This policy describes how Cassani SRL processes personal data of users who visit www.cassanisrl.it and use our contact services, in compliance with EU Regulation 2016/679 (GDPR) and applicable Italian law.
Data controller
The data controller is Cassani SRL, registered office at Via Lamarmora 233/235, 18038 Sanremo (IM), Italy, VAT IT00388710089.
For any privacy-related request you may write to info@cassanisrl.it or to our certified email cassani@pec.it.
Personal data processed
Through the site we may process: identification and contact data (name, email, phone) submitted via the contact form; technical browsing data (IP address, browser type, pages visited, interaction events) collected automatically by IT systems and, with consent, via Google Analytics; language preferences and cookie consent choices stored locally in the browser.
Purposes of processing
Data submitted through the contact form is processed to respond to information and quote requests.
Technical data is used to ensure security and proper site operation.
With your consent, Google Analytics collects statistical data on site usage (pages visited, traffic source, device type) to improve content and navigation.
Language and cookie preferences are used to personalize the browsing experience and respect user choices.
Legal basis
Processing of contact form data is based on Art. 6(1)(b) GDPR (pre-contractual measures at the data subject's request) and, where applicable, on consent given by submitting the form.
Technical cookies and strictly necessary preferences are based on Art. 6(1)(f) GDPR (legitimate interest) and applicable Italian ePrivacy rules.
Loading Google Maps, if accepted, is based on user consent (Art. 6(1)(a) GDPR), which may be withdrawn at any time.
Google Analytics is activated only after explicit consent via the cookie banner (Art. 6(1)(a) GDPR), which may be withdrawn at any time.
Retention period
Contact form requests are kept for as long as needed to manage the business relationship and, in any case, no longer than 24 months from the last contact, unless longer retention is required by law.
Technical log data is retained for limited periods compatible with security purposes.
Data collected via Google Analytics is retained according to Google's stated periods and for as long as needed for the statistical purposes described.
Cookie and language preferences remain stored until deleted by the user or until natural browser expiry.
Disclosure and transfers
Data may be processed by providers supporting site delivery (hosting, contact form email service Web3Forms) as data processors.
Google Maps, if accepted, may involve processing by Google LLC. See Google's privacy policy for details.
Google Analytics, if accepted, processes browsing data via Google LLC (United States). Google may transfer data outside the EEA with appropriate safeguards. See policies.google.com/privacy.
We do not sell or transfer personal data to third parties for marketing purposes.
Data subject rights
You have the right of access, rectification, erasure, restriction, objection and portability, as provided by the GDPR.
You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
You also have the right to lodge a complaint with your supervisory authority.
Security
We adopt appropriate technical and organizational measures to protect personal data from unauthorized access, loss or alteration.
Changes to this policy
We may update this policy. The date of the last update is shown above. Please review it periodically.