Privacy Policy

Privacy Policy

Article 13 of Regulation 2016/679 (GDPR)

1. WHY THIS NOTICE

This page describes the processing of personal data carried out by TECNORD Srl in relation to all categories of data subjects (hereinafter “data subjects”, e.g. Article 4(1) of the GDPR) who browse this website https://www.tecnord.com, and with the aim of setting out the Company Policy adopted to ensure compliance with the provisions of GDPR 2016/679, Italian Legislative Decree 196/2003, national provisions on this matter, Guidelines issued by the European Data Protection Board, as well as EU Directives relating to the protection of personal data. This is a privacy notice provided pursuant to Article 13 of EU Regulation 2016/679 to those who establish any form of relationship with this Company.

This privacy notice applies solely to the TECNORD Srl website and does not apply to any other websites that the user may access via links contained therein. Personal data subject to processing are also handled in light of technological innovations in such a way as to minimise, through appropriate preventive security measures, the risk of their destruction or loss, including accidental loss, unauthorised access to the data, or processing operations that are either unlawful or incompatible with the purposes for which the data were collected. Only those operations necessary to achieve the purposes indicated in this document and in the other notices provided to users at the time of data collection are carried out on the data.

2. IDENTITY AND CONTACT DETAILS OF THE DATA CONTROLLER

The data controller is TECNORD Srl, with its registered office at Via Malavolti 36, Modena (MO), tax code and VAT number IT 01914150360, tel +39 (059) 254895, fax +39 (059) 253512, e-mail: gdpr@tecnord.com.

3. CONTACT DETAILS OF THE DATA PROTECTION OFFICER

TECNORD Srl has appointed a Data Protection Officer (DPO) in accordance with Articles 37–39 of the GDPR. The DPO office is located in Modena (MO), Via Malavolti 36. Any enquiries may be sent to the email address gdpr@tecnord.com, or by calling +39 (059) 254895.

4. TYPES OF DATA PROCESSED

4.1. CONTACT REQUEST DETAILS

The optional, explicit and voluntary provision of personal data required to make an enquiry via the forms on this website, or via any email addresses listed on this website, entails the subsequent collection of only the data necessary to respond to the enquiries submitted.

Purpose and legal basis of the processing
(GDPR Article 13(1)(c))
This data is used solely for the purpose of responding to enquiries submitted via the forms on this website, or via any email addresses provided on this site.
Categories of personal data - personal details (first name, surname),
- contact details (email address, telephone number),
- any other data or information included in the request.
Scope
(GDPR Article 13(1)(e) and (f))
The data is processed exclusively by authorised staff who have been instructed in data processing and have received appropriate training. It may also be processed by other parties involved for purposes related to the processing itself (website management support; consultancy firms): these parties act as data processors and have entered into specific agreements in accordance with Article 28(3) of the GDPR.
Methods of processing
(GDPR Recital 39)
Personal data is processed lawfully, fairly and transparently, in accordance with the principles set out in current legislation. Personal data is processed using IT and automated tools. Taking into account the nature and characteristics of the processing, technical and organisational security measures have been put in place to minimise or eliminate the risks of data loss, unlawful or improper use, or unauthorised access.
Data retention
(GDPR, Article 13(2)(a))
Data is normally retained for short periods of time, solely for the purpose of responding to enquiries received.
Delivery
(GDPR, Article 13(2)(f))
Personal data is retained for as long as is necessary to manage the relationship with the applicant.
Lawfulness
(GDPR, Article 6(1))
The processing is necessary to respond to enquiries received; therefore, consent is given by completing the forms or by sending messages using any email addresses provided on this website.

4.2. CONTACT DETAILS FOR CLIENT COMPANIES AND SUPPLIER COMPANIES

The personal data provided by the individuals concerned, or collected by the undersigned in the course of activities arising from contractual relationships, is necessary for the performance of the activities agreed between the parties.

Purpose and legal basis of the processing
(GDPR Article 13(1)(c))
Data is collected and used for the following purposes:
- to enter into contractual or professional relationships;
- to fulfil pre-contractual, contractual and tax obligations arising from existing relationships, as well as to manage the necessary communications relating to them;
- to comply with obligations laid down by law, regulations, EU legislation or an order from the Authority;
- exercise a legitimate interest and a right of the Data Controller (for example: the right of defence in court proceedings, the protection of credit claims; ordinary internal operational, managerial and accounting requirements).
Scope
(GDPR Article 13(1)(e) and (f))
The data is processed exclusively by internal staff who are duly authorised and trained in data processing (GDPR Article 29) and will not be disclosed to external parties, disseminated or transferred to countries outside the EU. In any other cases, this will be specified in the relevant form.
Methods of processing
(GDPR Recital 39)
Personal data is processed lawfully, fairly and transparently, in accordance with the principles set out in current legislation. Personal data is processed using IT and automated tools. Taking into account the nature and characteristics of the processing, technical and organisational security measures have been put in place to minimise or eliminate the risks of data loss, unlawful or improper use, or unauthorised access.
Data retention
(GDPR, Article 13(2)(a))
Data is normally retained for short periods of time, strictly necessary to fulfil contractual or regulatory obligations.
Delivery
(GDPR, Article 13(2)(f))
The data is requested by the undersigned for the purposes indicated.
Lawfulness
(GDPR, Article 6(1))
The processing is necessary for the performance of a contract, and therefore consent is not required.

4.3. INTERNET BROWSING DATA

The IT systems and software procedures used to operate this website automatically collect certain personal data during their normal operation; the transmission of this data is implicit in the use of Internet communication protocols. This category of data includes the IP addresses or domain names of the computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the user’s operating system and IT environment.

Purpose and legal basis of the processing
(GDPR Article 13(1)(c))
This data is used solely to obtain statistical information on the use of the website and to ensure it is functioning correctly. The data may also be used to establish liability in the event of any cybercrimes committed against the website (legitimate interests of the data controller).
Scope
(GDPR Article 13(1)(e) and (f))
The data is processed exclusively by internal staff who are duly authorised and trained in data processing (GDPR Article 29) and will not be disclosed to external parties, disseminated or transferred to countries outside the EU. It may only be made available to the competent authorities in the event of an investigation. In other cases, this will be specified in the relevant form.
Data retention
(GDPR, Article 13(2)(a))
Data is normally retained for short periods of time, except where retention is extended in connection with investigations.
Delivery
(GDPR, Article 13(2)(f))
Non-identifiable data is collected automatically and without the need to seek consent. Identifiable data is provided voluntarily by the data subject following the giving of consent.

4.4. COOKIE

For further general information about cookies and how to enable or disable them, please refer to the Cookie Policy.

5. RIGHTS OF THE DATA SUBJECT (GDPR Articles 15–22)

At any time, the data subject may exercise the right to:

  • request confirmation as to whether or not personal data concerning them is held;
  • obtain information regarding the purposes of the processing, the categories of personal data, the recipients or categories of recipients to whom the personal data has been or will be disclosed and, where possible, the retention period;
  • obtain the rectification and erasure of the data;
  • obtain restriction of processing;
  • obtain data portability, i.e. receive the data from a data controller in a structured, commonly used and machine-readable format, and transmit it to another data controller without hindrance;
  • object to processing at any time, including in the case of processing for direct marketing purposes;
  • object to automated decision-making relating to natural persons, including profiling;
  • lodge a complaint with the Italian Data Protection Authority.

Requests should be addressed to the Data Controller by writing to the email address provided for the processing operations described. Every effort will be made to ensure that the features of this website are as interoperable as possible with the automatic privacy control mechanisms available in certain products used by users.

This information document is updated as of 24/04/2026.