PRIVACY POLICY

Data Controller

Esapro S.r.l. – Via Gustavo Fara 35 – 20124 Milano – Italy – Tax/VAT number 03836010409

Data controller email address: it_support@esapro.it

Types of data collected

Among the personal data collected by this website, either independently or through third parties: post code, name, surname, email address, cookies, usage data, additional information.

Full details on each type of data collected are provided in the various sections of this privacy policy or through texts displayed before data is collected.
Personal data can be freely provided by the user or, in the case of usage data, collected automatically when using this website.
Unless otherwise specified, all data required by this website is mandatory. If the user refuses to provide the requested data, it may be impossible for this website to provide the service. Data indicated as optional is not mandatory and users are free to refrain from communicating such data without any consequence to the service or operation.
Users who have doubts about what data is required are encouraged to contact the data controller.
Any use of cookies – or other tracking tools – by this website or by the owners of third-party services used by this website, unless otherwise specified, is intended to provide the service requested by the user, in addition to purposes described in this document and in the cookie policy, if available.

The user assumes responsibility of third-party personal data that is obtained, published or shared through this website and guarantees the right to communicate or disseminate it, freeing the data controller from any liability to third parties.

Methods and place of processing the collected data

Processing Method

The data controller takes the appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of personal data.
Processing is carried out by using IT and/or telematic tools, with organisational methods and logic strictly related to the indicated purposes. In addition to the data controller, in some cases, other parties involved in the organisation of this website could have access to the data (administrative, commercial, marketing, legal staff, system administrators) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communication agencies) and, if necessary, data processors appointed by the data controller. An up-to-date list of data processors can always be requested from the data controller.

Legal basis of the processing

The data controller processes personal data related to the user if one of the following conditions exists:

  • the user has given consent for one or more specific purposes. Note: in some jurisdictions, the data controller may be authorised to process personal data without the consent of the user or another of the legal bases specified, until the user opts out of such processing. However, this is not applicable if the processing of personal data is regulated by European legislation on the protection of personal data
  • processing is necessary for the execution of a contract with the user and/or the execution of pre-contractual measures
  • processing is necessary to fulfill a legal obligation to which the data controller is subject
  • processing is necessary for the execution of a task of public interest or for the exercise of public powers vested in the data controller
  • processing is necessary to pursue the legitimate interest of the data controller or third parties

It is, however, always possible to request that the data controller clarify the concrete legal basis of each processing and, in particular, to specify whether the processing is based on the law, provided for by a contract, or required to conclude a contract.

Location

Data is processed at the data controller’s operating offices and in any other place where the parties involved in the processing are located. For more information, contact the data controller.  A user’s personal data may be transferred to a country other than the one in which the user is located. To obtain further information on where data is processed, users can refer to the section on personal data processing.

Users are entitled to obtain information regarding the legal basis of the transfer of data outside the European Union or to an international organisation of public international law or an organisation constituted by two or more countries, such as the UN, as well as regarding security measures taken by the data controller to protect the data.

Users can verify if one of the transfers described above takes place by reading the section of this page on personal data processing or by requesting information from the Data Controller through the contact details listed here above.

Retention period

Data is processed and retained for the time required for the purposes for which they were collected.

Therefore:

  • Personal data collected for purposes related to the execution of a contract between the data controller and the user will be retained as long as the contract is in effect.
  • Personal data collected for purposes related to the legitimate interest of the data controller will be retained until such interest is satisfied. The user can obtain further information on the legitimate interest pursued by the data controller in the relevant sections of this site or by contacting the data controller.

When consent is required to process the user’s data, the data controller may retain personal data for longer, until such consent is revoked. Furthermore, the data controller could be obliged to retain personal data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period, the personal data will be deleted. Therefore, upon expiration of this term, the right to access, delete, rectify and the right to transfer the data can no longer be exercised.

Purposes of processing the collected data

Users’ data is collected to allow the data controller to provide their services, as well as for the following purposes: contacting the user, remarketing and behavioural targeting, interaction with external social networks and platforms, user database management, statistics and displaying content from external platforms.

To obtain detailed information on the processing purposes and on the personal data that is relevant for each specific purpose, the user can refer to the relevant sections of this section.

This type of service allows the data controller to create user profiles starting from an email address, a name or any other information that the user provides to this website, as well as to track the activities of the user through statistical functions. This personal data could also be cross-referenced with publicly available information about the user (such as profiles on social networks) and used to build private profiles that the data controller can view and use to improve this website.
Some of these services could also allow the scheduled sending of messages to the user, such as emails based on specific actions performed on this website.

ActiveCampaign (ActiveCampaign, Inc.)

ActiveCampaign is a user database management service provided by ActiveCampaign, Inc.

Personal data collected: cookies, email addresses, various types of data according to what is specified by the service’s privacy policy.

Place of processing: United States– Privacy Policy. Subject adherent to the Privacy Shield.

This type of service allows interaction with social networks or other external platforms directly from the pages of this website.
The interactions and information acquired from this website are subject to the privacy settings of the user on each social network.
This type of service may, however, collect data on traffic for the pages where the service is installed, even when users do not use it.
It is recommended to disconnect from the respective services to ensure that the data processed on this website is not linked to the user’s profile.

Like button and Facebook social widgets (Facebook, Inc.)

The “Like” button and Facebook social widgets are interaction services with the Facebook social network, provided by Facebook, Inc.

Personal data collected: cookies, usage data.

Place of processing: United States – Privacy Policy. Subject adherent to the Privacy Shield.

LinkedIn button and social widgets (LinkedIn Corporation)

The LinkedIn button and social widgets are interaction services with the LinkedIn social network, provided by LinkedIn Corporation.

Personal data collected: cookies, usage data.

Place of processing: United States – Privacy Policy. Subject adherent to the Privacy Shield.

This type of service allows this website and its partners to communicate, optimise and display advertisements based on the user’s past use of this website.
This activity is carried out by tracking usage data and the use of cookies, information that is transferred to the partners to whom the remarketing and behavioural targeting activity is linked.
Some services offer a remarketing option based on email address lists.
In addition to the possibility to opt-out offered by the following services, the user can opt to not receive cookies relating to a third service by visiting the Network Advertising Initiative opt-out page.

Remarketing Google Ads (Google LLC)

Remarketing Google Ads is a remarketing and behavioural targeting service provided by Google LLC that links the activity of this website with the Google Ads advertising network and DoubleClick cookies.

Users may choose not to use Google cookies to personalise ads by visiting Ad Settings of Google.

Personal data collected: cookies, usage data.

Place of processing: United States – Privacy Policy. Subject adherent to the Privacy Shield.

Facebook Remarketing (Facebook, Inc.)

Facebook Remarketing is a remarketing and behavioural targeting service provided by Facebook, Inc. that links the activity of this website with the Facebook advertising network.

Personal data collected: cookies, usage data.

Place of processing: United States – Privacy Policy. Subject adherent to the Privacy Shield.

LinkedIn Website Retargeting (LinkedIn Corporation)

LinkedIn Website Retargeting is a remarketing and behavioural targeting service provided by LinkedIn Corporation that links the activity of this website with the LinkedIn advertising network.

Personal data collected: cookies, usage data.

Place of processing: United States – Privacy Policy. Subject adherent to the Privacy Shield.

Remarketing with Google Analytics (Google LLC)

Remarketing with Google Analytics is a remarketing and behavioural targeting service provided by Google LLC that links the activity of tracking performed by Google Analytics and by its cookies with the Google Ads advertising network and Double-click cookies.

Personal data collected: Cookies; Usage Data.

Place of processing: United States – Privacy Policy. Subject adherent to the Privacy Shield.

The services contained in this section allow the data controller to monitor and analyse traffic data that are used to keep track of users’ behaviour.

Google Analytics (Google Inc.)

Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google uses personal data to track and examine the use of this website, compile reports and share them with other Google services.
Google may use personal data to contextualist and personalise the ads of its own advertising network. 

Personal data collected: Cookies, usage data.

Place of processing: United States – Privacy Policy. Subject adherent to the Privacy Shield.

LinkedIn Conversion Tracking (LinkedIn Corporation)

LinkedIn Conversion Tracking is a statistics service provided by LinkedIn Corporation that links data from the LinkedIn ad network with actions performed within this website. Personal data collected: cookies, usage data.

Place of processing: United States – Privacy Policy. Subject adherent to the Privacy Shield.

This type of service allows you to view content hosted on external platforms directly from the pages of this website as well as interact with them.
In the event that a service of this type is installed, it is possible that the service will collect traffic data relating to the pages on which it is installed, even if users do not use the service.

Widget Google Maps (Google Inc.)

Google Maps is a map visualisation service managed by Google Inc. that allows this website to integrate content within its pages.

Personal data collected: cookies, usage data.

Place of processing: United States – Privacy Policy. Subject adherent to the Privacy Shield.

Users can exercise certain rights in regard to data processed by the data controller.  

In particular, the user has the right to:

  • revoke consent at any time. Users may revoke previously granted consent to the processing of their personal data.
  • oppose to the processing of their data. Users can refuse the processing of their data when it occurs on a legal basis other than consent. Further details on refusal rights may be found below.
  • access their data. Users have the right to obtain information on data processed by the data controller, on certain aspects of processing and to receive a copy of the processed data.
  • check and ask for rectification. Users can verify the correctness of their data and request it be updated or corrected.
  • request limited procession. When certain conditions are met, users may request limited processing of their data. In this case, the data controller will not process the data for any purpose other than that for which it was obtained.
  • request the deletion or removal of personal data. When certain conditions are met, users can request the deletion of their data from the data controller.
  • receive their data or have it transferred to another data controller. Users has the right to receive their data in a structured format that is commonly used and readable by an automatic device and, where technically feasible, to obtain the unimpeded transfer to another data controller. This provision is applicable when the data is processed with automated tools and the processing is based on the consent of the user, on a contract of which the user is part or on related contractual measures.
  • lodge a complaint. Users can lodge a complaint to the relevant personal data protection supervisory authority or act in court.

Details on the right to deny processing

When personal data is processed in the public interest, in the exercise of public authority over which the data controller is invested or to pursue a legitimate interest of the data controller, users have the right to deny processing for reasons connected to their specific situation.

Users are reminded that, if their data was processed for direct marketing purposes, they can deny the processing without giving a reason. To find out if the data controller processes data for direct marketing purposes, users can refer to the appropriate sections of this site.

How to exercise rights

To exercise their rights, users may make a request to the data controller via the contact information available on this site. Requests are filed free of charge and processed by the data controller as soon as possible within one month.

This website uses cookies. To learn more and to view detailed information, the user may consult the Cookie Policy.

Further information on processing

Defense in Court

The personal data of the user can be used by the data controller in court or in the preparatory stages of establishing a defense against abuse in the use of this website or of related services committed by the user.
The user declares to be aware that the data controller may be required to disclose the data upon order of public authorities.

Specific Information

Upon request of the user, in addition to the information contained in this privacy policy, this website may provide the user with additional and contextual information regarding specific services, or the collection and processing of personal data.

System logs and maintenance

For needs related to operations and maintenance, this website and any third-party services it uses may collect system logs, i.e., files that record interactions and that may also contain personal data, such as the user’s IP address.

Information not included in this policy

Further information regarding the processing of personal data may be requested at any time from the data controller via the contact information available on this site.

Responses to “Do Not Track” requests

This website does not support “Do Not Track” requests.
To find out if any third-party services used by this website support “Do Not Track” requests, users are encouraged to consult the respective privacy policies.

Modifications to this privacy policy

The data controller reserves the right to make changes to this privacy policy at any time by informing users on this page and, if possible, on this website as well as. If technically and legally feasible, the data controller may also send a notification to users through one of the methods of contact made available to the data controller. Users are encouraged to visit this page regularly and to refer to the date of the most recent modifications, located at the bottom of the page.

If the modifications involve processing that legally requires consent, the data controller will collect the users’ consent again, if necessary.

Personal Data (or Data)

Personal data is any information that, directly or indirectly, even in connection with any other information, including a personal identification number, identifies or makes a person identifiable.

Usage Data

The information collected automatically through this website (also from third-party applications integrated in this website), including: the IP addresses or domain names of the computers used by the user to connect to this website, the addresses in URI format (Uniform Resource Identifier), the time of the request, the method used to send the request to the server, the size of the file obtained in response, the numeric code indicating the status of the response from the server (success, error, etc.) the country of origin, the characteristics of the browser and operating system used by the visitor, various time-related metrics of the visit (for example the amount of time spent on each page) and the details of the itinerary followed within the application, with particular reference to the sequence pages were consulted in, parameters relating to the operating system and the IT environment of the user.

User

The individual who uses this website who, unless otherwise specified, coincides with the data subject.

Data Subject

The natural person to whom the personal data refers.

Data Processor (or Processor)

The natural/legal person, public administration and any other entity that processes personal data on behalf of the data controller, according to what is stated in this privacy policy.

Data Controller (or Controller)

The natural or legal person, the public authority, the service or other body that, individually or alongside others, determines the purposes and means of personal data processing as well as the tools used, including security measures relating to the functioning and to the use of this website.

This Website (or this Application)

The hardware or software through which users’ personal data is collected and processed.

Service

The Service provided by this website as defined in the relevant terms (if any) on this site or application.

European Union (or EU)

Unless otherwise specified, any reference to the European Union contained in this document is extended to all current member states of the European Union and the European Economic Area.

Cookie

Small portion of data stored in the user’s device.


Legal References

The privacy policy is drafted on the basis of multiple legislative systems, including Articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy policy applies exclusively to this website.