Privacy Policy

This page describes how the website is managed with regard to the processing of personal data of users who consult it. This information is provided pursuant to Article 13 of EU Regulation 2016/679 (so-called GDPR) to those who interact with the web services of the Consorzio di Tutela Bresaola della Valtellina, accessible electronically at the following address:
http://www.bresaolavaltellina.it/

Please note that the information provided on this website may be subject to changes in order to remain up to date with current regulations. Users are therefore advised to periodically review this policy.


1. Types of Data Processed

The data processed include browsing data and data voluntarily provided by the user, as defined below.

Browsing Data

The IT systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.

This information is not collected to be associated with identified individuals, but by its nature could, through processing and association with data held by third parties, allow users to be identified.

This category includes:

  • IP addresses
  • Domain names of the computers used
  • URI addresses of requested resources
  • Time of the request
  • Method used
  • Size of the file obtained
  • Status code of the response
  • Other parameters relating to the operating system and IT environment

These data are used solely to obtain anonymous statistical information on website usage and to check its correct functioning, and are deleted immediately after processing.

Data Voluntarily Provided by the User

The optional entry of data in forms on the website, as well as the optional, explicit, and voluntary sending of data via web forms or email to the addresses indicated on the site, results in the subsequent acquisition of the sender’s address, necessary to respond to requests or provide the requested services, as well as any other personal data entered.

Specific summary information is provided on pages dedicated to on-demand services.


2. Purpose of Data Processing

The processing of data is carried out exclusively for the following purposes:

a) purposes related to the use of website services;

b) activities connected and instrumental to managing customer relationships (contact requests, sending offers, contracts, order management);

c) marketing and profiling activities, only with prior consent, for:

  • market research;
  • statistical analysis;
  • sending advertising and promotional material;
  • sending newsletters;
  • development and maintenance of commercial relationships;

d) processing of data relating to CVs for evaluating applications.

Providing data for purposes under points c) and d) is optional.

Marketing communications may be carried out through traditional means (postal mail, phone calls) and electronic means (email).

If the user is already a customer, communications relating to similar services may be sent, unless the user objects.


3. Processing Methods

Data processing may consist of operations such as:
collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, deletion, and destruction.

Processing may be carried out:

  • on paper;
  • through electronic and IT tools.

Appropriate measures are adopted to ensure data security and confidentiality.


4. Data Retention Period

Personal data are retained for the time strictly necessary to achieve the purposes for which they are collected, in compliance with applicable regulations.

In the event of a request for deletion, the data will be erased, unless legal obligations apply.

The Data Controller adopts a retention policy that limits the storage period to a maximum of two years.


5. Communication and Disclosure of Data

Data will not be disclosed and will be processed by authorized personnel.

They may be communicated to external parties appointed as Data Processors, including:

  • banks;
  • payment management companies;
  • law firms and consultants;
  • auditors;
  • public authorities;
  • Italian and foreign suppliers;
  • transport and financing companies.

Data may also be transferred abroad, in compliance with the guarantees provided by the GDPR.


6. Data Subject Rights and Withdrawal of Consent

The data subject may exercise the rights provided for in Articles 15–21 of the GDPR, including:

  • access to data;
  • rectification;
  • erasure;
  • restriction of processing;
  • objection;
  • data portability.

It is also possible to lodge a complaint with the Data Protection Authority.

Consent may be withdrawn at any time without affecting the lawfulness of processing based on consent before its withdrawal.

To exercise these rights:
info@bresaoladellavaltellina.it


7. Data Controller

Consorzio di Tutela Bresaola della Valtellina
Via Piazzi 23 – 23100 Sondrio
Tel. +39 0342 201984
Tax Code/VAT No. 00735490146
Email: info@bresaoladellavaltellina.it

The list of Data Processors is available at the Data Controller’s registered office.