Privacy policy

Ecco la traduzione in inglese, **mantenendo struttura, elenchi, grassetti e link** (ho corretto solo l’URL duplicato “https:// https://…” lasciandolo come singolo link):

—

BMA Group S.r.l., with registered office in Piazza della Vittoria 15/9 – 16121 Genoa (hereinafter “BMA”), pursuant to EU Regulation 2016/679 – the General Data Protection Regulation (“GDPR”), acknowledges the importance of protecting personal data and considers safeguarding it one of the main objectives of its activities.

Before providing any personal data, BMA invites you to carefully read this privacy policy (“Privacy Policy”), as it contains important information on the protection of personal data and on the security measures adopted to ensure confidentiality in full compliance with the GDPR. This Privacy Policy, furthermore:
applies only to the website [https://www.bmagroup.eu/](https://www.bmagroup.eu/) (“Site”) and does not apply to any other websites that may be consulted via external links;
is intended as the information notice pursuant to Article 13 of the GDPR for those who interact with the Site.

BMA informs you that the processing of your personal data will be based on the principles of lawfulness, fairness, transparency, purpose and storage limitation, data minimisation, accuracy, integrity, and confidentiality. Your personal data will therefore be processed in accordance with the provisions of the GDPR and the confidentiality obligations set out therein.

INDEX
Below is the index of this Privacy Policy so that you can easily find the information relating to the processing of your personal data.

  1. DATA CONTROLLER
    2. PERSONAL DATA PROCESSED
    a. Browsing data
    b. Data provided voluntarily
    c. Cookies and similar technologies
    3. PURPOSES, LEGAL BASIS, AND WHETHER PROVIDING DATA IS MANDATORY OR OPTIONAL
    4. RECIPIENTS
    5. TRANSFERS
    6. DATA RETENTION
    7. RIGHTS
    8. CHANGES
  2. DATA CONTROLLER

The Data Controller of the Site is BMA as defined above. For any information relating to the processing of personal data by BMA, including the list of data processors, you may contact the Data Controller at [info@bmagroup.it](mailto:info@bmagroup.it) or by phone at +39 0108984089.

  1. PERSONAL DATA PROCESSED

“Personal Data” means any information relating to an identified or identifiable natural person, with particular reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more elements characteristic of that person’s physical, physiological, psychological, economic, cultural, or social identity.

The Personal Data collected by the Site are as follows:

  1. Browsing data

The Site’s IT systems collect certain Personal Data whose transmission is implicit in the use of Internet communication protocols. This information is not collected in order to be associated with you, but by its very nature could, through processing and association with data held by third parties, allow you to be identified. These include IP addresses or domain names of the devices used to connect to the Site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (success, error, etc.), and other parameters relating to your operating system and IT environment.

These data are used in order to obtain anonymous statistical information on the use of the Site and to check its correct functioning; to enable—given the architecture of the systems used—the proper provision of the various features you request; for security reasons and to ascertain liability in the event of hypothetical cybercrimes against the Site or third parties, and are deleted after 7 days.

  1. Data provided voluntarily

Through the Site, you may voluntarily provide Personal Data such as your name and email address in order to contact BMA through the “Contacts” form or by sending an email to the addresses provided. BMA will process these data in compliance with the GDPR, assuming that they relate to you or to third parties who have expressly authorised you to provide them on the basis of an appropriate legal ground legitimising the processing of the data in question. In such cases, BMA acts as an independent data controller, assuming all legal obligations and responsibilities. In this regard, you grant the broadest indemnity in relation to any dispute, claim, request for damages arising from processing, etc. that may be brought against BMA by third parties whose Personal Data have been processed through your use of the Site in violation of the GDPR.

  1. Cookies and similar technologies

BMA collects Personal Data through cookies. More information on the use of cookies and similar technologies is available here.

  1. PURPOSES, LEGAL BASIS, AND WHETHER PROVIDING DATA IS MANDATORY OR OPTIONAL

The Personal Data you provide through the Site will be processed by BMA for the following purposes:

  1. a) purposes related to contact requests via the Contacts form or by email;
  2. b) purposes related to research/statistical analyses on aggregated or anonymous data, with no possibility of identifying the user, aimed at measuring the Site’s functioning, measuring traffic, and assessing usability and interest;
  3. c) purposes related to compliance with a legal obligation to which BMA is subject;
  4. d) purposes necessary to ascertain, exercise, or defend a right in court, or whenever judicial authorities exercise their judicial functions;

The legal basis for processing Personal Data for the purposes under point a) is the performance of a contract to which you are party or the implementation of pre-contractual measures taken at your request.
The purpose under point b) does not involve the processing of Personal Data; the purpose under point c) concerns compliance with a legal obligation; the purpose under point d) constitutes lawful processing of Personal Data under the GDPR since, once provided, the processing is necessary in order to comply with a legal obligation to which BMA is subject.

Providing your Personal Data for the purposes listed above is optional; however, failure to provide them may make it impossible to respond to your request or to comply with a legal obligation to which BMA is subject.

  1. RECIPIENTS
    Your Personal Data may be shared, for the purposes specified under point 3, with:
  2. a. parties necessary for the provision of the services offered by the Site, including by way of example email delivery and analysis of the Site’s functioning, who typically act as BMA’s data processors;
  3. b. persons authorised by BMA to process Personal Data who have undertaken confidentiality obligations or are subject to an adequate legal obligation of confidentiality (e.g., BMA employees and collaborators); (a. and b. are collectively the “Recipients”);
  4. c. judicial authorities in the exercise of their functions when required by the GDPR.

5. TRANSFERS
Your Personal Data are stored on servers located within the European Union. It is understood, however, that the Data Controller, where necessary, may move the servers also outside the EU. In such case, the Data Controller hereby assures that any transfer of data outside the EU will take place in compliance with applicable legal provisions, either on the basis of an adequacy decision or following the execution of the standard contractual clauses adopted by the European Commission.

  1. DATA RETENTION

BMA will process your Personal Data for the time strictly necessary to achieve the purposes indicated under point 3 (e.g., request for information). Without prejudice to the above, BMA will process your Personal Data for the period allowed by Italian law to protect its interests (Art. 2947(1)(3) of the Italian Civil Code). More information regarding the retention period of Personal Data and the criteria used to determine that period may be requested by writing to BMA.

  1. RIGHTS

As a data subject, you have the right to request from the Data Controller access to your personal data, rectification or erasure of such data, restriction of processing concerning you, or to object to processing (Articles 15 et seq. of the GDPR).

Requests should be addressed to the Data Controller, BMA Group S.r.l., with registered office in Piazza della Vittoria 15/9 – 16121 Genoa, email: [info@bmagroup.it](mailto:info@bmagroup.it) and phone: +39 0108984089.

You also have the right to lodge a complaint with the competent supervisory authority (Italian Data Protection Authority – Garante per la Protezione dei Dati Personali) as provided by Article 77 of the Regulation, or to bring proceedings before the competent courts (Article 79 of the Regulation).

  1. CHANGES

This Privacy Policy is effective as of March 2023. BMA reserves the right to amend or simply update its contents, in part or in full, also as a result of changes to the GDPR. BMA therefore invites you to regularly visit this section to review the most recent and updated version of the Privacy Policy, so that you are always informed about the data collected and how BMA uses them.