Privacy Policy
Updated: 2024In compliance with Regulation (EU) 2016/679 (European Regulation on the protection of personal data), we provide you with the necessary information regarding the processing of the personal data you provide. This information does not apply to other websites that may be accessible via links on the domain websites of the Data Controller, who is not in any way responsible for third-party websites.
1. Data Controller
The Data Controller is CINEDORA SRL, with registered office at GALLERIA CAVOUR N. 4, 40124 BOLOGNA, Italy – VAT no. 02730341209.
2. Personal Data Processed
- Browsing Data: The computer systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. These data are not collected to be associated with identified data subjects, but by their very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of computers used by users connecting to the site, URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the response status from the server (successful, error, etc.) and other parameters related to the user’s operating system and computing environment.
- Data Provided Voluntarily by the User: The optional, explicit and voluntary sending of emails to the addresses indicated on this site and/or the completion of data collection forms entails the subsequent acquisition of the sender’s address, which is necessary to respond to requests, as well as any other personal data entered.
- Tracking Data Collected by Site Cookies: A cookie is a small piece of data that a website stores on your computer or mobile device browser. This Privacy and Cookie Policy refers to all cookies and similar technologies (hereafter collectively referred to as “cookies”). Web pages have no memory. If you navigate from one page to another within a website, you will not be recognised as the same user across pages. Cookies allow a website to recognise your browser as a unique user. They also enable your preferences—such as your chosen language, currency, or search filters—to be remembered. Cookies allow you to be recognised during future visits as well. For cookie processing, please refer to the Cookie Policy available on this website.
3. Purpose and Legal Basis of the Processing
The personal data provided will be processed in accordance with the lawfulness conditions pursuant to Art. 6(f) of Regulation (EU) 2016/679 for the following purposes, unless objected to:
- Browsing this website;
- Any contact request, with subsequent sending of the information you requested;
- General administrative and accounting activities. For the purposes of data protection, these include organisational, administrative, financial, and accounting activities, regardless of the nature of the data processed. These include internal organisational functions, and activities aimed at fulfilling contractual or pre-contractual obligations and providing information.
The processing of data for these purposes is based on Article 6(1)(f) (Recital 47), considering the reasonable expectations of the data subject at the time and in the context of data collection, where the data subject may reasonably expect processing to occur for that purpose.
4. Data Recipients or Categories of Recipients
Your data will not be disseminated, except as explicitly indicated in this notice with your prior consent, and may be communicated to companies contracted in and outside the EU, in compliance with Articles 44 and following of Regulation (EU) 2016/679, to fulfil contracts or related purposes. Data may be communicated to third parties in the following categories:
- Parties providing services for the management of the information system and digital/telecommunications networks (including email services);
- Consulting firms or professionals providing assistance;
- Competent authorities for legal compliance and/or requests from public authorities;
- Parent or subsidiary companies for the provision of services (e.g. IT, accounting services).
Entities within these categories may act, where appointed, as Data Processors or as individuals acting under the authority of the Data Controller and the Data Processor (Article 29 of Regulation (EU) 2016/679), or they may operate independently as separate Data Controllers. An up-to-date list of appointed Data Processors is available at the Controller’s registered office. Any further communication or dissemination will only take place with your explicit consent.
5. Data Transfers to Non-EU Countries and/or International Organisations
Personal data are stored on servers located within the European Union. However, it is understood that the Data Controller may, if necessary, transfer the servers outside the EU. In such cases, the Controller guarantees that data transfers will comply with applicable legal provisions, including the adoption of standard contractual clauses approved by the European Commission or intergovernmental agreements such as the “Data Privacy Framework”.
6. Data Retention Period or Criteria for Determining It
Data will be processed using automated and/or manual methods with measures aimed at ensuring maximum security and confidentiality, by personnel specifically authorised to do so. Data will be retained for no longer than is necessary for the purposes for which they were collected and subsequently processed. Specifically:
- Website browsing (session duration);
- Contact requests and provision of requested information (maximum 12 months);
- General administrative/accounting activities (10 years or as otherwise required by law).
7. Nature of Data Provision
Apart from what is specified for browsing data, the user is free to provide personal data. Failure to provide personal data may result in the inability to use the services offered by the Data Controller.
8. Data Subjects’ Rights
You may exercise your rights as provided by Regulation (EU) 2016/679 by contacting the Data Controller at info@edbservice.net, or by sending a letter to the address indicated above. In particular, you have the right to:
- Obtain confirmation of whether your personal data are being processed, and if so, access to the data and further information including: the types of personal data; recipients or categories of recipients; data retention period or criteria for determining it;
- Request the rectification, erasure, or restriction of processing of your personal data;
- Object to the processing of data;
- Lodge a complaint with a supervisory authority;
- Receive information regarding the source of the data, if not collected from the data subject;
- Know the existence of automated decision-making (including profiling, as per Art. 22 GDPR);
- Receive details of guarantees in the event of data transfers to a third country or international organisation (Arts. 44 et seq. GDPR);
- Obtain a copy of the personal data being processed.