PRIVACY AND COOKIE POLICY
Through this Privacy and Cookie Policy, NI.VAL. GROUP SERVICE Srl, as the controller of personal data processing (hereinafter the “Controller”), describes how the personal data of users of this website are managed in accordance with EU Regulation 2016/679 on data protection (General Data Protection Regulation or GDPR).
The information below is provided pursuant to Article 13 of the GDPR to those who interact with the Site and complies with Recommendation No. 2/2001 on the minimum requirements for collecting data online in the European Union, adopted on 17 May 2001 by the Article 29 Working Party.
This notice does not apply to other websites that may be accessed through links on this Site, for which the Controller accepts no responsibility.
Controller contact details
The data controller is NI.VAL. GROUP SERVICE Srl, with registered office at Via F. Garofoli, 233 – 37057 S. Giovanni Lupatoto (VR), Italy.
Joint controllers
NIVAL GROUP SERVICE Srl manages all personal data acquired through this website jointly with the following companies, which also have their registered office at Via Garofoli, 233 - 37057 San Giovanni Lupatoto (VR), Italy:
- TEAM S.r.l.
- SAN MARTINO SERVIZI S.r.l.
- COOPERATIVA S.IN.CO.
The above companies have therefore entered into a joint controllership agreement pursuant to Article 26 of the GDPR. Further information may be requested by contacting the Controller.
Data Protection Officer
The Data Protection Officer is APTA Servizi Professionali Srl, Via F. Brindisi, 32 – 65017 Penne (PE), represented by Dr Eng Massimo Forestiero, who may be contacted at dpo@nivalgroup.com.
Limitation of liability
The Controller may not be held liable for damage of any kind caused directly or indirectly by access to the Site, by an inability or impossibility to access it, or by the use of information contained therein. Links to external websites are provided solely as a service to users, and no responsibility is accepted for the accuracy or completeness of those links.
The Controller also reserves the right to amend or update the Site’s content, in whole or in part, including as a result of changes to applicable law. The date of the latest update is shown at the bottom of this page.
Processing methods
Personal data collected through this website are processed using automated tools solely for explicit and specified purposes, lawfully, fairly and transparently in relation to the data subject, and are not used beyond the purposes for which they were collected.
Data minimisation (adequacy, relevance and limitation in relation to the purposes of processing), accuracy and confidentiality are therefore ensured.
To ensure appropriate protection of personal data provided by users and to prevent its loss, including accidental loss or theft, and unlawful use, the Controller has adopted technical and organisational measures that are monitored and updated when necessary.
Types of data processed
Data provided by the user
On the “Contact” page, after entering a name, surname, telephone number and email address (mandatory fields), users may request information by entering free text in the relevant field. Providing these data is required in order to send a message.
Where a user enters third-party data in the “message” field, the user is presumed to have been expressly authorised to provide it and therefore acts as an independent controller, assuming all obligations and responsibilities under the law and fully indemnifying the Controller against any dispute, claim or request for damages arising from it. Anyone providing false, misleading, bad-faith or otherwise inaccurate information bears full responsibility for doing so.
Failure to provide personal data may make it impossible to fulfil contractual and/or pre-contractual obligations undertaken towards you.
Browsing data
During normal operation, the IT systems and software procedures used to operate this website acquire certain personal data whose transmission is implicit in the use of Internet communication protocols.
This information is not collected in order to be associated with identified data subjects, but by its nature it could, through processing and association with data held by third parties, make it possible to identify users.
This category includes IP addresses or domain names of computers used by visitors, the URI/URL (Uniform Resource Identifier/Locator) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the response file, the numerical code indicating the server response status (successful, error, etc.) and other parameters relating to the user’s operating system and IT environment.
These data are used solely to obtain anonymous statistical information on use of the Site and to check that it is functioning correctly. As the data subject cannot be identified, this activity does not constitute personal-data processing.
Cookies
For a description of the cookies used by this website, please see our Cookie Policy.
Legal basis for processing
The legal basis for processing data acquired through this Site is:
- the Controller’s legitimate interest, with regard to browsing data and technical cookies;
- the performance of pre-contractual measures taken at the data subject’s request (Article 6(1)(b) GDPR), with regard to data entered in the “CONTACT” section;
- the data subject’s consent, with regard to the use of analytics cookies.
Recipients or categories of recipients
Personal data may be shared with:
- persons authorised by the Controller to process personal data who have undertaken confidentiality obligations;
- consultants acting as external processors, to the extent necessary to perform their duties, who are bound by confidentiality and security obligations;
- judicial authorities in the exercise of their functions where required by applicable law.
Personal-data retention period
The Controller will process personal data for the period strictly necessary to achieve the purposes set out in this Privacy Policy and for as long as permitted by Italian law to protect its interests (Article 2947 of the Italian Civil Code). Further information about the personal-data retention period and the criteria used to determine it may be requested by writing to the Controller.
Transfers outside the European Economic Area
Personal data will not be transferred to parties located outside the European Economic Area and will not be publicly disclosed.
Data-subject rights
Pursuant to Articles 15–22 of the GDPR, data subjects may contact the Controller at any time to request access to their personal data and to:
- obtain erasure, anonymisation or blocking of data processed unlawfully;
- obtain the updating, rectification and completion of data;
- obtain confirmation that such changes have been communicated to those to whom the data were disclosed;
- object on legitimate grounds to data processing or to any automated decision-making process, including profiling;
- obtain restriction of processing or portability to another controller;
- withdraw consent to processing for the purposes indicated above, without affecting the lawfulness of processing based on consent before its withdrawal;
- receive their data in a structured, commonly used and machine-readable format.
Data subjects also have the right to lodge a complaint with the competent supervisory authority, the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali), if they believe that the processing of their personal data does not comply with applicable law.
Last revised: 21 July 2026
