Privacy policy

Pursuant to and for the purposes of Art. 13 of EU Regulation No. 679/2016 on the protection of natural persons with regard to the processing of personal data ('GDPR')

With this privacy policy, Nextmind S.r.l. provides information regarding the processing of the User's personal data carried out through this Website, concerning both navigation within the Site and the activation of the specific service promoted by the Company (hereinafter, the "Service"), confirming henceforth that such processing will be based on the principles of correctness, lawfulness, transparency, and the protection of the User's privacy and rights.
DATA CONTROLLER
The Data Controller is Nextmind S.r.l., with registered office at Via Grande n. 225, 57123 Livorno (LI), Italy, and operational offices at Via Giovanni del Pian dei Carpini, 1, 50127 Florence (FI), Italy, and Via Aurelio Lampredi, 45, 57121 Livorno (LI), Italy - Email address: privacy@nextmind.it
TYPES OF DATA PROCESSED
  • Navigation data: these are data whose transmission is implicit in the use of the Internet, including data such as: the IP address of the device connected to the Website, the type of browser used, the name of the internet service provider (ISP), the date and time of the visit, and other parameters relating to the user's operating system and IT environment.
  • Data collected through cookies: for more information, please refer to the extended cookie policy.
  • Data requested for the activation of the Service: these are the data and/or information provided by the user through the specific form on the Website, necessary to provide the service and manage billing, including:
    • Company identification and tax data (name, company name, registered office, VAT number);
    • Data necessary for electronic invoicing (SDI code);
    • Identification and contact details of the individual company contact person (first and last name, role, telephone number, email address).
  • Data optionally provided by the user through the Data Controller's email or telephone contacts available on the Website, including identification and contact data.
PURPOSES AND LEGAL BASIS
In compliance with the conditions of lawfulness pursuant to Art. 6 of the GDPR, Personal Data will be used for the following purposes and legal bases:
  1. PURPOSE: Ensure the proper functioning of the website.
    LEGAL BASIS: Legitimate interest (Art. 6, paragraph 1, letter f, of the GDPR).
  2. PURPOSE: Provision of the Service activated by the user by filling out the dedicated form and operational management of the relationship (e.g., activation, file management, service communications).
    LEGAL BASIS: Performance of a contract or pre-contractual measures (Art. 6, paragraph 1, letter b, of the GDPR).
  3. PURPOSE: Administrative-accounting management and billing (including electronic invoicing and accounting records).
    LEGAL BASIS: Compliance with legal obligations (Art. 6, paragraph 1, letter c, of the GDPR) for billing and accounting (tax/fiscal regulations) and performance of a contract (Art. 6, paragraph 1, letter b, of the GDPR).
  4. PURPOSE: Respond to requests for information received through the telephone or email contacts made available on the Website.
    LEGAL BASIS: Compliance with pre-contractual and/or contractual obligations (Art. 6, paragraph 1, letter b, of the GDPR).
METHODS OF PROCESSING
The Data Controller processes Personal Data in compliance with current national (Legislative Decree 196/2003 and subsequent amendments) and European (EU Reg. 679/2016) legislation on the protection of personal data. The processing operations are carried out by specifically authorized personnel, also through the use of IT and telematic tools suitable to guarantee data security, adopting adequate technical and organizational measures to ensure the security and confidentiality of the information.
NATURE OF THE PROVISION OF DATA
The provision of the data requested for the activation of the Service is to be considered mandatory for the management of the contract and related billing. The provision of navigation data is mandatory, as such data are automatically acquired by IT systems and are necessary for the proper functioning of the Website; whereas the provision relating to cookies varies depending on the type of cookies installed: for non-technical cookies it is optional and subject to consent, as indicated in the cookie policy.
RETENTION PERIOD

In compliance with the provisions of Art. 5 of the GDPR, Personal Data will be kept for the period of time strictly necessary for the purpose for which they were acquired. In particular, the data provided by the user for the activation of the Service will be kept for the entire duration of its provision and, subsequently, for the time necessary to fulfill legal obligations regarding tax and accounting matters, as well as for the management of any disputes within the terms of the law. Once the purpose for which the data were collected has been fulfilled, they will be deleted or anonymized.

Regarding navigation data and data collected through cookies or other tracking tools, please refer to the contents of the Cookie Policy.

DATA TRANSFER TO THIRD COUNTRIES
In the event of a transfer of Personal Data to third parties located outside the European Union, such transfer will take place pursuant to and for the purposes of Art. 44 et seq. of the GDPR on the basis of: (a) adequacy decisions of the European Commission issued in favor of third countries; (b) adequate safeguards provided by the third-party recipient; (c) binding corporate rules. The Data Controller may use IT and cloud service providers who, for technical and organizational needs, may involve processing/access also from third countries; in this case, the guarantees indicated above will apply.
CATEGORIES OF DATA RECIPIENTS

Personal Data will not be subject to disclosure; however, they may be communicated to:

  • third parties who carry out certain processing activities and/or related and instrumental activities on behalf of the Data Controller, such as technical and/or organizational activities, including the management of the IT system, telecommunications networks (including email), IT and cloud service providers for the provision and management of digital platforms (e.g., hosting, storage, and collaboration services), appointed, where necessary, as Data Processors pursuant to Art. 28 of the GDPR.
  • competent authorities for the fulfillment of legal, contractual, or tax obligations.

The updated list of Data Processors or parties involved in various capacities is available upon request.

DATA SUBJECT'S RIGHTS

At any time, pursuant to Art. 15 et seq. of EU Regulation 2016/679, the User - as the data subject - may exercise the following rights, provided the necessary conditions are met:

  • access the data processed by the Data Controller, obtain information on certain aspects of the processing, and receive a copy of the processed data (Art. 15 GDPR, Right of access);
  • verify the correctness of their data and request its updating or rectification (Art. 16 GDPR, Right to rectification);
  • obtain the deletion or removal of their personal data by the Data Controller (Art. 17 GDPR, Right to erasure);
  • obtain the restriction of the processing of their data, when certain conditions are met (Art. 18 GDPR, Right to restriction of processing);
  • receive their data in a structured, commonly used, and machine-readable format, where technically feasible (Art. 20 GDPR, Right to data portability).
  • object to the processing of their data when it takes place on a legal basis other than consent (Art. 21 GDPR, Right to object).

The exercise of the aforementioned rights may take place by sending an email request to the address: privacy@nextmind.it

Lastly, the User has the right, at any time, to lodge a complaint with the Data Protection Authority or to take legal action.