Data Controller and Data Processor

Bandusia S.r.l., with its registered office at Viale Monza, 259 – 20126 Milan, VAT No. 07453420965 (hereinafter referred to as “Bandusia” or the “Data Controller”), in its capacity as Data Controller, hereby informs you, pursuant to Article 13 of Legislative Decree 30.06.2003 no. 196 (“Privacy Code”) and Article 13 of EU Regulation 2016/679 (“GDPR”), that the personal data you provide will be processed in accordance with the applicable data protection regulations.

The Data Processor is also Bandusia Editrice.

Data Protection Officer (DPO)

The Data Controller has appointed a Data Protection Officer (DPO), an expert and qualified consultant who assists the Data Controller in managing data processing in compliance with the current legislation. The Data Protection Officer can be contacted at the following email address: rpd@bandusia.it

Types of Personal Data

Personal data, including names, phone numbers, addresses (including email addresses) – whether provided directly by you through the Enrollment Form or obtained from public sources – will be processed by the Data Controller in accordance with the GDPR and national regulations (Privacy Code), including the measures issued by the Supervisory Authority (Data Protection Authority).

Object and Methods of Processing

The term “processing” of personal data, as defined by Article 4 of the Privacy Code and Article 4 of the GDPR, includes any operation or set of operations carried out with or without the aid of automated processes, applied to personal data or sets of personal data, such as collection, recording, organization, structuring, storage, adaptation, alteration, extraction, consultation, use, transmission, dissemination, restriction, deletion, or destruction.

Personal data will be processed manually and/or by means of IT or telematic systems, in accordance with the principles of fairness, lawfulness, transparency, and data minimization as outlined in data protection regulations, ensuring data security and preventing unauthorized access (except where the disclosure of data is mandated by law).

The processing of personal data is necessary for participation in projects managed by Bandusia Editrice. Failure to provide data will render participation in the project impossible.

Purpose and Legal Basis of Processing

The Data Controller will process your personal data as part of its activity as a publishing company and for "marketing and communication" purposes, for the purpose of providing services such as information requests, assistance and support, and participation in initiatives managed by Bandusia Editrice. The legal basis for the above purposes is your freely expressed consent via the channels made available to the user.

Your personal browsing data on the website will be processed solely for the purpose of monitoring the proper functioning of the website and for aggregated traffic statistics analysis.

The data processed may include:

Automatically collected data: The IT systems and applications dedicated to the functioning of this website detect, during their normal operation, some data (the transmission of which is implicit in the use of Internet communication protocols) potentially associated with identifiable users. The collected data includes IP addresses and domain names of the computers used by users who connect to the site, URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response given by the server, and other parameters related to the user's operating system, browser, and IT environment. This data is processed, for the time strictly necessary, for the sole purpose of obtaining statistical information on the use of the site and to ensure its proper functioning. The provision of such data is mandatory as it is directly linked to the web browsing experience.

Cookies: The site uses technical cookies necessary for the correct functioning of the site. The site also uses third-party cookies, subject to the user's consent. The legal basis for processing is your explicit consent provided through consent to the use of third-party cookies. For more information, please refer to the cookie policy.

Recipients of Personal Data

Your personal data may be disclosed, for the aforementioned purposes, not only to the Data Processor and DPO but also to employees and collaborators of the Data Controller authorized to process data under direct authority and solely according to the Data Controller's instructions.

In cases where data disclosure is mandated by law or contractual obligation, data may be communicated to parties legally authorized to receive it.

Data is processed within the European Union and is not transferred abroad. However, if the transfer of data to countries outside the EU is necessary due to server locations or group coordination, the Data Controller ensures adequate protection measures in accordance with GDPR, including the use of standard contractual clauses.

Personal data will not be visible to other users but only to trained and authorized personnel.

Cookie Policy

This Website uses Cookies. For further information and to review the detailed policy, the User is advised to consult the Cookie Policy.

Data Retention Period

Personal data processed for the above purposes will be retained in accordance with the storage limitation principle (Art. 5, GDPR) and applicable regulations. Data retention will be periodically reviewed to assess its relevance to the purposes for which it was collected.

Personal data will be retained for the specified period to propose participation in new projects.

Rights of Data Subjects

Pursuant to Articles 15–21 of the GDPR, you have the right to:

* Access: Receive confirmation of the existence of personal data and access its content;
* Rectification: Request the updating, modification, and/or correction of personal data;
* Erasure: Request the deletion of personal data that is no longer necessary, processed unlawfully, or for which consent has been revoked;
* Restriction: Request the limitation of data processing in certain circumstances, such as inaccuracy, unlawful processing, or legal disputes;
* Objection: Object to the processing of personal data;
* Withdrawal of Consent: Revoke consent without affecting the lawfulness of processing based on consent prior to revocation;
* Complaint: Lodge a complaint with the Supervisory Authority in case of data protection violations;
* Data Portability: Receive a copy of your data in a structured, commonly used, and machine-readable format and request the transmission of such data to another Data Controller.

To exercise your rights and revoke consent, you may contact privacy@bandusia.it

For further information regarding personal data, you may contact the Data Protection Officer of Bandusia Editrice at rpd@bandusia.it

Modifications to the Policy

Bandusia Editrice reserves the right to modify this policy to reflect changes in national or EU regulations or to adapt to technological advancements. Any changes will be published on this webpage, accessible through the hyperlink located in the Site footer. Users are advised to periodically review the policy for updates by Bandusia Editrice.