PRIVACY POLICY Website – BRD Innova
Pursuant to Article 13 of Regulation (EU) No. 679/2016 (“GDPR” or “Regulation”) and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, this Privacy Policy is intended to inform the user (“Data Subject”) about the protection of personal data, the type of data collected, and the processing methods adopted in relation to the services provided, in full compliance with applicable data protection laws, ensuring all necessary safeguards against any event that may result in a data breach.
Processing will be carried out in accordance with the principles of lawfulness, fairness, transparency, confidentiality, and protection of the Data Subject’s rights.
This Privacy Policy is provided to users who interact with the BRD Innova S.r.l. website, accessible online at https://www.brdinnova.it, corresponding to the home page of the website. It describes the practices of the company’s official site only, and does not apply to external websites that may be accessible through links.
- Data Controller
BRD Innova S.r.l. (VAT No.: 04531200246 | Tax Code: BRDSFN83H18A703V), with registered office at Via A. De Gasperi, 77C – Cassola (VI) – 36022 – Italy, acts as Data Controller and can be contacted at info@brdinnova.it.
- Categories of Data Processed
The Controller collects and/or receives the following information concerning the Data Subject:
- Personal identification data: first name, last name, company name, email address, message content entered in the contact forms on the website.
- Electronic traffic data: log files, originating IP address.
The BRD Innova website is accessible without requiring users to provide personal data. BRD Innova does not request special categories of personal data as defined by GDPR (Art. 9). If the requested service requires the processing of such data, the Data Subject will receive specific information in advance and explicit consent will be requested.
Legal Basis and Purposes of Processing:
- Compliance with legal obligations: general administrative and accounting activities, and fulfilment of legal, regulatory, national, and EU obligations applicable to the Controller.
- Execution of requests for registration, contact, and/or informational material by the Data Subject, or of pre‑contractual measures adopted at the Data Subject’s request, or performance of a contract to which the Data Subject is party, including all related obligations: handling contact requests and sending requested information, assistance, and provision of the selected Service and/or purchased Product.
- Legitimate interest: activities necessary to establish, exercise, or defend the Controller’s rights in legal proceedings.
The collected data allow the Controller to manage and execute contact requests, provide assistance, and comply with legal and regulatory obligations. Under no circumstances does BRD Innova sell personal data nor use them for undisclosed purposes.
Data Retention Period for the data mentioned above:
- For the duration of the contractual relationship and, after termination, for the standard statutory limitation period.
- For the time necessary to provide a response, until the Data Subject requests deletion.
- For the entire duration of potential legal proceedings, until all rights of appeal are exhausted.
Once these retention periods have expired, the data will be destroyed, deleted, or anonymized, in accordance with technical deletion and backup procedures.
After these periods, the rights of access, erasure, rectification, and data portability can no longer be exercised.
If a user submits personal data to Meccanica di Precisione Bordignon Stefano that are unnecessary for delivering the requested service, such data will not be considered as processed by the Controller and will be deleted as soon as possible.
Regardless of the Data Subject’s request for removal, personal data will still be retained according to legal and regulatory requirements when necessary for compliance with specific obligations.
For data provided for commercial promotion purposes concerning services other than those already acquired by the Data Subject (and only when explicit consent has been provided), the retention period is 24 months unless consent is withdrawn earlier.
For profiling purposes, data will be retained for 12 months unless consent is withdrawn earlier.
Type of Data Processed and Collection Methods
- Log files and IP addresses
The IT systems that operate this website automatically collect certain navigation data (whose transmission is implicit in Internet communication protocols) and which are not associated with directly identifiable users. Collected data include IP addresses, URI/URL addresses of requested resources, request timestamps, server response status codes (success, error, etc.), and other parameters related to the user’s device and operating environment.
This information does not include personal data but technical/IT data used in aggregate and anonymous form to verify proper website operation, monitor security, improve service quality, generate usage statistics, and determine responsibility in the event of cybercrimes against the site.
Where justified by legitimate interest or legal obligations, these data may be used to determine responsibility in cases of potential cyber offenses.
- Data voluntarily provided by the user
Sending voluntary, explicit, and optional messages to the Controller’s contact addresses, or completing and submitting forms on the site, results in the acquisition of the sender’s contact details and any personal data necessary to respond or provide the requested service. This processing is carried out in compliance with the principles of fairness, lawfulness, transparency, and confidentiality as established by GDPR (Art. 5).
Before activating certain services, specific information will be provided, and consent may be requested when required. Consent may be withdrawn at any time by contacting info@brdinnova.it, resulting in the loss of access to that service.
Failure to provide consent, or withdrawal thereof, does not entail any consequences except the inability to use the specific service or receive detailed information.
When justified by legitimate interest or by law, processing may occur without consent.
Data Processing Methods
Personal data are processed using automated tools for the time strictly necessary to achieve the purposes for which they were collected, in compliance with Art. 5 GDPR and the mandatory legal retention periods, by authorized personnel and in accordance with Art. 29 GDPR 2016/679.
Specific security measures are implemented to prevent data loss, unlawful or improper use, and unauthorized access, ensuring confidentiality, integrity, and availability of personal data.
The Controller requires third‑party providers and Processors to adopt similar security measures.
- Registration requests and contact/information requests
Data are processed to handle registration requests, information inquiries, contact requests, and the sending of informational material, as well as for all related obligations.
- IT Security
In accordance with Recital 49 GDPR, the Controller—also through third‑party providers—processes personal traffic data strictly necessary and proportionate to ensure network and information security, meaning the ability of a system to withstand unforeseen events or unlawful acts affecting data availability, authenticity, integrity, and confidentiality.
The Controller will promptly inform Data Subjects of any high‑risk data breach, without prejudice to obligations under Art. 33 GDPR concerning breach notifications.
- Profiling
The Data Subject’s personal data may be processed for profiling purposes (such as analyzing transmitted data and selected Services/Products, or delivering advertising or commercial proposals aligned with user preferences) exclusively when explicit and informed consent has been provided.
Consent may be withdrawn freely and at any time.
Data Communication and/or Disclosure
Personal data will not be publicly disclosed, but may be communicated to companies contractually linked to the Controller, within GDPR limits.
Personal data are stored on servers located within the European Union.
If necessary, the Controller may transfer servers outside the EU, ensuring full compliance with applicable law and the use of EU Standard Contractual Clauses. The Data Subject will be informed accordingly.
Data may be communicated to the following categories of third parties:
- providers of IT system and telecommunication network management services (including email);
- consulting or professional firms within the scope of assistance and advisory relationships;
- competent authorities for legal obligations or upon request;
- companies providing website and IT system maintenance services.
These entities act as Data Processors or, where applicable, independent Data Controllers.
Any further communication or disclosure will occur only with the explicit consent of the Data Subject.
Protection of Minors
This Website and the Controller’s Services are not intended for individuals under 16 years old, and the Controller does not knowingly collect personal data from minors. If such data are inadvertently collected, they will be deleted promptly upon request.
Data Subject Rights
The Data Subject may obtain information regarding personal data processing by contacting BRD Innova at: info@brdinnova.it
- Right of Access (Art. 15): request access to stored personal data at any time.
- Right to Rectification (Art. 16): correct inaccurate or incomplete information and request updates or modifications.
- Right to Erasure (Art. 17): request deletion of personal data by sending an email; the request will be processed within 30 days.
- Right to Restriction (Art. 18): request limitation of data processing.
- Right to Data Portability (Art. 20): request data export in a structured, commonly used, machine‑readable format for transfer to third parties.
- Right to Object (Art. 21): object at any time to specific uses of data by BRD Innova.
- Right to Lodge a Complaint (Art. 77): file a complaint with the competent authority via www.garanteprivacy.it or by emailing urp@gpdp.it.
Any update to this Privacy Policy will be communicated in a timely and appropriate manner. Should the Controller process data for additional purposes not outlined in this Policy, prior notice will be provided and consent requested when necessary.
View our Cookie Policy.