companies, communication agencies), all of whom act on the basis of specific instructions from the Data Controller. In any case, the Data Controller encourages users to take appropriate precautions to prevent unauthorized access to their private area and/or computer.
11. Data Subjects’ rights
In accordance with Chapter III of the GDPR, Data Subjects may exercise the following rights at any time: – **Right of access** (Art. 15): confirmation whether their data is being processed and, if so, access relevant details; – **Right to rectification** (Art. 16): request correction of inaccurate or incomplete data; – **Right to erasure** (Art. 17): request deletion of personal data (“right to be forgotten”), when applicable; – **Right to restriction** (Art. 18): request processing be restricted in certain cases; – **Right to data portability** (Art. 20): receive data in a structured, commonly used format and transmit it to another controller; – **Right to object** (Art. 21): object to data processing under specific circumstances, including direct marketing; – **Right not to be subject to automated decision-making** (Art. 22).
Requests can be submitted at any time to Drafinsub S.r.l. by post (Corso Concordia 11, 20129 – Milan (MI), Italy) or via email at [email protected].
Consents provided can also be revoked at any time without affecting the lawfulness of processing based on previously given consent.
Requests and responses are provided free of charge unless otherwise provided by Art. 12, paragraph 5 of the GDPR.
For further information regarding data processing through the Website, Data Subjects can also contact Drafinsub S.r.l. at +39 3393299740.
12. Right to lodge a complaint
If Data Subjects believe that the processing of their personal data via the Website violates the Regulation, they have the right to lodge a complaint with the Data Protection Authority (Art. 77 of the Regulation) or seek judicial remedy (Art. 79 of the Regulation).
13. Protection of minors
The Data Controller does not allow individuals under the age of 16 to use its services and does not knowingly collect information relating to them. If it becomes aware that it has collected data about individuals under 16 without verifiable parental consent, it will delete such data as quickly as possible.
14. Periodic updates to this privacy policy
This privacy policy has been valid and effective since 25 May 2018 and may be subject to future amendments, including as a result of changes in applicable legislation. In the event of significant changes, the Data Controller will inform Data Subjects through appropriate means (e.g., publication on the homepage of the Website and/or via newsletter to the email address provided). This privacy policy was last updated on 25 May 2018.
15. AI-generated content
Some content on the Website (including text, images, graphics, or multimedia elements) may be created, in part, using generative artificial intelligence tools. The use of such technologies is guided by principles of fairness, transparency, and reliability, aimed at offering users consistent, up-to-date, and engaging content. AI-generated content does not use personal information (such as name, email, preferences, or browsing behavior) of visitors. AI is not used to analyze or study user behavior for profiling, personalized advertising, or targeted content purposes.
This policy was last updated on 6 May 2025.