Privacy Policy – Processing of personal data
Pursuant to Article 13 of Regulation (EU) 2016/679
This Privacy Policy is provided in accordance with Article 13 of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, “GDPR”), to inform users of the website about how and why their personal data are collected and processed during browsing.
Data controller
The Data Controller of your personal data is MDCreate S.r.l. (hereinafter also “MDCreate”), VAT No. 12889570011, with registered office in Via Vela no. 42, Turin (Italy) (info@mdcreate.it).
Purposes, Legal Bases and Provision of Data
The Data Controller collects and processes different types of personal data for the following purposes:
- To enable users to browse the website. Browsing data (e.g. IP addresses or domain names of users’ computers) are acquired solely to obtain anonymous statistical information on the use of the website and to ensure its proper functioning. Legal basis: legitimate interest of the Data Controller in allowing users to browse the website and providing a fast, secure and efficient browsing experience. Provision of data: data are automatically provided during browsing. Users may choose not to provide data by not accessing the website, without any negative consequences.
- To respond to inquiries or requests submitted by users. Legal basis: legitimate interest of the Data Controller in responding promptly to user requests and providing information. Provision of data: users are free not to provide their data; however, in such case, the Data Controller will not be able to respond.
Recipients of Data
Users’ personal data may be processed by third parties acting as independent Data Controllers or as Data Processors on behalf of the Data Controller.
Recipients may include, for example:
- service providers (communication services, hosting, etc.)
- website development companies.
The full list of data recipients can be requested by contacting the Data Controller. Personal data will not be disclosed or made public.
Transfer of Data Outside the European Union
Data may be transferred outside the European Union. In such cases, transfers will take place in accordance with applicable laws, for example through Standard Contractual Clauses approved by the European Commission or other safeguards ensuring an adequate level of protection. For processing involving cookies, please refer to the relevant Cookie Policy.
Data Retention
The Data Controller will retain personal data only for as long as necessary to achieve the purposes for which they were collected. At the end of the retention period, data will be permanently deleted using secure deletion methods or anonymized in a way that does not allow, even indirectly, identification of the user.
Profiling
Data will not be used to derive information about users’ preferences or behavior, nor will users be subject to decisions based solely on automated processing of their personal data. For processing involving cookies, please refer to the relevant Cookie Policy.
Cookies
Cookies are pieces of information stored on the memory of computers, smartphones, or tablets used for browsing. Some cookies are necessary and essential for the basic functioning of the website. These are so-called technical cookies, used to provide certain services. For more information on the processing of personal data through cookies, please refer to our Cookie Policy.
User Rights
As data subjects, users may exercise at any time the rights provided for in Articles 15 et seq. of the GDPR, including:
- the right to access their personal data and obtain information about the processing;
- the right to obtain rectification, completion, erasure, or restriction of processing under certain conditions;
- the right to receive their personal data in a structured format and transmit them to another controller;
- the right to object to the processing of their personal data;
- the right not to be subject to automated decision-making.
Users may exercise their rights by sending a request to the email address of the Data Controller indicated above. The Data Controller will respond as soon as possible and in any case within 30 days.
Complaint
If users wish to lodge a complaint regarding how their personal data are processed or how a complaint has been handled, they have the right to submit a complaint to the supervisory authority, according to the procedures indicated on the website www.garanteprivacy.it.
Last update: febbraio 2026
