Privacy Policy

.

PRIVACY NOTICE – CONTACT FORM

As required by current legislation (Article 13 of the General Data Protection Regulation, hereinafter also “GDPR”), Francesco Uliano (hereinafter referred to as the “Controller”) provides users who wish to contact the Controller through the specific form available on the website www.16design.it with information regarding the processing of their personal data.

WHO IS THE DATA CONTROLLER AND HOW TO CONTACT THEM

The data controllers are Francesco Uliano and Jenny Pistarà, with offices in Milan, Via Giacomo Venezian no. 8, VAT no. 14061300969.
The co-controllers can be contacted by email at info@16design.it or by phone at +39 3317436343.

WHAT DATA ARE PROCESSED?

The data processed are those provided by the user through the completion of the contact form.
Users should not include any special categories of data (such as data concerning health status) in the message field, as the form is not intended for special assistance requests but only for general information inquiries.
Should the user mistakenly provide special category data when submitting the request, such data will be deleted.

PURPOSES AND LEGAL BASES OF PROCESSING

The personal data provided by the user through the contact form are used solely to respond to the data subject’s request.
The legal basis for processing such data is the performance of pre-contractual measures taken at the request of the data subject.

If expressly consented to, identifying and contact data may also be processed for sending advertising material or direct sales communications or for carrying out market research or commercial communications regarding the Controller’s activities and services, through traditional means (such as operator-assisted phone calls) as well as automated means (such as email and SMS).
The legal basis for processing identifying data for marketing purposes is consent.

Please note that any consent given for the sending of commercial and promotional communications, pursuant to Article 130, paragraphs 1 and 2, of Legislative Decree 196/2003 (the “Privacy Code”), entails receiving such communications not only through automated means (SMS, email, and similar messages) but also through traditional means (such as postal mail or operator-assisted calls).
Consent may be withdrawn at any time.

With explicit consent, personal contact data (phone number) may also be processed for profiling purposes aimed at targeting the data subject for the sending of personalized promotional communications and displaying targeted ads on Meta (Facebook, Instagram, and related services) and LinkedIn platforms.
The legal basis for this processing is consent, which can be withdrawn at any time.

If necessary, data may also be processed based on the Controller’s legitimate interest, which consists of verifying the security and proper functioning of IT systems used and performing defensive activities.

HOW DATA ARE MANAGED

Data collected are processed using electronic tools. Appropriate security measures are implemented to prevent data loss, unlawful or improper use, and unauthorized access.

TRANSFER OF DATA ABROAD

Requests submitted through the form are managed via the servers used by the Controller for the website and through third-party service providers (used for receiving requests by email and for marketing management), which may involve a transfer of data abroad in compliance with the necessary safeguards provided by the EU-U.S. Data Privacy Framework.

DATA RETENTION PERIOD

Data provided directly by the data subject are stored only for the time strictly necessary to process the requests.
If consent is given, data processed for marketing and profiling purposes will be retained for 2 years, without prejudice to the right of the data subject to freely object at any time, without any charge, including separately for promotional communications sent through automated or traditional means, as well as for profiling purposes.
Data may be retained for longer periods if required for defensive purposes.

WHAT HAPPENS IF DATA ARE NOT PROVIDED?

Providing data is optional; however, if not provided, the Controller will not be able to respond to the user’s requests.

WHO CAN ACCESS THE DATA?

Data will be processed by the co-Controllers and authorized collaborators.
Data may be disclosed to competent Authorities in case of specific requests to which the Controller is legally obliged to respond, to companies providing IT supply and support services, to companies managing the social networks where the Controller is present, and to consultants for dispute management and legal assistance, if required.

Some of the mentioned entities act as data controllers, others as data processors. Communication to those acting as independent controllers is carried out either because it is required by law or necessary to fulfill obligations deriving from a pre-contractual relationship or the Controller’s legitimate interest in maintaining IT system security and conducting defensive activities.

A detailed list of entities to whom data may be communicated can be requested by contacting the co-Controllers.
Data disclosure is in any case limited to categories of data strictly necessary for carrying out the intended activities and purposes.

DATA SUBJECT RIGHTS

Under applicable law, the data subject has the right to request from the Controller:

  • access to their personal data,
  • rectification or erasure of such data,
  • restriction of processing,
  • objection to processing, and
  • data portability.

In particular, the data subject may object at any time to data processing for marketing and profiling purposes.

The data subject may exercise their rights at any time, without formalities, by contacting the Controller or the Data Protection Officer using the contact details provided in this notice. The Controller will respond within 30 days of receiving the request, as required by current law.

Below is a detailed list of rights recognized under data protection law:

  • Right of access: to obtain confirmation as to whether personal data concerning them are being processed and, if so, to access such data and related information (purposes, categories, recipients, retention period, existence of rights, origin, automated decision-making, etc.).
  • Right to rectification: to obtain, without undue delay, the correction of inaccurate personal data and completion of incomplete data.
  • Right to erasure (“right to be forgotten”): to have personal data deleted without undue delay when certain conditions apply (e.g., data no longer necessary, withdrawal of consent, unlawful processing, legal obligation, etc.), except where processing is necessary for freedom of expression, legal obligations, public interest, research, or legal defense.
  • Right to restriction of processing: to limit processing in certain cases (e.g., contesting accuracy, unlawful processing, need for legal defense, pending verification of objections).
  • Right to data portability: to receive personal data in a structured, commonly used, and machine-readable format and to transmit them to another controller where processing is based on consent or contract and carried out by automated means.
  • Right to object: to object at any time, for reasons related to their particular situation, to processing carried out for legitimate interests or public tasks, and, in any case, to object to processing for direct marketing, including profiling related to such marketing.

Finally, the data subject is informed that, if they believe the processing of their personal data violates the GDPR, they have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezion dei Dati Personali), as provided by Article 77 of the Regulation, or to seek judicial remedy pursuant to Article 79.