PRIVACY AND COOKIE POLICY

Notice regarding the processing of personal data of users visiting the Aquanexa S.r.l. website pursuant to Article 13 of Regulation (EU) 2016/679

Pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter “Regulation”), this page describes the methods for processing personal data of users who visit the website of Aquanexa S.r.l., whose homepage is available at www.aquanexa.it

This policy applies exclusively to the Aquanexa S.r.l. website and not to other websites, pages, or online services that may be reached via hyperlinks published on this site.

 

Data Controller

The Data Controller is Aquanexa S.r.l. (hereinafter the “Controller”), headquartered at Via Montefeltro 4, 20135 Milan. Email: a.lanuzza@aquanexa.it
Certified email (PEC)[*]: aquanexa.srl@legalmail.it
Phone:

 

Data Protection Officer (DPO)

The Data Protection Officer is Trust Data Solutions S.r.l., headquartered at Viale Cesare Cattaneo 10B, 22063 Cantù (CO).

DPO Team – Trust Data Solutions
Phone: 031707879
Email: dpo@trustds.it
PEC: dpotrustds@legalmail.it

 

Legal basis for processing

Legitimate interest pursuant to Article 6(f) and Recital 47: processing is necessary for the purposes of the legitimate interests pursued by the data controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject, taking into account the data subject’s reasonable expectations based on their relationship with the controller. Activities strictly necessary for the functioning of the website and for the provision of the navigation service on the platform.

 

Purpose of processing, categories of personal data processed, and data retention period

The processing of personal data of users visiting the Controller’s website is solely intended to ensure the technical functioning of the website.

“Personal data” as defined by Article 4(1) of the Regulation refers to “any information relating to an identified or identifiable natural person (data subject).” Visiting the Controller’s site involves processing of personal data falling into one or more of the following categories:

 

Browsing data
The IT systems and software procedures used to operate this website collect, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes IP addresses or domain names of the users’ computers and terminals, URI/URL (Uniform Resource Identifier/Locator) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file returned, the numerical code indicating the response status from the server (success, error, etc.), and other parameters related to the user’s operating system and IT environment. For maintenance and operational needs, system logs may be collected—i.e., files (electronic documents) that record interactions and may also contain personal data such as the user’s IP address.

 

Cookies and other tracking tools
Cookies are strings of text that websites visited by users send to their terminals, where they are stored and later transmitted back to the same sites upon subsequent visits. Cookies may contain various types of information about the user’s online activity. Cookies are categorized into two main types: “technical cookies” and “profiling cookies.” Both can be “first-party” or “third-party” cookies. Profiling cookies are used to create user profiles in order to deliver advertising aligned with the user’s web browsing preferences. User consent is required for installing such cookies. This site uses Google Analytics profiling cookies.

Technical cookies allow users to navigate websites efficiently and use their features. These do not require user consent. This site uses session technical cookies for transmitting session identifiers (random numbers generated by the server), which are essential for effective navigation. Session cookies are not stored persistently and are deleted when the browser is closed.

 

Information on data processing via social media platforms used by the Controller

For the processing of personal data carried out by the administrators of social media platforms used by the Controller, please refer to their respective privacy policies. The Controller processes personal data shared by users through social media pages dedicated to Aquanexa, strictly for institutional purposes, to manage user interactions (e.g., comments, public posts), and in compliance with applicable laws.

 

Processing methods

Processing is performed by individuals authorized by the Controller, for the purposes indicated. Authorized individuals are bound by confidentiality. Processing may also involve external entities designated as Data Processors under Article 28 of the Regulation. A list of processors is available upon request. Processing is carried out in compliance with fundamental rights and freedoms and the principles set out in Article 5 of the Regulation, particularly those of lawfulness, fairness, and transparency. The Controller ensures the relevance and proportionality of processed data to the stated purposes.

 

Categories of data recipients

Processing is carried out by individuals authorized and bound to confidentiality. In performing its services, the Controller may disclose data to the following categories of recipients:

  • Public administrations;
  • Technical service providers (e.g., hosting providers);
  • Public entities, where required by law.

Recipients who are not independent data controllers are appointed as Data Processors under Article 28 of the Regulation. A complete and updated list of processors is available upon request.

Service providers, acting as Data Processors under service agreements, are required to process personal data only for purposes defined by the Controller, not to retain it beyond specified terms, and not to disclose it to third parties without express authorization from the Controller, in accordance with Article 28 of the Regulation.

 

Data transfer abroad

Personal data processed for the above purposes is not transferred to countries outside the European Union or the European Economic Area (EEA), nor to international organizations. The Controller commits to transferring data outside the EEA only in accordance with Chapter V of the Regulation.

 

Data subject rights

Data subjects (i.e., natural persons whose data is processed) have the rights established under Articles 15 et seq. of the Regulation, including the right to access, rectify, restrict, update, or erase their personal data where appropriate; the right to data portability; and the right to object to processing. To exercise their rights, data subjects may contact the Controller or the DPO using the contact details provided in this notice.

If data subjects believe that their data has been processed in violation of the Regulation or applicable law, they have the right to lodge a complaint with the Data Protection Authority (Garante), pursuant to Article 77 of the Regulation, or to seek judicial remedy under Article 79.

The contact details of the Italian Data Protection Authority are available at www.garanteprivacy.it.

 

Amendments to this Privacy Notice

The Controller reserves the right to make changes to this Privacy Notice at any time by notifying users on this page. Please check this page frequently, referring to the last updated date indicated below.

Unless otherwise stated, the previous version of this Privacy Notice will continue to apply to personal data collected up to that point.

 

Last updated: 22/05/2025

[*] Please note: certified email (PEC) addresses can receive messages only from other certified email accounts.