Privacy policy

Privacy Notice

Provided to users of this website pursuant to Article 13 of Regulation (EU) 2016/679

Purpose of this page

In this notice novenove srl explains what personal data it collects through the website novenovedesign.it, the reasons for which it uses that data, who it is entrusted to, and the means available to users to keep it under their control. The applicable framework is Regulation (EU) 2016/679, referred to below as the "GDPR", together with Legislative Decree no. 196/2003 as amended by Legislative Decree no. 101/2018 (the "Italian Data Protection Code").

What follows applies to this website only. Third-party websites reachable through the links provided here are operated by separate entities, which are independently accountable for the data collected on their pages: before submitting any information, it is advisable to read their own privacy notices.

What data we collect

Meaning of personal data. This category covers any information that makes it possible to identify a natural person, whether directly or by combining it with other elements: a name, an identification code or number, contact details, an online identifier, location data, or a feature describing that person's physical, genetic, mental, economic, cultural or social identity (Article 4(1) GDPR).

Technical information generated by browsing. Operating the website entails receiving certain data that the user's browser transmits automatically with every request, without any deliberate input. This comprises the originating IP address, the address of the resource requested, the time and method of the request, the status returned by the server and the size of the response, together with details of the browser, device and operating system in use. This information is used to deliver the pages requested, to monitor the proper functioning of the infrastructure and to compile traffic counts that contain no individual references. In the event of cyber-attacks or other unlawful acts against the website or third parties, it may be made available to the competent authority.

Information provided voluntarily by the user. Anyone who writes to the addresses published on the website, or completes and submits one of the available forms, provides us with their contact details together with the content of the message and any other data they choose to enter in the fields. Fields that are essential in order to handle the request are indicated on screen at the time of completion, usually with an asterisk.

Data generated by the reading of e-mails. For those who subscribe to the newsletter, the sending platform records certain information on the delivery and the opening of individual messages. Full details are set out under purpose E) in section 2.

Data collected through cookies and similar technologies. These are addressed in the paragraph below and, in full, in the Cookie Policy.

Contact through social media channels. On any social media pages operated by the Controller, content posted or sent by users — comments, publicly visible posts, private messages — is read and responded to. Processing carried out by the platform on its own account is instead governed by the operator's own rules, as set out in the notices it makes available.

Specific notices. Individual pages or services may be accompanied by dedicated notices, which supplement this document in relation to that particular processing activity.

Cookies and tracking technologies

The website installs technical cookies, which are essential for the pages to work, and — only after the user has made an express choice through the banner — cookies and equivalent technologies that are not technical in nature. The list of active tools, their duration, the party that issues them and the instructions for changing one's mind at any time are set out in the Cookie Policy (/cookie-policy), which is also linked from the footer of every page.

1. Data Controller and contact details

Decisions on the purposes and means of the processing described here are taken by novenove srl, via Dante Alighieri 32, 22066 Mariano Comense (CO), which therefore acts as Data Controller within the meaning of Article 24 GDPR.

For any matter concerning their data, users may use the following contact details: telephone +39 031761394, e-mail info@novenovedesign.it.

2. Purposes of processing, legal bases and retention periods

A) Delivery and security of the website

Technical browsing information makes it possible to deliver the content requested, to detect malfunctions or intrusion attempts promptly, and to obtain overall measurements of how the website is used, such as the number of visits or the most frequently viewed pages.

The processing rests on the Controller's legitimate interest in keeping its website reachable, intact and protected (Article 6(1)(f) GDPR, read together with Recitals 47 and 49). Anyone who wishes may ask to be informed of the outcome of the balancing exercise carried out between that interest and users' rights.

Log files remain available for 30 days. That period is extended only where a specific event — a cyber offence, a request from the judicial authority — requires their retention.

Providing this data is not optional: its transmission is inherent in the protocols on which the Internet operates and cannot be disabled without giving up browsing altogether.

B) Cookies and equivalent technologies

The purposes, duration and ownership of the individual tools are described in the Cookie Policy, which forms an integral part of this notice, including as regards the relevant retention periods.

Technical cookies, which serve to make the website work and to provide what the user has expressly requested, rest on the Controller's legitimate interest and, under Article 122 of the Italian Data Protection Code, do not require prior authorisation. All other tools are activated only after consent has been obtained through the banner (Article 6(1)(a) GDPR and Article 122 of the Italian Data Protection Code); that consent may be withdrawn at any time by following the instructions in the Cookie Policy.

Non-technical cookies may always be refused, and doing so does not prevent access to any content.

C) Responding to enquiries sent through the website

Data entered in the contact form, or sent to the published e-mail addresses, is used to examine and respond to requests for information, requests for quotations and support enquiries, including any subsequent communications needed to bring the matter to a close.

Where the enquiry is aimed at assessing a possible contractual relationship — typically a request for a quotation or a question about a service — the processing serves to act on steps taken by the data subject prior to entering into a contract (Article 6(1)(b) GDPR). For enquiries of a different nature, bearing no relation to a contract, the basis is the Controller's legitimate interest in responding to those who reach out through the channels it has made public (Article 6(1)(f) GDPR).

Correspondence is retained for 12 months from the last exchange: this is the period considered sufficient to handle the matter and any follow-up on the subject. Where the enquiry gives rise to a contract, the retention periods applicable to that relationship and to the related accounting and tax obligations apply instead.

Without the data marked as required, the enquiry cannot be processed. The remaining fields are left to the sender's discretion and leaving them blank has no bearing on the reply.

D) Newsletter and promotional communications

By ticking the dedicated box in the form, the user asks to receive the Controller's newsletter by e-mail, together with informational, commercial and promotional communications about products, services, initiatives and events.

The basis is consent, which must be freely given, specific to this purpose, informed and withdrawable at any time (Article 6(1)(a) GDPR and Article 130 of the Italian Data Protection Code). The box is separate from any other, is not pre-ticked when the page loads, and leaving it blank does not prevent the form from being submitted.

The address remains on the list until consent is withdrawn and in any event for no longer than 24 months from the last interaction with the messages received, after which it is removed.

Subscribing is optional: declining means only that the newsletter will not be received and has no effect whatsoever on the reply to the enquiry referred to under purpose C).

E) Delivery verification and measurement of communications

The communications referred to under purpose D) are sent through a professional e-mail marketing platform. For each message and each recipient, that platform records whether delivery was successful and, if not, for what reason; whether the message was opened; which links were clicked; on what date and at what time; from which IP address and with which device, operating system and mail client. Measurement relies on a small image embedded in the message, commonly known as a pixel, and on the rewriting of the links contained in the text.

This data makes it possible to verify that communications actually arrive, to clear the list of addresses that have become inactive or that return errors, and to assess in statistical terms the overall performance of each send. It is not used to build a profile of the individual subscriber, to assign scores or interest categories, or to tailor the content of subsequent messages to that person.

This measurement likewise rests on consent (Article 6(1)(a) GDPR): it is a technical component of the newsletter service and ceases the moment consent to purpose D) is withdrawn. Independently of this, the user may prevent open tracking by disabling the automatic loading of remote images in their mail client.

Individual delivery, open and click events are deleted or anonymised after 12 months. Only aggregate statistics per campaign remain, from which it is not possible to identify who opened or clicked.

F) Handling data subject requests and statutory obligations

Data is used to act on requests submitted under Articles 15 et seq. GDPR and to comply with requirements imposed by law, regulations, European legislation or measures of the competent authorities.

The basis is the existence of a legal obligation to which the Controller is subject (Article 6(1)(c) GDPR).

The related documentation is retained for 5 years from the closure of the request, unless a dispute arises.

Provision of the data is essential: without identification data the request cannot be handled and the legal obligation cannot be met.

G) Protection of the Controller's rights

Personal data may be used to establish or defend a legal position of the Controller, whether before a court or out of court.

The basis is the legitimate interest in protecting its own rights (Article 6(1)(f) GDPR and Recital 47).

Retention covers the entire duration of the dispute and extends until the time limits for appeal have expired.

3. How data is processed

Processing is carried out using paper, electronic and telematic means and lasts no longer than is necessary to achieve the purpose for which the data was collected, in accordance with the principles of lawfulness, fairness, transparency, purpose limitation and data minimisation laid down in Article 5 GDPR. As required by Article 32 GDPR, the Controller maintains technical and organisational measures proportionate to the risk, designed to prevent data from being lost, falling into unauthorised hands or being used improperly.

4. Who data may be disclosed to

Certain processing activities require the involvement of external parties, acting either as Processors appointed under Article 28 GDPR or, where they determine their own purposes independently, as separate Controllers. Access is also granted to those working with the Controller and its suppliers, formally authorised and bound by written instructions (Article 29 GDPR).

The categories involved are as follows:

  • providers of hosting, maintenance, development and technical management of the website and IT systems;
  • providers of e-mail services and of platforms for sending newsletters and commercial communications;
  • providers of statistical traffic measurement tools, where activated subject to consent;
  • professionals and firms assisting the Controller in legal, accounting and IT matters;
  • public authorities, where a rule of law or a measure requires their involvement.

No data is disseminated, that is, made accessible to an indeterminate range of persons. An up-to-date list of the appointed Processors may be requested by writing to info@novenovedesign.it.

5. Transfers outside the European Economic Area

Some of the services described — in particular the newsletter sending platform and any traffic measurement tools — may be supplied by companies established outside the European Economic Area, or by European companies relying on sub-processors or servers located in third countries.

In such cases the transfer takes place only within the conditions laid down in Articles 44 et seq. GDPR: an adequacy decision of the European Commission, including the decision on the EU-U.S. Data Privacy Framework for certified providers in the United States, or the Standard Contractual Clauses approved by the Commission, accompanied where necessary by further technical and organisational measures.

Upon written request to info@novenovedesign.it, it is possible to find out which countries the data is actually transferred to and to obtain a copy of the safeguards in place.

6. Automated decision-making

No decision producing legal effects concerning the data subject, or similarly significantly affecting them, is taken solely on the basis of automated processing, including profiling, within the meaning of Article 22 GDPR.

7. Data subject rights and how to exercise them

The rights conferred by Articles 15 et seq. GDPR may be exercised at any time by writing to info@novenovedesign.it or by using the other contact details given in section 1. In summary, the data subject may:

  • find out whether processing concerning them is taking place and obtain a copy of the data together with the detailed information (Article 15);
  • have inaccurate data corrected or incomplete data completed (Article 16);
  • request the erasure of their data, in the cases permitted by law (Article 17);
  • request that processing be suspended and the data merely stored, in the cases provided for (Article 18);
  • receive, in a commonly used electronic format, the data processed by automated means on the basis of consent or of a contract, and where applicable have it transmitted to another controller (Article 20);
  • object, on grounds relating to their particular situation, to processing based on legitimate interest, and if they so wish ask to be informed of the balancing exercise carried out (Article 21(1)).

Objection to direct marketing. Objection to promotional communications, and to the related measurement described under purpose E), requires no justification, entails no cost and may be raised at any time (Article 21(2) and (3) GDPR). Once received, that processing ceases.

Withdrawal of consent. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out beforehand. To leave the list, it is sufficient to use the unsubscribe link at the foot of every message, or to send an e-mail to info@novenovedesign.it with the subject line "newsletter unsubscribe".

Duty to inform recipients. Where data is rectified, erased or restricted, the Controller notifies those to whom it had previously been disclosed, unless doing so proves impracticable or involves disproportionate effort; upon request, it informs the data subject of the identity of those recipients (Article 19 GDPR).

Complaint to the supervisory authority. Other administrative and judicial remedies remain unaffected. Anyone who considers that their data has been processed in breach of the GDPR may apply to the supervisory authority of the country in which they reside or work, or of the country in which the alleged infringement took place (Article 77 GDPR). For Italy this is the Garante per la protezione dei dati personali, the Italian Data Protection Authority (www.garanteprivacy.it).

8. Updates to this notice

The Controller may update this notice at any time. Changes are published on this page and take effect from the moment of publication; the date shown below identifies the version in force.