PRIVACY NOTICE
pursuant to Articles 13 and 14 of Regulation (EU) 2016/679
www.igeas.com
1. Introduction and scope of application
This privacy notice describes how IGEAS Engineering S.r.l. processes the personal data of users who visit the website www.igeas.com, pursuant to Regulation (EU) 2016/679 (the “GDPR”) and the applicable national legislation on personal data protection.
This privacy notice applies exclusively to the website of IGEAS Engineering S.r.l. and does not apply to other websites, pages or online services that may be accessed through hyperlinks on the website.
2. Data Controller
The Data Controller is IGEAS Engineering S.r.l., with registered office at Corso Traiano 64/12, 10135 Turin, tel. +39 011 31 81 661, certified email (PEC) igeas@legalmail.it, Turin Companies Register no. 07226150014, R.E.A. Turin no. 879927, share capital € 57.000,00 fully paid up.
For any request relating to the processing of personal data and for the exercise of the rights provided for by the legislation in force, the data subject may contact the Data Controller using the contact details indicated above.
3. Types of data processed
When browsing the website, technical and browsing data may be processed, automatically acquired by the IT systems and software procedures used to operate the website. This category includes, by way of example, the IP address, the type of browser used, the operating system, the date and time of access, the pages visited, the URI addresses of the requested resources and other parameters relating to the user’s device and IT environment.
These data are necessary to allow consultation of the pages, ensure the security of the website, verify its correct operation and obtain aggregate statistical information on its use.
If the user voluntarily sends communications by email, contact form or other tools that may be available on the website, the personal data communicated by the user may be processed, such as name, surname, email address, telephone number, company or organisation to which the user belongs, content of the request and any further information entered voluntarily in the message.
4. Purposes of processing
Personal data are processed for the following purposes:
-
to allow browsing and proper use of the website;
-
to ensure the IT security of the website and prevent improper use, unauthorised access, attempts to damage it or potentially unlawful activities;
-
to respond to requests for information, communications or contacts voluntarily sent by the user;
-
to manage any pre-contractual, contractual, professional or administrative relationships arising from requests submitted through the website;
-
to comply with any applicable legal, regulatory, tax or administrative obligations;
-
to establish, exercise or defend a right of the Data Controller in judicial or extrajudicial proceedings;
-
to manage cookies and tracking tools as indicated in the specific “Cookie” section of the website.
5. Legal basis for processing
The processing of browsing data necessary for the operation of the website is based on the legitimate interest of the Data Controller in ensuring the security, functionality and proper technical management of the website.
The processing of data voluntarily sent by the user through contact requests or email communications is based on the performance of pre-contractual or contractual measures taken at the request of the data subject, as well as on the legitimate interest of the Data Controller in replying to the communications received.
Any processing necessary to comply with legal obligations is based on compliance with legal obligations to which the Data Controller is subject.
Processing by means of non-technical cookies or tracking tools, where present, is based on the user’s consent, according to the methods indicated in the “Cookie” section of the website.
6. Methods of processing
Personal data are processed using IT, telematic and, where necessary, paper-based tools, in ways strictly related to the purposes indicated and in compliance with the principles of lawfulness, fairness, transparency, minimisation, accuracy, storage limitation, integrity and confidentiality.
The Data Controller adopts appropriate technical and organisational measures to protect personal data against unauthorised access, loss, disclosure, alteration or unauthorised destruction.
7. Provision of data
The provision of browsing data is necessary to enable the technical operation of the website.
The provision of personal data by email, contact form or other communication tools is free and voluntary. Failure to provide the necessary data may, however, prevent the Data Controller from replying to the user’s request or providing the requested service.
8. Communication of data
Personal data may be processed by internal staff authorised by the Data Controller and by external parties carrying out activities instrumental to the management of the website, IT systems, hosting services, technical maintenance, IT security, email, administrative, tax, legal or professional consultancy.
Such parties, where necessary, are appointed as Data Processors pursuant to Article 28 of the GDPR or act as independent data controllers, according to the applicable legislation.
Personal data are not subject to indiscriminate disclosure and are not transferred to third parties for commercial purposes.
This is without prejudice to the possibility of communicating data to public bodies, competent authorities or supervisory bodies where this is required by law or necessary to establish, exercise or defend a right of the Data Controller.
9. Transfer of data to non-EU countries
Personal data are generally processed within the European Economic Area.
If, for technical reasons related to the use of IT services, external platforms, website management tools or third-party services, it becomes necessary to transfer personal data to countries outside the European Economic Area, the transfer will take place in compliance with Articles 44 et seq. of the GDPR, on the basis of adequacy decisions of the European Commission, standard contractual clauses or other safeguards provided for by the applicable legislation.
10. Data retention
Browsing data are retained for the time strictly necessary to ensure the technical operation of the website, the security of the systems and any assessment of liability in the event of IT offences.
Data voluntarily provided by the user through contact requests are retained for the time necessary to respond to the request and, where this gives rise to a contractual or professional relationship, for the period provided for by the applicable civil, tax and accounting legislation.
Any data processed for the establishment, exercise or defence of a right may be retained for the time necessary to protect that right.
11. Cookies and tracking tools
The website uses technical cookies necessary for the correct operation of the pages and, where present, preference, analytical or third-party cookies, as indicated in the specific “Cookie” section of the website.
Cookies and other tracking tools are managed through a dedicated consent system, which allows the user to view the categories of cookies used, modify their preferences or withdraw consent at any time.
For detailed information on the cookies actually present on the website, their providers, purposes, retention periods and the methods for modifying or withdrawing consent, please refer to the “Cookie” section accessible from the footer of the website.
12. Processing relating to clients, suppliers and professional partners
For the processing of personal data relating to contractual, professional, administrative, commercial or supply relationships, please refer to the specific privacy notice for clients, suppliers and professional partners, which can be consulted through the dedicated link.
13. Third-party services
The website may integrate, directly or through links, third-party services such as maps, videos, links to social networks, security tools, consent management systems or other technical services necessary for the use of the pages.
The use of such services may involve the processing of personal data by the respective providers, according to the privacy notices prepared by them. The Data Controller therefore invites the user to consult the privacy notices of any third-party services present on or referred to by the website.
14. Automated decision-making and profiling
The Data Controller does not use personal data collected through the website for automated decision-making processes capable of producing legal effects concerning the data subject or similarly significantly affecting the data subject.
The website does not carry out commercial profiling of users, except as may be indicated in the “Cookie” section in relation to non-technical tracking tools that can be activated only with the user’s prior consent.
15. Rights of the data subject
The data subject may exercise, within the limits and under the conditions provided for by the legislation in force, the rights recognised by Articles 15 et seq. of the GDPR, including the right of access to personal data, the right to rectification or completion of inaccurate or incomplete data, the right to erasure in the cases provided for by law, the right to restriction of processing, the right to object, the right to data portability in the cases provided for by the legislation and the right to withdraw any consent given, without prejudice to the lawfulness of the processing carried out before withdrawal.
Requests may be sent to the Data Controller using the contact details indicated in this privacy notice.
The data subject also has the right to lodge a complaint with the Italian Data Protection Authority, according to the procedures provided for by the legislation in force.
16. Updates to this privacy notice
The Data Controller reserves the right to modify or update this privacy notice at any time, including as a result of regulatory, technical or organisational changes.
Users are invited to consult this page periodically to check for any updates.
Last updated: April 2026.
