Privacy Policy

WEBSITE PRIVACY POLICY –www.adaptronics.it

Pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”)

This Privacy Policy describes how the personal data of users interacting with this Website are processed, with reference both to data collected during browsing and to data voluntarily provided through the contact channels and services available on the Website.

1. Data Controller

The Data Controller is Adaptronics S.r.l., with its registered office at Largo Guido Donegani 2, 20121 Milan, Italy, VAT No. 12394070960, e-mail: info@adaptronics.it.

2. Types of Personal Data processed

While browsing the Website, the Data Controller may collect the following categories of Personal Data:

  • Browsing Data: these data are collected automatically through the use of Internet communication protocols and include, for example, the IP address of the device connected to the Website, the type of browser used, the name of the Internet Service Provider (ISP), the date and time of the visit, and other parameters relating to the user’s operating system and IT environment.
  • Data Provided Voluntarily by the User: these include identification data, contact details, Curriculum Vitae – including all the information included therein – and any additional information voluntarily provided through the “Contacts” or “Careers” sections, or through the e-mail addresses published on the Website.

3. Purposes of processing, legal bases and retention periods

In accordance with the lawfulness requirements set out in Article 6 GDPR, the Personal Data will be processed for the following purposes, on the corresponding legal bases, and retained for the periods indicated below.

a) Website operation and security
Purpose:to ensure the proper functioning of the Website and the security of information and systems, including the prevention of unlawful or fraudulent use.
Legal Basis:Legitimate interest (Article 6(1)(f) GDPR).
Retention Period:Browsing data (e.g., system logs, IP addresses) are retained for no longer than 7 days, unless further retention is necessary for the investigation of cybercrimes or upon request by judicial authorities, in which case they may be retained for the period strictly necessary to protect the Data Controller’s rights.

b) Responding to contact requests
Purpose:to respond to requests submitted through the “Contact Us”, “Careers” sections or through the contact details available on the Website.
Legal Basis:Performance of pre-contractual and/or contractual measures (Article 6(1)(b) GDPR).
Retention Period:Personal Data will be retained for the time necessary to respond to the request and, in any event, for no longer than 12 months from the last contact, unless a contractual relationship is established, in which case the data will be processed in accordance with the retention periods applicable to that relationship.

c) Soft spam communications
Purpose:to send, via e-mail, information about products, services and offerings similar to those already purchased by the User (“soft spam”).
Legal Basis:Legitimate interest (Article 6(1)(f) GDPR).
Retention Period:Personal Data will be processed for this purpose until the User exercises the right to object and, in any event, for no longer than 24 months from the last purchase or commercial interaction.

d) Compliance with legal obligations
Purpose:to comply with legal obligations and requests issued by public authorities.
Legal Basis:Compliance with a legal obligation (Article 6(1)(c) GDPR).
Retention Period:Personal Data will be retained for the period required by applicable law and, in particular, for administrative and tax purposes, for no longer than 10 years, unless longer retention periods are required by law.

e) Establishment, exercise or defence of legal claims
Purpose:to establish liability in the event of alleged cybercrimes affecting the Website or its users.
Legal Basis:Legitimate interest of the Data Controller (Article 6(1)(f) GDPR).
Retention Period:Personal Data will be retained for the period strictly necessary to establish, exercise or defend the Data Controller’s rights and, in any event, no longer than the applicable statutory limitation period (generally 10 years), unless legal proceedings are initiated.

4. Methods of processing

Personal Data are processed by duly authorised and instructed personnel acting under the authority of the Data Controller through electronic, digital and, where necessary, paper-based means, in accordance with the principles of lawfulness, fairness and transparency.

Pursuant to Article 32 GDPR, appropriate technical and organisational measures are implemented to ensure a level of security appropriate to the risks involved, in order to safeguard confidentiality, integrity, availability and resilience of processing systems and services.

5. Personal Data Transfer to Third Countries

Where it is necessary to transfer Personal Data to third parties located outside the European Union for the provision of the Data Controller’s services, such transfers shall take place in accordance with Articles 44 et seq. GDPR on the basis of one of the following safeguards:

  • an adequacy decision adopted by the European Commission;
  • appropriate safeguards provided by the recipient;
  • Binding Corporate Rules (BCRs), where applicable.

6. Categories of Data Recipients

Personal Data will not be disclosed to the public. However, they may be communicated, within the limits of the purposes described above, to:

  • third-party service providers performing technical and/or organisational activities on behalf of the Data Controller, including IT, telecommunications, communication, e-mail marketing, support and consultancy services. Such entities act as Data Processors duly appointed pursuant to Article 28 GDPR;
  • companies belonging to the same corporate group as the Data Controller or parent, subsidiary or affiliated companies pursuant to Article 2359 of the Italian Civil Code, which process Personal Data for administrative/accounting purposes and/or to pursue the purposes described above, acting as independent Data Controllers or, where applicable, Data Processors.

An updated list of Data Processors and other entities involved in the processing activities is available upon request.

7. Data Subject’s Rights

At any time, pursuant to Articles 15 et seq. GDPR, Users, as Data Subjects, may exercise the following rights, where the relevant legal conditions are met:

  • to obtain confirmation as to whether or not Personal Data concerning them are being processed, access such data and receive a copy thereof (Article 15 GDPR – Right of Access);
  • to request the rectification or updating of inaccurate or incomplete Personal Data (Article 16 GDPR – Right to Rectification);
  • to obtain the erasure of Personal Data where the conditions set out in Article 17 GDPR apply (Article 17 GDPR – Right to Erasure);
  • to obtain restriction of processing where the conditions set out in Article 18 GDPR apply (Article 18 GDPR – Right to Restriction of Processing);
  • to withdraw consent at any time, without affecting the lawfulness of processing carried out prior to such withdrawal;
  • to object to the processing of Personal Data where processing is based on a legal basis other than consent (Article 21 GDPR – Right to Object).

These rights may be exercised by sending a request via e-mail to info@adaptronics.it.
Users also have the right to lodge a complaint with the competent supervisory authority, namely the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali), or to seek a judicial remedy.

8. Updates and amendments

This Privacy Policy may be updated from time to time. Any amendments shall become effective upon publication on the Website. Users are therefore encouraged to review this section regularly in order to remain informed of the latest version of this Privacy Policy.

Last updated: July 2026