Privacy Policy
This notice is provided pursuant to Article 13 of EU Regulation 2016/679 (hereinafter "GDPR") and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, to those who consult the website www.primehabitat.net.
This policy describes how the personal data of users interacting with the site is processed, in compliance with European and Italian data protection legislation.
1. Data Controller
Prime Habitat S.r.l.
Registered office: Via Pesciatina 197 — 55012 Capannori (LU), Italy
VAT No. / Tax Code: 02725210468
Business Register: Chamber of Commerce Toscana Nord-Ovest — REA LU-266416
Email: info@primehabitat.net
Certified email (PEC): primehabitatsrl@pec.it
Phone: +39 379 110 7668
2. Types of data processed
2.1 Browsing data
During their normal operation, the IT systems and software procedures used to operate this website acquire certain personal data whose transmission is implicit in the use of Internet communication protocols. This category includes IP addresses, browser type, operating system, request timestamp and other parameters relating to the user's operating system and IT environment. This data is used solely to obtain anonymous statistical information on site usage and to ensure its proper functioning.
2.2 Data provided voluntarily by the user
The optional, explicit and voluntary sending of email messages to the addresses indicated on this site entails the subsequent acquisition of the sender's address, necessary to respond to requests, as well as any other personal data included in the communication. The data will be processed exclusively to follow up on the user's request.
2.3 Cookies and tracking tools
This site does not use profiling cookies or tracking tools for advertising or behavioural analysis purposes. The site only uses technical cookies strictly necessary for its operation, for which consent is not required pursuant to Article 122 of Italian Legislative Decree 196/2003.
The site uses Google Fonts for the display of typefaces. The service is provided by Google Ireland Ltd. and may involve the transmission of the user's IP address to servers located also outside the European Union. Google Fonts is used on the basis of the Controller's legitimate interest in offering a consistent and pleasant browsing experience. For further information, please refer to Google's privacy policy: policies.google.com/privacy.
3. Purpose of processing and legal basis
Personal data is processed for the following purposes:
- Responding to contact requests: processing is necessary to follow up on explicit requests from the data subject (Art. 6(1)(b) GDPR — performance of pre-contractual measures).
- Complying with legal obligations: processing is necessary to comply with legal obligations to which the Controller is subject (Art. 6(1)(c) GDPR), such as tax, accounting and administrative obligations.
- Ensuring the proper functioning of the website: processing is based on the Controller's legitimate interest in maintaining the security and functionality of the website (Art. 6(1)(f) GDPR).
4. Processing methods and security
Personal data is processed using IT and electronic tools, with logic strictly related to the indicated purposes and, in any case, in such a way as to guarantee the security and confidentiality of the data. The Controller adopts adequate technical and organisational measures to prevent the loss, unlawful or incorrect use of, and unauthorised access to the data, pursuant to Articles 24, 25 and 32 of the GDPR.
5. Communication and dissemination of data
The personal data collected is not subject to dissemination to indeterminate parties. It may be communicated to:
- Employees and collaborators of the Controller, authorised to process data according to their duties.
- Technical service providers (e.g. hosting services, email providers), appointed as Data Processors pursuant to Article 28 GDPR, who operate exclusively according to the Controller's instructions.
- Public or administrative authorities, where required by law.
The updated list of Data Processors is available at the Controller's registered office.
6. Transfer of data abroad
Personal data is primarily processed within the European Union. If, for technical or organisational reasons, it becomes necessary to transfer data to third countries not deemed adequate according to European Commission standards, the Controller will adopt the safeguards provided for by Articles 44 et seq. of the GDPR (Standard Contractual Clauses, binding corporate rules or other appropriate measures).
7. Data retention period
Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected:
- Contact data (email): for the time necessary to handle the request and, in any case, no longer than 24 months from the last communication, unless legal obligations require longer retention.
- Browsing data: retained for the technical period necessary to provide the service, in any case no longer than 7 days, without prejudice to any investigations of computer crimes by the judicial authorities.
- Administrative and tax data: retained for 10 years as required by applicable civil and tax legislation.
8. Data subject rights
Pursuant to Articles 15 to 22 of the GDPR, the data subject has the right to:
- Access (Art. 15): obtain confirmation as to whether or not personal data concerning them is being processed and access such data and related information.
- Rectification (Art. 16): obtain the correction of inaccurate personal data or the integration of incomplete data.
- Erasure / Right to be forgotten (Art. 17): obtain the erasure of personal data, in the cases provided for by law.
- Restriction of processing (Art. 18): obtain the restriction of processing where the applicable conditions are met.
- Portability (Art. 20): receive personal data in a structured, commonly used and machine-readable format, and transmit it to another controller.
- Objection (Art. 21): object to the processing of personal data on grounds relating to their particular situation, including processing for direct marketing purposes.
- Complaint (Art. 77): lodge a complaint with the competent supervisory authority (Garante per la Protezione dei Dati Personali — www.garanteprivacy.it).
To exercise their rights, the data subject may contact the Controller at any time using the contact details provided in Section 1 of this notice. The Controller undertakes to respond within 30 days of receiving the request, which may be extended by a further 60 days in particularly complex cases.
9. Changes to this policy
This policy may be subject to changes over time, including as a result of regulatory developments or changes in processing methods. Users are encouraged to periodically consult this page for any updates. In the event of material changes, the Controller will provide appropriate notice on the site.